How it works

Two loops. Neither one can send a word.

One loop quietly maps how you actually correspond. The other hands you what matters in the moment you write. Between them sits everything this page explains: receipts, confidence gating, and the deliberate absence of a send button.

The two-loop architecture Your sources flow through a consent gate into the map. The mapping loop cycles between sources and the map in the background. When you write, the ritual reads the map, assembles draft context with receipts attached, and hands it to you. You are the only send. Every statement in the map links down to episodes, the actual messages. the mapping loop · consent-gated · background the ritual · runs only when you write Your sources mail, read-only, consent per source The map who, what, when — and when it stopped The ritual constraints first, then knowns, then asks Draft context receipts attached, marked provisional You the only send in the system consent gate Episodes — the actual messages every statement above keeps its receipts down here
Sources flow through the consent gate into the map; the ritual assembles draft context from the map; you decide what leaves. Everything above the line answers to the episodes below it.

Loop one

The mapping loop

With your consent — granted source by source, never assumed — collectors read your own correspondence, read-only. Every message becomes an episode: a record tagged, at the moment it's written down, with who was involved. Untagged material can't enter the map at all; the schema refuses it.

The map itself is bitemporal: it stores not just what's true but when it was true. People change roles. Relationships end. The map keeps the fact and its dates, and retrieval respects them — ask about last spring and you get last spring's truth, not today's retrofitted onto it.

The map is built in two passes. A structural pass first: who answers whom, what stalls, which commitments are still open, which threads you dropped. Then a deeper, budgeted reading pass turns what happened into observations — and that budget is a hard stop, not a suggestion. Every observation the deeper pass produces must carry receipts. No receipts, no observation.

Loop two

The retrieval ritual

When you're about to write to someone, your assistant calls the ritual, and the ritual assembles a packet in a strict order:

  • Constraints first. What must not be touched is computed before anything is weighed or ranked: ended relationships, sensitive contexts, the explicit walls you've drawn. (Walls today match on the people involved; walls that understand topics are in development.) Relevance never gets to outrun restraint — the filters run before the weights, structurally, not as a post-hoc check.
  • Then knowns. What the map can say about this person, with receipts attached and a provisional flag on anything that hasn't earned better.
  • Then asks. What the map can't say yet, stated as plain questions for you — not filled in with guesses.

The packet goes to whatever drafting tool you use. The system is model-agnostic on purpose: it supplies context and constraints over an open protocol; it doesn't care which assistant does the writing.

Receipts

Every statement links to real evidence.

Each profile statement in the map is indexed to the episodes it came from — the actual messages. That isn't a nice-to-have in the data model; it's a gate at display time. A statement that arrives without receipts is refused: the system declines to show it rather than show it naked. There is a test that fails if that refusal ever stops working.

Confidence gating

It asks. It never guesses.

Every observation sits above or below an evidence floor. Below the floor, the system doesn't round up: scores are withheld, sensible priors are labeled as priors, and you get a short list of plain questions instead of a confident answer. An unfamiliar contact gets questions, never silence and never invention. And everything, floor or no floor, carries a provisional flag wherever it goes — an admission the system never quietly graduates out of.

The missing feature

Nothing sends itself.

There is no send path in the system — not a disabled one, not a flagged-off one. None. Its live connections to your accounts are read-only. The draft ends in your hands, and what leaves is what you chose to send. This is checked by an automated sweep of the codebase, so it stays true by test rather than by promise.

Where this stands today

What you just read is built, not projected.

The architecture on this page — the consent gate, the bitemporal map, both mining passes, the ritual, the receipt and confidence gates — is implemented and tested against a synthetic corpus with hand-computed expected results. Live mailbox runs are the current work in development, and this page will say so until they're not.

Next: the rules it all answers to