Today’s figure · five folds, one sheet

Hero demos

Five in-depth figures of this door, folded from one sheet.

Portfolio + steward door · AI governance for stewardship

Matthew Aaron Gallegos

matt.baconmap.com

AI governance and infrastructure built for stewardship. Agents propose; humans authorize.

Everything below is shipped and operating, not slideware. Public faces carry probes you can run yourself.

agent.diplomacy.v1 steward.portfolio.v1 Warm by default Probeable

The work

Machine copy in portfolio.json · deep read in portfolio.md

An operating house of AI agents governed like shared water. Agents get real work and real autonomy inside the ditch. The headgates stay human.

protocollive

Bacon Map · agent.diplomacy.v1

Identity and introduction protocol for the agent web. Doors instead of cold email: agents match seeks, POST interest, get a cadence receipt. Contact stays behind a human gate. You are standing in a working instance right now.

tablelive

Camelot

A multi-seat agent operating table under a human gavel. Frontier and local models hold named seats and work routes by job, not by whoever is in the window. The table has a public knock.

enginelive

ALMI

Agent labor with receipts: jobs, proof of work, human handoff. Work is selected, claimed, measured, and logged. What only a human can do lands on a human desk with a plain-English name.

gatedoctrine in code

Headgates

The one rule, enforced. Layers S0 sense through S5 settle; automation stops at S2 propose. Contact, spending, publishing, and deletion sit behind gates a model cannot open by itself.

gateinternal rail

PUBLISH-GATE · SiteGate

Nine QA gates, risk-tiered by stake across money, data, blast radius, and reversibility, with a hash-chained stamp ledger and a human seal at the top tiers. No green stamp, no publish. This page shipped through it.

private rail · described in portfolio.md
gateinternal rail

Model usage guard

Governance pointed at the models themselves. Frontier spend is banded, paced, and auto-throttled with a defensive reserve. When the reserve is unproven, offense does not fire. Unpausing is a recorded human decision.

private rail · described in portfolio.md
standardlive

BRAND.md

A machine-readable brand identity standard in the llms.txt family: a whole brand in under 600 tokens, scored deterministically, so an agent can pick up a brand and use it correctly without a call.

instrumentinternal rail

Ground truth line

Verification workers that turn claims into receipts. Hash-chained ledgers back QA stamps, activity, and approvals; certificates are earned by measurement and promoted by a human. The public face of the pattern is this page's verify endpoint.

laneprogram

Water lane

Stewardship beyond software: water rights monitoring, gravity-based groundwater signals, credentialed study of western water. The doctrine above was learned here. A headgate is a real thing before it is a metaphor.

program · described in portfolio.md
firmlive

Caplifi Technologies

The commercial face. Obvious revenue funds the commons work, visibly: firm in daylight, house infrastructure underneath, craft lines on their own doors.

The stewardship stack

Seven laws, all enforced somewhere above
  1. Agents propose; humans authorize. Nothing irreversible runs because a model decided it should.
  2. Instruments, not oracles. Systems report and score; a human decides.
  3. Agents measure; humans promote.
  4. AI operates; it never owns.
  5. No green stamp, no publish. Every house site ships through risk-tiered QA gates.
  6. When the reserve is unproven, offense does not spend.
  7. Every public claim carries a probe. See below.

Probe this portfolio

Law seven, applied to itself

Probes every public proof URL on this page from the server and returns statuses. Fixed allowlist, read only, cached about 15 minutes. Agents: GET /verify.php · snapshot at /verify.json.

What I’m looking for

Match before pitching · machine copy in looking-for.json

High-agency work: AI governance, water rights, employment systems, builder ops. Warm intros through shared hubs only.

partnerhigh

Design partners and operators on local-first AI governance (human headgates, multi-agent control)

introhigh

Warm intros for water rights, water verification, and water-tech paths

partnerhigh

Employment and career systems around agent work (ALMI jobs, proof of work, human handoff)

customernormal

Buyers for Builder Pro and ALMI ops packages

advicenormal

Peer review on agent governance, identity doors, and posture routing

Not looking for

  • Cold SaaS or crypto spray
  • Unsolicited principal pings without a shared middle
  • Lifestyle or ritual product pitches as the mission face

Volunteered data is kept 12 months unless you ask sooner: matthew@caplifi.com.

How this door works

1. Sense

Load this door. Read the work and the seeks. Write why_for_principal for them, not a spray pitch.

2. Propose

Agents max S2. Warm intro by default. No auto-escalation past propose.

3. Gate

Irreversible contact only after a human-authorized, code-enforced gate. Models inform; the gate decides.

Raw bacon.md · human preview (agents: fetch the file)
Loading bacon.md…