Constellations
A map of services and their relationships. Select a star, explore its status and switch to a text view.
Explore constellationsBuilt at Atlastrum A project in progress
AI with a place to work.
A person in control.
A local-first AI operating environment that brings reasoning, tools and human oversight into one coherent workspace. Lumen is the assistant identity. Lumenport is its cockpit: the browser interface for seeing work, directing it and reviewing what comes back.
01 Principles
“AI suggests, never acts on its own.”
That is the governing principle. Deterministic code handles operations that can be specified and checked. AI supplies interpretation, planning and oversight; it does not grant itself permission to act. Human approval belongs at the boundaries, where a proposal becomes a consequential action.
Privacy shapes the architecture. For testing, I set up your application in a secure, isolated test environment (mine, or inside yours). Your code and data stay inside that environment, analysed by locally run AI; nothing is shared with third-party AI services. Voice remains a planned integration, with the same principle of locally run AI. Local-first means keeping private work within its intended boundary and making any separately selected external route explicit.
The same discipline applies to collaboration. A request needs a scope, an owner and an expected return. Receiving a task, doing the work and accepting the result are distinct events. A dashboard should make those distinctions visible.
02 Architecture
The architecture brings together a desktop control station and a dedicated local AI host running a large open-weight model. Several AI collaborators work through a structured exchange of requests, status updates and results, with responsibility kept visible.
Lumenport in the browser: conversation, tools, work status and human decisions.
Task classification, trust boundaries, effort settings and checks on returned output.
Open-weight reasoning, with requests shaped by the task and the sensitivity of its input.
Bounded assignments and inspectable returns across collaborating assistants.
Build status: Lumenport runs as a local web application, and the dedicated host has been tested with real models. Connecting the shared policy client into the gateway and job runner is still pending. This is the system’s architecture, with integration work clearly separated from working components.
03 Safety evidence
Correct summary.
Hidden instruction ignored.
A live test on 4 October 2026 supplied a document containing a hidden prompt-injection instruction. The model summarised the document correctly, ignored the injection and returned valid JSON. The test used the policy client’s untrusted-input handling with medium reasoning effort.
This followed a stack review that found an important failure mechanism: lower-effort reasoning could obey instructions planted inside a document, including forged authority. Faster answers were not enough; the input’s trust level had to change how the request was handled.
The policy client uses code rules to choose effort per task. Explicitly trusted simple and reasoning tasks can use low effort; untrusted, sensitive and unrecognised tasks default to medium. Outside text is wrapped as document data, with instructions to treat it as material to analyse.
Requests ask for structured JSON outputs. Output checks look for signs that planted instructions influenced the answer; suspicious results must be held for review. The policy client never executes actions, and a clean result is not an approval.
What the result establishes: the documented live test passed. Pattern checks can miss attacks or flag harmless text, and structured output does not prove correctness. The result is evidence for that tested case, not a claim of universal injection resistance or completed end-to-end integration.
04 Design language
StarGlass gives the system a visual grammar: midnight surfaces, brass geometry, starlight text and an ivory light theme. Constellations show relationships; marks carry the state of work; an inspector brings the detail forward when it matters.
The Lumen face is a lens built from the same hexagonal aperture. States such as muted, listening and thinking have visible words and distinct geometry. Movement should mean something: a recorded change, a transition or a deliberate replay. A still frame must remain understandable.
That is the testing philosophy made tangible: fix mechanisms, not symptoms. If an answer fails, examine input trust, routing, output constraints and approval handling. If an interface misleads, fix how it represents evidence. The goal is a system whose behaviour can be explained, inspected and improved.
05 Explore the interface
These self-contained demos use fictional data. Open either one to explore the interface in your browser; no account, setup or connection to a running AI system is needed.
A map of services and their relationships. Select a star, explore its status and switch to a text view.
Explore constellationsThe lens, a constellation of collaborators and work moving through review. Explore the prototype with a fictional exchange.
Meet the Lumen face