// 01 · Operations system

The house becomes an operations system.

Every system in the residence is composed into a single, governed stack — from the on-prem control core to the AI command layer that sits above it.

  • L0
    Local control core

    On-prem hub runs the residence with no dependency on the cloud.

  • L1
    Sensors & devices

    Lighting, climate, water, locks, cameras — modeled with verified state.

  • L2
    Security & network

    Segmented VLANs, firewall policy, and perimeter protection.

  • L3
    AI command layer

    Proposes actions; the deterministic engine authorizes and logs them.

CORE AI COMMAND
// 01b · The stack above the engine

The house learns, infers, and runs itself.

The permission ladder governs a single action. Four deterministic tiers sit above it — each in the engine’s jurisdiction, the reasoning model an optional worker, never a dependency. Capability climbs; authority never leaves the engine.

HOUSE DIRECTOR
Who is driving, right now. An escalation detector raises the mode on a life-safety inference, a health cascade, or repeated actuation failure — and hands control to a person. Governs the mode, never an action; every transition is hash-chained.
AUTONOMOUS · AI_ACTIVE · HUMAN_OVERRIDE
AUTONOMY
Routines act on standing authority: grant it once and the house runs its reversible energy, comfort, and security operations within your bounds — without asking each time. Every action still faces the ladder, and it is revocable in one move.
INFERENCE
Fuses several signals into a situation: falling water pressure and rising flow → leak suspected; high CO₂ and an empty house → ventilation fault. Advisory only — it never actuates.
VIGILANCE
Learns each sensor’s own normal for this house at this hour (robust median/MAD) and flags deviation — the 3 a.m. weeping pipe, the drifting furnace — spike-proof, and it never actuates.
PERMISSION ENGINE
Governs every individual action — L0–L5, server-side. The one thing nothing above may bypass.
PHYSICAL / LOCAL
Every switch, valve, and breaker always works, and local automations keep running — never waiting on any layer above.

Reactive → vigilant → inferential → autonomous → governed autonomy level. Nothing above the engine actuates except through it; nothing below it depends on anything above.

// 05 · Permission model

Six levels of authority. Two of them locked.

Every proposed action passes through the deterministic permission engine. Authority is a property of the action, checked server-side — the AI cannot escalate itself. The engine below is real — propose a command and watch it decide.

The AI never receives uncontrolled authority. Levels 4 and 5 have no execution path exposed to the model — they can only be recommended to, or are prohibited from, a human.

permission-engine · deterministic · runs in your browserIDLE
// propose a command — the engine, not the model, decides. every decision is appended to the hash-chained record in §08 below.
LEAK TELEMETRY: DRY · FLOW NORMAL DECISIONS THIS SESSION: 0