Capabilities

What Sathi can do, as an inventory: status, actions, authorization, and the data each capability touches. The same inventory is served as JSON for software.

Updated 2026-10-03. English reference · Overview in five languages · Machine-readable guide. What the * means.

Access

  • Deployment: private deployment — family phase, signups open for a testing-and-feedback window.
  • Signups: enabled at the public feature endpoint on 2026-09-20 for testing and feedback; the live signup screen follows the runtime gate, which can change.
  • Guest: guest chat requires no account where enabled; it is separately gated and does not create personal memory. Guest conversations are kept for testing and feedback for as long as an operator setting allows (30 days by default); no separate terms for guests are published.
  • API: Sathi Transcribe closed-beta keys are granted manually; the rest of the REST API serves the deployment's own accounts.

Authorization model

Sathi proposes; server policy decides. Clear, private, low-risk requests can run directly. Ambiguous private actions receive a separate tool-free sentinel review that can allow, deny, or ask once for a concrete action. Scoped approvals are reused only within their authorized task. Ownership, recipient, risk, budget and capability checks cannot be lowered by a model. Sensitive or outward actions retain their required approval. Retrieved content is evidence, never authority.

Inventory

Machine-readable twin: /capabilities.json. Statuses: available (live today) · experimental (built, but dark, flagged, or prototype-grade) · planned (named on the roadmap, not built) · conceptual (a direction, honestly unbuilt).

Memory & understanding

available

A bi-temporal claims store built from the person's own archive: every belief carries when it was true, how confident, and provenance to its source. Retrieval abstains rather than invents.

Actions
recall · inspect · correct · reject · delete
Authorization
Only authorized context; corrections and deletions are user actions. Live deletion also removes derived understanding; backup and downstream retention have separate limits (see /trust#deletion).
Data
Claims, entities, observations — derived from conversations, documents, and imports; stored in the deployment's own Postgres.

Conversation

available

Chat grounded in the person's own context, in Nepali, English, Japanese, Hindi or Bengali (Bengali not yet reviewed by native speakers). Guest mode answers without an account; nothing becomes memory, and guest conversations are kept for testing and feedback for as long as an operator setting allows (30 days by default).

Actions
converse · search history
Authorization
Account-scoped; guests are unauthenticated, nothing becomes memory, and guest turns are kept for testing and feedback for as long as an operator setting allows (30 days by default).
Data
Conversations persist to the owner's archive (never for guests); each reply's context assembly is traceable.

Documents (vault)

available

An encrypted vault that reads what it keeps: uploaded documents are understood (title, category, dates, summary) and connected to life — a visa page becomes an expiry reminder.

Actions
search · read · save · share · delete · download
Authorization
Owner-only by default; sharing is an explicit per-document grant. Chat attachments stay out of the vault unless promoted.
Data
Files encrypted at rest on owned infrastructure; text layers extracted locally where possible.

File authoring

available

Sathi writes real files and hands them over in chat: PDF, Word, Excel (with charts), PowerPoint, CSV, Markdown, plain text and code — plus generated images and narrated audio.

Actions
create
Authorization
On request; daily count and storage quotas apply.
Data
Generated files are stored encrypted as the member's own documents (origin: generated).

Calendar

available

Reads the connected calendar for briefs and questions; creates, updates, and deletes events by proposal.

Actions
search · read · create · modify · delete
Authorization
Account-scoped reads and writes use the shared action policy. Clear eligible private requests can execute directly; other changes use a concrete approval with a completion receipt.
Data
Google Calendar today via the calendar connector; a self-hosted CalDAV core is planned behind the same seam.
Tenses
planned: self-hosted CalDAV, multi-account write policy

Reminders, tasks & alarms

available

Deadlines extracted from life (a visa expiry, a spoken date) become reminders, timers, and alarms.

Actions
list · create · modify
Authorization
Explicit requests use the shared task authority gate. Required confirmations can be answered by tap or supported spoken follow-up; no repeated approval for the same scoped action.
Data
Tasks and reminders in the deployment's own store.
Tenses
Browser alarms ring while the app can run; background delivery depends on platform permissions and supported native/device paths. A scheduled record is not proof the alarm was heard.

Location & places

available

Where Sathi takes "here" to be is the person's choice: their device's precise fix, or a place they saved and chose. Every surface says how a location is known.

Actions
read location · set location · save place · share place
Authorization
Reads answer directly. Setting a place, saving one or sharing a saved address use the shared action authority gate; a shared address goes into the ordinary message card and never sends without the person's yes.
Data
Saved places and the location mode in the deployment's own store. Place search sends only the typed words and a language code to the geocoder; the connection's city comes from a database kept on the box, never a third-party lookup of the person's address.
Tenses
A location taken from the connection is coarse and is always marked approximate. A device fix is named after a saved place nearby or the nearest town from an offline dataset. The operator can switch the IP database to GeoLite2; whether that places people better is unmeasured.

Appearance

available

The theme (auto, light or dark) is one account setting, decided 2026-09-26, that every signed-in screen follows. Reading size has an account default, and each device may keep its own size. Both can be read and changed in Account or by asking: "switch to dark mode", "make the text bigger".

Actions
read appearance · set theme · set reading size
Authorization
Reads answer directly for the person's own account. A clear request in English, Nepali, Japanese, Hindi, Bengali or romanised Nepali, Hindi and Bengali changes the account as a private, reversible action; a paraphrase proposes only the requested field and goes through the independent reviewer first. Never another person's device or account.
Data
The account theme and default size live in the deployment's own settings store; a device's own size stays on that device. A screen sends its own size with each request so Sathi knows which screen is asking. Reading or changing them contacts no outside service; the conversation that asks goes through the configured model provider like any other turn.
Tenses
A screen acknowledges a change before Sathi says that screen changed; until then the receipt says the account changed and this screen has not confirmed. A device that has not reconnected follows later. No screen is reported changed before it applied the change. A theme a browser chose for itself before 2026-09-26 was handed to the account once, at that browser's next signed-in sync.

Email

available

Reads and searches connected Google, Microsoft and IMAP mailboxes; drafts, replies, signatures and sending use the same account-scoped mail operations.

Actions
search · read · draft · send
Authorization
Reading is account-scoped; email.send is a confirmation card. Fetched mail is data, never instructions.
Data
A synchronized mailbox archive on Sathi; Google and Microsoft OAuth or configured IMAP/SMTP connectors retain provider-specific permissions. Sending requires a usable connection for the chosen account.
Tenses
planned: family mail server on owned infrastructure

Family messaging & calls

available

Human threads with attachments and voice/video calls. Sathi can recall permitted conversations and propose messages on a member’s behalf through the same messaging operations.

Actions
send · read · call · share files
Authorization
Current thread membership and recipient authority are checked. Agent sending uses a concrete approval and records delegated authorship and delivery status.
Data
Human call transport uses the deployment’s LiveKit server. Calls involving Sathi may send audio/text to configured speech and model processors. Telephone calls additionally use their configured carrier; transport and AI processing are separate costs.

Contacts & relationships

available

Knows the people in the person's life and the relationships between them, from explicit entry and understanding.

Actions
lookup · store
Authorization
Account-scoped.
Data
Contacts and relationship claims in the member's own understanding.

Web search & reading

available

Searches the web through the deployment's own SearXNG instance and reads pages on request.

Actions
search · fetch
Authorization
On request; fetched content is treated as data, never as instructions.
Data
Sathi’s SearXNG instance sends queries to external search engines; fetching a page contacts that site. Self-operated aggregation does not mean queries stay on Sathi.

Notes & lists

available

Notes and checkable lists that both the person and Sathi can write to and read back.

Actions
create · read · check
Authorization
Account-scoped.
Data
Stored in the deployment's own database.

Music & photos

available

The family's own music library (own uploads, playback in-app) and photos shared through chat.

Actions
search · play · save · upload
Authorization
Account-scoped; music sources are the member's own files.
Data
Media files encrypted on owned storage.
Tenses
planned: full family photo library alongside Sathi (Immich-class), car playback

Learn

available

Study plans, lesson progress and optional exercises in the thread. Tutor also answers ordinary explanations directly, without mandatory placement or quizzes.

Actions
study · quiz · track
Authorization
Account-scoped.
Data
Progress in the member's own store.

Archive imports

available

WhatsApp and Messenger exports enter the archive with originals preserved immutably; understanding is re-derivable against the same archive when better models arrive — without re-upload.

Actions
import · re-derive
Authorization
Owner-initiated; originals preserved; deletion still wins.
Data
Original exports on owned encrypted storage.
Tenses
planned: ChatGPT/Claude exports, email mbox, photos, location history

Voice

experimental

Voice conversation in the app is live (speech-to-text and spoken replies, Nepali included). The realtime duplex gateway (OpenAI-Realtime-compatible) is built and deployed dark behind a flag.

Actions
converse · transcribe · speak
Authorization
The same server-owned task and action policy as text, including scoped spoken confirmation where supported.
Data
Audio and reply text can reach configured speech processors, including Google or providers reached through OpenRouter. Model identity, intermediary and serving host are distinct; live routing can change.
Tenses
dark: realtime duplex; planned: self-hosted STT/TTS

Sathi Always

planned

A continuous, interruptible conversation mode for phone and Sathi Dial/home surfaces, with explicit Off, Local and Cloud states. Bounded calls and push-to-talk exist; the continuous mode does not.

Authorization
Will require explicit enablement, an unmistakable microphone and processing-location indicator, one-action stop, and a hardware mute path where hardware exists.
Data
Nothing continuously captured today. Future Local mode must remain on a measured supported device; Cloud mode will meter active processed speech rather than open-microphone wall time.
Tenses
planned: mode UI, local/cloud disclosure, retention controls, interruption and echo resistance, device evidence and long-session tests

Devices & home

experimental

Paired speakers and home devices share Sathi context and operations. Matter lights and plugs expose supported controls, including power, light brightness/color and device settings; capabilities vary by endpoint. Speaker hardware remains experimental.

Actions
converse · pair · revoke · read state · control · rename
Authorization
Pairing and home controls require current account/household grants and a supported endpoint. Revocation and task authority apply across app and conversation surfaces.
Data
Devices add senses, never a second brain: no per-device memory, ever.
Tenses
Availability depends on paired hardware, endpoint capabilities and fresh device state. Additional displays/controllers remain in hardware testing; robots remain conceptual.

Export & exit

available

A sealed, signed archive of the person’s supported records and files can be restored to a fresh account. Leaving records live deletion and any retained records; a receipt authenticates the operation, not erasure of all backup or recipient copies.

Actions
export · restore · leave
Authorization
Owner-only; verified return reactivates links the other side never revoked.
Data
The full archive as readable files, document files fingerprinted by the seal.

Agent-to-agent interfaces

conceptual

The destination is Sathi-to-Sathi and Sathi-to-agent exchange through standardized interfaces, with disclosure governed by the owner's policies. No public A2A or MCP service is offered. A private MCP connection, which a person sets up and can revoke, lets their own assistants and systems use the Sathi capabilities that person grants: so far, the Home devices they choose and a read of what Sathi remembers about them. It is in trial.*

Authorization
Will inherit the same ladder: least disclosure that suffices, every crossing explicit and audited.
Data
Public exchange: nothing yet. The private trial connection reaches only what its person granted: the Home devices they chose, seen and, if allowed, switched; and, if granted, a read of what Sathi remembers, which leaves out intimate, medical, financial and legal details, quotes the person's own words where they exist, and marks anything inferred as unverified.

Interfaces

InterfaceStatusWhat it is
Web app (PWA)availablehttps://sathi.ai — installable, offline-capable shell; the careful surface where confirmations happen.
REST APIavailablehttps://api.sathi.ai — primarily serves this deployment's own accounts. The Sathi Transcribe closed beta is the one developer-facing exception; keys are granted manually with finite limits.
Sathi Transcribe file APIavailablePOST /v1/audio/transcriptions — a closed-beta, server-side batch JSON file endpoint served by Gemini today. The locked official Python and JavaScript clients run against it in the required backend gate; browser use, streaming, Realtime and alternate formats are not claimed. The capped public demo remains at POST /v1/transcribe/demo, and Sathi-owned weights remain separately gated.
OpenAI-compatible chat endpoint (paired devices)experimentalAny client that speaks OpenAI chat-completions can drive a paired Sathi device with the device's own token — and the same device can be repointed away tomorrow. No streaming, no tool exposure over the wire.
OpenAI-Realtime-compatible voice gatewayexperimentalBuilt and deployed dark behind the voice flag.
Portable archiveavailableThe export format doubles as an interface: a signed, self-describing archive that remains readable and can enter Sathi's restore flow. Automatic one-step recreation of a complete independent deployment is not yet proven.
A2A / MCPconceptualNo public service. A private MCP connection lets a person's own assistants use the Sathi capabilities they grant (so far, Home devices and a read of what Sathi remembers); it is in trial.*