Midas 1 · the machine

An operations system that happens to be intelligent.

Before anything leaves the firm, the machine stops and waits for a person. The AI inside is one part of it, the way a database is part of your accounting system.

The machine

One sealed box, and it is yours.

Midas 1 on black, low-key warm side light, three-quarter view
Midas 1 on black, low-key side light, dust-free, three-quarter view, no props, no hands
6.7 petaflops

AI speed, both graphics processors combined

64 GB
Memory for the AI itself
128 GB
Working memory for everything else the machine does
4 TB
Stored twice inside the machine, plus an encrypted backup in your office
8–15
Jobs running at once

Memory, storage and user figures are the shipping configuration. Throughput ranges are observed on deployment-representative workloads and vary with document size and portal latency. AI performance is quoted as FP4 Tensor throughput with 2:4 structured sparsity, aggregate of two RTX 5090 GPUs (3,352 AI TOPS each, per NVIDIA's RTX Blackwell architecture whitepaper); ≈1.7 petaflops at FP8 dense.

The run record

Replay any run, step by step, after the fact.

One finished run: what set it off, where it stopped, who said yes, and what came out the other end. A second screen tells the other half of the story — the record of everything that has ever left the building

RUN #4,812 · CANDIDATE PACK → CLIENT Tue 10:14 HKT · 6 steps · 04:41 elapsed · 1 approval

Run trace

STEP 01 · 10:14:02 HKT · TRIGGER

NONE YET

What started the run

            trigger: workflow "candidate_pack_to_client" v4
source:  recruiter action — pipeline stage moved to "client review"
role:    Head of Compliance · Meridian Partners
queue:   position 2 of 14 · admitted 10:14:02
          

Every run starts from an orderly queue, not from a chat message. What started it is always written down.

Run #4,812 opened Browser identity: ROY-4812-a Audit trail: writing

1 / 6

STEP 02 · 10:14:19 HKT · LOCAL

NONE YET

What the machine looked at

            11 passages from 4 documents, all resident on the box:

  · CV — Raman, P. (2024-11).pdf            p.1–2
  · CV — Cheung, W. (2025-02).pdf           p.1, 3
  · Meridian — role brief.docx              §1–3
  · Firm template — candidate pack.dotx

retrieval: BGE-M3 · Qdrant · in-memory · 380ms
          

All of this reading happens inside the machine. Nothing is sent anywhere; it is how the machine knows what it is doing.

Local · 0 bytes out 11 passages · 4 documents

2 / 6

STEP 03 · 10:16:04 HKT · BROWSER SESSION

APPROACHING

The machine working the portal, under its own named account

            session ROY-4812-a · isolated profile · no shared cookies

10:16:04  open   client portal → submissions
10:16:11  read   role reference MRD-118 confirmed
10:16:29  fill   candidate fields from local record
10:17:02  fill   attachment: pack draft (on-box render)
10:18:41  halt   submit is a gated action — not clicked

frames captured: 37 · replayable below
          

Each job signs into the portal under its own named account, so work for one client never mixes with another.

Frames: 37 · retained on-box No click on submit No credential shared

3 / 6
Action boundary

STEP 04 · 10:18:41 HKT · HELD AT GATE

HELD

Where it stopped and asked a person

            action:   submit_to_client_portal + send_pack
verdict:  HELD — external submission requires approval
enforced: server-side gate, outside model context
held for: Priya Wong, Director — Compliance

artifact ready for review:
  candidate_pack_MRD-118_v1.pdf  · 3 claims cited
  faithfulness gate passed · 0 orphan citations

elapsed in queue: 00:26 before approval
          

The stop is built into the machine itself, not written into the AI's instructions. The run has no way around it and cannot argue with it.

Board state: waiting for you Nothing submitted Nothing sent

4 / 6

STEP 05 · 10:19:07 HKT · APPROVED

RELEASED

One tap, recorded against a name

            approved_by: Priya Wong · Director, Compliance
method:      run board · single tap · on-premises session
reviewed:    candidate_pack_MRD-118_v1.pdf
scope:       this run only — approval is not a standing grant

10:19:09  submit  client portal · accepted, ref MRD-118-S3
10:19:14  send    pack to client contact · logged at egress
          

Approval covers this run only, is recorded against a person's name, and stays in the record. There is no blanket yes.

Approver: named Egress: 1 logged send Run resumed: 10:19:09

5 / 6

STEP 06 · 10:19:22 HKT · COMPLETE

CLOSED

What the run produced

            artifact:  candidate_pack_MRD-118_v1.pdf (on-box render)
filed:     CRM · opportunity MRD-118 · stage "with client"
sent:      1 recipient · approved · logged
trace:     6 steps · 37 frames · 1 approval · retained
total:     04:41 elapsed · 03:12 unattended
          

The full record stays on your premises and can be handed to an auditor. Nothing is pieced together after the fact.

Run #4,812 closed Audit trail: complete Exportable: yes

6 / 6

10:16:04 · session ROY-4812-a · client portal · read

10:18:41 · session ROY-4812-a · halted at gate · nothing submitted

An illustrative example — no client data. The structure is exactly what a real record looks like. Every run on a client's machine keeps the same record, stored in your own office and ready to hand to an auditor.

Where it stops

The stop is built into the machine, not written into the AI's instructions.

Runs alone

  • Shortlisting, reading documents, tidying records
  • Chasing references and licence checks
  • Drafting from your templates, on the machine itself
  • Matching CRM records against your accounting system
  • Reading files overnight and preparing summaries

Twenty-three of the thirty-one shipped workflows. See the atlas →

Stops for a person

  • Anything sent, submitted or saved outside the firm
  • Compliance and eligibility decisions
  • Offer figures and negotiating positions
  • Rejecting a candidate
  • Any change to a system you have marked as protected

It cannot be talked out of stopping, and only an administrator at the machine can change where a stop sits.

Knowing its limits

What not to hand it.

These are the jobs it prepares but must hand to a person — and the jobs it should not be given at all.

  • Final judgement about a person. It gathers the evidence and stops.
  • A legal or regulatory position. It drafts from your precedents; it does not invent a position for you.
  • Questions your files cannot answer. It says so rather than guessing.
  • Arithmetic that moves money, unchecked. Figures come from your records and are checked by a person — never worked out freehand.
  • Anything that must leave the building without a person. There is no such job on this machine.

How it arrives

Runs in week one. Compounding after that.

01

Week one — install and read in

We install it in your office and connect your files, portals and CRM. The first workflows run quietly alongside your team, so you can compare before anything goes live.

02

Month one — the library live

Thirty-one recruitment workflows up and running, the stopping points agreed with your compliance lead, and the board up on the wall.

03

From month three — it learns

Your team's corrections teach it overnight, on your own machine. Each improvement is tested before it is used, and deleted if you ever leave.

Specification

Before your IT team asks.

Orchestration 8–15 agent runs in parallel, 1–2,000 tasks a day, each run under its own browser identity against templated per-portal task flows. Complete audit trail per run.
Approval gates Server-side, per workflow, in front of every send, submit and external write — the stop is built into the machine itself, and the AI cannot skip it. Configurable only by an administrator on the box.
Compute Dual RTX 5090, 64GB VRAM. 16-core CPU, 128GB RAM.
Enclosure 4U, tamper-evident. One network port, one power inlet, nothing else. 1.8 kW peak, 61 dB(A).
AI performance 6.7 petaflops¹
Storage 4 TB mirrored NVMe — everything is stored twice inside the machine — plus an on-site encrypted backup, keys held by you.
Retrieval BGE-M3 embeddings tuned for mixed English and Traditional Chinese, Qdrant vector store, fully memory-resident. In plain terms: how the machine reads and finds things across all your files, in both languages.
Model Open-weight instruction model, ~27B class, served locally — the AI itself lives on the machine, weights on your disk. A component, not the product.
Interactive load 10–20 concurrent users at sub-two-second responses alongside the run queue, with an overnight batch layer.
Hybrid Reasoning Off by default. Enabled per workflow, by you, for reasoning-heavy steps inside a run.

Memory, storage and user figures are the shipping configuration. Throughput ranges are observed on deployment-representative workloads and vary with document size and portal latency. AI performance is quoted as FP4 Tensor throughput with 2:4 structured sparsity, aggregate of two RTX 5090 GPUs (3,352 AI TOPS each, per NVIDIA's RTX Blackwell architecture whitepaper); ≈1.7 petaflops at FP8 dense.

Rear elevation of Midas 1 — one network port, one power inlet, one tamper seal, nothing else
One port, one inlet, one seal.

Watch a run work your portal with the internet cable unplugged.

Half an hour, no slides. Bring the work you'd give a capable new hire.