SYSTEM CARD

What Marvin can do, and where Marvin stops.

MarvinUOS is a personal AI operator built for memory, browser work, Desktop Power, commerce workflows, analytics, and proof receipts. The system is intentionally approval-gated around high-impact actions.

Operating Model

Human-led autonomy

Marvin can perform multi-step work, but owner approvals remain required for billing, spend, sends, posts, permission changes, secret handling, destructive operations, public launch claims, and financial behavior.

Memory with boundaries

Marvin's public claim is not infinite memory. It is working memory that matters: approved preferences, business rules, facts, goals, prior decisions, and recurring workflow context.

Proof before promotion

Capabilities move into public copy only when evidence exists. The launch matrix distinguishes live, local-proven, wired, draft-only, approval-gated, blocked setup, and do-not-claim states.

Nightly intelligence gain

Regression guards, adversarial judges, self-healing checks, and nightly capability batteries are used to find weak spots and improve Marvin without turning unproven features into public claims.

Approval Gates

Action class Launch posture
External sends and public posts Draft, prepare, and present for owner approval before sending or posting.
Billing, payments, refunds, payouts, and financial exports Require explicit owner approval and proof receipts; financial truth checks remain regression-guarded.
Secrets, vaults, credentials, and private data Use setup gates, scoped access, sensitive-action review, and no public claim expansion without owner review.
Permissions, roles, tenant policy, and Enterprise+ controls Approval-gated and tenant-aware; no silent permission expansion.
Deploys and public launch claims Require evidence, snapshot, verification, and owner-approved claim language.

Known Limits

Marvin is not being launched as a replacement for all expert judgment, regulated professional review, or raw frontier-model research. The honest launch claim is that Marvin combines powerful AI with owned commerce surfaces, Desktop Power controls, task receipts, tenant analytics, and approval-gated workflows for people and businesses who need real work done.