Skip to main content

Dreaming

Dreaming maintains an agent’s durable memory from attributed evidence. It never changes the persona, grants itself tools, sends messages, or broadens an audience. The memory ledger and its revision-scoped permissions remain authoritative.

Cadence and eligibility

Per-agent defaults are a four-hour learning interval, a one-hour conversation quiet period, a daily lifecycle sweep, and a seven-day event grace period. Installation upgrades leave dreaming disabled until an operator enables it. Preview and automatic modes share the same planner and validation. Manual runs obey the quiet period, authorization, and budgets too. The learning interval is a minimum between passes over each conversation; initial eligible history can be processed immediately after enabling. The worker drains one bounded scope at a time, checks for work every minute, and never polls the model when there is no eligible evidence. Lifecycle eligibility is checked daily per conversation. Unchanged durable memories are revisited after 30 days; dated events are scheduled for their end plus the grace period when sooner. Only new, durably recorded messages are learning inputs. Receipt order, not a connector’s historical timestamp, controls checkpoints. A completed turn is not proof of a completed conversation or commitment. Pending intake and active runs make that conversation ineligible. A fixed snapshot is revalidated at commit; new activity defers the changes. Other quiet conversations remain eligible. Jobs have database-clock leases, bounded input/output, a wall-clock deadline, rolling token reservations, and a mutation allowance. Retries cannot apply an operation twice. A crash leaves a visible abandoned job; its checkpoint does not advance. Empty work requires no inference. Live work has priority.

Evidence and permissions

Each invocation belongs to one agent and one conversation audience, or to an independently registered public source. Eligibility precedes text hydration. Every exposed history message and memory revision contributes provenance, even if the model cites a smaller subset. Unknown sources cannot become public. Amendments preserve all earlier restrictions. Public memories with a private extension stay separate rather than making the public entry private. Public-source ingestion is a trusted operator API: an operator attests an exact document body and URL as public. Extraction runs with only that document and publicly sourced memories, never its requesting DM. This is also the integration boundary for future authenticated public-document adapters. An arbitrary tool result or a model’s sensitivity judgment is not public-source evidence. Sharing grants apply to immutable revisions. Changes to shared entries require review and explicit permission to release the replacement to the displayed audiences. The existing revision remains available while review is pending. Operator-authored or protected memories also require review. Review is an operator surface guarded by per-agent grants, not a private actor portal. A proposal from automatic mode can include a deferred privacy question. It remains pending, and the next verified one-to-one turn can offer the question only in its original conversation, to its original authenticated actor, with the same audience. Source eligibility is rechecked and the entire source provenance follows the question into the reply. Each question is offered to the turn model at most once; this is not a delivery acknowledgment. The worker itself never sends a message. The next turn can use an answer through the normal memory tools; sharing still requires the existing explicit revision-specific authorization flow. The original proposal remains in operator review until accepted or rejected.

Learning and lifecycle

The planner proposes create, amend, forget, or lifecycle-only review operations. An independent verification call checks support, lost negations/quantities, attribution, outcome claims, and whether user review is needed. Deterministic checks enforce source identity, scope, revision freshness, bounds, and lifecycle rules; a model’s confidence never changes permission. Ambiguous proposals remain in review. Old assistant claims are not independent corroboration. Lifecycle data records an event end, status, unresolved obligations, and a keep-details flag. Date passage never proves completion. Planned or uncertain events with unresolved work retain operational detail. Completed/cancelled events can be compacted after the grace period. Durable preferences do not expire. Current compact revisions serve ordinary retrieval; old detail remains auditable. No-op review does not refresh a memory’s evidential recency. Actor profiles use this same ledger. The planner attributes stated preferences and recurring communication-style observations to the evidenced participant, preserves uncertainty, and favors explicit corrections. Repeated behavior may support a tentative communication_style memory; a single sarcastic remark does not establish a permanent trait. Dreaming never chooses or replaces preferred names, which require a live, explicit answer. See actor profiles (repository). Explicit retirement suppresses re-learning from its original evidence. Dreaming does not erase the archive. Undo appends a compensating revision and preserves all restrictions learned since the original version; it never copies old grants.

Operation and implementation

Open an agent’s Memory → Manage dreaming page. Enable scheduled dreaming, adjust the four intervals and rolling daily budgets, or run a manual preview. Automatic mode applies supported changes and queues exceptions. Preview mode queues every change. Both record the source checkpoint so the same history is not repeatedly proposed. Operator approval rechecks original source permissions, retired evidence, memory revisions, and sharing grants under lock; later conversation activity alone does not invalidate an explicit approval. Automatic commits still require the original quiet, unchanged conversation. Review cards expose before/after text, source messages and memories, verification, privacy questions and sharing destinations. Undo appends a new memory revision only while the applied revision is still current. Lifecycle-only reviews do not create text revisions and have no text undo. Keep-full-details protection can be removed through the lifecycle API. internal/dreaming owns snapshot selection, planning, validation and mutation; internal/app/dreaming.go runs the worker after the HTTP listener starts. Migration 0088 adds receipt ordering, checkpoints, leases, jobs, proposals, public sources and lifecycle metadata. SQL remains in db/queries/dreaming.sql. Jobs do not use conversational runs, whose trigger/final-reply contract would misrepresent background maintenance. The configured heartbeat model falls back to the fast model and then the primary model. One job has a 120-second deadline, two model calls of at most 50 seconds, a 24 KB source snapshot, at most eight proposals, and a conservative 65,536-token reservation. Reported usage replaces that reservation; unknown usage retains it. Defaults allow 262,144 tokens and 50 changes per rolling 24 hours. One install-wide lease limits background inference to one job at a time. Agent disablement, the install-wide stop, or changes to settings invalidate in-flight jobs before the next call and before committing. A two-second ownership watch cancels inference already in flight, and the final transaction holds the install-stop fence and agent row until it commits. Failed sources retry after an hour; expired jobs remain visible as abandoned. An oversized single message fails visibly instead of silently truncating evidence. Jobs and proposal bodies contain private evidence and have the same agent-scoped operator access boundary and archive retention as memory revisions. They are not sent to public logs. Public-document extraction requires an authenticated operator’s attestation; automatic public-source adapters are not part of this implementation. The regression suite uses scripted models and real PostgreSQL. It tests source isolation, incremental processing, compaction safeguards, review/undo, concurrent activity, budget/lease loss, rollback and deferred questions. It does not establish a live model’s semantic accuracy; that remains dependent on the selected model.

Acceptance cases

  • Victor’s surprise-party DM and later balloon update remain unavailable to the coworker, public channels, other connector namespaces, and other agents.
  • A public Mesh document yields public facts without revealing its requesting DM.
  • New activity, a concurrent memory edit, disablement, or lost lease prevents a stale commit; a retried job cannot duplicate entries.
  • The event date alone cannot turn “planned” into “happened.” The seven-day grace, unresolved work, and keep-details controls survive cleanup.
  • Compaction preserves attribution, negations, quantities, and meaningful outcomes.
  • A revoked grant or forgotten source cannot be restored by summary or replay.
  • Operators can inspect sources, before/after text, verifier outcome, usage, review decisions, and compensating revisions.