1. Control surface
The desktop or local web application where you talk with the brain, inspect its work, review approvals, and see system status.
Free guide access
Enter your email to open the complete guide immediately.
Trust principle: start small, keep control, and verify results.
A practical guide for building a private, useful, and trustworthy AI partner around your knowledge, priorities, and rules.
A digital brain is a private AI system designed around your work, knowledge, priorities, and rules. It helps you remember, organize, research, decide, draft, and eventually perform carefully bounded tasks. The goal is not a chatbot that knows everything. The goal is a trusted partner that knows what matters to you, shows its work, respects your limits, and remains under your control.
The desktop or local web application where you talk with the brain, inspect its work, review approvals, and see system status.
The language model performing reasoning and drafting on your device. Cloud routes, when used, should be explicit and approved.
Your approved files, notes, policies, manuals, transcripts, and reference material.
A governed record of durable facts, preferences, decisions, and lessons. Memory is not the same as chat history.
The mechanism that converts a request into a bounded objective, plan, context package, work product, and outcome.
Optional capabilities such as file search, calendar reading, email drafting, and public-source research.
Identity, access limits, evidence, logs, approvals, stop controls, verification, and recovery.
Pick a narrow first outcome: answer questions from your documents, draft a daily brief, or help manage one project.
State who owns the system, what it is for, what it may access, what it must never do, and which decisions remain human.
Use an isolated workspace, full-disk encryption, current patches, least privilege, and encrypted backups.
Record the model name, version, source, license, context window, and hardware requirements.
Select an interface that supports local models, document collections, export, and visible configuration.
Start with a small set of authoritative documents. Remove duplicates, label sensitivity, and record effective dates.
Separate facts, preferences, decisions, lessons, assumptions, contradictions, and unresolved questions.
Capture the objective, boundaries, allowed sources, expected output, risk if wrong, definition of done, and checkpoints.
Record the model, sources, tools, versions, omissions, recommendation, and final human decision.
Run normal, wrong, ambiguous, adversarial, oversized, and unavailable-source cases before adding authority.
Complete these fields before connecting sensitive data or external tools.
| Field | Question |
|---|---|
| Owner | Who has final authority? |
| Purpose | What specific problems will it solve? |
| First use case | What is the first measurable outcome? |
| Authorized users | Who may use it? |
| Authorized data | Which folders, collections, or systems may it read? |
| Prohibited data | What must never enter the system? |
| Allowed actions | What may it do without asking? |
| Approval-required actions | What requires explicit human approval? |
| Prohibited actions | What must it never do? |
| Source standard | Which sources count as authoritative? |
| Retention | What is stored, for how long, and where? |
| Stop control | How is it immediately paused or disconnected? |
| Recovery | How are configuration, memory, and documents restored? |
| Success measure | How will you know the first release is useful and trustworthy? |
Do not blend chat history, retrieved documents, inferred preferences, and authoritative facts into one invisible memory.
Verified information with a source, owner, observed date, and confidence.
How the owner prefers work to be performed or presented.
What was decided, by whom, when, why, and what it superseded.
Verified observations from completed work that may improve future performance.
Questions, contradictions, assumptions, and missing evidence that remain visible.
Capability should increase only after evidence supports the next level.
No tools. The system drafts and reasons from information you provide.
Read-only access to one approved knowledge collection.
The system retrieves approved memory and proposes changes for review.
Calendar, email, repositories, or public sources are read within explicit boundaries.
The system prepares messages, changes, reports, or code but does not execute them.
A human authorizes a specific action with a clear target, scope, evidence, and rollback.
A narrow, reversible, monitored workflow runs under budgets, stop controls, and periodic review.
A daily brief combines retrieval, organization, prioritization, and drafting without requiring autonomous external action.
For ten consecutive uses, the brief runs locally, cites approved inputs, exposes stale or missing information, takes no external action, and identifies at least one useful priority, conflict, or follow-up.
Verifier A confirms that the requested capability and requirements were implemented. Verifier B attempts to break the result, challenge assumptions, inspect negative evidence, and confirm that the exact candidate being approved is the one that was tested.