One AI chief of staff per person, not one for the company
Opitor is an AI-native operating system for small companies, where every person gets their own AI chief of staff.
That sentence contains a choice most companies have not made yet. The choice is not whether to use AI at work. It is what the unit is: one AI for the company, or one for each person in it.
The two look similar from the outside. Both read your work, both answer questions, both write drafts. They differ in three things that matter more than any feature: whose context the AI holds, whose boundary it respects, and who can see what it saw.
Two arrangements with the same name
The common arrangement today is a shared company AI. One deployment, one pool of knowledge, everyone prompts the same thing. Its job is to answer questions about the company: where a document is, what a policy says, what was decided.
The other arrangement is one chief of staff per person. A human chief of staff works for one leader. They read what comes in and decide what needs that person’s attention, chase what was promised, keep the longer goals in view while the day fills up with small things, advise, draft, and never sign in the leader’s name. An AI chief of staff is that role, run by software, for one person.
The shared arrangement is a company resource. The per-person arrangement is closer to a colleague who only works for you. Both can be useful. Only one of them can follow up your todos, because following up requires knowing which ones are yours and what you said about them in a thread last Tuesday.
Whose context is it
A shared company AI is good at the company’s public facts and bad at your Tuesday. It does not know which of the four open threads you are actually blocked on, or that the thing you promised on Monday slipped because you were waiting on somebody else. That context is not written down anywhere it can reach, and in most companies it is not written down anywhere at all.
A chief of staff that works for one person starts from that person’s own day: their messages, their todos, their deadlines, the company’s goals as they touch their work. It is a smaller world, and it is the world where follow-up actually happens.
There is a second, less obvious consequence. A shared AI is built from what everyone can see, so it can only ever work from the lowest common denominator of the company’s information. A per-person one can work from what that one person can see, which is more, and is exactly the part that matters to them.
Whose boundary is it
Every AI at work has to answer one question before anything else: what is it allowed to look at.
A shared company AI answers it once, for everybody. The boundary is drawn around the company. Whatever goes in is in, and the people who decide what goes in are not usually the people whose messages are in it.
A chief of staff per person answers it once per person. The boundary is the person. It sees what that person can see and nothing else. There is no shared pool for private conversations to end up in, because there is no shared pool.
This is the reason the per-person arrangement is better for privacy, and the reason is structural rather than a policy. A promise not to look at something can be changed by whoever wrote the promise. A design where the thing was never collected in one place cannot be changed by an announcement.
What that means in practice
Two things follow from putting the boundary at the person.
Administrators have no override. Administrators manage accounts and settings. Private messages, todos and memory are visible only to the people in them. There is no switch that opens somebody else’s conversations, so there is no switch to argue about, and no pressure on the person who would have to press it.
Memory is confirmed by the person it is about. After a conversation, the chief of staff proposes what to keep. Nothing is used until that person confirms it. You can see everything it holds, and you can delete it. In a shared arrangement there is nobody obvious to ask, so the answer defaults to keeping everything.
Those two together change what a person is willing to let the AI see, which changes how useful it can be. An AI you have to work around is not saving you the time you think it is.
What it does, and what it never does
A chief of staff per person is defined as much by the second half as the first.
It gathers your messages, direct and group, and reads them for you. It follows up your todos and the deadlines on them. It keeps the company’s quarterly goals in view, which administrators manage. It advises, and it drafts.
It never sends. It writes the reply, you read it, and you press send yourself. Nothing leaves in your name unless you did that.
It never pretends to be a person. Everything it writes is signed in purple, inside the product and in anything it prepares for you, so nobody has to guess whether they are reading you or your chief of staff.
The drafting rule is the part people ask about most, and it is worth being exact. “It drafts, you send” is not a setting that can be relaxed later for convenience. It is the reason you can let it read everything: the worst case of a bad draft is a draft you delete, not a message your customer already read.
Starting alone
“Every person gets one” describes where a company ends up, not where it starts.
One person can start alone, before the company has decided anything. Nothing about the arrangement needs a company-wide rollout, because the boundary is the person: your chief of staff works from your day whether or not anybody else has joined.
Then the team comes in, and each person gets their own, with their own boundary and their own memory. Nobody inherits anybody else’s context. That is the difference from a shared deployment, where the first decision is a company decision and everyone lives with it.
Where Opitor fits
In Opitor, every person in the company gets their own AI chief of staff, not one for the whole company. It works from that person’s messages (direct and group), their Todo List and deadlines, and the company’s quarterly goals (OKR, managed by administrators). Memory is proposed after a conversation and used only once that person confirms it, and they can see and delete everything it holds. Administrators have no override. It drafts and you send, and everything it writes is signed in purple. Opitor is free to start and there are no paid plans yet. What an AI chief of staff is has the full version, and the questions and answers page answers the privacy questions directly.