IRIN · IRINITY

Your agent said
it was done.
Who checked?

IRIN is structured multi-model deliberation you run at home on macOS or Ubuntu. War Room is the face: assigned seats, streamed rounds, evidence checks, a chair ruling. Direct provider transport is the default; Gateway is explicit per-seat opt-in. A separate Sentinel/Watch lane — disarmed by default — can end in a signed Outbox directive, so observation, judgment, and authorization stay separated by design.

Below this line, thousands of events are drifting past. One of them matters.

descend
01Sentinel · Runtime altitude
Watch is cheap.

Sentinels are deterministic watchers: files, queues, feeds, ledger deltas. No model calls, no reasoning, a fire decision in at most 100 ms. They watch, and they never speak.

When observed state crosses a declared line, a sentinel fires: an evidence-based escalation (facts only, no inference), recorded to a hash-chained fire log. That amber trace is one fire, leaving the noise.

The Watch producer ships disarmed by default. Loading or enabling a Sentinel is not arming; a hardware ceremony arms the Gateway Watch producer — on IRIN.app, that ceremony runs from Settings with Touch ID. Arming authorizes paid deliberation; it is not a convenience switch.

watches · never speaks
02Gateway · The governed path
Governance is
opt-in.

Direct provider transport is the default. Gateway is explicit per-seat opt-in — never a silent detour applied to every call. IRIN.app keeps it off until the operator enables it: Settings → Enable Gateway starts an app-owned local pack and proves authenticated readiness before any governed call. On the Watch lane, an escalation that is promoted crosses Gateway: it meters spend against a hard budget, enforces policy, and can write a signed audit-ledger record for that path. The fire that just passed is now inside irin.comms.v0.1: a versioned envelope with a TTL, a budget hint, and a reply address.

Most events stop here. That is what makes the next tier rare.

governs · when opted in
03Council · Deliberation altitude
Thought is rare.

The Council is where reasoning finally happens — and War Room is the room you live in. Multiple frontier models deliberating under a chair, with frame checks, flip-flop detection, budget pause, a convergence judge. The signed IRIN_<ver>_aarch64.dmg installs that room on macOS — pick a cabinet, ask a real question, watch the seats argue and converge. Real deliberation still needs a usable provider transport (API key or authenticated CLI).

The Council speaks, but it never acts. An ordinary War Room run does not create a signed Outbox directive — that is the separate Watch→Outbox lane. Budget and clock are hard stops: closed-loop triage is bounded at 120 seconds; sessions you convene run on your clock. When the Watch lane does triage, the answer is a directive: a named job, a scope, a stop condition, and what must come back.

speaks · never acts
04Signed outbox · The record
The record is final.

The directive is canonicalized, then signed. RFC 8785 JCS bytes, an Ed25519 signature, a signed row in directive_outbox. The companion fire lives on the watch_fires hash chain; each outbox row is individually signed; the governed audit ledger is a separate signed surface. Not a dashboard claiming success: a verifiable artifact that does not trust anyone's self-report, including ours.

The signed record is the product endpoint — no autonomous operator-ready Worker ships. Not every action is recorded or executed.

signed · not executed
Watch is cheap. Thought is rare. Action is final. Each tier earns the next.
The system is the proof. Watch a real council move from live seats to a filed ruling.
A real IRIN War Room proceeding with three model seats deliberating before the chair files a ruling A completed IRIN War Room proceeding showing the seat ledger and final council ruling
Three seats, one real security decision. IRIN streams the arguments, tracks the proceeding, and files the chair's ruling.

Run your first council.

One signed download. No source checkout, no build, no Docker for the core product. Bring a provider API key or an authenticated local CLI — Discover shows what is available before any paid inference call.

1 · Download IRIN_<ver>_aarch64.dmg
2 · Verify check against HASHES.txt
3 · Open IRIN.app the app starts its own local Council
4 · Discover, then deliberate see detected providers, convene a cabinet
macOS on Apple silicon only; Intel Macs are not supported. Pre-release and single-operator. Local-first; the browser War Room from source is also supported on Ubuntu. Direct provider transport is the default. Gateway and Watch are optional governed paths, off until you enable them. Building from source stays in the repository for contributors.