Acme Org/How it works
L3 · Restricted

DESIGN & DATA BOUNDARIES

How Receipt works

From a visible participant in your email to an evidence-backed project memory.

Collect

Imported Acme records and new messages addressed to the project agent.

Connect

Sources, decisions, commitments and people retain dated evidence links.

Prepare

Personal briefings, supported answers and useful email contributions.

Submission documents

Read the one-page design, independently reviewed practice answers, actual model evaluations and validation results.

Open submission documents

Access before inference

Project membership and clearance determine available evidence before it reaches the model. L1 contains customer-shareable sources, L2 adds internal material, and L3 adds restricted context.

Customer cards and email replies use a fresh context for their intended audience. Personal conversations and preferences belong to the selected employee.

Every answer has a receipt

Claims connect to original passages with authors, dates and message or utterance positions. The source viewer shows the current application-owned record.

The archive can contain conflicting accounts, corrections and unavailable attachments. Answers must preserve those distinctions.

What the demonstration simulates

The email screen represents an employee's Outlook. Sending runs actual ingestion and model participation in the local application. Demo identities represent the production SSO boundary. Calendar entries and new example emails are labelled additions.

The initial Acme archive is imported historical material. Archive coverage and generation times are shown separately.

Erasure and retained boundaries

Person erasure cleans runtime source copies, withdraws unsupported derived information and invalidates affected generated artifacts. A receipt records the operation without repeating deleted personal content.

The supplied reference fixtures and previously downloaded exports remain outside the runtime erasure operation. Reopening this workspace preserves its erasure state.

Inference in Helsinki

GLM 5.3 Flash runs through the configured endpoint in a Helsinki datacentre. The application stores its working memory in SQLite and runs on the host.

Generated answers and citations are validated before publication. Model requests use bounded execution and failures remain visible for retry.

A prepared personal workspace

The morning brief combines permitted project evidence, your role, followed topics and upcoming simulated meetings. Prepared briefs are saved between visits, with their generation time.

You can inspect and change remembered goals, refresh a brief and explicitly share a private note with the project.

Receipt · Acme project memoryArchive through 2026-07-02 · Workspace a47a4ba4