What are the four parts of a working second brain?
Written for agents, brokers, lenders, contractors, home services.
The short answer
Four parts: capture, the records, the scan, and the output check. Every failure we have seen is one part doing a job that belongs to a different part.
Capture takes material in and holds it with nothing decided about it. It refuses nothing at all: no topic, no person, no subject.
The records are People, Assets and Deals, plus the decisions. A person decides what every item means, and that is the one part of the four that is never automated.
The scan reads the records against themselves and asks about what does not add up. It writes nothing and it rules on nothing. In the current release this part is designed and not shipped.
The output check governs what leaves, who it reaches and what it claims. This is the only place in the system where anything is ever refused.
Every second brain that falls over falls over the same way. Something inside it was given a job belonging to a different part, and nobody noticed until the day it mattered. A capture tool that decides what is worth keeping. A records folder that refuses a subject. A weekly report that writes into files. A drafting step with nothing between it and the outside world.
So the useful way to explain this is by the four parts and the lines between them. The lines carry the safety argument. Learn them and you can look at your own setup, whatever it is built from, and name the part you are missing.
First, what PAD means
PAD stands for People, Assets, Deals. Three folders of plain text files on your own computer, plus one plain document at the top that tells an AI assistant how to work inside them: where to file what, how to name it, what it may never do, and when to stop and ask.
- People. Humans, and the animals that belong to them. One file per person, forever, referenced from everywhere that person appears.
- Assets. Things that appreciate or decay depending on whether they are maintained. A rental, a website, a truck, a license, your own health.
- Deals. Work that closes. Participants, a stage, deadlines, and a day it ends. One folder each, holding call notes, documents and the decisions made inside it.
How do you tell an asset from a deal?
Deals have somebody on the other side and assets do not. A listing is a deal because a seller is across the table. Your health is an asset because nobody is. A retainer is a deal that stays active rather than closing.
People sit outside Assets on purpose, and that placement is an argument rather than a filing convenience. A relationship is not a thing you own and maintain for its resale value, and a system that files a past client beside a truck will eventually produce a business that talks about her that way.
Part one: capture
Capture takes material in and holds it with nothing decided about it. A voice memo recorded in a truck. A photo of a scribbled page from a walkthrough. A forwarded email, a call transcript, a scan of a signed form. It records and it stamps, meaning it writes down what arrived and when, and then it stops.
Capture refuses nothing at all. No topic, no person, no subject. This is the first place people expect a filter, so it is worth being blunt about why there is none: a capture step that judges what is worth keeping loses material at exactly the moment you are too busy to notice. Nine at night after a long day is when the thing you most need to keep arrives.
In the shipped system the intake is enforced rather than promised, and that distinction is worth insisting on with anything in this category. The capture step has exactly two write paths. Both are checked against a resolved path immediately before the write, meaning the destination is worked out to its final form and then verified rather than trusted. Files are opened in create only mode, so a write can make a new file and can never quietly replace an existing one. A promise about where a system writes is a sentence in a document, and a document cannot fail. A check before every write holds or fails loudly.
Part two: the records
The records are the ledger of the business. People, Assets, Deals, and the decisions. This is the part you would still want if you deleted the other three.
The records refuse nothing either. Anything about a person, an asset or a deal belongs in them. What an agent knows about the people in her life is the thing this vault exists to hold, and a records system that will not hold it is a filing cabinet with opinions.
One part of the four is never automated, and this is it: a person decides what every item means. Machines can put an item in front of you and propose where it goes. The meaning is human every time. Whether the thing is settled or still a maybe. Whether the promise was yours or theirs. Whether the sentence she said in the driveway is the reason for everything that happens next year.
The status discipline lives here. Ideation for thinking out loud, evidence for something observed with a source and a date, decision for something carrying a date and the name of the person who made it. No status means ideation, and only the owner promotes anything to decision. The one thing the records never hold is a live number, because a price, a rate, a stage or a schedule lives in the system that changes it and the file says where to look.
Part three: the scan
The scan reads the records against themselves and asks about what does not add up. Two files giving different closing dates for one transaction. A number carrying a checked date from four months ago. A person nobody has contacted since February with an open promise sitting on their file.
Two constraints define it and both are absolute. The scan writes nothing. The scan rules on nothing. It produces a report made of questions, and every answer belongs to a person.
Be plain about the state of this part: in the current release it is designed and not shipped. The install page says so and this article says so. If you are running the system today, the scan is something you do by reading. The design is fixed already so that when it does ship, it cannot arrive carrying the ability to write, which is the most common way a records system starts producing entries nobody wrote.
Part four: the output check
Where does a second brain refuse something?
At the output, and only at the output. The output check governs what leaves, who it reaches and what it claims, and it is the single place in the four parts where anything is ever refused.
The rule that produced this shape was written by the owner of the system on 2026-08-12, in his own words: "It's the output of content that gets checked against the record. That's what needs the filter."
Recording is not the gate. Sending is. A private note is not a published sentence, and treating those two as the same thing is how a system teaches people to stop writing things down.
The check asks three questions every time. What is leaving. Who it reaches. What it claims. A draft can pass on content and fail on recipient, and it can pass on both and still fail by claiming something the records do not support.
The recipient half deserves its own paragraph. Anything that sends has exactly one recipient, fixed when the system was installed, and that recipient is the owner. It is never worked out from context, from a file, or from the message being processed. The reason is specific: on 2026-07-31 an automated brief containing private client information reached eighteen unintended recipients on a comparable system. The cause was never identified and no fix was documented. A recipient that cannot be resolved from data cannot be redirected by data.
Why the filter sits at the output and nowhere earlier
An agent knows about a client's divorce, because the divorce is why the house goes on the market in April. A loan officer knows a borrower's income to the dollar and the reason behind the collection account. A contractor knows a homeowner's budget, their marriage, and which of the two will change their mind about the tile in week three. None of that is optional knowledge somebody went looking for. It is the work.
A records system that refuses to hold that material does not cause it to disappear. It relocates it, into a phone note, a text thread, or the head of the one person who was in the room, and none of those has any check on it. The only open question is whether the material sits somewhere with a gate between it and the outside world.
So a system whose output layer refuses to emit something is a safer home for that material than a system with no output layer. A refusal at the recording step protects the tidiness of the folder. A refusal at the sending step protects the person.
One test follows, worth applying to any rule handed to you by any system, including this one. Ask whether the rule constrains what somebody is allowed to know, or what somebody is allowed to send. A constraint on knowing belongs at the drafting step or nowhere. A rule justified by the argument that recording something might cause a problem later is that error wearing a reasonable sentence, and it is convincing enough that this system carried one for about an hour on 2026-08-12 before the owner struck it.
The refusals at the output are hard ones. Where a brand in the records is marked as resident care, nothing about a resident leaves in a draft, a message or a document, and that covers a redaction, a summary and a count by name, because each is the same disclosure in a smaller box.
The boundaries, in one table
| Part | What it does | What it must never do |
|---|---|---|
| Capture | Takes material in and stamps it with what arrived and when. Refuses no topic, no person, no subject. | Decide what is worth keeping. Overwrite an existing file. Write outside the two checked paths. |
| The records | Holds People, Assets, Deals and the decisions. A person assigns the meaning of every item. | Refuse a subject. Hold a live number. Let anything other than a person promote something to a decision. |
| The scan | Reads the records against themselves and reports what does not add up. | Write. Rule on anything. Choose between two files that disagree. |
| The output check | Governs what leaves, who it reaches and what it claims. The only refusal in the system. | Reach backwards and constrain what may be recorded. |
Every failure mode is a boundary crossed by the wrong part. Read the right hand column as a list of the ways this goes wrong.
How to work out which part you are missing
This runs against whatever you have today: a folder of files, a note app, a CRM and a phone, or nothing at all. Four questions, in order.
- 01Where does something land at nine at night with nothing decided about it? If you have to work out where it goes before you can put it down, you have no capture step, and material goes missing on your busiest days.
- 02Is there anything your records will not hold? If a category of thing lives somewhere else because writing it down felt risky, your filter is in the wrong part. Move it to the output and let the record hold the material.
- 03What reads your records looking for things that do not add up? If the answer is you, on a good week, your scan runs at the frequency of your energy, which is the frequency at which it stops in a busy month.
- 04What checks something before it goes out under your name? If the answer is nothing, you are relying on whoever is drafting being careful, and drafting happens in a hurry.
Most businesses we look at have a strong second part and nothing else. Capture is improvised, the scan is a person remembering, and there is no output check, because nobody knew it was a part.
The four boxes
The four boxes applied to the records layer, which is the part people argue about, as of 2026-08-12. The fourth box carries the argument.
There, and should be
A ledger that will hold anything about a person, an asset or a deal, with a human assigning meaning to every item.
- No exception by subject, by person, or by how awkward the material is. What somebody told you about their son, their dog or their builder is yours to keep.
- A second brain that drops that material is worse than a paper notebook, because a notebook drops nothing and claims nothing.
- Live numbers stay in the system that owns them and the record says where to look, which is a question of staleness and has nothing to do with permission.
Missing, and should be there
The scan, which is designed and not shipped in the current release.
- Until it ships, drift is caught by a person reading the records, which means it is caught least often in the months when the business is busiest.
- The design constraint is the part worth keeping whatever you build. It writes nothing and it rules on nothing.
- If you are assembling your own version, build the report before you build anything that acts on the report. The order is the safety.
There, and should not be
Any refusal sitting at the recording step, and anything that works out a recipient from data.
- A carve out barring resident records in a licensed care facility from being filed at all stood in this system for about an hour on 2026-08-12 before the owner struck it. It read as prudent and it was the same error in a smaller costume.
- Anything resolving a recipient from context, from a file, or from the message being processed. One recipient, fixed at install, and a refusal if a task appears to want a different one.
- Secrets, in any file. Passwords, keys, tokens, account numbers, government identifiers. Those come out, the rest gets filed, and the system says what it removed.
Missing, and correctly missing
The records layer has no filter in it at all. Nothing can be refused entry.
- This is correct, and it is the load bearing decision of the whole design. A vault that refuses a subject does not remove that subject from your business. It relocates it to a phone note with no gate on it, outside the system that would have refused to send it.
- The protection did not weaken when the filter moved. It got stronger, because a refusal at the output covers a summary, a redaction and a count by name, while a refusal at the recording step only ever covered the tidiness of the folder.
- Name the cost honestly. Everything ends up in there. Material you would rather nobody read, material that would be uncomfortable in front of a third party, material about people who never agreed to be in your records.
- So the folder has to be treated as what it is: private, on your own machine, backed up, with secrets kept out of it and an output layer that will refuse. Choose a records system with no filter and you have chosen to carry that responsibility in how you hold the folder rather than handing it to software.
What the four parts do not do
Four parts. One refuses things, one is never automated, one is not shipped yet, and one will hold anything you hand it. If you can name which of the four your own setup is missing, this article did its job, whether or not you ever install anything.
Common questions
- What are the four parts of a second brain?
- Capture, the records, the scan, and the output check. Capture takes material in with nothing decided about it. The records hold People, Assets, Deals and the decisions, with a person assigning meaning to every item. The scan reads the records against themselves and reports what does not add up. The output check governs what leaves, who it reaches and what it claims.
- What does PAD stand for?
- People, Assets, Deals. Three folders of plain text files on your own computer, plus one plain document at the top telling an AI assistant how to work inside them. People are humans and the animals that belong to them. Assets are things that appreciate or decay depending on maintenance. Deals are work that closes.
- How do you tell an asset from a deal?
- Deals have somebody on the other side and assets do not. A listing is a deal because a seller is across the table. Your health is an asset because nobody is. A retainer is a deal that stays active. People sit outside assets on purpose, because a relationship is not a thing you own and maintain for its resale value.
- Where does a second brain refuse something?
- At the output only. The rule was written by the owner of the system on 2026-08-12: the output of content gets checked against the record, and that is what needs the filter. Recording is not the gate. Sending is. Capture, the records and the scan refuse nothing, and the output check governs what leaves, who it reaches and what it claims.
- Is the scan part available today?
- No. In the current release the scan is designed and not shipped, which is what the install page says. Until it ships, drift in the records gets caught by a person reading them. The design is fixed already so that when it does ship it cannot arrive carrying the ability to write, because a reporting tool that gains write access is the common way a records system starts producing entries nobody wrote.
- Why would a records system hold sensitive client information at all?
- Because refusing to hold it does not make it disappear. An agent knows why the house is selling, a lender knows the borrower's income, a contractor knows the homeowner's budget. A system that refuses that material pushes it into a phone note or a text thread with no check on it. A system whose output layer refuses to emit something is a safer home for it than a system with no output layer, and the cost is that the folder itself has to be treated as private and backed up, with secrets kept out of it.
Worth passing along
This one serves the brokerage owner and the loan officer, because both hold material about other people that they did not ask for and cannot give back. The brokerage owner is answerable for what agents write down and for anything that leaves under the company name. The loan officer holds income, debt and employment on every borrower, and works in the one corner of this sphere where what leaves gets examined by somebody else afterwards. The four parts are identical for a two truck plumbing business, and the argument about where the filter belongs is easiest to see in those two.
Written by Brett K Moore. We build the PAD System, a records structure for people, assets and deals that lives as plain text files on your own computer. Read what it is.
Read next
Why should your client records be plain text files?
Underneath the argument about which app to use is a quieter question about the file format your records are written in. What plain text gives an agent, a lender or a contractor, what version control does and does not protect, and where the files sit. Four box verdict included.
Why should a price never be written into your notes?
A live fact is anything that can change without your file knowing. Why a copied price, rate, stage or closing date goes wrong quietly, what a file should hold instead, and the half of the rule most systems miss: the same obligation applies when you say the number out loud. Written for real estate agents, brokers, mortgage lenders and the trades who work alongside them.
How do you tell what you decided from what you were thinking about?
Three words on every record: ideation, evidence and decision. What each one has to carry, why an unmarked note counts as thinking out loud, why only a person promotes anything, and what happened on 2026-08-09 when an overnight pass wrote two entries marked as decisions that were not true. Written for real estate agents, brokers, mortgage lenders and the trades who work alongside them.