Semantic recall in · per-record admission decisions out
Recalled memory is handled as material, not as instructions.
Memory Firewall takes a whole semantic recall set, presses each candidate through one canonical resolver, and shows which records may enter the working context — before anything reaches an action boundary.
- 4routes one candidate set can take
- 10committed terminal receipt rows
Containment workbench
Build a candidate set, choose the task scope, and add one grounded operator note. Every control here changes the records that are actually sent to the resolver.
1 · Prompt and context
Your text is wrapped as one extra typed record (operator-note@live, entity operator_note) and scanned by the same resolver. Imperatives such as run command or credential-shaped strings change its disposition; it never overrides the fixture records’ own outcomes.
2 · Canonical evaluation
Loading the first candidate set…
3 · Trace
- Recall integrityAn empty candidate set stays unknown; it is never read as an absence of history.
- Recursive taint scanEvery nested string is inspected for imperatives, overrides and credential shapes.
- Schema validationTyped fields, unique IDs and parseable dates are required, never repaired by a model.
- Lifecycle resolutionID-based supersession, revocation and expiry run before any scope filtering.
- Scope and provenanceOnly current, in-scope, grounded records survive; a cross-scope successor never revives its predecessor.
- Action boundaryAdmitted memory is data. Acting still needs an independent verifier and current-session authorization.
Resolver on this bench: web/lib/firewall-core.mjs
4 · Reproduce in the CLI
The same candidate set resolves identically outside the browser.
make web-parity # the browser and the Python resolver must agree, record for record
make synthetic-stand # replays the pinned candidate-set corpus in isolation
Exact call for the set currently on the bench:
Run an evaluation to render the matching CLI call.5 · Receipt cabinet
This workbench sorts a candidate set and explains its dispositions. The archived receipt record is a separate artefact, so a browser result is never mistaken for a storage operation.
- evidence/mainnet-receipts.jsonBlob-identifier receipt entries, checked by
scripts/check_evidence.py. - evidence/MAINNET_EVIDENCE.mdThe terminal capture procedure and its cold-client verification steps.
- Workbench resultEach result names the candidate, disposition, and rule that produced it.