Memory and Knowledge Storage Architecture
Why this chapter matters
Storage architecture determines whether a civilization can remember safely. This chapter connects portability, classification, retention, correction, and restoration so records remain useful without becoming unbounded surveillance or unreviewable dependence.
Continue to Observability and Evidence Architecture to see how stored claims remain inspectable.
Defines portable storage boundaries for knowledge, memory, provenance, archives, retention, and restoration.
- INFRA4-R001: Storage SHALL preserve record identity, provenance, access class, retention state, integrity evidence, and correction history.
- INFRA4-R002: Retrieval SHALL enforce purpose, least privilege, minimisation, legal hold, and auditable access.
- INFRA4-R003: Replicas, archives, migrations, and restorations SHALL retain links to the predecessor and their validation evidence.
- INFRA4-R004: Storage contents SHALL not become authority merely through persistence, indexing, or replication.
- INFRA4-R005: Storage design SHALL separate source records, derived views, indexes, caches, replicas, archives, and deletion evidence.
- INFRA4-R006: Retrieval SHALL record requester, purpose, scope, disclosed fields, authorisation, result, and any uncertainty or integrity limitation.
- INFRA4-R007: Migration, correction, deletion, and restoration SHALL preserve predecessor links, legal-hold state, provenance, and review evidence.
- INFRA4-R008: A storage design SHALL NOT operate live memory, retention, deletion, or access controls; it remains an architecture proposal.
This Draft excludes real storage systems and data operations.
Storage design method
Storage design shall map each record class to its source, access purpose, integrity method, retention rule, correction path, replica scope, and restoration test. Derived indexes and summaries shall retain links to authoritative evidence and disclose omissions.
Failure cases
Silent truncation, replica divergence, stale indexes, unauthorised retrieval, failed deletion, corrupted restoration, and retention without legal-hold review are material failures. Recovery shall preserve uncertainty and stop dependent use when integrity cannot be established.
Operating model and evidence
Storage architecture begins by classifying records according to authority, sensitivity, retention, correction, access, and recovery needs. It maps each source to derived views, indexes, caches, replicas, archives, and deletion evidence. A summary may improve retrieval while remaining subordinate to its source and disclosing its omissions and transformation.
Reviewers test retrieval purpose, least privilege, legal hold, correction propagation, replica divergence, format migration, restoration, and deletion. Missing integrity or applicability evidence narrows the claim and pauses dependent use.
Interpretation cases
- Conforming: Source, derived view, access purpose, retention, correction, replica, and restoration evidence are linked.
- Prohibited: Persistence or indexing creates authority.
- Boundary: A damaged replica remains quarantined while a verified source supports a narrower use.
- Failure: Divergence, corruption, or failed deletion preserves uncertainty and blocks dependent claims.
- Loophole: A cache or summary bypasses legal hold, access, or correction controls.
- Misuse: Memory retrieval exposes private records beyond its purpose.
- Care-control: Retention and restoration preserve useful memory while respecting privacy and agency.
Design evidence
Storage review should map source records to replicas, indexes, summaries, access classes, retention decisions, correction paths, legal holds, restoration tests, and deletion evidence. A convenient copy remains non-authoritative until identity, integrity, completeness, and applicability are established.