One folder. Plain language.
Everything it changes can be put back.

Synod is an assistant for the work on your desk — the spreadsheets, the letters, the scans. You give it one folder; it works in that folder inside a virtual machine of its own, and the rest of your computer is not in there with it.

Describe the job the way you would to a colleague

Fill in a spreadsheet from a stack of forms. Draft the reminder letters and prepare the mail merge. Pull the tables out of forty PDFs. Rename and file a folder of scans. Convert the lot for the archive.

There is no command to learn and nothing to install inside the folder. The window asks for a folder and a sentence, and what comes back is written the same way — no version-control vocabulary appears anywhere in it, because the person doing this work should not have to learn one to keep their documents safe.

Work, then review, then put back

The assistant works in your folder itself, not in a copy you have to approve line by line. What makes that safe is a net with three parts, all of them on your own computer.

BEFORE

The folder is recorded

Every file and every byte, into a private history on your machine, before any work begins. That recording is what the job is judged against, and what every undo returns to.

AFTER

The changes are reported

One card per file, in plain language — including when a job fails partway. Before and after open in your own applications: Word, Excel, Preview.

ANY TIME

Anything can be put back

One file, one folder, or the whole job. A rename undone by either of its names undoes both sides, never half — and an undo is itself recorded first, so it destroys nothing either.

What changed 4 files · enrolment-2026
Modified invoices-2026.xlsx Put back
Created reminder-letters/ Put back
Renamed scan001.pdf → enrolment-form.pdf Put back
You edited covering-letter.docx Put back anyway

A file you changed yourself after the job is a conflict, never a silent overwrite: your newer version is kept, and replacing it is a separate, deliberate answer.

Anything the assistant says about its own work is shown as the assistant's claim. The two versions of the file are the truth.

The granted folder is the only part of your computer inside

Every conversation boots a real virtual machine, and the assistant works inside it. Your other documents, your home folder, and your saved passwords are not kept out by a rule telling the assistant to leave them alone. They are not in there to reach.

One guest runs on both platforms — Virtualization.framework on macOS, Hyper-V on Windows, where a system service the installer registers creates the machine, so nobody has to be given a hypervisor's privilege to run synod. There is no software-only mode: a synod that cannot put hardware between the assistant and the rest of your computer refuses to start rather than run in a weaker one.

Inside
Your folder, and a full office toolkit: LibreOffice, pandoc, OCR with language packs, the Python document stack, a wide font set and complete locales — so a converted letter renders in your own fonts.
Not inside
Everything else on the computer, and every credential. The model is called from your machine, never from the guest, so no key or account token ever goes in.
Forgotten
The machine's own disk is made fresh at every start. Nothing the assistant installs survives a session, and nothing it leaves behind accumulates.

One road out, and we built it

The machine has no network adapter at all. Its only route out is a program running on your own computer that speaks for it: a proxy that accepts an exact list of names on the one secure port, looks each name up itself, discards every address that is not public, and writes down every connection it opened and how many bytes crossed in each direction.

Outward actions draft; they do not send. Email and calendar, when they arrive, will produce a draft in your own mail client — so an outward action becomes real by your hand, in the place you already review things. Nothing leaves on the assistant's authority.

Said plainly

  • Close your documents first. The assistant works in the folder itself, so a file left open in Word while a job runs can be overwritten under you, mid-edit. Synod says so before it starts. The recording bounds that to an undo — the interruption is still real.
  • It can be wrong. An assistant that edits documents can write bad or mistaken content; that is inherent to the job, not a gap left in this one. The report and the undo are the answer, which is why they are the product rather than a feature of it.
  • The list of names narrows where, not what. It says which destinations the machine may reach; it does not and cannot limit what is sent once a connection is open. Nothing here prevents information leaving through an allowed destination. What narrows the risk is that the list is short, every connection is logged, and the only data in reach is the folder you granted.

Built on ral, and on exarch

Synod is not a fork of exarch and not a mode of it: it uses exarch as a library and supplies only what differs — the grant, the persona, the safety net, the machine, and a surface with no jargon in it. Underneath, both products run every action as a program in ral, inside a boundary the model can work within but cannot edit.

Not packaged for download yet

Synod runs, and it is not yet something to hand someone as an installer. The code is in the open, and so is the account of what is finished and what is not.

Built with funding from the Advanced Research + Invention Agency (ARIA).