Skip to content
Rooyande
All work
OngoingPersonal AI operating system

Jarvis

A private AI company with one client: it remembers, plans, acts within permission, checks its own work and reports back.

Role
Product, architecture, AI-assisted build
Year
2026
Built with
Python 3.12, SQLite, SQLAlchemy, FastAPI, OpenRouter, Next.js, Tailwind
Private system: no public link
Jarvis UI prototype: a black command-center screen with the JARVIS wordmark, the line 'Your operating company of one' and a composer input, marked Demo.

Private system. The screenshots show demo records only.

Context

Most personal AI tools are chat windows: they answer, then forget. I wanted something that runs my work the way a small company would, with memory, a task list that understands dependencies, and the judgement to ask before doing anything that matters.

Jarvis is that company. It has exactly one client, me, and it is also the most complete thing I have built.

The problem

Language models are good at proposing and bad at being trusted. A system that sends messages or spends money on its own has to stay predictable, reversible and accountable, even on the days the model is wrong.

The approach

State lives in a database, not in prompts. Agents propose; deterministic code decides and executes. Every request travels the same path: it is ingested as an event, becomes tasks with dependencies, and any action a model proposes goes through policy, and through approval when the risk requires it, before an executor runs it and verifies the result. Everything is written to an audit log.

The whole core runs end to end with no API key, no Telegram and no internet, which made it possible to test every rule before a real model was attached.

How a request travels

Drawn on the hexagonal lattice of ice. The warm point is the one place a human is asked.

  1. 01Transport
  2. 02Ingest
  3. 03Events
  4. 04Tasks + deps
  5. 05Proposed action
  6. 06Policy
  7. 07Approval
  8. 08Executor
  9. 09Audit + outbox

Decisions that shaped it

  1. 01

    Risk tiers and approvals

    Every action is a typed verb with a risk tier. A ten-step policy engine decides whether it runs, waits for approval or is refused. An approval that nobody answers expires into a denial, never into a yes.

  2. 02

    One way out

    People are only ever contacted through a single outbox, so nothing reaches anyone by accident. A kill switch stops everything at once.

  3. 03

    Dependencies that explain themselves

    When a task is blocked, for example on a voice sample only a human can record, Jarvis creates a task for me and says exactly what would unblock the original one.

  4. 04

    Memory that understands Persian

    Full-text search normalises Arabic and Persian keyboard variants, so the same word typed two different ways is still found.

  5. 05

    Cost is part of the state

    A cost ledger and budget modes (normal, degraded, restricted, frozen) sit in front of every model call. The model layer routes through OpenRouter with a fallback model when the primary one fails.

  6. 06

    An audit you can verify

    The audit log is append-only and hash-chained with SHA-256: if any past record were altered, verification would fail.

Screens

Jarvis Ops Console, Approvals: a pending risk-T3 'send message' action with Persian and English body, policy reason and Approve / Deny buttons (demo records).
Jarvis Ops Console, Approvals: a pending risk-T3 'send message' action with Persian and English body, policy reason and Approve / Deny buttons (demo records).
Jarvis Ops Console, Blocked: a task waiting on a human, explaining the missing asset and what would unblock it (demo records).
Jarvis Ops Console, Blocked: a task waiting on a human, explaining the missing asset and what would unblock it (demo records).
Jarvis Ops Console, Memory: a Persian full-text search matching different keyboard spellings, with profile, semantic and episodic memory panels (demo records).
Jarvis Ops Console, Memory: a Persian full-text search matching different keyboard spellings, with profile, semantic and episodic memory panels (demo records).

Where it stands

  • BuiltCore runtime, dependency engine, policy and approvals, memory, audit, cost ledger and ops console: Python 3.12, SQLite, 161 automated tests.
  • LiveReal model layer, live since 26 September 2026 (OpenRouter, with a fallback model).
  • BuiltInterface direction: a Next.js prototype of the command center. It shows demo data and is not yet connected to the core.
  • In progressText capture end to end, and a read-only bridge to my notes vault.
  • NextVoice, Telegram, calendar, connecting the interface to the core, and deployment.

What I learned

The interesting part of an AI system is not the model. It is everything around it that decides what the model is allowed to do, and an honest record of what it did.

Contact

Say something on the glass.

A website, an AI or software project, English lessons, or a job offer. Write a few lines about it; every message gets a personal reply.

[email protected]
Write an email

or go to the contact page