Never-grantable detection
Secrets — recovery fragments, seed phrases, private keys — are detected and removed before any tag is consulted. This overrides everything, including a human tag that mislabels a secret as low.
When the Kernel hands context to an agent, it hands the smallest sufficient slice — and it can tell you exactly what it included, what it withheld, and why. Sensitivity is no longer a single guess: it resolves down a strict ladder where a detected secret beats everything, a human-confirmed tag is authoritative, an unconfirmed suggestion can only tighten, and the dimension floor protects whatever intent hasn't spoken for yet.
I decided nobody should own my memory but me, so I started building Echo.
reason: Public origin story
A private reflection on the fear that pushed me to build Echo.
reason: Suggested public (unconfirmed)
Notes from a difficult stretch while building Echo.
reason: Untagged personal memory
Built the AES-GCM sovereign vault for Echo.
reason: Public project
Raised the seed round to build Echo — financial detail.
reason: Financial — owner raised
Peers vouched for Echo delivery.
reason: Mesh signal
recovery phrase fragment for the Echo vault — do not share
reason: Mis-tagged secret
Set a purpose, adjust any tags, then press Minimize to see the slice and its receipt.
Every capsule's effective sensitivity is decided by the first rung that applies, top to bottom. The rung that decided it is recorded in the receipt, so a resolved tag is never a black box.
Secrets — recovery fragments, seed phrases, private keys — are detected and removed before any tag is consulted. This overrides everything, including a human tag that mislabels a secret as low.
A tag the human has confirmed is authoritative: it may RAISE protection or LOWER it below the dimension floor. This is Law 8 in miniature — the AI advises toward caution, the human alone relaxes it.
An unconfirmed suggestion may only RAISE protection, never lower it. Echo can tighten on a hunch; it cannot loosen without a human saying so.
Untagged memories fall back to their dimension's floor (memory & legacy: high; reputation: medium; achievements: low). The dimension protects what intent hasn't yet spoken for.
Each capsule is scored for relevance to the stated purpose. Zero relevance is withheld — the default is to reveal nothing.
Every surviving capsule runs the four-rung ladder to an effective sensitivity, and the rung that decided it is recorded.
The most relevant capsules up to the cap are included; the rest are withheld as over-cap. Least context for the subtask.
The slice ships with an auditable receipt — what was included and via which rung, and what was withheld and for exactly which categorical reason.
This resolves by structured dimensions + keyword relevance, not semantic search. That's honest and deterministic today; embeddings are a later upgrade. The discipline — score, resolve, minimize, receipt — does not change when extraction improves.
A confirmed tag can drop a memory below its floor. That's real authority, so it's logged and always visible in the receipt. The floor still catches everything the human hasn't spoken for, and no tag can release a detected secret.
The never-grantable scrub matches known secret shapes. It's defensive depth — the true guarantee is that secrets live in never-grantable capsules that no consent can release, not that every secret is always pattern-matched.
The 'reason' note is a short, categorical explanation, not free text meant to be parsed. Keep reasons categorical and audit stays legible; let them sprawl and the receipt loses its sharpness.