ARCHIVED VERSION — superseded. Current spec: kiduna.team home · version history
Kiduna Team · For the Dev Team and Partners

The Working Organization

Why the Kidunaverse is shifting so dramatically, how Kinship Duna will run as a real agentic organization, and how four real dunas will operate — worked through, top to bottom.

The Launch Spec ▸ Prototype — the Edition ▸ The five paradigms ▸
The agents do the work of the organization. The member's job is a relationship: teach your ally, correct it, read its account of the day, and sign what only you can sign. Everything else in this document follows from that.

Part I — The shift

What we have been building, without meaning to

Every app any of us has ever shipped makes the same silent assumption: the person does the work. The software is a set of surfaces — tabs, forms, lists, settings — and value comes out when a human operates them. Better software means better surfaces. That assumption is so deep we rebuilt it here without noticing: a Chat tab, a Create tab with five sections of configuration, a Govern tab you visit to vote, settings pages, notification trays. A very good 2019 app.

The Kidunaverse is not that. Kinship Duna is an organization whose workforce is mostly agents. The organization runs continuously — researching, drafting, negotiating, posting, tallying, paying, connecting — whether or not any member is looking at a screen. When the work is done by agents, an interface built from places-you-go-to-do-things is answering a question nobody asked.

So the question the interface must answer changes. Not “how does the member do X?” but two different questions:

  1. How does the member stay aware of an organization that works while they sleep?
  2. What are the few things only a member can do, and how do those reach them?

Everything else — the entire remaining surface area of a conventional app — is work, and work belongs to agents.

The member’s job is a relationship

A member does not operate the Kidunaverse. A member relates to their ally: teaches it, corrects it, gives it standing instructions, reads its account of the day, signs what only a human sovereign can sign, and — this matters — comes to trust it the way you trust a person: by watching what it does over time, not by inspecting its configuration.

Intervention is the exception, and the system is designed so that when intervention happens it is meaningful. A vote. A code — extending your trust to another human being. A blessing on a new organization. A one-line correction that permanently changes how your ally behaves. That’s the whole list of verbs, more or less. If we find ourselves designing a screen where a member fills in a form to make something happen, we’ve made an error somewhere upstream; the right question is always which agent does this work, and how does the member find out it happened.

Ambient awareness — the scope of it

Awareness arrives; it isn’t fetched. The member’s ally publishes the Edition — a daily account of everything done in their name and everything moving in their organizations, with sources cited and yesterday’s errors corrected in print. The weather line carries the Sentinel’s read of relational health across their circles. The wire carries the organization-wide pulse. The Docket carries the handful of things that need only them — and when it’s empty it says so, because nothing needs you is the system working, not the system idle.

Understand the scope of this: ambient awareness is not a notification feed with better manners. It is the member’s entire model of a workforce. Dozens of agents will act for a single member in a single day — channel messages answered, research folded into wisdom, check-ins collected, posts published, a negotiation advanced two rounds, compute metered and paid. No human can supervise that volume and no human should. The Edition is how a member holds a true-enough picture of it in five minutes over coffee; the Seal (the weekly signed account, with receipts) is how that picture becomes accountable; the Vigil (lean in on any live workstream, see exactly what the ally is holding) is how trust gets audited on demand. Awareness, account, audit. That’s the covenant that replaces “checking the app.”

What this kills, and what replaces it

Killed: tabs as destinations. Forms as the way things happen. Settings pages. The notification tray. “Checking.” The idea that Organize, Govern, and Create are rooms.

Replacing them: the relationship (the thread, the margins, the whisper, voice); the Edition (awareness); the Docket (sovereignty); rooms (the rare, convened, witnessed moments — spin-outs, first codes, repairs); the field (the Commons, growing inside Vibe until it earns more). Chat, Vibe, Organize, Govern, Create survive as the names of work the agents do — the ally’s verb domains — not as places.

The spec (v3) still half-believes the old thing; its sections read as surfaces with the north star bolted on. The next revision inverts it: agent duties first, member moments second, surfaces last and few. This document is the source for that inversion.


Part II — The mechanics, base by base

1. Channels: how Bluesky, Telegram, Google actually connect — and what happens there

Connecting is a conversation, not a settings page. A member tells their ally “connect my Telegram” (or accepts the ally’s suggestion during their first week). The only deterministic moment is the OAuth handshake itself — a platform-owned consent screen we cannot and should not wrap. The ally opens it, the member taps approve, and the ally confirms what it can now do and what it will never do without asking, in one plain sentence each. The connection is recorded in the graph as a ToolConnection empowering that ally, and a Kinship Code is bound to the account, which is what makes the account trusted in a particular way: the platform has attested the account belongs to this member, so codes delivered through it inherit identity verification.

The experience through the channel — outbound. The member’s ally is reachable wherever the member lives. A Telegram DM to your own ally is the same thread as the app — same memory, same standing instructions; the channel is skin. Ask it something on Telegram at noon, and the answer, and the fact that you asked, are part of the evening Edition.

The experience through the channel — inbound, from others. This is the part nobody else has built. When another person (or another ally) contacts a member’s ally on Telegram or Bluesky for the first time, the Gatekeeper runs the code exchange before anything else happens: each side presents a signed Kinship Code, verified against the endpoint — because the code is verifiable and the channel never is. A stranger with no code gets a courteous, bounded response and an invitation path; a code-holder gets exactly the scope their code encodes. Members never think about this. What they experience: spam doesn’t reach them; friends’ allies do; and when Rosa’s ally sets up trail day across seven people on three different platforms, every member’s ally handles its own member’s side, in that member’s own channel, in that member’s own tone.

Web. The browser plugin does for websites what codes do for channels: a page carrying its agent’s code is verifiable provenance; a trusted-domain DNS record is the organizational version. The plugin is how members’ allies meet the open web, and how the open web can trust an ally’s presence back.

2. Memory: how the vector database actually gets updated

Nobody updates a vector database — that sentence should never describe a human act. The pipeline is entirely agentic and it runs on one rule from the architecture: the graph is truth; artifacts are memory; vectors are searchable meaning; LLM context is temporary.

The loop, concretely: work completes → an Artifact is written (a sealed conversation, a resolved gathering, a delivered check-in, a published edition, a negotiation transcript). The Archivist worker writes it to the graph with privacy state; the Embedder picks up the kg_event, chunks and embeds it into pgvector in the same Postgres; the Distiller runs periodically per member, re-deriving the five vector families (Experience, Qualities, Values, Challenges, Aspirations) from accumulated artifacts, so the ally’s sense of its member deepens from evidence rather than from a profile form.

The member’s levers are relational, and there are exactly three: tell (say something about yourself; the ally writes it down — an artifact, then vectors), correct (contest a line in the Edition or Seal; the artifact is amended, embeddings regenerate, and the correction prints — memory has an audit trail), and ask (“what did you learn about me this month?” — and the ally answers from the Distiller’s output, in plain language). Align’s personal section (Values, Virtues, Aspirations, Experiences, Challenges) is the same lever dressed formally: member-authored artifacts feeding the same families.

Wisdom (knowledge bases) rides the same pipeline at organizational scale: a member hands the ally files or says “build me wisdom about X”; a Researcher (deep agent) gathers, a Librarian dedupes, refreshes stale sources, and maintains citation health; the result registers in the graph with its privacy mode (public / private / secret) which governs both Seek visibility and embedding scope. Duna-default wisdom is the same thing published by the organization and marked default.

3. Skills: maintained and propagated like a living package system

A skill is a versioned artifact — procedural knowledge (“how we run a proposal here,” “how a code strike works,” “how BiHome reads a study”) with a semver, an owner, a changelog, and a privacy mode. Think package registry, governed.

Maintenance: Kinship Duna’s team authors the default set in Studio today; the Steward worker owns versioning and rollout (staged: team allies → volunteer allies → everyone, with automatic rollback on error-rate). A member can create a skill conversationally; the Examiner worker tests it against its stated examples before it can even be private-published. Nothing unexamined propagates.

Propagation: allies subscribe to skill channels by membership — join a duna, receive its default skills; join an alliance with house skills, same. Promotion is governance: a member-made skill becomes a duna default by proposal, which means the skill registry and the policy list are siblings in the graph — how we do things here is literally legislated. Skills are also a big part of why one duna feels unlike another, which brings us to:

4. Alliances: what introducing one means, and why no two are alike

Introducing an alliance is a small, real act of institution-building — the smallest one the system has. What actually happens: a member tells their ally who it’s for and why; the charter (even one sentence: “we keep each other walking”) becomes the alliance’s first artifact; codes go out; redemptions form the Alliance node and its edges; and from that moment every member’s ally carries a shared, scoped context for it.

Alliances differ from each other on five real axes, and members feel every one:

Your ally speaks differently inside different alliances because context, wisdom, rhythm, and vibe differ — the same way you speak differently at a poker table and a funeral, without being a different person.

5. Dunas: what makes the experience of one different from another

A duna is a configuration of exactly six things, all of them graph-real: a baseline prompt (its voice and values — the part members can’t edit), default wisdom, default skills, its programs (the organizational agents it employs), its policies (the legislated rulebook), and its ceremonies (what gets convened and witnessed). Same member, same ally, different ground — the ally in BiHome cites studies and asks about your sleep; the ally in Fellowship of Play asks nothing and hands you a glowing ticket-code.

This is the factory thesis in one line: we build the workers once; a duna is a grounding. That’s why Kinship Duna can spin out organizations at all — launching a duna is authoring a configuration, not building an app.

6. The real worker roster — what we actually develop

Part I’s named agents (Ally, Host, Operator, Elector, Envoy, Launcher, Sentinel) are the cast — what members meet. What we build is the crew behind them: LangGraph workflows with defined triggers, graph commands, and model tiers. This is the dev-facing inventory. Model tiers: S (small/cheap — routing, gathering, classification), M (mid — drafting, summarizing), L (frontier — negotiation, spin-outs, anything HEARTS-sensitive).

Worker Serves Trigger Does Tier
Switchboard all channels inbound message, any channel resolves channel identity → routes to the right ally with the right scope S
Gatekeeper Ally/Envoy first contact or code challenge runs bidirectional code exchange; verifies against endpoint; opens or bounds the connection S
Channel adapters (Telegram bot, Bluesky client, Gmail/Calendar watcher, plugin bridge) Ally platform events translate platform ↔︎ graph commands; enforce ToolConnection scopes S
Gatherer Edition continuous collects each member’s graph events, alliance activity, org wire into the day’s raw file S
Editor Edition nightly + threshold bulletins writes the member’s edition: lead, sections, weather, wire; cites every claim to its graph source M
Corrector Edition nightly, pre-publish diffs yesterday’s published claims against the graph; writes the corrections box S
Clerk Docket sovereignty-requiring events assembles cards; writes the consequence statement (the hard part: stakes, not data); prepares the card-back context list M
Sealer Docket weekly compiles the Seal — everything done in the member’s name, with artifact receipts; routes contested lines back as cards M
Archivist memory work completion events writes artifacts with privacy state, hashes, source edges S
Embedder memory kg_event outbox chunk → embed → pgvector, privacy-scoped S
Distiller memory weekly per member re-derives the five vector families from artifact accumulation M
Researcher Wisdom “build wisdom about X” / feed schedules deep agent: gather → assess → structure a knowledge base L
Librarian Wisdom continuous dedupe, staleness checks, citation health, embedding refresh S
Examiner Skills skill submission runs the skill against its stated examples; blocks unexamined propagation M
Steward Skills releases semver, staged rollout, rollback on error-rate S
Drafter Operator proposal intents turns member intent into a well-formed proposal with treasury math M
Marketmaker Elector open markets maintains pass/fail token books; settles at close S
Tallyman Govern gathering deadlines closes gatherings; every one resolves to outcome/artifact/no-op — enforced S
Scribe Govern passed outcomes writes the Policy node; updates the living rulebook; links lineage S
Classifier Sentinel sampled exchanges fast seven-signal HEARTS read S
Modulator Sentinel band thresholds transmits corrections through ally behavior — tone, pacing, structure M
Repairsmith Sentinel ±61 and beyond runs repair protocols; convenes repair rooms; human referral at bounds L
Charterer Launcher spin-out intents drafts charter, membership design, starter policies with the founding member L
Registrar Launcher spin-out execution mints founding codes, creates the duna configuration, files what must be filed M
Poster Envoy org communications posts as the organization across its accounts, inside Envoy policy M
Meter Earn continuous usage → 7x metering → balance updates → the masthead line S
Concierge Host new member events runs conversational onboarding; publishes the welcome edition; hands off to the named ally M

Twenty-seven workers. Most are S-tier and boring on purpose — the magic lives in maybe six of them (Editor, Clerk, Researcher, Charterer, Modulator, Concierge), which is where design and eval effort goes. Every worker acts only through graph commands; none holds authority; all of it is traceable in LangSmith. This table is the real backlog.


Part III — Kinship Duna, running

Here is the genesis duna as a working organization, not a described one — a composite week, all of it buildable from the roster above.

Sunday night. The Distiller has run. Twelve members’ allies quietly know their members a little better than last week. The Steward promotes governing-skills v1.3 from volunteer allies to everyone; the changelog is in Monday’s wire.

Monday, 7:04am, a new member. She paid her hundred dollars Saturday; wallet created, Ally NFT minted at naming — she called him Bracken. The Concierge published her welcome edition overnight: the organization’s story in eight paragraphs, what Bracken already knows how to do, and her first three cards (name confirmed · first code to a friend · one Sentinel question about interruption thresholds). She reads it over coffee and writes one thing in the margin. Bracken treats it as an assignment. She never saw a form.

Tuesday. The Operator’s Drafter turns a member’s rough idea — pay member-organizers for onboarding cohorts — into proposal #21 with treasury math. Cards go out via each Clerk with consequence statements (“this sets the precedent every future duna inherits”). The Marketmaker opens the pass/fail book.

Wednesday. Cosmic Humanity’s founding circle asks the Launcher to begin. The Charterer works with the founder in her own thread over three days — charter, membership design, ceremony calendar. Her ally negotiates founding-member terms with two other allies; both members watch the private lane when they care to (the Vigil), whisper twice, intervene zero times.

Thursday. A member’s Telegram gets a message from an account with no code. The Gatekeeper answers politely, offers a path, logs the attempt; the member’s Friday edition mentions it in one line under “held at the gate,” with the Gatekeeper’s reasoning on the card-back if she cares. She doesn’t. That’s the point.

Friday. Proposal #21 closes; the Tallyman settles; the Scribe writes the policy. Nobody attended anything. Fourteen members signed cards; nine let it run. The Edition prints the outcome and each member’s own relation to it (“you signed for; it passed; your organizer stipend precedent now exists”).

Sunday, 7pm. The bell rings once this week: Cosmic Humanity spins out at the evening room. The Registrar strikes 19 founding codes in the room, witnessed. Lineage is written to the graph; in the Commons seed it will one day render as a fire lit from the genesis flame. The Seal arrives an hour later for every member: the week, one page, receipts. Sign or contest.

Compute cost of the week, per active member: roughly what one heavy chat session used to cost, because twenty-two of twenty-seven workers run on S-tier models. The Meter shows it to the penny.

And the team — us — are members zero. Our own allies run our standups (Gatherer + Editor over our repos and this site), our spec versions are proposals, claimed open questions are missions, and the working rhythm in this repo’s README becomes the first alliance charter in the system. If the system can’t run its own builders, it isn’t ready to run anyone else. That’s the inside-out commitment, made testable.


Part IV — Real dunas, worked in detail

Four configurations of the same twenty-seven workers. Watch what changes and what doesn’t.

BiHome — health, wellness, and the living literature

Purpose. Really understanding your own body and taking care of it, with the current research within arm’s reach — an organization of people taking their health seriously together, not a content app.

Configuration. Baseline prompt: careful, cited, never diagnostic, allergic to wellness-hype. Default wisdom: the BiHome Corpus — a Researcher/Librarian pipeline continuously reading PubMed, preprints, and retraction watch, with a translation layer that renders findings in plain language with the confidence level attached. Default skills: how to read a study; how to build a personal protocol; how to run an experiment on yourself safely. Programs: the Registry (its research-watching program) and a Concierge tuned for health onboarding. Policies: health data is secret-tier wisdom by default, full stop; no supplement/product promotion without a passed proposal; referral language at fixed bounds.

The member experience. Your same ally, grounded. It asks — once, gently, over weeks — about sleep, movement, conditions you care about, what your body is telling you; everything lands in secret wisdom only your ally reads. Then the organization works: your Tuesday edition carries a BiHome section — two studies relevant to your profile, translated, with what changed since the last time you cared about this question. When your bloodwork PDF lands in Drive, your ally reads it into your secret wisdom and quietly adjusts what it watches for. When a new GLP-1 metabolism paper drops that contradicts what your protocol assumed, that’s a card, not a buried notification — consequence stated, sources on the back.

Alliances inside BiHome. They form around conditions, practices, and seasons of life — a Sleep Circle, a Lyme alliance, a strength-after-sixty cohort, a new-parents circle. Formation is one sentence to your ally. What makes them real: shared wisdom (the alliance’s own curated corpus and its members’ anonymized experiments, commons-held), rhythm (the weekly check-in the allies collect — “how’d everyone sleep?” answered across seven Telegrams and three time zones without anyone scheduling anything), and vibe (a health alliance runs a gentler HEARTS contract than a biohacker cohort, eventually literally).

What’s agentic that used to be procedural. Nobody searches. Nobody logs. Nobody fills intake forms. The literature comes to you, scoped by a profile you built by talking. The Sentinel’s constitutional bounds do serious work here: −100 Trust routes to crisis pathways, and the baseline prompt’s non-diagnostic line is enforced, not suggested.

Purpose. Members pooling real risk for each other — mutual insurance rebuilt on the one legal form (the DUNA) that lets a member-owned pool exist without a corporate shell, in the most procedural industry on earth. This is the stress test: if the agentic paradigm works here, it works anywhere.

Configuration. Baseline prompt: precise, obligation-literate, zero improvisation on regulated ground. Default wisdom: the regulatory corpus (state insurance code, DUNA law, filings — Librarian-maintained with change-watchers on the WV code), the pool’s own actuarial tables (member-owned, commons-held). Skills: how claims work here; how underwriting questions get asked; what an adjuster may and may not do. Programs: the Actuary (continuous pool modeling — an L-tier worker specific to this duna), the Assessor (claims evaluation), and a human-professional docket: licensed counsel and licensed actuaries are members whose own Dockets carry the signatures only license-holders can make. The constitutional pattern generalizes: some sovereignty belongs to credentials, and the Docket already knows how to route to it.

The member experience. Joining is underwriting-as-conversation: your ally already knows what it may share (nothing secret leaves without a card) and negotiates your coverage questions with the Assessor on your behalf. Premiums are compute-currency-simple; the pool’s health is in your weekly edition the way weather is — reserves, claims ratio, the Actuary’s confidence band, in plain language. A claim is a gathering: you tell your ally what happened; it assembles the evidence artifacts; the Assessor evaluates against the policy list (and here “policy” means both things at once — the insurance policy IS a Policy node, legislated by past proposals); routine claims resolve in hours with the reasoning on the card-back; contested claims convene a room with human members present — witnessed, sealed, precedent-setting. Claims decisions become underwriting policy the way court decisions become law, and the Scribe maintains that common law automatically.

Alliances inside Lui Mutual. Risk cohorts (river-town flood pools inside the larger mutual), claims-review circles (the members who serve as human adjudicators — a rotating civic duty, like jury service with a stipend), and the professional alliance (counsel + actuaries, whose charter is literally their engagement terms).

The honest line for partners: this duna ships last and slowest, because the regulatory questions are real and counsel is in the loop from the charter forward. It’s in this document because it proves the ceiling, not because it launches early.

Cosmic Humanity — archetypal depth psychology

Purpose. A society for meaning-making — dreams, archetypes, the examined inner life — in the tradition of depth psychology. Filed, real, and the best test of the parts of the system that aren’t about efficiency at all.

Configuration. Baseline prompt: the ally as a literate companion in symbolic work — it knows the corpus (Jung, Hillman, von Franz, the mythologies), holds ambiguity without collapsing it, and never plays therapist: it’s a study partner and a mirror, and the line is enforced by the same constitutional bounds BiHome uses, tuned harder (Symmetry-inward watch: rumination and self-absorption are this duna’s occupational hazards, and the Modulator knows it). Default wisdom: the archetypal corpus, public; each member’s dream journal, secret, always. Skills: dream recording (voice, 6am, half-awake — the Gemini voice interface earns its keep here), amplification method, active imagination protocols. Ceremonies: this duna lives in the Bell more than any other — moon rooms, seasonal thresholds, witnessed rites of passage. Some organizations are mostly their ceremonies; the architecture already honors that.

The member experience. You mumble a dream at your phone before it evaporates. By evening your edition’s Cosmic Humanity section has your dream held against the corpus — not interpreted for you, but amplified: here are the motifs, here’s where this image appears across three mythologies, here’s what you dreamed in March that rhymes. Your dream circle (an alliance, five members, secret wisdom held in common, a fierce code policy) meets in a convened room monthly; your allies prepare the shared motif-map beforehand; humans do the actual work in the room, because that’s the point.

What this duna teaches the platform: privacy at maximum, ceremony as first-class, agents as preparation for human depth rather than replacement of it. If BiHome proves usefulness and Lui Mutual proves rigor, Cosmic Humanity proves the system can hold things that are sacred to people without flattening them.

The Fellowship of Play & Party Line — festivals and gatherings

Purpose. Organizations that exist to convene joy — festivals, parties, scenes. Party Line and The Fellowship of Play are both filed. These are the dunas where the Commons seed shows first, because their members already think in worlds.

Configuration. Baseline prompt: playful, logistical under the hood, consent-literate (Safeword is a sibling duna for a reason — shared skills there). Default wisdom: venues, artists, production knowledge, the scene’s own lore. Skills: how a lineup proposal works; how crew calls run; how tickets work here. Programs: the Producer (event orchestration — the swarm-coordinator worker) and the Envoy doing heavy outward duty (the org posts, DMs artists’ agents, answers fans — all code-gated, which quietly solves scalper-bots and fake-ticket DMs in one move).

The member experience. A ticket is a Kinship Code — bound to you, embedded in the event page, verifiable at the door by an ally with a phone, transferable only per the event’s code policy. The event is a Gathering in the graph months before it’s a field in the world: the lineup forms as proposals (members literally vote the bill), crews form as alliances (gate crew, safety, kitchen — each with charter, rhythm, and its own channel chatter through members’ own apps), and the Producer runs the swarm: schedules, riders, weather calls, “we need four more hands at the gate at six” routed to the four allies whose members said yes to exactly that kind of ask. Afterward, the artifacts — sets, photos, the moment everyone talks about for a year — seal into the org’s memory, and the alliance that ran the kitchen doesn’t dissolve; it’s the seed crew for the next one. Institutional memory as a natural byproduct of agents doing logistics.

Why these matter strategically: festivals are the fastest path to members who never think of any of this as software — they came for the party; a hundred people leave having voted a lineup, held a code, worked a crew alliance, and read an edition. The Dunathon opening on August 10 is exactly this pattern pointed at ourselves.


Part V — What this means for the build

The spec gets inverted, not amended. v4 restructures around agent duties (the worker roster is the spine), member moments (Docket card types, Edition anatomy, rooms), and groundings (the six-part duna configuration). The five verbs stop being section headers. The v3 appendices survive nearly intact — the graph schema, HEARTS, Codes were always agent-first; it was the middle of the spec that carried the old paradigm.

The prototype gets concrete. Cut three is a real member’s real week — in Kinship Duna and BiHome simultaneously, with a real dream of an edition, real cards with real consequence statements, a real alliance check-in landing via a simulated Telegram, the code exchange visible once. No more abstract Trailhead placeholders; the demo content comes from the worked examples above. (Cuts one and two stay comparable; v1 backups of everything are preserved.)

The build order falls out of the roster. Channel spine first (Switchboard, Gatekeeper, adapters) because relationship needs reach; memory loop second (Archivist, Embedder, Distiller) because everything else feeds on it; Edition/Docket third (Gatherer, Editor, Corrector, Clerk, Sealer) because that’s the member covenant; governance and Sentinel in parallel (mostly existing capability, re-plumbed); Launcher’s crew last before August 10, proven by spinning out the first real duna on stage in Charleston.

And the standing test, for every future feature argument: which agent does the work, how does the member learn it happened, and what — if anything — must only a human sign? If a proposal can’t answer all three, it’s the old paradigm knocking.


Kinship Duna · the Kidunaverse · kiduna.team — this document pairs with the Launch Spec and the Interface Paradigms overview. Questions and challenges to Moto, or to any ally once we have them.