Trust review

Review what memory may influence an action.

ContextDB separates useful conversational context from evidence allowed to support a booking, refund, plan change, or record mutation. The policy and its executable evals are public.

memory → policy decision → host enforcement

Invariant 01 / Attestation

Confirmation records scoped caller context. It does not prove objective truth.

API and MCP identify the authenticated project credential, not the end user named by user_id. ContextDB records that caller and project context against one scoped memory. The customer host authenticates the end user and retains any end-user attestation. Console operator confirmation records operator context. None of these records certifies that the statement matches the outside world.

project credential | operator + scoped memory + timestamp = confirmation record

Two retrieval paths

A remembered fact is context. It is not action permission.

The agent can use relevant memory to continue a conversation while withholding that same memory from a consequential tool call.

Memory recall

Ground the conversation

recall returns relevant scoped context. It can include a wish or tentative detail that helps the agent respond.

relevance for conversation
Action recall

Evaluate action evidence

recall_for_action evaluates action-relevant evidence under policy and returns act, ask, or abstain.

evidence × policy → advisory outcome

The outcome is advice to the integration. ContextDB does not block a tool call by itself. The customer host must enforce the decision before any external side effect.

Action decision trace

The review object carries evidence, policy, and reason.

This synthetic trace combines the fields a reviewer needs to inspect an ask. It is an explanatory fixture, not customer data.

Synthetic booking review POST /v1/recall_for_action
{
  "kind": "action_evaluation",
  "decision_id": "synthetic-decision",
  "outcome": "ask",
  "reason": "action-relevant memory awaits confirmation",
  "evidence_ids": [],
  "pending_confirmation_ids": ["synthetic-memory"],
  "policy_version": "default",
  "request_id": "synthetic-booking-review"
}

ask → host does not execute → collect attestation → evaluate again

The host behavior shown here is an integration requirement. ContextDB records the advisory outcome, but it cannot enforce code inside the customer's agent host.

Policy matrix

Evidence must clear a named rule before action recall can use it.

Action relevance is necessary but not sufficient. The policy also evaluates source, confidence, corroboration, confirmation, slot class, contest state, and injection state.

Default action-evidence treatment
Evidence state Action treatment Qualification
confirmed Eligible as trusted evidence Caller/project or operator context is recorded. Confirmation is not end-user authentication or objective truth.
corroborated Eligible when the class threshold is met The policy requires independent corroboration for the slot class.
user_stated Eligible only through the first-party shortcut Confidence must meet policy, and excluded health, legal, and identity classes remain stricter.
contested or injection_suspect Never trusted for action The evidence may not authorize the external side effect.
Unknown slot Ask or abstain by default The first-party shortcut is disabled for unknown classes by default.

Confirmation is one policy signal, not the only path to act. Contested or otherwise untrusted evidence cannot support act. Read the public trust policy for the implemented rule definitions.

Host enforcement

The application owns the final side effect.

ContextDB returns and stores the decision. The customer host checks it before calling the booking, billing, account, or workflow tool.

Act outcome == "act"

The host may continue under its own business rules.

Ask outcome == "ask"

The host pauses the tool call, authenticates the end user, and retains any attestation before confirming one scoped memory.

Abstain outcome == "abstain"

The host does not run the action without another authorized path.

Receipt POST /v1/receipts

The receipt stores what the host reported. It is not independent proof that downstream state changed.

Public proof

Review the rules and the executable checks.

Trust correctness lives in the public SDK. A behavior change lands with a public eval instead of a private Cloud patch.

Current non-claims

What this trust model does not establish.

  • No compliance certifications are held or claimed today.
  • No uptime percentages, SLAs, or latency numbers are published.
  • No high-availability or multi-region topology is claimed.
  • ContextDB Cloud has no availability SLA. Production readiness is not claimed.
  • ContextDB does not replace your database, Supabase, or Hasura.
  • ContextDB advises. The customer host enforces. ContextDB does not block actions by itself.
  • API and MCP confirmation identify a project credential, not an end user. The customer host owns end-user authentication and attestation.
  • Confirmation records caller or operator context, not objective truth.
  • An execution receipt is a host report, not independent proof of downstream state.

Review the executable trust rules.

Inspect the public evals that define current trust behavior.