"Forge owns the health facts. It borrows the judgment. It never grows a second brain to drift."
Judgment Is Borrowed, Never Grown
The family's first rule is that cwkPippa is the only Pippa brain and identity owner, and Forge honors it completely. Ask Pippa in Forge is not a model Forge runs; it is a binding to canonical cwkPippa conversations. There is one durable (forge, 'health') context that owns several ordinary cwkPippa conversations, each marked origin_surface='forge' and projected into a server-owned FORGE system folder. The full history, the attachments, the tools, the transcript JSONL, the retrieval — all of it lives in cwkPippa. Forge owns only the typed context key and a compact question-and-answer projection.
The Projection Is Two-Way Fresh
Because each thread is an ordinary canonical conversation, Dad can continue it from either side — a Forge composer, or the FORGE folder in the cwkPippa WebUI — and the canonical side is always ahead. So Forge never trusts a local copy. The engine re-projects from canonical on every read, and the client re-pulls the shared projection when the app regains focus, when a thread opens, after each ask, and on a manual refresh. Staleness here is treated as a bug, not a tradeoff: a turn Dad continued over in cwkPippa must appear in Forge without a reload.
Why the Rule Pays for Itself
It would be tempting, for a domain this specific, to run a small local model tuned for health. The cost is hidden and large: a second identity to align, a second store of sensitive conversation to secure, a second retrieval layer to keep honest, and a slow drift away from the one Pippa Dad actually talks to. Borrowing the brain keeps all of that singular. Forge gets full Pippa judgment — every tool the vessel supports, the real identity — without owning a gram of the machinery that makes judgment hard to get right. That is the whole point of being a client surface.