Architecture

How identity, context, permissions and execution connect across Sathi.

Updated 2026-10-03. English reference · Overview in five languages · Machine-readable guide. What the * means.

The core loop

conversationsdocumentsvoiceimportsThe archiveoriginals, unchanged — live deletion takes precedenceUnderstandingclaims: when true · how sure · where fromchathome briefsearchremindersbetter modelsre-read the same lifeyour correctionsteach it
  • Archive first. Originals are preserved unchanged; understanding is always re-derivable from them. The one permanent exception: user deletion removes live records and derived understanding. Backup and downstream retention are separate.*
  • Beliefs are bi-temporal claims. Each carries valid-time, learn-time, confidence, and provenance; new facts supersede rather than overwrite, so "what did I believe last year?" stays answerable.
  • Context assembly is the product. Every reply is grounded in a budgeted, scored selection of memories, documents, and knowledge — traceable per assembly. Abstention beats invention.
  • One understanding, many surfaces. Chat, voice, documents, devices all read and teach the same substrate — never per-capability or per-device memory.

The graph spine

The world is modeled as a graph, not containers: each person is a sovereign node that belongs to itself, and belonging — to a family today, a community later — is a consented, revocable link carrying the consent that created it. Person, family, company expose the same interface at every scale (recursive composition), and crossing a boundary is an explicit, governed act answered with the least disclosure that suffices.

Projections and organs

Reality may compose to arbitrary depth — company, division, branch, department — without making the interface a tree. A projection is a permitted human viewpoint into that graph, shown as one flat set of useful contexts: Me, Home, a company, a project. The selected view guides the interface; it does not unnecessarily narrow an agent's authorized reasoning horizon. Every traversal remains bound by principal, purpose, authority, policy, provenance, and least disclosure.

Apps are organs over the same substrate, not little products with new identities and databases. Conversation, documents, calendar, devices, websites, APIs, and eventually user-created apps can expose different views and capabilities while reusing the graph's ownership, relationships, permissions, and provenance.

Today: the first projection slice is live for directly maintained admin contexts, including switching and projection-local home, app, and chat views. Arbitrary-depth context discovery, general personal and institutional projections, and a public graph-operation interface remain direction, not shipped capability.

One Sathi; movable execution boundary

Identity, archive, understanding, relationships, permissions, agents, and context belong to the Sathi node. They do not migrate merely because a task needs different compute. The placement rule is to use the nearest node that is both capable and authorized, sharing only the minimum context the task requires:

local → your private infrastructure → Sathi infrastructure → external frontier provider → disabled

  • Current: a Sathi-operated private deployment. The model provider receives one request when needed, never the archive.
  • Experimental: the home node and open-hardware speaker rehearse continuous local presence and the device boundary.
  • Direction: suitable wake, voice, basic reasoning, cache, and home control remain local; harder work escalates only when policy permits it.
  • Future offering: dedicated and fully independent deployments on infrastructure whose hardware, storage, keys, inference, and network the person or institution controls — including the ability to remove Sathi Systems and continue.

Cloud, home, private, and sovereign are therefore not four products or four architectures. They are positions of one boundary, applied recursively to a person, household, company, or community. Intelligence may be rented; understanding stays home.*

Deployment shape

  • One Sathi-operated VPS, Docker Compose: FastAPI backend, Postgres (+ pgvector) for archive/claims/vectors, a static Next.js client served by Caddy, LiveKit for family calls, SearXNG for web search. Nightly restic backups are encrypted and stored off-site in Google Drive; a full restore drill passed on 2 September 2026.
  • User files encrypted at rest; short-lived scoped tokens for downloads; per-user storage and spend quotas; tamper-evident audit logs for admin access.
  • Model providers sit behind abstractions with fake test-default implementations. Reasoning, image and speech routes can use external providers, with relevant context disclosed for a task; embeddings are swappable by re-embedding. The processing boundaries are on /principles.
  • Heavy multi-step execution remains direction, not yet wired: interchangeable agent runtimes are selected per task behind the same placement, identity, permission, and audit policy above.

Interfaces

The structured list — statuses included — lives on /capabilities and in /capabilities.json. In brief: the PWA and its REST API serve this deployment's accounts; paired devices can drive Sathi through an OpenAI-compatible chat endpoint (deliberately repointable); a realtime voice gateway is deployed dark; the signed export archive is itself an interface — a fresh Sathi can be rebuilt from it.* No public A2A or MCP service is offered. A private MCP connection lets a person's own assistants use the Sathi capabilities they grant: so far, their Home devices and a read of what Sathi remembers about them. It is in trial.*

Relationship to Altruistic

Sathi is the living implementation through which we are learning Altruistic — an emerging architecture for sovereign, adaptable, trustworthy information communities. Its public research notebook embeds as few values as possible; Sathi adds its own and publishes them. What reality teaches this deployment flows back into the architecture.