Working model: relationships as data
The entire architecture reduces to a node, a link, and policies that evaluate them. Everything else — memories, documents, conversations, whole institutions — attaches. Before any idea is adopted, one question: can it be expressed with the existing primitives?
A comparison I want to run
Run one workflow through personal, team and composed-community arrangements with comparable capabilities. Record what survived, what needed rewriting, costs and failures. This is a proposed experiment, not a result or a prerequisite for revising these pages.
I’m investigating whether a shared graph can coordinate relationships, identity, information and authority while supporting very different personal and community arrangements. Organs may keep whatever internal databases, models, runtimes and specialized structures they need. A compact substrate is not a ban on useful implementation structures.
The intended extension is recursive composition without losing constituent capabilities: a community can join a larger arrangement while keeping its competence, identity and legitimate control.* Representing those relationships is not evidence of preserved capabilities or competitive performance. This is more than choosing several models behind a chat box, and does not require one global database.
Openness should enable understanding, interoperability and independent implementations. Replication should be able to create another independent cooperating participant—not just another instance we control. Copies need not share our brand or choices, and copied code does not guarantee goodwill. Commercial sustainability is legitimate; disclosure is not a contest in selflessness.
Refined August 2026The loop, five invariants, three recursions
Reality is the ultimate teacher. Reality generates observations; observations contribute to understanding; understanding informs action; reality evaluates whether the understanding was correct. Everything else exists only to support this loop while preserving continuity and sovereignty.
Five invariants guard the loop.
- Reality
- Reality is primary. Digital versus physical is provenance, not rank.
- Locality
- Each node acts only from its own observations, explicitly shared understanding, adopted institutional capability and negotiated relationships. Global behaviour can emerge from these local interactions, as complexity can emerge from simple rules in a cellular automaton.
- Context
- Information’s meaning and permitted use depend on its context. A boundary is not merely a wall around data; it is a change of law. Two institutions can therefore apply different policies to their respective views of the same person without collapsing those views into one record.
- Recursive composition
- Person, family, company, hospital, village, federation: the implementation changes; the interface does not.
- Propagation
- Understanding does not travel merely because it exists. Crossing a boundary is explicit and governed. What arrives does not inherit its source’s permissions; it answers to the receiving context’s law. Each request returns the least disclosure that suffices: non-identified forms where possible, and personally identifiable information only with genuine need and an explicit, valid authority basis.
Data minimization becomes a structural privacy control. Generalized, anonymous or aggregated answers are preferred where they suffice; identification is an explicit exception, not the default.
Three independent recursions run through the whole design.
- Structural
- Every scale is a node with links. Membership is an explicit, governed link, not a container; its authority basis and exit conditions are recorded.
- Computational
- Every node exposes the same interface, regardless of scale.
- Learning
- Bounded disclosures propagate through negotiated local interactions; receiving nodes may adopt local claims under their own policy. Source records and ownership do not transfer.
Collective intelligence without collective ownership. This is the design’s newest and least-tested claim, so it remains a hypothesis under field testing.
Institutions hold capability for defined missions. Their assistants act on the institution’s behalf, but neither the institution nor its assistant owns anyone’s substrate.
Execution placementCompute may travel. The durable substrate stays with its node.
Locality is not merely where bytes are stored. A node’s identity, graph, archive, accumulated understanding, permissions and relationships are its durable substrate. Consulting a stronger model must not require moving that substrate or making the model the new owner of the relationship.
For each capability, execution should occur at the nearest node that is both capable and authorized. If work crosses a boundary, only the minimum context required for that task crosses with it.
Sathi makes the locality continuum concrete without presenting it as finished.
- Implemented
- A Sathi-operated private deployment.
- Experimental
- A home node and speaker.
- Direction
- Policy-governed hybrid and local routing.
- Future offering
- Dedicated and fully independent deployments that can remove Sathi Systems and continue.
These are deployment options along one locality continuum, not four products. The same rule recurses through a person, household, company and community.
Data structuresThe node and the link
A node is a sovereign entity — a person, a community, an institution, an agent. It carries its own keypair (it can sign what it says about itself) and, optionally, a constitution. A link is a governed edge between two nodes: its kind, the named capabilities it grants, the policy it carries, and the recorded basis for authority at each end. That basis may be consent, delegation, contract or lawful duty, depending on the context. Revocation ends future authority where revocation is permitted; it is recorded as an event and cannot undo completed acts or information already disclosed.
contains
applies to resources, never people.AttachmentOrgans attach; the spine never holds content
Rich data — a family's memories, a company's procedures, documents, conversations — lives in organs: ordinary, optimized storage, each shaped for its job. Organs reference the spine; the spine holds only relationship facts. So policies and governance can change without migrating a single byte of content, and new organs join without asking the architecture's permission.
Why it helpsRelationships become editable structure
Because relationships are data, many organizational shapes can be represented as sets of links: a family, a hierarchy, a matrix or a village federation. Adopting a new shape changes links rather than migrating people or memory. That makes restructuring more inspectable and less disruptive when needs or tools change.
Why usefulThe portable node
A node can be serialized: its record, its links (authority basis and revocations included), and an inventory of everything its organs hold — signed with the node's own key. The manifest makes an export self-describing and verifiable: anyone can check the archive’s integrity and signer offline. It does not, by itself, prove legal ownership. Signed export and offline verification are implemented; automatic one-step re-instantiation on a replacement deployment remains in development.
Scale hypothesisThe same shape at every zoom
A person, a family, a company or a federation exposes the same interface: a node with links. A federation is communities linked one level up; a community of one is already complete. Institutional capability can be retained at community nodes while each person’s substrate stays their own. Whether that reduces coordination cost at larger scales remains a field question.
Today’s Sathi deployment runs a whole family — messaging, calls, documents, realtime voice, and the understanding substrate — on one small server. That demonstrates a low starting footprint, not general scalability. Scaling beyond the current household and small-community tests remains work to be measured.
Earlier technical notes
The technical material remains available below. These are working models and retrospective accounts; the revised distinctions above govern where earlier language was broader.
Working modelOne reality, many projections
The system underneath may be deep and recursive. The human surface should remain simple. Four layers keep those concerns apart:
- GraphPeople, institutions, resources and links with an explicit authority basis — the sovereign structure of reality.
- UnderstandingClaims, context, provenance and confidence derived from that reality.
- Organs & capabilitiesConversation, documents, calendar, devices, websites, APIs and tools people create over the shared substrate.
- ProjectionsFlat, human-usable viewpoints into whatever part of the graph a person may inhabit.
Propagation sits beside these layers: governed movement between sovereign contexts. Each request should use the least revealing representation that suffices — generalized, aggregated or anonymized where possible; identified only when necessary and supported by an explicit, valid authority basis. “One reality” never means one global database.
Status: this is a research direction being tested through Sathi, not an installable framework. Durable patterns will be distilled, generalized and opened only after saturation and repeated frontier-system, human and security review.
ArchitectureSeparation of concerns
The framework separates what most systems entangle: reality, the architecture that models it, the implementations communities actually run, and the operators who keep them running.
FoundationsFive axioms
- Every sentient being is a sovereign community of one. Families, companies, villages and nations are recursive compositions of sovereign communities. The individual remains the fundamental unit.
- Individuals are never owned. Communities coordinate individuals. They do not possess them.
- Ownership, authority and maintenance are different questions. Who ultimately controls a resource; who may perform which actions; who keeps it running. Conflating them is how institutions rot.
- Every community has a constitutional root — and it is not omnipotent. It maintains governance and shared resources. It cannot rewrite another individual's memories, observations or personal data.
- Leaving must always be possible. Participation is earned through trust and value, never lock-in. Exit must be safe. Forking should be supported. Migration must become inexpensive.
Scope today: the first axiom states the intended moral scope. The current Sathi product represents human people and institutions only; it does not claim to settle machine sentience or non-human legal personhood.
CompositionA graph, not a pyramid
Nobody lives inside one box. The same person is in a family, a company, a club and a village — at the same time, with full standing in each. So the architecture is a graph of nodes and links, never a hierarchy of containers: every deployment of Altruistic AI is a node that belongs to itself — sovereign, addressable, portable — and a community is nodes joined by explicit, inspectable links. Consent is required where consent is the basis; delegation, contract, guardianship and lawful duty are bounded alternatives, never implied ownership.
Because every node exposes the same interface, the graph is designed to compose in either direction — a community of one is already complete, and a federation is just communities linked one level up. The same shape at every zoom:
It also gives scale a useful property. A verified lesson — a better onboarding, a safer procedure, a clearer workflow — can become a resource on the community’s own node while each person’s substrate stays their own. The aim is to make later onboarding easier because the institution learned — individuals come first, and the boundary between personal and shared is verifiable by both sides, not promised. Institutions — education, health, government, finance — are first-class objects here, and they represent accumulated capability, not accumulated authority.
The same shape serves a person, a family, a company, a village, an institution, a civic body. Implementations differ; the architecture does not.
DataFacts are not interpretations
The substrate separates what happened from what it means. The observation log is append-only: corrections and deletions are explicit new events rather than silent rewrites. Interpretations are expected to evolve.
Each resource carries metadata: identity, owning node, sensitivity, jurisdiction, temporal validity, confidence, provenance, retention and visibility. One owning node is named, but that node may itself be jointly governed. Authority is separate from ownership and capability-specific — read, write, share, delegate, audit — and always explicit, inspectable and revocable where reality permits. Information voluntarily disclosed cannot generally be undisclosed; the architecture does not pretend otherwise.
VocabularyThree primitives, endlessly composed
NodeLinkPolicy
Everything else attaches. The older, richer vocabulary — Entity, Resource, Capability, Constraint, Institution, Community, Observation, Claim, Authority, Audit — remains useful as language, but each of those is expressible as a node, a link, a policy, or an attachment. See Architecture for the two tables this reduces to.
IntelligenceAI is a capability, not the center
Artificial intelligence is one capability within the architecture — which must therefore survive changing models, vendors, hardware and interfaces. An "agent" is an implementation detail: the intelligence around a person may at any moment be one model, many models, deterministic software, humans, or forms not yet named. The durable questions are the ones the architecture fixes — what intelligence is available around me, what does it know, and what authority does it have? Phones, speakers, displays, vehicles, robots, browsers, and whatever comes next are embodiments. They come and go. The intelligence remains continuous, because the community — not any device or vendor — owns the substrate it learns from.
And the ordering is deliberate: identity, consent, authority and policy are built before the intelligence becomes extremely capable. AI proposes; policy decides — no generated instruction bypasses deterministic authorization, and a system capable of almost anything is still authorized to do only what its grants allow. Capability is not authority.
Evidence takes precedence over preference. The architecture explicitly distinguishes objective observation, scientific consensus, derived hypothesis, cultural norm, personal belief, and fiction — and expects uncertainty to be stated, with confidence attached to conclusions.
AgentsIdentity, delegation, revocation
When intelligence acts for someone, four questions must remain easy to answer.
- Identity
- The person and the agent each have a persistent, verifiable identity independent of any model or vendor.
- Grant
- Delegated authority names the actions, resources, spending limit and duration.
- Provenance
- Every act points back to the grant that authorized it.
- Revocation
- Revocation ends future authority when enforced. It cannot undo completed acts.
Spending makes the test concrete: who authorized it, from which resource, up to what limit, until when, and how can a counterparty verify the grant? The authority lives in that grant, never in the model.
The identity substrate is deliberately open: conventional cryptography, decentralized naming, or something not yet built. The problem is identity, authority and trust; no ledger is the product.
DisciplineEngineering principles
Optimize for adaptability · inspectability · reversibility · iteration speed · capability compounding · scalability · interoperability · sovereignty.
Never optimize for captivity.
The business model follows the same rule: revenue comes from creating value — hosting, convenience, maintenance, support, operations — never from making departure expensive. Trust is earned by making departure safe.
EvolutionWhat reality taught
Reality remains the ultimate teacher. Sathi is tested on its builders first, and the lessons that generalize are recorded here — what was believed, what reality showed, what changed. Dated, so the principles can be seen to move.
- 2026-09
- Compute may travel; the durable substrate stays with its node. Saying models were replaceable described the software seam but not its physical deployment. Changed: every capability is intended to route to the nearest capable and authorized node — local, private, operated, external, or disabled — while only minimum task context crosses. A receiving context may form its own local claim; the source node’s durable substrate does not migrate. These are deployment options along one locality continuum, not separate products.
- 2026-08
- A paraphrase is not testimony. The system had asserted a false family relationship, derived from its own summary of a conversation rather than from anything the person said. Changed: only a person's own words may become claims about them; the system's notes and other people's words are archive, never testimony; every claim quotes its source; what is inferred renders as unverified.
- 2026-08
- No proposal without the person's words on the card. A “journey” had been proposed from a question about a word, not from any stated intent. Changed: a proposal must quote the sentence that states the move, and the sentence must really be there.
- 2026-08
- Understanding must be regenerable from the archive. Fixes to how understanding is derived were being applied by hand, per person. Changed: every derivation stage carries a version; a bumped version regenerates understanding for everyone from the archive, staged and measured before it replaces what people see; the person's own decisions — forget, correct, reject — are a ledger every regeneration re-applies, so nothing decided against is re-learned.
- 2026-08
- Capability is not authority, and the executor is never the asset. Competing with frontier agents at execution was a losing frame. Changed: agents and models are replaceable execution engines behind one interface; the architecture owns identity, memory, permissions and orchestration — improvements arrive by upgrade, not reproduction.*
- 2026-07
- Exit must be a tested code path, not a policy. “You can always leave” was a sentence. Changed: signed export, deletion receipt and archive validation are exercised by tests. Automatic one-step re-instantiation on a replacement deployment remains in development.
StatusWhere this stands
This is the public scratchpad of a living architecture, not a released framework. Its implementation remains inside Sathi while daily use is still changing the structure.
We will distill, generalize and publish the framework and reusable code only after Sathi reaches saturation: the core patterns survive repeated use, adversarial review by multiple frontier systems, and independent human and security scrutiny. Until then, Sathi is the learning product and these pages record what appears durable.
There is no package to install yet. If this direction matters to you, write: info@altruistic.ai.
A small * after a sentence on these pages marks a claim that is still being implemented, planned, or not yet independently verified. The reference implementation publishes each capability’s status at sathi.ai/capabilities; the convention is explained at sathi.ai/trust.