Estate & architecture
One portfolio. Selective systems.
Every CyberG7 estate group gets a role across the business. Each SME buys only the subset needed to move its chosen workflow. Jarvis coordinates; WhatsApp communicates; business records remain authoritative.
The operating loop
- 01Outside the businessWeb, AEO, creative and referrals
- 02At the boundaryWhatsApp and one operator queue
- 03Inside the businessJarvis policies and record systems
- 04Across the loopAnalytics, Academy and GRC evidence
Use the whole portfolio across CyberG7’s business; keep each SME scope bounded.
A useful division of responsibility
Separate the system of interaction (conversation), system of decision (policy/approvals), system of record (business objects) and system of evidence (outcomes, cost and acceptance). Jarvis can join the loop; it should not silently replace the financial ledger or grant the customer new privileges.
| Layer | Named assets | Selected job | Boundary |
|---|---|---|---|
| Acquire / distribute | Corporate, agency, .digital, LaunchFast/LaunchNow, blog, ebook, AEO, retailer | Client-facing discovery or optional separately contracted growth work | Neither site count nor AEO score is a grant productivity result. |
| Engage | GPT WhatsApp, 88bots, Botsify chatbot, Vapi voice | One bounded customer channel and owned handover | Choose one runtime/queue; voice is a separately proven variation. |
| Orchestrate | Jarvis / Agent OS / Mission Control, Helix, Hermes / roles | Propose, validate, approve, execute, receipt and reviewed learning | An OS or three agents does not create three ERP functions. |
| Keep records / execute | GHL now; proposed Twenty, Chatwoot, Cal.com, n8n, Formbricks/Typebot, listmonk | One authoritative object record, integrations and next-action ownership | Roadmap modules and cold legacy services are not client deployments. |
| Create / measure | SynapticOne, Ad Analytics, AEO cohorts, publisher | Reviewed content and source-to-business-outcome reporting | Verify connectors and real data; seeded demonstrations are not causal proof. |
| Govern / adopt | CyberGRC / API, MSSP/security, Academy | Permissions, evidence, processing, operating SOP and competency | No inferred certification or grant approval; course count is not adoption. |
| Produce efficiently | Website factory, SaaS MVP Factory, cyberg7-skills / ClaudeGenie | Reusable supplier delivery/test assets | CyberG7 internal tools are not automatically client-funded expenditure. |
| Demonstrate / reserve | Vertical spec builds, previews, scratch and dormant surfaces | Labelled workflow education and future options | No reference clients or claim proof inferred from a preview. |
Source: Supplied August estate map ↗ · Updated receptionist demonstration ↗
Three SME assemblies
| Assembly | Core selected system | Optional expansion | Required result |
|---|---|---|---|
| Lynn Beauty | WhatsApp + signed facts + CRM/inbox + operator + Jarvis brief | Calendar after proof; AEO/Synaptic/voice only where needed | Accepted request → confirmation → attendance. |
| Kim Pong | WhatsApp intake + actual sales/service/finance ERP + Jarvis approvals | AEO acquisition and CRM adapters without duplicate authority | Completed job → correct invoice without reconstruction. |
| GetSGPR | Public facts + secure workspace/case record + reviewed AI checklist + consultant | Broader cross-system integration only if economic gate passes | Complete source-linked file accepted for consultant review. |
Academy and GRC support all three through role competence and operating controls. Ad Analytics supports only a verified data connection and a defined outcome cohort. A client’s marketing and implementation costs remain separately itemised; inclusion in the architecture does not imply grant eligibility.
The Jarvis action contract
| Step | Rule | Receipt |
|---|---|---|
| Propose | Read only the authorised tenant facts/records | Source and proposed action ID. |
| Validate | Check permitted action, fields, limits and current state | Validation result and exception reason. |
| Approve | Routine replies use owner-approved policy; transactions require the appropriate approval | Approver, actual final values and expiry. |
| Execute | Use a scoped tool adapter, duplicate protection and recoverable retry | Business record ID and delivery/operation result. |
| Reconcile | Confirm record/output state and operator ownership | Accepted next step and remaining exception. |
| Improve | Propose knowledge/process changes for review | Versioned approved change; no unreviewed learning changes policy. |
Choose GHL or the validated migration target as the authoritative opportunity record. A future Twenty/Helix/Hermes stack is a direction, not current production proof. Keep a separate ERP where genuine operations/finance are required.
Known readiness gaps affect the plan
| Dated source observation | Delivery consequence | Gate |
|---|---|---|
| 2 Oct handoff update: booking-request capture and owner alert documented as deployed | After an invitation, the next message supplies day/time to a fixed handoff; nothing is booked until the confirmer replies | Witness client-tenant behaviour, staff acknowledgement and authoritative calendar confirmation before “booking automation”. |
| 2 Oct handoff: hosted logging still not started; demo settings must close before a client number goes live | The deployed request handoff does not establish accepted client reporting, exports or operational acknowledgement | Client production configuration, delivery/acknowledgement/error logs, report/export and client acceptance. |
| Aug 4 Ad Analytics: dark publisher, connector/telemetry/strategist gaps | Public/seeded dashboards do not establish real client attribution | Verify connector, consent/access, events and paid-outcome reconciliation. |
| Local CRM: legacy Baserow and nine services cold/off | Old “live” documentation can mislead the solution scope | Confirm the selected actual deployment and migration ownership. |
The receptionist handoff entry marked 2 October was reviewed for this update; other local documentation and grant rules were reviewed October 1. These are documentation observations, not an independent runtime audit or a fresh audit of the whole estate. Sources: business/HANDOFF-2026-10-01.md §§2–4, including its 2 October update; receptionist-site README “Known gaps”; CRM README “Current direction”; Ad Analytics handoff revised August 4. No secrets or customer exports were used.
The full named estate inventory
Brand and entry surfaces
| Named surfaces | Role / disposition |
|---|---|
| agency.cyberg7.com.sg; cyberg7.com.sg; cyberg7.digital | Canonical identity and offer routing; consolidate different audiences/prices. |
| cyberg7.com; www.cyberg7.com.sg; agency-demo.cyberg7.com.sg | August expired/dark/alias respectively; historical state, not fresh audit. |
| blog.cyberg7.com.sg; blog.cyberg7.com; blog.cyberg7.digital; ebook.cyberg7.com.sg | Education/distribution; .com.sg live in August, other blogs dark, ebook thin. |
| launchfast.cyberg7.com.sg; launchnow.cyberg7.com.sg; helix.cyberg7.com.sg | Website entry products and consulting/orchestration positioning; do not count as distinct core functions. |
Products, platforms and delivery services
| Named surfaces | Selected role |
|---|---|
| jarvis-agent; jarvis; app; helix | Public assistant, internal Mission Control, GHL and policy/orchestration. |
| whatsapp; wa; 88bots; chatbot; voiceai1256; auto | Updated GPT channel/runtime, engagement variations and labelled demo. |
| aivisibility; synaptic; ads | AEO, 15-tool AI/media workspace and campaign analytics. |
| academy; claudegenie; mvp | Training, builder skills and seven-agent blueprint / delivery tooling. |
| grc; grc-api; CyberG7 security/MSSP services | Governance workspace/backend and contracted controls; no inferred certification. |
| Website factory; Twenty/Helix/Hermes; n8n/Chatwoot/Cal.com/Formbricks/Typebot/listmonk; later Mautic/Metabase | Local direction and replaceable modules; verify deployment rather than assuming they run for clients. |
Unqualified subdomains in this group are under cyberg7.com.sg. Public tool lists and local architecture are capability references, not accepted client deployments.
Vertical demonstrations and real business references
| Named surfaces | Role / proof boundary |
|---|---|
| logistics-demo; education-demo; tkl-demo | Strait Logistics, Lumen Academy and group-buying demonstrations/prototype. |
| kopi-atelier-preview; cathode-ledger-preview | Wholesale/roastery and accounting previews, not funded clients. |
| kimpong.com.sg; lynnbeauty.com.sg; getsgpr.com | Public trading-business context; relationship, eligibility and deployment require confirmation. |
| retailer.sg; sgbizsolution.com; lingoexpress.com.sg; normalasia.com | Directory, parked and historical dark distribution/localisation/health-beauty surfaces; no current active delivery inferred. |
Internal, dormant and reserve properties
demo.cyberg7.com.sg; retail.cyberg7.com.sg; test.cyberg7.com.sg; members.cyberg7.com.sg; platform.cyberg7.com.sg; master-claude.cyberg7.com.sg; demo1.cyberg7.com.sg; ecommerce.cyberg7.com.sg; realestate.cyberg7.digital; immigrant.cyberg7.digital; shop.retailer.sg.
These are preview, scratch, default, dark or broken surfaces in the supplied August snapshot. Assign no client outcome or grant value until a specific service is intentionally activated and verified. The artifact reports 54 hostnames; this is a role mapping of its named groups plus later products, not a new hostname-count reconciliation or HTTP scan.
A fourth industry pattern worth demonstrating
Wholesale/roastery is a stronger ERP teaching example than another general chatbot: WhatsApp order → stock/production plan → fulfilment → invoice. Kopi Atelier is a preview, so it cannot serve as a real applicant or customer reference. Discover a genuine wholesaler before pricing or making eligibility claims.
This pattern shows how the same Jarvis/WhatsApp architecture can be reused while the authoritative business objects change.