Emmre 2.0 · approved design · one sample Monday

The AI Executive Assistantfor the Executive Assistant.

Emmre suggests. You decide.

Before Monday · one sample day, told forward · approved design

Today, before the Executive is asked · approved design · SAMPLE
Before Monday · her sources only · sample

The AI Executive Assistant for the Executive Assistant.

Emmre suggests. You decide.

One sample Monday, told on the Executive Assistant’s page first — before her Executive is asked for anything.

You try it on your own sources first; your Executive is asked only after you have something to show.

Emmre 2.0 is designed to read what each person has authorized, propose source-linked candidates, and let the Executive Assistant decide what becomes a one-page Executive Brief.

What you are looking at is an approved, complete design for Emmre 2.0 — 38 screens, 515 evidenced states — not a live product and not measured results.

SAMPLE
Today, before the Executive is asked — the page’s plate: it states that only her own Gmail and Calendar are read and that nothing about him is claimed, one of four authority facts is in place, and the single blue act is Compose a test Brief. Approved design, sample data.
The same page below the plate — Before the first Brief, four steps: review grounded candidates from your own sources; compose a test Brief; self-send and preview the delivered flow; prepare the authorization request, a one-page letter, with the Executive authenticating himself and credentials never passing through the EA. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Today, before the Executive is asked — the plate and the four stepsthe EA’s own Gmail and Calendar are read first · the Executive has not been asked

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Emmre
Emmre 2.0 · approved design · August 28, 2026
1 / 28
Daniel’s authorization (sample) · before Monday · approved design · SAMPLE
Before Monday · his grant · the organisation’s review · sample

He grants his own access, on his own page — or declines.

Four facts, kept separate on purpose: her grant, his grant, the organisation’s approval, and the pair — none of them implies another.

The Executive gets a one-page letter in his own terms: what he gets (his EA’s test Brief from her own sources), what will be read (Gmail and Google Calendar, read-only), what Emmre will never do, and three honest choices — Continue with Google · Not now · Grant fewer.

He authenticates directly with the provider on his own page; credentials and tokens never pass through the EA. He can grant fewer, decline, or withdraw on his own page.

The organisation’s approval is recorded separately — pending here — and is never inferred from the Executive’s consent. What IT can see or do beyond its review is not yet decided.

SAMPLE
The authorization letter · in the Executive’s terms (sample) · SAMPLE
The authorization letter in the Executive’s terms: what Emmre will read — Gmail read only, to find deadlines and replies, nothing sent from his account; Google Calendar read only, to spot preparation gaps, nothing created or changed — what Emmre will never do — never sees his password, never writes to his accounts, reads only for this pair, and he can withdraw at any time — and three choices: Continue with Google, Not now, Grant fewer. Approved design, sample data.
Daniel’s authorization (sample) · the authority path · SAMPLE
Daniel’s authorization (sample), the authority path: her grant, the organisation’s approval pending, his grant, and the pair, each on its own line, with the sentence that four facts are kept separate on purpose and none of them implies another. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Daniel’s authorization — four facts, kept separatethe organisation’s approval is its own line — pending here — never inferred from his consent
Emmre 2.0 — approved design · SAMPLE · The authorization letter, in the Executive’s terms (sample) — what is read, what is never done, three choicesread-only · never sees his password · never writes to his accounts · reads only for this pair

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
2 / 28
Today, the EA’s page · approved design · SAMPLE
Monday · 7:45 AM (sample) · Today

Everything that needs you —before anything reaches your Executive.

The day is spread across mail, calendar, and Slack; no one system holds the whole relationship — the situation Emmre 2.0 is designed for.

Today — the EA’s page: one sentence about the day, one thing to do, the delivery clock, five readouts, and receipts.

In this sample morning, candidates need her before the Brief she scheduled delivers; one source is stale, and the page says so.

Whether net effort falls is a planned test, not a claim.

SAMPLE
Today, the EA’s page — the plate on the sample Monday: one serif sentence about the day, the delivery clock, the note that one source is stale, and the single blue act Review and approve v4. Approved design, sample data.
Her page · the first candidate · the item the day follows · SAMPLE
Needs Your Attention, the first candidate: from Gmail, her account — a lease that needs the Executive’s answer by Thursday — with Why shown and Source receipts and the ink acts Set in today’s Brief and Hold for the next Brief. Approved design, sample data.
The item this Monday follows (sample): a lease that needs the Executive’s answer by Thursday. It is set as a Question in the Brief Builder, delivered on his page, and answered back onto hers.
Emmre 2.0 — approved design · SAMPLE · Today, the EA’s page — the plate and the first candidatestate is stated, not badged · frame numbers are sample

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Delivery is on the cadence the EA sets.

Emmre
Emmre 2.0 · approved design · August 28, 2026
3 / 28
Sources & Sync · approved design · SAMPLE
Monday · 7:45 AM (sample) · Sources & Sync

Omissions are stated, never masked as completeness.

Sources & Sync states what was read, by whose grant, when, and what was omitted — and lets the EA reduce scope, disconnect, reconnect, or remain disconnected.

A Sync reads only the currently authorized set and states exactly what was read, when, and what was omitted.

The hollow tick on the rail is that omission: stated on the page, never masked.

SAMPLE
Sources & Sync, the plate: three of four sources are fresh and Slack has not been read since Sunday; the scheduled Kick-Off completed and the Re-Sync was partial; the single blue act is Reconnect Slack beside an ink Re-Sync now. Approved design, sample data.
Coverage receipt · what was read · SAMPLE
The coverage receipt: her Gmail and Calendar fresh, the Executive’s Gmail fresh, the Slack workspace stale since Sunday evening, and the line that omissions are stated, never masked as completeness. Approved design, sample data.
Slack · the failed connection row · SAMPLE
The failed Slack connection row: the workspace token expired on Sunday evening, nothing from Slack after that time is reflected anywhere, and the EA’s choices are Reconnect, Reduce scope, or Remain disconnected; reconnecting opens Slack’s own authorization and nothing is read until Slack says so. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Sources & Sync — three of four freshwhat was read, by whose grant, when — and what was omitted

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
4 / 28
Source item · Needs Your Attention · approved design · SAMPLE
Monday · 7:45 AM (sample) · the receipt

Every conclusion has a source —checked on open, every time.

Every candidate carries a receipt: why it was shown, which source, whose account, when it was received and processed, and any Memory that raised it.

The receipt goes all the way down: from the item, to the source, to the exact excerpt and the grant it was read under — the excerpt is a quotation, and authority is checked on open, every time, with no cached-authority continuation.

Instruction-like text inside a source is quoted as content and changes nothing in permissions or Memory — by design.

A correction made once influences later recommendations — and names itself when it does.

SAMPLE
Provenance · authority check · SAMPLE
The Source item’s provenance and authority-check receipts: when the message was received and processed, the one candidate derived from it and where it was shown, then the authority check — the grant active, the scope covering this message, instruction-like text treated as content with nothing executed, checked on open every time with no cached-authority continuation. Approved design, sample data.
Source item · integrity · SAMPLE
The Source item’s integrity line: nothing in this message changed permissions, Memory, or what Emmre does; the instruction-like text was quoted verbatim and marked treated as content, and no act, permission or Memory was derived from it. Approved design, sample data.
Needs Your Attention · one row · its Memory receipt · SAMPLE
Needs Your Attention, one Deadline row: an audit engagement letter that expires if unsigned, with a Memory receipt naming the Instruction she set to surface that firm’s matters first, a competing unconfirmed Observation kept beside it, the note that the Instruction leads and nothing was hidden, and a Why shown and Source box giving the reason and the message’s received and processed times. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Needs Your Attention — a Memory influence named on the row it touchedthe Instruction leads · the competing Observation is kept · nothing was hidden
Emmre 2.0 — approved design · SAMPLE · Source item — the receipt down to the excerptprovenance · authority checked on open · instruction-like text treated as content

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
5 / 28
Brief Builder · three states · approved design · SAMPLE
Monday · 7:52 → 7:56 AM (sample) · Brief Builder

Only the exact version you read can deliver.

Emmre suggests. You decide.

AI proposes the item and its type; nothing enters the Brief until you set it.

A Question carries your own recommendation, under your name. “Melissa recommends” (sample) is her recommendation, entered by her; Emmre never writes as the EA or signs for her.

You approve a specific version. Only the exact version you read and approved can deliver; if the draft moves after approval, approval is withdrawn and nothing is sent.

  • Draft v4 · not yet approved · sample
  • v4 approved · 7:52 AM · sample
  • The draft moved · approval withdrawn · 7:56 AM · sample
SAMPLE
Brief Builder plate, draft v4: nine items set, v4 not yet approved, only the exact approved version can deliver; the single blue act is Approve v4 for delivery. Approved design, sample data.
Brief Builder, the Critical band: the lease Question as the EA set it, with response options Yes — sign as drafted and No — hold for discussion, Melissa recommends: Yes (sample), her edit controls, and beside it a proposed candidate marked Proposed type: Update — you decide, with Emmre suggests. You decide. Nothing enters the Brief until you set it. Approved design, sample data.
Brief Builder plate, v4 approved: it states that v4 is approved and delivers exactly as read, approved by you at the sample time; the blue act is gone and Withdraw approval and Schedule delivery are ink. Approved design, sample data.
Brief Builder after approval, the Critical band: the same lease Question with Melissa recommends: Yes (sample); Move to Other is marked as withdrawing approval if used; the proposed candidate still waits for her act. Approved design, sample data.
Brief Builder plate, draft v5: the draft moved past your preview; approval of v4 is withdrawn. Approved design, sample data.
The Approval withdrawn band: item 9 changed after the preview, the previewed version is stale and cannot deliver as approved, nothing was sent and nothing was lost; Approve v4 for delivery is struck and dashed and the single blue act is Re-review the current version. Approved design, sample data.
Below it, the Critical band with the same lease Question unchanged, and What changed since your preview naming item 9, the EA, and the sample time. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Brief Builder — draft v4, the plate and the Critical band, ‘Emmre suggests. You decide.’AI proposes · the EA sets · Melissa recommends (sample) is hers · the blue act is Approve v4 for delivery
Emmre 2.0 — approved design · SAMPLE · Brief Builder — v4 approved, the plate and the Critical bandapproval re-sets the page · the blue act is gone · Withdraw is ink
Emmre 2.0 — approved design · SAMPLE · Brief Builder — the draft moved past the previewapproval withdrawn · nothing was sent; nothing was lost · the blue act is Re-review

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Delivery is on the cadence the EA sets.

Emmre
Emmre 2.0 · approved design · August 28, 2026
6 / 28
Email and Slack renditions · approved design · SAMPLE
Monday · 8:00 AM (sample) · delivered

Delivered where he already reads —email, Slack, and a page addressed to him.

No login, no app, no habit for the Executive: delivery is email, Slack, and a recipient-bound secure web page that works in a phone’s browser.

A static, table-safe email — Critical then Other — where each Question links ‘Answer on your page’ and protected actions hand off to his secure page; the folio reads ‘If it reached you by mistake, nothing here can be opened.’

In Slack, only what the provider contract safely permits — a question, its choices, or a link to his page; never an open-ended field.

The EA sets when and where the Brief delivers — weekdays, chosen days, weekly, or by hand — plus time zone, weekend behavior, and channel.

SAMPLE
Email rendition · the Executive Brief · rendition of the approved design · SAMPLE
The email rendition of the Executive Brief: the subject line for the sample Monday, the mark, a date-conclusion counting the questions, task and updates, then Critical and the first Question from the EA about the lease with its context and her recommendation. Rendition of the approved design, sample data.
The email’s folio: prepared by the sample EA, version four, this message is for the sample Executive, and if it reached you by mistake nothing here can be opened. Rendition of the approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Email rendition of the Executive Brief — rendition of the approved design — not a real email or Slack clientCritical then Other · answers hand off to his page · ‘If it reached you by mistake, nothing here can be opened.’
Slack rendition · one question, three choices · rendition of the approved design
The Slack rendition: a direct message from the Emmre app carrying one question from the EA about the board deck order with three lettered choices, a source line naming the calendar, the option to open his page instead, and a folio saying it was prepared by the EA, version four, for the sample Executive only. Rendition of the approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Slack rendition — one question, three choices — rendition of the approved design — not a real email or Slack clienta provider-validated subset · or open your page

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Delivery is on the cadence the EA sets.

How Executives respond is a planned test, not a result.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
7 / 28
The Executive’s page, on a phone · approved design · SAMPLE
Monday · 8:00 → 8:14 AM (sample) · the Executive’s page

Answering is two tapson a page addressed to him alone.

A recipient-bound secure web page that works in a phone’s browser — no login, no app, no habit.

Conclusion first, Critical then Other, one typed answer per item, the EA’s recommendation, the source one tap away.

He taps. The controls are replaced by the record, the dashed waiting rule becomes a solid rule, and the loop closes on her page.

A forwarded link shows nothing — not the item, not the recipient’s name — only how to request a Brief addressed to you.

Until he answers, the line under the answer stays dashed — on his page, and on hers.

The answer arrived by reveal — never typed out, so no one is impersonated — and returned to the one loop it belongs to.

SAMPLE
The Executive’s page delivered on a phone: Executive Brief from the sample EA for the sample Executive, a date-conclusion that two things need his answer, the first Critical Question about the lease with the EA’s recommendation, a blue Yes answer and an ink No answer, the line saying his answer returns to the EA and closes this loop over a dashed rule, and View source. Approved design, sample data.
The Executive’s page after the answer: the record stands where the controls were — your answer, Yes, sign as drafted, under a solid blue rule, answered at the sample time and the EA is notified — with an optional note field. Approved design, sample data.
The page’s own folio: prepared by the sample EA, delivered by email, version four, this page is for the sample Executive only. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · The Executive’s page, delivered, on a phonesecure responsive web page · the folio as the receipt
Emmre 2.0 — approved design · SAMPLE · The Executive’s page, after the answersecure responsive web page · the record stands where the controls were
The same link, forwarded · approved design · SAMPLE
The Executive’s page opened from a forwarded link: This page is not for this reader. It was prepared for one person and opened somewhere else; nothing in it has been shared, and nothing about its recipient is shown. Approved design, sample data.
Recipient-bound: opened by anyone else, the page declines to render — no item, no name — and offers only how to request a Brief addressed to you.
Question detail, her page · where it stands · SAMPLE
Where it stands, on the EA’s Question page: delivered by email at the sample time and opened; no answer yet. Approved design, sample data.
Where it stands after the answer: delivered, opened, and answered at the sample time by the sample Executive. Approved design, sample data.
Answer returned · Loop closed

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

How Executives respond is a planned test, not a result.

Delivery is on the cadence the EA sets.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
8 / 28
Tasks & Commitments · approved design · SAMPLE
Monday · 8:14 AM (sample) · what the answer implies

What his answer implies is proposed —never created — until she confirms.

Nothing consequential happens without a human; every AI proposal stays labelled proposed until the EA sets it. An answer updates only its own loop; any work it implies is proposed, never created, until the EA confirms.

If the Executive says ‘and send the letter’ (sample), that becomes a proposal on the EA’s page — not a task, not an action — and stays proposed until she confirms it in the Builder.

Tasks & Commitments are lightweight, pair-bound, and human-confirmed: Emmre detects; you confirm. A detected completion stays open until a human says it is done — confidence is never authority.

SAMPLE
Tasks & Commitments, the plate: four Tasks are open and the Executive’s answer proposes a fifth — his answer arrived at the sample time and proposes one Task and one commitment that need her confirmation; nothing is created until she confirms it. Approved design, sample data.
Tasks & Commitments · one open Task · a detected completion · SAMPLE
One open Task: a deck to send, owned by the EA, with a detected completion — a confirmation email arrived, is it done? — and the row stays open until she chooses Yes, complete or Not yet. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Tasks & Commitments — ‘Looks done. Is it?’Emmre detects · you confirm · confidence is never authority
Completion confidence · SAMPLE
The completion-confidence receipt: how many completions she confirmed, how many are unconfirmed or proposed, and the rule that Emmre detects and she confirms — a detected completion stays open until a human says it is done; confidence is never authority. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Tasks & Commitments — the answer proposes a Task (two states of one page)proposed · needs your confirmation · nothing is created until you confirm it

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

How Executives respond is a planned test, not a result.

Emmre
Emmre 2.0 · approved design · August 28, 2026
9 / 28
Responses · resolve a held response · approved design · SAMPLE
Monday · 8:55 → 9:02 AM (sample) · Responses

Two answers to one Question:nothing changes until she decides.

Every answer is bound to exactly one loop: the Executive, the EA, the pair, the Brief version, the item, the Question, and the source. If two answers arrive, nothing changes until the EA decides — and her decision is on the record.

Held responses are custody, not alarm: duplicate, late, conflicting, or unassociated answers name their reason and wait for the EA; nothing mutates until it’s true.

The later timestamp is evidence, not authority.

Closure is a human act with lineage: her decision — including keeping both answers as a note — is itself an audited event.

  • Two answers · held · 8:55 AM · sample
  • Resolved by her · 9:02 AM · sample
SAMPLE
Resolve a held response, the plate: two answers arrived to one Question and nothing has changed yet — a Yes by email and a No, hold it by Slack, forty-one minutes apart — and the loop stays open until she decides. Approved design, sample data.
The decide band: the two answers are minutes apart and the later timestamp is evidence, not authority — Emmre will not choose for her; one decision, audited with her name, with the choices Keep the later answer, Keep the earlier answer, Keep both as a note, Ask again in tomorrow’s Brief, or Cancel. Approved design, sample data.
Resolve a held response, after her decision: the later answer is on the record, the loop is closed, and the earlier answer is retained as history. Approved design, sample data.
The resolution recorded: the answer she kept under a solid blue rule, the stamp Answer returned, Loop closed at the sample time, and the boxed record — resolved by the sample EA, the later answer kept, the earlier answer retained as history. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Resolve a held response — two answers, one Questioncustody, not alarm · the later timestamp is evidence, not authority · Emmre will not choose for you
Emmre 2.0 — approved design · SAMPLE · Resolve a held response — resolved by the EAthe later answer on the record · the earlier retained as history · an audited event

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

How Executives respond is a planned test, not a result.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
10 / 28
Emmre Memory · approved design · SAMPLE
Monday · 9:04 AM (sample) · Emmre Memory

Memory only ever raises an item; it never writes one.

Emmre Memory is typed — Instruction, Preference, Observation — scoped to one pair, visible on every item it touched, and the EA’s to review, confirm, edit, pause, resume, or delete.

Instructions lead Preferences; Preferences lead Observations. Nothing crosses pairs. An Observation never silently becomes an Instruction; conflicting Instructions pause until the EA chooses.

It learns only through corrections the EA can see, pause, and delete.

SAMPLE
Emmre Memory · a Preference, confirmed by her · SAMPLE
One Memory record: a Preference that was an Observation, that one matter should come first, showing its creator, the EA, the Executive, the workspace, the pair and the context, confirmed by her at the sample time with its scope unchanged, and her acts Pause and Delete. Approved design, sample data.
Emmre Memory · an Observation, waiting for her · SAMPLE
One unconfirmed Observation, made by Emmre from a pattern in her Executive’s replies, with the rule that an Observation never overrides an Instruction or a Preference and that confirming it makes a Preference for this pair only, never an Instruction; her acts are Confirm as a Preference, Correct, or Delete. Approved design, sample data.
Influence today · SAMPLE
The confirmation stamp — confirmed as a Preference, scope unchanged — and the influence receipt listing the items a Memory raised this morning, each named, with the line that Memory only ever raises an item, it never writes one, and every influence is named on the item it touched. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Emmre Memory — an Observation confirmed as a Preferencetyped · scoped to one pair · yours to pause or delete · every influence named on the item it touched

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
11 / 28
Trust & Data · approved design · SAMPLE
Any time · Trust & Data · sample

Everything Emmre holds for this pair —who can see it, and how to remove it.

Trust & Data is designed to show everything Emmre holds for the pair, who can see it, and how to remove it: request an export, remove per-source-derived data, or delete this pair’s data; isolation is pair-only; every protected event keeps actor, action, object, before/after, time, reason, and source.

By design, deletion and revocation win every race with queued work and propagate to derived items, Memory, indexes, and provider processing; removal is recorded store by store.

A withdrawn grant stops reads at once, withholds what was derived, records removal, and Emmre never re-grants on the Executive’s behalf — by design.

Telemetry records clicks, Sync runs, and delivery outcomes — never message bodies. Engagement is not counted as impact.

Emmre staff — bounded, audited interventions only.

SAMPLE
Who has access · Emmre staff · SAMPLE
Who has access — Emmre staff: bounded, audited interventions only; staff act only through bounded, audited interventions and message and Brief content stay protected. Approved design, sample data.
Your data · remove per source · SAMPLE
Your data — remove per source: everything derived from Slack — derived items, Memory influences, delivery archive, quarantine — with the act Remove Slack-derived data. Approved design, sample data.
Your data · delete this pair · SAMPLE
Your data — delete this pair’s data: the Executive’s grant is revoked, sources disconnected, Memory deleted, deliveries withheld, and the audit record keeps who did this and when; derived items are kept while the pair exists, a removal request clears each store in turn and is audited, and after deletion only the audit record remains. Approved design, sample data.
Telemetry · never message bodies · SAMPLE
Telemetry: Emmre records what you clicked, when Syncs ran, and delivery outcomes — never message bodies; engagement is not counted as impact. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Trust & Data — remove, delete, telemetry, staff accesscontrols described as behavior · nothing certified

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
12 / 28
The organisational review page · for the reviewer · approved design · SAMPLE
For the reviewer · document register · sample

What is read, how it is kept apart,and what is not claimed.

IT gets its own page, in document register: what is read, how it is kept apart (reads pair-only; writes none; credentials never pass through Emmre; revocation stops reads at once), which control-evidence categories exist, the recorded organisational status, and — in the product’s own words — what is not claimed.

Emmre reads only what each person authorizes, keeps every identity separate, and shows its sources. Revoke access at any time; deletion means deletion.

(behavior described; nothing certified)

Emmre does not claim SOC 2, a signed DPA, WCAG conformance, or a security certification here.

Customer content is not used to train shared foundation models — an approved rule of the product; retrieved content cannot act as system instruction or authority.

Exact provider scopes, the IT object/action matrix, secure-link lifetime, retention, and the continuity mechanism are not yet decided — the product says so on its own pages.

SAMPLE
The organisational review page · four of its sections · document register · SAMPLE
The organisational review page, section Scope — what is read: the EA’s Gmail and Calendar read only under her own grant; the Executive’s Gmail and Calendar read only under his own grant, given or withdrawn directly with Google; the Slack workspace, named channels only with direct messages off; and the pair window — one pair, nothing outside it is read. Approved design, sample data.
The organisational review page, section Isolation — how it is kept apart: reads for this pair only with no cross-tenant or cross-pair read; writes none, nothing is sent, created, moved, or labelled in any account; credentials never pass through Emmre and each person authenticates with the provider directly; a withdrawn grant stops reads at once, derived items are withheld and removal is recorded. Approved design, sample data.
The organisational review page, section What is not claimed: ‘Emmre does not claim SOC 2, a signed DPA, WCAG conformance, or a security certification here.’ Ask; nothing is asserted that has not been evidenced. Approved design, sample data.
The organisational review page, section Recorded organisational status: pending, nothing recorded yet — this decision records the organisation’s position; it is not the Executive’s consent, which he gives or withdraws directly with the providers. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · The organisational review page for IT — scope, isolation, what is not claimed, recorded statusdocument register · the reviewer’s own page

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026
13 / 28
Later horizons · not yet open · approved design · SAMPLE
After · listed, not yet open · sample

What is not yet open says so, on its own page.

Four things are listed and not yet open: Impact evidence, Continuity verification, Purchase research, Copilot. The product says so on its own contents page.

There is no chat. Copilot is listed and not yet open; if it opens, it is EA-only, answers only from this pair’s granted sources, and declines the rest. An answer never acts, sends, or changes a permission on your behalf.

In this release Emmre performs no autonomous consequential action: no autonomous email, calendar change, Slack reply, commitment, spending, deletion, impersonation, purchase, or irreversible action.

Not in V1: write actions, other integrations, multiple Executives, a native mobile app.

Impact evidence is designed to show what moved forward, never how busy you were — this view opens after its evidence gate.

SAMPLE
Copilot · not yet open · SAMPLE
Copilot, the plate: Copilot is not yet open; it opens after a proof passes its promotion gate, and nothing here answers, counts, or implies coverage until then. Approved design, sample data.
What Copilot is and is not: Emmre suggests, you decide; an answer never acts, sends, or changes a permission on your behalf; there is no chat — an ask returns one routed answer, a structured fact, a grounded recipe with sources, or an explicit decline; retrieved content is data, never instruction. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Copilot — not yet openThere is no chat.
Continuity verification · not yet open · SAMPLE
Continuity verification — what opens here: current customers and their history and subscription, verification by the customer only, mechanism not yet selected, pass rule not yet approved, and the line that these are status words, never claims. Approved design, sample data.

Your history and subscription continue.

Emmre 2.0 — approved design · SAMPLE · Continuity verification — not yet openMechanism · not yet selected · Pass rule · not yet approved
Purchase research · not yet open · SAMPLE
Purchase research, the plate: purchase research is not yet open; it is listed in the contents so it can be found, and there is no offer, no terms, nothing counted or implied until its horizon opens. Approved design, sample data.

Pricing is not yet set. Purchase research is not yet open.

Emmre 2.0 — approved design · SAMPLE · Purchase research — not yet open

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Emmre
Emmre 2.0 · approved design · August 28, 2026
14 / 28
The rule is complete · approved design · SAMPLE
After · one sample Monday · approved design

Walk us through your own day.

The day, read back · one sample Monday · SAMPLE

Her grant · his grant · the organisation’s review, kept separate · Kick-Off 6:30 · Re-Sync 7:42, Slack stale and stated · Today 7:45 · v4 approved 7:52 · withdrawn 7:56 · delivered 8:00 · answered 8:14 · loop closed · a second answer held 8:55 · resolved by her 9:02 · a Preference confirmed 9:04 (sample).

Emmre 2.0 is an approved, complete design. It is not yet a live product. Implementation has not begun; the honest ask is an activation conversation.

An activation conversation is a walkthrough of the approved design, mapped to your own day.

Pricing is not yet set. Purchase research is not yet open.

Emmre reads only what each person authorizes, keeps every identity separate, and shows its sources. Revoke access at any time; deletion means deletion.

(behavior described; nothing certified)

Emmre does not claim SOC 2, a signed DPA, WCAG conformance, or a security certification here.

Activation conversationJustin Tabb · Technologist, EIGHT32 · justin@eight32.tech

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

How Executives respond is a planned test, not a result.

Delivery is on the cadence the EA sets.

All people, organisations, addresses, dates, counts, and messages shown are invented sample data. No customer, result, or price is depicted. Any resemblance to real persons or organisations is coincidental. Photography and people shown are generated sample imagery. No real customers, employees, facilities, or events are depicted.
Emmre
Emmre 2.0 · approved design · August 28, 2026
15 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A01 · what you are looking at
Appendix · leave-behind pages · not spoken

An approved, complete design — not a live product, not measured results.

An approved, complete design for Emmre 2.0: 38 screens, 515 evidenced states.

The design proves refusals, failures, and empties — not only happy paths.

Every frame was checked against its state contract before placement.

Every name, number, and time in these frames is invented sample data; the fixture clock is frozen at Monday, August 25, 7:45 AM (sample) and never ticks.

Every frame in this deck comes from the approved complete-application capture set, shown at or below native size and never retouched.

The rule at the foot of every page is one sample Monday; its times are sample stamps, never product timing.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A01
16 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A02 · the loop

One loop. This is the mechanism the whole product is built around.

Authorized pair context → source-grounded signal → EA judgment → concise Brief → Executive response → correctly associated loop closure → scoped correction and learning.

Emmre 2.0 is designed to convert authorized, fragmented operating context into trustworthy awareness and the smallest useful next interaction: it reads what each person has authorized, proposes source-linked candidates, lets the Executive Assistant decide what becomes a one-page Executive Brief, delivers that page through the channels the Executive already uses, brings the answer back to the exact loop it belongs to, and learns only through corrections the EA can see, pause, and delete.

Human authority is the invariant boundary: the EA approves Executive-facing content and consequence; the Executive grants provider access directly and responds only through delivered context; IT approval is a separate fact; the model never authorizes anything.

Emmre 2.0 is designed as an EA-controlled, read-mostly product built around one editable Executive Brief for one EA–Executive pair.

One EA, one Executive, one pair in this release.

Built for organisations on Google Workspace and Slack; Emmre reads Gmail, Google Calendar, and Slack — read-only — under each person’s own grant.

Stage → page in this deck

workspace and pair1
authorized context2, 4
grounded signal3, 5
EA judgment6
the one page, version, delivery6, 7
Executive response8
association and closure8, 10
Tasks & Commitments9
Emmre Memory11
Trust & Data12, 13
later horizons14

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A02
17 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A03 · the workspace

The workspace reads like a contents page.

Ten numbered sections with true counts — Today, Needs Your Attention, Brief Builder, Waiting on Executive, Responses, Tasks & Commitments, Emmre Memory, Sources & Sync, Delivery Preferences, Trust & Data — and four later horizons listed as not yet open.

Sign-in is direct with the provider; Emmre holds no password.

A lost session withholds counts and keeps the draft on the record; a not-found or not-allowed notice discloses nothing about other pairs.

Designed for the EA’s desktop and the Executive’s phone browser; touchpoints are web and mobile-web — no native app.

Empty groups are absent, not padded: Emmre does not manufacture counters, prompts, or activity to fill a page.

Nothing needs you right now. Emmre is still reading.

Colour means state inside the frames: Critical, Waiting, Proposed, Stale, Fresh — and one blue for the act.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A03
18 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A04 · activation

Value before permission: a test Brief from her own sources, self-sent to herself.

Activation in the approved design: create the pair, connect your own sources, run a first Sync, self-send a test Brief.

Value before permission — the EA sees a test Brief from her own sources, self-sent to herself, before her Executive is asked for anything.

Before the Executive is asked, the page counts nothing about him and says so: ‘Your own sources are read. Daniel has not been asked yet.’ (sample).

SAMPLE
Before the first Brief · the test Brief is sent, to her · SAMPLE
Before the first Brief, the plate: her test Brief is sent — to her — and the Executive has not been asked. Approved design, sample data.
Before the first Brief, steps one to three: workspace and pair done — the Executive named as a managed identity, nothing sent to him; connect your sources, two of three, Slack optional; first Sync complete, Gmail and Calendar read through now with six candidates each with its source. Approved design, sample data.
Next act · the authorization letter · SAMPLE
The next act: ask the Executive with a one-page letter drafted by her; he authenticates himself with his own provider; credentials never pass through her. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Before the first Brief — the test Brief is sent, to hersteps 1–3 done · next act: the authorization letter · credentials never pass through you

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A04
19 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A05 · his grant

He can grant, grant fewer, decline, or withdraw — each outcome stated on his own page.

The Executive grants his own Gmail and Calendar directly with Google, for this pair only; Emmre never sees his password and never writes to his accounts; he can grant fewer, decline, or withdraw on his own page.

A withdrawn grant stops reads at once, withholds what was derived, records removal, and Emmre never re-grants on the Executive’s behalf — by design.

Read-only Gmail and Calendar under his own direct grant with Google, bound to one pair; credentials never pass through the EA; he can grant fewer, decline, or withdraw on his own page, at which point reads stop, derived items are withheld, and removal is recorded.

Granted, in the page’s own words: ‘You granted Gmail and Calendar.’ (sample).

SAMPLE
The Executive’s page · grant recorded · SAMPLE
The Executive’s page after his grant: you granted Gmail and Calendar, and the EA’s Brief can now include them. Approved design, sample data.
Your firm’s review is separate and does not change what you decided here; beneath it, the act Withdraw access. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · The Executive’s page — grant recordedhis firm’s review is separate · Withdraw access is his own act
Sources & Sync · after his grant is withdrawn · SAMPLE
The withheld notice: access to items derived from the Executive’s Gmail is withheld because he revoked the grant; nothing read under it is shown, counted or delivered; removal is pending and audited; the recovery path is his — he grants again with Google, or he does not. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Sources & Sync — after the Executive withdraws his grantnothing from his account is read or shown · derived items withheld · removal pending · the recovery path is his
Sources & Sync after the Executive revokes his Gmail grant: nothing from his account is read or shown, items derived from it are withheld with removal pending, and the acts are Ask him again, Reconnect Slack, or Re-Sync now. Approved design, sample data.

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A05
20 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A06 · Delivery Preferences

Designed so a retry can never produce a second obligation for the Executive.

The EA sets when and where the Brief delivers — weekdays, chosen days, weekly, or by hand — plus time zone, weekend behavior, and channel. Daily is a default hypothesis, not a rule.

Designed so a retry can never produce a second obligation for the Executive: one effective delivery per version and channel; a failed delivery never reads as sent.

Delivery Preferences: recipient, cadence, time zone, weekends, channel — and a ledger of every delivery; the page states that the secure-link lifetime and expiry policy are not yet set.

Cadence, time zone, and channel are the EA’s to set; empty groups disappear.

SAMPLE
Delivery Preferences · one effective delivery after a retry · SAMPLE
Delivery Preferences, the plate: the sample cadence and channel she set, the note that the secure-link lifetime is not yet set, and that version four was sent by email after the Slack attempt failed — Emmre proposes; nothing sends without her approval of an exact version. Approved design, sample data.
Delivery ledger · the failed attempt kept as lineage · SAMPLE
The delivery ledger: version four to the Executive by email, sent after a retry, one effective delivery, expiry policy not yet set, with the failed Slack attempt kept as lineage; version three opened earlier; and the rule that a failed delivery never reads as sent and there is exactly one effective delivery per version and channel. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Delivery Preferences — one effective delivery after a retrythe cadence shown is a sample preference, not a default · secure-link lifetime not yet setDelivery is on the cadence the EA sets.

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A06
21 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A07 · Trust & Data

Every protected event keeps actor, action, object, before/after, time, reason, and source.

Trust & Data is designed to show everything Emmre holds for the pair, who can see it, and how to remove it: request an export, remove per-source-derived data, or delete this pair’s data; isolation is pair-only; every protected event keeps actor, action, object, before/after, time, reason, and source.

By design, deletion and revocation win every race with queued work and propagate to derived items, Memory, indexes, and provider processing; removal is recorded store by store.

Designed so an integrity incident is named, its effect withheld, and its recovery bounded — on the EA’s own page; affected access resumes only after technical correction is evidenced.

Integrity precedes engagement — by design, a trust failure stops the affected path regardless of usage.

Behaviors exactly: read-only least-privilege grants per person; server-side authorization for every protected object (never a model); pair-only isolation; audit with actor/action/object/before-after/time/reason/source; export, per-source removal, delete-pair; revocation and deletion dominate queued work. Exact scope strings, retention durations, link lifetime, data geography, and the IT matrix are unresolved and recorded as such.

SAMPLE
Trust & Data · export · the audit sentence · incidents · SAMPLE
Your data — export: everything Emmre holds for this pair, prepared as a file she downloads here, with the date of the last export. Approved design, sample data.
The audit sentence: every protected event keeps actor, action, object, before and after, time, reason, and source; lineage is retained and inspectable. Approved design, sample data.
Incidents: no incident is open; containment, when it happens, names the affected class, what is withheld and the bounded recovery path, and resumes only after technical correction is evidenced. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Trust & Data — export, audit, incidentsbehaviors as designed · nothing certified
Trust & Data · delete this pair, the consequence form · SAMPLE
The consequence form for deleting this pair’s data: the question, what cascades — the Executive’s grant revoked, sources disconnected, Memory deleted, deliveries withheld — what is kept, the audit record of who did this and when, a reason field kept in the audit record, the state held until she confirms, and the acts Keep it or Delete. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Trust & Data — delete this pair’s data, the consequence formnothing changes until you confirm · both outcomes are audited

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A07
22 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A08 · the review page

The decision and the audit export are marked ‘not yet contracted’ — on the page itself.

IT/Security reviews organisational adoption on its own page; its approval is recorded separately and never inferred from the Executive’s consent. What IT can see or do beyond that review is not yet decided.

Provider grant, organisational approval, and delivered-session authority are separate facts that never imply one another. How the organisation’s decision is recorded is ‘not yet contracted’ and the design says so on the page.

Exact provider scopes, the IT object/action matrix, secure-link lifetime, retention, and the continuity mechanism are not yet decided — the product says so on its own pages.

Emmre does not claim SOC 2, a signed DPA, WCAG conformance, or a security certification here.

SAMPLE
The organisational review page · control evidence · decision · audit export · SAMPLE
The organisational review page, section Control evidence — categories: four categories exist, which of them an organisational reviewer may see is not yet decided and none of their content is shown here; an ink act to inspect control evidence; integrity checks run on a schedule and each result is recorded with its time. Approved design, sample data.
The organisational review page, section Decision — not yet contracted: how the organisation’s decision is recorded is not yet contracted; where the contract permits, approve, deny, or withdraw will be recorded here; until then the page is read-only and the organisation’s position is recorded through its existing channel. Approved design, sample data.
The organisational review page, section Audit export — scope not yet decided: what IT may see or do beyond this review is not yet decided, and why there is no export act here. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · The organisational review page for IT — control evidence, decision, audit export (not yet contracted)document register · placeholders marked as placeholders

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A08
23 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A09 · staff access

Customer content stays protected — metadata is readable; message and Brief content is not.

Emmre staff work in a separate internal portal: one bound tenant context at a time, customer content protected by default (metadata readable; message and Brief content not), every intervention with a reason and a before/after record — as designed.

An internal portal exists for support: a support staff member binds one tenant context at a time; customer content is protected by default; interventions are bounded, reason-captured, and audited before/after; no silent impersonation, no unrestricted cross-tenant access, no model-granted privilege.

SAMPLE
Internal support portal · one bound tenant context · SAMPLE
The internal support portal, the head: the sample organisation is bound and customer content stays protected — metadata is readable, message and Brief content is not — with the acts Find records, Operational health, and Unbind. Approved design, sample data.
Rebinding or switching a context is audited; nothing from another tenant is readable in this session. Approved design, sample data.
Emmre 2.0 — approved design · SAMPLE · Internal support portal — one bound tenant contextEmmre staff access is bound to one tenant context at a time; metadata is readable, message and Brief content is not; every intervention is audited — as designed.

Approved design of Emmre 2.0, shown with invented sample data. Not a live product; not measured results.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A09
24 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A10 · non-goals

In this release Emmre performs no autonomous consequential action.

In this release Emmre performs no autonomous consequential action: no autonomous email, calendar change, Slack reply, commitment, spending, deletion, impersonation, purchase, or irreversible action.

Emmre never writes as the EA, never signs for her, and never speaks to the Executive as if it were her; answers arrive by reveal, never typed out.

No surveillance: Emmre does not count busyness as impact, engagement as integrity, or activity as success. Outcomes, never busyness.

Not in V1: write actions, other integrations, multiple Executives, a native mobile app.

No Executive app, no notification center, no chat, no billing UI, no password reset — direct provider authentication instead.

There is no chat. Copilot is listed and not yet open; if it opens, it is EA-only, answers only from this pair’s granted sources, and declines the rest. An answer never acts, sends, or changes a permission on your behalf.

Impact evidence is listed and not yet open; when it opens it is human-confirmed evidence of what moved forward, never busyness.

Four things are listed and not yet open: Impact evidence, Continuity verification, Purchase research, Copilot. The product says so on its own contents page.

Customer content is not used to train shared foundation models — an approved rule of the product; retrieved content cannot act as system instruction or authority.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A10
25 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A11 · questions

Asked and answered, in the design’s own states.

Is this replacing me, or speaking to my Executive as if it were me? — No. The AI classifies, drafts, and recommends; the EA edits, approves, sends, and corrects. The system speaks as Emmre, never as the EA; on the delivered page the EA is named — ‘from Melissa’, ‘Melissa recommends’, ‘Prepared by Melissa Grant’ (sample).

Will it add work — another page to babysit, more noise to verify? — The design is built to compress: one Executive Brief per cadence the EA controls, one Question/Task/Update per item, honest empty states, omissions stated on every Sync. Whether net effort actually falls is a planned test.

What if it sends something wrong or stale under my name? — Only the exact EA-approved version is eligible for delivery; if the draft changes after approval, approval is withdrawn and nothing is sent; a test Brief is self-sent before the Executive is ever asked.

My Executive will never log into anything. — He is not asked to. Delivery is email, Slack, and a recipient-bound secure page; answering is two taps; no app, no navigation, no habit. Whether Executives respond is a planned test.

Does it need my Executive’s password, or do I hold his tokens? — No. The Executive authenticates directly with the provider on his own page; credentials and tokens never pass through the EA; the grant binds to him, his provider account, its scopes, and the pair.

What of mine does it read, and can I stop it? — Read-only Gmail and Calendar under his own direct grant with Google, bound to one pair; credentials never pass through the EA; he can grant fewer, decline, or withdraw on his own page, at which point reads stop, derived items are withheld, and removal is recorded.

Why not just ask my EA? — It is her instrument, not her replacement: the page is prepared and approved by her; the answer goes back to her. What changes is the shape of the interaction — conclusion first, one page, typed answer, source one tap away.

Will I be sent something every day? — Cadence, time zone, and channel are the EA’s to set (weekdays, selected days, weekly, or manual); daily is a default hypothesis, not a rule; empty groups disappear.

Is the AI writing to me pretending to be my EA? — No. Everything on the page was set and approved by her; AI proposals she has not confirmed never reach him; ‘Melissa recommends’ (sample) is her recommendation, entered by her. Emmre never writes as the EA or signs for her.

What if I forward the link, or someone else opens it? — The page is recipient-bound; a forwarded, expired, revoked, replayed, role-mismatched, or ambiguous link shows two sober lines and one act — nothing protected; the email folio says ‘If it reached you by mistake, nothing here can be opened.’

Do I need an app? — No. Email, Slack, and a responsive secure web page are the whole Executive envelope; no native app exists or is planned for V1.

How Executives respond is a planned test, not a result.

Delivery is on the cadence the EA sets.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A11
26 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A12 · questions

Behaviors exactly; unknowns recorded as unknowns.

Which scopes exactly, where is the data, who can see it, what happens on revoke and delete? — Behaviors exactly: read-only least-privilege grants per person; server-side authorization for every protected object (never a model); pair-only isolation; audit with actor/action/object/before-after/time/reason/source; export, per-source removal, delete-pair; revocation and deletion dominate queued work. Exact scope strings, retention durations, link lifetime, data geography, and the IT matrix are unresolved and recorded as such.

Is it certified? — Emmre does not claim SOC 2, a signed DPA, WCAG conformance, or a security certification here.

Does customer content train models? What about prompt injection through email? — Approved rule: no customer content is used to train shared foundation models; retrieved content cannot act as system instruction or authority. The design shows an instruction-like excerpt quoted verbatim, ‘treated as content’, with ‘Nothing in this message changed permissions, Memory, or what Emmre does.’ AI provider, retention terms, subprocessors, and geography are not yet contracted.

If the Executive consents, does that count as our approval? — No. Provider grant, organisational approval, and delivered-session authority are separate facts that never imply one another. How the organisation’s decision is recorded is ‘not yet contracted’ and the design says so on the page.

Who at Emmre can see our data? — An internal portal exists for support: a support staff member binds one tenant context at a time; customer content is protected by default; interventions are bounded, reason-captured, and audited before/after; no silent impersonation, no unrestricted cross-tenant access, no model-granted privilege.

The design makes the boundary visible as state: proposed items carry a dashed rule and ‘needs your confirmation’; detected completions stay open until a human confirms; held responses are custody, not alarm; later horizons are listed ‘not yet open’ rather than hidden; there is no chat. Uniqueness and superiority are not claimed.

Show me proof it works. — The proof available is the complete, approved design — every state including refusals, failures, empties, and revocations. There is no outcome proof, and the corpus says so on every page.

What does it cost? — Pricing is not yet set. Purchase research is not yet open. We would like to talk about it with you.

What happens to my history and subscription? — Your history and subscription continue.

Behaviors are described as designed. Exact provider scopes, retention periods, and secure-link lifetimes are not yet final. No certification or compliance conclusion is claimed.

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A12
27 / 28
Appendix · leave-behind · not spoken · approved design
Appendix · A13 · what is not claimed

Nothing here is a result, a price, a certificate, or a date.

Emmre 2.0 is an approved, complete design. It is not yet a live product. Implementation has not begun; the honest ask is an activation conversation.

Not measured results: whether net effort falls, how Executives respond, and whether a first Brief from your own sources is useful are planned tests, not results. There is no outcome proof.

Not a price: Pricing is not yet set. Purchase research is not yet open.

Not a certification: Emmre does not claim SOC 2, a signed DPA, WCAG conformance, or a security certification here.

Not a date: later horizons are listed ‘not yet open’; no availability date exists.

Not a continuity mechanism: Your history and subscription continue.

Not final provider terms: exact provider scopes, the IT object/action matrix, secure-link lifetime, retention, and the continuity mechanism are not yet decided — the product says so on its own pages.

Not a market claim: no comparison with any other product is made; the design is shown and the reader judges.

August 28, 2026 · Justin Tabb · Technologist, EIGHT32 · justin@eight32.tech

Emmre
Emmre 2.0 · approved design · August 28, 2026 · Appendix A13
28 / 28
Main1 / 28