Trust

Trust should not require unnecessary trust.

Trust is not a page in a policy document. It is a property of how the system is built — what it can access, what it may use, what it remembers, and what a person can take with them when they go.

Steward remembers. Intelligence interprets. The person decides.

01

The minimum necessary

For a given task, Steward assembles a small, relevant, task-specific context package — never the whole life. Only the context needed for the authorized task is used, and narrow disclosure is the default rather than a setting.

  • Minimum necessary access
  • Least privilege
  • Narrow disclosure

02

Permission follows purpose

Access is granted for a purpose, and it ends when that purpose does. Access to information in one place does not create permission to use it everywhere, and holding information is not the same as being permitted to use it.

  • Purpose-bound permission
  • Possession is not permission

03

Know where an answer came from

Facts, source records, summaries, inferences and AI interpretations remain distinguishable. Provenance survives synthesis: when things are understood together, where each piece came from is never lost.

  • Provenance
  • Evidence you can inspect

04

Access should leave footprints

Every meaningful use is observable and every grant is revocable. A person should be able to see what was accessed, by whom, for what purpose — and stop it without negotiation.

  • Observable access
  • Revocable access

05

Your continuity remains yours

Continuity that cannot be taken with you is not yours. Portability and model independence are design requirements, so that continuity never becomes captivity and leaving never means starting over.

  • Portability
  • Model independence
  • Context without captivity

06

Memory should be purposeful

Memory is selective. Connection does not automatically mean collection, and access does not automatically mean permanent memory. What is kept is kept because it carries meaning forward.

  • Selective memory
  • Connection is not collection
  • Access is not memory

Minimum necessary

Reachable is not the same as used.

A permitted task draws on a small, purpose-bound subset of what Steward could reach. The rest stays where it is.

What Steward could reach

  • Sleep
  • Medications
  • Income
  • Travel
  • Messages
  • Lab results
  • Calendar
  • Weight
  • Insurance
  • Documents
  • Purchases
  • Contacts

Access to information in one place does not create permission to use it everywhere. Possession is not permission.

What the task receives

Permission gate
  • Sleep
  • Calendar
  • Lab results

Minimum necessary, for one purpose, for as long as that purpose lasts.

Provenance

An answer should carry its own sources.

When Steward assembles context, each layer stays distinguishable. A person can follow an answer back to the record it came from, and see where recording ends and interpretation begins.

Source record

The original entry, exactly as the system that produced it recorded it.

Fact

A stable, checkable detail drawn from that record.

Summary

A condensed view, always traceable back to what it condensed.

Inference

A pattern across records, labelled as a pattern — not as fact.

AI interpretation

A model's reading of the assembled context, marked as interpretation.

Permission as relationship

Each relationship receives only what its purpose requires.

Permission is easier to reason about as a relationship than as a settings screen. The same life, seen differently by each party the person allows in.

Physician

Clinical history relevant to the visit

Financial advisor

Financial position and stated goals

Family member

What the person chose to share, and nothing beyond it

Employer sponsor

That the benefit is used. Not what it contains.

AI provider

The task-specific context package. Never the archive.

Complexity belongs in the system.
Control belongs with the person.

Next

One life. Many domains. One continuity.