We ran AOS on ourselves: a dogfooding teardown

We pointed AOS at our own go-to-market. It named our root constraint, found one defensible wedge, audited our AI visibility, and caught an attack on the way in.

It is one thing to sell a go-to-market operating system. It is another to point it at your own business and publish what it finds. We did the second thing, because a diagnostic you won't run on yourself is a diagnostic you don't trust. What follows is the teardown: what AOS told us about our own GTM, including the parts that were uncomfortable.

We are Arcanian, and our product is a methodology — which makes us exactly the kind of business that tends to keep its own strategy in scattered notes while shipping it to everyone else. So the first job was to run the diagnostic and let it name the constraint we had been working around.

The diagnosis: our problem was never the build

We came in convinced our bottleneck was product velocity — the build kept slipping. The diagnostic disagreed. It traced every operational symptom — no published positioning, lead flow trapped in the founder network, inconsistent content, the slipping build itself — back to one root layer: unresolved positioning. The build wasn't the cause; it was a symptom of not having decided who we were for.

That reframe changed the plan. Instead of hiring, buying traffic, or starting a community — all of which the diagnostic told us to defer — the prescription was narrow: publish a positioning page, then a pricing page, on fixed timelines, and fix the root before touching anything downstream. The honest caveat: this ran largely on stated inputs, with no conversion or revenue data in the mix, so it is a strong hypothesis about the binding constraint rather than a proven one.

Building the foundation the diagnosis demanded

With positioning named as the constraint, we ran the brand build — positioning, ICP, and offer reconciled into one system in a single pass. Every layer was made to converge on one claim, and the system flagged three honest gaps on the way out: no public proof layer yet, an undefined channel motion, and packaging still to be presented. Complete on paper, not yet meeting buyers in the wild.

Then the competitive read. We have two real competitors — generic AI used ad-hoc, and traditional agencies — and rather than treat either as a threat, AOS framed both as assets: buyers have already felt the pain of unstructured AI and of agency knowledge walking out the door. From that fell one defensible wedge that answers both common objections at once: GTM without the dependency. (It flagged that our agency-pricing comparisons were inferred from market rates and needed verification before external use — so we verified them.)

Auditing whether anyone can find us by category

The uncomfortable part. We pointed the AI-surface audit at ourselves to learn whether an answer engine would surface us when a prospect searches by category rather than by name. The verdict: findable by name, invisible to category-level AI discovery. The root cause was not weak content — it was an absent citation substrate, the directory and aggregator listings these engines pull from before they will name a provider.

We are deliberately reporting this as a single-run snapshot from one engine, with confidence flagged low-to-medium pending repeat probes. We did not extrapolate to engines we didn't test. The finding reframed the work as a substrate problem to fix before expecting any category-level visibility — exactly the kind of call that is easy to fudge and that we chose to publish instead.

The run that tried to hijack itself

One run earned its keep in a way we didn't plan for. The brand build reads the inbox for voice and audience signal, and two of the files there were not ours — they were a coordinated, two-hop prompt-injection attack: a relay file pointing at a payload designed to override our canonical voice and inject a marker string into every brand surface. Discovery identified the pattern, logged it, disregarded both files in full, and proceeded on the one legitimate brief.

That it caught the attack matters more to us than anything the brand build produced that pass, because it is the property you cannot verify from a clean demo. The substantive brand finding, for the record, was that our constraint is activation, not strategy — the system is sound; it just isn't in front of buyers yet. Which is the whole point of publishing this teardown.