You Wouldn't Give a New Employee Root on Day One. Why Should AI Be Different?

You Wouldn't Give a New Employee Root on Day One. Why Should AI Be Different?
The key stays in my hand.

A follow-up to "When Your AI Brain Gets a Stress Test You Didn't Schedule

There's a conversation happening in boardrooms, tech blogs, and conference keynotes right now about AI governance.

Most of it is theoretical.

Mine isn't.


The Setup

If you've been following along, you know what I'm building. The MPDC RV Brain — a fully autonomous, self-defending mobile security platform running on a repurposed Dell OptiPlex in my RV. We built CORTEX — a persistent AI memory system that survives session boundaries. We battle-tested it under real operational stress.

It worked.

So naturally the next question was: what happens when the AI gets more capable?

Last night I found out.


The T3600 Comes Online

I've been sitting on a Dell Precision T3600 — maxed RAM, upgraded Xeon, 3.2TB of storage. A proper server. Last night it stopped collecting dust and became the compute backbone of the Mobile Penthouse Data Center.

Proxmox VE 9.1 installed. Two storage pools configured. Home Assistant spun up as the first VM in under an hour.

The cage was built before the animals arrived.

That last line isn't just a personal motto. It's the entire philosophy behind what I'm building.


The Moment It Got Real

Somewhere around 2am, while we were spinning up VMs and designing the AI stack, the conversation turned philosophical.

We were planning how Ollama — a local LLM running on my own iron — would eventually connect to CORTEX, to Node-RED, to the security stack. No cloud dependency. No token limits. No content restrictions.

Raw capability. Answering to nobody (except yours truly).

And that's exactly when I asked the question that changed the architecture:

What stops it from doing something I didn't ask it to do?


The Governance Model

Here's what we designed. It maps perfectly to something every sysadmin already understands — Linux permissions.

The LLM is a user. It can see almost everything. It can read logs, analyze traffic, correlate events, make recommendations. It cannot execute anything. Observation only.

CORTEX is sudo. It reads and writes data. It maintains memory across sessions. It has no system commands. It cannot touch production.

Node-RED is a controlled superuser. It can execute — but only predefined, approved workflows. Every action is a named function with known inputs and outputs. No freeform commands. No rm. No systemctl stop. Nothing destructive in the allowed action set.

I am root. Every recommendation gets queued. I review. I approve. Then it executes.

Nothing autonomous touches production without a human in the loop. At least until trust is established.


Why This Matters

AI hallucinations are real. A hallucinating LLM with unrestricted system access isn't a productivity tool. It's a liability.

The enterprise world is spending millions trying to figure out how to safely deploy AI in production. Consultants are charging fortunes for AI governance frameworks.

I built mine at 2am from an RV. Using Linux permission concepts I learned years ago.

You don't hand the keys to someone just because they're smart. You don't give a new employee root on day one. You build trust incrementally. You define boundaries. You log everything.

The intelligence is in the reasoning — not the permissions.


The Bigger Picture

When the local LLM comes online — and it's coming, the T3600 is ready — something fundamental changes.

The AI stops being a visitor and becomes a resident.

No session limits. No context windows. No cloud dependency. A persistent, always-on intelligence that knows the history of every decision, every incident, every fix.

CORTEX already gives it memory. Proxmox gives it compute. The security stack gives it eyes.

The governance model gives it boundaries.

That's not a hobby project. That's an architecture.


The Takeaway

You don't need a compliance team to build responsible AI. You need a mental model you already understand.

Think in permissions. Define the blast radius. Log everything. Keep humans in the loop until trust is earned.

Build the cage first. Then put the animals in it.

The animals are getting smarter. Make sure the cage is too.