> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mesh.texturehq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Dreaming

# Dreaming

Dreaming maintains an agent's durable memory from attributed evidence. It never
changes the persona, grants itself tools, sends messages, or broadens an audience.
The memory ledger and its revision-scoped permissions remain authoritative.

## Cadence and eligibility

Per-agent defaults are a four-hour learning interval, a one-hour conversation
quiet period, a daily lifecycle sweep, and a seven-day event grace period.
Installation upgrades leave dreaming disabled until an operator enables it.
Preview and automatic modes share the same planner and validation. Manual runs
obey the quiet period, authorization, and budgets too.

The learning interval is a minimum between passes over each conversation;
initial eligible history can be processed immediately after enabling. The worker
drains one bounded scope at a time, checks for work every minute, and never polls
the model when there is no eligible evidence. Lifecycle eligibility is checked
daily per conversation. Unchanged durable memories are revisited after 30 days;
dated events are scheduled for their end plus the grace period when sooner.

Only new, durably recorded messages are learning inputs. Receipt order, not a
connector's historical timestamp, controls checkpoints. A completed turn is not
proof of a completed conversation or commitment. Pending intake and active runs
make that conversation ineligible. A fixed snapshot is revalidated at commit;
new activity defers the changes. Other quiet conversations remain eligible.

Jobs have database-clock leases, bounded input/output, a wall-clock deadline,
rolling token reservations, and a mutation allowance. Retries cannot apply an
operation twice. A crash leaves a visible abandoned job; its checkpoint does not
advance. Empty work requires no inference. Live work has priority.

## Evidence and permissions

Each invocation belongs to one agent and one conversation audience, or to an
independently registered public source. Eligibility precedes text hydration.
Every exposed history message and memory revision contributes provenance, even
if the model cites a smaller subset. Unknown sources cannot become public.
Amendments preserve all earlier restrictions. Public memories with a private
extension stay separate rather than making the public entry private.

Public-source ingestion is a trusted operator API: an operator attests an exact
document body and URL as public. Extraction runs with only that document and
publicly sourced memories, never its requesting DM. This is also the integration
boundary for future authenticated public-document adapters. An arbitrary tool
result or a model's sensitivity judgment is not public-source evidence.

Sharing grants apply to immutable revisions. Changes to shared entries require
review and explicit permission to release the replacement to the displayed
audiences. The existing revision remains available while review is pending.
Operator-authored or protected memories also require review. Review is an
operator surface guarded by per-agent grants, not a private actor portal.

A proposal from automatic mode can include a deferred privacy question. It remains pending, and the
next verified one-to-one turn can offer the question only in its original
conversation, to its original authenticated actor, with the same audience.
Source eligibility is rechecked and the entire source provenance follows the
question into the reply. Each question is offered to the turn model at most once;
this is not a delivery acknowledgment. The worker itself never sends a message.
The next turn can use an answer through the normal memory tools; sharing still
requires the existing explicit revision-specific authorization flow. The original
proposal remains in operator review until accepted or rejected.

## Learning and lifecycle

The planner proposes create, amend, forget, or lifecycle-only review operations.
An independent verification call checks support, lost negations/quantities,
attribution, outcome claims, and whether user review is needed. Deterministic
checks enforce source identity, scope, revision freshness, bounds, and lifecycle
rules; a model's confidence never changes permission. Ambiguous proposals remain
in review. Old assistant claims are not independent corroboration.

Lifecycle data records an event end, status, unresolved obligations, and a
keep-details flag. Date passage never proves completion. Planned or uncertain
events with unresolved work retain operational detail. Completed/cancelled events
can be compacted after the grace period. Durable preferences do not expire.
Current compact revisions serve ordinary retrieval; old detail remains auditable.
No-op review does not refresh a memory's evidential recency.

Actor profiles use this same ledger. The planner attributes stated preferences
and recurring communication-style observations to the evidenced participant,
preserves uncertainty, and favors explicit corrections. Repeated behavior may
support a tentative `communication_style` memory; a single sarcastic remark does
not establish a permanent trait. Dreaming never chooses or replaces preferred
names, which require a live, explicit answer. See [actor profiles (repository)](https://github.com/TextureHQ/mesh/blob/main/docs/runtime/actor-profiles.md).

Explicit retirement suppresses re-learning from its original evidence. Dreaming
does not erase the archive. Undo appends a compensating revision and preserves
all restrictions learned since the original version; it never copies old grants.

## Operation and implementation

Open an agent's **Memory → Manage dreaming** page. Enable scheduled dreaming,
adjust the four intervals and rolling daily budgets, or run a manual preview.
Automatic mode applies supported changes and queues exceptions. Preview mode
queues every change. Both record the source checkpoint so the same history is
not repeatedly proposed. Operator approval rechecks original source permissions,
retired evidence, memory revisions, and sharing grants under lock; later conversation
activity alone does not invalidate an explicit approval. Automatic commits still
require the original quiet, unchanged conversation.
Review cards expose before/after text, source messages and memories, verification,
privacy questions and sharing destinations. Undo appends a new memory revision
only while the applied revision is still current. Lifecycle-only reviews do not
create text revisions and have no text undo. Keep-full-details protection can be
removed through the lifecycle API.

`internal/dreaming` owns snapshot selection, planning, validation and mutation;
`internal/app/dreaming.go` runs the worker after the HTTP listener starts.
Migration `0088` adds receipt ordering, checkpoints, leases, jobs, proposals,
public sources and lifecycle metadata. SQL remains in `db/queries/dreaming.sql`.
Jobs do not use conversational runs, whose trigger/final-reply contract would
misrepresent background maintenance.

The configured heartbeat model falls back to the fast model and then the primary
model. One job has a 120-second deadline, two model calls of at most 50 seconds,
a 24 KB source snapshot, at most eight proposals, and a conservative 65,536-token
reservation. Reported usage replaces that reservation; unknown usage retains it.
Defaults allow 262,144 tokens and 50 changes per rolling 24 hours. One install-wide
lease limits background inference to one job at a time. Agent disablement, the install-wide stop, or changes to
settings invalidate in-flight jobs before the next call and before committing.
A two-second ownership watch cancels inference already in flight, and the final
transaction holds the install-stop fence and agent row until it commits.
Failed sources retry after an hour; expired jobs remain visible as abandoned.
An oversized single message fails visibly instead of silently truncating evidence.

Jobs and proposal bodies contain private evidence and have the same agent-scoped operator
access boundary and archive retention as memory revisions. They are not sent to
public logs. Public-document extraction requires an authenticated operator's
attestation; automatic public-source adapters are not part of this implementation.

The regression suite uses scripted models and real PostgreSQL. It tests source
isolation, incremental processing, compaction safeguards, review/undo, concurrent
activity, budget/lease loss, rollback and deferred questions. It does not establish
a live model's semantic accuracy; that remains dependent on the selected model.

## Acceptance cases

* Victor's surprise-party DM and later balloon update remain unavailable to the
  coworker, public channels, other connector namespaces, and other agents.
* A public Mesh document yields public facts without revealing its requesting DM.
* New activity, a concurrent memory edit, disablement, or lost lease prevents a
  stale commit; a retried job cannot duplicate entries.
* The event date alone cannot turn “planned” into “happened.” The seven-day grace,
  unresolved work, and keep-details controls survive cleanup.
* Compaction preserves attribution, negations, quantities, and meaningful outcomes.
* A revoked grant or forgotten source cannot be restored by summary or replay.
* Operators can inspect sources, before/after text, verifier outcome, usage,
  review decisions, and compensating revisions.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.