Karui app icon

KN002: Accessing Private Cloud Compute in an App Through Shortcuts

Karui

How Karui asks Apple’s Private Cloud Compute for a second opinion through the user’s shortcut, and the alerting modes built on it.

September 28, 2026 · iOS 27.0 · Measured on iPhone 17 Pro

Overview

Karui is an on-device iPhone notification filter built on iOS 27’s new notification trigger. Its on-device model is rate limited while Karui runs in the background, as Technical Note KN001 describes. When that happens, Karui can ask Private Cloud Compute instead. The request doesn’t come from Karui: the user’s shortcut makes it with the Use Model action, and Karui prepares the prompt and applies the answer.

The round trip

  1. The Shortcuts automation runs Karui’s triage intent, an App Intent, for each notification.
  2. The intent classifies the notification and returns an entity with the History item’s ID, a flag asking for a second opinion, and a ready-made prompt.
  3. If the flag is set, the shortcut runs Use Model with Private Cloud Compute and that prompt.
  4. The shortcut passes the ID and the model’s answer to a second intent, which updates the classification and alerts the user if the answer is Important.

The entity’s properties are what the shortcut reads:

struct TriageOutcomeEntity: TransientAppEntity {
    @Property(title: "Record ID")
    var recordID: String?

    @Property(title: "Wants Second Opinion")
    var wantsSecondOpinion: Bool

    @Property(title: "Second Opinion Prompt")
    var secondOpinionPrompt: String?
}

Reading the answer

Use Model returns plain text, so the prompt asks for exactly three lines:

Category: Important, Neutral, or Spam
Confidence: a number from 0.0 through 1.0
Reason: the reason, in at most 20 words

The parser still forgives extra words, missing lines, and labels written in Japanese. If no line is labeled, the first category word in the answer decides.

Three modes

The whole trip through the shortcut usually takes 2 to 3 seconds, so Karui offers three modes:

In First mode, the held alert is a local notification scheduled 20 seconds out with a known identifier. When the answer arrives, the second intent cancels it if it hasn’t fired, then sends the alert only if the cloud agrees. If the shortcut fails partway, nothing cancels the held alert, so iOS delivers it anyway. If it already fired and the cloud disagrees, Karui removes it.

Asking from inside the app

Karui can’t run a shortcut in the background, but it doesn’t need to. When someone reruns a classification in Karui, the app posts a quiet notification carrying the item’s ID. The notification trigger fires for Karui’s own notifications too, so the user’s automation runs, the triage intent recognizes the marker and returns that item’s prompt, and the shortcut’s usual steps do the rest.

What’s sent

The prompt contains only the notification’s text and app, whether it’s one of the user’s important apps, the user’s name, handles and any nickname, and their sorting terms. Notifications decided by rules, contact details, and calendar events never leave the iPhone.

Revision History

← All Technical Notes