What an operator’s customer sees
An agency’s merchant signs into an admin carrying the agency’s name and logo, at the agency’s own domain. The colours, spacing and shape of the interface are the agency’s. The assistant, if it is switched on, answers under a name the agency chose. Emails arrive from the agency’s sending address. Even the API keys carry the agency’s name — a merchant copies a key beginning with the agency’s own vendor token rather than the platform’s. Key format is otherwise unchanged, so an integration written against one operator’s keys works against another’s.Signature and environment headers on webhook deliveries are structural, not branding, and they do not
change. A developer writing a webhook handler will see the platform’s header names there.
Pricing is the operator’s own
An operator defines their own tiers — as many or as few as they want, named and priced how they like. A three-tier ladder is a convention rather than a constraint. What a tier may grant is bounded. Every operator account carries a ceiling, and entitlement is clamped against it each time it is read rather than when a tier is saved. A tier claiming a capability the operator’s own account does not include resolves to what the account includes, so an operator can never grant more than they hold — including by editing the underlying data directly. Annual pricing is expressed as a price, not a discount. The saving a customer sees is derived from the monthly and annual figures whenever it is displayed, so the two can never disagree.Money does not net
Two separate flows, and they never meet:Domains
An operator brings their own domain —studio.youragency.com — and a certificate is issued for it
automatically. Their customers never see a platform address.
Connected applications
An operator issues their own “Login with «Operator»” applications. Their clients are isolated to their own merchants, and the consent screen a merchant approves carries the operator’s branding rather than the platform’s. Reference: GC ConnectWhere the brand boundary stops
Presentation carries the operator’s brand. The security and money boundary does not, and that is deliberate — a signature is a claim about who produced a payload, and it means nothing if anyone can mint one under their own name. So the parts of the platform that establish trust stay constant: signature and environment headers, the integrity of orders and payments, and the platform’s own billing relationship with the operator. An operator’s invoice from the platform comes from the platform, because that is a relationship between those two parties and not something to disguise. An operator also composes their tiers from the platform’s capabilities rather than inventing new ones. A capability has to exist before it can be sold, and a name for something the platform does not do is a promise nothing can keep.Across the three products
Anvil’s dependency on Galactic Core is a product decision rather than an accident: it generates
storefronts wired to commerce APIs, and an Anvil without them would be generating against nothing.
TLDP has no such tie — a logistics operator can run it without adopting a commerce platform, and an
agency running Galactic Core may either contract such an operator or run TLDP themselves.
Reference: Agencies · Anvil · Platform surfaces

