MEMORYEvidence product
Memory Receipts
Gives every act of remembering a record of its own. What a system carried forward, when it was written and where it came from are each an operation, and each one leaves something a reader can check. A memory with a receipt stops being editable and becomes verifiable.
Memory is the part of a system nobody can see. That is exactly why it needs a receipt.
Memory is an assertion about the past.
When a system carries something forward, it is asserting that this came from somewhere and that it still applies. Both halves of that assertion can be wrong, and neither is visible in the thing being remembered. What makes it checkable is the operation that wrote it.
- Something remembered: Appears without an origin
- A recorded remembering: Names where it came from
- Something remembered: Cannot be dated
- A recorded remembering: Carries the moment it was written
- Something remembered: Cannot be told from a guess
- A recorded remembering: Either has a receipt or does not
The absence of a receipt is the useful part.
If a system carries something forward and nothing recorded it being written, that is a fact worth knowing. It does not prove the content is wrong. It means nothing here can support it, and the reader is told so rather than reassured.
A receipt for each memory operation.
| Sealed | Operation | Origin | Receipt |
|---|---|---|---|
| 09:20:04.036 | write | operation · read src/billing/rates.py | ev_4c1d90a7f2b8 |
| 09:20:04.058 | read | ev_4c1d90a7f2b8 | ev_77a0e5b31c46 |
| 09:20:04.071 | write | operation · write src/billing/rates.py | ev_d2839f04a6e1 |
| 09:20:04.087 | seal | runtime | ev_bf6442d03d1d4… |
.058 names the write at .036 as its origin. That link is what turns a remembering into something a reader can follow back to an operation that actually happened. A history answers what happened in what order. This answers what was carried between those moments, which a sequence of operations alone cannot show.Reads are operations too
Recalling something is recorded as deliberately as writing it. A system that only recorded what it stored would leave the more consequential half unaccounted for: what it chose to bring back, and when.
The receipt is not the content
A receipt establishes that a memory operation occurred, when, and against what origin. Reading it does not require reading what was remembered, which is what lets a memory be accounted for without being exposed.
Only what passed through the runtime.
This is the product’s single axis, and the place it could most easily overclaim: nothing here can account for what a model holds internally, and pretending otherwise would be the one dishonest thing this page could do.
Each operation carries its moment, its origin and its receipt.
Accounted for by construction: the receipt is produced as part of the operation, so nothing has to be collected afterwards.
Not observed, not inferred, not estimated.
Weights and context are not memory operations and produce no receipt. A product claiming to account for them would be describing something it cannot see.
TELEMETRY, OPERATIONAL, DEEP_CAPTURE, FORENSIC. Each is opt-in, and each is a superset of the last.
The set of receipts is the same at every level. What changes is how much each one carries about the memory it refers to.
Evidence views stop at 25 rows by design, and say so.
A screen showing part of a set says so. The bound is a property of the view, not of the receipts behind it.
Asked about memory outside the path, the answer is that nothing could look. Not that nothing was remembered, and never that nothing was wrong. An unanswerable question is returned unanswered, with the reason stated.
It begins the moment the runtime does.
Like the other evidence products, this has no install path of its own. Receipts are produced from the first governed memory operation onward, and there is nothing to switch on to start them.
- Run an assessment
- A run produces receipts you can follow back to the operations that made them. Nothing is installed.
- Install the runtime into an editor
- Receipts then accumulate as work happens. Two editors install today.
Nothing to migrate, and nothing to backfill
Memory a system already carried before the runtime was in the path has no receipt, and one cannot be issued afterwards. A receipt written later would attest to a moment nobody observed.
What existed before is reported as unaccounted for, which is the only honest thing to call it.
There is no packaged installer for anything in the platform, no separate memory store to operate and nothing on this page to download. The two routes above are the whole of it.
A receipt is not a judgement about the memory.
This is the distinction the whole product rests on. A receipt establishes that something was written or read, when, and from where. It says nothing about whether the memory was correct, appropriate or worth keeping, and nothing here is capable of deciding that.
Nothing reads what was remembered and forms a view about it. There is no summary, no classification and no assessment of content.
This does not delete a memory, expire one or guarantee that anything was removed. It records operations; it does not perform them on your behalf.
Receipts are not assembled into a picture of a person or a team. Nothing aggregates across them into a characterisation of anyone.
What a model holds in weights or context is outside this entirely. Nothing here observes it, and nothing infers it from what it can see.
Nothing is written to a time series, so no claim about memory growing, improving or degrading over a period can be made.
No severity is produced, so no receipt is presented as more important than another. Order is chronological only.
It makes the invisible part of a system answerable, without pretending to understand it.
Someone asking why a system carried something forward wants to know when it was written, what it came from, and whether anything recorded it at all. Answering those three and stopping there is the whole discipline. It is also what keeps a decision checkable long after it was made: a decision that relied on something remembered can be followed back to the moment that memory was written, so the reasoning behind it stays open to inspection rather than closing when the session ends.
