← Runtime integrity sprint
Mechanism reportMemory boundaryAppend-oriented evidence

Journal provenance

What Kairo’s retrieval and context-injection receipts establish, where they fail closed, and why model-boundary exposure is not evidence of attention or causality.

Two records, two different events

journal_retrieval_eventsretrieval auditRecords how an audited foreground retrieval evaluated a candidate: query/hash, rank, eligibility, selection or withholding, algorithm/configuration, and job/candidate provenance.
journal_context_injectionsboundary receiptRecords that selected, non-withheld journal material was present in a bounded block at an identified final model-call boundary, with retrieval linkage, location, hash, size, and range.

The proven chain

Journal candidatetyped source + event identity
→
Retrieval decisionscore, eligibility, select/withhold
→
Durable retrieval receiptrequired before use
→
Bounded context blockselected, non-withheld only
→
Durable injection receiptmodel-call ID + exact block facts
→
Inference beginsafter confirmation

If required retrieval-audit creation fails, journal-derived context is withheld. If durable injection confirmation fails, the block is removed before inference. This is fail-closed behavior at the audited foreground path.

Non-implications

retrieval receipt ≠ injection receipt retrieval does not prove injection injection receipt = recorded model-call-boundary exposure boundary exposure ≠ attention boundary exposure ≠ semantic use boundary exposure ≠ response influence boundary exposure ≠ causality

An injection receipt proves more than “nothing”: it proves the recorded block reached the model-call boundary identified by the receipt. It proves nothing stronger about internal processing or the counterfactual cause of the response.

Missing rows remain ambiguous

A missing retrieval row does not prove that no memory existed and does not prove the audit path was never invoked. Depending on the route and failure point, absence may reflect a bypass, no candidates, a failure, or simply a lack of committed evidence. These tables are not universal logs of every memory or recall operation.

Unknown stays unknown. “There is no row” is an observation about committed provenance. It is not a license to manufacture the reason the row is absent.

Durability and exception boundary

The schema and endpoint behavior are append-oriented and guarded against ordinary mutation. A narrowly authenticated privacy-purge path is the documented exception; the public contract does not describe the tables as metaphysically immutable. Inspection surfaces expose recorded facts without upgrading them.

Capability projection

The first accurate prose description could disappear when compact conversation mode replaced the prompt. Journal-provenance questions were also not recognized by the topic detector. The fix introduced a typed capability contract and deterministic journal-topic recognition, then projects the facts after full/fast/compact selection. Compact replacement therefore cannot remove them. The 35B remains the exclusive foreground final voice; no 9B capability-answer fallback was introduced.

Regression questions cover direct table names, retrieval-versus-injection, attention/use/influence/causality, universality, and the exact prior failure: “no retrieval row” must remain insufficient evidence to establish why the row is absent.

Evidence and limits

None of these records proves phenomenal awareness or gives a direct measurement of model attention. They provide bounded operational provenance.