Project case study
Recovery OS
A mode-separated system for public information, individual reflection, and accountable organizational workflow design
Status Live-static public mode with synthetic interactive designs
Recovery OS explores what recovery-oriented software can provide without becoming a monitoring system. The project combines public pages generated from reviewed sources rather than from a live private-data service—its live-static public-information pipeline—with synthetic interactive designs for individual reflection and organizational workflow. Its architecture separates public content, individual control, institutional visibility, and human support rather than blending them into one data model. Public summaries remain source-bound and subject to final-output review. Individual and Organization Mode designs use temporary, non-persistent state and fixed synthetic examples. No live private-data, account, clinical, crisis, scoring, staff-decision, or institutional runtime is currently authorized. The project is as much an exercise in product governance and evidence discipline as it is an interface system.
Thesis
Recovery OS is a mode-separated system for delivering trustworthy public information, supporting individual reflection, and designing accountable organizational workflows without turning recovery into surveillance.
System thesis
Public information, individual reflection, and organizational workflow remain separate by default.
- Maturity
- Architecture diagram — current boundaries
The problem
Recovery environments depend on repeated structure: reliable information, daily orientation, private reflection, clear responsibilities, and communication that can survive stress. Software can help organize those functions, but it can also distort them. A check-in can become a compliance signal. A journal can become an institutional record. A workflow can become a ranking system. An automated response can acquire authority it has not earned.
Generic wellness software often flattens the specific realities of recovery, while institutional software can over-collect data and turn participation into monitoring, compliance, or scoring. A single application with progressively broader access would make it difficult to know what is public, what belongs to the individual, what an organization can see, and which decisions must remain human.
Recovery OS began from a different premise: structure should support agency without converting a person into a monitored object. The product problem is therefore not how to accumulate more recovery data, but how to organize distinct contexts without creating an invisible bridge between them.
The system
Recovery OS uses a mode-separated architecture rather than one shared data model.
Public Packet Mode: live-static public mode, with output generated from reviewed sources rather than live private data. It compiles public information into a canonical briefing used by reading, print, spoken-presentation, and diagnostic surfaces. Public summaries remain tied to their sources and the final rendered packet remains subject to human review.
Individual Mode: synthetic interactive design — no runtime. It demonstrates reflective sequences, journaling, intentions, routines, educational lenses, and privacy-control concepts using fixed fictional examples and temporary page-local state. Reloading clears the state. There is no account, persistence, analysis, memory, transmission, or organization visibility.
Organization Mode: synthetic interactive design and architecture — no runtime. It demonstrates configuration, role and workflow templates, visibility policy, operational accountability, and communication drafting. It creates no tenant, identity, role assignment, workflow record, submission, review queue, staff decision, placement, or analytics stream.
Human support remains outside the present product. The current system does not detect crisis, infer risk, route support, notify an organization, score recovery, or replace professional care.
How it works
Public Packet Mode
The public pipeline separates source fetching, parsing, normalization, freshness and source-quality checks, safety and section fit, duplicate suppression, diversity, optional source-bound summarization, final-output validation, and canonical compilation. Print and spoken views derive from the same accepted selection rather than rebuilding the packet independently.
The operator surface exposes source health, section counts, warning categories, timing, and generation mode as read-only evidence. Those diagnostics do not override the rendered output. A parser or automated test can pass while a packet remains repetitive, stale, thin, or editorially unsuitable, so human review of what will actually be read remains part of acceptance.
When safe source material is insufficient, the pipeline may underfill a section rather than manufacture fluent filler. Optional AI assistance is limited to public, supplied source context and remains behind schema, budget, and output validation. Source-only output remains available as the fallback.
Individual Mode
The Individual design explores optional morning and evening check-ins, a journal, self-review before feedback, intentions, routines, private-accountability concepts, human-support planning, and privacy and control. Current feedback is fixed design copy and does not read or analyze a draft. The person encounters their own review before any feedback surface appears.
Interaction is real enough to evaluate sequence, language, skip and reset paths, keyboard behavior, mobile behavior, and coercion risk, but it is not a private-data application. The temporary controls do not submit, store, transmit, score, remember, or share anything. Consent, deletion, inventory, and export are inspectable interface concepts rather than live operations.
Organization Mode
The Organization design explores how settings, roles, shared tasks, blockers, accountability, and community communication might be represented without turning operational status into recovery status. Fixed fictional examples and page-local state allow the workflows to be reviewed without creating organizational records.
Drafting and visibility previews stop before submission. Accountability examples stop before evidence upload, approval, discipline, or scoring. Organization Mode has no default access to Individual Mode content or activity, and the two designs do not share a hidden user record, memory layer, or analytics stream.
Architecture
Recovery OS is an Astro static application supported by Node-based generation and validation and Playwright-based browser, interaction, print, and deployment evidence. The public system compiles one canonical packet for multiple presentation surfaces and keeps source evidence, transformations, warnings, and readiness distinguishable.
A narrow public packet-history design can retain sanitized public runs and diagnostic state when configured. It is not a private recovery database and provides no foundation for Individual or Organization Mode records. The current synthetic modes contain no network request, browser persistence, telemetry, identity field, or submission behavior.
The safety model is layered. Ordinary public routes retain strict static boundaries. Explicitly marked synthetic routes use a separate interaction contract that permits temporary controls while rejecting persistence, network activity, telemetry, identity, and runtime claims. Cross-mode rules prohibit a shortcut that would join individual reflections, organization workflows, identities, support activity, public packet use, billing, analytics, or AI history.
Automated tests, structural scans, build output, deployment markers, rendered screenshots, and human acceptance remain different kinds of evidence. One does not silently stand in for another, and none establishes clinical, privacy, security, legal, accessibility, adoption, pilot, or launch approval.
Decisions and tradeoffs
Mode-specific boundaries require more architecture and more qualification language than a single privacy claim, but they make visibility and authority inspectable. Public information, individual reflection, organizational workflow, AI assistance, and human support are separated by default rather than connected first and restricted later.
Keeping source material separate from interpretation can produce shorter or less polished public sections when evidence is thin. That tradeoff keeps fluency subordinate to truth. Requiring self-review before feedback reduces conversational immediacy, but it prevents fixed or future automated responses from becoming the first authority over a person’s writing.
Temporary synthetic interaction cannot demonstrate continuity, deletion, consent, or security behavior in a future runtime. It does allow interaction, accessibility, and coercion risks to be examined without collecting private information or prematurely authorizing accounts, storage, AI analysis, memory, or organization workflows.
The system treats unresolved and underfilled states as legitimate results. That refusal limits the appearance of completeness, but protects the boundaries the project is designed to study: what the software knows, who can see it, what authority it claims, and what must remain human.
Evidence and current status
-
Public Packet Mode
The source-backed public briefing pipeline, canonical packet compilation, print view, read-aloud view, and read-only operator evidence are live-static.
Qualification Source volatility and final rendered-content review remain part of acceptance.
-
Deployment evidence
The reviewed commit matched the deployment marker and passed automated deployed-presentation review.
Qualification This does not establish deployment-matched human editorial acceptance of the current packet or broader launch readiness.
-
Mode maturity
Individual Mode and Organization Mode are integrated synthetic interactive designs.
Qualification They have no live private data, accounts, persistence, AI analysis, memory, tenant, RBAC, records, staff decisions, crisis services, billing, analytics, pilot, or operational runtime.
Current status
Public Packet Mode is source-backed and live-static. Individual Mode is synthetic interactive design with no runtime. Organization Mode is synthetic interactive design and architecture with no runtime. No clinical benefit, institutional adoption, privacy certification, security certification, pilot, or launch readiness is claimed.
Responsibility and limits
Mode separation and human authority
Public information, individual reflection, organizational workflow, AI assistance, and human support remain separate by default. The current designs do not create private records, analyze writing, share individual content with organizations, score participation, make staff decisions, or provide crisis or clinical services.
Artifact record
Selected project artifacts
Public Packet Mode
A source-backed daily briefing compiled through editorial and final-output gates.
- Maturity
- Live-static public mode
- Disclosure
- Source-backed live-static public mode; final rendered content remains subject to human review.
Individual Mode
The writer reviews a temporary draft before any fixed feedback architecture appears.
- Maturity
- Synthetic interactive design — no runtime
- Disclosure
- Synthetic design with temporary state; no account, persistence, analysis, memory, or runtime.
Individual privacy and control
Consent, memory, deletion, and export are represented as inspectable concepts, not live operations.
- Maturity
- Synthetic interactive design — no runtime
- Disclosure
- Synthetic design with temporary state; no consent record, memory, deletion operation, export, or runtime.
Organization Mode
Operational status is kept distinct from recovery status.
- Maturity
- Synthetic interactive design — no runtime
- Disclosure
- Synthetic design with temporary state; no tenant, RBAC, workflow record, staff decision, or operational runtime.
Evidence and current status
The maturity map keeps live-static, synthetic, architecture-only, and unauthorized runtime states distinct.
- Maturity
- Architecture diagram — current boundaries
What the project demonstrates
Recovery OS demonstrates that safety architecture can be part of the product rather than a disclaimer added afterward. Its central contribution is a disciplined separation of public information, individual reflection, organizational workflow, AI assistance, and human authority.