Status
contract + as-built (Hindsight, case library)
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 8, section 3.6.4
ADR
021 · 025
Siblings
05-context-engineering.md · 13-improvement.md · 14-ask.md · 22-missed-opportunities.md

Purpose#

Memory improves the next card without poisoning thresholds, inventing outcomes, or letting Ask chat rewrite plant truth. Each tier earns its place. When Hindsight disagrees with the case libraryEpisodic store of traces joined with L5 outcomes; authority when it disagrees with Hindsight on outcomes, the case library wins and the disagreement is traced.


Tiers#

Working ledger (per run)#

Typed rows for one DecisionCaseOne run unit: intake + snapshot + obligations + candidates + terminal. Frozen into the DecisionTraceAlways-on record: observed, context, action, policy, approval, outcome (and seam decisions), then discarded. Keeps a run bounded and replayable. Replay does not re-query Hindsight; it reads the frozen rows.

Hindsight plant bank (per plant)#

  • Typed world facts and short learning facts from L5
  • Observations with proof counts
  • observations_mission tuned to durable operating patterns
  • Directives mirror hard stops as a soft second layer (never a substitute for kernel hard stops)
  • Mental models: owner-approved questions (per asset, constraint, family); refreshed content is advisory only and never changes a threshold or playbook

Hindsight dialogue banks (per Ask thread)#

Hard wall from the plant bank. Stated retention. Promotion to the plant bank only on explicit confirmation or verified closure. Ask does not get a second judge (14-ask.md).

Case library (episodic)#

Past traces joined with L5 outcomes, retrievable by condition keyStable id for “this plant condition”; one open card per key, asset, family, pattern, footprint. Lives in the L4 store. Authority for outcomes.

Negative memory#

Re-proposal cooldown per condition key and pattern after reject or no-change. Lifted only by materially new evidence. Soft-gate threshold; calibrated via the opportunity ledgerStore of every blocked candidate with gate id and later outcome if known.

Procedural memory#

Registries, workflow recipes, analysis contracts, patterns, playbook bullets, prompts, seam thresholds — all under the release lockfile. Versioned like code (CoALA procedural memory).

OE knowledge corpus (general methods — not plant memory)#

Versioned document store + sparse method ontology for industrial efficiency literature (DOE sourcebooks, lean/energy toolkits, curated method cards). Retrieved into the advisory partition only. See 23-oe-knowledge-corpus.md. This is not Hindsight and not the case library: it answers “what methods exist for this class of waste,” not “what worked on this asset last Tuesday.”

Not in v1: cross-plant priors#

Designed as a future seam (anonymised, owner-approved bullets). Transfer validity and privacy cannot be judged from one pilot plant.


Rules#

RuleDetail
Ineligible closeOutcome set to null — does not count as success or failure for proof
Proof countsOnly independent eligible closures across shifts and dates
Selection biasOutcomes exist only for proposed actions; closure rate alone never ranks patterns
Bias correctionOpportunity ledger + exploration outcomes (exploration=true) stored alongside ordinary closures
Version / epoch changeMemory re-keyed or quarantined when detector/pattern version, asset epoch, or Hindsight version changes
ReplayEvery memory read frozen as ledger rows
Domain tagsUse domain registry ids so a new domain gets its own scope without re-tagging

What memory must not do#

  • Change hard gates, money ownership, or write bans
  • Promote playbook / prompt / threshold / model pin without lockfile + owner path
  • Accept free chat into the plant bank
  • Treat an unverified close as a high-proof “action works here”

Plant bank learning facts and case-library outcomes feed the offline council (13-improvement.md). Soft-gate blocks feed the opportunity ledger (22-missed-opportunities.md). That is half of how the system improves: learning from what it said no to.


v1 slice vs later#

v1Later
Working ledger + Hindsight plant/dialogue banks + case library + negative memory + procedural lockfileSame tiers
Cross-plant priorsNot in v1; designed as future seam
Mental-model questions owner-gated; content advisorySame
Opportunity-ledger linkage for selection-bias correctionFull calibration scorecards in ops
Page history: last 4 changes
  1. 2026-10-07 docs(technical): rewrite l4 00-10 to the architecture c52a111
  2. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872
  3. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  4. 2026-09-25 docs(l4): agentic decision architecture, ADRs, and production hardness 8275e7c

Diagram

100%

Search the architecture