Libranis documentation · concept

Libranis

The product and the substrate underneath it — one record type, explicit relationships, and an AI that reads only what the caller's scope and authority allow.

Canonical identifier
https://libranis.com/docs/libranis/
Last updated

Definition

Libranis is a relational substrate and a single consumer application in which people, organizations, physical things, places, documents, conversations, commitments, and an AI participant are all held as records of one kind — a libran — and related to one another through explicit, permissioned, dated relationships.

A libran holds identity, current state, provenance, history, and relationships. It remains addressable across changes of owner, service provider, and application surface, subject to transfer and privacy rules. Libranis is published by Maturation Mechanics, LLC.

Purpose

To give the things that make up a person's world one durable place to keep their identity and their story, and to give an AI participant access to exactly the part of that graph the person's current scope and authority allow — no more.

What problem it solves

The record of a single physical thing is normally split across systems that cannot reference each other: the receipt in an email account, the manual in a drawer, the warranty in a PDF, the installation date in a contractor's job system, the service history in a second contractor's job system, the conversation about it in a message thread, the photograph in a camera roll. Each system holds a fragment and none holds the relationship between fragments. When the thing changes hands, nearly all of it is lost.

The same fracture applies to a home, a business, a vehicle, a memorial, a park, an estate, or a project. Libranis holds the entity itself as the durable unit, and holds the people, organizations, documents, work, and conversations around it as relationships to that entity rather than as rows inside separate applications.

What it is not

  • Not a note-taking or inventory application. The unit is a related entity with its own identity and permissions, not a row in a list owned by one user.
  • Not a chatbot with a knowledge base. Ari's context is derived at request time from the relationship graph and the caller's authority. It is not a fixed corpus, and it is not the same for two different callers looking at the same thing.
  • Not a QR-code generator. A code is an address for an entity that already exists in the graph. Generating codes is the trivial part; holding the entity, its relationships, and its permissions is the product.
  • Not an asset-management database. Asset databases are owned by one organization and describe assets from that organization's point of view. A Libranis entity is related to several parties at once, each with a different view, and it survives the exit of any one of them.
  • Not a family of separate products. Libranis is one product with one subscription. Orbitals are experiences inside it.
  • Not a public directory. Records are private by default. Publication is a deliberate act by the party who stewards the record.

Entity types

Libranis holds all of these as librans. The list is descriptive of what exists today, not exhaustive of what the model permits.

TypeWhat it holds
HumanA person's identity within the system. Exactly one per person, permanent, free.
AgentAn AI participant. Ari is an agent libran, instanced per tenant relationship.
ObjectA physical or informational thing: an appliance, a vehicle, a document, a photograph, a tree, a program.
PlaceA stewarded site people visit: a park, a memorial, a church, a trailhead, a rental property.
OrganizationA business, non-profit, agency, or other body that relates to things and people.
RelationshipThe connection between two entities, held as a record in its own right rather than as a field on either side.
ScopeThe region of the graph a conversation or action is bound to.
SessionA bounded unit of one relationship's conversation.
Conversation and utteranceWhat was said, by whom, in which relationship.
MeetingA multi-party conversation with its own membership and its own permission boundary.
Work itemA unit of work related to an entity and to the people responsible for it.
Document and mediaFiles, photographs, and scans attached to an entity.
PlanA published subscription plan. Plans are entities; a subscription is a relationship expressing a plan.
CredentialA way a person proves they are their identity. One identity may hold several.
EntitlementWhat has been purchased. Never required in order to hold an identity or to claim a thing.

Relationships

Relationships in Libranis are first-class records, not fields. Each carries its own permission boundary, its own conversation, and its own dates.

  • Stewardship — who keeps a record, answers for it, and decides what it publishes. Every libran is stewarded.
  • Ownership and claim — who holds a thing now. Transferable; the record continues rather than restarting.
  • Service — an organization's relationship to a thing it installed, sold, or maintains. Survives the organization losing contact with the current owner.
  • Membership — a person's relationship to an organization or a meeting.
  • Containment — a thing inside a place, a place inside a portfolio. Containment is not a relationship in the permission sense; it does not by itself grant anyone anything.
  • Tether — the dated grant of what a party may do with an entity. Authority lives here, not in a role name.

Because a relationship is itself a record with its own boundary, the graph of relationships is the privacy architecture. A meeting is a group relationship with its own boundary; the private side-conversations nested inside it have their own, and are not visible to the meeting.

Capabilities

What Libranis does today, stated as operations rather than as features.

  • Establish a persistent identity for a thing, place, person, or organization, and address it by a stable URL.
  • Attach descriptive state, documents, photographs, and history to that identity.
  • Relate entities to one another, and relate people and organizations to entities under dated, revocable authority.
  • Resolve a scanned code or tag to the entity it addresses, and render a view of that entity appropriate to the caller's authority.
  • Claim a thing that was scanned, transferring stewardship to the person who claimed it.
  • Transfer a thing to a new owner so its record continues rather than restarting.
  • Ask Ari a question inside a scope, in text or by voice, and receive an answer drawn only from what that scope and authority permit.
  • Hold a conversation, a meeting, or a unit of work against an entity, so that the discussion stays attached to its subject.
  • Publish a selected record, or a selected part of one, to people who are not in a relationship with it.

Authority model

Four questions are answered by four different things and are never collapsed into one another.

QuestionAnswered byCardinality
Who you areA core identity — the human libranExactly one, permanent, free
How you get inA credential bound to that identityOne or many, revocable, some borrowed
What you may doA tether into a relationshipMany, each dated
What you have boughtAn entitlementZero or many, never required

Three rules follow, and they are the load-bearing ones:

  1. Identity is not authority. Possession of an identifier — a scan code, a URL, a record id — never implies permission to read private data or to act. Every request is authorized on its own terms.
  2. Authority attaches to an identity, not to an assertion of it. A given sign-in, link, or token is a way of asserting an identity; it does not itself carry authority.
  3. A subscription is never required in order to exist in Libranis. Identity is free. Claiming a thing that was scanned to you is free. What a subscription buys is the ability to create and steward your own things at scale, plus the hub that holds them.

Actions with consequences outside the acting party's own boundary require a person's explicit confirmation at the time. An agent may propose them; it may not complete them unattended. The full list is on Security and consent, and includes ownership transfer, disclosure of private history, communication sent to another party, changes to what another party may do, granting an organization access, deletion, and publishing anything that was private.

Privacy boundary

  • Records are private by default. Nothing becomes public because it exists, because it was scanned, or because someone holds its address.
  • Publication is an act, taken by the party who stewards the record, and it is scoped: a record may publish part of itself and hold the rest back.
  • A visitor is not a user. A person who scans a public marker reads what that marker publishes. They are not enrolled, not billed, and not required to have an account.
  • Different callers see different things about the same entity. The public view of a thing, its owner's view, and a servicing organization's view are three different renderings governed by three different relationships.
  • A name is the discloser's to give. A name disclosed into a relationship flows through that relationship only. A private annotation you make about someone is yours and is never shown to them.

Pricing

Libranis is sold as one subscription that covers every experience in it. Prices are in US dollars, billed monthly, and are what a customer is charged today.

PlanPrice
Personal$3.00 / month
Place — a park, memorial, church, trail, rental, or similar stewarded site$3.00 / month per place
Business$27.00 / month

Extra QR stickers are $0.09 each, one-time, at cost, with shipping passed through at cost.

Three rules govern the rest:

  • A business never funds a customer's subscription. An organization pays $27/month for itself. When it stickers a customer's equipment, that customer pays nothing, and the thing works for them permanently. If that customer later wants to record their own things, they subscribe at $3/month by their own choice.
  • A place stays one place no matter how much is tagged inside it. A park with ten thousand tagged trees, benches, and trailheads is one place at $3/month. Visitors never pay, anywhere, ever.
  • There are no coupons, promotional codes, gift purchases, sponsorships, or free tiers. The price is the price. A non-profit or public-good body is a distinct rate class — $3/month for its headquarters and $3/month per place — rather than a discount applied to another price.

Subscriptions are purchased at get.libranis.com. No other site sells Libranis.

Examples

A water heater. A plumber installs a water heater and applies a sticker. The thing becomes an entity with a model, an installation date, a warranty term, and a service history. The homeowner scans it and claims it — free, no subscription. Two years later they ask it when it was last flushed and where the shutoff is, and it answers. When the house sells, the record transfers with the house and the new owner inherits the history instead of starting from nothing.

A memorial. A cemetery stewards a marker as a place. A visitor scans it, reads the person's story, and listens to it aloud. The visitor pays nothing and creates no account. The family, in relationship with the record, can add to it.

A service business. A plumbing company holds its fleet, its equipment, and its job sites as entities. The trucks answer for their own mileage and service intervals. The questions customers ask of stickered equipment are visible to the business, and the answers it gives are kept.

What is live today

  • iOS application, in beta, distributed through TestFlight. Adding a thing, scanning, claiming, asking Ari in the context of what is on screen, and speaking with Ari.
  • Ari in a browser at libranis.com/ari — answers by text, speaks aloud, and listens. No account required.
  • Scanning and claiming on the web. A scanned code resolves without an application installed.
  • Purchase, receipt, and account surfaces on the web.
  • Meeting records on the web, reachable from a meeting's own link.
  • A public MCP server at https://mcp.libranis.com/mcp.

Not available today: an Android application, a full web application, public write APIs, and autonomous agent actions. Orbitals other than ScanThis are described but not released.

Machine interfaces

PurposeAddress
These definitions, for modelshttps://libranis.com/llms.txt
MCP serverhttps://mcp.libranis.com/mcp
MCP discoveryhttps://mcp.libranis.com/.well-known/mcp.json
Public read-only HTTP APIhttps://libranis.com/api/v1
OpenAPI descriptionhttps://libranis.com/openapi.json
AI cataloghttps://libranis.com/.well-known/ai-catalog.json
Canonical address of an entityhttps://libranis.com/<id>
Address printed on a sticker or taghttps://libran.io/<id>

An entity's address deliberately asserts no kind. A memorial, a business, a house, and a transaction are all addressable, and none of them is an "object", so the address is the bare identifier. Modalities hang off the same address rather than off separate namespaces.

ScanThis · Ari · Orbitals · Primitives · Security and consent

All Libranis documentation