How it works
Nothing at runtime is invented.
Joyce is built out of restraint rather than capability. Everything she can do was deliberately written and typed; everything that happens is a lookup against something a person said. That constraint is the product, and it is what the interesting engineering is about.
Your instructions
Help, on
your terms.
What you asked Joyce to watch.
When soccer is cancelled, tell me.
Active
Two weeks before a birthday, tell me.
Active ยท Tell me
A closed vocabulary
There is a fixed set of things Joyce can do and a fixed set of things she can watch for. Neither grows at runtime, and neither grows as a side effect of adding something else โ widening either is a deliberate edit in two separate places, so it is a decision somebody made rather than a capability that appeared. If you ask for something outside the set, she says so instead of improvising.
One hop
Something happens, the standing orders watching it fire, and whatever those orders write may set orders off once more. Then it stops. Orders react to changes and orders make changes, so a pair of them can feed each other forever; the only thing between that and somebody's phone at two in the morning is a depth limit of one. It is not a placeholder for a larger number.
Exactly once, and on the edge
Every firing happens exactly once, even when the thing that triggered it keeps being true. That guarantee is a database constraint rather than a check in the code, because checking and then acting is correct right up until two writes land in the same millisecond โ and being told the same thing twice is the one failure this product cannot afford.
Watches fire on the edge: the moment a condition becomes true, never for as long as it stays true. A product that tells you every minute that something is still overdue is a product you turn off.
Nothing is deleted
A cancelled match is struck through, not removed. Something that vanishes the moment it is cancelled is indistinguishable from something the app lost โ you go looking for Saturday's practice, find nothing, and have no way to tell "called off" from "never saved".
Where the model sits, and where it does not
A language model turns what you said into a call to one of those typed capabilities, and helps shape a standing order while you are setting it up. That is the whole of its authority. It never decides to contact anybody, never spends anything, never commits you, and never changes a rule you approved. It also never chooses how far an order goes โ every order begins at "just tell me", and raising it is a tap a person makes.
The clock is ordinary code. Nothing Joyce tells you at seven in the morning came from asking a model what it thought.
What deliberately does not exist
- Any way for Joyce to send a message to another person.
- Any way for her to spend money.
- An open-ended tool that does whatever a model asks of it.
- A rule that fires on a level rather than on an edge.
- A destructive delete.
- A setting that lets her act without a person having said so.
She is measured on whether she wires these things up correctly from the way people actually talk โ against known-correct answers, with wordings held back so she cannot be tuned to the test. The interesting results are the ones where the harness was wrong.