A sample of a personal-assistant contract for hardware you operate

What matters gets through.

Moneypenny is being built as a personal-assistant system for computers you operate. This public site uses real visitor request metadata for analytics and signup as disclosed below, but its workflow examples use sample data only. It does not read live messages or prove a private runtime.

The private-runtime target is to read only the channels you connect, keep message records on your machines, and disclose any approved task-scoped processing by an outside AI service. This public sample does not prove that final-effect gate. Exactly what leaves, and when →

Fair warning, up front: this is one engineer's personal build, not a product you can buy yet. The workflow examples and demo use sample data; the public signup and analytics paths process real visitor data as disclosed below. Private-runtime capabilities described below are target contracts unless a current canary is named; this page claims no such canary. Get told when that changes →

One promise, start to finish

From a loose sentence to a finished job

Illustrative target walkthrough — not live execution evidence: picture a Tuesday morning when a call ends with a promise to sort out a flight. The sample below shows the contract Moneypenny is being built to enforce; it did not hold a fare, book travel, update a calendar, or produce a real receipt.

Illustrative sample of the target contract — not live execution evidence: no fare hold, booking, calendar update, or receipt shown here was executed.

  1. Listen — a spoken promise ("find me a flight east, hold the best refundable option") is caught from the meeting notes you've connected, the way texts and email are: quietly, on your own computer.
  2. Sort — the loose sentence becomes one tidy card: what was asked, for whom, by when. The rest of the day's noise is filed without reaching you.
  3. Desk — one paper lands on your Desk: the held 9:40 flight, the rejected alternatives, the exact decision needed. Sign it, send it back, or bin it.
  4. Do (illustrative target) — the sample depicts a signed flight being booked, a calendar being updated, and a confirmation being filed; none of those actions occurred.
  5. Prove (target contract) — a real execution would need evidence-backed closure; this page supplies only a sample receipt.
The Desk

Your side of it is one desk

Not a status page and not a feed. Work arrives as paper, sits where you put it, and leaves when it's done. The one-decision chores get swiped away one at a time; the longer things wait where you can see them. An empty desk means "already handled."

Four plain moves decide each paper — on a phone, they're swipes: done · swipe right snooze · swipe left delete · swipe down star · swipe up open · tap

On a big screen the same verbs are clicks and drags: tap a paper to open it, drag it to the outbox (done), the tray (snooze), or the trash (delete) — the demo's hint bar shows the mapping.

Try it yourself — the sample demo runs in your browser →

Who it's for

Anyone whose day leaks promises: the parent juggling school threads and appointment reschedules, the founder with forty unanswered messages, the person who says "I'll sort it out tomorrow" on every call. If your follow-ups live in six apps and your own memory, this desk is for you.

Why it isn't another inbox

Four things it does that a to-do app can't

The target reader handles connected text sources

Target contract: explicitly connected text sources would be processed without requiring manual polling.

open

The intended private runtime would classify a connected message and stage the follow-up. This public sample reads no messages and proves no continuous ingestion.

The target has no ambient microphone: voice memos, dictation, and meeting notes would be explicit text-source inputs selected by the operator.

Data locality remains a private-runtime requirement, not a capability proved by this public sample.

full story →

One desk, one decision at a time

The sample shows the target Desk contract: one prepared decision at a time.

open

Under the target contract, only reversible preparation may precede the Desk. The public sample compares no live fares, places no hold, and executes no final effect.

A reviewed implementation must surface one bounded decision with its evidence rather than fragmented interruptions.

full story — try the Desk →

Swap the AI; keep your history

Target architecture: the AI runner is replaceable; durable state must remain outside it.

open

A reviewed runtime would route an approved task to a selected runner while keeping the job and evidence elsewhere. This public sample invokes no runner and proves no mid-task vendor swap.

The target is operator-owned continuity rather than vendor-owned state.

full story →

Receipts, not promises

The target contract requires every claimed completion to have source-backed evidence you can read.

open

"Done" is a claim, and claims need evidence. When Moneypenny finishes something, it files a receipt — the confirmation number, the sent reply, the updated calendar entry — next to the request that started it. If a job can't show its receipt, it isn't done, and it goes back on the Desk.

The receipts on this site are illustrative samples of the target contract; they do not prove a live job or the shape of a production receipt.

full story →
What "done" looks like

One job, closed, with the receipt

This is an illustrative target-contract receipt from the in-browser sample. No fare was held, no flight was booked, no calendar was updated, and no confirmation was filed. It demonstrates the intended evidence fields, not live execution or closure.

Illustrative sample receipt · flights east · no booking occurred
askedTue 09:12 · "hold the best refundable option"
preparedsample outcome · 3 fares compared · hypothetical 9:40a hold · no charge
signedTue 11:02 · you, from your phone
donesample outcome · booking and calendar update were not executed
proofsample identifier only · no confirmation or card receipt exists
target receipt contract · illustrative only · not proof of live execution or closure

The target contract requires an evidence-backed receipt before a job can be called closed. This sample is not stored with an airline and does not link to a real confirmation. The rules that keep receipts honest →

The practical part

What it runs on

The intended packaged runtime is software for hardware the operator controls.

Planned connectors include email and Apple-hosted Messages, and the Desk is designed as a browser surface. No current public canary proves those connectors or a packaged installation.

A packaged, plug-in version remains roadmap work — the email list below is where a proved release would be announced.

Who's behind it

Built by Joe Lanzone, an AI product engineer, as the assistant system he wants to operate. This public site is a sample-only workflow demonstration; it is not evidence of a live private runtime.

The name is borrowed from Miss Moneypenny, the fictional assistant who quietly kept the office running. This one is a program, not a person — but the job description stood.

Joe's engineering notebook →