101 lines
6.2 KiB
Markdown
101 lines
6.2 KiB
Markdown
# Open Questions for Member Discussion
|
|
|
|
A living list of decisions the cooperative needs to make. Each question is framed for discussion on [Loomio](https://forum.inference.coop). As questions are resolved, they move to a "Decisions" log (to be created) rather than being deleted.
|
|
|
|
---
|
|
|
|
## Privacy & Infrastructure
|
|
|
|
### Search: self-managed or Tinfoil's encrypted search?
|
|
|
|
We currently run our own [SearXNG](https://searxng.github.io/searxng/) instance (`search.inference.coop`) to power web search in the chat. Tinfoil also offers a `websearch` model — a private, encrypted search that runs inside their enclave.
|
|
|
|
- **Self-managed (SearXNG):** full control, no external dependency, but search queries are visible to our own infrastructure (and to the search engines SearXNG queries).
|
|
- **Tinfoil's encrypted search:** queries are encrypted end-to-end, but it's a third-party dependency and may cost per-query.
|
|
|
|
**Question:** Do we prioritize self-hosting (control, no external deps) or encrypted search (stronger privacy, but a dependency on Tinfoil)?
|
|
|
|
### Green energy vs. privacy — when we can't have both?
|
|
|
|
Our inference runs through Tinfoil (TEE-protected, verifiable privacy), but Tinfoil's energy mix is not disclosed. Self-hosting on renewable-powered hardware (e.g. Hetzner hydropower, Scaleway wind+hydro) would be greener but would lose the TEE privacy guarantee at our current scale.
|
|
|
|
- **Privacy-first (current):** TEE inference, energy mix unknown.
|
|
- **Green-first:** renewable hosting, but policy-based privacy (we *promise* not to read data, but can't *prove* it architecturally).
|
|
|
|
**Question:** When the two conflict, which value wins? Is there a threshold (e.g. member count, cost) at which we'd switch?
|
|
|
|
### Should we adopt Tinfoil's other models (embeddings, private search, audio)?
|
|
|
|
Tinfoil's catalog includes `nomic-embed-text` (embeddings), `websearch` (private search), and audio models (Whisper, TTS). We currently use Open WebUI's bundled local embedding model for file uploads.
|
|
|
|
**Question:** Do we standardize on Tinfoil for all model needs (consistency, privacy), or keep the local embedding model (no per-token cost, no dependency)?
|
|
|
|
### Which models should we offer?
|
|
|
|
We currently expose three chat models: DeepSeek V4 Flash (default), GPT-OSS 120B, and GLM-5.3 Flash. Tinfoil's full catalog also includes GLM-5.3 (full), Kimi K3, Llama 3.3 70B, Gemma 4 31B, and others.
|
|
|
|
**Question:** Which models should members have access to? Should we offer a curated few (simpler, cheaper, easier to govern) or the full catalog (more choice, but more cost and governance overhead)? Who decides when to add or remove a model — the General Manager, or members via Loomio?
|
|
|
|
### Should personal data be collectively or individually managed?
|
|
|
|
Currently chat history is stored on co-op servers. We could potentially switch to storing it in browser cache, which would be more private but less convenient. How do we balance privacy and convenience?
|
|
|
|
### Should we prioritize running and owning our own infrastructure, or are we comfortable collectively buying tokens from others?
|
|
|
|
---
|
|
|
|
## Pricing & Fairness
|
|
|
|
### How should pricing account for unequal usage?
|
|
|
|
Members currently pay a flat $15/month for a $15/month credit budget. But usage is unequal — some members use far more tokens than others.
|
|
|
|
- **Flat (current):** simple, predictable, but heavy users subsidize light users (or vice versa).
|
|
- **Usage-based:** pay for what you use, but unpredictable and may discourage experimentation.
|
|
- **Tiered:** a few usage bands, balancing simplicity and fairness.
|
|
- **Sliding-scale + usage cap:** pay what you can afford, with a shared usage ceiling.
|
|
|
|
**Question:** What pricing model best balances fairness, simplicity, and the cooperative's solidarity values? How do we handle a member who consistently exceeds their budget?
|
|
|
|
### What happens when a member's budget runs out mid-month?
|
|
|
|
Members have a **flexible balance**, not a hardcoded $15/month. The balance starts at $15 but can be topped up by payments (via Open Collective or another system) through the portal's `/admin/set-balance` endpoint, which pushes the new cap to the member's LiteLLM team budget (chat + API draw from the same balance). LiteLLM enforces the cap — requests stop when it's exhausted.
|
|
|
|
**Question:** Should members be able to top up self-serve? Should there be a grace period? Should the co-op pool surplus to cover light users? (The *mechanism* is built — these are now governance decisions, not technical blockers.)
|
|
|
|
---
|
|
|
|
## Governance & Membership
|
|
|
|
### What does "member-governed" mean in practice before 50 members?
|
|
|
|
The charter says the General Manager (Nathan) has full governance until 50 members, then transitions to member governance. But members can already deliberate on Loomio.
|
|
|
|
**Question:** Which decisions should be opened to member input *now* (even if non-binding), versus reserved for the General Manager during the pilot?
|
|
|
|
### How do we handle institutional members?
|
|
|
|
AI Potluck's "government-as-contributor" framing suggests a path for institutions (universities, municipalities) to contribute compute or data without owning the whole.
|
|
|
|
**Question:** Should we create an institutional membership tier? What would institutions contribute, and what would they get?
|
|
|
|
---
|
|
|
|
## Values & Product
|
|
|
|
### Should we adopt "provenance transparency" as a product feature?
|
|
|
|
AI Potluck commits to "every response shows its provenance: the model, the organization, the compute, the country." We could surface which model served each response (already possible via LiteLLM).
|
|
|
|
**Question:** Is this worth building? What's the right level of transparency without cluttering the chat?
|
|
|
|
### Should we articulate an "anti-engagement" stance?
|
|
|
|
AI Potluck explicitly rejects the extractive engagement model ("AI that wants you to turn it off," "doesn't sell you sycophancy"). A cooperative has no engagement-maximization incentive — a structural advantage.
|
|
|
|
**Question:** Should we name this explicitly in our charter and product copy? What does "AI for human flourishing, not engagement" mean concretely for our chat?
|
|
|
|
---
|
|
|
|
*This list is maintained in the [docs repository](https://git.inference.coop/co-op/docs). Add questions via pull request or raise them on [Loomio](https://forum.inference.coop).*
|