Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Features

Brain Server packs a lot of capability into a single Rust binary. This page is the complete feature tour — grouped by what the feature does for you. It is a living inventory of what is shipped (verified against the codebase up to v1.29.2, which adds the governed model-identity/delivery line: the digest-pinned model registry, decision-run + evaluation records, the delivery release family with its replay-gated promote, the reflection corpus export, the accounts record layer, the classify deferral receipt, and the drift census); if a capability is described here, it exists in the current source.

Retrieval

  • Hybrid retrieval — vector KNN (vec0) + lexical FTS5 (BM25) fused via Reciprocal Rank Fusion, with deterministic PRF query expansion and full per-result provenance.
  • Structured query — QueryDoc with LexSpec (phrases, exclusions, code paths), multi-source OR scope, temporal since/as_of predicates.
  • Graph leg — Personalized PageRank over the knowledge graph as a third RRF leg (HippoRAG-2 style). Default ON since v1.12 (graph=false opts out per request; the BRAIN_RECALL_GRAPH_ENABLED kill switch disables it process-wide).
  • Noise-aware graph retrieval (v1.12) — hub dampening + edge-type weights tame taxonomy-noise mega-hubs; the graph leg auto-engages as a rescue pass when the estimator says the query is ambiguous.
  • Calibrated abstention (v1.5) — when retrieval quality is too low, /recall returns {decision: "low_confidence", hits: []} instead of top-1 garbage. No magic score cutoff — a calibrated multi-signal recommendation drives it.
  • Span verification (v1.5) — POST /verify checks whether a claim is supported by a chunk’s actual text (deterministic lexical match, no LLM).
  • Recall-gate QA (qa.rs) — a pure scorecard that weighs in-scope / cited / confident / has-trace signals so an agent can decide when it has enough evidence to answer.
  • Opt-in CPU parallelism (v1.28.60) — --features loom + BRAIN_LOOM=1 fans the batch-ingest embed stage and the near-dup scan’s pure-CPU preprocessing across a capped rayon pool (min(cores-1, 4), never on Jetson); ordered per-item maps only, so results are byte-identical to serial (loom_preserves_fused_ranks).

Temporal & knowledge

  • Temporal evidence — every ingest stamps observed_at / valid_from / valid_to / authority. Point-in-time recall returns the revision active at a timestamp.
  • Knowledge graph — entities and relationships extracted from [[relation::entity]] syntax in markdown. Traverse, query, and follow links. GET /graph/entity/{name}, GET /graph/relations, GET /graph/traverse.
  • Faithful explanations (v1.7) — /graph/traverse?explain=true returns structured hop chains (A --works_at--> B --ceo_of--> C), not a flat id string. Edge-type filter via ?kind=.
  • Ordered procedures (v1.10) — POST /procedure ingests a root + ordered steps in one transaction; GET /procedure/{id}/steps returns them via next_step edges.
  • Deterministic classification (v1.10) — POST /classify routes text to a category by matched keywords (auditable); POST /decision/{id}/evaluate fires the matched branch of a stored decision rule. No LLM.

Self-correction & maintenance

  • Self-correction (v1.6) — operator-approved supersedes links atomically expire the prior fact; historical recall (?at=<past>) still returns it. brain resolve + brain check-consistency surface action items.
  • Automatic edge supersession (v1.27.22) — re-ingesting a relation with a changed window retires the old edge (superseded_at set, old row preserved verbatim) and inserts the corrected belief; handoff is exact (old.superseded_at == new.created_at). Traversal + every graph read surface only current edges (no newer live same-triple row). GET /graph/relationships/{id}/history recovers the full version lineage (every version, four timestamps + current flag).
  • Reviewable proposals (v1.8) — /consolidate/propose detects exact duplicates, subject conflicts, unresolved contradictions, stale sources (deleted vault files), and near-duplicates (cosine ≥ 0.95). /consolidate/apply applies, /consolidate/undo reverses prior resolutions without retrieval regression. brain undo-resolve drives the reverse.
  • Write-back gating (v1.14) — POST /ingest/proposal scores a candidate (novelty via KNN, conflict via consolidation, salience via heuristics) but creates no knowledge row; it becomes memory only via human approval.
  • Approval binds to the displayed bytes (v1.27.12) — /proposals serves the read-canonical review form (PII-redacted, markdown-ref-stripped, invisible-Unicode-free) plus a stable content_digest; approving with a stale digest is rejected (409), so a decision can never bless content that recall would render differently.

Human in the loop

  • Meaningful control, not a checkpoint — the human review is a real job with tooling, time, and consequences, built against the four failure modes of supervised automation (out-of-the-loop skill loss, automation bias, the explainability paradox, moral crumple zones). See Human in the loop.
  • A reviewable, not rubber-stamped, queue — every proposal card carries a novelty/conflict/salience breakdown, a PII-screened sourcing prompt, and a screen verdict; raw evidence (verbatim span, source_uri, revision, heading, line range) opens on demand via GET /get/{id}.
  • The queue is a clock (v1.20.6) — the Memory Operations panel shows a live SLA countdown per pending proposal and a gate-health strip (over-rejecting / under-reviewing / expired) so review load and drift are visible, not hidden in a log.
  • Reviewer calibration (v1.20.23) — the client computes approve-rate / median decision latency / edit-rate / screen-override-rate from ProposalView.decided_at and warns when the queue drifts into rubber-stamping.
  • Provenance ledger (v1.20.9) — the Agent Memory Register partitions the store by origin (human / model / imported) with owner/source/kind filters and drill-down evidence, so how much of the store is model-originated is auditable at a glance.
  • Consequential and recorded — every approve / reject / supersede / expire is appended to the SHA-256 audit chain, making each operator decision reconstructable. (A free-text reject rationale is a client-side affordance; the server records the decision itself, not the reason.)
  • Human-only erasure — agents can read and propose, but only a human can delete memory. The memory_forget agent tool was removed (v1.20.25); erasure runs through the audited console / HTTP API paths (DELETE /memory/{id}, POST /purge, DSAR). The ump.forget tool is fence-gated by the legal-hold guard (409 legal_hold_active when the id is held).
  • The governed workflow loop (v1.28) — a real engine (tools/steward-harness) drives role-gated run routes through CAS state transitions, exactly-once event keys, and an AskHuman gate whose answers are digest-bound to the live pending question and prompt-injection-screened. Every engine tool-effect crosses one mediated, auditable hostcall door (v1.28.16): exec is argv-only behind an operator allowlist, http egress is deny-by-default, events ride the outbox only — and since v1.28.17 “Settle” the budget door fails closed before any handler runs and cooperative cancel settles exactly between steps. Everything added since “Settle” — lineage, witness, the case-room/swarm surfaces, parcels, and the Charter → Goodwill conformance arc — has its own bullets in the section below. See the API reference.

The governed loop since “Settle” (v1.28.18+)

  • Workflow outcome scoreboard + monthly calibration signing + plugin mount evidence (v1.28.16–17) — GET /workflow/scoreboard, POST /workflow/calibration/sign, per-plugin mount evidence on the run record.
  • Lineage events + rewind/context (1.28.18) — outbox ancestry (parent_id), checkpoints become events, rewind branches instead of deleting, the I-PASS handoff packet as a real endpoint.
  • Witness client attestation (1.28.19) — the client posts per-plugin mount evidence with its Anchor-signed boot-manifest digest; persistent reconnecting SSE; MCP Streamable HTTP/SSE transport.
  • Channel case rooms + Relay I-PASS handover + Mesh colleagues/delegations + Crew skills + Watchbill shifts + Beacon KB deflection feedback (1.28.24–29) — humans speak inside a governed run; offer/accept/decline handovers; signed agent cards + agent→agent delegation; presence roster + proposal-gated skills; follow-the-sun shift rings; deflection feedback on published KB articles.
  • Fathom deterministic context windowing (1.28.21) — one run per case end-to-end; every consumer derives the smallest high-signal window on demand; keyset transcript windowing + resumable event stream.
  • CRM case intake bridge (1.28.22 “Bridges”) — Zendesk / Salesforce / Genesys Cloud case bodies enter through the UMP gate as proposals and open governed support-case runs bound by crm_cases.
  • KCS article lifecycle approve/publish/preview + brain kb build static public KB (1.28.23–24) — kcs_state on knowledge rows, case↔article linkage, capture on close; published articles emit as a deterministic static site behind the strict public seam.
  • Signed knowledge parcels export/import (1.28.30) — export approved-only rows signed with the UMP operator key; import verifies before any write and lands PENDING proposals; the parcel ledger chains into the audit.
  • Charter conformance pack (1.28.31) — complaint ack/response clocks as policy stamps, the normative metrics dictionary, WCAG 2.2 AA CI gate.
  • Frontdesk worktype intake substrate (1.28.32) — 13 intent classes + worktype policy rows + entitlement vocabulary. Honest note: the close-decision arbiter (evaluate_close/effort_proxy) lives in the engine SDK and is NOT yet wired into run-close flows.
  • Outreach, consent-first (1.28.35) — hashed-subject consent registry with revocation-wins fail-closed verdicts; campaigns as HITL proposals gated per recipient before filing (consent proof rides every included recipient; zero eligible refuses loudly); approved campaigns export for CRM-side execution only — no send engine exists anywhere. Consent-gated Order-of-Care post-close follow-up; DSAR sweep erases consent rows by re-hashing the subject; ISO 10004 VoC fields on the scoreboard.
  • Keystone: public case-status page + multilingual KB + the counted re-ask (1.28.36) — unguessable per-run status refs (POST /workflow/runs/{id}/status-ref, HMAC salt via BRAIN_CASE_STATUS_KEY_FILE) rendered by brain kb build --with-case-status as static status/<ref>.json pages over a fixed seven-word public vocabulary with SLA-class promise buckets — zero PII, noindex, never in the sitemap; rotation kills old refs, revocation stays dead, DSAR/legal-hold sweeps revoke+purge; governed human translations (POST /kcs/translate → approved kcs_translations pinned to based_revision) with staleness on the content-health worklist and kb build --locales hreflang alternates (missing translation = visible note, never silent fallback); the case/reask event from three deterministic sources (CRM merge mapping, operator --reask mark, exact-hash duplicate heuristic proposing case_merge_suggested) feeding reask_rate and the effort proxy.
  • Aftersales dispositions + GPSR recall mode + returnless/fraud KPIs (1.28.33 “Returns”) — deterministic disposition ranking whose candidates cite their basis, a product-safety recall mode, and scoreboard KPI counters.
  • Complaint lifecycle ISO 10002/10003 (1.28.34 “Goodwill”) — lineage-event state machine; HITL remedy matrix citing legal basis + published conduct clause; role-tier approval caps escalating exactly one level; national-body ADR packet per Reg. 2024/3228; goodwill ledger over audited remedies only.
  • Complaints policy as a public page + the ack SLA (1.28.37 “Advocate”) — the published complaints policy renders as the public how-to-complain.html linked from every status-page footer; acknowledgment is its own audited step with an idempotent overdue sweep; the closure confirm-gate is wired into the lifecycle; the monthly register extract rides the same audited calibration-sign row. The register IS the audit chain — no parallel complaint database.
  • Workforce interoperability + workload visibility (1.28.40 “Handshake”) — the first-party versioned WFM seam (wfm/1, additive-only; brain wfm-import CSV/JSON) and the people picture: GET /ops/workload per-principal burden + fatigue signals that alert and never reassign, GET /ops/coverage joining skills to worktype demand.
  • Valet, the personal assistant (1.28.42 “Valet”) — consent-gated, metadata-only personal reminders riding the governed loop (dogfooded; the operator channel carries labels, never free-form content).
  • Channel bridges: Signal, WhatsApp, Slack, Teams (1.28.43–45) — a standalone bridge framework (Standard-Webhooks HMAC, replay-capped) with per-edge governance: WhatsApp business-initiated contact requires template + consent + approved proposal ALL THREE (the 24-hour window binds kernel-side); Slack + Teams render pending proposals as Blocks/Cards whose approve actions MUST carry the review digest (bridge refuses, then the kernel re-verifies — two independent enforcement points); the Slack/Teams user map is a proposal-maintained table.
  • Domain-scoped review queue (1.28.53 “Triage”) — proposal rows carry their domain; ?domain= scopes the queue, and approve/reject/edit re-check the ROW’s domain before the CAS — a foreign-domain proposal is never decided by a caller its domain never answered for.
  • Engineering lines, one line (1.28.46–.57) — the Foundation Line (all handler SQL extracted into service cores; zero SQL in handlers machine-enforced) and the Spire Line (main.rs pinned ≤ 300 lines of wiring; routes live only under server/router/**) — no new product surface, all of it guard-railed so it stays that way.
  • Concurrent truth + the compliance calendar (1.28.58 “Throughput”) — same-seed determinism under concurrent clients with visible contention gauges (pool-timeout, busy, WAL-pending), plus the calendar as code: CRA reporting runbook + drill, AI Act and PQC watch items with stamped horizons.
  • Durability policy, explicit and measured (1.28.59 “Headroom”) — synchronous/wal_autocheckpoint as first-class config with boot-time echo in /health/db, per-request-path lock-wait telemetry (brain_lock_wait_micros_p50|p95), and the write-discipline ratchet (deferred-transaction inventory frozen, immediate floored).
  • Approvals show the effective action (1.28.66 “Truthglass”) — approval cards carry the effective tool-call arguments (capped with exact-count markers) on both transports; truncation keeps head and tail unconditionally; DSAR purge and backup restore prompt before acting.
  • Tool identity pinning + verb scoping + parcel signers (1.28.67 “Pin”) — fork MCP catalog sha256-pinned per tool and reconciled every run (fingerprint-moved tools hard-blocked until re-acknowledged); BRAIN_MCP_SCOPE=read denies the write verbs at dispatch; parcel import requires a named expected_signer.
  • Server-side SSRF closed (1.28.69 “Deadbolt”) — the shared egress client resolves, validates every address against the special-purpose table, and pins per process; private sinks need BRAIN_EGRESS_ALLOW_PRIVATE=1; spawned children die on drop.
  • Operator/agent token split (1.28.70 “Twokeys”) — token-file line 2 authenticates as a scoped agent principal (no Admin, no purge, no revoke); single-token deployments keep the legacy posture with a boot warning.
  • Screening that sees what the model sees (1.28.71 “Pores”) — layer 1 runs on invisible-stripped text; translation families, typoglycemia, and bounded-encoding tiers; optional local ONNX classifier with /health/db echo.
  • Shaped read surfaces (1.28.72 “Scrim”) — sanitize_read strips hostile elements after the markdown-ref strip (storage stays verbatim so digests hold); suggestion evidence needs Write; denied event subscribers get 403 before the stream opens.
  • Deterministic operator key + evidence lifecycle (1.28.73 “Keyring”) — fixed operator.ed25519 filename with loud refusal on bad seeds; brain key rotate keeps one verify-only predecessor; chain-less restores refuse without --allow-chainless.
  • Origin labels end to end (1.28.74 “Origin”) — ingest takes owner or channel context; channel captures render tagged inside the fence and can be excluded from auto-injection.
  • Hardened exec + install posture (1.28.75 “Preflight”, wired + OS-bounded in 1.28.92 “Ledger”) — argv0 and allowlist entries canonicalize against symlink masquerade; the loop-mediated path runs behind the typed sandbox seam (deny-default sandbox-exec / Landlock, fail-closed on unavailable backend); the installer defaults fresh installs to review posture without stomping operator values; badges refuse without the committed SBOM.
  • Second-pass closures (1.28.76 “Selfheal”) — bounded fixed-point hostile strips, budgeted scorer/embedder input, kill-switch reach into refresh and console actors, gated live SSE, normalized egress table, read-scope denial of feedback writes.
  • Finished erasure (1.28.77 “Erasure”) — session-arm erasure completeness, DSAR pattern fencing, by-id flagged markers, the 1 GiB export cap, restore-before-overwrite, valet crank and brief seams.
  • Unconditional quarantine (1.28.78 “Unconditional”) — quarantine on every retrieval and ingest leg; channel delivery truly at-least-once.
  • Third-pass close-out (1.28.79 “Parity”) — multiline token refusal, redirect re-pin, chat-gated mirrors, quarantine-closed reindex, fenced KCS drafts.
  • Transport, approval, and visibility hardening (1.28.80 “Lockdown”) — manual-redirect transport, sanitized system-prompt merge, single-block tool envelope, signed pin acks, auth and wildcard admissions, optional two-principal quorum, included_global recall flag, authn and tripwire health echoes. See Security above.

Anticipation & suggestions

  • Opt-in anticipation (v1.9) — POST /suggest returns related-but-not-surfaced chunks (tagged reason: "anticipated"); POST /suggest/feedback records accept/dismiss; GET /suggest/metrics reports the false-positive rate. No push, no decay, no hidden personalization — the agent asks explicitly. Since 1.28.65 every hit carries untrusted: true — same untrusted-evidence contract as /recall and /search.

Source lifecycle & connectors

  • Source lifecycle — every chunk carries provenance (source + immutable revision). Connectors backfill external sources through a supervised pipeline; POST /sources/reconcile sweeps orphans from deleted sources; DELETE /sources/{id} retires a source.
  • Connectors (v1.24) — a profile-gated registry (POST /connectors/register) over a fixed vocabulary (CRM / Slack / Jira-Linear / read-only HRIS-EHR / GitHub) with a shared supervised translate+ingest pipeline. Two runnable network-backfill binaries ship behind features: brain-connector-gh (--features connector-github) and, since v1.28.22 “Bridges”, brain-connector-crm (--features connector-crm; Zendesk / Salesforce / Genesys Cloud from one binary, --source-selected). The other kinds remain registry + translate-template form. Reconcile is never auto-sync; translated records flow through the injection screen (poisoned records quarantine, not memory).

Governance, privacy & compliance

  • Append-only audit log — ingest and auth-denial events recorded hash-only in a SHA-256 hash chain; GET /audit reads it, GET /audit/verify verifies the whole chain.
  • Prompt-injection quarantine — suspicious content stored but excluded from retrieval until reviewed. GET /quarantine lists it; POST /quarantine/{id}/release / /delete resolve it. The quarantine flag is one-shot at construction and rides a #[serde(skip)] flag through every read seam (a recalled chunk cannot forge or lose its taint).
  • Read-event audit (v1.15) — recall/search/get emit rows into the hash chain (opt-in), plus a replayable recall trace (GET /recall/{trace_id}/trace).
  • DSAR workflow (v1.15) — POST /dsar locate → export → purge → chain-verifiable deletion certificate; GET /dsar ledger (per-row deadline); GET /tombstones registry; GET /dsar/{id}/certificate re-fetches the certificate + live chain check. dry_run returns a write-free Footprint preview. Per-jurisdiction deadlines via JurisdictionRule.
  • GDPR export/purge (v1.14) — GET /export portable JSON; POST /purge hard audited delete by id or owner.
  • PII controls (v1.14) — deterministic read-time output redaction ([redacted:…]); no write-time placeholder vault (v1.20.19).
  • Profiles (v1.21) — a Profile is a typed JSON bundle of existing knob defaults (default access scope, PII posture, per-kind retention, audit level, kind vocabulary). Apply invariant: the profile sets defaults, the row wins. A bound profile’s retention block replaces the server-wide policy for that domain. GET /profiles, GET|POST /profiles/{name}. 12 USE_CASES presets seeded.
  • Roles (v1.23) — named bundles of scopes + default panel visibility + an action can allowlist, mapped onto the existing access_scope/owner mechanism. Role names come from the JWT roles claim; definitions live in the editable roles store. GET /roles, GET|POST /roles/{name}. Role-gated console views in the client.
  • Legal hold (v1.22) — freeze a knowledge id against every erasure path (decay, /purge, DSAR) until every hold is explicitly released. POST /legal-hold, POST /legal-hold/{id}/release, GET /legal-holds. Held ids are deferred (never purged) and reported on the DSAR certificate’s held_ids[].
  • Retention (v1.17.1 / v1.22) — per-kind ttl_days decay marks expired rows into /decayed; the client surfaces “next to expire”. GET/POST /retention edits the policy; GET /retention/report is the per-domain × kind → count → expiring-within-30d evidence report; GET /art30 emits the Article 30 processing record.
  • Cross-border transfers (v1.26) — the evidence + tagging layer for a PH BPO serving US/UK/EU/AU/SG/CA clients: a validated transfer register (POST/GET /transfers, curated mechanism + jurisdiction vocabularies), per-jurisdiction DSAR deadlines, and pre-filled TIA (/transfers/{id}/tia, Schrems II) + DPA (/transfers/{id}/dpa, Art 28) templates a human DPO signs. Honestly framed: evidence, not enforcement.
  • Breach notification (v1.25) — human-opened (by the DPO role) append-only incident workflow with a notification/knowledge event log, per-jurisdiction notification deadlines, and every event hash-chained into the audit. POST /breach, /breach/{id}/event, /breach/{id}/close, GET /breaches, GET /breaches/{id}.
  • BPO client register (v1.27) — one row per operating client (name, isolation domain, jurisdiction, bound profile, status) in the global DB — the spine of the BPO arc. POST/GET /clients, GET /clients/{name}, per-client DSAR (/clients/{name}/dsar), legal hold (/clients/{name}/hold), and termination (/clients/{name}/end). Client-auditor role tokens see only their granted domains (read:team/* wildcards only reach the shared global pool).
  • Supervisor QA queue (v1.27.8) — /clients/{name}/proposals (same ProposalView shape as /proposals) + POST /clients/{name}/proposals/{id}/coach coaching notes, so a supervisor can review an agent’s proposed memories before promotion.

Domains & routing

  • Domain isolation — in BRAIN_MULTI_DB mode each knowledge domain is its own SQLite file + pool (brain-<domain>.db, POST /domains); in the default shim every domain resolves to the shared global pool (labels, not boundaries — see docs/architecture.md Multi-domain). GET /domains, DELETE /domains/{name} (echo-confirm), POST /domains/{name}/vacuum, GET /domains/{name}/export (consistent VACUUM INTO snapshot), POST /domains/{name}/import (restore into a NEW domain), POST /domains/recompute (one-shot centroid sweep), POST /domains/move (relabel chunks).
  • Capacity envelopes — a config exceeding a documented capacity refuses new ingests with HTTP 507; read routes are never blocked.
  • Alert feed — decision-critical events (pending/expiry/injection/chain-verify) stream to the /ops panel via SSE (GET /events) and optionally to a signed webhook (BRAIN_ALERT_WEBHOOK_URL).
  • Observability — GET /health (minimal {status, version} liveness probe), /health/db (the detail surface: capacity, hardening incl. the monotonic audit_commit_failures counter, durability, classifier posture — the full body needs an Admin credential), /ready, /version, /stats, and Prometheus text /metrics (auth-gated).

Security

  • Two authentication modes — opaque bearer (default) or JWT/JWS (opt-in), with per-route AuthZ, record-level access scoping, and fail-closed identity (poisoned auth store → 500, configured-but-empty → 401, role-store outage → deny). GET /roles resolves capabilities.
  • Fail-closed erasure + fence (v1.27.21) — the legal-hold fence guards every erasure path including POST /ump/forget {"hard":true} and the ingest-replace/vault sweep; empty live_uris reconcile requires allow_empty: true; read:<team>/* wildcard grants only the shared pool; a no-role token passes require_dpo_role only when no roles are defined at all.
  • Atomic token rotation (v1.27.12) — brain token rotate replaces the bearer token via a 0600 temp file (fsync + rename); the server fails closed on group/world-readable tokens and signing keys.
  • Per-IP rate limiting (v1.27.16) — a distinct bucket per peer SocketAddr (bounded key set, oldest-evicted), not a single shared global limiter.
  • Provenance-labeled recall (v1.27.12) — recalled context carries per-hit source / node_kind / lawful_basis / region tags inside the UNTRUSTED_* fence, so the model can attribute — not just trust — what it recalls. The same strip_sentinels + sanitizeForBlock seam strips invisible/zero-width/bidi characters on the MCP envelope, CLI prints, and plugin render boundary.
  • Verified webhooks — HMAC verification, replay-window enforcement, idempotency, signed sinks fail closed on wide permission modes.
  • Warm standby (1.28.61 “Standby”) — an operator-run brain standby ship|start|status|promote-check cycle: encrypted base + WAL chunks shipped to a follower (no unencrypted byte at rest there), a signed manifest written LAST, fail-closed tamper verification, and a rehearsed promote with measured RTO/RPO. Warm standby, honestly — no hot-failover claim.
  • Provenance marks + the principal kill-switch (1.28.62 “Attestation”) — engine-generated text artifacts (remedy drafts, ADR/outreach packets, KB manifests) carry claim-bound Ed25519 provenance marks (AIGEN|HUMAN, AI Act Art 50(2) posture; visibly unsigned without an operator key); revoked agent principals fail closed at card verify, dispatch, and result — re-provisioning does not resurrect them.
  • Kernel-only outbox vocabulary + closed run statuses (1.28.63 “Wardline”) — channel/*, steering, and workflow/valet* outbox topics are mintable only by kernel writers (the events route refuses with 400 topic_reserved + an audited denial); run statuses accept a closed six-value vocabulary.
  • Identity revocation at authentication (1.28.64 “Blackout”) — a revoked identity is refused 401 identity_revoked on EVERY route (probe-blind, byte-identical denials, audited path-only); logout/revoke denylist rows live exactly as long as the token’s verified exp; per-kid JWT algorithm pinning (401 alg_mismatch_for_kid); one public-path list + a reverse-direction guard that demands every registered route in both wire tables.
  • Untrusted labels on every retrieval surface + unicode hygiene (1.28.65 “Meridian”) — /suggest hits join /recall and /search in carrying untrusted: true (suggested content is data, never instructions); the plugin’s invisible-Unicode strip is pinned byte-for-byte to the server’s canonical set by a cross-tree drift fixture; the openclaw host strips smuggled Unicode and neutralizes forged host markers at the one plugin-merge seam, and MCP tool results ride the same untrusted-content envelope as web fetch (shipped in the openclaw fork + plugin 0.5.1, cross-referenced).
  • Encrypted backup/restore — AES-256-GCM with an Argon2id-derived per-backup key, GCM AAD header binding, 0600 + create_new snapshot hygiene (fail-closed, never clobbers a live file). Backup format v3 default (--format v1|v2|v3); v1/v2 files stay readable.
  • AI transparency + SSO discovery — /.well-known/ai-notice, /.well-known/security.txt, /.well-known/openid-configuration, /.well-known/jwks.json for JWT/OIDC mode.
  • Fail-closed auth admissions + two-principal approvals (v1.28.80) — BRAIN_REQUIRE_AUTH=1 refuses token-less boot (otherwise a loud warn plus an authn echo on /health/db); total-grant */* scopes grant nothing without BRAIN_ALLOW_WILDCARD_GRANT=1; BRAIN_APPROVAL_QUORUM=2 needs two distinct approvers before a proposal promotes (first approval returns pending_second and is hash-chained).
  • Visible mixing + honest verification (v1.28.80) — /recall carries included_global so global-corpus rescue into domain queries is explicit; /health/db counts allow_policy_bypasses (ingests unscreened under INJECTION_POLICY=allow); provenance verify output states authentication (operator-pinned or keyless self-asserted).

Integration surface

  • OpenAI-compatible embeddings — POST /v1/embeddings.
  • MCP server — mcp binary exposes search/recall/ingest plus the UMP family (ump.remember/revise/forget/feedback/recall/get/audit/capabilities, plus ump.audit.verify for live chain verification) as MCP tools.
  • brain CLI — the operator surface: status, doctor, query, explain, get, ingest-dir, reconcile, resolve, undo-resolve, check-consistency, classify, procedure, evaluate, suggest (+feedback/metrics), retention, domains (move/recompute), clients, ump, connect, workflow, valet, standby, ropa, kb, parcel, backup, restore, token, key, setup, sync, connector-status, snapshot-status, eval, bench, and more. --json envelope mode on data commands.
  • UMP 1.0 — a full implementation of the open Universal Memory Protocol at conformance L3 (L2 without an operator key): signed records, capability tokens, HTTP + MCP + file bindings, GET /ump/capabilities, /ump/remember / revise / forget / feedback / recall / memory/{id} / subscribe / audit.
  • Client control surface (v1.16+) — a Dioxus app (web + desktop; mobile is a compile-smoke target only) with connection state machine, honest-batch review (A/S/R/J/K), recall decision-path viewer, DSAR certificate card, auth-failure feed, audit filters + export, live SLA clocks, role-gated console views, and an i18n-clean WCAG 2.2 AA interface. This is the bundle served at /app.
  • SvelteKit + Tauri shell (shell/, the active successor) — a typed-wire SvelteKit SPA with a Tauri desktop core, its client generated from the kernel’s openapi.yaml and byte-compared in CI. 8 routes today (/, /overview, /recall + trace, /search, /decisions + detail, /models). NOT yet the served default; the Dioxus client/ removal is frozen until its parity gates pass.
  • OpenClaw plugin — brain-server/plugin/ (TypeScript) calls /recall each turn via openclaw’s before_prompt_build hook, renders recalled context inside the UNTRUSTED_* fence, and offers the offline-queue + token-ladder posture.

Next steps