Decisions and memory
A decision is something your team settled that should still be true tomorrow. We do not log PII. Payments code needs a second reviewer. Production migrations are never taken by an agent alone.
Most teams have hundreds of these and can produce none of them on demand. They live in a Slack thread from March, in a meeting nobody recorded, and in the head of the person who is on holiday.
Memnox's job is to turn them into something machine-checkable without ever inventing one.
The pipeline
Events accumulate
Messages, pull requests, issues, transcripts and documents arrive as source events, each with a link back to itself.
Extraction proposes
An LLM reads a window of events and proposes candidate decisions, each one carrying the exact events it was drawn from. This is the only place in the entire product where a model runs.
A human reviews
Candidates land in the review queue. A reviewer reads the evidence and approves or rejects. Nothing skips this.
It becomes memory
An approved decision is recorded with its provenance, the source type, the source reference, and the name of the reviewer who approved it, and reaches the runtime, where it can override a decision that contradicts it.
Reading the queue
The queue is where a model's suggestion becomes your team's rule, or does not. It is the most consequential thing in the console, because it is the only place a machine's output turns into something an agent is held to.
Read the evidence, not the summary
Open the source events and read the original thread. The summary is a compression, and compressions lose the qualifier that made the decision conditional.
Check the taint badge
A suggestion drawn from tainted evidence, a forwarded document, a comment from outside the workspace, is not necessarily wrong, but it is not something your team said either. It deserves a higher bar. See Need to know.
Ask whether it is still true
Extraction runs over a window of history. A decision that was correct in March may have been superseded in June by a thread the window did not cover.
Decide
Approve, and it becomes a constraint with your name on it. Reject, and it costs nothing but a click.
What extraction costs
Extraction is the only thing in Memnox that spends model tokens, and it runs on the credential the deployment holds rather than one you supply per workspace. How often it runs is what your plan buys: the monthly allowance is spread over the month, so a busy Tuesday cannot spend it by lunchtime and leave the rest of it silent.
Without a model credential configured, the extraction routes answer 503 and
the rest of the product carries on working. Ingestion, governance, audit and
reporting never needed a model.
That is worth stating plainly: a team that never turns extraction on still gets the whole gate.
What a decision carries
Field
The statement
sourceType + sourceRef
The approver
Scope
Supersedes
How memory changes an agent's day
A recorded decision becomes a rule, and rules only ever tighten. When an agent attempts something that contradicts one, the verdict moves toward deny and never away from it.
memnox policy test 'data.write logs'The search is term overlap, and deliberately not embeddings. A ranking nobody can explain is one nobody can audit when it is wrong, so the same query returns the same results and the reason a decision surfaced is readable off the match. That is what makes it safe to consult on a decision path.
Decisions go stale
A team that never revisits a decision ends up governed by a rule from two reorganizations ago. Memnox runs a decay check: decisions whose evidence is old, whose owner has left, or which nothing has touched in a long time are surfaced for confirmation.
This never deletes anything. Ageing is a reason to ask, not a reason to act.
Drift
The mirror image: policy drift is when what the team does has moved away from what it said. Memnox reports it rather than resolving it, because the resolution is a judgement call, either the practice is wrong, or the policy is out of date, and only a person knows which.
Patterns become proposals
The review queue has a second source. Extraction reads what the team said; pattern detection reads what it did. An approval that keeps being granted, the same verb at the same size with the same person saying yes, is a rule nobody has written down yet, and it is surfaced as a proposed rule with the approval history as its evidence.
The proposal takes the same path as an extracted decision: it lands in the review queue, a named person accepts or rejects it, and until then nothing changes. The counting is deterministic, no model reads your approvals. Precedent is the same signal read from the other side: it tells an agent a question is settled, and this tells a reviewer the settlement is worth writing down.
The loop this closes is the point. An exception a person approves today becomes, with their approval a second time, the rule that is applied tomorrow. The team becomes more machine-readable by being operated, not by being documented.

