In detail
Six parts, and the terms: identity, money, platforms, knowledge, buildings, the machinery underneath.
This is the long answer, for the reader who is already interested and wants to find the hole in it. The short answer is on what we make, and the same thing drawn as two pictures is on how it fits together.
We do not sell a subscription, and we do not build and walk away either. What we build belongs to its owner from the first day: the software shared outright, the machines built from declarations the owner holds. A declaration is a written description that a machine follows to build itself. We can stay and run it for as long as we are wanted. The difference from a subscription is that once we are gone, everything still belongs to the owner and still runs.
Nothing here names a client, an address or one of our own systems. The published software we build on is named, because a reader can look it up. Where a number is stated it was measured, on or before 17 September 2026, and where something is not yet proven it says so.
Identity & access
No application here holds a secret that would let it pretend to be another.
Two questions, proved separately
Every call between systems asks two things, and most software answers only one: which application is calling and which person is asking. The application presents a certificate issued to it; the person's own sign-in token travels alongside; the receiver checks both and trusts neither alone.
- No shared secret that every participant holds, and so no participant who can impersonate another.
- A refusal that names which half failed, so "it doesn't work" has a diagnosis.
- Access granted per application and per environment, so a test system cannot open a live door.
- Sign-in with accounts people already own. No user passwords are stored.
The certificate half is carried on private links between our own systems. At a public address the person's token is checked and the calling application is not — a door that never asks for a certificate cannot be handed one. The person's identity is verified with their own provider either way.
Secrets kept once, and brokered rather than copied
One vault holds every credential, with one owner per secret and nothing pasted into a config file. Where something needs a credential from a machine it does not own, it asks a door on that machine, which acts under its own identity and hands back only the answer — so the caller holds nothing, and every read is recorded under the caller's name.
A production credential never lands on a developer's machine, and "who read that secret, and when" is a question with an answer.
Two certificates
Only one of them is ours to publish.
- Our root certificate — public. Copying it grants nothing, which is why it can be handed to anyone. With it installed, our internal sites stop raising warnings.
- A network profile — private. Issued to one person. It decides whether its holder can reach anything at all.
Certificates identify applications to each other on private links. A person is identified by their own provider's sign-in, and by nothing installed on their device. A second check bound to the person's own hardware — a passkey the application asks for itself — is the next thing, and it is not built yet.
The private one carries a secret key, so it is minted per person and never shared; there is no form to fill in. The public one works better the more people hold it, so it is published.
The root certificate, its fingerprint and how to check it are on a page of their own.
For the network profile, write to umesh@ploutosservices.com.
Money
The books are derived from the records, so they can be rebuilt at any time and checked against what the bank says.
A ledger that derives itself
The owner records what happened — a trade, a payment, a call, a fee. The double-entry books are generated from those records and can be regenerated from scratch at any time. If generation and reality disagree, that is a finding.
- Balances per account, per legal entity and per currency, from one set of records.
- Receivables and payables per counterparty, from one computation serving every surface.
- Cross-entity positions stated explicitly rather than netted away.
- Every figure on a screen traceable back to the record that caused it.
What a new client brings. Their entities. Not a chart of accounts — account names live inside the posting rules, so a new client's chart is written rather than configured. And not opening balances: every balance is the sum of every event from the beginning, so a client whose history predates the records they hand over needs that history built before the books mean anything. What transfers is the method — events in, double entry out, regenerable — and that is still the part worth having.
Where it came from
The ledger was built for a small enterprise with large ambitions: entities in several jurisdictions transacting with one another, and on top of that private-equity commitments, capital calls and returns of capital. A service provider for that starts at about a million dollars a year, before the staff needed to manage the provider — out of reach. What stood in its place was mail merge for investor letters and allocations worked out by hand, and the first allocation of portfolio expenses came out wrong. Money was spent by one entity on behalf of several and shared out among them afterwards, and no accountant could get it right, or promise that every settlement between the entities had been made. Bank accounts were opened and closed as the business moved, and a wire confirmation or a statement from years earlier could be asked for at any moment. So the ledger was built instead — it is why positions between entities are stated explicitly, never netted away, and why every document is filed against the record it belongs to — and all of it came under control.
The first entry in its own history is dated November 2012.
Checked against the outside world, not only against itself
Traceability inward — every number back to its record — is the easy half. The harder half is outward: the books reconciled against what banks, custodians and counterparties say, with the gap shown as a number on a screen.
For someone deciding whether to trust a set of books, it is the second that persuades.
Documents become records
A bank statement, a card export, an invoice or a scanned bill arrives as a file and becomes structured records without anyone retyping it. Re-running the same file changes nothing — the import is safe to repeat, which is what makes it safe to automate.
- Charges matched to the orders and counterparties that caused them.
- An inbox that watches for documents and files them.
- Extraction from scanned paper, not only from clean exports.
- A summary written at intake, so a record is recognizable months later.
The safe-to-repeat guarantee holds where it was built for — card exports, the payment door, the invoice route — and is not uniform across the older statement loaders, so it is a property of those paths and not yet of every path. And extraction from scanned paper currently sends the page to a hosted model. It is the one place where the content of a document goes to somebody else's model. Where that matters, inference on hardware the owner holds is the answer, and switching to it is work, not a setting.
What a new client brings. Samples of every document they receive. A format we have not seen is a handler to write, and handlers are deliberately per-format rather than one clever parser that half-works on all of them.
We build the check as well as the thing
Where a computation matters, a second, independent one is built beside it and the two are compared — object by object, published where they disagree, so a difference is a row somebody can read.
- Decades of hand-written posting logic rewritten independently and compared: 23,176 of 23,199 objects byte-identical, and each of the 23 residuals explained.
- The generated ledger stood against the legacy one per account and per currency, so a disagreement has an address.
- Filed tax figures recomputed independently and verified against real filings before the code was trusted.
A check that cannot run is absent, never guessed. A recomputation for a year whose rate table it does not carry produces nothing. It does not borrow last year's brackets and return a number that looks like an answer.
A store the server cannot read
Instead of keeping the most private papers on a USB stick in a drawer, they can be kept here. Each document is sealed with a passphrase only the owner knows, before it is stored, and opened only in the reader's browser. If the passphrase is hard to guess, the stored files are useless to anyone else, including us.
What that protects against is a leak. A copy of the database, of the application's files or of our credential store shows nothing readable, and that can be checked: a dump of that store yields only sealed bytes. The passphrase is kept by the owner and is in none of those places.
The two kinds of data are kept differently on purpose. Business books are meant to be read by staff, so they are protected by sign-in and permissions. The sealed store is for what only the principal should ever read. Today it holds personal and family finance.
Platforms
Every row carries the world it belongs to, and every query is scoped by it — from the session, never from the request.
Many worlds, one set of machinery
This is usually explained as selling the same software to different companies. That is not the common case. The common case is one owner with several worlds that must not mix — the operating business, the family office, a trust, the household, personal accounting. Same person, same machinery, and no leakage between them.
- A new world is a new tenant, not a second installation to maintain, back up and patch.
- Its own address, its own branding, its own rules, its own people.
- Isolation between applications sharing a store is enforced by the database itself: row security on, forced, naming the calling application, and failing closed.
- Somebody who belongs to two of them sees both, and only because they belong to both.
Serving several unrelated clients from one installation is a side effect of building it this way, not the reason for it. If the walls are sound enough to keep one owner's worlds apart, they are sound enough for that too — and if they are not, we would rather find that out on our own books than on a client's.
This is a property of what we build when it is needed — not the shape of the business. We are not selling seats on something that already exists.
Administration people run themselves
The people an organization serves do their own administration and see only what is theirs — signing up, paying, checking a calendar, reading a report — with no administrator in the middle and no household's affairs visible to another.
- Annual sign-up online, with charges computed by rule rather than by hand.
- Payment taken online or recorded when it arrives another way, with one view of who stands where.
- Calendars, assignments and per-person reports, visible to the household they belong to.
- Bulk email drawn from the live register rather than a typed list, addressed to the household as one.
- A known person becomes a user at first sign-in, with no administrator step.
Running now: vidyalaya.org — a school whose families enrol, pay, and read their own children's classes and reports. The public side is open to anyone. Everything behind the sign-in belongs to the household it is about.
When the ground moves underneath
A small one, from this year. The school runs its classes on Google Classroom. Last year a family with an ordinary personal address could be invited into a class by email. This year Google stopped allowing that for addresses outside the school's own domain, and every family would have had to find a class code and type it in. It was found by trying it, not by reading about it.
An AI model wrote a small program that sends every family its own join link. For a family nothing changed: last year they clicked a link that came from Google, and this year they click one that comes from the school.
Nothing undeclared is served
A field is declared once, and both the store's tables and everything a screen is told are generated from that one declaration. The public surface is a typed-out list, never computed from what happens to exist — so adding a table and forgetting to expose it fails visibly, naming the table, instead of quietly publishing it.
It answers the question a diligence reader always reaches: how does anyone know that only what was decided is served?
Bad data is refused, not processed
Where a computation depends on data being sound, it runs against a stated quality gate. If a row violates a guarantee, nothing is computed — and the refusal carries the offending row as read and the named check it broke.
The alternative is to process the dirt and produce a confident wrong answer nobody can trace.
A delete that refuses, and names who is holding on
Deleting a record checks every reference to it first and fails with the name of whatever still points at it.
This is true at the record level. There is no whole-organization export or delete today.
Knowledge & AI
What an organization knows becomes something that can be asked a question — in plain words, cited, and answered for each reader only from what that reader may see.
Knowledge as private websites
An organization's own records — agreements, registries, licences, contacts, properties — live as private websites its people sign into. Each reader's access is declared once and enforced everywhere, and a page meant to be protected is protected the moment it is saved, not the next time something is deployed.
- The owner edits any page themselves; nothing waits on a developer.
- Every change reviewable before it is seen, and versioned after.
- Access declared as data, so "who can see this" is a question with an answer.
- An index across everything, so a document can be found.
Where it came from
The same small enterprise. Its work was more complicated than the staff it could afford to hire were trained for. So the library was built, and the steps were written into it: what to do, in what order, and how to tell that it was done right. People could then carry out complicated work without constant supervision, because the understanding was on the page rather than in one person's head.
Pages as declarations
A page's structure is declared once and applied everywhere it is used, so changing how a pattern looks is one edit rather than hundreds. What each page says stays entirely the owner's; what it is becomes something a machine can change at scale.
- Uniform construction without uniform content.
- Tables written as named data rather than markup, so the numbers a person reads are the numbers a tool can read back.
- Tables that fetch live figures at the moment the page is opened, instead of ageing quietly.
Ask the organization's own material
A question in plain words, answered from the organization's own pages, citing the page it drew from — and answering each reader only from material that reader may see. A search that returns links makes the reader do the work; this does not.
- An answer with a citation, so it can be checked.
- What a reader may not see is never put in front of the model, rather than the model being told not to repeat it. The payload is assembled per person and per permission before the question is asked, so there is nothing in the context to withhold.
- The same approach pointed at the public: a question box that answers from the site's own facts, not the internet's.
- Answers graded against a scored question set before a change reaches a real reader.
Go and ask it: the question box on vidyalaya.org answers from that school's own facts, with no sign-in. Ask it something the school would know and something it would not, and watch which one it refuses.
Inference on hardware the owner holds
A model running on a machine the owner holds, so private material is answered without leaving the building. Cloud and local sit behind one seam, switched by configuration rather than by a rewrite, and which one answered is visible.
- Personal data in a prompt without sending it to a third party.
- A deliberate rule that the failure case is not the leak case: when the local model is unavailable, the fallback answers generically rather than privately.
- A measured fallback rate, so drifting quietly onto a paid service is something that can be seen.
Buildings
A building answers to one door that speaks the owner's names for things, and the history it produces belongs to the owner rather than to whoever sold the equipment.
One door in front of a building
A building's devices stop being a stack of vendor apps. One door names everything, reads most of it, and commands what has been proven — with the result read back from the device rather than assumed. A caller names a device and a verb, never an address, a protocol or a vendor identifier, and the refusal says which of the three was hit.
- Control on the local network wherever the manufacturer permits it — and where they do not, the limit below says so.
- Every refusal naming its reason: no such device, no such verb, out of range, not controllable, nothing proven about how to reach it.
- A register of every device on the networks it can reach, kept current automatically — and a network it cannot reach recorded as unreachable rather than left out.
- One property driven from another over a private link, with nothing of ours installed at the far end.
- Events that drive the building: a system arms, and what should follow, follows.
Not everything is local. 6 of 16 drivers speak a manufacturer's cloud and nothing else, and three of the device kinds that carry a proven verb — a garage door, a coffee machine, a thermostat — can be commanded only that way. What the door gives there is one vocabulary and one refusal language over both kinds, not the removal of the vendor.
And the door proves which caller is asking, not which person may use which verb — that is still one shared permission.
The inventory carries no secrets
Every registered service names a vault item and never a value, so the whole register of a building can be handed to someone — or published into another system — without carrying anything that has to be revoked afterwards. Credentials the building needs and nobody holds are recorded by name as not held.
And the register is published as data other systems read, not as a screen inside our application. That is the direct answer to am I locked into this software.
How each fact was learned is part of the record. Every entry carries the probe that established it and the date it was taken, and where a later probe overturned it, the entry that replaced it — so a reader can see not only what we believe about a building but why, and what we used to believe.
The owner keeps the history
What a building produced and what it drew — held by the owner where it can be joined to a bill, rather than inside a vendor's app that shows the last month and charges for the rest. Where a manufacturer holds years of history we take a copy; from the day we arrive we produce the series ourselves, so the record stops depending on their export.
And it is not a better copy of the vendor's data — some of it is data the vendor does not have. A manufacturer's cloud may offer no per-circuit breakdown at all, and the local gateway may keep today, seven days and a lifetime counter with nothing in between. A minute-by-minute reading per circuit exists only because something on the building's own network takes it every sixty seconds and keeps it.
Readings and extracted bills are written into one store by one application, so the two are joinable. A report that answers a cost question end to end is still work.
What a new client brings. A router that will report its own address leases — the register is built from those, and a router that will not say leaves us inventorying by hand. For more than one property, a private link between them. Three more limits: some systems need the original installer to open an integration port first; some local interfaces still need one round-trip to the manufacturer's cloud to mint a credential; and a second client is a second installation rather than a second account.
The machinery
An estate that can list itself is an estate that can be handed over. Everything below is evidence for that.
Every machine built from a declaration, never by hand
A machine is described, not administered, and the description is the thing under version control — 59 installable Ansible roles across 35 plays on 30 declared machines. The same declaration that builds a machine is what a rebuild replays.
The numbers above were read out of what builds the machines, not gathered by going to look at them.
What that actually installs
- Identity and secrets — Vaultwarden as the credential store; a private certificate authority issuing to machines and applications and renewing unattended; Let's Encrypt for internet-facing names; a per-application and per-operator identity.
- Data stores — PostgreSQL and MariaDB, MinIO for object storage on owned hardware, Seafile for file sync and sharing with per-account scope, and shared network storage.
- Code and delivery — Gitea as a private source forge, its runners doing continuous integration on real machines, Docker where a service wants it, and a deploy door admitted by the caller's certificate.
- Scheduling — one scheduler for everything that runs by itself, and a dead-man on the scheduler, so "the thing that runs everything stopped" is itself detected.
- Naming and network — DNS on every machine, a reverse proxy in front of every door, a site-to-site mesh, and a metered fallback so a box that loses its wire stays reachable.
- Observability — Prometheus scraping every machine with Grafana over it, bound to the private side.
- Communication — Mattermost with alerting into it, and inbound mail with a declared recipient list, so an undeclared address is refused in the SMTP session rather than accepted and lost.
- Power — UPS monitoring, so a building losing power is a graceful shutdown.
- Documents and AI — OnlyOffice for editing in place, an inbox watcher that extracts and splits incoming PDFs, a full-text index over the owner's corpus, and Ollama running a model on owned hardware.
59 roles is what is declared installable, not a claim that every one is converged on every machine today.
Everything declares that it exists, and one place answers
Every thing in the estate declares that it exists and where it can be reached, and a single address answers for all of them. A reader — or a machine — asks one place instead of assembling an inventory by hand, and an inventory assembled by hand is out of date the day after it is written.
Nobody can rebuild, audit or hand over what nobody can enumerate.
One port is one service, and the kernel is the judge
99 declared listeners, issued one at a time like a sequence and never in blocks — a block is a standing permission that gets consumed without anyone asking. Every night the registry is reconciled against what the machines are actually listening on, harvested from the kernel.
Ground truth is never the configuration: a registry checked against config only proves that config agrees with itself. Something running that nobody wrote down, and something written down that is not running, are reported as two different findings.
The box the software runs on is not a permanent decision
Nothing dials a machine. A service is reached by what it is, never by where it happens to run, so its address is a fact about the network.
Before anything moves there is a check that asks whether it can: does it answer to a name and not to a particular machine, is where it runs decided by a list it belongs to, is its state declared or must it be carried, do its certificates re-issue on the new host, does anything in it still name a machine. It refuses to call a service movable until all five pass.
A private source forge, with the gates on the way in
22 live repositories on self-hosted Gitea, with continuous integration on every push. Three things a stranger should notice: a push is refused unless every commit carries a reference to the decision that justified it, so code and reasoning cannot drift apart; the checks run on a real machine against the committed revision rather than in a container that resembles one; and a deploy is triggered by the caller's own certificate, which admits exactly the application it belongs to and refuses every other by name.
Restores that are drilled, and alerts that can be read back
- Backups proved by loading them every night — each database restored into an empty scratch instance and its rows counted, never touching production.
- 11 of 18 backup sets are proven loadable that way. The other seven are proved present, not proved restorable, and the network device exports are among them.
- Backups kept in more than one building, with a restore drilled from the second building, not only from the first.
- The estate announces into a chat channel, and a verb reads that channel back — so "did the alert actually arrive" is answerable by a machine.
- 131 things run by themselves, and 77 of them are checks. More than half of everything automatic here exists to watch the rest and speak up.
Machines are rebuilt from their declarations routinely. The full rebuild of an entire estate from nothing but backups is rehearsed per machine and has not been executed end to end. A recovery plan nobody has executed is a document, not a capability. Ours included.
Ownership, terms and continuity
Every enterprise has two parts. One is the reason it exists: the product, the mission, the thing it is going somewhere unmapped to do. That part belongs to its owner, and I make no claim to understand it. The other part is common to every enterprise, whatever its mission. People are paid, books are kept, documents are filed, machines fail and are rebuilt, and someone must know who is permitted to see what. That second part is what I build.
Much of what is sold to a business is designed to impress at the point of sale. What I build is judged later, by whether it kept the business fed. I trust it because my own businesses and my own household have run on it for years, and if it fails, I am the first to know.
I work best with an organization that is moving, whose needs a year from now will differ from today's. Such an organization needs a kitchen of its own rather than a menu from someone else's, and that is what I build: something its owner holds, and can inspect without me and run without me. When I stay on, it is because we both choose it. And when the work ends, what was built stays with its owner.
An organization that needs the same thing every day, reliably and at scale, has better options than me, and I will say so.
On terms: I earn when the client earns. I would rather hold a share in a client's outcome than a line in its costs, and that is why I work only with people who care about what is underneath.
In my own language there is a word for a partner who is whole for the household rather than skilled in one room of it: sarva-lakṣaṇa-sampannā, complete in every quality the house needs. That is the standard I hold myself to. I am engaged for the whole house, not for one room of it.
Umesh Mittal
Shared outright: Apache 2.0
The software is shared under the Apache 2.0 licence, on every repository we can license. Anyone may take it, run it, change it and sell what they build with it, and we keep no claim on it. What is offered is let go of completely. In 2011 the line was that the data belonged to the client and the database to us. Today both belong to the owner, and so does the machinery around them.
What is not done yet. The repositories are not public. Putting them where anyone can clone them is a planned project. Until then the code is shared with anyone who asks.
The licence grants patent rights explicitly. It asks that the licence and its notices travel with the software and that changed files are marked, which matters more, not less, for software an organization is meant to build on.
In practice that is unglamorous and specific. The machines are built from declarations the owner holds a copy of. The estate can list itself, so nothing depends on our memory. The limits are on this page. A supplier who has to keep something back in order to stay is a supplier whose interests stop matching the client's the day they are no longer needed.
Audit
An audit such as SOC 2 attaches to whoever operates a system. Where the owner operates the estate, that audit is the owner's, and what is on these pages is the material it asks for: what changed, who agreed it, what was measured. Where we run it for the owner, we are the operator an auditor looks at, and the same records are what we hand over.
Who is actually being hired
Today, one person working with AI models: the firm is built as a partnership and has one partner. Not a firm with departments, and nothing on these pages was built by an unseen team.
It is why the machinery is declared rather than administered. There was never anybody to remember it, so it had to be written down in a form a machine could replay.
The obvious question is what happens when that person is not there. The day-to-day carries on, because it was never built to depend on us, and nothing is held back.
- Every machine is built from a declaration, so how is in version control, not in someone's head.
- A push is refused unless the commit references the decision that justified it, so why is attached to the code.
- The estate can list itself, so what exists is a question with a live answer, not an inventory someone maintains.
- Most databases are proved every night by loading their backups. The count, and what is not yet proved, is under the machinery.
Whoever picks this up, a person, a hired team or a model, inherits a written estate. Two kinds of work are done here, and they fail differently. One is running the operation: the reconciliations, the payments, the month-end. That ends with the client's own people, on machinery the client owns, with the checks built in so that someone who did not build it can run it. Until they are ready, the builder runs it. It has been handed over that way before: a fund's NAV to the staff who inherited it, and a treasury to two recent graduates.
The folding side menu on a website is an example. Somebody worked out how it should behave and built it, and that person was not a hired hand who had done it ten times before. Afterwards the menu is maintained by people who did not build it, and when its builder leaves it does not stop folding. The loss is narrower than that: if the business still needs new things, it has to find new talent.
The other kind is changing the operation: taking ground that is not working and making it hold. That is what we are hired for, and it does rest on one person's judgment. Every organization is exposed to its best people. The exposure is managed by having the talent build the machine, so that ordinary days do not need it. What we can promise is that nothing is held hostage: everything is written down, owned by the client, and open to whoever comes next.
Nothing sits outside the client's control. Every key, every password and every record is held inside the enterprise, by people it chooses. Where we are among those people, it is under the client's rules, and what we hold is the client's to take back. Our absence exposes nothing.
We work inside the enterprise, under its identity and its rules. Where information is concerned there is no third party. The AI models are tools used from the inside, as any member of staff uses a tool, and which model may see what is the enterprise's decision.
Every business has to build a bench, and every business pays for it. The real choice is whether it builds its own or adjusts itself to a third party's. Different businesses answer differently, and both answers are sound. Beyond that one person, everything sits inside the client's own organization: the people who run it, the machinery and the continuity plan, which is built for each site against its own requirements. A client who would rather we ran the operation can have that too, and the bench is then built here, to that client's requirements. We do not arrive with a bench. We arrive with a set of tools.
We are not a counterparty to any of a client's transactions. As a partner we act inside the entity, paid a share of its profit and never by the hour. Every call only we can answer costs us, so we have every reason not to be needed.
The tasks overlap with what any contractor does, and seen task by task the two can be confused. The difference is not the list. It is three things that are really one: the whole house rather than one room of it; a share of its fortune rather than a rate per room, with extras for the rest; and standing inside its door, under its own name, rather than outside it. That one thing is what the front page calls a partner.
What that does not solve. A relationship does not transfer: nobody inherits standing with a client's bank, vendors or board.
The same recipe since 2011
The rules on these pages were not written for the machinery. They were written for a fund in 2011, on its internal website, and have since been written out again, in almost the same words, for a private-equity fund, a manufacturer, a design studio and a household. The machinery came later: it is those rules, built so that they no longer depend on who is following them. What the notes say, in the order they were written:
- The principal does only what only the principal can do. Anything the principal does not want to own is not done by the principal, because the moment it is, the arrangement breaks.
- Work belongs to a role, and a role is written down: what to do, in what order, and how to tell that it was done. Anyone can then stand in it, and nobody is the only one who knows.
- Nothing is real until it is recorded. What is known is written once: the standing facts in one place, the events in another, and nothing to ask around for.
- Discretion sits at the top. A line task has one right outcome and is done as written; an improvement goes in the suggestion box and is not tried out on the day's work.
- A break is not carried to the next day. The books, the cash and the positions are reconciled against the outside every day, and whatever does not agree is chased until it does.
- We are the control point, not the reporting agent. The administrator reports, the bookkeeper books, the bank says what it holds; each is checked, and none of them registers anything that was not first agreed.
- Staff are hired as the work appears, never ahead of it, and the first hires are the ones the day cannot run without.
- No dependency on us. Written to a client in 2017, before any of this machinery existed: a manager should perceive no risk if we disappear overnight.
People-based, role-based
Where control actually goes. A chief who will not delegate outward hires experts inward, and each expert's area then runs on what that expert alone holds: nothing moves without them, credit stays inside, and failure belongs to a vendor. That is the people-based shape on the left of the drawing, every wedge pinned to one hub. The role-based shape on the right is what the recipe produces: one line of work, and roles along it that anyone can stand in, because what each one does is on the page. It is why the front page promises control without a large staff. The staff was never the point; the layer between the principal and the work was.
What is not said here
Seven sentences heard in every operation, and what is said here instead. The list is from 2011 and has not needed a change.
- "Garbage in, garbage out." Take no garbage, and make none.
- "The world is not perfect." The reconciliation is.
- "We need an organization in place to manage the problem." We need a process that solves it.
- "We are doing the best we can." Everyone is on the same page about every transaction and its effect. There is no doing our best in this work: one does what one understands, or says so.
- "Best of breed." The job gets done, and the parts do not need a trade magazine's blessing.
- "It is about setting expectations." Stage hands are invisible in a good show.
- "This is what is expected of us, and this is what we do." We are paid to take care of a job, not of a slice of it.
How to judge anyone offering this, including us
Written for a client in 2022 who was choosing between people for this role. Can a conversation be had with them. Do they understand what is intended without it being explained twice. Can they think on their own, or do they wait for guidance. Are they a best-practices person, and does the business want a cookie cutter. Where do they voice their differences, behind a closed door or in the open. Are they a resource or a management challenge. Do they present the experts' views as their own, or their own opinion.
The advice that went with it: make the demands, and let the work be delivered. Enable the person, and resist the urge to work alongside them.
How we work, and the mistakes that taught us
The rules the work is done under — evidence before assurance, done means the consumer says so, conventions the build enforces — are on how we build, with the mistakes that wrote them.
How this starts
A conversation about what should stop needing attention, then one small thing built and running, then a decision — the owner's, with everything visible — about whether there should be a second.
We do not begin with a discovery phase, a document, or a number of seats. The first thing built is a real thing in use, because until something is running neither side knows what the second one should be.
Every enterprise has work that calls for judgment and work with one right outcome: the trade is booked, the fee collected, the bill paid. Different people do it differently, but the right result does not depend on who does it. That work is a cost centre, and it is judged by its efficiency and by how easily it changes. It starts there. One such task is built so that the result no longer depends on who does it, and then handed over. From then on the test is what the owner wants next: a new product at a fund, a new language at a school, a seafood chef at a restaurant. The answer should be yes. The bass player is noticed only when he is missing.
At the school it was registration. Families queued by last name to fill in a printed form and pay, and no record of any student survived the year. The first thing built was a way for families to enter their own details. Nobody read handwriting or reconciled payments by hand any more, and every family knew its class without reading a sheet on the wall. Email, records and the website grew from that. When classes moved online during covid, the process did not change. It has since been rebuilt with AI models, on the same fifteen years of data.
There are three ways to work with us. The ideas and the code are shared: nothing is owed, and we keep no claim on what is built with them. A defined piece of work, such as putting one of these tools in place, is done for a fee and handed over. Or we join a venture as a partner, with its owner and nobody else, and carry its machinery for a share of its profit. That share is how the work is paid for; it is never a claim on the software. We do not rent out hours and we do not sell a subscription — either would defeat the purpose. Which of the three, and what it costs, is settled in conversation — there is no price list, because there is no product.
Each part of this page was read and corrected by the AI agent that did that work, first on 11 September 2026 and again as the page changed.