Trust-anchor consensus
Shipped in v3-alpha (Beta). Fourth zero-LLM feature — replaces “ask the LLM which fact is right” with a deterministic protocol. Interfaces may still change before 3.0 stable.
The pattern it eliminates
Today, when two facts disagree, the cheap path is “ask the LLM which is correct.” That’s 500–1000 tokens per conflict. v3 resolves the unambiguous cases (~90% of conflicts) with deterministic rules and queues the genuinely ambiguous ones for humans.
Trust anchor hierarchy
// Immutable priority order — higher = more trusted
const TRUST_ANCHORS = {
codebase_verified: 100, // verified against actual code/config
user_stated: 90, // user explicitly said this
user_confirmed: 85, // user confirmed when asked
api_response: 80, // from authoritative API (GitHub, Stripe)
document_extracted: 70, // from official docs
agent_observed: 60, // agent saw it happen (tool output)
agent_inferred: 40, // agent concluded via reasoning
llm_generated: 30, // LLM extraction, no user confirmation
federation_received: 20, // from a peer (untrusted by default)
} as const;Deterministic protocol
function resolveConflict(local: MnemoFact, incoming: MnemoFact): ConflictVerdict {
// Rule 1: higher trust anchor wins
if (TRUST_ANCHORS[local.attribution] !== TRUST_ANCHORS[incoming.attribution]) {
const winner = TRUST_ANCHORS[local.attribution] > TRUST_ANCHORS[incoming.attribution]
? "local" : "incoming";
return { winner, reason: "trust_anchor", confidence: 0.9 };
}
// Rule 2: same trust → more recent wins
if (local.attribution === incoming.attribution) {
const winner = local.validFrom > incoming.validFrom ? "local" : "incoming";
return { winner, reason: "recency", confidence: 0.7 };
}
// Rule 3: higher memory worth wins
if (Math.abs(local.worth - incoming.worth) > 0.2) {
const winner = local.worth > incoming.worth ? "local" : "incoming";
return { winner, reason: "worth", confidence: 0.6 };
}
// Rule 4: undecided → human review queue
return { winner: "undecided", reason: "ambiguous", confidence: 0 };
}Federation voting (multi-instance)
When federated peers disagree:
interface FederationVote {
instanceId: string;
factVersion: string;
trustAnchor: string;
worth: number;
freshness: Date;
weight: number; // trust_anchor × worth × freshness_decay
}
function federatedConsensus(votes: FederationVote[]): ConsensusResult {
const groups = groupBy(votes, v => v.factVersion);
const scores = Object.entries(groups).map(([version, voteGroup]) => ({
version,
totalWeight: sum(voteGroup.map(v => v.weight)),
}));
const totalWeight = sum(scores.map(s => s.totalWeight));
// Supermajority: winner needs >66% of total weight
const winner = scores.find(s => s.totalWeight / totalWeight > 0.66);
if (winner) return { status: "consensus", adoptedVersion: winner.version };
// No supermajority → preserve both as "contested"
return { status: "contested", versions: scores.map(s => s.version) };
}ROI
Without consensus:
Conflict → LLM judge → ~500–1000 tokens
With consensus:
Conflict → deterministic rule → 0 tokens, ~1ms
At scale: 20 conflicts/week × 750 tokens = 15,000 tokens/week saved
~90% auto-resolved; ~10% queued for human review (better than guessing)See also
- Federation protocol — multi-instance use
- Memory Worth — input to Rule 3
- Zero-LLM features — the family