{
  "abstract": "A deterministic, privacy-preserving guide for classifying accessible context, selecting among local and remote inference architectures, bounding coding agents, reviewing re-identification risk, approving exact processing paths, and preserving evidence without copying the sensitive corpus.",
  "author": {
    "email": "tony@malott.ai",
    "email_url": "mailto:tony@malott.ai",
    "id": "person:tony-malott",
    "name": "Tony Malott",
    "resume_url": "https://malott.ai/resume/",
    "url": "https://malott.ai/"
  },
  "authority": {
    "creative_state": "CREATIVE_LOCKED",
    "governing_issue": 214,
    "implementation_state": "IMPLEMENTATION_AUTHORIZED",
    "owner_uat": "REQUIRED",
    "production_authority": "NOT_AUTHORIZED",
    "publication_boundary": "PROTECTED_DEVELOPMENT_ONLY",
    "semantic_state": "SEMANTICS_COMPLETE"
  },
  "card": {
    "kicker": "AI architecture · Privacy engineering",
    "orientation": "Use frontier intelligence without surrendering frontier custody.",
    "visual_motif": "custody-boundary"
  },
  "claims": [
    {
      "id": "claim:214:custody",
      "posture": "owner-locked-primary-doctrine",
      "support": [
        "source:shareplane-platform-issue-214"
      ],
      "text": "Keep authoritative source custody under organizational control. Export only the minimum reasoning surface required for the approved task."
    },
    {
      "id": "claim:214:frontier",
      "posture": "owner-locked-primary-distinction",
      "support": [
        "source:shareplane-platform-issue-214"
      ],
      "text": "Use frontier intelligence without surrendering frontier custody."
    },
    {
      "id": "claim:214:agent-boundary",
      "posture": "owner-locked-control-statement",
      "support": [
        "source:shareplane-platform-issue-214"
      ],
      "text": "A local coding agent becomes a privacy-preserving architecture only when source access, outbound context, network behavior, persistence, and authority are all bounded and provable."
    },
    {
      "id": "claim:214:path-approval",
      "posture": "owner-locked-governance-statement",
      "support": [
        "source:shareplane-platform-issue-214"
      ],
      "text": "A provider is not approved in the abstract. A specific processing path is approved for a specific purpose, data class, architecture, configuration, and period."
    },
    {
      "id": "claim:214:control",
      "posture": "owner-locked-final-control-statement",
      "support": [
        "source:shareplane-platform-issue-214"
      ],
      "text": "Privacy is not achieved by refusing to reason. It is achieved by controlling what the reasoning system receives, where it operates, what it retains, what it can infer, what it can change, and what evidence remains."
    }
  ],
  "collections": [
    {
      "id": "collection:governed-ai-operations",
      "position": 8,
      "title": "Governed AI operations"
    }
  ],
  "current_standing": "Semantic, creative, architecture, classification, decision-logic, privacy, toolkit, and Development publication authority locked by Issue #214. Owner UAT is required at the exact protected Development head.",
  "dates": {
    "created": "2026-07-29",
    "updated": "2026-07-29"
  },
  "featured": false,
  "format": {
    "depth": "Architecture guide, deterministic decision aid, operating model, and offline controls toolkit",
    "interaction": "Client-side deterministic assessment with no answer storage or transmission",
    "label": "Guide and Toolkit",
    "reading_time": "28 min"
  },
  "id": "artifact:frontier-inference-without-frontier-custody",
  "lifecycle": {
    "merge_authority": "not-granted",
    "owner_review": "required-at-exact-head-protected-development-preview",
    "production_authority": "not-granted",
    "state": "PUBLISHED"
  },
  "presentation": {
    "motif": "custody-boundary",
    "visual_blocks": [
      {
        "accessible_label": "Six architecture outcomes identify what remains local, what may cross the boundary, and when work must stop.",
        "section_id": "approved-architecture-model",
        "type": "responsive-ledger"
      },
      {
        "accessible_label": "Five information classes run from public through prohibited, with highest-class, mixed-classification, unknown, and output rules.",
        "section_id": "classification-model",
        "type": "responsive-ledger"
      },
      {
        "accessible_label": "Nine deterministic questions resolve to one of six ordered architecture outcomes.",
        "section_id": "deterministic-decision-guide",
        "type": "decision-matrix"
      },
      {
        "accessible_label": "Twelve ordered operating steps move from task definition through classification, minimization, inference, local reconstruction, and closeout.",
        "section_id": "twelve-step-operating-model",
        "type": "sequence"
      },
      {
        "accessible_label": "A coding-agent control profile bounds execution, inference, source access, outbound context, networks, persistence, authority, monitoring, and evidence.",
        "section_id": "local-coding-agent-control-profile",
        "type": "responsive-ledger"
      },
      {
        "accessible_label": "Twelve synthetic worked examples apply the classification and architecture rules without exposing real organizational information.",
        "section_id": "worked-examples",
        "type": "responsive-ledger"
      }
    ]
  },
  "presentation_status": "candidate",
  "provenance": {
    "ai_assistance": {
      "role": "Exact authority serialization, Platform-native implementation, deterministic toolkit generation, validation, and protected Development UAT.",
      "used": true
    },
    "boundary": "Public-safe doctrine, synthetic examples, empty templates, schemas, and validation evidence only. No real organization, project, source corpus, credential, provider approval, regulated record, assessment answer, private locator, or hidden operational evidence is included.",
    "posture": "Tony-authored, issue-first semantic and implementation authority serialized without reopening the locked doctrine, architecture, classification, decision precedence, privacy boundary, toolkit inventory, or Production boundary.",
    "sources": [
      {
        "description": "The complete issue-first authority. Implementation does not reopen or reinterpret its semantic model.",
        "id": "source:shareplane-platform-issue-214",
        "locator": "https://github.com/pinklon/shareplane-platform/issues/214",
        "publiclyExposed": true,
        "role": "Governs the doctrine, architecture, classification, decision precedence, privacy boundary, operating model, controls, toolkit, validation, and Development-only stop.",
        "title": "Publish Frontier Inference Without Frontier Custody as a SharePlane Guide and Toolkit",
        "type": "owner-locked-semantic-and-implementation-authority"
      },
      {
        "description": "NIST framework context for governing, mapping, measuring, and managing AI risk.",
        "id": "source:nist-ai-rmf-1",
        "locator": "https://www.nist.gov/itl/ai-risk-management-framework",
        "publiclyExposed": true,
        "role": "Public lifecycle risk-management context; it does not authorize a provider, endpoint, workload, or SharePlane decision.",
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)",
        "type": "public-standard"
      },
      {
        "description": "Framework context only; the Issue #214 classification and branching model remain owner authority.",
        "id": "source:nist-privacy-framework",
        "locator": "https://www.nist.gov/privacy-framework",
        "publiclyExposed": true,
        "role": "Public privacy-risk context for identifying and controlling data processing.",
        "title": "NIST Privacy Framework",
        "type": "public-standard"
      },
      {
        "description": "Supports the general minimization posture without certifying this artifact or any processing path.",
        "id": "source:nist-data-minimization",
        "locator": "https://www.nist.gov/itl/applied-cybersecurity/privacy-engineering",
        "publiclyExposed": true,
        "role": "Public privacy-engineering context for data processing and system design.",
        "title": "NIST Privacy Engineering Program",
        "type": "public-guidance"
      }
    ]
  },
  "public": true,
  "public_safe_status": "accepted",
  "relationships": [
    {
      "label": "Authored by Tony Malott",
      "target_id": "person:tony-malott",
      "type": "authored_by"
    },
    {
      "label": "Semantic, creative, implementation, and Development authority: Issue #214",
      "target_id": "issue:shareplane-platform:214",
      "type": "governed_by"
    },
    {
      "label": "Defines controlled frontier inference",
      "target_id": "principle:frontier-custody",
      "type": "related_to"
    },
    {
      "label": "Defines minimum reasoning packages",
      "target_id": "principle:minimum-reasoning-surface",
      "type": "related_to"
    },
    {
      "explanation": "Continue from information custody into the mechanical controls that keep an agent-bounded system safe when the agent is wrong.",
      "label": "Companion: The Agent Is Not the Security Boundary",
      "reader_group": "foundations",
      "target_id": "artifact:the-agent-is-not-the-security-boundary",
      "type": "companion"
    },
    {
      "explanation": "Connect the local-agent control profile to the broader control-plane architecture around authority, evidence, recovery, and valid action.",
      "label": "Companion: The Agent Is Not the Product",
      "reader_group": "applications",
      "target_id": "artifact:the-agent-is-not-the-product-the-control-plane-is",
      "type": "companion"
    },
    {
      "explanation": "See how custody, authority, provenance, freshness, and next-valid-action semantics fit into a durable cross-system operating model.",
      "label": "Companion: The Semantic Operating System",
      "reader_group": "companions",
      "target_id": "artifact:the-semantic-operating-system",
      "type": "companion"
    }
  ],
  "schema_version": "2.0.0",
  "semantic_entities": [
    {
      "id": "person:tony-malott",
      "label": "Tony Malott",
      "type": "Person"
    },
    {
      "id": "issue:shareplane-platform:214",
      "label": "Issue #214 authority",
      "type": "Issue"
    },
    {
      "id": "principle:frontier-custody",
      "label": "Frontier inference without frontier custody",
      "type": "Principle"
    },
    {
      "id": "principle:minimum-reasoning-surface",
      "label": "Minimum reasoning surface",
      "type": "Principle"
    }
  ],
  "semantic_status": "locked",
  "slug": "frontier-inference-without-frontier-custody",
  "source": {
    "content_status": "canonical-full",
    "format": "markdown",
    "path": "content/artifacts/frontier-inference-without-frontier-custody/source.md",
    "public_projection_name": "frontier-inference-without-frontier-custody.md"
  },
  "subtitle": "A practical architecture guide and offline toolkit for using frontier reasoning while keeping authoritative source custody under organizational control.",
  "thesis": "Keep authoritative source custody under organizational control. Export only the minimum reasoning surface required for the approved task.",
  "title": "Frontier Inference Without Frontier Custody",
  "topics": [
    "ai-architecture",
    "privacy-engineering",
    "data-governance",
    "coding-agents"
  ],
  "type": "guide-and-toolkit"
}
