This week I built something that leaned into method and use depth. I wanted to see how far a folder-based AI researcher could go when the folder stays canonical and the model has to earn its answer through structure, context, and review. I spent hours testing it, refining the flow, and pushing it until the research behavior felt reliable. In that process I found the arena this is needed is in on a tight schedule and even tighter understanding of what the compliance landscape is. The consensus was simple, you don’t know where you need to be if you don’t know where you are. This is Quaesitor: Demo: https://l-conder.github.io/CMMC-Readiness-Researcher/ The build:https://github.com/l-conder/CMMC-Readiness-Researcher# Quaesitor means “inquirer” or “investigator,” which is basically the whole idea here. It is a folder-based AI researcher for small U.S. defense contractors dealing with CMMC and NIST SP 800-171. Instead of dumping a checklist on the user, it starts by figuring out the real facts first: what data is being handled, where it lives, who touches it, what evidence exists, and which sources actually matter. The build is meant to slow down before it answers. It scopes the contractor, checks whether the work involves FCI or CUI, weighs source authority, and only then moves toward conclusions. OARS (Open-ended questions, Affirmations, Reflective listening, Summarizing) is part of that process, but the bigger point is research, not interviewing. I chose CMMC because it is a high-stakes domain where bad assumptions are expensive, and if this method works here, it should work in other focused research domains too. It does not certify, give legal advice, or make binding CUI determinations; it is there to help the user get to a better answer by asking better questions and following the evidence. The demo already runs and it’s genuinely interactive. Where I’d take it with a little more time: make it live so anyone can free-type and get a real folder-driven response.