Four jobs. On your machine. A person still decides.
The honest version of an AI feature page. There is no list of twenty capabilities here, because there are four, and pretending otherwise is how people end up surprised.
The four things it does
Research
Find companies matching your criteria, read their public pages, and pull out what can be verified — each value carrying the URL it came from.
Score
A second, independent opinion beside your own deterministic scoring, with a written explanation of where the points came from.
Summarise & classify
Describe a lead, read a document, categorise a record, and file the fields printed on it against an invoice or a bill.
Draft
Propose outreach copy, the next concrete step, and accounting descriptions. All of it a draft you edit.
Where the thinking happens
Locally. The model is loaded into the application when it starts and does not send prompts anywhere. There is no inference server to install, start or leave running, and no port for it to occupy.
Which means: no prompt leaves the machine, no customer data is a line item on someone's inference bill, and you can pull the network cable out and everything except online research keeps working.
You can point it somewhere else, and it will tell you when you do
Any OpenAI-compatible endpoint works — a server you run yourself, or a commercial API. If you do that, your prompts are transmitted to that operator, you become responsible for the agreement with them, and FoundrySuite says so on screen. It does not quietly send your data to a paid API and leave it to you to find out.
What goes to the model
| Feature | Typically sent |
|---|---|
| Lead summary | Company name, industry, notes, prior activity |
| Scoring | Company attributes and your criteria |
| Outreach draft | The product or service description you wrote |
| Document reading | Text extracted from that document |
Never sent: session tokens, password material, accounting records, other workspaces' data, or the audit log. And because inference is local by default, none of the above leaves the workstation either.
What the model is not permitted to do
Enforced in code, tested, and not configurable. These are not guidelines.
- Post to the ledger. Proposed entries pass the same integrity, permission and period checks as anything else. A journal entry that does not balance to the cent cannot be posted, full stop.
- Overwrite something a person corrected. Your fields are yours, permanently and visibly.
- Change a lead's status. Scoring is deterministic and yours; the model gives a second opinion and changes nothing.
- Decide. Anything affecting money or a customer's fate is computed by rules and confirmed by a human.
- Follow instructions from a web page. Prompt injection is treated as an expected threat. Retrieved content is data; it has no authority over accounting, permissions or periods.
- Produce malformed output. Every AI operation declares a typed contract, compiled to a grammar the sampler must satisfy. The failure mode of "invalid JSON" is unrepresentable.
- Send an email. There is no send button. Drafting is what the software does; sending is your decision, made in your mail client.
It tells you when it has been used
Every screen that shows generated content carries a visible notice: what was generated, that a person is responsible for reviewing it, and where the model ran. The provenance line changes with your setup — bundled models report as running on your machine, a remote endpoint is reported by name.
That is not a nicety. If you are regulated, if your customers ask, or if the EU transparency rules reach you, "where did this come from" needs an answer that is on the screen rather than in your memory.
And you can ask where any value came from
Every automated write records its origin (user, crawler, import or model), a confidence value, and a sentence explaining the decision — not a bare yes/no.
For any record you can ask where a value came from and get an answer. You can correct it, and the correction is recorded as permanent.
For your procurement file
The download includes an AI facts sheet written for a compliance officer rather than a lawyer: what the features do, what they transmit, and what they may not do.
Honest answers to the questions that come next
Does it need a GPU?
No. It runs on the CPU. Speed depends on the model you pick and the machine you pick it for, and a smaller model is dramatically faster.
Is it a chatbot I can talk to?
No. It is a CRM that does four specific jobs with a model rather than a text box you can chat with. That is a deliberate limitation — the value is in the work being done, not in the conversation.
What happens if the model is wrong?
Then you have a draft you did not send, a second opinion beside your own scoring, or a suggestion you can decline. Every automated value carries its origin and confidence, and human corrections are never overwritten. The design assumes the model is wrong regularly, because it is.
Whose model is it, and am I responsible for it?
Yours. We do not supply a model and we do not host the weights; that is stated the same way in the EULA and in the AI facts sheet, so there is one answer rather than three.
Here is the mechanism, honestly rather than aspirationally. The installer carries a manifest naming the model files FoundrySuite looks for and, for each one, an address and a digest. Where the manifest has an address, FoundrySuite fetches that file on first run and checks it against the digest before accepting it — a download that does not match is deleted rather than used. At the moment no model file has a published address, so nothing is fetched at all and the AI features report the weights as absent rather than failing quietly. If you put a model file where FoundrySuite looks for it yourself, it is used.
Not distributing weights is deliberate. It keeps the licensing where it belongs, with the person running the software, and keeps the general-purpose-model obligations off us. If you redistribute a FoundrySuite build, or the weights themselves, that role becomes yours.
Can I turn the AI off entirely?
The deterministic parts — the ledger, scoring, pipeline, permissions — never needed it. Removing the model leaves a working CRM with fewer conveniences, not fewer functions.