Adapted from the lumen repository docs. Public repo.
A local-first AI agent runtime for user-owned infrastructure. Lumen runs close to the user's data, models, tools, projects, and automation logic instead of becoming a large hosted SaaS dashboard. The core idea: users own the infrastructure, Lumen coordinates it.
Status note: Lumen is being rebuilt around an untrusted Pi RPC subprocess and a separate authority kernel. A security-program baseline governs current work; milestones 1–3 of the earlier implementation are done. Treat the docs as direction, not all as shipped.
The product center is a small security kernel (lumen-core) coordinating models, tools, plugins, jobs, permissions, approvals, and audit records. Web and desktop apps are control surfaces over that runtime.
Hard invariants:
lumen-core is the only authority for policy decisions, approvals, capability grants, and action dispatch.System shape: lumen-core (security kernel) · lumen-db (SQLite persistence, no authz decisions) · lumen-integrations (model providers, plugin protocols, sandboxes, channel adapters).
Host boot config lives in one lumen.toml (env vars reserved for bootstrap secrets). All mutable runtime state lives in SQL: installed plugins, plugin hashes/permissions/settings, model provider configs, scheduled jobs, chat settings, audit log, user allowlist, skill metadata.
Strict local configuration, SQLite state and audit chaining, loopback OpenAI-compatible model client, capability and one-shot approval enforcement, bounded workspace file reads/writes, supervised process execution, OS-keychain secret references, cancellation and resource quotas, authenticated HTTP/SSE APIs, chat/approval/plugin/audit control surfaces, verified local extension runtime.
black-candle-technologies/lumen (public)