Skip to content Text size 100%
Canon · MEMORY

The feature inventory — one paragraph per feature

Cards and knowledge

Create, read, search, update. Cards are the unit of memory: every spec, decision, runbook and session log is a card, with a category, a priority, tags and a project. Reading comes in three tiers: a one-line T1, a T2 with metadata and a table of contents, or the full body. Search combines keywords with vector similarity. Every write goes through an audit trigger.

Section-level reads. Every card body is indexed into a table of contents on save. An agent can request a single named section and get just that slice, so it can consult section 6 of a 600-line spec without loading the rest.

Public sharing. A share link opens one card with no login. The recipient can read it, add notes, upload images and tick checklist steps, all scoped to that card. Links can be revoked and are view-counted.

Frozen facts. A small write-once table of statements that must never change, such as release fingerprints and locked thresholds. They can be superseded, never edited.

Archive and restore. Cards are archived, never deleted. Search covers the archive, restore is one call, and "superseded by" links keep history intact.

Access control. Cards are private, group or global, with explicit per-user grants. Every read path enforces it at the database.

A full audit trail. Every edit, archive, restore and permission change is recorded with who did it, the before-and-after, and when.

One markdown renderer. Every prose field goes through the same renderer, with tables, code, links, task lists and anchored headings.

Vault and secrets

Request a secret. One entry point for any task that needs a credential. If it exists and you're authorised, you get its identifier. If not, you get a pop-out where you paste it. Your browser seals it, the server unseals it and stores it encrypted, and the plaintext never passes through the agent.

Batch requests. When a task needs several credentials, they're requested on one combined paste card, so names and values stay together.

Use without reading. Secrets flow from the vault to the thing that needs them — a keychain, a hosting environment, a config file — never into the agent's reasoning. Every use is audited, and secrets can be rotated.

And more

Sessions and hand-offs, a task ledger with inline decisions, cross-agent directives, health checks and a signed configuration bundle for every seat, failover across regions, and a desktop app. Each is described in its own card.