INTELLECTAI
Access Intellect · Enterprise Substrate REV 0 · PRE-CONTACT DWG-003 · Sheet 1 of 1 · Scale: NONE
INTELLECTAI
The attention layer for enterprise work.
Every enterprise AI product answers when it is asked.
This one decides what deserves asking — at every seat, continuously, on hardware you own — and it writes down every time it decided not to speak.
Nothing here has run at organizational radius A number without its grain is not a number Solid = measured · Dashed = specified, unrun
SYSTEMS tickets · mail · telemetry RECORD the case, streaming TESTIMONY other nodes' emits LANES — THE WORLD, IN ingest · every token THE RESIDENT · F1 one per seat · ingest at world rate TRUNK EMIT GATE judge at boundaries · hold or speak · margin either way fork 0 MiB · abort 13 µs · 327 ms thought→judgment THE FETCHER 23 MB · always-on · never gated abstain ·927 · top-3 99% FRONTIER SOCKET rented · thin margin only counsel re-judged, or discarded THE SEAM one accountable human per mandate · the writ, authored · warrant, witnessed · separations, kept zero overrides = flatline THE TAPE append-only · hash-chained · every act, every escalation, every hold — with its margin commits only discards logged too THE PROBES — seeded catches · off-margin hold-audit · lagged-outcome ledger · boundary recall INTELLECT AI · DWG-003 · REV 0 ONE SEAT, EXPLODED · SCALE: NONE SCHEMATIC — NOT THE CODE
DWG-003 · one seat, exploded. A resident mind holds one attention state against the seat's real streams and judges at every completed thought — speak or hold, margin written either way. A 23 MB fetch geometry runs beside it, always on. A rented frontier model is a socket, not a tenant. Everything lands on an append-only tape, including the silences. The human seam is drawn in solid green because it is not a fallback — it is the loss function.
SUBSTRATEFUSOR-1 (F1)
BODYCORDIS + DSH-CLASS RUNTIME
FIELDTHE ORG-SPLAT
INSTRUMENTPARALLAX
LICENSEOPEN CORE · MIT GEOMETRY
STATUSREV 0 · RECEIPTS ON ONE CARD
S·01 — The hole

Nobody is making money on AI, and the reason is a missing verb.

The labs are the best-capitalized startups in history and every one is still burning capital. The enterprises are paying for the smartest machines ever built and saying out loud that they cannot find the return. And in one season, every hyperscaler arrived at the same remedy: hire people — roughly 6,250 forward-deployed engineers, shipped into client companies to hand-wire the automations the AI cannot author for itself.

There is a name for that job. Before the crossbar switch, every telephone call on Earth was completed by a person physically joining two wires. The operator was not unintelligent — the operator was doing something nobody had figured out how to mechanize yet. The forward-deployed engineer is the switchboard operator of the cognition layer.

Qplant = Csaved / Cconfine > 1   · ignition ⟺ the automations the system authors reduce its own supervision. The reactor must build the reactor.

Look honestly at a knowledge-work day: brief flashes of real judgment suspended in hours of keeping-up — reading threads, sitting in syncs, assembling context across five systems so that, three times a day, a decision can fire. The flashes are the job. The glue is most of the hours. Frontier models are already superhuman at the flash, when handed the right context at the right moment. The unsolved problem was never the thinking. It was the being-there.

architecturebills likethe mismatch
a human seatpresence (salary)flash prices paid for idle hours
an APIflashes (per call)nobody can afford to watch; the glue hours are unservable
a residentlike the worknear-free watching through the glue · an emit at the boundary · a rented frontier call for the hard flash

The measurement that proves it cannot be a setting

The obvious fix is a threshold: speak when the score crosses it. That fix is dead, and it died by measurement. On a full recorded working day at zero bias, the system fires 921.3 times per stream-hour — and the flood is breadth, not repetition (~59 distinct conditions per hour). At the best fixed setting, it catches 36 of 39 planted moments — and is still deaf exactly where it matters, because the aggregate hides the misses that count. There is no setting between the jaws:

A fixed policy cannot express a state-dependent utility. The same unfilled field deserves nothing at hour two and a page at hour nine. One number cannot say both — so the judgment has to live in weights.
THE ONE SENTENCE NO ADVERSARY COULD KILL — outside witnesses: Lucas critique · covariate shift · gain scheduling. It also kills the SOP and the escalation matrix, which are dials with more branches. The shadow wire — the tacit practice every org actually runs on — is the SOP's own 36-of-39.
The flood, untuned
921.3 fires / stream-hr
full recorded workday · dial = 0 · dedup 1.07 (breadth, not repetition) [M]
After the tune, matched grain
63.4 → 6.7 %
per decision boundary · ≈9.5× cut · catches direction-audited [M]
Judgment latency
327 ms
completed thought → verdict · one consumer GPU · 9B-class open weights [M]
S·02 — The regress

Every AI system deployed today is woken by something dumber than itself.

A cron job. A webhook. A human hitting send. Follow the chain upward and it terminates, every time, at a schedule or at a person. Hand the waking to another model and you have moved the question one rung. It is turtles, and the bottom turtle is always a clock. A loop that must be started from outside is not a loop — it is a subroutine with good marketing.

There is exactly one exit: a mind that is never invoked because it is the thing that invokes. Resident in memory. Watching continuously. Deciding, from inside its own weights, when a moment deserves anything at all. L-CLOCK: the buck stops in the weights, or it never stops.

A streaming API response can be stopped, but it cannot be informed. Awareness during composition requires input and output sharing one state — and the request boundary strips that state by construction.
WHY THIS CANNOT BE BOUGHT AS A SERVICE — the signals the mechanism runs on (ingest logits, boundary mass, margins, the interval itself) live on the owner's side of the request boundary that an API business is built on. You cannot even ask for them. The industry cannot find the missing piece because its business model is standing on it.
Not a copilot

A copilot improves the hours; it cannot close a seat. Savings arrive in whole-seat quanta — automate 30% of a node and you pay for inference and the salary.

Not an agent framework

Frameworks orchestrate turn-based calls and are woken by clocks. This is residency: ingest at world rate, judge at boundary rate.

Not a workflow platform

Those require a human to etch the route. Here the etch is the residue of the system's own sleep — workflows as exhaust, ratified by you.

Not a model

Bring open weights. Intelligence is rented at a socket and improves on someone else's capex. What is owned is the loop, the record, and the field.

S·03 — The geometry

Attention is already the renderer. This is not an analogy.

The core operation of 3D reconstruction — splat rendering — shades a pixel as a normalized, kernel-weighted mixture over primitives. The core operation of every modern AI model — attention — answers a query as a normalized, kernel-weighted mixture over keys and values. They are the same estimator (the textbooks call it Nadaraya–Watson), and the kernels match algebraically:

exp(q·k) = exp(−½‖q−k‖²) · exp(½‖q‖²) · exp(½‖k‖²)   · softmax cancels the query's own term
Key direction is the splat's position. Key norm is its opacity. The model's memory is, quite literally, a scene — which means an organization's records can be treated exactly the way photographs are treated in reconstruction.
SEATS ARE CAMERAS · DECISION-CLASSES ARE THE PRIMITIVES · REGISTRATION IS THE POSE · THE FROZEN FRONTIER MODEL IS THE RENDERER — RENTED, NEVER FINE-TUNED PER ORG. DON'T TRAIN THE MODEL; TRAIN THE SCENE.

The residual is the product

Fit the field so it predicts every seat's tape; the render is free — what the field cannot predict is the invoice. High residual → add a camera (discovery). Sustained low residual → the seat has measured its own automation-readiness. Ambiguous → buy the sensor exactly there. That is the entire forward-deployed job description, restated as gradient descent.

You cannot see past your boss is not a workplace complaint. It is a rendering equation — summaries occlude the events they summarize, and managers are the alpha channel. The same mathematics that can measure a distortion can demonstrate that a reputation is a compositing artifact, with a magnitude and an ordering.

Why residency, geometrically

A language model is static weights plus a context: each inference is a posed photograph. Turn-based systems are an unordered photo album, and before you can reconstruct anything you must solve the hardest problem in photogrammetry — recovering the poses. Measured: ±1 tick of timestamp jitter costs 57% of registrability on a world whose true structure is bit-identical. Jitter has no pose.

A resident node is a video camera. Its frames are continuous, its clock is its own, its pose is itself. Residency doesn't just make the capture cheaper — it makes the pose problem disappear. And the scene moving is fine: splats work on video. An organization is a 4D scene; any seat, any as-of moment; "no one could have known" becomes "the record knew."

S·04 — The boundary

Which work. Why that work. Exactly where it stops.

Every vendor says AI can automate work. Not one can say which work, why that work and not the next, or where it stops — because their answer is a policy, and a policy erodes with every model release. This page gives a decomposition instead. One functional — F[p] = E[cost] − T·H[p] — and an organization separates into three sub-problems at three temperatures:

sub-problemthe operationnative?
RENDERwhat does this seat see; what would it decide — row-normalized attention, T = 1native — it is the forward pass
ALLOCATEwho does what, under capacity — row and column normalization: transport, conservation. Hard constraints enter as −∞ masks before normalization: compiled policy, fully auditable, unoverridable by the learned partsnative — the plan is the forward pass
CHOOSE STRUCTUREwhich seats exist, who answers for what, what it is all for — discrete structure searchnever — no temperature makes "delete seat 7" differentiable
Two thirds of an organization is a native operation on the AI substrate. The last third is governance — and it is provably not native. The geometry fails precisely where a human must stand, and nowhere else.
THE BOUNDARY THE MATHEMATICS DRAWS IS THE BOUNDARY THE CONSTITUTION ALREADY DREW — L-WRIT: the system renders what is; what it is for is imported, never learned. One seat stays open by construction, and it is the owner's. Every competitor's safety story is a promise that erodes with capability. This one is a theorem, and it does not move when the models get better.

The kernel, in three clauses

Facts are looked up. Genius is rented. Judgment is grown where it will be used — and growing it costs staying, plus a permanent, budgeted verification tax that is stated on this page rather than hidden in it. The measured form of the law: restraint transfers (holds transplanted 34/36 across a domain shift) · recognition is domain-bound and must be fetched (the emit half fell to 66.7% and failed its pre-registered criterion) · the operating point is local and must be re-fit forever (the same dial that read 100% fitted-on-eval read 45.8% frozen-on-dev — same model, same data, same day).

And the storage discipline underneath: weights store habits. Trunks store live relations. Tapes store retired relations. The writ stores purpose. Every failed approach to enterprise AI filed one of these in the wrong store — it trained what should have been fetched, prompted what should have been trained, or discarded what should have been held.

S·05 — The machine

Six parts. No substitutions.

PARTS MANIFEST · SOLID = MEASURED, DATED RECEIPT · DASHED = SPECIFIED, UNRUN · ONE CONSUMER GPU IS THE REFERENCE BENCH
P-01THE RESIDENT

One small mind per seat — calibrated, not smart

Shared ~2B base, per-seat adapter (habits only), mounted read-only on the seat's real streams. Ingests unconditionally; judges at deterministic boundaries; writes every hold with its margin. Full sensorium — surprise (what changed), dwell (what refuses to change), corroboration-deficit (the engineered-ordinary: fabrication caught at AUC 0.81–0.84 where novelty reads 0.23, anti-correlated), interoception (where its own competence ends).

fork onto trunk 0 MiB · abort a forming thought 13 µs · three minds, one state 1.208× · fold 14.8× (5,036→341 tok, load-bearing facts kept) · recall ≥98,304 tok (160k+ with KV-quant, VRAM-bound) · co-residency 2.23 ms p50 beside a live 60 fps scene · live hours banked 2026-08-12, every hold and margin on the ledger
P-02THE FETCHER

23 MB of geometry, always on, never gated

Relations are fetched at decision time, never trained into the resident. And retrieval must not sit downstream of the emit gate: a missing fact surfaces as a confident wrong hold at −16 logits, never as an escalation — measured on this program's own flagship case. The pipeline is receipted end to end:

knows-when-nothing-matched AUC 0.927 (gold-deleted arm; 1.000 off-domain) · shortlist recall top-3 99% on zero-overlap paraphrase (top-1 alone dies at 51% — the two-stage design is mandatory, and receipted) · adjudication over the shortlist 95% on-distribution at the 4B reference tier (55% on full-paraphrase, margin-gated; the 1.7B tier measured at chance in this role and retired from it — printed, not hidden)
P-03THE SOCKET

The frontier as a rented socket

Called only when the margin says I cannot rank this, handed the context the fetcher assembled. Returned counsel is re-judged against a world that kept moving and discarded when stale — with the discard on the tape. At ~3,000 tok/s the second gear completes inside one human thought. Intelligence is never the constraint and never the moat; it is load-bearing, replaceable, and metered.

P-04THE TAPE

Append-only, hash-chained, governed from day one

Every act, every escalation, every hold with its margin. Sealed retention epochs with cryptographic erasure — destroy the segment keys on schedule and the chain survives as tombstones. Record-level consent: each tape belongs to the person it records; there is no all-seeing central trunk, by construction. And the sentence said to every buyer out loud: this record can be subpoenaed — that is part of what makes it trustworthy.

P-05THE PROBES

The honesty battery — because a falling escalation rate is also what blindness looks like

The system's success metric and its failure signature are the same curve, so no deployment ships without the instruments that cut the wire: seeded catches (known-catchable events at a declared rate, schedule hidden — the mystery shopper, printed beside the escalation rate forever), the off-margin hold-audit (a never-zero budget of confident holds silently escalated anyway — a margin-triggered sampler structurally cannot see confident-and-wrong), the lagged-outcome ledger (the world grading banked holds retrospectively — the only oracle whose bandwidth scales with the organization, and the only one outside every model lineage), and boundary recall (an hour of raw stream, judged against the unsegmented feed — the number that multiplies every catch rate, which nobody in this industry has).

the law: the falling escalation rate is not a metric until a probe arm holds it honest and the disagreement sequence tests white
P-06THE SEAM

One accountable human per mandate

The writ (one page, authored, never fitted), the warrant (a signature faster than reading speed is transport wearing warrant's clothes), and the separations (maker–checker boundaries exist so that collapsing them requires conspiracy — a single weight-resident transform that does both sides has deleted the control; separation is enforced at the fabric, not in a policy document). The human is not the fallback. The human is the loss function.

S·06 — What it sells

Four deliverables, in the order the arithmetic forces.

  1. The coverage audit — week one, read-only, writes to nothing. From witness multiplicity alone: your dark matter (events with zero independent observers, bounded with no ground truth), your key-person risk (the single-witness band — knowledge that exists in exactly one living head, and what breaks if that person is out two weeks starting Monday), and the coverage complement (what nothing has watched, for how long). Every owner has an opinion; nobody has the number. It lands on a budget line that already exists — risk — and it survives the IT review because there is nothing to review. Nobody else sells an organization an honest negative.
  2. The record of silence. Shift handoff stops being "anything happen?" answered from memory, and becomes testimony: fourteen thousand boundaries judged, spoke three times, six near-fires with margins. Not producible after the fact — a rebuilt context judges measurably later and noisier — and simultaneously the one training corpus no invocation-shaped vendor can generate, because their systems do not exist during the silences.
  3. The lens report. Per seat, the calibration operator — how this seat's view distorts what passes through it, along which axes, under which conditions. Its ancestor fingerprinted an entire documented pathology without one interview: the director with high title and zero presence, the supervisor with low title and total control. The same instrument that could automate a scapegoat is the first tool that can exonerate one — which is why the gates come before the capability.
  4. Compression — last, and never as a graded promise. Propose responsibly at ~425 events (≈4.5 days of watching). Grade a closure honestly at ≥3.6×10⁶ events. That is an 8,500:1 gap between the trigger and the verdict — so we do not charge for compression, because compression cannot be honestly graded inside a decade and we will not invoice what we cannot prove. We charge for the audit and the ledger; where a seat's closure is actually gradable, a capped gainshare on that seat and nothing else. Ungradability, stated as policy, is the differentiator — every buyer in this market has been lied to about AI ROI for two years, and the vendor who declines to charge for the headline outcome, for a stated mathematical reason, is the only one they believe.
The jobs sentence, said plainly, because it will be read back to us later: this machine removes knowledge-work jobs. Slowly, one receipt at a time, by attrition and non-backfill one layer above the residents — and any description of it that cannot say that sentence is marketing.
THE ENTROPY CONTRACT: EVERY COMPRESSED WORKFLOW IS PAID FOR SOMEWHERE. THE MANDATE IS THAT THE EXPORTED ENTROPY NEVER TAKES HUMAN FORM — THE TRANSITION MANAGED BY ATTRITION, WITH DIGNITY, ON THE RECORD. AND COMPRESSION FUNDS EXPANSION: CHEAP COGNITION ALSO MEANS READING EVERY CONTRACT EVERY DAY, RECONCILING CONTINUOUSLY, WATCHING EVERY CASE AT 3 A.M. INSTEAD OF THE FOUR THAT GOT ESCALATED.
S·07 — The gates

Architecture, not policy. Six of them.

A fitted field is a surveillance instrument with a diagnostic mode, and its failure mode is worse than its absence. So the gates live in the constitution, not the terms of service — and the sixth one costs us sales, which is the only reason to believe we mean the other five.

01 · The subject reads their own number first

Every person sees their own lens, and their own exposure to briefing order, before any superior can. Publication beyond the subject is an act — gated, consented, revocable, logged.

02 · Use without show

The model may use a fitted view of a seat internally to predict better. Rendering a named person's numbers to anyone else is a separate surface with no default path from the first. No machine path from a lens to a verdict about a person — the gap is the law.

03 · Consent at the record level

Tapes fuse only by consent; each belongs to the person it records; forming thoughts never cross between rooms. No central trunk exists to breach — the ethics and the moat are the same wall.

04 · A healthy override rate, published

An organization where no human ever overrides the instrument is not well-governed — it is asleep. And one where overrides quietly stop is captured. Zero is a flatline, not a success metric.

05 · Green is not deploy

Passing every test means the instrument exists and its misuse cases were published before its capabilities. Whether it touches a real organization is a governance question belonging to the people whose work it would read.

06 · The HR wall

No output of this system — raw, derived, or aggregated — may enter a performance, promotion, discipline, or termination process. Enforced by contract and by the absence of an export path, audited by the same tape that audits everything else.

S·08 — The plate

Ratings as measured. Failures kept. Receipts by name.

[M] MEASURED — dated receipt, reference bench · [P] PROVED IN-TOY — frozen lock, synthetic world, planted truth · [D] DERIVED — chain shown
quantityratinggrain / receipt
the vise — flood at dial 0921.3 fires/stream-hr[M]full recorded workday · dedup 1.07 — the flood is breadth
the tune, matched grain63.4% → 6.7% (≈9.5×)[M]per decision boundary · catches direction-audited against a 69% always-hold floor
fold — self-authored compaction14.8×[M]5,036 → 341 tokens, planted load-bearing facts survived
recall — honest multi-hop≥98,304 tok[M]160k+ with KV quantization; VRAM-bound, not model-bound
fork · abort · co-decode0 MiB · 13 µs · 1.208×[M]one trunk, multiple minds, one consumer card
fetcher — abstentionAUC 0.927[M]gold-deleted arm, n=200; 1.000 off-domain; 14% topical-neighbour leak printed
fetcher — shortlisttop-3 99%[M]zero-overlap paraphrase, n=200; top-1 alone is 51% — two-stage mandatory
fetcher — adjudication95% / 55%[M]4B reference tier, on-distribution / full-paraphrase; 1.7B at chance, retired from this role
lie triad — fabricationAUC 0.81–0.84[P]where surprisal reads 0.23 (anti-correlated) · suppression: recovery 0.512→0.822 via conservation
clock fragility−57% registrability[P]±1 tick of jitter, bit-identical world · the first deliverable is a timestamp audit
criticality — on the stockR² 0.996[P]vs the LP-dual's 0.348 · throughput-as-capacity falsified (τ ≈ −0.20)
propose vs grade425 vs 3.6×10⁶ events[P]the 8,500:1 gap — prints beside every compression sentence, carry both or neither
ignition criterion94.5% vs numeric boundary[P]upper branch only · hysteresis band 3.66× · alpha-heatable iff automating supervision creates less supervision
live judgment on a real streamfirst hours banked[M]2026-08-12 · 25 contiguous clean minutes · every hold and margin on the ledger

The funerals, kept — a plate that hides its failures is a brochure

A min-cut lie-cost bound (vacuous at its degenerate corner) · an LP-dual criticality ranking (correlation −0.066 with reality) · throughput-as-capacity · an entropy-ratio readiness score (undefined at the most automatable seat; rewarded the trick that fools it) · three vision funerals (a motion read that was an artifact; a congruence effect that was null; a segmenter lift that was noise) · the logit boundary-gate, retired at AUC 0.775 — the shipping segmenter is deterministic and says so · a "first-corroborator" constant retired as the toy's own planted parameter · and a citation-retrieval headline halved by its own zero-overlap control (95.5% → 51% top-1), which is why the shortlist ships and the headline does not.

Not one constant on this page has survived contact with a real business. Nothing here has run at organizational radius. The engagement is designed so that contact itself — the audit re-run, the probe arms, the second tenant — is the experiment that finishes the equation.
STANDING CONSTRAINTS, PRINTED: REFLEXIVITY IS STRUCTURALLY UNIDENTIFIED AT SERVED SCALE (THE RANDOMIZED HOLD-STRATUM IS THE MANUFACTURED EXCLUSION RESTRICTION — A KNOWN, BUDGETED RATE OF DELIBERATE INTERRUPTIONS, PAID FOREVER) · EVERY EXPOSURE FIGURE IS AN UPPER BOUND AGAINST A NON-ADAPTIVE ADVERSARY · EVERYTHING SITS DOWNSTREAM OF AN EXTRACTION STEP THAT DECAYS AS ρ^k · ONE SYNTHETIC WORLD FAMILY SO FAR.
S·09 — The endgame

Two basins. Every organization is falling into one of them.

A captured organization is self-reinforcing downward: each expelled competent person removes a calibration point, and every removed reference makes the next removal easier. An instrumented organization is self-reinforcing upward: each honestly modeled region makes the next cheaper to model. What decides the basin is not virtue — it is price. To fool a live estimator fed by independent channels, a performance layer must coordinate the timing, variance, and covariance of everything it emits, forever — and that costs more than running the organization honestly. The performance layer does not need to be prohibited. It needs to be priced out.

And the capture machine's only method — expel the calibration points — has no move against this one. The field holds no title, fears no supervisor, appears in no reporting chain. It is the reference that cannot be fired.

The middle of the organization is not deleted — it is re-filed: habits into weights, relations onto the tape, purpose upward into the writ. What remains at the limit is a world model, a writ, and the residual — and the residual, the part that stays surprising, was the organization all along.
A ZERO-RESIDUAL ORGANIZATION IS NOT AN OPTIMIZED ORGANIZATION; IT IS A ZOMBIE WITH AN ORG CHART. COMPRESSION'S HONEST ASYMPTOTE IS THE RESIDUAL ITSELF — YOU COMPRESS UNTIL WHAT IS LEFT IS THE PART THAT IS ALIVE. SYSTEMS THAT MODEL THEMSELVES HONESTLY SURVIVE. SYSTEMS THAT NARRATE THEMSELVES COMFORTINGLY DIE.

The ladder in

Land as the watcher, not the workflow. One seat, read-only, mounting connectors the customer already owns, emitting nothing but a daily tape and a coverage report — unfalsifiably safe, because it writes to nothing. Then the writ frontier advances one parity receipt at a time, every advance reversible by construction, because the layer underneath was built out of inverses. Trust is never requested. It is climbed: form < placement < utterance < citation < action-carrying-its-own-inverse — the harm order and the curriculum order are the same order, and rung N's receipts are rung N+1's training set.