Solutions
The five pillars of the Joyint Trust Model.
The Joyint Trust Model is built on five pillars. Together they answer the fundamental questions of human-AI collaboration: who acts, what is protected, how work flows, what happened, and what it cost.
1. Trustship - Who Do I Trust?
Identity, capabilities, and delegation. Every actor in the system - human or AI - has an identity and a set of capabilities that define what they can do.
- Solo: Implicit trust. One person, all capabilities, no gates. Nothing to configure.
- Team: Explicit trust. Members have defined capabilities (conceive, plan, implement, review, etc.). AI members get the same model with sensible defaults.
- Enterprise: Verified trust. Delegation chains track who authorized what. AI actions always trace back to a human.
Trustship scales without changing the workflow. You add accountability when you need it, not before.
2. Guardianship - What Do I Protect Against?
Runtime validation, encryption, and three-layer protection.
- Prevent: Capability checks stop unauthorized actions before they happen. Gates with
allow_ai: falserequire a human at critical transitions. - Detect: The event log captures every action. Anomaly detection through Judge reports is planned.
- Prove: Append-only logs in Git keep the trail, and member entries carry signed attestations. Signed events are planned. Crypt adds encryption for sensitive items and files.
3. Orchestration - How Do I Steer Work?
Jobs, interaction levels, and dispatch. Orchestration bridges Joy (planning) and Jyn (execution).
- Jobs define units of AI work with a scope, a budget, and a time window.
- Interaction levels control autonomy:
autonomous,confirmed, orproposing, where the human decides every step. - Dispatch (planned) will route tasks to the right actor based on capabilities, availability, and cost.
Today a human approves a job, and the Joyint app or platform runs it in a container within its budget. The Dispatcher will automate the routing, respecting trust boundaries and budget limits.
4. Traceability - What Happened?
Event log today, Judge audit and signed events planned.
- Every Joy command produces a structured event: who, what, when, on which item, and under whose delegation.
- Events are appended to plain files in your repo, and your commits carry them into Git history, where every change to the log shows.
- The event log is human-readable (one file per day, plain text).
- Judge (planned) will provide independent verification: it reads the log, validates consistency, and produces audit reports.
Traceability is always on. There is no way to use Joy without producing a trace.
5. Settlement - What Did It Cost?
Per-job cost tracking, budget enforcement, and future on-chain settlement.
- AI operations have costs (API calls, tokens, compute). Every job keeps its tokens and cost, and the platform tracks spend per key, per team budget, and per member.
- Budget limits prevent runaway costs. A team can set per-job caps, monthly caps per key, and a team budget with a per-member share.
- Future: on-chain settlement enables transparent, verifiable cost tracking for AI work across organizations.
Settlement turns AI usage from an opaque expense into a traceable, controllable line item.