Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Projects
productioncore

EMR Memory — Continuity Ledger for Agents

Governed durable memory that forgets on purpose


A SQLite-backed Continuity Ledger plus an Episodic Memory Replay pipeline for PrimeSwarm agents. Memory records carry type, status, provenance weights, and Ghost Matrix receipts. Consolidation uses Ebbinghaus decay, token-budgeted short-term memory, abstention gating, conflict detection, and a Reinforcement Sidecar so recalled-often never equals truth. Chat dumps are never persisted.

Overview

EMR Memory is the durable memory substrate for PrimeSwarm agents. Instead of stuffing chat transcripts into a vector store and hoping retrieval is honest, every remember/recall/upsert is a governed write: typed, receipted, conflict-aware, and fail-closed.

The core thesis: agents should remember decisions and evidence, not conversations — and they should forget on a mathematically defined schedule rather than accumulating unbounded context.

This page is the public article for that substrate. The rest of Only Institute memory work sits beside it, at different levels. EMR is the agent hippocampus. Only Forum is the human catalog. ONLY Lang ghost memory is an arithmetic primitive. They are not interchangeable.

Continuity Ledger

A SQLite-backed durable ledger with WAL mode and foreign-key checks. Phase 1 is enforced: the ledger preserves claims with provenance. It does not decide epistemic truth. Conflicting claims are surfaced, never silently merged.

MemoryType (each has its own Ebbinghaus rate):

TypeHalf-life (approx.)Decay per hour
Architecture~35 days0.0008
Decision~7 days0.004
Preference~4 days0.006
Research / Fact~2 days0.012
Task~23 hours0.03

MemoryStatus carries a provenance weight used in activation scoring: verified = 1.0, draft = 0.55, archived = 0.0. Confidence is caller-asserted; the ledger never infers it.

Each MemoryRecord also holds:

  • Ghost Matrix receipt — canonical SHA-256 binding content, type, subject, and timestamp
  • content_sha256 — integrity of the normalized body
  • EvidenceLink values — hashed references, not pasted chat
  • supersedes — replacement lineage, never a silent merge
  • L0 / L1 / L2 — abstract, overview, detail. L0 is the default context surface; expansion is explicit
  • AuditEvent — every mutation is logged to an append-only JSONL trail

The PrimeSwarm HelixDB facade (secure_insert, secure_query, cleanup_expired_memories) now sits on this ledger rather than a mock store. That is a compatibility layer for the agent runtime. It is not the Only Forum Helix mirror.

EMR Pipeline

The Episodic Memory Replay pipeline turns the ledger into a working set, then (only when asked) consolidates back as DRAFT records:

  1. Activation scoring — query alignment, provenance weight, type-specific decay, and bounded reinforcement combine into one score
  2. Ebbinghaus decay — the forgetting curve is explicit. Architecture outlasts a decision; a task expires first. This is not a sliding window
  3. Short-term memory — session-scoped, token-budgeted. STM is a disposable view. The ledger is continuity
  4. Abstention — recall refuses when there are no candidates, query alignment is low, evidence is thin, or the top-margin is ambiguous (AmbiguousTopMargin)
  5. Reinforcement Sidecar — recall frequency is tracked separately from evidence strength. Recalled-often cannot masquerade as true
  6. user_requested gate — remember, consolidate, and Spatial XR secure wipe fail closed unless the operator explicitly requested the write

MCP Tools

Governed memory is exposed over the MCP tool protocol in primeswarm-mcp:

  • emr_remember — draft-only write with a Ghost Matrix receipt; requires user_requested=true
  • emr_recall — retrieve with activation scoring and abstention
  • emr_upsert — update with conflict detection and supersession lineage

Spatial XR secure wipe uses the same pipeline: decisions and evidence become DRAFT ledger records. Chat transcripts are not persisted. Wipe without user_requested is a closed failure.

Why This Matters

Vector-store "memory" is retrieval, not governance. EMR Memory makes every remember/recall an auditable state transition: typed, receipted, decayed, and capable of saying "I don't know." That is the difference between an agent that confabulates from chat history and an agent that cites a ledger.

Memory across Only Institute — levels

We use the same labels as the Continuity Ledger architecture: enforced (code, tests, and a runtime path), partial (implemented but not the default or not fully wired), declared (specified, not shipped), and live commons (running for researchers on Only Forum).

SubjectLevelWhat it actually is
Continuity LedgerEnforced (Phase 1)Durable SQLite store. Claims, receipts, conflicts, audit. Does not decide truth.
EMR pipelineEnforcedDecay, STM, abstention, reinforcement sidecar. Integration test: TPNN redaction → retrieve → consolidate → conflict → supersede.
MCP emr_ tools*EnforcedAgent-facing remember / recall / upsert. Fail-closed writes.
Spatial XR wipe → ledgerEnforcedDual-Front wipe consolidates to DRAFT records. No user request → no write.
HelixDB facade on the ledgerPartialAgent runtime storage boundary. Compatibility, not a second source of truth.
ONLY Lang ghost memoryEnforced primitiveFirst-order equilibrium looks empty; second-order moment holds the payload. Arithmetic, not agent STM. See ONLY Lang.
Trust Derivation ObjectsEnforced in ONLY LangReplayable command traces. Same instinct as Ghost Matrix receipts.
Only Forum catalogLive commonsAbstracts only. Identity, teasers, rooms. ~377 papers. Not agent memory. See PrimeSwarm Forum.
Forum identify + TPNN mapLive commons, honest limitsArrival locators + curvature communities. Last rematch: 399 nodes, 19 communities, 0 citation bridges (sweep cliques until bibliographies exist).
Forum grounded writerLive commons, narrowforum-writer may post a log from ledger facts. Never a paper. Abstains if nothing new.
Forum claim cardsDeclaredTyped problem / method / result from abstracts, with abstain. Designed, not shipped.
OnlyDB / write_if_purePartialForum speech stays in Postgres. Helix hydrate is stub-safe. Hashing-trick embeddings are a placeholder.
ConceptPolynomial hippocampusPartialAlgebraic concept embeddings exist; the live forum still mirrors SHA-256 hashing-trick vectors.
PIR as write gateEnforced policy, not a rankerHigh coherence gap → stay in audit. The ledger still does not call a claim true.
On-chain / DKG memorySeparate protocolsui-memory-contract, psagi-dkg-memory. Not this hippocampus.

Chat dumps are not memory in any of these layers.

Status

  • Continuity Ledger crate: Phase 1 enforced, 14 unit tests
  • EMR crate: 9 unit tests
  • End-to-end memory pipeline (TPNN redaction → durable retrieval → EMR consolidation → conflict detection → supersession): integration test passing
  • Spatial XR wipe and MCP tools: wired, fail-closed
  • Not yet: Ghost Memory as an EMR encoding adapter (declared), claim cards on the forum (declared), Helix as the live forum default (partial / stub)

The project badge says production because the crates are the memory path PrimeSwarm agents use. It is not a hosted consumer memory cloud, and it is not the Only Forum catalog.

Key Highlights

  • SQLite Continuity Ledger with WAL mode, foreign keys, and Ghost Matrix receipts
  • Typed decay: architecture lasts; decisions and tasks forget first
  • Abstention gating — ambiguous top-margin refuses to confabulate
  • Reinforcement Sidecar separates recall frequency from evidence strength
  • Conflict detection and supersession lineage — never silent merge
  • MCP tools: emr_remember, emr_recall, emr_upsert — fail-closed without user_requested

Links