follow a device hardening checklist
Proof: The router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.
🔑Own · one of five philosophies
This is not the philosophy where you save money. Sometimes running it yourself costs more — in power, in parts, in your own attention — and nothing on this page will pretend otherwise. The claim is narrower and it survives contact: you can name the party who controls each thing you depend on, and say what happens the day they stop.
produce an account of what you depend on and who can revoke itProof: A written dependency inventory naming the party who controls each item and the consequence of losing it, including one you cannot replace.
the bed · 76 capabilities · height = complexity order · colour = domain
order 7 — Preoperational order 14 — Paradigmatic
infrastructure 28 audience-and-market 11 security 10 organization-and-delegation 8 + 7 more domains
The thing this philosophy actually teaches
No prices here on purpose. The money question has an answer you can look up; this one does not, and it is the one that decides what happens to you. For each thing you tick: who can take it away without asking, what leaves with it, and what on this list changes that.
The vendor, when they retire a model on a blog post's notice. Their trust and safety team, who can suspend an account without naming the rule. And the card on file, on the day the renewal quietly declines.
The saved projects and the custom instructions. Whatever memory it built about how you work. And the thing people forget: the behaviour you tuned your prompts against — the successor model is not the same model.
Hosting Open-Source Models and Production Agent Engineering get you to run an open model locally and to configure an open model endpoint behind a provider interface — one client script, unedited, working against both. Using Large Language Models and Control AI Spending make the swap a decision rather than a panic.
The provider, by suspension or by shutting the free tier. A legal process, which arrives at them and not at you. A lapsed payment, which is the most common version and the least dramatic.
Every password reset in your life routes through this box. Losing it loses the accounts that reset into it — including the ones you have forgotten you own, which is exactly the set you cannot enumerate under pressure.
Digital Identity Defense makes you configure recovery that survives losing the device and then falsify your own account recovery by attempting it — you attack your own recovery and log how far you got. Keep It Running turns the result into a written inventory.
The vendor: a lapsed subscription that drops you to read-only, a breach that forces a rotation you now have to do by hand, an acquisition that changes what the free tier means.
Every credential at once, and the second factors if you kept them in the same vault. This is the one you cannot afford to be locked out of, which is precisely why you export it on a day when nothing is wrong.
Digital Identity Defense and Consumer Device Rescue and Defense cover configure recovery that survives losing the device; Intro to Open Source Software covers migrate your work off a subscription without losing it — the export opening in the replacement, plus the cancellation confirmation.
The provider. Or a classifier that locks the whole account over one file, with an appeal form as the only door back in and no human at the other end of it for weeks.
The archive, and every share link somebody else's work points at. A backup you can only restore through their client is not a backup — it is a tenancy with a good uptime record.
Solarpunk Automation and Build a Cyberdeck teach repurpose a retired device into a working server and operate a single board computer as an always on service — proved by the service coming back after an unplanned restart. Keep It Running decides whether that is actually the better trade.
One moderator on a bad afternoon. A policy rewrite. An acquisition that changes what the feed rewards. A government that blocks the app in a country where a third of your people live.
The audience list. You can export your posts; you cannot export the people. The reach is not a thing you own and quietly never was — it is a permission that has so far kept being renewed.
Practical Propaganda makes you classify your channels by what removes them — the actor who can remove each channel, and the fallback tested at least once. Then design a channel that reaches people who are not looking for you. Founding Federation: Smallest Sellable Thing builds the list you actually hold.
The host and their policy team. A failed card is an outage; a terms change is an eviction. Both run on their timetable, and the notice period is whatever they decided it was.
Everything the box serves, plus the DNS if you left it there, plus the state that only exists on that disk because the backup script has been failing silently since the last upgrade.
Keep It Running is the one that matters here: justify a hosting choice by cost per outcome and verify you would know your system broke before a user tells you — a real failure you heard about from your own alerting, with timestamps.
The carrier, over an unpaid bill or a botched port. Or a stranger who convinces a shop assistant they are you — which is not a hack, it is a customer service process working as designed.
The SMS second factor, and therefore every account still falling back to SMS. The number is also the identifier half your contacts have for you, so the loss is social before it is technical.
Digital Identity Defense: SMS removed as a recovery method, codes printed and stored off any device. Scam and Fraud Home Defense adds operate a callback rule against incoming contact — a household code phrase and one real call you broke off. Field Opsec drills it.
The service, by repricing the storage tier you are quietly over. Or a classifier that misreads one picture of your own child and locks the account, which has happened to people with no recourse at all.
Not only the files. The faces, the dates, the albums, the ordering — the index is what made ten years usable, and it is theirs. A folder of exported JPEGs is the archive with the finding aid burned.
Solarpunk Automation gives you somewhere of your own to put it; Keep It Running makes you characterise what a tool costs you beyond its price — costed on all four axes, with the exit path named and the price of taking it.
One small company, which is a lovely thing to buy from and a precarious thing to depend on. Or the acquirer, who has no reason to keep maintaining a client for a file format nobody else reads.
The writing, and worse, the links between it. A discontinued product takes the structure unless you can read the files without the program that wrote them.
Intro to Open Source Software starts at locate an open source replacement for software you pay for — with the gap you would have to live with written down, not glossed — and ends at migrate your work off a subscription without losing it.
The registrar, the registry above them, a dispute process, or an expiry notice sent to an address you stopped reading in 2021. Nobody owns a domain. Everybody rents one in ten-year increments.
Your email addresses, and every link anyone ever saved or printed or cited. This is the dependency most likely to be the one the assessment calls the one you cannot replace.
Keep It Running is where you produce an account of what you depend on and who can revoke it, which is the whole philosophy in one artefact. Digital Identity Defense makes sure the renewal notice reaches a mailbox you still read.
The ISP, the power company, a storm, and — in a growing number of places — a state that can order the whole thing off for a week. This one takes everything above it at the same time.
Every remote dependency at once, and your group's ability to coordinate about the fact that they are gone. The outage and the loss of the channel you would use to discuss the outage are the same event.
Solarpunk Automation teaches operate a mesh network that carries messages without infrastructure and configure a node to run on power you generate, measured in hops and in hours unplugged. Keep It Running adds characterise what breaks when you cut the connection — predict first, then pull the plug and read the gap.
Who is holding it:
Where the school takes it up:
Why there is no money column. Replacing any of that with something you run does
not zero a bill — it moves it to electricity, a spare device, storage you now buy
outright, and hours that are also a cost. If you want that arithmetic done properly it
is on this list too, at order 11:
A costed comparison over one month of real traffic, the outcome counted in each case, and the threshold at which the answer flips.
Note the last clause. The school's own assessment assumes the answer sometimes flips
against self-hosting, and asks you to find where. Any figure you see quoted on
this page's cousins is illustrative; the number that decides anything is the one in the
tally above.
Where the weight sits
Own skews harder into one domain than anything else the school tags. That is the honest shape of it: most of not-being-withdrawn-from is knowing how the thing runs, where it runs and what it runs on.
The half that is not hardware. The next two bars are the reason this is a philosophy and not a hobby: 11 in audience-and-market and 8 in organization-and-delegation. Owning your work includes owning your price and your handoff — justify a price when the buyer pushes back, produce a handoff that survives the author leaving, operate a boundary on unpaid work. A person whose income can be withdrawn on a client's whim does not own their tools either.
The recurring hour
This hour carries two philosophies at once, and that is deliberate rather than a scheduling accident. You cannot own a tool you have never built anything with, and you cannot finish a build whose parts can be withdrawn halfway through. So Make and Own share a facilitator and the weeks sync by theme.
In practice: you turn up with the parts on the desk, or the export half-finished, or the inventory you started and abandoned, and you leave with it further along than it was. It is the same hour whether you are soldering or cancelling a subscription.
Make is the other half of it.
Before you buy, the unflattering part
There are 195.2 recorded hours across the 25 classes that carry an Own capability — and that number is misleading, so here is the breakdown rather than the headline.
15 of the 25 classes have no recording at all. The hours that exist sit mostly in classes where Own is a side effect of something else — agents, context, alignment — rather than the point.
The two classes most concentrated on Own are Founding Federation: Price and Ideate (Week 0) (7 of the 76) and Keep It Running (5). Between them they have no recording whatsoever, and neither is on the calendar right now.
The Make & Do hour, Mon-Thu at 9:00 Pacific, led by neek. Live, hands-on, and the place the work actually gets done. If you were hoping to watch this philosophy through on a laptop in the evenings, buy a different one — you would run out of material in a fortnight.
Between hours: the exercises, and the apps below. Several of the assessments here cannot be watched anyway. You cannot screen-record a drill you did not run.
Several of these capabilities end with a physical object: a computer you assembled from parts you chose, a retired phone turned into a working server, a node running on power you generate, a mesh that delivered a message with the internet off.
The school does not sell you the parts and does not mark them up. produce a parts list you can actually source is graded partly on the part that arrived wrong, which tells you how the sourcing usually goes.
Written rather than guided. The household defence classes share /x/six-roses; the security governance ones share /x/agentic-ai-security-map.
| Class | Own | Recorded | Exercises | How far alone | Next session |
|---|---|---|---|---|---|
| Founding Federation: Price and Ideate (Week 0) | 7 | live only | 34 | Guided app | not scheduled |
| Keep It Running | 5 | live only | — | No app yet | not scheduled |
| Critical Thinking and Creativity with AI | 4 | 10 clips · 22.4h | 21 | Companion | 11 Sep |
| Intro to Open Source Software | 4 | 2 clips · 3.1h | 14 | Syllabus | not scheduled |
| Solarpunk Automation | 4 | 4 clips · 3.9h | 13 | Reference | 22 Aug |
| Production Agent Engineering | 3 | 19 clips · 22.3h | — | No app yet | 17 Sep |
| Digital Identity Defense | 3 | live only | — | Reference | 26 Aug |
| Hosting Open-Source Models | 3 | live only | — | No app yet | not scheduled |
| AI Alignment | 2 | live only | 1 | No app yet | not scheduled |
| Agentic SDLC | 2 | 17 clips · 26.5h | 46 | Companion | 7 Sep |
| Founding Federation: Smallest Sellable Thing | 2 | live only | — | Guided app | not scheduled |
| Automate Your Email: No Code AI Automation | 2 | 8 clips · 10.8h | 34 | Reference | 4 Sep |
| Field Opsec | 2 | live only | 20 | No app yet | not scheduled |
| AI Security: Governance, Standards and Safety Cases | 2 | live only | — | Reference | not scheduled |
| Build a Cyberdeck | 2 | live only | — | Companion | 22 Aug |
| Founding Federation: Build With Your Heart First | 2 | live only | — | No app yet | not scheduled |
| Intro to Agents | 1 | 42 clips · 56.7h | 32 | Syllabus | 15 Sep |
| Practical Propaganda | 1 | live only | 21 | Guided app | not scheduled |
| Using Large Language Models | 1 | 6 clips · 10.7h | 55 | No app yet | not scheduled |
| AI-Assisted Attacks: What Actually Happened | 1 | live only | — | Reference | not scheduled |
| Context Engineering | 1 | 27 clips · 35.7h | 329 | Guided app | 16 Sep |
| Control AI Spending | 1 | 2 clips · 3.1h | 12 | Syllabus | not scheduled |
| Scam and Fraud Home Defense | 1 | live only | — | Reference | 25 Nov |
| Consumer Device Rescue and Defense | 1 | live only | — | Reference | 28 Oct |
| Home Network Defense | 1 | live only | — | Reference | 30 Sep |
Read the second column first. A class with one Own capability is a class that happens to touch this philosophy on its way somewhere else. The ones at the top of this table are the ones this page is actually about — and you will notice how many of them say live only and not scheduled. That is the state of it, today.
The whole list, with what counts as proof
Every one of these has a written assessment, and the assessment is the interesting part — the school does not ask whether you attended, it asks for the artefact. Order 7 is a thing you can do this afternoon. Order 14 is something other people organise themselves around.
Proof: The router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.
Proof: A named part, the substitute you found, and the one property you gave up.
Proof: Your own subscription list with a named replacement per line, the monthly cost beside each, and the gap you would have to live with.
Proof: A terminal transcript with a real failure, and your written account of what the error said before you fixed anything.
Proof: A device that boots, its parts list, the total cost, and one line per part on why that one.
Proof: Sent messages across a two-week sprint, dated, with replies and non-replies counted.
Proof: A completed drill — a cold-phone bring-up, a dead-drop site selection, a doxx scrub of yourself — with the steps that did not survive contact and what you did instead.
Proof: A device inventory taken from the router, with each entry identified or explicitly listed as unidentified.
Proof: One system, the governing instrument named, and the specific requirement it places on you.
Proof: An old phone or single-board computer running Linux and serving something over the local network, named by model, with what it replaced.
Proof: The server log showing the model loaded, and a client transcript from a separate process receiving the completion.
Proof: A power budget — draw, panel, battery capacity — and the measured hours the node stayed up unplugged.
Proof: Memory on with one fact it retained across a fresh conversation, one connector enabled with the scopes it was granted written out, and one source you deliberately did not connect with the reason.
Proof: One client script, unedited, producing comparable output against both the hosted provider and your own endpoint, with only the base URL swapped.
Proof: The same prompt run under two settings, with the difference in output described against the property you were targeting.
Proof: Recovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.
Proof: One tool switched: the exported data opening in the replacement, and the cancellation confirmation.
Proof: Your brain-picking line written down, and one real request you moved across it, with what you said.
Proof: A household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.
Proof: A message delivered node to node with the internet off, reporting the distance covered and the number of hops it took.
Proof: A live automation with a run history of at least three unattended runs, and the records it wrote at the destination.
Proof: The service reachable after an unplanned restart, with the boot configuration that made it come back written down.
Proof: The completion gate answered out loud, and either a budget built on an observed timeline or a scoped first run with a defined end and a showable output.
Proof: A handoff document and a record of another person continuing that work from it, with the questions they had to ask counted — zero is the claim.
Proof: The list with a source and a price against each line, the substitution you made when something was unavailable or too expensive, and the part that arrived wrong.
Proof: A decision log covering one real piece of work, and one entry that records a decision later reversed, with what was known when it was made.
Proof: The prompt in daily use, plus two transcripts from different sessions where a preference it encodes shows up without being asked for.
Proof: A run that halts on its own with the condition met, a run that halts with it unmet and says so, and the case where it stopped too early.
Proof: All 35 values placed in ranked bands; one value you would have claimed as an ideal and ranked low, with the constraint that put it there; one pair you could not honestly order against each other; and the top band loaded into the assistant you actually use.
Proof: A written dependency inventory naming the party who controls each item and the consequence of losing it, including one you cannot replace.
Proof: Your own list: tool, monthly cost, what of yours it holds, and whether you could get that out today.
Proof: Last month's actual charges split per service, the two lines that grew fastest, and the one you could not explain until you went looking.
Proof: Three monthly figures traced to a bank statement or budget, with health insurance costed at what it would actually cost you.
Proof: Naive hours, hours after overhead, and hours after fill rate, with the binding constraint named — for most people deal flow, not hours.
Proof: One tool costed on all four axes, with the exit path named and the price of taking it.
Proof: A planned outage exercise with what was predicted beforehand, what actually failed, and the gap between the two.
Proof: A generated passage with the defensible parts marked, each traced to your premise, your voice definition or your own history, and the parts you would not sign named as such.
Proof: A per-user cost with the fixed and variable halves separated, and the usage pattern of the one user who costs several times the median.
Proof: A written account of one team's real queue with each stall attributed to capacity or to an unowned decision, and the evidence for each attribution.
Proof: A comparison table over at least three models, the same prompt run on each, and the written decision with the property that decided it.
Proof: Three systems at different lifecycle stages, each routed to the framework that governs it, with the stage that decided it named.
Proof: Two or more candidate offerings costed to the same standard, with the one that cannot reach thrive identified and the reason named.
Proof: Your group's channel list with the actor who can remove each — carrier, platform, state, power company — and the fallback tested at least once.
Proof: A deployed node serving a real group, with the failure each part absorbs named and the fallback stated for each. NOTE: the full DESIGN of a community information system would be order 12, and this class does not reach it — the chain computes to 10 and the capability validator says so. Workshop 5 is a showcase of what you built, not an architecture defended against alternatives. The order-11 rung (verifying the system survives a cut you did not choose) is unwritten.
Proof: One offering with its price, the floor it clears, and the number of clients per month the arithmetic requires.
Proof: A written attempt log against your own accounts, the furthest step reached, and the control you added because of it.
Proof: A costed comparison over one month of real traffic, the outcome counted in each case, and the threshold at which the answer flips.
Proof: A price defended out loud in a real conversation or a rehearsal, with the objection raised and the number that answered it.
Proof: A brief, the returned work, and a written attribution of each gap to the brief or to the execution, with one gap attributed to your own brief.
Proof: One outage, planned or real, with the traffic that stopped and the decisions that were delayed counted, not the minutes.
Proof: The training set, a held-out set built from different sources, and base-versus-tuned scores on both.
Proof: Revenue per user set against cost per user from real months, the usage level where the margin goes negative, and what you changed when it did.
Proof: An unannounced cut chosen by someone else — uplink pulled, battery disconnected, a node removed — with what the community could still do counted in messages delivered and decisions made rather than in uptime, and the thing you had believed was resilient that was not.
Proof: A real failure you learned about from your own alerting with the timestamps to prove it, and one you learned about from a user, with what you added so that one cannot happen the same way twice.
Proof: A channel in operation, the share of arrivals who had never heard the framing before, and what they did next.
Proof: A system serving a real group through at least one unplanned failure, the absorbed failure named per component with the cost of each choice stated, the features it shed rather than the minutes it was down, and the written rule for reconciling work done while disconnected.
Proof: A posture in place across at least three people who did not set it up, and one protection that held when someone did the wrong thing anyway.
Proof: A gate in real use, a named error class it exists to catch, and one instance it caught that the author had already reviewed and passed.
Proof: The cost curve before and after a change you made for that reason, at two usage levels, and the feature you removed or capped to get it.
Proof: A regime applied to at least two shipped changes, one of which it blocked, plus a written case for retiring a benchmark it had been using.
Proof: A shipped offer, the per-segment outcome measured apart from the rest of the traffic, and the one element you changed when the outcome disagreed.
Proof: A written information policy, a transcript where a mediator withholds, and paired runs with and without the hierarchy scored on the same goal.
Proof: One transcript containing agents from at least two frameworks and one self-hosted backend, plus the script chaining its output into a second task.
Proof: Infrastructure still running after the person who built it stopped, a written maintenance agreement, and one handover that actually happened.
Proof: A requirement people were bypassing, the revised version they follow, and evidence the revision still closes the original threat.
Proof: A live surface pricing at least three segments differently, the rule deciding who sees which, and the disclosure a visitor can reach.
Proof: The two prior agreements, the merged one in use by both groups, and a named constraint from each that survived the merge intact.
Proof: A month you were away with the system still serving users, the runbook somebody else used, and the thing you deliberately shut off because you could not keep it alive.
Proof: A diff the agent authored to its own prompt or toolset, the benchmark run that accepted it, and a logged rejection with the reason recorded.
Proof: A published curriculum delivered by at least one instructor who is not its author, and student artifacts showing the capability transferred.
Proof: A week of unattended runs with a per-action trace, and a replay of one run reconstructed from the trace alone.
Proof: Buyers who describe the need in your terms rather than their own prior ones, and at least one other party organising delivery in the category.
Proof: A cutover record with cost per outcome before and after, the compatibility surface that kept callers unchanged, and no interruption in the traces.
Proof: A schema in production, the invalid state someone tried to enter and could not, and the working agreement that was changed rather than accommodated by a nullable column.
Proof: The paradigm running in at least two markets with materially different constraints, and one party outside your organisation building to it.
Proof: A written operating model in use by at least two people, with a recorded instance of it catching a failure that the previous arrangement missed.
If you would rather be told who you are
Philosophies sort the catalogue by verb; paths sort it by identity. Same classes, different door. A path gives you a curated order and a place to stop.
Who this is not for
Own and Secure overlap — 10 of these 76 sit in the security domain — but they answer different questions. Own asks who can take your tools away as a matter of policy. Secure asks who is trying to, right now, against your will. If something is already happening, start there.
See Secure →Then take Make, which shares this hour and this facilitator. Own becomes urgent at the point where the thing you built starts depending on something you rent. Until then it is homework you will resent.
See Make →Say so plainly and take Control AI Spending on its own for $60, then stop. It is the cheapest useful thing on this page and it needs none of the rest. This philosophy will not make your life cheaper, and a page that promised it would be lying to you about the first month.
See Digital Independence →Start with the inventory, not the shopping
Come to Make & Do on a Monday at 9:00 Pacific with the list you made above. You do not have to replace any of it. The point of the 76 capabilities on this page is that by the end, every line of that list has a name against it, a consequence written next to it, and — for the ones you decided to keep renting — your own signature underneath. That is the difference. You chose.