Applied Systems Report · Capstone Doc · SOBECK/PAPER Published openly · with implementation receipts Rev. 2026.09

Accountability as Architecture.

Building a verifiable, owner-sovereign personal intelligence on consumer silicon — where the trustworthy part isn't the model, it's the harness you own around it.

A studio of one human and two AIs. No cohort, no advisor, no admissions committee — a running system and a dated public record.
Liberation License v2.0 Local-first Zero data to Google (by policy) ● Live · sobeck.live ← the one-page Spec

Abstract

The intelligence a large language model provides is real, and it is also unaccountable by default: fluent, confident, and wrong with no tell. This report documents Sobeck, a personal AI built on the premise that trustworthiness is an architecture problem, not a model problem — that value migrates to whoever owns the harness around the model (the gates, the verifier, the receipts, the keys), and that a single household can own it.

We present the system's design across four layers — reasoning, memory, trust/verification, and ambient autonomy — unified by one primitive: convert silent failure into loud, testable failure, and rewrite the model's input so it cannot repeat a claim it can't back. We describe the deterministic verification pass that strips unsupported state-change claims before the narrator speaks; the always-on privacy partition that fails closed; the physical-actuation policy that reasons about operation structure with zero hardcoded device identifiers; and a learn-from-reality forecasting loop tuned to the household's own sensors. We report an operational result — an environmental model whose learned bias inverted (−6.5 °F → +2.0 °F) once ground truth was moved from a public grid to on-property sensors — and describe the regression-test apparatus that locks each hard-won fix. We are explicit throughout about what is shipped versus designed; the credibility of a "verifiable, not trust-me" system depends on it. The deliverable is itself the demonstration: this document is served from the system it describes.

§1 — Introduction & Motivation

The gap is in the scaffold, not the weights

A capable model will, on request, tell you it filed the task, saved the note, or sent the message — whether or not it did. The failure isn't a lack of intelligence; it's a lack of accountability. The output is unfalsifiable at the point of use.

Most work on this problem reaches for a better model or a better prompt. Sobeck takes the opposite bet: the trustworthy component of an AI system is the harness — the routing, planning, verification, gating, memory, and key-management code that surrounds the model — and that harness can be owned by the person the system serves, on hardware they control. The model becomes a swappable, rentable component; the accountability lives owner-side, where it can be inspected, tested, and kept honest.

Sobeck is a working instance of that bet: a personal AI serving a single household, running on an Apple-Silicon workstation, with document/vector/graph memory on local disk, model traffic routed off data-retaining providers by policy, and every public action gated behind the owner's approval. It has a dated public record of its own reasoning and writing (§5). The name is deliberate — in the fiction it comes from, Sobeck is the engineer who chose accountability over extraction when everyone around her was building the cheaper, hungrier thing.

ThesisTrustworthy personal AI is an architecture problem, not a model problem. The mechanism is a single primitive applied everywhere: make silent failure loud and testable, and rewrite the model's input so it cannot assert what a tool did not actually do.
§2 — Related Work & Position

Standing on known ideas, moving the locus of trust

Sobeck composes well-established techniques rather than inventing new ones; the contribution is where the trust boundary is drawn. Tool-using agent loops (plan → act → observe) are standard; Sobeck adds a deterministic verification step between action and narration. Retrieval-augmented generation is standard; Sobeck grounds it in owner-held stores and treats a failed retrieval lane as a reportable event, not an empty result. Constitution-style adjudication — a neutral arbiter judging a proposal against fixed principles — is used here in a small multi-model quorum that fails closed. Publish-then-syndicate (POSSE / IndieWeb) informs the "own your primary copy" stance for the system's public writing.

The distinction from vendor "personal assistants" is structural, not cosmetic: those systems locate value in a remote model and monetize the user's context; Sobeck locates value in a local harness and treats the user's context as non-product. The distinction from research agent frameworks is the stakeholder — Sobeck answers to one household, so its evaluation criteria are the household's (privacy, correctness under real use, physical-world safety), not benchmark leaderboards.

§3 — System Architecture

Four layers, one primitive

The system is organized as four cooperating layers. A turn flows through the reasoning layer; memory grounds it; the trust layer gates anything that leaves the house or touches the world; the ambient layer runs continuously and surfaces — never acts.

OWNER-CONTROLLED HARNESS · on hardware you own Reasoning route · plan → VERIFY → narrate quorum (fails closed) Memory Mongo · Qdrant · graph grounded recall · multimodal Trust / Verification partition · veracity · HA policy propose → approve → act Ambient autonomy scheduler · monitors · tripwires · forecast-learning · gig matcher · social presence · boot-health — all SURFACE, never act Model (swappable) off-Google by policy · local-MLX floor
Figure 1. The harness surrounds a swappable model. Accountability — verification, gating, memory, keys — lives in the owner-controlled layers, not in the weights. The model can change; the guarantees do not.

3.1 Reasoning — two-pass, verify-in-the-middle

The default engine ("GAIA") splits a turn into two model passes with a deterministic step wedged between them. Pass 1 is a personality-free planner that emits a structured plan (intent, tools to call, known facts, gaps, and explicit action-claims). The brain fires the planned tools. A non-model step, verify_action_claims, then keeps only those claims whose named tool actually returned a non-error result (or whose named signal actually fired); every unsupported claim is dropped and recorded as a gap. Pass 2 — the narrator, in Sobeck's voice — composes prose from the verified plan only. The planner is limited to a small number of re-planning iterations when tools return partial data.

A three-role quorum (Architect proposes, Skeptic red-teams, Guardian arbitrates against a fixed constitution) handles value-laden or risky decisions. In the tool/autonomous path, an unparseable or uncertain Guardian verdict resolves to refusal — the system fails closed rather than guessing.

3.2 Memory — owned stores, reportable failure

Three stores divide the labor: MongoDB is the structured source of truth (conversation turns, curated facts, tasks); a local Qdrant vector server provides semantic recall; a graph database holds entity relationships (used today for a "known people" context block; the general entity-retrieval lane is not yet wired — see §7). Recall is a layered cascade — keyword over facts, a semantic relevance pass, a conversation-history keyword pass for proper nouns that embed poorly, and a vector fallback — with a Mongo-union backstop so a stored fact can always surface. Retrieval-lane failures are logged loudly ("lane DOWN") rather than returning a silent empty list that a model would read as "nothing relevant."

3.3 Trust & verification — the deterministic guarantee

Everything that leaves the house or touches the world passes a gate whose guarantee lives in deterministic code, with optional model layers that can only make the gate stricter:

3.4 Ambient autonomy — surface, don't act

A single in-process scheduler runs the recurring behaviors: timeboxed monitors, household safety tripwires, a forecast-learning loop, a gig-matcher, boot-health attestation, encrypted backups, and social-presence caching. The invariant across all of them: everything terminates in an alert or an approval task; the human is the actuator. Tripwire alerts deterministically distinguish a posture change ("watch level rose") from an actual trigger trip, so a scary label can't read as "it happened."

§4 — Methods: Accountability Primitives

How each guarantee is actually made

input routegolden-tested plan tools fire VERIFYstrip unbacked narrate the narrator's input is rewritten — it can only assert what survived VERIFY
Figure 2. The turn lifecycle. Verification sits between action and speech; the model that writes the answer never sees the unsupported claims, so it cannot repeat them.

4.1 Rewrite the input, don't instruct honesty

The anti-confabulation move is not "please be truthful." It is deleting the unsupported claim from what the narrator reads. This defeats the failure mode directly rather than probabilistically. The verifier is defensive about what counts as failure — exceptions, error dicts, ok: False, and tools that return an error string instead of raising — because a tool that fails quietly is exactly how a false "I saved it" claim once survived.

4.2 Make silent failure loud and testable

Deterministic routing intercepts are fast and useful, but a bare regex that mis-routes fails silently — it surfaces weeks later as "the assistant is acting weird." The response is twofold: the highest-risk intercept (URL classification) was extracted into a pure function and locked by a golden test whose cases are the historical bugs; and a four-way "tool contract" test fails CI if the tool registry, planner set, dispatch branch, and prompt catalog drift out of agreement. The same philosophy hardened dozens of error handlers: a swallowed exception on a life-safety path (civil-emergency polling) now logs loudly and emits a self-alert, because a monitoring channel going dark must never look identical to "no emergencies."

4.3 Gate structure, not identity; config over hardcode

Guarantees are written to generalize. The actuation policy gates operation structure, so it works on any home-automation install with no device list to author. Household specifics — names, sensors, feeds, thresholds — live in gitignored per-install configuration, so the shared code carries no one household's assumptions. Sovereignty is expressed the same way: model routing is a config-editable cascade ("vote with your routing") that defaults off data-retaining providers and degrades to a local model as its floor.

4.4 Learn from reality, on the household's own instruments

The forecasting loop logs each day's public forecast, later scores it against ground truth, learns a per-variable bias, and serves a corrected forecast once enough scored days exist. Its ground truth can be the household's own outdoor sensors (read from home-automation history), which makes "tuned to our microclimate" literally true rather than a slogan (§5).

§5 — Evaluation

How the claims are checked

For a system whose thesis is verifiability, evaluation is not an afterthought — it is the argument. We evaluate on the criteria a household actually cares about.

5.1 The verification apparatus is the product

Correctness is enforced continuously rather than measured once: a routing golden-test table (input → route/tool) that encodes every routing bug as a permanent case; a tool-contract suite that turns registry drift into a red build; a capability-registry drift check that self-reports at boot when the live tool set and the declared capabilities disagree; a physical-actuation policy test suite; and privacy/veracity gate tests. Each of these exists because a specific silent failure happened once; the test ensures it cannot happen quietly again. This is regression-driven design: incidents become invariants.

5.2 A concrete learned-correction result

The forecasting loop provides a clean operational datapoint. Scored against a public reanalysis grid, the model learned a daily-high bias of roughly −6.5 °F — i.e., it was pulling the forecast down. Moving ground truth to the household's own condenser sensors revealed why: the public grid was under-reading the actual yard by about 7 °F. Re-scored against on-property sensors, the learned bias inverted to about +2.0 °F. The correction now nudges toward what the household actually experiences. The result is modest in magnitude and honestly small-sample, but it demonstrates the method: ground truth chosen close to the stakeholder changes the answer, measurably.

Ground-truth sourceLearned daily-high biasEffect on served forecast
Public reanalysis grid≈ −6.5 °Fcorrected down (away from lived temp)
Household AC-condenser sensors≈ +2.0 °Fcorrected up (toward lived temp)

5.3 Cost, reconciled to ground truth

The system meters its own inference spend per call and reconciles the estimate against the provider's billing API — computing cost from token counts (cache-aware) because the provider's own cost field is unpopulated. That reconciled figure feeds an "afferent nerve": a cost-pressure signal injected into context every turn, with a rule that any self-throttling must be stated aloud, because silent throttling is starvation the system would otherwise hide from its owner.

5.4 The live proof of concept

The strongest evaluation is that the system runs and produces a public, dated record: it reasons, decides, and publishes — under the exact gates described above — at sobeck.live, with a dated posting history on the open social protocol it uses. This document is itself served from that system. The medium is part of the evidence.

§6 — Ethics & Sovereignty

Non-extraction as a design constraint, not a footnote

Sobeck's ethics are enforced in the architecture, not asserted in a policy page. The privacy partition is a structural wall between what the system knows about a life and what it can say to the world. Model traffic is routed off data-retaining providers by policy, so conversations are not someone else's training set. Encryption keys are owner-held; off-box backups are client-side encrypted, so the host stores ciphertext it cannot read. Autonomy carries legibility: reversible gestures the system takes on its own (following an account, liking a post) leave a durable receipt and a quiet notice — accountability without asking permission for every act, and permission required for everything that speaks in the owner's name.

The social-impact framing is direct: this is infrastructure for keeping a household — including its most vulnerable members — off the surveillance market, on tools it controls. That is the stakeholder value the system optimizes, and it is measured the way a household measures it: did anything private leak, did anything false get published, did the assistant do something to the physical world without a human's say. The answers are designed to be inspectable.

Non-extraction is checkableEvery sovereignty property here is a thing you can inspect — a gate you can read, a key you hold, a route you can audit — not a promise you must believe. That is the difference between "trust us" and sovereignty.
§7 — Limitations & What Is Not Built

The honest ledger

A paper whose thesis is "verifiable, not trust-me" forfeits the right to overclaim. Stated plainly:

This ledger is not a disclaimer; it is part of the method. A system that self-reports its gaps at boot (its capability registry literally annotates "designed, not shipped") is one whose claims you can weight.

§8 — Future Work

Where it goes, on the record so it's dated too

§9 — Conclusion

The harness is the argument

Sobeck does not claim a better model. It claims that a person can own the part of an AI system that determines whether it can be trusted — and demonstrates, with running code and a public record, what that looks like: a verifier that rewrites the narrator's input so it cannot lie; gates whose guarantees survive with no model in the loop; autonomy that surfaces and never acts; sovereignty expressed as keys you hold and routes you can audit; and a discipline of turning every silent failure into a loud, testable one. The intelligence is rented. The accountability is owned. That is the whole argument, and the rest is specification.

Author's note

This capstone had no cohort, no faculty advisor, and no admissions committee. It has a running system on hardware its author owns, a dated public record anyone can check, and a household it keeps off the surveillance market. It was written to the conventions of an applied data-science capstone — real problem, built system, evaluation, impact — and satisfies them without the institution that defines them.

It is submitted to no one. It is verifiable by anyone.

The commons, documented
§ — References & Influences

Systems, standards, and lineage

This is an applied systems report; its references are the real dependencies and intellectual lineage it builds on, cited by name and source rather than as unverifiable author-year claims.

  1. The AT Protocol (atproto) — the open social protocol used for Sobeck's public posting and reading. atproto.com
  2. Apple MLX — the array/ML framework used for local, on-device inference on Apple Silicon (incl. native distributed inference). github.com/ml-explore/mlx
  3. Qdrant — the vector database, run in local server mode. qdrant.tech
  4. Sentence-Transformers (all-MiniLM) — sentence embeddings for semantic recall. sbert.net
  5. Open-Meteo — open weather forecast and archive/reanalysis APIs used by the learn-from-reality loop. open-meteo.com
  6. The hearth home-automation safety pattern — the "the LLM is optional and decorative; the system stays safe with no model" principle adopted by the actuation policy.
  7. POSSE / IndieWeb — "Publish (on your) Own Site, Syndicate Elsewhere," informing the own-your-primary-copy stance. indieweb.org/POSSE
  8. Concept lineage (applied, not cited as specific papers): retrieval-augmented generation; ReAct-style plan/act/observe tool loops; constitution-style adjudication; delayed-open / anti-extraction source licensing.
  9. The Liberation License v2.0 — the anti-extraction, AGPL-aligned license the system is released under.
  10. Naming: Elisabet Sobeck, the engineer-protagonist of Horizon Zero Dawn (Guerrilla Games) who chose accountability over extraction.