Altruistic AI

Working model: relationships as data

The entire architecture reduces to a node, a link, and policies that evaluate them. Everything else — memories, documents, conversations, whole institutions — attaches. Before any idea is adopted, one question: can it be expressed with the existing primitives?

A comparison I want to run

Run one workflow through personal, team and composed-community arrangements with comparable capabilities. Record what survived, what needed rewriting, costs and failures. This is a proposed experiment, not a result or a prerequisite for revising these pages.

I’m investigating whether a shared graph can coordinate relationships, identity, information and authority while supporting very different personal and community arrangements. Organs may keep whatever internal databases, models, runtimes and specialized structures they need. A compact substrate is not a ban on useful implementation structures.

The intended extension is recursive composition without losing constituent capabilities: a community can join a larger arrangement while keeping its competence, identity and legitimate control.* Representing those relationships is not evidence of preserved capabilities or competitive performance. This is more than choosing several models behind a chat box, and does not require one global database.

Openness should enable understanding, interoperability and independent implementations. Replication should be able to create another independent cooperating participant—not just another instance we control. Copies need not share our brand or choices, and copied code does not guarantee goodwill. Commercial sustainability is legitimate; disclosure is not a contest in selflessness.

Refined August 2026The loop, five invariants, three recursions

Reality is the ultimate teacher. Reality generates observations; observations contribute to understanding; understanding informs action; reality evaluates whether the understanding was correct. Everything else exists only to support this loop while preserving continuity and sovereignty.

Five invariants guard the loop.

Reality
Reality is primary. Digital versus physical is provenance, not rank.
Locality
Each node acts only from its own observations, explicitly shared understanding, adopted institutional capability and negotiated relationships. Global behaviour can emerge from these local interactions, as complexity can emerge from simple rules in a cellular automaton.
Context
Information’s meaning and permitted use depend on its context. A boundary is not merely a wall around data; it is a change of law. Two institutions can therefore apply different policies to their respective views of the same person without collapsing those views into one record.
Recursive composition
Person, family, company, hospital, village, federation: the implementation changes; the interface does not.
Propagation
Understanding does not travel merely because it exists. Crossing a boundary is explicit and governed. What arrives does not inherit its source’s permissions; it answers to the receiving context’s law. Each request returns the least disclosure that suffices: non-identified forms where possible, and personally identifiable information only with genuine need and an explicit, valid authority basis.

Data minimization becomes a structural privacy control. Generalized, anonymous or aggregated answers are preferred where they suffice; identification is an explicit exception, not the default.

Three independent recursions run through the whole design.

Structural
Every scale is a node with links. Membership is an explicit, governed link, not a container; its authority basis and exit conditions are recorded.
Computational
Every node exposes the same interface, regardless of scale.
Learning
Bounded disclosures propagate through negotiated local interactions; receiving nodes may adopt local claims under their own policy. Source records and ownership do not transfer.

Collective intelligence without collective ownership. This is the design’s newest and least-tested claim, so it remains a hypothesis under field testing.

Institutions hold capability for defined missions. Their assistants act on the institution’s behalf, but neither the institution nor its assistant owns anyone’s substrate.

Alice Health bounded disclosure Caroline Health
A bounded disclosure crossed. Alice’s source record stayed with her; Health may adopt a local claim under its own policy. The bar is the governing gate, shown open for this request.

Execution placementCompute may travel. The durable substrate stays with its node.

Locality is not merely where bytes are stored. A node’s identity, graph, archive, accumulated understanding, permissions and relationships are its durable substrate. Consulting a stronger model must not require moving that substrate or making the model the new owner of the relationship.

For each capability, execution should occur at the nearest node that is both capable and authorized. If work crosses a boundary, only the minimum context required for that task crosses with it.

Does not move just because compute moves identity · graph · archive · accumulated local understanding · permissions
Localfirst Private infrastructurethe node’s Sathi infrastructureoperated Frontier providerminimum context Disabledpolicy says no
nearest capable + authorized node · least context · explicit escalation
Compute may travel. A bounded disclosure may cross, and the receiving context may form its own local claim; the durable substrate does not migrate.

Sathi makes the locality continuum concrete without presenting it as finished.

Implemented
A Sathi-operated private deployment.
Experimental
A home node and speaker.
Direction
Policy-governed hybrid and local routing.
Future offering
Dedicated and fully independent deployments that can remove Sathi Systems and continue.

These are deployment options along one locality continuum, not four products. The same rule recurses through a person, household, company and community.

Data structuresThe node and the link

A node is a sovereign entity — a person, a community, an institution, an agent. It carries its own keypair (it can sign what it says about itself) and, optionally, a constitution. A link is a governed edge between two nodes: its kind, the named capabilities it grants, the policy it carries, and the recorded basis for authority at each end. That basis may be consent, delegation, contract or lawful duty, depending on the context. Revocation ends future authority where revocation is permitted; it is recorded as an event and cannot undo completed acts or information already disclosed.

NODE kind: person · community · institution · agent keypair — signs its own claims constitution (optional) belongs to itself LINK kind: member_of · maintains · contains* · shares_with · delegates capabilities — named, never a % policy — transitivity, gates authority basis recorded revocation is a fact, not a delete joins two nodes
That is the whole substrate of relationships. Five link kinds; special cases must compose, never grow new tables. contains applies to resources, never people.

AttachmentOrgans attach; the spine never holds content

Rich data — a family's memories, a company's procedures, documents, conversations — lives in organs: ordinary, optimized storage, each shaped for its job. Organs reference the spine; the spine holds only relationship facts. So policies and governance can change without migrating a single byte of content, and new organs join without asking the architecture's permission.

the spine nodes + links relationship facts only memories — what was understood conversations — what was said documents — what was kept procedures — what was learned to do
Change the constitution, keep the data. Different communities evaluate the same substrate differently.

Why it helpsRelationships become editable structure

Because relationships are data, many organizational shapes can be represented as sets of links: a family, a hierarchy, a matrix or a village federation. Adopting a new shape changes links rather than migrating people or memory. That makes restructuring more inspectable and less disruptive when needs or tools change.

Why usefulThe portable node

A node can be serialized: its record, its links (authority basis and revocations included), and an inventory of everything its organs hold — signed with the node's own key. The manifest makes an export self-describing and verifiable: anyone can check the archive’s integrity and signer offline. It does not, by itself, prove legal ownership. Signed export and offline verification are implemented; automatic one-step re-instantiation on a replacement deployment remains in development.

serialize node + links + inventory sign with the node’s own key carry anywhere integrity + signer verifiable offline status: automatic one-step re-instantiation remains in development
The archive is portable evidence. Recreating a running node from it automatically remains a separate capability in development.

Scale hypothesisThe same shape at every zoom

A person, a family, a company or a federation exposes the same interface: a node with links. A federation is communities linked one level up; a community of one is already complete. Institutional capability can be retained at community nodes while each person’s substrate stays their own. Whether that reduces coordination cost at larger scales remains a field question.

Today’s Sathi deployment runs a whole family — messaging, calls, documents, realtime voice, and the understanding substrate — on one small server. That demonstrates a low starting footprint, not general scalability. Scaling beyond the current household and small-community tests remains work to be measured.

Earlier technical notes

The technical material remains available below. These are working models and retrospective accounts; the revised distinctions above govern where earlier language was broader.

Working modelOne reality, many projections

The system underneath may be deep and recursive. The human surface should remain simple. Four layers keep those concerns apart:

  1. GraphPeople, institutions, resources and links with an explicit authority basis — the sovereign structure of reality.
  2. UnderstandingClaims, context, provenance and confidence derived from that reality.
  3. Organs & capabilitiesConversation, documents, calendar, devices, websites, APIs and tools people create over the shared substrate.
  4. ProjectionsFlat, human-usable viewpoints into whatever part of the graph a person may inhabit.

Propagation sits beside these layers: governed movement between sovereign contexts. Each request should use the least revealing representation that suffices — generalized, aggregated or anonymized where possible; identified only when necessary and supported by an explicit, valid authority basis. “One reality” never means one global database.

Status: this is a research direction being tested through Sathi, not an installable framework. Durable patterns will be distilled, generalized and opened only after saturation and repeated frontier-system, human and security review.

ArchitectureSeparation of concerns

The framework separates what most systems entangle: reality, the architecture that models it, the implementations communities actually run, and the operators who keep them running.

Reality the ultimate teacher Altruistic AI emerging research architecture Personal companion one person, one family Hospital system an institution Company system an organization implementations — communities run whichever serves them best Lifecycle managers deploy · upgrade · migrate · monitor a capability any node may hold — never load-bearing, always replaceable
Nothing in the architecture may require any particular implementation or operator. Everything remains replaceable.

FoundationsFive axioms

  1. Every sentient being is a sovereign community of one. Families, companies, villages and nations are recursive compositions of sovereign communities. The individual remains the fundamental unit.
  2. Individuals are never owned. Communities coordinate individuals. They do not possess them.
  3. Ownership, authority and maintenance are different questions. Who ultimately controls a resource; who may perform which actions; who keeps it running. Conflating them is how institutions rot.
  4. Every community has a constitutional root — and it is not omnipotent. It maintains governance and shared resources. It cannot rewrite another individual's memories, observations or personal data.
  5. Leaving must always be possible. Participation is earned through trust and value, never lock-in. Exit must be safe. Forking should be supported. Migration must become inexpensive.

Scope today: the first axiom states the intended moral scope. The current Sathi product represents human people and institutions only; it does not claim to settle machine sentience or non-human legal personhood.

CompositionA graph, not a pyramid

Nobody lives inside one box. The same person is in a family, a company, a club and a village — at the same time, with full standing in each. So the architecture is a graph of nodes and links, never a hierarchy of containers: every deployment of Altruistic AI is a node that belongs to itself — sovereign, addressable, portable — and a community is nodes joined by explicit, inspectable links. Consent is required where consent is the basis; delegation, contract, guardianship and lawful duty are bounded alternatives, never implied ownership.

Family Company Club Village … federation You
You never sit inside anyone's field. A governed link reaches in, and what lives there is only your projection — the slice of you that context is allowed to hold. Joining adds a link, leaving removes it; you remain a community of one.

Because every node exposes the same interface, the graph is designed to compose in either direction — a community of one is already complete, and a federation is just communities linked one level up. The same shape at every zoom:

an individual = a community = a federation same interface at every scale
The repeating interface is intended to avoid requiring a new kind of system at every level.

It also gives scale a useful property. A verified lesson — a better onboarding, a safer procedure, a clearer workflow — can become a resource on the community’s own node while each person’s substrate stays their own. The aim is to make later onboarding easier because the institution learned — individuals come first, and the boundary between personal and shared is verifiable by both sides, not promised. Institutions — education, health, government, finance — are first-class objects here, and they represent accumulated capability, not accumulated authority.

The same shape serves a person, a family, a company, a village, an institution, a civic body. Implementations differ; the architecture does not.

DataFacts are not interpretations

The substrate separates what happened from what it means. The observation log is append-only: corrections and deletions are explicit new events rather than silent rewrites. Interpretations are expected to evolve.

Observations append-only · correction/deletion are events Claims current understanding · confidence attached Hypotheses candidate beliefs · tested against reality Policies evaluate — never rewrite history new intelligence re-reads history; it never rewrites it
Different constitutions can evaluate the same resources differently — changing governance rarely requires changing data.

Each resource carries metadata: identity, owning node, sensitivity, jurisdiction, temporal validity, confidence, provenance, retention and visibility. One owning node is named, but that node may itself be jointly governed. Authority is separate from ownership and capability-specific — read, write, share, delegate, audit — and always explicit, inspectable and revocable where reality permits. Information voluntarily disclosed cannot generally be undisclosed; the architecture does not pretend otherwise.

VocabularyThree primitives, endlessly composed

NodeLinkPolicy

Everything else attaches. The older, richer vocabulary — Entity, Resource, Capability, Constraint, Institution, Community, Observation, Claim, Authority, Audit — remains useful as language, but each of those is expressible as a node, a link, a policy, or an attachment. See Architecture for the two tables this reduces to.

IntelligenceAI is a capability, not the center

Artificial intelligence is one capability within the architecture — which must therefore survive changing models, vendors, hardware and interfaces. An "agent" is an implementation detail: the intelligence around a person may at any moment be one model, many models, deterministic software, humans, or forms not yet named. The durable questions are the ones the architecture fixes — what intelligence is available around me, what does it know, and what authority does it have? Phones, speakers, displays, vehicles, robots, browsers, and whatever comes next are embodiments. They come and go. The intelligence remains continuous, because the community — not any device or vendor — owns the substrate it learns from.

And the ordering is deliberate: identity, consent, authority and policy are built before the intelligence becomes extremely capable. AI proposes; policy decides — no generated instruction bypasses deterministic authorization, and a system capable of almost anything is still authorized to do only what its grants allow. Capability is not authority.

Evidence takes precedence over preference. The architecture explicitly distinguishes objective observation, scientific consensus, derived hypothesis, cultural norm, personal belief, and fiction — and expects uncertainty to be stated, with confidence attached to conclusions.

AgentsIdentity, delegation, revocation

When intelligence acts for someone, four questions must remain easy to answer.

Identity
The person and the agent each have a persistent, verifiable identity independent of any model or vendor.
Grant
Delegated authority names the actions, resources, spending limit and duration.
Provenance
Every act points back to the grant that authorized it.
Revocation
Revocation ends future authority when enforced. It cannot undo completed acts.

Spending makes the test concrete: who authorized it, from which resource, up to what limit, until when, and how can a counterparty verify the grant? The authority lives in that grant, never in the model.

The identity substrate is deliberately open: conventional cryptography, decentralized naming, or something not yet built. The problem is identity, authority and trust; no ledger is the product.

DisciplineEngineering principles

Optimize for adaptability · inspectability · reversibility · iteration speed · capability compounding · scalability · interoperability · sovereignty.

Never optimize for captivity.

The business model follows the same rule: revenue comes from creating value — hosting, convenience, maintenance, support, operations — never from making departure expensive. Trust is earned by making departure safe.

EvolutionWhat reality taught

Reality remains the ultimate teacher. Sathi is tested on its builders first, and the lessons that generalize are recorded here — what was believed, what reality showed, what changed. Dated, so the principles can be seen to move.

2026-09
Compute may travel; the durable substrate stays with its node. Saying models were replaceable described the software seam but not its physical deployment. Changed: every capability is intended to route to the nearest capable and authorized node — local, private, operated, external, or disabled — while only minimum task context crosses. A receiving context may form its own local claim; the source node’s durable substrate does not migrate. These are deployment options along one locality continuum, not separate products.
2026-08
A paraphrase is not testimony. The system had asserted a false family relationship, derived from its own summary of a conversation rather than from anything the person said. Changed: only a person's own words may become claims about them; the system's notes and other people's words are archive, never testimony; every claim quotes its source; what is inferred renders as unverified.
2026-08
No proposal without the person's words on the card. A “journey” had been proposed from a question about a word, not from any stated intent. Changed: a proposal must quote the sentence that states the move, and the sentence must really be there.
2026-08
Understanding must be regenerable from the archive. Fixes to how understanding is derived were being applied by hand, per person. Changed: every derivation stage carries a version; a bumped version regenerates understanding for everyone from the archive, staged and measured before it replaces what people see; the person's own decisions — forget, correct, reject — are a ledger every regeneration re-applies, so nothing decided against is re-learned.
2026-08
Capability is not authority, and the executor is never the asset. Competing with frontier agents at execution was a losing frame. Changed: agents and models are replaceable execution engines behind one interface; the architecture owns identity, memory, permissions and orchestration — improvements arrive by upgrade, not reproduction.*
2026-07
Exit must be a tested code path, not a policy. “You can always leave” was a sentence. Changed: signed export, deletion receipt and archive validation are exercised by tests. Automatic one-step re-instantiation on a replacement deployment remains in development.

StatusWhere this stands

This is the public scratchpad of a living architecture, not a released framework. Its implementation remains inside Sathi while daily use is still changing the structure.

We will distill, generalize and publish the framework and reusable code only after Sathi reaches saturation: the core patterns survive repeated use, adversarial review by multiple frontier systems, and independent human and security scrutiny. Until then, Sathi is the learning product and these pages record what appears durable.

There is no package to install yet. If this direction matters to you, write: info@altruistic.ai.

A small * after a sentence on these pages marks a claim that is still being implemented, planned, or not yet independently verified. The reference implementation publishes each capability’s status at sathi.ai/capabilities; the convention is explained at sathi.ai/trust.