Muin is in private beta.Watch the public release announcement —talk to us.
Falaah Falaah AI

Grounded AI drafts

AI draft replies built only from your organization's verified records — events, profile, documents, and the sender's history — each fact carries provenance.

When someone asks your organization “where is the distribution tomorrow?” or “is my membership still active?”, the AI draft that answers them is built only from facts retrieved from your own records — your published events, your organization profile, your indexed documents, and (when identity is verified) the sender’s own history. Nothing is invented.

How it works

Before writing a draft, Muin runs a set of read-only grounding skills over your data and assembles a fact ledger:

  • Upcoming events — live calendar events with times and venues
  • Organization profile — name, address, phone, business hours
  • Documents & knowledge base — content you’ve indexed or connected
  • Connected sources — web pages and files you register, each with an explicit visibility class
  • The sender’s own records — membership or giving history, released only when the sender’s identity is verified on that channel

The draft may state only facts present in the ledger. An automatic entity validator rejects any address, time, phone number, or amount that isn’t backed by a verified fact — a draft caught inventing specifics is regenerated and flagged for careful review.

Provenance you can see

Every fact the AI used appears as a chip under the draft — Event: Flood Relief Distribution (Jun 8), KB: relief-ops.pdf — and each chip links to the source record. When sources disagree (a stale document vs. a live event), the draft uses the live record and shows a Conflicting sources chip. When nothing relevant is found, the draft says so honestly and the question is filed to your knowledge-gap inbox as a work item with a suggested fix.

Privacy by construction

  • Visibility classes — every source is classified public (may appear in customer replies) or internal (searchable by your team, never in customer-facing drafts). Enforcement happens in the database query, not by instructing the model.
  • Identity tiers — personal facts (giving history, membership status) are released only at a strong identity tier: the sender is provably the person the records belong to on that channel. An impostor emailing from a lookalike address gets a polite verification invite, never the data.
  • Refs-only ledger — what’s stored alongside each draft is a list of record references, never fact text, so a person-deletion request leaves no orphaned copies.

The payoff loop

Unanswerable questions become knowledge gaps with one-click fixes — create the event, publish the record, complete your profile, or save your manual reply as a published FAQ. Your weekly briefing reports how many questions your records answered; working the gap inbox raises that number every week.