Prepared 2026-07-22. Figures verified as of this date unless marked otherwise. Scope: which AI tools Mitchell uses, for what jobs, at what cost, under what rules. This document is written to be handed to Ready Mortgage compliance for written approval before go-live.
Core operating principle (non-negotiable):
AI researches, drafts, organizes, rehearses, and measures. Mitchell decides, verifies, communicates, and owns the relationship.
Core stack cost: $40/month (Claude Pro $20 + ChatGPT Plus $20). Everything else is $0 or dropped.
| Tool / tier | Job assignment | Cost | Data-safety posture | Company approval |
|---|---|---|---|---|
| Claude Pro ($20/mo) | The system-builder and long-horizon research engine: multi-source research and synthesis; parallel subagent fan-out (e.g., profiling the 30-agent pilot list); building and maintaining the business-plan file tree, data models, scripts, and website prototype; compliance checklists; red-team review of drafts and plans; scheduled weekly routines (Monday pipeline review, Friday metrics rollup). Only tool in the stack that natively edits local files. | $20 | Training toggle OFF day one (Settings → Privacy → "Help improve our AI models" = OFF). No NPI ever — consumer tier. Repo stays free of borrower data. Upgrade to Max 5x ($100) only if weekly caps interrupt work 2+ consecutive weeks. | Yes — disclose in written AI-use approval |
| ChatGPT Plus ($20/mo) | The rehearsal and voice engine: one dedicated Project ("Mitchell — Approved Materials") holding only public/approved scripts, objection libraries, and product one-pagers; Advanced Voice Mode daily role-play against those materials; Deep Research (~10 runs/mo) for narrowly scoped questions; script refinement; meeting prep; weekly review accountability. | $20 | Training toggle OFF (Settings → Data Controls → "Improve the model for everyone" = OFF — paying $20 does NOT change the default). Temporary Chat for anything borderline. Project holds public/approved content only. | Yes — same disclosure |
| Kimi K3 / Kimi Claw | Public-content-only at most; recommended default: skip entirely. If approved at all: long-context research on public documents, formatting already-public content. Never borrower docs, never credentials, never secure systems, never autonomous sends. | $0 | Security basis (documented, factual): Moonshot is Beijing-based; hosted prompts sit under Chinese law including National Intelligence Law compelled-disclosure obligations. Its privacy policy states prompts/uploads may be used to train models, with no clear consumer opt-out. The Institute for AI Policy and Strategy published a specific risk analysis of Kimi Claw as a Chinese-hosted always-on agent; Harmonic Security measured Kimi as the most-used China-based AI tool inside enterprises (~3.5x DeepSeek), with leaked financial and PII data categories; Fisher Phillips issued employer guidance on controlling Kimi use at work; US federal restrictions on Chinese AI services are reportedly under consideration. Under a GLBA Safeguards mindset this is an unvetted offshore service provider with zero contract. | Yes — explicit written approval required; expect "no." The plan loses nothing if Kimi is dropped. |
| Grok (free tier) | Optional only: X/Twitter trend and local-conversation discovery, alternative brainstorming. Never authoritative for rates, law, program guidelines, or product claims. | $0 | Trains on user data (incl. X activity) by default — opt out under X Privacy & Safety → Grok data controls. No paid tier in year one. | Yes if used for any work content |
Redundancy check: no two tools share a primary job. Claude builds and researches; ChatGPT rehearses and voices; Kimi and Grok are droppable experiments. If budget must go to $20, drop ChatGPT Plus last-in-first-out is wrong — drop nothing; $40/mo is the floor for the plan as designed, and both core tools carry non-overlapping load.
The differentiator framing: Fannie Mae Lender Letter LL-2026-04 (2026-04-08) requires AI/ML governance frameworks of seller/servicers using AI in origination or servicing; Freddie Mac added parallel servicer-guide requirements in late 2025. Every mortgage employer now needs (or soon will have) a written AI policy. A brand-new MLO who shows up to his manager with this SOP already written is ahead of most veteran LOs on a requirement the company itself is now under. Present it that way: not "please let me use AI," but "here is my governance framework, ready for your file."
Why this is absolute: an MLO handles nonpublic personal information — exactly what the GLBA Safeguards Rule (16 CFR Part 314) obligates the institution to protect, including oversight of service providers. A personal consumer AI account is an unvetted service provider with no contract, no audit rights, and (on consumer defaults) active training use. Pasting borrower data into one is a Safeguards Rule gap and, at most companies, a fireable policy violation.
Every research output retains its source URLs. Any claim without a checkable source is marked "unverified" and never reaches a borrower, an agent, or a published page. Anything Ready-specific stays marked [UNVERIFIED — confirm with manager] until confirmed in writing.
YYYY-MM-DD_topic_status.md — e.g., 2026-07-22_fthb-dpa-stack-onepager_DRAFT.md.
Status values: DRAFT → REVIEWED (Mitchell verified numbers) → APPROVED (compliance sign-off) → PUBLISHED. Nothing leaves DRAFT without passing a gate in §2.3. Bill-facing/company-facing documents carry the date prefix so versions are never ambiguous.
compliance/ folder).Stored in the repo; each template used verbatim, then refined monthly. All templates assume public/approved inputs only.
T1 — Daily planning (Claude or ChatGPT, 5 min, morning): "Here is my calendar for today and my current next-actions list [paste anonymized list — initials or codes only]. Order my day: 60–90 min outreach sprint placement, prep blocks before each call, one recovery block after the highest-social-intensity item, and the top 3 outcomes that would make today a win. Flag anything overdue."
T2 — Realtor research brief (Claude): "Build a one-page brief on [AGENT NAME], a real estate agent at [BROKERAGE] in [TOWN], using only public sources (their website, public listings, public social posts). Include: apparent niche and price band, recent listings/sales activity, communication style, one genuine specific compliment I could make, and one difficult-scenario opener relevant to their business. Cite every source URL. Mark anything inferred as inference."
T3 — Scenario drill (ChatGPT, daily): "Act as an underwriter quizzing me on [PRODUCT: FHA / conventional / VA / bank-statement / DPA pairing]. Present a realistic but fictional borrower scenario for the Chicago southwest suburbs ($250–400k price band). Let me talk through qualification, then critique my answer against published agency guidelines. Do not invent guideline numbers — if unsure, say so and I'll verify."
T4 — Objection role-play (ChatGPT Advanced Voice, daily): "You are a skeptical listing agent in Orland Park who already has a preferred lender. I'm going to practice my Scenario Desk pitch. Push back realistically — busy, mildly dismissive, 'my lender is fine.' After 5 minutes, break character and score me on: opener, credibility without borrowed experience, the one-scenario ask, and close. Persona is fictional."
T5 — Call debrief from written notes (either tool): "Here are my written notes from a call with a realtor [anonymized — no borrower info, agent first name only]. What did I miss? What was the real objection under the stated one? Draft the follow-up email (for my review, not sending) and the specific next-action with a date." (Written notes only — no recordings, no transcripts of the other party without consent; Illinois is a two-party consent state.)
T6 — Content fact-check (Claude, before anything moves to REVIEWED): "Fact-check this draft line by line. For every number, program name, limit, date, or legal claim: state whether I've provided a source, and flag it 'VERIFY' if not. Flag any sentence that implies experience I don't have, any guarantee-like language, and any missing licensing disclosure. Do not fix silently — list findings."
T7 — Weekly KPI review (Claude, Fridays, feeds the §23 scorecard): "Here are this week's KPI numbers [anonymized counts]. Compare to targets and last 3 weeks. Which leading indicators moved? Which stop/continue rules from 23_kpi_scorecard.md are triggered? Give me the 3 highest-leverage adjustments for next week — behavior changes, not platitudes."
| Account | Setting | State |
|---|---|---|
| ChatGPT | Data Controls → "Improve the model for everyone" | OFF |
| Claude | Privacy → "Help improve our AI models" | OFF (note: opted-out = 30-day retention; opted-in chats retained up to 5 years; safety-flagged conversations may be used regardless — another reason NPI never goes in) |
| Grok / X | Privacy & Safety → Grok data controls | OFF |
| Kimi | No reliable consumer opt-out exists | Treat every input as public — which is why only public content may enter, if used at all |
Also: unique passwords + MFA on every AI account; all work AI use in a dedicated work browser profile (reduces accidental paste from personal contexts and vice versa).
Quarterly re-verify (calendar recurring, 1st business day of Jan/Apr/Jul/Oct): reopen each settings page, confirm toggles survived app updates, screenshot, file in repo.
It keeps Mitchell fast where AI is safe (research, drafting, rehearsal, measurement) and slow where the law and the license live (numbers, borrower data, external communication). A CCO reading any file in this repo should be able to see exactly which gate it passed. That is the whole design.