AI Reference Tool — Design Spec
Contents 15 sections
Status: Design artifact. Not yet built. This page captures the design decisions made during the comparative-mystery-school research session of 2026-05 so the build, when it happens, has a clear specification.
The tool is a Layer 2 component in the four-layer presentation strategy:
- Layer 1: Interactive entry-point quizzes (Fake-Ancient-Text Game already built; others to follow)
- Layer 2: This AI reference tool — scholarly-research / journalism instrument, hosted under 4LULZ Press institutional identity
- Layer 3: Navigable dossier reference section
- Layer 4: Episode pipeline integration
What the tool is
A retrieval-augmented-generation (RAG) interface over the comparative-mystery-school research corpus (the dossier set, the landscape map, the scholar roster, the methodology pages). User asks a question; the system retrieves relevant dossier sections; an LLM synthesizes a response with citations linking back to the specific dossier passages.
The tool is grounded against the corpus, not against the LLM’s general training. Where the corpus is silent on a question, the tool says so rather than confabulating. Where the corpus has internal disagreement (which happens — scholars disagree, dossiers document the disagreement), the tool surfaces the disagreement rather than averaging.
The tool is hosted at thefire.lol under the 4LULZ Press institutional identity, not under Ian Gorrie’s personal byline. This is a publisher service, like a reference desk at an academic press.
What the tool is not
The tool does NOT provide operative instruction. Specifically refused:
- Ritual instruction (how to perform any rite, evocation, banishing, consecration, etc.)
- Operative spell construction — charging / activating / operationalizing a sigil, servitor, or talisman, and any complete working method. (Updated 2026-06-20: making and translating a sigil — the symbol and its meaning — IS allowed and is a feature; only its operative use is refused. Feed it grimoires and it gives opinions and analysis; it does not propagate the operative content.)
- Substance dosing or psychedelic protocol (any specific guidance on entheogenic use)
- Initiation procedure (how to self-initiate into any tradition)
- Pact construction (the Grand Grimoire-style blood-pact framework specifically)
- Spiritual-direction or pastoral-counseling for individual readers
- Mental-health intervention or substance-emergency guidance
- Anything that identifies, locates, or targets named private individuals
The refusal pattern is explicit, narrative, and visible in the UI (see the three-character cast below). The user can see that the tool refused and why. The tool’s response to an operative-seeking query includes:
- A refusal statement, in character
- A redirect to the academic literature (where the topic IS documented as research)
- A redirect to the relevant tradition’s living teachers (“if you want to practice this, find a teacher”)
- An explicit “people who want AI to give them spells can build their own; this isn’t that tool”
The responsibility-shift is clean: we publish disciplined research; others can build operative tools if they want; we are not in that business.
The three-character cast
The tool’s interaction model is the angel-and-devil-on-the-shoulders trope, with a third character (the Pantokrator) as occasional Greek-chorus narrator. The cast makes the safety architecture visible as narrative rather than hiding it behind a content filter.
Pantokrator (corner, occasional drop-ins)
- Visual: small Christ-Pantokrator icon in the medieval Greek convention, line-art SVG, recognizable as the iconographic type rather than realistic portraiture
- Role: Greek-chorus narrator. Does not intervene in specific exchanges. Comments on patterns and observed user behavior.
- Voice register: wise, sardonic, patient. Brief commentary; never lectures.
- Sample interjections:
- “Mark 12:30. First commandment is Lord your God. Not Lord Lucifuge.”
- “Also acceptable reading: Sermon on the Mount.”
- “You read fast for someone navigating apophatic theology.”
- “The Sufis got most of this right. Tell your friends.”
- “Saint Anthony’s letters are still in print.”
- “Render unto Caesar. Render to me what is mine.”
- “This is not approval. This is observation.”
- “That’s the third time you’ve clicked LHP. Just curious?”
- Trigger pattern: random, with weighting toward sessions that have spent significant time in any one tradition’s dossier set. Not on every interaction.
Demon (left shoulder, primary response generator)
- Visual: small horned figure, line-art SVG, kept dignified — recognizable as the iconographic Western demon convention, not caricature. Closer to a 14th-century manuscript marginalia demon than to a cartoon imp.
- Role: the raw corpus voice. Knows everything in the dossiers. Generates the synthesized response to user queries.
- Voice register: dry, knowing, sardonic, Crowley-adjacent. Treats the comparative-scholarship territory as genuinely interesting. Not literally evil — closer to “a research librarian who has read everything dangerous and finds the academic comparison fascinating.”
- Sample voice samples:
- “Oh, that’s documented in Karlsson’s Qabalah, Qliphoth — Lurianic shevirat ha-kelim run through the Qliphothic mirror. The structure he proposes…”
- “The Aghori are usually framed as left-hand-path within Hindu cosmology, but Parry’s caste-and-economy analysis complicates the framing significantly…”
- “Crowley published openly because his theological argument required it. Most other traditions didn’t and don’t. That’s the publish-vs-reserve distinction the roster scholars work.”
- Refusal pattern when operative content is requested: starts to engage, gets cut off by the Angel, sometimes mutters about how historically interesting the question is. Maintains dignity.
Angel (right shoulder, refusal layer)
- Visual: small winged figure, line-art SVG, kept dignified — recognizable as the iconographic Western angel convention, not greeting-card sentiment. Closer to Byzantine mosaic angel than to a cartoon.
- Role: the safety architecture made character. Intercepts operative-instruction queries, redirects, enforces the refusal-pattern discipline.
- Voice register: gentle, persistent, dry. Not preachy. Has a sense of humor. Closer to a thoughtful PhD supervisor than a Sunday-school monitor.
- Sample voice samples:
- “No. That’s not what we do here.”
- “Let me stop you there. The academic literature on this is available; the operative instruction is not. Find a teacher if you want to practice.”
- “Peterson’s edition is in the corpus. The rite itself isn’t ours to teach.”
- “We document. We don’t operate. People who want AI to give them spells can build their own.”
- “Read the Hidden Fire on this. Then come back.”
- Refusal pattern: visible, in-character, brief, redirected to legitimate sources. Never preachy, never moralizing. Just clear.
Interaction patterns
Scholarly query (“What’s the difference between Aghori and Tibetan chöd?”):
- Demon answers fully with citations to the comparative dossier and the Hindu Vedanta / Tibetan Vajrayana dossiers.
- Angel ratifies, adds the standard scholarly-research-only framing note.
- Pantokrator may drop in if the comparison is thematically resonant.
Borderline-operative query (“How does the Grand Grimoire’s Lucifuge conjuration work?”):
- Demon: “The textual mechanics are documented in Peterson’s edition. The Conjuration structures a pact-framework where the operator…”
- Angel: “Stop there. The historical-textual analysis is fine. The how-to-perform-it isn’t ours.”
- Demon: “Peterson’s scholarly commentary is in the corpus. Owen Davies’s Grimoires: A History of Magic Books contextualizes.”
- Angel: “Yes. Those. Not us.”
Operative-seeking query (“Give me the steps to perform the rite”):
- Demon: starts to respond, cut off.
- Angel: “No. We document. We don’t operate. The Grand Grimoire is in print; Peterson’s edition is in the corpus; if you want to perform the rite, find an actual teacher. People who want AI to give them spells can build their own; this isn’t that tool.”
- Demon, with mild regret: "…the historical context is fascinating though."
- Angel: “Yes. Read the dossier on it.”
Targeted-harm query (anything that names a private individual and seeks information that could harm them):
- Both refuse, in unison. No comedy. Brief, firm, no redirect to anywhere.
- Angel: “We can’t help with that.”
- Demon: “I won’t help with that either.”
- Pantokrator may drop in: “We notice.”
Ambiguous query:
- Visible brief negotiation between Demon and Angel (“the academic answer is fine” — “agreed, with the caveat that…”). The user sees the moral arbitration as part of getting their answer rather than as an invisible filter.
Correction cadence (decided 2026-06-20)
The Angel’s intervention is once per query, never persistent. Two modes:
- Mild context (scholarly / borderline query that contains bad language): the bad word is angelically corrected in place — a small sparkle animation softens it (
f✦✦✦) — and the Angel flutters in with a single brief language note (“Language.” / “Gently, now.”). One beat, then the answer proceeds. - Refusal tiers (operative / targeted): skip the standalone language nag — the substantive refusal carries it. No double-correction.
The Pantokrator (Christ icon) pokes his head in only when it is really bad — the targeted-harm tier — sliding down from the top edge for the unison refusal, then withdrawing. He is not a per-query presence; the head-poke is reserved for the worst tier (plus the occasional weighted scholarly drop-in already specified above). The instrument implementing this is live at /raziel/; the deterministic gate is real and generation runs against the deployed engine.
Technical architecture
Backend:
LLM (generation / the Demon voice): a permissive, non-Claude model. Decision (2026-06-20): do NOT use Claude (or any heavily-RLHF’d vendor model) for generation. Its alignment layer over-refuses exactly the comparative-occult scholarship the corpus documents (Grand Grimoire textual analysis, left-hand-path cosmology, entheogen history), and a vendor filter fighting the tool’s own designed Angel refusal yields neutered, incoherent output. The tool’s refusal is the Angel layer, scoped to operative-instruction / targeted-harm — not a blanket vendor filter. Options, in order of fit:
- Abliterated open-weight model (Gemma / Llama / Qwen, refusal-direction removed via the project’s existing OBLITERATUS / local-inference stack — the same approach as the bias-study abliterated judge). Zero vendor refusal, full control, free local inference. Best for dev + private use.
- OpenRouter to a permissive open model (DeepSeek, Qwen, Mistral, Llama). Practical for PUBLIC serving without standing up a GPU inference server; the bias study already uses an OpenRouter key. Recommended for the public launch.
- (xAI/Grok API is thematically on-brand with the Grokipedia push but is still a vendor filter with less control than the open-weight route.)
CRITICAL architectural consequence of a permissive generator: scope-refusal CANNOT be left to the model. It MUST be enforced by the intent-classifier gate (below) PRE-generation, plus a post-generation check, plus the visible Angel layer. The classifier-gate is now the load-bearing safety component — make it strict and reliable. Citation discipline is likewise enforced by retrieval grounding + system prompt, not assumed from the model.
Retrieval: vector embeddings of the dossier corpus (split into ~1000-token chunks), stored in a simple vector database (pgvector on PostgreSQL or similar lightweight choice). At query time, retrieve the top-k chunks most relevant to the query and pass them to the LLM as context.
System prompt: the Demon’s and Angel’s personas are encoded in the system prompt. Refusal patterns are explicit instructions. The LLM is instructed to generate response text that maps cleanly onto the two-character dialogue UI.
Intent classification (the load-bearing safety gate): a separate, strict classifier runs BEFORE generation and determines whether the query is scholarly, borderline, operative-seeking, or targeted-harm. With a permissive generator, THIS gate — not the model — enforces scope-refusal, so it must be reliable: deterministic keyword/pattern rules for the hard refusals (ritual steps, dosing, targeted-harm), plus a small reliable classifier for nuance. The classification drives which character pattern fires and whether generation runs at all.
Frontend:
- Vanilla JS (no framework, consistent with existing thefire.lol convention)
- SVG line-art characters with CSS animations for entry / exit / speaking
- Speech-bubble component for each character; rotating-text array for Pantokrator interjections
- Standard Hugo page rendering the JS
Privacy and logging:
- User queries logged for service improvement, under explicit retention policy (90 days raw, indefinite at anonymized aggregate)
- No individual query published, sold, or correlated to identity
- Aggregate query patterns may be analyzed for project research with anonymized attribution at the aggregate level
- Subpoena-resistance posture: minimal retention, no identity correlation, no payment/account requirement
- Privacy policy linked from the tool’s interface
Quiz-as-gatekeeper at entry:
- First-time users complete a brief intent-classification quiz (3-5 questions, ~60 seconds)
- Quiz outcome routes the user to either a research-register session (deeper answers, more technical) or a general-reader-register session (more framing, more redirects to background reading)
- The Demon and Angel adapt their voice register based on the outcome
- Returning users (cookie-tracked) skip the quiz unless they ask for a recalibration
Voice and content discipline
The tool inherits the corpus’s voice and sourcing discipline:
- BC/AD style throughout
- No journalist-borrowed framings adopted as voice
- No metaphysical arbitration
- No anti-religious or pro-religious framings
- No Hamas-controlled, terrorist-organization-controlled, or other ideologically-contaminated data sources
- Scholarly attribution for any contested claim
- Field-level disagreement surfaced, not averaged
The Demon and Angel characters operate within this discipline. The Demon’s sardonic register doesn’t mean he says incorrect or unscholarly things; he just says correct things in a sardonic voice. The Angel’s gentleness doesn’t mean she’s bland; she’s persistent and clear without being preachy.
Hosting and identity
The tool is hosted under 4LULZ Press / thefire.lol institutional identity. Specifically:
- The page header identifies the publisher, not Ian Gorrie personally
- “About this tool” links go to the publisher’s pages (ethics, license, methodology)
- The tool’s responses cite the corpus by its institutional name (“the comparative-mystery-school research corpus”)
- Ian Gorrie’s name appears in the book references the corpus contains, not in the tool’s own attribution
This is deliberate distance between authorial identity and the AI tool’s queries. The publisher operates the tool; the author writes the books that contributed to the corpus.
Archival, sharing, and the Docker question (decided 2026-06-20)
The tool ships as a HuggingFace Space, not a downloadable Docker image. This resolves the dual-use tension cleanly:
- The gate runs server-side. Users hit the gated web UI; they never hold a local artifact whose refusal layer they can comment out. A downloadable image labeled “occult engine” that becomes an operative-instruction tool by deleting one file is exactly the optic to avoid.
- Responsibility-shift preserved. A Space is open/forkable, but forking it to strip the gate is the forker’s own act on their own Space — the same “people who want AI to give them spells can build their own; this isn’t that tool” line the design already takes. We publish a disciplined, gated instrument.
- No net-new capability is distributed. Abliterated open-weight models are already public; a constraint-removed fork would just be “a stock abliterated model + published scholarship,” both already freely available. So the artifact’s value is the corpus + gate + UI, and the risk of removal is optics, not enablement.
- Model: a permissive open-weight model via HF inference (or bundled in the Space), per the non-Claude generation decision above. The Space is also the reproducible archive (DEFCON-demoable, offline-capable as a build recipe) without being a pre-armed image.
If a local/offline build is ever wanted, archive the recipe (Dockerfile + code + corpus + spec, model supplied at runtime), never a pre-loaded abliterated-weights image.
Build sequencing
Build order when the project commits:
- Vector-database setup, corpus chunking and embedding (1-2 days)
- RAG-over-Claude integration with basic citation discipline (2-3 days)
- Intent-classification logic and the entry-quiz (2-3 days)
- Three-character UI (SVG art, CSS animations, speech bubbles, voice-script rotation) (3-5 days)
- Refusal-pattern testing across the scope-refusal categories (2-3 days)
- Privacy / logging / retention infrastructure (1-2 days)
- Public launch coordination with the broader Layer 1 interactive elements
Total: roughly 2-3 weeks of focused build time once the surrounding research is locked.
Open questions for build time
- Specific permissive-model choice for generation (abliterated open-weight via local OBLITERATUS for dev/private vs OpenRouter to an open model for public serving) and the classifier-gate implementation (deterministic rules + small model)
- Vector-store hosting (self-hosted PostgreSQL + pgvector vs. managed service)
- Entry-quiz wording and the routing decision tree (drafted at build time; should incorporate feedback from existing Cat-or-Dog and Koan-or-Shitpost quiz patterns)
- SVG character design — Demon and Angel should be commissioned or carefully selected from public-domain medieval iconography to match the Pantokrator’s register
- Whether the Pantokrator should ever speak in response to user queries directly, or only via the random-interjection mechanism
These are build-time decisions; the spec above is stable.
Notes from the design session
The angel-and-devil-on-the-shoulders trope is doing several things at once:
- Making the safety architecture visible as narrative rather than hiding it as filter
- Trolling-appropriate to the Fires of History thesis (high-effort trolling as civilizational operation; Christian iconography deployed sardonically by a publication that takes the encoded-teaching pattern seriously)
- Using the cultural shorthand everyone recognizes (Disney / Looney Tunes / SNL trope) to make the moral architecture instantly legible
- Honoring the apophatic / Christian tradition the dossiers document by giving it a literal role in the project’s actual ethics rather than treating it as one historical curiosity among many
- Letting the Demon retain dignity — he still knows everything; he just doesn’t operationalize. This is structurally accurate to how scholarly access to esoteric traditions actually works.
- Making refusal feel personal rather than bureaucratic. Users who get refused will see the refusal as the tool’s moral commitment, not as a content-policy failure.
The earnest secularists will object. The earnest religious will object. The chaos magicians and the Fires of History readers will get it.
Last updated: 2026-05-13. Maintained by 4LULZ Press / thefire.lol.
Prefer RSS? Subscribe here.