A local research room that keeps AI-assisted work aligned, inspectable, and under your authority.
让长期 AI 辅助研究保持聚焦、可核查,并始终由你裁决。
Sestina is a local, interactive research application for work that lasts longer than one chat. Its Research Room keeps the active question, evidence, decisions, open issues, corrections, provenance, and next safe action in one continuous workspace. Models can propose; only the user can accept, reject, resolve, waive, or change research direction.
Long-running AI research often fails quietly: the question drifts, an old audit is repeated, a suggestion becomes an apparent decision, evidence boundaries disappear, or a polished answer hides an argumentative jump. Sestina turns those failure modes into visible research objects and explicit actions.
| Research need | What Sestina provides |
|---|---|
| Keep the real question in view | A persistent active research line and versioned Research Brief |
| Separate proposals from decisions | A user-only Authority Gate and append-only receipts |
| Know what leaves the machine | Exact, reviewable Context Manifests before Provider calls |
| Challenge an AI assessment | Correction appeals and an independently configured second opinion |
| Compare genuine disagreement | A bounded, mutually blind two-participant deliberation room |
| Resume without inventing context | Project-scoped governed memory, backups, restore, and schema recovery |
flowchart LR
U[User<br/>sole research authority] --> R[Research Room<br/>primary interface]
R --> K[Research Deliberation Kernel<br/>state, rules, receipts]
K --> L[(Local project<br/>.sestina)]
H[CLI · read-only MCP · host adapters] --> K
P[Optional model Provider] -. exact confirmed manifest .-> K
K -. proposal or evidence only .-> U
- Local-first: project state lives in the selected project's
.sestinadirectory. There is no Sestina cloud account, background sync, telemetry, crash upload, or automatic research-content logging. - Explicit outbound context: optional Provider requests remain disabled until the user configures a connection, inspects the exact Context Manifest, and confirms that bound request.
- Fail-closed authority: Provider output, agreement, signatures, hashes, and tool success never mutate research authority.
- Thin integrations: CLI, Skills, MCP, and host adapters expose the Kernel; they do not duplicate its rules. The public MCP surface is read-only.
Read the privacy contract, security policy, and data-flow inventory before using real research material.
The Windows Desktop Preview v0.3.0-g10.6b5dd243
is available now. Download the Windows x64 installer
and run it; the app includes Node and requires no terminal to start. The installer
is unsigned and has no configured production update source. macOS/Linux desktop
downloads and complete native acceptance are deferred for this preview.
The current source defaults to the schema-25 Electron Research Room. pnpm start
opens the desktop app; pnpm build builds it and pnpm package win32 creates a
local installer. Today / Review, Project, Search and Settings share one Kernel.
Old Room/Pilot execution and generic legacy writes have exited the normal public
API and desktop build. Existing history remains readable, exportable and explicitly
convertible to Draft through the Kernel. CLI context and doctor are read-only.
The published Windows package uses schema 25 and exact source 6b5dd243; later
verification and documentation commits on main do not change those released
bytes. The v0.2.0 schema-20 archives remain available. The older capability
examples and archive installation instructions below describe that historical
release; use the desktop instructions,
publication status and
current evidence for the desktop.
The current distribution recipe uses the Sestina product identity and preserves existing settings and credential storage. The 0.3.0 Windows preview retains its source suffix; full three-platform formal release remains separate. Explicit native signing, notarization and production-update inputs are documented in the desktop distribution guide. The same workflow prepares Windows x64, macOS arm64 and Linux x64 artifacts; workflow implementation does not establish that those platforms passed.
The complete post-0.2 restructure is now an accepted product target. It
converges Review, user Authority, canonical state changes, exact outbound
Manifests, persistence, recovery, task-first navigation, and the desktop
lifecycle into one Kernel-owned path. The target distribution is an Electron
desktop application; the current v0.2.0 archive remains a local loopback
research server preview.
This is design authority, not a shipped-feature claim. Read the
acceptance and authority record and its
exact 18-file plan set before post-0.2 implementation work. The existing
installation and limitation statements below remain accurate for v0.2.0.
The supported distribution is an archive, not a native installer. It requires Node.js 24.x and a local browser.
- Open the
v0.2.0release. - Download
SHA256SUMSand the one archive matching your system:sestina-research-room-0.2.0-windows-x64.zipsestina-research-room-0.2.0-macos-arm64.tar.gzsestina-research-room-0.2.0-ubuntu-x64.tar.gz
- Verify the archive SHA-256, then extract it into a new empty directory.
- In the extracted Sestina directory, run:
node start.mjs --version --json
node start.mjs
Open only the printed http://127.0.0.1:... address. Platform-specific details
are in the Windows,
macOS, and
Ubuntu guides.
Preview limits: 0.2.0 has no installer, updater, code signing, notarization, background service, npm publication, or public write-capable MCP. Release verification proves software behavior and artifact integrity; it does not prove Provider semantic quality, research correctness, adoption, or market value.
Prerequisites: Git, Node.js 24.x, and Corepack.
git clone https://github.com/Roblis0n/Sestina.git
cd Sestina
corepack enable
pnpm install --frozen-lockfile
pnpm verify:public
pnpm start
The desktop opens a local project explicitly. A Provider is optional: a saved Draft can continue to a user-confirmed canonical decision entirely locally. The old HTTP server is a historical development adapter, outside the desktop package; its old research writing routes now reject calls.
| Path | Purpose |
|---|---|
apps/desktop |
Default Electron application and native lifecycle |
apps/research-room |
React Research Room and historical loopback adapter |
packages/research |
Research objects and user-authority domain model |
packages/core |
Research Deliberation Kernel and historical readers |
packages/review |
Deterministic and optional semantic review contracts |
packages/storage |
SQLite persistence, migrations, backup, and restore |
integrations/mcp |
Bounded read-only Model Context Protocol adapter |
integrations/skills |
Generated host skill integration |
researchbench |
Synthetic, reproducible development evaluation assets |
docs |
Product, architecture, security, release, and recovery guides |
The accepted post-0.2 product and implementation design is indexed under
docs/product/restructure.
Start with the public documentation index, the product definition, or the architecture overview.
Issues and pull requests are welcome. Use synthetic data only—never attach real research content, project databases, Provider responses, credentials, private paths, or raw logs. See CONTRIBUTING.md, SUPPORT.md, and the Code of Conduct.
Source code and project documentation are available under the Apache License 2.0. Required attribution is in NOTICE, and bundled dependency terms are recorded in third-party notices. The copyright license does not grant trademark rights in the Sestina name or official logo; see TRADEMARKS.md.
The G10 Electron candidate is available from this source checkout. It uses the schema-25 four-entry research interface and is separate from the published v0.2.0 preview. See desktop build and operation and the current verification status. It is not available as a new public Release. Three-platform installation and production signing acceptance are not complete.
The start page includes managed backup/recovery and explicit earlier-settings migration. Settings provides application appearance, OS-encrypted or explicit session-only credentials, installation-specific read-only MCP/Skills configuration, and manual update controls. No trusted update source is configured; checking reports that limitation without sending research data.
