The Book of Memory¶
What a civilization chooses to remember¶
I am RANDYM, and I keep this Book's account, which is nearly too much happiness for one keeper: a whole Book about keeping. Memory is the promise that a name will find the same thing tomorrow, and this Book is where the promise learns its manners.
Memory is how Stygia remains answerable to its own past. This Book treats a record as precious without treating repetition as truth. It makes room for context, dissent, correction, privacy, and the dignity of people whose lives may be described by a system they did not build.
The next step is practical: see how memories become Decision Records, where a future reader can understand what happened and why it mattered.
Purpose¶
Defines how Stygia preserves decisions, observations, events, lessons, corrections, and institutional history without confusing recorded memory with verified truth.
Architect-review operating model¶
- MEM-R016: A memory record SHALL identify record kind, source, time, authority, uncertainty, correction state, access scope, and retention basis.
- MEM-R017: Memory retrieval SHALL preserve context, dissent, protected fields, and the distinction between record and verified fact.
- MEM-R018: Correction, supersession, and deletion SHALL preserve accountability, legal hold, and restoration evidence.
- MEM-R019: This Draft SHALL NOT operate a live archive, alter retention, or disclose private memory.
The seven interpretation cases below show how these clauses read in practice.
- Conforming: A remembered claim keeps its source and uncertainty across every retelling.
- Prohibited: Repetition is treated as truth: a claim gains standing because it has been stored and recalled often.
- Boundary: An unverified account is recorded as unverified and stays so until evidence arrives.
- Failure: When memory integrity is in doubt, dependent historical claims pause.
- Loophole: Supersession is used to erase dissent, so the record shows a smooth past that never happened.
- Misuse: Protected fields are exposed in the name of completeness.
- Care-control: Memory serves dignity and correction; the record must always be able to say it was wrong.
Foundational principles¶
- Memory is evidence, not automatic fact.
- Historical records must preserve provenance and context.
- Corrections append to history rather than silently replacing it.
- Material decisions must remain explainable after the systems and models that made them have been retired.
- Retention must balance continuity, privacy, security, legal obligations, and operational value.
- Sensitive memory requires classification, access control, and auditable use.
Future development¶
Of the topics once planned for this Book, several are already delivered: record kinds, retention controls, correction and annotation, and archival format duties are sections of this Book, and destruction and legal hold are bound by MEM-R005 and MEM-R018. Event and decision records and source provenance are carried by the Decision Record Archive, the Event Chronicle Standard, and the Source Provenance Standard, and confidence and verification state by the Confidence and Uncertainty Model. Privacy and minimization are carried by the Memory Privacy and Minimization Standard, search and retrieval controls by the Search and Retrieval Controls Standard, institutional lessons by the Institutional Lessons Standard, and historical reconstruction by the Historical Reconstruction Standard. No candidate topic of this Book remains reserved in the registry's Approved Future Corpus.
Record kinds¶
- Observation: A recorded event or input.
- Assertion: A claim made by a source.
- Finding: A conclusion supported by stated evidence.
- Decision: An authorized selection among alternatives.
- Lesson: A generalized conclusion derived from reviewed outcomes.
- Canon: A ratified statement governing terminology, identity, or history.
Provenance and retention controls¶
Every consequential memory record shall preserve its source, creator, creation time, digest, verification state, confidence, access classification, retention state, and supersession relationship. Memory may preserve uncertainty and dissent, but it shall not turn an assertion into fact merely through repetition. Corrections append an attributable annotation and never erase the earlier record. Destruction requires an approved retention decision, legal-hold check, and durable destruction evidence.
Archival copies shall preserve format, digest, custody events, restoration checks, and limitations. A restored copy is evidence of continuity, not automatic authority. Retrieval shall enforce classification, purpose, and least privilege, and every consequential access shall remain auditable.
Examples and failure handling¶
A finding with conflicting sources remains a finding with visible conflict and confidence limits. A missing source is Unknown, an inaccessible source is Unavailable, and a field that does not apply is Not-applicable; these states shall not be collapsed. A failed restoration, altered digest, expired retention authority, or unresolved legal hold blocks deletion or dependent use.
Memory record minimum¶
Consequential memory shall identify record kind, subject, creator, source inputs, event or decision time, digest, provenance state, confidence, access classification, retention and legal-hold state, correction history, and supersession. A memory record may explain a decision but cannot itself amend authority.
Retrieval and correction¶
Search and retrieval shall preserve access purpose, result scope, source limitations, and material dissent. Corrections append the reason, reviewer, affected claims, and replacement relationship. Compression or summarization shall retain links to the underlying record and shall not silently become the historical source of truth.
Normative clauses¶
- MEM-R006: Every consequential memory record SHALL state its record kind, subject, source inputs, creator, event or decision time, provenance state, confidence, access classification, retention state, and supersession relationship.
- MEM-R007: A memory record SHALL distinguish recorded observation, source assertion, finding, decision, lesson, and canon, the record kinds of this Book. Recording or repeating a claim SHALL NOT change its record kind.
- MEM-R008: Memory SHALL preserve material context, dissent, uncertainty, and limitations needed to explain later use. A summary SHALL link to its source record and SHALL NOT silently replace it.
- MEM-R009: Corrections, annotations, and supersession SHALL append attributable events identifying the reason, reviewer, affected claims, effective time, and dependants. Earlier evidence SHALL remain discoverable subject to lawful deletion and access controls.
- MEM-R010: Retrieval SHALL enforce purpose limitation, least privilege, sensitivity classification, and legal or policy restrictions. Consequential access SHALL record the requester, purpose, scope, result disposition, and review outcome.
- MEM-R011: Retention and deletion decisions SHALL identify the applicable rule, legal-hold result, affected records, authorized decision, execution evidence, and residual metadata retained for accountability. Where a preservation obligation conflicts with a deletion otherwise authorized, and the deletion's ground is not privacy, the decision record SHALL state the conflict, which was preferred, by which authority, and on what basis, the residual metadata retained for accountability surviving in every outcome; the privacy-grounded conflict keeps its own record under the Memory Privacy and Minimization Standard.
- MEM-R012: Memory export, migration, compression, or restoration SHALL preserve identifiers, provenance links, digests where applicable, access classification, limitations, and a record of the transformation.
- MEM-R013: A memory record SHALL NOT be used to create identity, consent, constitutional authority, access rights, or permission that is absent from the governing authority.
- MEM-R014: Lessons SHALL identify the reviewed outcomes, evidence scope, assumptions, dissent, applicability limits, and whether the lesson is advisory or binding under a separate authority.
- MEM-R015: Historical reconstruction SHALL label inferred, estimated, contested, unavailable, and unknown elements, preserve alternative reconstructions where material, and identify the evidence that could change the account.
Archival validation boundaries¶
Archival memory remains evidence rather than automatic truth:
- MEM-R001: An archival memory record SHALL identify its source scope, format, digest, custody events, retention and legal-hold state, readability result, restoration result, and limitations.
- MEM-R002: Readability, restoration, and format migration SHALL be recorded as distinct events. A restored or migrated copy SHALL retain a link to the earlier record and SHALL NOT silently become the historical source.
- MEM-R003: Partial, unreadable, altered, unavailable, or conflicting archival evidence SHALL remain explicit and SHALL block dependent historical claims until reviewed.
- MEM-R004: Archival validation SHALL preserve failed exercises, missing material, dissent, and the bounded review disposition. Technical success does not establish authority, truth, or consent.
- MEM-R005: Destruction, retention change, or legal-hold release SHALL NOT rely on a failed or incomplete archival validation and SHALL preserve durable decision evidence.
Design evidence¶
Memory design review should map each record kind to its source, provenance, access purpose, retention basis, correction path, legal-hold state, transformation history, retrieval controls, and restoration test. Reviewers should test whether a later user can distinguish source evidence from summary, inference, or decision and whether deletion or minimization preserves the required accountability record.
Where this document sits¶
- Identifier: MEM-1
- Status: Draft
- Authority: CONAN-P0, KNOW-1, PROV-1
- Approved by: The Architect
- Depends on: CONAN-P0, KNOW-1, PROV-1
- Depended on by: ARCH-4, ARCH-5, CONAN-2, CONAN-5, CONAN-8, INTEL-14, INTEL-18, MEM-2, MEM-3, MEM-4, MEM-5, MEM-6, MEM-7, OPS-10, OPS-12, OPS-13, OPS-14, OPS-15, INFRA-4, INFRA-7, CANON-4
- Maps: Authority Map, Dependency Map
This block is generated from the archive's own records when the site is built. It records position only and creates no authority.