MemoryStand

Evidence-gated memory for AI agents

checking…

CockroachDB AI Hackathon candidate

Memory that must prove it worked.

MemoryStand stops an AI agent from turning a lucky coincidence into permanent authority. A past fix can guide action only after outside evidence supports it.

Checking the live CockroachDB-backed demo…

A two-minute judge path

See the thesis in three clicks.

The default path hides setup and raw JSON. Each click tells you what happened and why it matters.

1

Load the incident

Read two competing memories: a closer restart story and a farther scale-up row whose service and receipt still need checking.

Expected: both remain inspectable.
2

Ask MemoryStand

Run the real /decide path. Only matching, receipt-backed evidence may steer; otherwise the fixed fallback is disclosed.

Expected policy: wrong-service proof refused.
3

Inspect the receipt

Open CockroachDB time travel for the recorded decision and preserve the exact ranked context.

Expected: auditable history · no overwrite.

Live product

Proof must match the service.

The seeded incident is designed to make dangerous evidence look relevant. Run it and verify what was eligible, excluded, and cited.

Payments latency incident

Read-only comparison first. One live decision only when you click.

live API
Expected closer memoryRestart · unconfirmed
Expected wrong-service rowVisible · excluded
Expected policyFallback disclosed

Loading the two decisive memories from the live deployment…

First, compare what is close with what is trusted. Then run the decision.

The trust ladder

Keep the memory. Limit its authority.

Disagreement is recorded instead of erased. A stronger receipt changes what may act, not what remains auditable.

unconfirmed

Stored, not trusted

No outcome receipt has been independently checked.

attested

Reported

An outcome was reported, but no system of record was re-queried.

verified

Externally checked

CloudWatch agreed on metric, direction, amount, and entity.

disputed

Contradicted

A rollback, false positive, or outside mismatch blocks authority.

How it works

One ledger. Three independent jobs.

The public demo uses the deployed API and CockroachDB Cloud. Detailed implementation notes stay available without crowding the judge path.

CR

CockroachDB ledger

Stores facts, sources, trust tiers, ranked retrieval receipts, and later decisions together. Time travel reconstructs what the agent knew.

CW

CloudWatch check

Metric-based promotion requires the external system of record to agree. A direction, amount, metric, or entity mismatch refuses the claim; non-metric reports cannot reach verified.

0

Model-free authority

A model may propose an action, but it does not promote its own memory. The authority path reports zero model calls.

Advanced workspace Manual ingest, outcome confirmation, time travel, raw JSON, and connection settings

Seeded demo tenant

Read a small live sample from the isolated public tenant. This route does not mutate data.

Checking for existing memories…

1Incident feed

Post a synthetic alert. The agent recalls what it knows, then records the action it took and why — every consulted memory is shown ranked by distance with its trust tier. Leave "Proposed action" blank. The seeded default alert is built so a closer unconfirmed restart cannot steer. A farther row also needs the same target service and a complete outcome receipt before it may enter decision context.

No decision posted yet.

2Memory admission

Submit a memory. Admission control checks it against what the agent already believes before it becomes recallable at all — the verdict, and why, is shown here.

No memory submitted yet.

3MemoryStand (outcome gate)

Report what actually happened. Memories that decision produced are promoted or demoted based on that outcome — never on a model's opinion of itself.

The trust ladder

unconfirmed

No outcome has been reported for this decision yet.

attested

An outcome was reported, but this deployment could not independently re-check it (no PagerDuty token; a human sign-off has no system of record to re-query).

verified

Re-queried against the external system of record (CloudWatch), which agreed.

disputed

The reported outcome was a rollback, a false positive, or the external system of record disagreed with the claim.

Verification is delayed by design: confirming an outcome moments after a decision often lands on unavailable because the "after" metric window is still in the future — that is expected behaviour, not a broken feature.

model calls on this path
0

By design, before any outcome is confirmed: this promotion path never asks a model anything. Confirm an outcome below and this updates from the real response.

No outcome confirmed yet.

4Cross-examine

Pick a decision. See exactly what the agent believed the moment it acted, next to what is true now — additions, removals, and changed trust tiers marked.

No decision cross-examined yet.