Problem
A local assistant becomes dangerous when language-model intent and system execution share an implicit authority boundary.
Private local agent · active
Private local assistant architecture built around explicit IPC, approvals and bounded system tools.
A local assistant becomes dangerous when language-model intent and system execution share an implicit authority boundary.
Execution is separated behind explicit IPC contracts, policy checks and human approval surfaces for sensitive actions.
An assistant model that treats system authority as a separate controlled capability rather than an automatic consequence of chat.
The public surface documents the authority model only.
Local message transport between UI and assistant core.
Allow/deny and approval constraints around execution.
Durable pending decisions before sensitive operations.
Explicit local capabilities exposed under policy.
A local assistant should not treat model intent as authority to perform sensitive system actions.
No additional public experiment records.
No project-specific public release record.
Authority and approval architecture is public; IPC, commands and local memory remain private
source-contract · checked 2026-08-11 · fresh until 2027-08-11
No IPC endpoint, workstation control, command execution or local memory is exposed by the public website.