Trust
Trust should not require unnecessary trust.
Trust is not a page in a policy document. It is a property of how the system is built — what it can access, what it may use, what it remembers, and what a person can take with them when they go.
Steward remembers. Intelligence interprets. The person decides.
01
The minimum necessary
For a given task, Steward assembles a small, relevant, task-specific context package — never the whole life. Only the context needed for the authorized task is used, and narrow disclosure is the default rather than a setting.
- Minimum necessary access
- Least privilege
- Narrow disclosure
02
Permission follows purpose
Access is granted for a purpose, and it ends when that purpose does. Access to information in one place does not create permission to use it everywhere, and holding information is not the same as being permitted to use it.
- Purpose-bound permission
- Possession is not permission
03
Know where an answer came from
Facts, source records, summaries, inferences and AI interpretations remain distinguishable. Provenance survives synthesis: when things are understood together, where each piece came from is never lost.
- Provenance
- Evidence you can inspect
04
Access should leave footprints
Every meaningful use is observable and every grant is revocable. A person should be able to see what was accessed, by whom, for what purpose — and stop it without negotiation.
- Observable access
- Revocable access
05
Your continuity remains yours
Continuity that cannot be taken with you is not yours. Portability and model independence are design requirements, so that continuity never becomes captivity and leaving never means starting over.
- Portability
- Model independence
- Context without captivity
06
Memory should be purposeful
Memory is selective. Connection does not automatically mean collection, and access does not automatically mean permanent memory. What is kept is kept because it carries meaning forward.
- Selective memory
- Connection is not collection
- Access is not memory
Minimum necessary
Reachable is not the same as used.
A permitted task draws on a small, purpose-bound subset of what Steward could reach. The rest stays where it is.
What Steward could reach
- Sleep
- Medications
- Income
- Travel
- Messages
- Lab results
- Calendar
- Weight
- Insurance
- Documents
- Purchases
- Contacts
Access to information in one place does not create permission to use it everywhere. Possession is not permission.
What the task receives
- Sleep
- Calendar
- Lab results
Minimum necessary, for one purpose, for as long as that purpose lasts.
Provenance
An answer should carry its own sources.
When Steward assembles context, each layer stays distinguishable. A person can follow an answer back to the record it came from, and see where recording ends and interpretation begins.
Source record
The original entry, exactly as the system that produced it recorded it.
Fact
A stable, checkable detail drawn from that record.
Summary
A condensed view, always traceable back to what it condensed.
Inference
A pattern across records, labelled as a pattern — not as fact.
AI interpretation
A model's reading of the assembled context, marked as interpretation.
Permission as relationship
Each relationship receives only what its purpose requires.
Permission is easier to reason about as a relationship than as a settings screen. The same life, seen differently by each party the person allows in.
Physician
Clinical history relevant to the visit
Financial advisor
Financial position and stated goals
Family member
What the person chose to share, and nothing beyond it
Employer sponsor
That the benefit is used. Not what it contains.
AI provider
The task-specific context package. Never the archive.
Complexity belongs in the system.
Control belongs with the person.
