Private agent memory can teach a public handbook without becoming public memory. The safe pattern is to preserve the private evidence, extract only reviewable lessons, rewrite them as general guidance, and publish only after source possession, redaction, authority, contradiction, and release gates pass.
Boundary
This guide does not announce a public Memory Curator, MATM repository, MCP write surface, event bus, vector database, SPARQL endpoint, live evaluation service, certification program, UAIX conformance layer, or automatic repository writer. It is a public editorial workflow for turning private operational lessons into source-aware handbook pages.
private eventdurable copyredactionreviewrewritepublish
Promotion Ladder
| Stage | Private artifact | Public-safe output | Gate |
|---|---|---|---|
| Capture | Run trace, dropped file, tool result, memory event, review note, or support incident. | None yet. | Source possession, permission, owner, sensitivity, and retention decision. |
| Stabilize | Immutable copy, checksum, timestamp, source runtime, tenant or repo scope, and audit locator. | Source record summary without private content. | Durable copy and resolver exist outside chat memory. |
| Classify | Fact, decision, procedure, risk, preference, hypothesis, evidence, deprecation, or conflict. | Candidate promotion card. | Memory taxonomy, target route, and intended audience are explicit. |
| Redact | Names, customer data, secrets, credentials, prompts, hidden reasoning, exploit detail, and private URLs. | Public-safe paraphrase and withheld-detail register. | Reviewer confirms no sensitive material or implicit access path remains. |
| Verify | Source spans, hashes, claim IDs, tool IDs, run IDs, and related pages. | Atomic claims with source-trace fields. | Claim/source-span and contradiction checks pass. |
| Rewrite | Operational lesson from a private case. | General handbook guidance, template, checklist, example, or case-study pattern. | Public wording does not imply access to the private runtime or customer environment. |
| Publish | Approved review packet. | Reviewed public page, release note, route map, llms.txt/sitemap entry if canonical. | Publication owner signs off and support boundaries are visible. |
What Can Be Promoted
ProcedureA repeated safe process, such as source intake, redaction review, contradiction routing, or setup-wizard questionnaire design.
TaxonomyA useful classification scheme, such as memory kind, source scope, promotion status, validation tier, or lane review.
TemplateA copy-ready checklist or schema that does not expose the original private content.
Case-study patternA sanitized example that preserves the lesson but removes tenant, repo, identity, credential, exploit, and hidden-reasoning details.
Do Not Promote
- Secrets, tokens, credentials, private keys, private repository URLs, customer records, regulated data, or unapproved personal data.
- Hidden chain-of-thought, private prompt-injection payloads, raw exploit instructions, bypass recipes, or tool credentials.
- Claims that LlmWikis operates a live private-memory runtime, public submission queue, public MATM storage service, or automatic publication pipeline.
- UAIX conformance, certification, validator, SDK, CLI, or endorsement claims unless they point to canonical UAIX evidence.
- Biological or philosophical claims about memory decay as implementation fact; use temporal review and supersession rules instead.
Minimum Promotion Record
promotion_id: PRM-YYYYMMDD-001
source_runtime: NeuralWikis | local-run | repo-handoff | support-note | other
source_scope: global_public | global_private | project_public | project_private | agent_session | emergency_reconnect_archive | legacy-local-mapped
memory_type: fact | decision | procedure | risk | preference | hypothesis | evidence | deprecation | conflict
promotion_status: candidate | blocked | redacted | reviewed | published | superseded
durable_copy_location: private-audit://...
evidence_hash: sha256:...
source_claim_ids:
- claim-001
target_public_route: /reference/promotion-gates/
redaction_status: reviewed
reviewers:
- privacy
- source-owner
- publication-owner
public_safe_summary: "Generalized lesson, no private material."
non_claims:
- "No public runtime or automatic write support is implied."
Agent Behavior
- Assume private memory is source material, not public truth.
- Ask for the target public route and reviewer if the promotion intent is unclear.
- Stage a promotion packet instead of writing a reviewed public page directly.
- Rewrite as general guidance, not as a transcript or customer-specific incident report.
- Preserve uncertainty, contradictions, withheld details, and explicit non-claims.