TOME — THE PLATFORM UNDER EVERY WABBIT BUILD

It’s how we work. Lately, it’s also what we sell.

Tome is the application platform every Wabbit build runs on — dozens of packages, live in production and actively maintained under everything we ship. Because the foundation is already built — identity, permissions, commerce, the machinery every platform needs — your budget goes to the part that’s actually yours instead of rebuilding plumbing. That’s how a platform launches in months instead of years.

We didn’t build it to sell. We built it because the alternative was watching every client project turn into a fight with the architecture.

Why it exists

For years, we built on other people’s parts.

WordPress, mostly — and we still reach for it when it fits. But our clients kept needing things the parts couldn’t do, and we kept walking into the same three walls.

A membership organization

needed permissions that followed the org chart: a unit leader who could see her own teams and no one else’s, access that flexed as people moved. WordPress offered four flat roles. Rigid. All-or-nothing.

Wall.
A client’s money

needed to move cleanly — out of one account, into another, every change on the ledger, nothing ever left half-finished. In software that’s called an atomic transaction: everything succeeds together, or nothing changes at all. WordPress offered custom post types and crossed fingers.

Wall.
A training platform

needed courses tied to certifications tied to prerequisites, with progression rules that enforced themselves. WordPress offered a shelf of plugins, each solving ninety percent of the problem and fighting the other two for the last ten.

Wall.

We finally named the thing we’d been avoiding: the clients were never asking for too much. We were asking too much of the wrong architecture.

Then a launch taught us the law

One collapse, in 2021, settled it. We’d built a client’s community on the industry-standard stack — the exact plugins the vendors themselves recommend, the setup thousands of sites run on. Launch day brought real load: a quarter-million visitors, twenty thousand of them members trying to log in at once, on a third-party, enterprise-grade cluster configured for exactly that load.

It went down in an instant.

You inherit every failure point in software you don’t control.

Our client, our build, our responsibility — and the vendors whose parts had buckled under the very load their stack was sold for wouldn’t touch it. That’s the law we build by now. So we stopped assembling other people’s parts and built our own foundation. We called it Tome, and for the last two years everything we’ve shipped has stood on it.

What is in it

Every package speaks one language.

Tome is a set of packages, each owning one job — who people are, what they’re allowed to see, what they’ve paid, what they’ve learned. Whole business engines — Commerce, CRM & Marketing, Learning — are built on top of that plumbing. And all of it has been hardened against real production demand at organizational scale. Not in theory. In production, today.

What holds it together is that they all speak the same language. One identity model. One permission system. One audit trail that every package writes to. Add a new capability and it already knows who your people are, what they’re allowed to do, and what needs recording — instead of bolting a fourth opinion onto the pile.

The domains · eight views, one systemReal screens — structure over data, no member PIICaptures pending · David’s shot list
identity
content
training
commerce
governance
operations
realtime
editorial
identity · view 01 of 08

Take identity, the foundation the rest stands on. Member identity kept distinct from user accounts — the person is the record, the login is just a key, so a lost or changed login never takes someone’s history with it. Permissions that bend to the org chart instead of the other way around. Sessions, multi-factor, passkeys, and revocation that takes effect the instant someone’s standing changes — with a full record of every access decision behind it. Four packages underneath, behaving as one identity system.

That’s the pattern everywhere in Tome. Shared foundation, pieces that meet cleanly — and still, every project we build on it is custom. Tome is a foundation, not a template.

What it runs

The proof is what it already runs.

Not a demo. Not unshipped code waiting for its first real user. Right now, at organizational scale, three very different operations run on Tome, sharing nothing with each other except the foundation underneath — and the range between them is the whole point.

Vanguard

A 700-member organization, run on one platform.

A Star Citizen milsim, eight years in the making, that used to live in a dozen disconnected tools. It runs on Tome now: the full order of battle — wings, units, squadrons, billets — with hierarchical command and delegated authority; a training academy with prerequisites and certifications; multi-signature governance, where a ban, a senior promotion, or a change to the organization’s governing documents each needs a signature quorum before it takes effect; a live Discord integration.

85+ collections · 48 access policies
Every site we ship

Static one-pager to full platform, all on one foundation.

Every Wabbit Static and Platform build. wabbit.com, the site you’re reading right now. The Living Library, with its essays and series and methodology. The same foundation that carries Vanguard’s chain of command carries a simple one-page marketing site — and neither one knows the other exists.

6DOF Academy (beta)

A flight trainer for the genre’s hardest-to-please pilots.

It reads input straight off real flight-stick rigs in the browser and replays every training run with frame-perfect accuracy — stress-tested by exactly the people most likely to break it. Same foundation as the order of battle.

A 700-member chain of command, a one-page marketing site, and a six-degree-of-freedom flight sim, all standing on the same floor. That’s the range Tome already spans before we build anything specific to your business.

What changes

When we build for you on Tome, four things change.

Speed.

The hardest, most dangerous parts of a platform — identity, permissions, governance, training — are already built and already battle-tested. A comparable build from zero spends a year or more laying that plumbing before it does anything unique. A build on Tome inherits it, so the build — weeks to a few months for a first working piece — is spent on the part that’s actually yours: the thing your operation does that nobody else’s does.

Quality.

The errors your customers would otherwise meet in production get caught before anything deploys: Tome is type-safe from the database to the interface, so whole classes of mistakes can’t ship. That, not a promise to be careful, is where the performance, the security, and the maintenance story come from.

Ownership.

You own the platform and the source code outright, from launch. No renting access to your own data, no lock-in. If you ever decide to part ways, we help you take the whole thing with you — the contract makes that answer easy, and we wrote the promise down where you can hold us to it. The Eject Pledge →

Longevity.

Unmaintained software rots — yours won’t. Every build ships with its retainer: security patches, platform updates, and evolution as your business changes, ending the $800-per-emergency-fix trap. Ownership means you can fire us any day; the retainer means neglect will never be the reason.

We’ll tell you when it’s overkill

Tome is unnecessary for a simple website or a basic online store.

WordPress and a good designer handle those beautifully, and we’ll say so on the call — cheerfully, before you’ve spent a dollar with us. But when your organization needs software that matches how it actually operates, when off-the-shelf has stopped being able to hold it, that’s the room Tome was built for.

Straight answer

Is Tome a product we sell? These days — yes, most of it.

For years the honest answer was no: Tome was how we deliver, and the only way to benefit was to hire us. The marketplace changed that. Today you can run Tome without ever hiring us to build. The starter — a ready-to-fork site — gets you running the same day. The capacity plans are the hosting tiers that put the real platform under it. The business engines — Commerce, CRM & Marketing, Learning — bolt on as your operation needs them. And the block library is open, some of it free.

For now every paid door opens with a note rather than a checkout — we set each one up by hand, same day. Self-serve is coming for the smaller tiers; Agency and Commerce will stay a conversation by design: those tiers put us behind your uptime and your checkout — other people’s money and other people’s deadlines — and we’d rather set that up right than hand you a button.

What still comes only one way is us: the bespoke build, where we model your operation and shape the platform to it. And one door stays deliberately closed for now — Tome as a service, where we’d host and run your deployment for you. That turn would make us a software company on top of an agency, and we won’t take it until we’re sure it’s right.

We’d rather sell you the workshop than pretend it’s a museum.

The shelf is open

Take the platform for your own build.

The blocks, plans, engines, and packs Tome ships with — the same shelf every Wabbit build pulls from.

Under the hood

Production-grade, observable, ours.

For the engineer in the room, the honest version. The whole library, 190,000+ lines of strict TypeScript end to end, published to a private registry we run ourselves.

UI

React with GSAP motion and Yjs collaborative editing; App Router and server components, client components where they earn it.

API / state

TanStack Query and Zustand; server state with real cache invalidation, UI state kept separate.

Auth

Better Auth plus payload-auth, server-side sessions, passkeys, 2FA, OAuth. Revocation is instant; rate limiting fails closed.

Tome

PayloadCMS 3 and the published @wabbit/tome-* packages. The foundation: identity, content, training, commerce, ops, realtime, all on one identity model and one audit trail.

Runtime

Next.js, Node, TypeScript in strict mode with null checks throughout. Type-safe from database to UI.

Persistence

MongoDB, Redis, BullMQ, and a CDN with media isolated per member.

Infrastructure

Tuned for Coolify on dedicated bare-metal hardware. Real machines, containerized, predictable cost — not a serverless bill that surprises you.

Compliance isn’t bolted on: data-subject rights are modelled into the schema, security enforcement lives at the database read layer rather than the interface, and every access decision leaves a trail.