Whose tool is it?
There is a long-standing argument in museum technology — made sharply by Koven Smith in “At what cost?” — that the field as a whole shouldn’t cede control of its tools, because tools built elsewhere carry the interests of elsewhere. The pattern is familiar: an outside platform arrives, does impressive work for free — for its reputation, or for the data — displaces the field’s own cooperative efforts, and then moves on a few years later when priorities shift, leaving institutions no better off than before. Nowhere are the stakes higher than AI: when a system speaks about a collection, it borrows the museum’s authority.
But the answer is not every museum building its own. Maintaining technology is a distraction from an institution’s actual mission — a museum’s core competency is its collection and its public, not its software. The field needs control; the individual institution needs to not be the maintainer.
The right-shaped tool threads both: reusable and remixable like a product, so no museum starts from scratch and no museum carries the maintenance alone; customized to each institution’s unique constellation of infrastructure, because no two museums run the same systems; and cumulative, so every deployment stands on the shoulders of the institutions before it. Kepler was built to be exactly that shape.
What that shape looks like, concretely
A product core, adapted per institution. The recognition engine is one maintained core, and the way to connect it to a collection is open and documented — so it joins the collections systems a museum already runs, whatever they are. The collection stays the institution’s system of record; Kepler meets the infrastructure where it is, not the other way around.
Calibrated on the institution’s own data. Kepler’s confidence bar isn’t a vendor’s constant — it’s measured on the institution’s own objects, the way we validate published research, because every collection has its own pairs of easily-confused objects and the institution deserves to know exactly how its instance behaves.
Honest about uncertainty. Smith has also warned what AI’s failure mode does to a museum: systems that are right most of the time and confidently wrong the rest, eroding the visitor’s trust error by error until it collapses. Kepler is engineered against exactly that. It doesn’t just search for the most similar object — it then verifies that the match is real, and only a decisive match is returned. Otherwise it asks for a better photo, or says the object isn’t in the collection. Never a confident wrong answer, because the museum’s credibility is what’s on the line.
Open-core, so it outlives any steward. The engine can be examined, questioned, extended — and continued. If its maintainer ever walked away, the field would keep the tool. That is the structural answer to the arrive-impress-abandon pattern: control held by the field, maintenance held by a party whose entire practice — not a side project — is museum infrastructure.
Why it exists
Sitara’s operational thesis is that the digital layer of an institution is infrastructure — and infrastructure the field doesn’t control isn’t the field’s. Kepler applies that thesis to AI at the moment museums need it most: recognition engineered to the standard of everything else Sitara ships, shaped so institutions get the benefit of a shared, living tool without inheriting the burden — or the abandonment risk — of someone else’s.