Authority Memory¶
Phase 8 of the Authority Control Plane gives a workspace a memory of its own decisions: what is normal here, and what has no precedent. It is not a monitor and it is not a model. It is a set of baselines computed from the authority telemetry the layer already keeps (no argument values, no content), and one new rule type, precedent, that asks before an action runs whether the organisation has ever done this before, in this department, under this mission, or with this approver.
Anything that learns is advisory before it enforces (excellence bar E16). A precedent rule fires only when the baseline is established, and the switch from advisory to enforcement is a signed mandate.
Baselines¶
A baseline is computed per scope (workspace, department:<id>, principal:<agent_id>) over the last 90 days of authority_events:
| What | From |
|---|---|
| capabilities | action families, with counts, first and last seen, by principal, by department, by mission, by resource, delegated or not |
| resources | resource classes touched |
| missions | missions the events served |
| hours and weekdays | when decisions happen |
| approvers | who resolved escalations, and for which families |
| delegations | source to target chains created |
| sequences | which family followed which within a session |
Each baseline carries its history: events, first and last seen, days of history, and whether it is established. The minimums are 50 events and 14 days by default (XYBERN_MEMORY_MIN_EVENTS, XYBERN_MEMORY_MIN_DAYS). Baselines are cached for five minutes per scope.
The precedent rule¶
Before any rule runs, the control plane computes the precedent of the action from the baselines and puts it on the Authority Slice. A precedent primitive in a mandate names the checks it cares about:
{"type": "precedent", "action_types": ["*"], "decision": "escalate",
"conditions": {"checks": ["never_before", "not_by_this_department", "not_in_this_mission"], "advisory_until": "2026-12-01"}}
| Check | Fires when |
|---|---|
never_before |
the family has never been used in the workspace, or never by this principal |
not_by_this_department |
the workspace has done it, this department never has |
not_in_this_mission |
the mission has at least five events and has never needed this family |
not_this_approver |
at resolution: the approving person has never approved this family here |
new_resource |
the resource class has never been touched |
unusual_hour |
the hour has no history |
new_sequence |
this family has never followed the previous step in a session |
Advisory first. When the baseline is not established, or the rule's advisory_until date is in the future, the rule does not hold the action. The finding is recorded on the decision (decision_analysis.precedent with advisories) and appears in the Memory view and the decision record with an advisory pill. When the baseline is established and the advisory period is over, the rule fires and holds or refuses; the record shows enforced. A precedent hold is a definite condition: content verification never lifts it.
not_this_approver runs when a person resolves an escalation. The response carries the approver's precedent; if a live precedent rule with block names the check and the approver has no precedent for the family, the approval is refused and a different approver is needed.
Learning a rule¶
The Memory view lists the recent decisions with findings and the learned rules, and offers Turn into a rule: it creates a signed mandate with a precedent primitive, compiles it and seals the Charter. The same through the API:
GET /v1/enforce/memory/baseline?scope=workspace|department:<id>|principal:<agent_id>&days=90
GET /v1/enforce/memory/precedent?agent_id=&action_type=&mission_id=&resource_class= pure, records nothing
GET /v1/enforce/memory/findings?days=7 decisions with findings, and the learned rules
POST /v1/enforce/memory/rules approvals scope: {checks, decision, agent_id?, advisory_until?, min_events?, min_days?}
SDK: memory_baseline, precedent, memory_findings, learn_rule.
Ask Xybern¶
Questions about precedent ("has the buyer ever signed a contract?", "is this normal for the support agent?", "how often does anyone export?") are answered from the baselines with no model call: how many times, first and last, by whom, in which departments and missions, and whether the baseline is established. Nothing is recorded.
Positioning¶
Memory is framed as the rules the organisation learned from its own decisions, and the rules it may choose to sign. It never watches people, never stores content or argument values, and never decides on its own: a person signs the mandate that turns an advisory into a hold.