Skip to content
Hussh
Connect MCP

The Hussh Mega Map

One picture of the whole Hussh platform: seven layers (what it is) and ten end-to-end user-story flows (how it connects), with the consent model, encrypted personal memory, agents, and channels in a single view.

About Wiki

TL;DR: The Hussh Mega Map is one diagram that shows the entire platform at a glance: a seven-layer stack of what each part is and why, plus ten end-to-end user journeys that each read as a single left-to-right sequence. Every story is its own lane, so the connections are fully traceable and never tangle.

Status as of 2026-06-10: see body.

Hussh The Whole Map . Human Secure Socket Host — Consent-Driven Personal Intelligence. Your data. Your agents. Yours to own. Read down: ① decode the words · ② the platform (what it is) · ③ end-to-end flows (how every story connects). [LIGHT MODE] AS OF June 11, 2026 SHIPPED — live APPROVED — direction FUTURE — planned shape = status (colorblind-safe): ● shipped ◆ approved ○ future ① KEY — every acronym in plain English (decode FIRST, then read the map) Hussh Human Secure Socket Host PKM Personal Knowledge Model — your encrypted memory PCHP Personal Consent Handshake Protocol (6-phase) BYOK Bring Your Own Key — only you hold it ZK Zero-Knowledge — server sees ciphertext only VAULT_OWNER master consent token (24h) CRT / DAT consent receipt + data-access token HCT Hussh Consent Token format MCP Model Context Protocol — the AI tool bridge agent dev kit Agent Development Kit (the cloud provider) A2A Agent-to-Agent delegation protocol on-device ML on-device ML agent runtime on-device agent runtime AlphaAgents Kai's 3-agent investment debate DecisionCard Buy / Hold / Reduce verdict One·Kai·Nav orchestrator · finance · privacy RIA Registered Investment Adviser OSINT open-web intelligence X25519-AES-GCM scoped-export encryption push messaging push messaging Tri-flow web / native / MCP parity ② THE PLATFORM — what it is. Seven layers; each card shows the name, its generic role (tag), then what · why · how · e.g. Read top → down. EXPERIENCE · INTERACTION — where a person or an AI meets Hussh — web, native, on-device, external hosts Web · web framework 1 web app browser app on shared React shell WHY reach anyone, zero install HOW web-proxy transport → /api e.g. app.hushh.ai iOS / Android · native shell 8 native mobile app native shell, secure enclave WHY device biometric + push HOW native-plugin transport e.g. biometric unlock On-device compute 9 on-device compute unified-memory local machine WHY private local compute, dev power HOW runs agent runtime · on-device ML e.g. "set up my cloud" External AI hosts 7 external AI host 3rd-party AI clients WHY meet users where they work HOW MCP consent tools e.g. AI host reads scoped data the surfaces reach people through governed channels … CHANNELS · ECOSYSTEM — governed ways results & capabilities reach users, devs, partners Developer API · /api/v1 7 5 REST API REST consent surface WHY integrate from any stack HOW discover→consent→export e.g. curl the flow Hosted MCP server 7 5 tool-call bridge managed MCP server WHY plug AI tools in instantly HOW 6 consent tools e.g. an AI host asks for data A2A 5 agent-to-agent transport Agent2Agent protocol WHY agents call agents safely HOW A2A over scoped consent e.g. One → partner agent Marketplace 10 exchange RIA ↔ investor exchange WHY share strategies safely HOW relationship-share grant e.g. adviser shares picks Certification 5 trust tiers agent trust tiers WHY users trust what they install HOW Sandbox→Verified→Trusted e.g. "verified" badge channels distribute the same governed truth to the agents that … INTELLIGENCE · AGENTS — reason, debate, delegate & act inside scoped authority — never raw keys Agent runtime 9 1 agent runtime the runtime One runs on WHY one runtime, many surfaces HOW streaming loop + tools + MCP e.g. powers One / Kai / Nav Agent ONE 1 orchestrator agent the top personal agent WHY one mind that coordinates HOW Listen·Remember·Decide·Act e.g. routes to specialists Nav 12 7 guardian agent privacy / consent guardian WHY enforce scope, reserve, deletion HOW validates every request + bid e.g. blocks over-broad asks Kai · finance runtime 4 finance specialist shipped finance agent WHY real investing help HOW agent runtime + tools e.g. analyze one stock AlphaAgents → broker 4 execution engine debate → DecisionCard → trade WHY reasoned calls, not hype HOW 3-agent debate + systematic e.g. Buy/Hold/Reduce Hussh SDK 5 agent dev kit build-your-own agent WHY everyone extends Hussh HOW know · do · remember + MCP e.g. ship a custom agent act on scoped memory provided by … DATA · KNOWLEDGE · PKM — the heart: one encrypted store the user truly owns (zero-knowledge) pkm_blobs 1 encrypted store encrypted domain data WHY this IS the memory HOW ciphertext·iv·tag per domain e.g. server can't read it manifests + scope registry 1 metadata index structure & visibility WHY know what exists & who sees HOW revisions + posture e.g. field-level scopes 24-domain schema 2 1 data ontology life in 6 families WHY shared meaning for agents HOW Being·Knowing·Relating·Having·Wanting·Acting e.g. finance·health·brands pkm_index 1 discovery view safe discovery projection WHY find without exposing HOW projection, no plaintext e.g. "has finance: yes" market & provider caches 6 3 derived cache freshness-aware derived data WHY fast, degraded-state aware HOW accounts · email · market state e.g. portfolio refresh the encrypted PKM, whose every read/write is gated by … TRUST · IDENTITY · CONSENT · PCHP — every action proves identity & earns consent first — the gate Identity provider 8 1 identity provider bootstrap who is acting WHY anchor the actor HOW ID token (1h) e.g. Sign in — identity provider Vault Unlock · BYOK 7 1 key custody biometric key unlock WHY only you hold the key HOW PBKDF2 100k, key in memory e.g. device biometric Capability Tokens 7 access tokens scoped, least-privilege WHY limit blast radius HOW VAULT_OWNER 24h · scoped 7d e.g. HCT:… signed PCHP 7 consent protocol 6-phase consent handshake WHY revocable, purpose-bound HOW Discover→Hello→Offer→Consent→Deliver→Ack e.g. brand asks "receipts" ZK Scoped Export + audit 7 encrypted release encrypted field release WHY server never sees plaintext HOW AES-GCM + X25519 wrap; CRT/DAT e.g. share only "food prefs" the trust & consent layer, enforced through … CORE PLATFORM SERVICES — the backend that enforces policy & brings chosen data in Consent Protocol routes 7 policy API FastAPI policy surface WHY clients can't improvise HOW consent·PKM·IAM·Kai·RIA e.g. /api/* contracts AI-Memory Import 2 import connector import past AI chats WHY bootstrap PKM fast HOW OAuth → parse → domains e.g. an AI provider export Email connector 5 3 email connector receipts & brand signals WHY understand real spending HOW scoped read (receipts) e.g. 1yr receipts → brands Accounts connector 6 3 accounts aggregator financial-accounts link WHY advise on real holdings HOW read-only account link e.g. balances → portfolio RIA Intelligence API 10 3 OSINT engine public-profile dossier engine WHY claim who you are online HOW verify→dossier→image rank e.g. verify adviser core platform services, all running on the infrastructure foundation. INFRASTRUCTURE — the governed foundation everything above runs on Cloud compute + LLM cloud compute + LLM serverless compute + model WHY scales · governed deploys HOW UAT → prod parity e.g. hosts API + MCP Database database relational data plane WHY durable workflow state HOW consent·audit·metadata e.g. ciphertext rows Secret store secret store secret store WHY no keys in code HOW runtime refs · BYOK refs e.g. model API keys Auth + push auth + push auth + push messaging WHY identity & notifications HOW tokens + messaging e.g. consent push prompt CI/CD delivery pipeline delivery pipeline WHY safe, repeatable ships HOW parity gates UAT→prod e.g. blocked on red test ③ END-TO-END FLOWS — how it connects. Each story is ONE left → right sequence of real steps. Lanes never cross. Experience Channels Commerce/Pay Agents Memory Trust Services External 1 Build PKM SHIPPED EXP Sign in — identity provider TRUST Mint VAULT_OWNER · 24h TRUST Unlock vault · BYOK biometric MEM Client encrypts domain INGEST POST /api/pkm/store-domain MEM pkm_blobs ciphertext + index 2 Import an AI provider / an AI host FUTURE EXT OAuth the AI provider INGEST Download memory export INGEST Parse → map to 24 domains MEM Client encrypts MEM store-domain → mind·prefs 3 Claim public profile APPROVED INGEST Seed: name·email·phone INGEST Stage 1 · verify (regulators) INGEST Phase 2 · dossier (web OSINT) INGEST Image discover + rank EXP User selectively claims MEM store-domain 4 AlphaAgents → trade APPROVED EXP Ask Kai · /api/kai/analyze AGENT 3-agent debate · Fund·Sent·Val AGENT systematic overlay tiers AGENT DecisionCard · Buy/Hold/Reduce MEM store decision · financial PAY (future) broker order 5 Build Hussh agents APPROVED CHAN SDK · know·do·remember CHAN Register + certify (tiers) CHAN Publish to marketplace AGENT Runs under One / Nav contract CHAN Requests data via /api/v1 6 CRM via CRM + iPaaS FUTURE EXT Enterprise CRM request TRUST Consent · narrow fields only PAY iPaaS proxy EXT CRM updated — never a PKM mirror TRUST consent receipt logged 7 Consent via MCP · PCHP SHIPPED EXT RS Discovery · .well-known/hussh EXT Hello — UA capabilities EXT Offer — scopes · purpose · TTL TRUST Consent · biometric → CRT TRUST ZK export · AES-GCM + X25519 TRUST Ack → audit / transparency log 8 Native + Web parity SHIPPED EXP User triggers an action EXP Generated action plane EXP web proxy / native native shell INGEST Consent Protocol API EXP same truth, any surface 9 On-device edge FUTURE EXP On-device · agent runtime EXP on-device memory / on-device GPU AGENT on-device ML on-device inference AGENT Dev tools · cloud·source·CLI·MCP TRUST Acts under same consent 10 RIA shares strategies APPROVED AGENT Advisor builds picks CHAN Marketplace · relationship grant CHAN ria_active_picks_feed_v1 EXP Chosen investor contacts EXP Investor market home Greenfield (future): AI-memory import · public-profile→PKM · broker execution · partner-system sync · on-device edge. Grounded in the canonical Hussh platform docs, the SDK protocol spec, and the research engine. Status is honest, not aspirational.
Light mode
Hussh The Whole Map . Human Secure Socket Host — Consent-Driven Personal Intelligence. Your data. Your agents. Yours to own. Read down: ① decode the words · ② the platform (what it is) · ③ end-to-end flows (how every story connects). [DARK MODE] AS OF June 11, 2026 SHIPPED — live APPROVED — direction FUTURE — planned shape = status (colorblind-safe): ● shipped ◆ approved ○ future ① KEY — every acronym in plain English (decode FIRST, then read the map) Hussh Human Secure Socket Host PKM Personal Knowledge Model — your encrypted memory PCHP Personal Consent Handshake Protocol (6-phase) BYOK Bring Your Own Key — only you hold it ZK Zero-Knowledge — server sees ciphertext only VAULT_OWNER master consent token (24h) CRT / DAT consent receipt + data-access token HCT Hussh Consent Token format MCP Model Context Protocol — the AI tool bridge agent dev kit Agent Development Kit (the cloud provider) A2A Agent-to-Agent delegation protocol on-device ML on-device ML agent runtime on-device agent runtime AlphaAgents Kai's 3-agent investment debate DecisionCard Buy / Hold / Reduce verdict One·Kai·Nav orchestrator · finance · privacy RIA Registered Investment Adviser OSINT open-web intelligence X25519-AES-GCM scoped-export encryption push messaging push messaging Tri-flow web / native / MCP parity ② THE PLATFORM — what it is. Seven layers; each card shows the name, its generic role (tag), then what · why · how · e.g. Read top → down. EXPERIENCE · INTERACTION — where a person or an AI meets Hussh — web, native, on-device, external hosts Web · web framework 1 web app browser app on shared React shell WHY reach anyone, zero install HOW web-proxy transport → /api e.g. app.hushh.ai iOS / Android · native shell 8 native mobile app native shell, secure enclave WHY device biometric + push HOW native-plugin transport e.g. biometric unlock On-device compute 9 on-device compute unified-memory local machine WHY private local compute, dev power HOW runs agent runtime · on-device ML e.g. "set up my cloud" External AI hosts 7 external AI host 3rd-party AI clients WHY meet users where they work HOW MCP consent tools e.g. AI host reads scoped data the surfaces reach people through governed channels … CHANNELS · ECOSYSTEM — governed ways results & capabilities reach users, devs, partners Developer API · /api/v1 7 5 REST API REST consent surface WHY integrate from any stack HOW discover→consent→export e.g. curl the flow Hosted MCP server 7 5 tool-call bridge managed MCP server WHY plug AI tools in instantly HOW 6 consent tools e.g. an AI host asks for data A2A 5 agent-to-agent transport Agent2Agent protocol WHY agents call agents safely HOW A2A over scoped consent e.g. One → partner agent Marketplace 10 exchange RIA ↔ investor exchange WHY share strategies safely HOW relationship-share grant e.g. adviser shares picks Certification 5 trust tiers agent trust tiers WHY users trust what they install HOW Sandbox→Verified→Trusted e.g. "verified" badge channels distribute the same governed truth to the agents that … INTELLIGENCE · AGENTS — reason, debate, delegate & act inside scoped authority — never raw keys Agent runtime 9 1 agent runtime the runtime One runs on WHY one runtime, many surfaces HOW streaming loop + tools + MCP e.g. powers One / Kai / Nav Agent ONE 1 orchestrator agent the top personal agent WHY one mind that coordinates HOW Listen·Remember·Decide·Act e.g. routes to specialists Nav 12 7 guardian agent privacy / consent guardian WHY enforce scope, reserve, deletion HOW validates every request + bid e.g. blocks over-broad asks Kai · finance runtime 4 finance specialist shipped finance agent WHY real investing help HOW agent runtime + tools e.g. analyze one stock AlphaAgents → broker 4 execution engine debate → DecisionCard → trade WHY reasoned calls, not hype HOW 3-agent debate + systematic e.g. Buy/Hold/Reduce Hussh SDK 5 agent dev kit build-your-own agent WHY everyone extends Hussh HOW know · do · remember + MCP e.g. ship a custom agent act on scoped memory provided by … DATA · KNOWLEDGE · PKM — the heart: one encrypted store the user truly owns (zero-knowledge) pkm_blobs 1 encrypted store encrypted domain data WHY this IS the memory HOW ciphertext·iv·tag per domain e.g. server can't read it manifests + scope registry 1 metadata index structure & visibility WHY know what exists & who sees HOW revisions + posture e.g. field-level scopes 24-domain schema 2 1 data ontology life in 6 families WHY shared meaning for agents HOW Being·Knowing·Relating·Having·Wanting·Acting e.g. finance·health·brands pkm_index 1 discovery view safe discovery projection WHY find without exposing HOW projection, no plaintext e.g. "has finance: yes" market & provider caches 6 3 derived cache freshness-aware derived data WHY fast, degraded-state aware HOW accounts · email · market state e.g. portfolio refresh the encrypted PKM, whose every read/write is gated by … TRUST · IDENTITY · CONSENT · PCHP — every action proves identity & earns consent first — the gate Identity provider 8 1 identity provider bootstrap who is acting WHY anchor the actor HOW ID token (1h) e.g. Sign in — identity provider Vault Unlock · BYOK 7 1 key custody biometric key unlock WHY only you hold the key HOW PBKDF2 100k, key in memory e.g. device biometric Capability Tokens 7 access tokens scoped, least-privilege WHY limit blast radius HOW VAULT_OWNER 24h · scoped 7d e.g. HCT:… signed PCHP 7 consent protocol 6-phase consent handshake WHY revocable, purpose-bound HOW Discover→Hello→Offer→Consent→Deliver→Ack e.g. brand asks "receipts" ZK Scoped Export + audit 7 encrypted release encrypted field release WHY server never sees plaintext HOW AES-GCM + X25519 wrap; CRT/DAT e.g. share only "food prefs" the trust & consent layer, enforced through … CORE PLATFORM SERVICES — the backend that enforces policy & brings chosen data in Consent Protocol routes 7 policy API FastAPI policy surface WHY clients can't improvise HOW consent·PKM·IAM·Kai·RIA e.g. /api/* contracts AI-Memory Import 2 import connector import past AI chats WHY bootstrap PKM fast HOW OAuth → parse → domains e.g. an AI provider export Email connector 5 3 email connector receipts & brand signals WHY understand real spending HOW scoped read (receipts) e.g. 1yr receipts → brands Accounts connector 6 3 accounts aggregator financial-accounts link WHY advise on real holdings HOW read-only account link e.g. balances → portfolio RIA Intelligence API 10 3 OSINT engine public-profile dossier engine WHY claim who you are online HOW verify→dossier→image rank e.g. verify adviser core platform services, all running on the infrastructure foundation. INFRASTRUCTURE — the governed foundation everything above runs on Cloud compute + LLM cloud compute + LLM serverless compute + model WHY scales · governed deploys HOW UAT → prod parity e.g. hosts API + MCP Database database relational data plane WHY durable workflow state HOW consent·audit·metadata e.g. ciphertext rows Secret store secret store secret store WHY no keys in code HOW runtime refs · BYOK refs e.g. model API keys Auth + push auth + push auth + push messaging WHY identity & notifications HOW tokens + messaging e.g. consent push prompt CI/CD delivery pipeline delivery pipeline WHY safe, repeatable ships HOW parity gates UAT→prod e.g. blocked on red test ③ END-TO-END FLOWS — how it connects. Each story is ONE left → right sequence of real steps. Lanes never cross. Experience Channels Commerce/Pay Agents Memory Trust Services External 1 Build PKM SHIPPED EXP Sign in — identity provider TRUST Mint VAULT_OWNER · 24h TRUST Unlock vault · BYOK biometric MEM Client encrypts domain INGEST POST /api/pkm/store-domain MEM pkm_blobs ciphertext + index 2 Import an AI provider / an AI host FUTURE EXT OAuth the AI provider INGEST Download memory export INGEST Parse → map to 24 domains MEM Client encrypts MEM store-domain → mind·prefs 3 Claim public profile APPROVED INGEST Seed: name·email·phone INGEST Stage 1 · verify (regulators) INGEST Phase 2 · dossier (web OSINT) INGEST Image discover + rank EXP User selectively claims MEM store-domain 4 AlphaAgents → trade APPROVED EXP Ask Kai · /api/kai/analyze AGENT 3-agent debate · Fund·Sent·Val AGENT systematic overlay tiers AGENT DecisionCard · Buy/Hold/Reduce MEM store decision · financial PAY (future) broker order 5 Build Hussh agents APPROVED CHAN SDK · know·do·remember CHAN Register + certify (tiers) CHAN Publish to marketplace AGENT Runs under One / Nav contract CHAN Requests data via /api/v1 6 CRM via CRM + iPaaS FUTURE EXT Enterprise CRM request TRUST Consent · narrow fields only PAY iPaaS proxy EXT CRM updated — never a PKM mirror TRUST consent receipt logged 7 Consent via MCP · PCHP SHIPPED EXT RS Discovery · .well-known/hussh EXT Hello — UA capabilities EXT Offer — scopes · purpose · TTL TRUST Consent · biometric → CRT TRUST ZK export · AES-GCM + X25519 TRUST Ack → audit / transparency log 8 Native + Web parity SHIPPED EXP User triggers an action EXP Generated action plane EXP web proxy / native native shell INGEST Consent Protocol API EXP same truth, any surface 9 On-device edge FUTURE EXP On-device · agent runtime EXP on-device memory / on-device GPU AGENT on-device ML on-device inference AGENT Dev tools · cloud·source·CLI·MCP TRUST Acts under same consent 10 RIA shares strategies APPROVED AGENT Advisor builds picks CHAN Marketplace · relationship grant CHAN ria_active_picks_feed_v1 EXP Chosen investor contacts EXP Investor market home Greenfield (future): AI-memory import · public-profile→PKM · broker execution · partner-system sync · on-device edge. Grounded in the canonical Hussh platform docs, the SDK protocol spec, and the research engine. Status is honest, not aspirational.
Dark mode

Relations

  • Three-layer architecture — the protocol, platform, and fund framing the map expands into detail.
  • PCHP — the consent, export, and audit boundary that forms the Trust layer and Flow 7.
  • One — the orchestrator that sits at the top of the Agents layer.
  • Kai — the finance specialist and the AlphaAgents investing flow.
  • Nav — the privacy and consent guardian among the agents.
  • BYOA — Bring Your Own Agent, the developer-extension story the map calls Flow 5.

The Hussh Mega Map is a single picture of the entire platform. Most architecture diagrams force a choice between what the system is and how it actually works — the Mega Map shows both, in one view, without turning into a tangle of arrows.

It answers two questions at once:

  • What is the platform? A clean seven-layer stack. Each layer holds its real components, and every component says what it is, why it exists, how it works, and gives a concrete example — so each claim is something you can question, not decoration.
  • How does it connect? Ten end-to-end journeys, one per user story. Each journey is a single left-to-right sequence of real steps. Because every story has its own lane, the connections are fully traceable and no two lines ever cross. That is the whole trick behind "connections without spaghetti."
  • Consent Reverse-Auction — the Intention Economy on PCHP + UCP + AP2 — the consent reverse-auction — flipping data value to the user

How to read it

  1. Decode the words first. The map opens with a plain-English key for every acronym — personal knowledge model, consent handshake, bring-your-own-key, zero-knowledge, and the rest. Nobody should have to already know the vocabulary to follow the picture.
  2. Walk the stack top to bottom. Each layer hands off to the one below it, and the short sentence between layers states that dependency in words: experience reaches people, the trust gate earns consent, services bring data in, the encrypted memory holds it, agents act on it, channels distribute the results, and the infrastructure carries it all.
  3. Trace a journey left to right. Pick a story at the bottom and follow its steps. Each step is color-tagged to the layer it touches, which is what ties the two halves of the map together: the same colors you met in the stack reappear in the flows. Reading each component. Every box in the stack now shows two things at once: its plain role (a small tag — accounts connector, agent runtime, identity provider) and, beneath, what · why · how · e.g. so each claim is debatable, not decorative. Status is shape-coded for colorblind readers — ● shipped · ◆ approved · ○ future — so you never rely on colour alone.

The seven layers — what it is

  1. Experience and interaction. Where a person or an AI meets Hussh: the web app, the native iOS and Android app, an on-device runtime on the Mac, and external AI hosts. The same product truth shows up on every surface.
  2. Channels and ecosystem. The governed ways results and capabilities reach people, developers, and partners: a developer API, a hosted consent-tool server, a marketplace where advisers can share strategies, certification tiers that tell users which agents to trust, and partner integrations that receive only narrow, approved fields — never a copy of your private memory.
  3. Intelligence and agents. The reasoning layer that acts inside scoped permission and never touches raw keys: an orchestrator that coordinates, a privacy guardian that enforces consent, a finance specialist, a multi-agent investing debate that produces a clear Buy / Hold / Reduce decision, and a developer kit so anyone can build new agents under the same rules.
  4. Data, knowledge, and the personal memory. The heart of the system: one encrypted store that the user genuinely owns. The server only ever holds ciphertext. Personal data is organized into 24 domains across six human families — who you are, what you know, who you relate to, what you have, what you want, and how you delegate.
  5. Trust, identity, and consent. The gate every action passes through: sign-in, a biometric vault unlock where the key lives only in memory, short-lived scoped permission tokens, a six-phase consent handshake, and an encrypted, audited release of exactly the fields you approved.
  6. Core platform services. The backend that enforces the rules and brings chosen data in: the consent routes, an AI-memory importer, a receipts connector, a read-only accounts connector, and a public-profile research engine.
  7. Infrastructure. The governed foundation underneath everything: compute, the database, the secret store, authentication and push, and a release pipeline with safety gates.

The ten journeys — how it connects

Each is one left-to-right sequence on the map, with an honest status.

  1. Build your personal memory (shipped) — sign in, unlock the vault, the app encrypts a domain on your device, and only ciphertext is stored.
  2. Import past AI conversations (future) — connect an AI provider, parse the export, map it into the personal-memory domains.
  3. Claim your public profile (approved) — the research engine verifies and assembles a profile from public sources; you choose what to keep.
  4. From debate to a trade (approved) — ask the finance specialist, a three-agent debate weighs the case, and you get a clear decision; placing the order is future state.
  5. Build your own agent (approved) — use the kit, get certified, publish to the marketplace, and run under the same consent contract everyone else does.
  6. Keep a partner system in sync (future) — a partner receives only the narrow fields you approve, with a consent receipt logged — never a mirror of your memory.
  7. Consent through the protocol (shipped) — an outside service discovers what it can ask for, makes a scoped request, you approve with biometrics, and an encrypted, audited export is delivered.
  8. Same truth on web and native (shipped) — one action resolves through either the web or native path to the same backend, so every surface agrees.
  9. On-device edge (future) — the Mac runs the agent locally with on-device inference and developer tools, still acting under the same consent.
  10. Advisers share strategies (approved) — an adviser publishes picks to chosen contacts through a consented relationship, and those investors see them at home.

Why it stays calm

The map earns its readability from two disciplines. The flows are true swimlanes, so a connection is always a single horizontal line that structurally cannot cross another. And the layout is balanced by arithmetic rather than by eye — the content is centered, every layer fills the width evenly, all ten lanes share the same step span, and each handoff marker sits at the exact middle of the gap between layers. The result reads as one coherent document instead of a wall of boxes.

Sources