System configuration
This is not a list of features switched on. It is the architecture of a working environment that has been shaped, corrected, and hardened over months of daily use. One question sits behind every layer: getting a general-purpose model to behave like a trusted senior colleague who already knows the institution, its voice, its risk posture, and its standards, without re-briefing it each morning.
The system is organized as concentric layers: an instruction spine that loads every session, a voice system that governs how anything gets written, an agent architecture for specialist work, an automation layer that runs on a schedule, a memory system that turns corrections into standing rules, and a security layer that keeps the data safe by treating external content as untrusted by default.
A · Operating model
A.1 The four questions. Every substantive output is required to answer: What is happening? Why now? What is at stake? What should happen next? A communications discipline that forces each deliverable to carry narrative, timing, stakes, and a next step.
A.2 The priority stack. Clarity over cleverness. Resonance over volume. Authority over complexity.
A.3 Operating principles. Field-builder posture over org-builder. Institutional staying power over short-term visibility. A five-to-ten-year horizon. Separate fact from inference from speculation, always. Flag reputational and governance risk proactively.
A.4 Quality protocol. Before any deliverable is presented, three checks run: confirm it meets the specific request, name two concrete ways it could be stronger, and surface any assumptions worth flagging.
B · Instruction spine
B.1 A master instruction file auto-loads every session with identity, output discipline, task-planning rules, and the agent-system map.
B.2 Ten governance rule files load every session and cannot be overridden by anything the model reads through a tool.
| File | Governs |
|---|---|
| writing-voice | Voice routing, word blocklists, anti-AI-speak rules |
| data-sensitivity | RESTRICTED / SENSITIVE / INTERNAL classification and child-safety provisions |
| citation-standards | Source attribution, date-flagging, inference-versus-fact labeling |
| version-discipline | Date-stamped naming; never overwrite; increment versions |
| knowledge-capture | Schema and routing for captured external knowledge |
| attachment-authorization | Attaching a file grants read authorization |
| external-facing-review | Pre-publication checklist and link-liveness sweep |
| session-history-lookup | Finding and resurfacing prior sessions |
| autonomous-run review | Protocol for prompts written for long autonomous runs |
| personalization-map | Single index to every personalization asset |
C · Writing-voices
Identification of the appropriate voice based on context (institutional or individual, and email, LinkedIn, or long-form writing), enforced with word blocklists and an anti-AI-speak discipline. Four registers, one router, and the most heavily engineered layer, because writing is the primary work product.
C.1 The router auto-loads every session and routes any writing task to the correct voice before drafting begins.
C.2 Institutional voice, for the organizations and the Fellowship; deliberate antithesis and parallel cadence are on-brand and protected.
C.3 Personal voice, for me as myself, with a separate long-form methodology and an accumulating file of line-edit preferences.
C.4 Creative voice, fiction craft mode, where most anti-tell rules are suspended.
C.5 Mechanical guards: a standing word blocklist of machine-writing tells, structural rules against padded triads and hollow summaries, and dash discipline.
C.6 A craft layer for reports, essays, and opinion writing applies on top of whichever voice is selected; it governs form, not voice.
D · Agent architecture
D.1 Sixteen active agents load every session as the core team; seventy-nine more sit in cold storage, spawned only when a task calls for their expertise.
D.2 The hard rule: never load more than six agents for a single task; capacity is a liability to manage, not a score to maximize.
D.3 The active core: team-dispatcher, grant-writer, philanthropic-strategist, impact-storyteller, brand-designer, presentation-architect, research-synthesizer, ai-safety-researcher, fellowship-coordinator, policy-drafter, coalition-builder, business-developer, session-designer, thought-leader, strategic-comms-creator, quality-reviewer.
D.4 Cold-storage teams: Research Institute (32), Education & Training (10), Consulting Delivery (6), Design (4), Engineering (4), Operations (3), Product (3), Project Management (3), Shared Context (5), plus a reputation-management team.
D.5 Agent Teams: multi-agent parallel work, teammates in their own context windows, peer-to-peer communication, a shared task list.
E · Skills library
E.1 Reusable prompt programs invoked by slash command or fired automatically by keyword.
E.2 By domain: fundraising, voice and reputation, analysis and research, verification, operations, and organizational standards.
E.3 Plus document production (Word, PowerPoint, Excel, PDF), presentation building, data visualization, web artifacts, memory consolidation, and a developer-facing set.
F · Automation layer
F.1 Local scheduled tasks on the Mac: a morning Chief-of-Staff briefing; a news-scan processor; weekly donor-pipeline, fellowship-status, and research scans; a daily playbook-maintenance pass; an end-of-day ritual check; a monthly archive routine; one-time reminders.
F.2 Remote cloud routines on Anthropic's infrastructure, independent of the laptop: a daily news scan and a weekly self-optimization brief that reviews the configuration itself.
F.3 Notifications reach a phone, and a mobile channel is wired in for capture and briefing on the move. Nothing is sent, posted, or published automatically.
G · Memory system
G.1 Two persistent stores: working style, organizational ground truth, and active-session state in one; auto-captured project memory, indexed in a lean file, in the other.
G.2 Four types: user, feedback (corrections and confirmed approaches, always with the reason), project, and reference.
G.3 The verification discipline: a memory naming a file or flag is a claim it existed when written, verified against the live system before it is acted on. The single rule that prevents long-run drift.
H · Security and safety layer
H.1 Pre-fetch URL screening against a malicious-URL feed and request-forgery patterns.
H.2 Command risk scanning before any shell command runs.
H.3 Prompt-injection detection on fetched and scraped content.
H.4 A standing deny list: destructive deletes, privilege escalation, credential access.
H.5 Permission governance: a curated allow-list for trusted reads, a timeout hook for unattended dialogs, and an autonomous-mode declaration affirming child-safety data rules apply to every output.
I · Connectors and external tools
I.1 Workspace: mail, calendar, drive, spreadsheets, and notes; reads and drafts pre-authorized, anything that sends, posts, or deletes requires explicit confirmation.
I.2 Documents and design: word processing, presentations, a PDF toolkit, a design workspace, image and slide generation.
I.3 Data and research: a database connector, a spreadsheet toolkit, web search and scraping, and a document-to-markdown converter.
I.4 Publishing: a social-scheduling connector for managed, reviewed posting.
J · Knowledge and session infrastructure
J.1 Output discipline: every deliverable lands date-stamped and version-named in a project folder; nothing overwritten; names always intelligible.
J.2 A curated session log: a hand-maintained index of every substantive session, each with title, key finding, output paths, and a resume command.
J.3 A unified transcript archive: the full history across surfaces recovered into one keyworded, cross-linked, searchable corpus, kept current by a monthly routine.
J.4 Session rituals: a start-of-session state briefing and an end-of-session ground-truth diff proposed for approval.
J.5 A model advisor recommends the right model and effort level for each session's first message.
K · Environment settings
Long transcript retention with auto-delete disabled; auto-memory enabled; multi-agent teams enabled; additional trusted working directories so partnership and consulting files are reachable without re-permissioning.
What this configuration is for
The point of all of it is leverage with judgment. Each layer removes a category of repeated work, so attention goes to the decisions that actually require it. The security and data-sensitivity layers exist because the work touches child-safety material and cannot afford a careless output. The memory and archive layers exist because an institution being built for a decade should not lose what it learned last week. The configuration is, in effect, an argument that a single operator can run a serious multi-organization enterprise at a standard usually reserved for a much larger team, provided the operating environment is engineered with the same rigor as the work.
Roles generalized for sharing. This page was drafted with AI assistance, directed and edited by John Zoltner. Companion pages: Overview, Full report, and Responsible & safe use.
