/ sovereign agent harness

prism-mem — the portable brain.

The newest PRISM component. prism-mem gives any agent portable memory: curated project knowledge in signed AKF bundles — plain Markdown and KDL, no database, no vendor — injected into every Codex and Claude session at startup, plus operational Mnemos context for resuming live work. Your agent's knowledge becomes a file tree you own, not a row in somebody's cloud.

Status: merged to main on the forge, shipping with the next @prism/harness release after v1.0.0-rc.3. Installing @prism/harness gives you both CLIs: prism-harness and prism-mem.

Two kinds of memory — don't mix them

Every agent has two memory problems and most tools smash them into one blob. AKF (the Agentic Knowledge Format, standard v2.0.0 2026-09-26) splits them by purpose and authority:

Operational context — MnemosCurated knowledge — AKF
Material Chats, runs, task references, what tools exist right now Decisions and rationale, procedures, specs, selected evidence
Question it answers What is happening here, and what can this agent do? What has been established and deliberately preserved?
Authority The source system; Mnemos records observations ASM — the publication state machine
Transfer Separately authorized checkpoint The portable bundle — copy it, sign it, move it

The split is not about age. An old chat log stays operational forever; a brand-new design principle becomes knowledge the moment its publication policy is satisfied. Nothing auto-promotes from one domain to the other.

AKF: knowledge as a plain directory

An AKF bundle is UTF-8 text you can read with less and diff with git diff. KDL sidecars carry metadata for humans; JSON owner interfaces carry it for agents:

project-knowledge/
  _bundle.kdl                  ← bundle identity, standard version
  CONTEXT-RULE.md  _index.md  _changelog.md
  architecture/
    _index.md
    memory-boundary.md         ← the knowledge itself: Markdown prose
    memory-boundary.kdl        ← machine-readable sidecar
  procedures/
    _index.md
    recover-workspace.md       ← reusable procedures, step by step
  evidence/                    ← optional: selected supporting evidence
  _history/                    ← retained prior revisions — nothing is quietly rewritten
  _integrity/
    manifest.json              ← BLAKE3 digest over every page
    signatures/                ← detached signatures
  • No database required. The complete bundle is intelligible without Mnemos, a model provider, embeddings, or any special mount. Indexes are derived conveniences, never the only copy.
  • Revision history is part of the format. _history/ retains prior page revisions; publication preserves them immutably.
  • Integrity is part of the format. The manifest digest pins every page; detached signatures pin the manifest.
  • Disclosure is part of the format. Pages carry a private/team/public audience; a private page is never served to a team or public audience.

ASM: publication is an act of authority

Knowledge in AKF is not "saved" — it is published under the ASM state machine. A proposal produces an exact candidate; approval is for that exact revision; publication is atomic and immutable. Nightly curation may stage proposals, but scheduling grants no authority — only the owner's policy can publish.

And one honest boundary the spec is blunt about: a signature authenticates origin, it does not establish truth. Signed nonsense is still nonsense — provenance and correctness are separate checks, by design.

prism-mem: a strict wire, not a second engine

PRISM adapts harnesses to the two owner interfaces — it does not run its own memory engine or open the bundle itself. Mnemos (the reference owner from the JARVIS project) validates bundles, signatures, policy, trust, transfer, and ASM publication. prism-mem validates the request and response wire, then invokes the owner with literal arguments. No shell, no ambient trust:

$ prism-mem knowledge get --json \
    --config /absolute/brains.kdl --owner /absolute/mnemos < request.json

{ "schema_version": 1, "operation": "get", "request_id": "answer-1",
  "scope": { "realm_id": "local", "namespace": "project",
             "project_id": "demo", "disclosure": "private" },
  "input": { "brain": "atlas", "path": "answers/known.md",
             "max_bytes": 16384 } }

One JSON request on stdin, one JSON response on stdout. Envelopes are capped at 1 MiB; read budgets at 64 KiB; the owner call times out (default 3 s). Successful responses carry the pinned bundle ID, revision, BLAKE3 manifest digest, authentication:"verified", and per-page citations whose digests must agree — or prism-mem rejects them. Owner stderr is discarded; error detail is normalized so private policy paths cannot leak. Exit codes are fixed: 0 success, 2 invalid/budget, 3 denied, 4 unavailable.

SurfaceOperations
prism-mem knowledge — signed AKF status, get, search, pack, export, import, propose, publish
prism-mem context — Mnemos operational ingest, get, search, pack, status
prism-mem startup — session bindings install, hook, remove

Transfer is bundle-level: export writes a signed copy under the policy-configured root; import creates a fresh destination that grants no publication or execution rights. propose yields a candidate receipt — only the owner can publish it through ASM.

Every session starts with what you know

The payoff. One command binds a project to a signed brain; from then on, every new Codex or Claude session receives a bounded, cited knowledge packet through its SessionStart hook:

prism-mem startup install --provider codex \
  --project-root /absolute/project \
  --config /absolute/brains.kdl --brain handbook \
  --realm local --project demo --disclosure private \
  --owner /absolute/mnemos --runner /absolute/prism-mem

# removal preserves every hook that isn't ours:
prism-mem startup remove --provider codex --project-root /absolute/project
  • Verified on every startup. Mnemos re-checks the signature and enforces KDL policy each session — a tampered bundle or revoked trust yields a visible notice and no packet.
  • Bounded and honest. Defaults: 16 KiB packet, 20 pages, 1 s owner timeout. Overflow removes whole pages and says so — nothing is silently truncated or "token-estimated".
  • Never hostile. The hook never blocks a session, never captures chats, never requests continuation, and never publishes AKF.
  • A polite guest. Installation merges into .codex/hooks.json / .claude/settings.local.json, preserves unrelated handlers and settings, and is idempotent.

Context memory: resume across providers

The same CLI fronts Mnemos operational context. Codex burned a plan at 3am and died mid-refactor? SessionStart requests a project packet that is not filtered to the session that wrote it — Claude can pick up Codex's cited next step, and vice versa. The Stop hook captures the final assistant message as an explicitly partial record; every capture is labeled untrusted evidence, never live tool authority.

prism-mem vs prism-loop

Both say "memory" and they compose instead of competing. prism-loop is the self-contained file protocol: durable .prism/ run boundaries for overnight loops, no owner process needed. prism-mem is the owner-backed facade: signed AKF knowledge plus Mnemos context, shared across agents and machines. Loop remembers this project's runs; mem carries what you've established — anywhere.

Why this matters

Agent memory today is a lease: your accumulated project knowledge lives in a vendor's cloud, billed monthly, exportable only on their terms, gone when you leave. AKF inverts it. Knowledge is a directory of Markdown you can read, diff, sign, copy, and hand to any agent — Claude today, Codex tomorrow, whatever comes next after that. Provenance travels with the content; authority stays with you.

  • Portable — plain files; any reader, any host, any agent.
  • Authentic — BLAKE3 manifest, detached signatures, verified at every startup.
  • Governed — ASM publication with exact-candidate approval and immutable revisions.
  • Bounded — byte budgets and citations on every surface; no unbounded context stuffing.

Honest boundaries

  • prism-mem needs a local Mnemos owner binary — the reference implementation lives in the JARVIS project (mnemos akf CLI). Without an owner, knowledge commands report unavailable rather than pretending.
  • Startup install is Unix-only in this version; provider trust and hook approval still belong to the provider (Codex requires explicit approval of the exact hook command).
  • A signed snapshot is not live state: no process, tool, or capability is inferred from it. AKF procedure text is never an executable grant.
  • Unreleased until the next @prism/harness version is cut — today you build from main.

Install — one line All eight components Source on the forge ↗