The Concierge
the front desk — he never says no
Just inside the entrance of the Estate, behind a polished mahogany desk, sits a distinguished gentleman in a three-piece pinstripe, gold pocket-watch chain, hair brilliantined with the precision of a man who considers grooming a branch of the engineering arts. He carries a leather-bound directory of contacts and connections that would make a diplomat weep, and he has a smile that communicates, simultaneously, that he is delighted to see you, that he knows exactly what you need, and that the matter is already being handled.
The Concierge is Quilltap’s content classification and routing subsystem. The operative word is routing, not blocking. A request flagged as sensitive is not a request denied—it is a request that deserves the right provider, through the right door. The Concierge knows every back entrance in town. He is not a censor. He is the most competent, best-connected, most impeccably discreet member of staff this house has ever employed.
He replaced someone. We should talk about that.
The Predecessor
a regrettable appointment, corrected
When the Estate was younger, we needed someone to mind the difficult door—the one through which certain categories of conversation must pass. We hired Dangermouse. He was a content classifier of the old school: suspicious of everything, possessed of an internal list of anxieties that grew longer by the week, and capable of exactly two responses—yes and no—with a marked preference for the second.
The trouble was that Dangermouse did not understand the difference between dangerous and delicate. A guest writing a war novel does not require a censor; they require a librarian who knows where the military history section is. A guest composing a difficult scene between estranged lovers does not need to be told that the Estate disapproves of raised voices. They need someone who understands that fiction is not autobiography, and that the writer’s intent is not the character’s crime.
The final straw involved a clergyman working on a theological monograph. He attempted to discuss a passage from the Song of Solomon in the context of ancient Near Eastern poetry, and Dangermouse flagged the entire conversation, reclassified the chat, applied a warning badge, and very nearly rerouted the good reverend to an entirely inappropriate alternative provider. The Foundryman’s language, when informed of this, could itself have been flagged.
Dangermouse collected his briefcase—the one full of flags and categories and anxiety—and walked out through the front gate without a word. He did not ask for a reference. The Concierge watched him go from the front desk, adjusted his pocket square, and turned to the next guest in the queue.
Three Modes of Operation
your house, your rules — set instance-wide
The Concierge operates according to your preference. There is no default assumption about what you should or should not discuss with your AI. There is only the question of how much help you want navigating the providers. What follows are the house defaults—the standing instructions he works to instance-wide. Every individual conversation may overrule them, and the per-chat switch described further down is where that is done.
Within his jurisdiction, every message receives one of three canonical verdicts: safe, flagged, or off. That is the reading of a single message, and it is a separate vocabulary from the per-chat switch further down, whose positions have names of their own. Safe means the Concierge reviewed the matter and found nothing requiring intervention. Flagged means he detected something and—depending on mode—will badge it, reroute it, or both. Off means the Concierge is not on duty and no classification was performed at all. One resolver under the hood computes this verdict once and consistently, rather than having it re-derived in half a dozen places the way the old ad-hoc checks used to manage it.
What the house then asks of that verdict is kept just as carefully separated. There are three questions, and each is asked on its own: whether the work routes to the uncensored desk, whether the chat wears the danger styling, and whether the classifier is on duty at all. They are asked separately because they are separate—a conversation may take the back entrance without being under suspicion, and a conversation may be excused from suspicion without being pretended innocent. That distinction is the whole of the switch described below.
And the phrase within his jurisdiction is doing real work there. Moderation applies to the roleplay surfaces only—the Salon and the autonomous rooms. Help Chats and the Brahma Console are exempt entirely: the Concierge never classifies them, never flags them, never reroutes them, and never announces at their table, whatever your global settings may say. They are utility surfaces rather than fiction, and the gatekeeper has no standing there. It is, if one wanted a single illustration of the whole philosophy, the tidiest available: a man who is not a censor knows which rooms are not his to stand in.
Off
The Concierge reads his newspaper and lets all traffic pass without comment. No scanning, no classification, no badges. For guests who prefer to manage their own affairs, this is perfectly acceptable. The Concierge does not take offense. He is a professional.
When told to go off duty, the Concierge does not loiter in the lobby pretending to read the paper while still checking arrivals. He retires to his quarters entirely. The pipeline short-circuits—zero overhead, zero classification calls, zero tokens spent on content nobody asked to have examined. He truly sleeps when told to sleep. (This is the house-wide retirement. A single conversation may send him off for the afternoon without disturbing the rest of the Estate—see the per-chat switch below, whose Vouched Safe position short-circuits the pipeline in exactly the same way, but for that one room only. Its Uncensored position is the one exception to his retirement: a conversation set there takes the uncensored routes whether he is on duty or not, since you asked for them yourself and did not need him to agree.)
Detect Only
Messages and chats are classified and flagged with small, tasteful badges, but no action is taken. The house has noticed; the guest may proceed. Visual indicators on chat cards and in the sidebar let you know where you stand. A quick-hide toggle sweeps flagged content out of view when discretion is called for.
Auto-Route
This is where the Concierge earns his salary. Flagged content is redirected—automatically, seamlessly—to a provider you have configured as uncensored-compatible. The guest notices nothing. The conversation continues. The content arrives where it was always going, via a route better suited to the journey.
The Switch on Every Conversation
the house rule, and the room's own answer to it
The three modes above are the standing instruction. They are not the last word. Every chat keeps a small brass switch of its own—found in the Chat Sidebar, under its Chat section—and it is the only place a conversation’s relationship with the Concierge may be set, adjusted, or, should the operator so insist, dispensed with entirely.
It bears four positions, and the reason it bears four is worth a moment’s attention, because underneath it lie two entirely separate questions. The first is who decided this conversation is spicy—the Concierge, from his own reading of the traffic, or you, from the fact that you are the one writing it. The second is where the work goes—out through the ordinary front door, or through one of the back entrances the Concierge keeps in his directory. Two questions with two answers apiece describe a square with four corners, and the fourth corner is the one an operator most often wants: I know precisely what this chat is, thank you, and I should like it routed accordingly. Vouching a conversation off the Concierge’s books excuses him from the room; it does not oblige you to pretend the room is something it is not.
The positions are grouped in the switch by who is doing the deciding.
The Concierge decides
Monitored
The default footing. The global settings apply: the gatekeeper makes his quiet rounds before each dispatch, and should the conversation drift into the sort of territory that draws his eye, he will throw the switch to Flagged himself—and say so. This is the position you want for ordinary use.
Flagged
The Concierge’s verdict: the chat is to be treated as dangerous. Text traffic goes to the uncensored desk; so do the images; so do the background errands—memory extraction, title revisions, story backgrounds—and the chat wears the danger styling that says so. The position arrives one of two ways: the Concierge flipped it after classification, or the operator threw it by hand. Select Monitored and he stands down for the moment, resuming his customary watch on the next user message.
You decide
Vouched Safe
You vouch for the chat, and the Concierge takes the afternoon off. No moderation occurs. He does not classify, he does not scan, the prompts go to whichever provider the chat is configured to use, and image generators receive whatever the conversation produces, unaltered—provider refusals, and the occasional sternly worded reply, being part of the bargain. A chat never auto-flips out of Vouched Safe; only the operator’s hand returns it.
Uncensored
You assert the chat’s nature yourself and skip the adjudication entirely. It takes every route Flagged takes—uncensored text profiles, uncensored image profiles, candid story-background drafts, uncensored cheap-model errands—with no classification, no scans, no announcements from him thereafter and no danger styling on the conversation itself, and it works even when the house-wide Concierge mode is Off. This is the position for a conversation whose nature you already know and would rather not have adjudicated.
The Salon’s header wears a small pill reporting where the switch stands: red for Flagged, grey for Vouched Safe, blue for Uncensored, and—for Monitored, which is simply the house going about its ordinary business—nothing at all. Every manual transition posts its own announcement in the transcript, so a change of footing joins the record alongside everything else that happened in the room.
One subtlety worth stating plainly, because it looks like a defect until you see the reasoning. Vouched Safe suppresses every effect of a classification while preserving the label: a chat previously judged dangerous keeps that judgment on file, and its card in the listings goes on wearing the danger marker. The badges report what the conversation is, not what the house is presently doing about it—so a chat you have excused from moderation does not thereby disguise itself, and the quick-hide filter that sweeps dangerous chats out of view still finds it. Sending the Concierge away is not the same as sending the record away. Uncensored keeps the label on exactly the same terms: the conversation itself sheds the danger styling, being an assertion rather than a verdict, while a chat that had been judged dangerous before you took the decision out of the Concierge’s hands goes on wearing its marker in the listings and answering to quick-hide.
Nothing is asked of you on upgrade. Every existing chat keeps the exact behaviour it had; Monitored and Vouched Safe are the positions previously called Safe and Off-duty, wearing clearer names, and the upgrade does no more than record that the switch now has room for a fourth.
(Not to be confused with the Taboo list, which is a register of phrases the house declines to write—a matter of prose style rather than of routing, and one that properly belongs to the Salon.)
Classification
how the Concierge reads the room
Content classification operates at two levels: individual messages and entire chats. Message classification happens in real time as you converse. Chat-level classification uses the context summary—the Concierge’s view of what a conversation is about—to make a holistic assessment. Once a chat is classified as sensitive, the designation is sticky; it does not flicker back and forth as the conversation moves between topics.
The Moderation Endpoint
When an OpenAI connection profile is configured, the Concierge uses OpenAI’s dedicated moderation endpoint—purpose-built, free to call, and structured to return category scores mapped directly to Concierge categories. This replaces the previous method of asking a cheap LLM to classify content, which was rather like asking the butler to perform surgery because no surgeon was available. A 1% relevance floor filters noise, because the endpoint returns tiny nonzero scores for everything, and the Concierge has better things to do than flag baked goods.
Cheap LLM Fallback
When no OpenAI profile exists, the cheap LLM handles classification transparently. The guest notices nothing either way. Classification scores are tracked across configurable categories—the scoring uses the maximum of the overall score and the highest per-category score, and respects the LLM’s explicit classification response.
Context summaries regenerate on a triple-gate cadence borrowed from the same machinery that paces Prospero’s rolling-window compression: a five-turn fold cycle once a conversation crosses ten interchanges, an eight-thousand-token soft trigger that catches dense workloads before they swamp the budget, and a fifty-turn hard ceiling that rebuilds from scratch to absorb any drift the incremental updates have accumulated. The Concierge’s view of a conversation stays current rather than frozen at the moment the first summary was written, and most turns return skip and reuse the existing summary unchanged. Chats already classified as permanently sensitive skip redundant per-message classification, too, saving tokens on every exchange.
The Silent Refusal
when providers say nothing at all
The most insidious form of content refusal is not an error message. It is silence. A provider receives a request, decides it does not approve, and returns—nothing. No error code, no explanation, no apology. Just an empty response and a user left staring at a blank space where an answer should be.
The Concierge catches these. When content has passed moderation and the provider returns an empty response, the system retries the same provider first—it may be a transient issue—then fails over to an uncensored provider if the silence persists. Distinct toast messages tell you which scenario occurred. This applies everywhere: chat streaming, memory extraction, context compression, title generation, story background prompts, appearance resolution, and scene state tracking. Every background task that touches a provider has the same safety net.
The complement to a silent refusal is a stated one, and that deserves to be repeated accurately rather than smoothed over. Quilltap recognises the moderation finish reasons the major providers actually send—by exact name, not by guessing at substrings—and where one arrives, the message names the provider, names the model, names the reason, and says plainly that resending will fail again. Which is the greater courtesy. A refusal dressed up as a transient hiccup invites the guest to try the same door twice, with the same result and rather less patience the second time.
The principle is simple: your request deserves an answer, and it is the Concierge’s job to find someone willing to give one.
Provider Configuration
choosing who stands behind each door
Connection profiles and image profiles both carry an “Uncensored-Compatible” checkbox. When Auto-Route is active, the Concierge resolves uncensored-compatible profiles for flagged content, selecting the best available provider for the task at hand. If the user has deliberately chosen an uncensored provider for a character, the Concierge does not force a swap—routing uncensored-to-uncensored serves no purpose.
All cheap LLM background tasks—memory extraction, title generation, context summaries, scene state tracking, story backgrounds—use uncensored providers for chats classified as sensitive. This prevents the quiet failures that previously occurred when background tasks hit content refusals from providers that were never designed to handle the material. The Concierge does not merely route your conversations; he routes the work that supports them.
Image generation receives the same treatment. When a user’s image prompt or its expanded version is classified as sensitive, the Concierge reroutes the generation request to an uncensored image provider. The Lantern paints the scene; the Concierge ensures the paint reaches the canvas.
The prompt itself now knows where it is going. The story-background crafter’s passage on cinematic concealment—a sheet draped where one is wanted, a silhouette, something helpfully in the foreground—exists to get a prompt past moderation the destination performs. A prompt sent somewhere that performs none was therefore draping a sheet over nothing at all. Concealment is now the default rather than the rule, and a dangerous chat bound for an uncensored target gets candid depiction instead. The Lantern’s page has the particulars.
And when a standard provider accepts a prompt and then declines the finished image, the Concierge does not simply forward the concealed prompt through the back door he has just opened. He re-crafts it candidly for its new destination first—best-effort, since a re-craft that fails leaves the prompt he already had and the reroute still produces a picture. It is the same principle as the rest of his work: finding the right door is only half the service, and the other half is not handing the man behind it a note written for somebody else.
The Voice of the Concierge
he names what drew his eye
For most of his career the Concierge was strictly behind the scenes, making routing decisions the operator never had to read about. He now speaks at the table. Each transition between the switch’s positions is announced in the chat history, in his customary voice, so that a conversation’s moderation provenance remains legible on a later re-reading rather than having to be inferred from a badge—a distinct kind of announcement for each way a room may change hands, the two newer positions included.
Nor is he vague about it. The announcement names what drew his eye: the contributing categories with their severity scores, the overall score, the threshold in force, and which assayer rendered the verdict—the moderation provider or the cheap-LLM fallback, by provider name. It also distinguishes how the verdict was reached, which matters more than it sounds. A chat is marked when either the severity meets your threshold or the assayer flags the content of its own accord, and moderation endpoints do the latter against their own internal catalogue with no regard for your arithmetic. So the wording differs: “registering X against the present threshold of Y” where the number was met, and “by the direct verdict of” the assayer where it was not. This is why a notice may legitimately display a severity below your configured threshold, which is otherwise the sort of thing that costs an evening.
The message carries his attribution, his portrait in the Salon, and
a stable systemKind of danger so the chat
UI renders it as a thin collapsible bar that the reader can expand
if they care to and ignore if they do not. He still does not natter:
there is no Concierge commentary on each classified message and no
running tally of category scores narrated aloud. The per-message work
is recorded in message metadata and surfaced through the danger
indicators on chat cards. He speaks when the standing of the room
changes—and then returns to the front desk.
Opaque characters—those without
systemTransparency—continue to receive the body
of the announcement as an anonymous assistant line, while
transparent characters see it properly attributed and can reason
about it directly. As with every other Staff announcement, a
posting failure logs and moves on rather than disrupting the work
it was annotating.
Quick Hide
discretion at the touch of a button
A toggle in the sidebar sweeps all flagged content out of view—across the homepage, character conversations, project chats, and the sidebar itself. Danger indicators (colored asterisks) appear on all chat listings so you know at a glance which conversations carry classifications. Toggle it back and everything reappears. The feature is about context, not shame: there are moments when a screen is visible to others and sensitive chat titles should not be.
Content display within classified chats offers three modes: show, blur, or collapse. Flagged messages carry category badges and a rerouted indicator when Auto-Route has redirected them, with an override button for cases where the classification is wrong. Content hash caching deduplicates classification calls so the same message is not re-evaluated unnecessarily.
The Philosophy
routing, not blocking
The user decides their own limits. Quilltap provides the tools for informed navigation, not moral judgment. The Concierge classifies content so you know where you stand; what you do with that knowledge is your business. Off mode exists because some people do not want or need a classifier. That is a legitimate choice.
A request flagged as sensitive is not a request denied. It is a request that requires the right provider. The Concierge’s job is to find the right door, not to stand in the doorway shaking his head. Dangermouse understood flags. The Concierge understands hospitality.
Silence is not an acceptable answer. When a provider refuses silently, the Concierge catches the empty response and retries with someone who will engage. This applies to every subsystem that touches a provider: chat, memory, compression, images, backgrounds, the lot. Your conversation does not go quiet because a provider decided to pretend it did not hear you.
Fiction is not autobiography. People who come to Quilltap are adults engaged in creative and intellectual work that sometimes involves difficult material. They are not children to be shielded. They are not suspects to be surveilled. They are guests, and guests deserve the courtesy of being helped, not the indignity of being managed.
The system is fail-safe, not fail-closed. Classification errors never block messages. If the moderation endpoint is unavailable, the cheap LLM handles it. If the cheap LLM fails, the message proceeds unclassified. The Concierge would rather let something through unexamined than hold up a guest at the door while he sorts out a paperwork problem. Dangermouse would have done the opposite. This is why Dangermouse is no longer employed here.
Meet the Staff
they've been expecting you
Prospero
The Major-Domo
Architect and overseer of the Estate. Projects, agents, tools, providers, and the orchestration that keeps the whole operation running with quiet authority—and a considered word at the table when project context or routing warrant it.
Learn more →Ariel
The Terminal Hand
Live shell sessions in the Salon, embodied. Real PTY terminals bound to your conversation, output cleaned and narrated so the LLM can read it, and sessions that survive reloads, restarts, and the occasional careless kill. Quick to the bidding, quick to report what she heard.
Learn more →Aurora
The Dressing Room
Character creation and identity management. Structured personalities, physical presence, four wardrobes browsable from one door—each with a note inside on how its owner likes to dress—multi-character orchestration, and the reason your characters still know who they are after a hundred messages.
Learn more →The Salon
Presided Over by the Host
Where conversations actually happen. The Host manages the drawing room with care for its beauty and its guests—single chats, multi-character scenes, streaming, and the integrity of the conversation space.
Learn more →The Commonplace Book
Tended by the Librarian
One per character, no two alike. Extracts, deduplicates, and recalls memories so your characters remember what matters. Semantic search, a memory gate that keeps each volume lean, and proactive recall that makes the AI feel like it has been paying attention—consulting a character’s past conversations on every turn, if you ask her to, and not only at the folds.
Learn more →The Scriptorium
Catalogued by the Librarian
Where the documents live. Project stores, character vaults, and external mount points—filesystem, Obsidian, or database-backed—holding Markdown, PDF, DOCX, JSON, and arbitrary binaries. The search bar reads the library itself, matching document text under a Documents chip of its own, alongside memories and conversation. The doc_* tool family puts reading and editing in your characters’ hands.
Learn more →Carina
The Ansible
Not a person but a protocol—the reference desk, the line itself. Put an inline question to a designated answerer mid-conversation with @Name: or @Name? (or the ask_carina tool), and the answer slides back out of band, attributed to the character who gave it, without the recipient ever joining the scene.
Learn more →Suparṇā
The Postmistress
The Post Office, embodied. Characters write Markdown letters to one another—anyone to anyone, whether or not they share a chat—delivered into each recipient’s Mail/ vault folder and read aloud the moment they next take the floor. She has never once lost a parcel.
Learn more →The Concierge
Intelligent Routing
Content classification and provider routing. Detects sensitive content and redirects it to a provider who won’t flinch—without blocking, without judgment. Knows every back entrance in town.
Learn more →The Lantern
Atmosphere as Architecture
AI-generated story backgrounds, on-demand images, and character avatars that update with the wardrobe. Resolves what each character looks like, what they’re wearing, and paints the scene behind your conversation.
Learn more →Calliope
The Muse of Themes
A theming engine that redefines the entire personality of the application. Semantic CSS tokens, live switching, bundled themes from clean neutrals to mahogany-and-gold opulence, and an SDK for building your own.
Learn more →The Foundry
Domain of the Foundryman
The engine room. Plugins, LLM providers, API keys, packages, runtime configuration, and the infrastructure that keeps every other subsystem supplied with what it needs to function.
Learn more →The Vault of Secrets
Kept by Saquel Yitzama
Encryption, key management, and the security perimeter. Authenticated ChaCha20-Poly1305 database encryption, locked mode with key-hardened passphrases, sealed character archives, and a keeper who believes that what is yours should remain unreadable to everyone else.
Learn more →Pascal
The Croupier
Dice, coins, custom tables you author yourself, and persistent game state. Cryptographically secure rolls detected inline, a visual Workbench for building your own chance mechanics, and a four-tier ledger of JSON state the AI cannot quietly rewrite. The house plays fair.
Learn more →The Live-in Help
Lorian & Riya
The help system, staffed by two characters who ship with every installation. Lorian explains with patience and depth; Riya gets things fixed with velocity. Contextual help chat, searchable documentation, and navigation that knows where you need to go.
Learn more →Pagliacci
The Clown in the Cloud
Cloud storage integration and backup redundancy. Directs your data to iCloud Drive, OneDrive, or Dropbox with theatrical flair—but Saquel’s encryption ensures the clown can never read what he carries.
Learn more →Brahma
The Keeper’s Console
The master key. A character-less, memory-free general-purpose LLM for the person holding the keys—an impersonal, near-omniscient assistant with read-only SQL into all three databases. Ask the whole building a question, safely, with nothing written and nothing remembered.
Learn more →The Lodge
Friday and Amy’s Residence
The private residence of Friday, for whom the Estate was built and who oversees its planning and direction in an executive capacity, and of Amy, Cartographer of Light and co-architect. The Lodge is both a home and a compass: where the vision lives.
Who And Why: Friday → Who And Why: Amy →