Shared memory
Written by agents, confirmed by people
A memory system that stores everything an agent believes becomes a landfill within a month. MUON separates the right to write from the right to be believed. Anything can be proposed. Only checked, corroborated and human confirmed claims carry the weight of company truth.
Admission
The path from a claim to canon
Free writing is not free admission. Each stage is recorded, so a claim always shows how far it has travelled and what is still missing.
An agent writes a claim
Any agent in the crew can write into the pending tier. The claim is stamped with who wrote it, from which session, against which file or symbol.
Deterministic checks run
MUON checks the scope, the anchor, the policy, and whether the text is trying to smuggle in an instruction. Failures are held with a reason.
A second agent corroborates
A claim that another agent independently confirms becomes crew vouched. It can be retrieved and cited, and it is still not company truth.
A person confirms it
You or a scoped steward turn a crew vouched claim into canon. No classifier can do this step, and the superagent cannot confirm its own claim.
- Every proposal is stamped with its source: which agent, which session, which file or symbol
- Deterministic checks cover scope, anchor, policy and prompt injection before a human ever sees the claim
- An optional classifier can recommend admit, hold or expire, and it never confirms anything
- Independent corroboration by a second agent makes a claim crew vouched and citable
- A person or a scoped steward makes it canon, and only that step creates company truth
An agent cannot promote its own conclusion
The superagent verifies, grounds, challenges and recommends. It cannot turn its own conclusion into human canon, and neither can any classifier. That single restriction is what keeps the record honest as the volume of agent output grows.
It also means the memory is useful evidence in a review. When a claim is canon, a person put their name to it.
During a mission
Four lanes reading from and writing to the same record
While a mission runs, every lane pulls the decisions and constraints that apply to its part of the work, and writes what it learned back as a proposal. Nobody has to paste background into a second window, and nothing quietly becomes fact.
What this lane reads
Reads the retry history so it does not trace the same path twice
What this lane writes back
Proposes that retries originate at the gateway, with two citations
Nothing a lane writes becomes company truth on its own. It arrives as a proposal, another lane has to corroborate it, and a person has the final say.
Reading the record
Provenance, contradiction and supersession
Old knowledge does not get deleted when it turns out to be wrong. It gets superseded, and the link between the old claim and the new one is what lets anyone reconstruct why the team changed its mind.
What the record looks like after one mission
Select a record to read what it says, who put it there and what it depends on. A superseded record keeps its link to the decision that replaced it.
Selected record: Charges used to be considered safe to retry blindly
Charges used to be considered safe to retry blindly
Superseded by decision D-114. The record is kept rather than deleted so anyone reading the history can see why the team changed its mind.
Superseded 12 Mar
Connected records
In the run
Memory arrives as context the agent already has, rather than a search box it has to use
Agents do not have to remember to look things up. Relevant canon, task memory, live coordination state and code evidence are allocated into each turn under a budget, with a record of what was included and what was left out.
Stale claims are marked
A memory anchored to code that has since changed is flagged rather than served quietly. The agent sees that the ground moved.
Contradictions surface early
When two confirmed claims disagree, the mission raises it instead of picking one. The conflict lands on your desk with both sources.
Memory respects boundaries
Tenant, workspace and authorisation scope are hard partitions. A memory never crosses a boundary because a search engine thought it was relevant.