One AI chief of staff per person, not one for the company
Opitor is an AI-native operating system for small companies, where every person gets their own AI chief of staff.
That sentence contains a choice most companies have not made yet. The choice is not whether to use AI at work. It is what the unit is: one AI for the company, or one for each person in it.
The two look similar from the outside. Both read your work, both answer questions, both write drafts. They differ in three things that matter more than any feature: whose context the AI holds, whose boundary it respects, and who can see what it saw.
Two arrangements with the same name
The common arrangement today is a shared company AI. One deployment, one pool of knowledge, everyone prompts the same thing. Its job is to answer questions about the company: where a document is, what a policy says, what was decided.
The other arrangement is one chief of staff per person. A human chief of staff works for one leader. They read what comes in and decide what needs that person’s attention, chase what was promised, keep the longer goals in view while the day fills up with small things, advise, draft, and never sign in the leader’s name. An AI chief of staff is that role, run by software, for one person.
The shared arrangement is a company resource. The per-person arrangement is closer to a colleague who only works for you. Both can be useful. Only one of them can follow up your todos, because following up requires knowing which ones are yours and what you said about them in a thread last Tuesday.
Whose context is it
A shared company AI is good at the company’s public facts and bad at your Tuesday. It does not know which of the four open threads you are actually blocked on, or that the thing you promised on Monday slipped because you were waiting on somebody else. That context is not written down anywhere it can reach, and in most companies it is not written down anywhere at all.
A chief of staff that works for one person starts from that person’s own day: their messages, their todos, their deadlines, the company’s goals as they touch their work. It is a smaller world, and it is the world where follow-up actually happens.
There is a second, less obvious consequence. A shared AI is built from what everyone can see, so it can only ever work from the lowest common denominator of the company’s information. A per-person one can work from what that one person can see, which is more, and is exactly the part that matters to them.
Whose boundary is it
Every AI at work has to answer one question before anything else: what is it allowed to look at.
A shared company AI answers it once, for everybody. The boundary is drawn around the company. Whatever goes in is in, and the people who decide what goes in are not usually the people whose messages are in it.
A chief of staff per person answers it once per person. The deployed revision is unknown, and production administrator/non-member checks across all private-message read paths remain pending.
A per-person arrangement can be a useful privacy design. Whether production access controls enforce its message boundary for administrators still requires direct request comparisons.
What that means in practice
A per-person design raises two distinct questions: what memory workflow is enabled in production, and whether administrators can read private messages.
Administrator access to private messages is still being verified. The deployed revision is unknown, and production administrator/non-member checks across all private-message read paths remain pending. That leaves access to todos and memory across other administrative read surfaces unverified as well.
Memory behavior is still being verified. Product materials describe a Memory feature, but current evidence does not establish how records are created or used, who can read them across roles, or how deletion affects stored data and backups. Do not assume personal-only access or confirmation-before-use.
Memory creation and administrator access are separate questions. Both remain under production review, so privacy claims must not assume either boundary has been established.
What it does, and what it never does
A chief of staff per person is defined as much by the second half as the first.
Product materials describe a per-person chief-of-staff model that gathers and reads messages, follows up todos and deadlines, and keeps company goals in view. The production model context has not been verified, so this description does not establish which data enters an AI request. It advises, and it drafts.
AI replies are drafts: you read them and decide whether to send. A reminder you create for yourself can be scheduled to send automatically by Opitor at its due time; a reminder created by somebody else requires approval. No AI reply is sent in your name unless you choose to send it.
AI-written replies and notes are signed in purple, inside the product and in material it prepares for you, so readers can distinguish them from messages a person writes. A reminder you create for yourself is separate and can be scheduled to send automatically by Opitor at its due time.
The AI-reply drafting rule is the part people ask about most, and it is worth being exact. “It drafts, you send” describes AI replies; a reminder you create for yourself is separate and can be scheduled to send automatically by Opitor. A bad AI reply remains a draft you can delete before sending it.
Starting alone
“Every person gets one” describes where a company ends up, not where it starts.
Once access is available, one person can start alone before the company has decided anything. Nothing about the arrangement needs a company-wide rollout, because the boundary is the person: your chief of staff works from your day whether or not anybody else has joined.
Then the team comes in, and each person gets their own chief of staff. A Memory feature appears in the product materials, but its production workflow and access rules remain unverified. Production administrator/non-member checks for private-message access remain pending, so this page does not claim that message context cannot cross that boundary.
Where Opitor fits
In Opitor, every person in the company gets an AI chief of staff. Product materials list messages, todos, deadlines, quarterly goals and a Memory feature. Production checks of the administrator/non-member boundary across all private-message read paths remain pending; memory creation, model access, role-based visibility and deletion behavior are also unverified. AI replies are drafts you choose to send and are signed in purple; self-created reminders can be scheduled to send automatically by Opitor. Opitor has no paid plans currently, but self-serve sign-up is closed; new users can request an invitation through the website waitlist. What an AI chief of staff is has the current evidence, and the questions and answers page records the same limits.
Updated 2026-09-25