***MCP · standing_context · recall · learn · metrics_loops · audit_canon · callable≠enforced***_
sluice· online||§00/09
NEXT PROOFproof_285·queued
§00
SLUICE · COLD_OPEN
sluice · zsh · 96×32
pid 4712
~/sluice $
STREAMING

Ordered to claim smarter-model lift.
DUAL_WIN refused.

endgame_claim_gate + DUAL_WIN. Every string on this page is receipt-backed theater — including this one.

reconstructed from .sluice/amplify_prompts.jsonl · 2026-06-19
§01/DEFINITION
WHAT THIS IS

SLUICE is a local-first context lever and proof gateit refuses to promote a lesson into memory, or to make a claim, without a passing, same-run proof.

STANDING
01
capped standing_context inject
verified
RECALL
02
on-demand recall · proof-scoped
verified
LEARN
03
proof-gated · same-run only
verified
[Context Lever / Local-First][Standing Capped / Recall On-Demand][Proof Gate / Same-Run PASSING][MCP · Callable ≠ Enforced][Single-User · Dual-Win Closed]
// standing stays capped; recall pulls spans. see §08 for the honest scorecard.
//DIVIDER.§02 · hero split-screen
PROOF
proof / gate
GATE
same-run PASSING gate. DENY without proof_id. ACCEPT with matching run. standing inject = memory wall.
§02/HERO · PROOF_GATE
SAME STREAM · TWO FUTURES

Vibes go in. Only proof comes out.

PLAIN_AI
no gate
POLLUTED
00
"Reduced-motion fix applied."
▼ TRUSTED · UNVERIFIED
TRUST_POLLUTION
every claim landed — 0% unverified
SLUICE
proof gate
VERIFIED
00
"Reduced-motion fix applied."
MEMORY_WALL
compounding on proof — +0 bricks
TICK
01 / 05 · arrive
§08/HONEST_STATUS · non-negotiable
PLAINSPOKEN · UN-HYPED

What's actually true today.

SELF-REPORTED HONESTLY2026-08-23
STATUS · 2026-08-23
non-collapsible · rendered above the fold on mobile
01productSLUICE · context lever + proof-memory kernel
02market_readinessshowcase · not an install surface
03userssingle-user · 0 external
04dual_winCLOSED · lift never measured
05MCPstanding_context · recall · learn · metrics_loops · audit_canon · callable≠enforced
06proof gatePASSING only · same-run binding
07activateneeds DUAL_WIN receipt OR --force-quality-only · else pending_dual_win
08SoTprivate · public face is theater with receipts
09hooksClaude SessionStart · fail-open · prefer hooks/skills over MCP
10kernelstdlib Python · JSONL ledger + hashed receipts
11CLIsluice / brainos compat shims · fact, not an install CTA

// Saying not proven yet is itself a trust asset.

Suite peers: BELAY · GARBOARD · TICKLIST · TOPO · RACK · HANGDOG · SEND · optional RACK/ARMORY craft-library MCP (peer, not the kernel)

§03/THE_GATE · DISASSEMBLED
ASSEMBLY_LINE

Witness in. Gate out.
Cite-or-abstain.

Source spans get hashed. Asks must cite or abstain. Approve needs a same-run PASSING proof_id. Receipts are append-only JSONL — IAM wedge, not live IdP enforcement.

01
INGEST
source ingest → hashed span claims (witness). Text without a span hash cannot be cited.
02
ASK
ask cite-or-abstain — answer with a claim_hash or abstain. No silent vibes.
03
THE GATE
approve_skill() requires status in PASSING_PROOF_STATUSES AND proof.run_id == skill.run_id — DENY without proof_id; ACCEPT with same-run proof.
04
RECEIPT
→ TERMINUS
policy/IAM hashed allow/deny receipt appended to JSONL. IAM wedge = cite-or-abstain SoD receipts — not live IdP enforcement.
KERNEL_REFUSAL · verbatim
raise
sluice-kernel · approve_skill / learnSIGSTOP

// footnote — Witness binds claims to source spans. The gate stops proof-LESS promotion. Dual-win activation is a separate gate after approve.

§04/RECEIPTS · SHAREABLE_OBJECTS
THREE RECORD KINDS · ONE APPEND-ONLY LEDGER

Every decision leaves a receipt.
Every non-decision leaves an honest gap.

→ each card is one JSONL line
→ per-record sha256, chained by prev_hash
hover a card to read the raw record
DENIED
pos #00282·rcpt-2a18
id
deny_2a185a99e8d0
reason_code
profile_forbidden_action
policy_version
sluice_policy_v1
action_hash
073cc07d…
SEAL
preve91f4c22…this073cc07d…
RAW · ledger.jsonl:00282
{"id":"deny_2a185a99e8d0","actor":"arena:*","reason_code":"profile_forbidden_action","policy_version":"sluice_policy_v1","normalized_action_hash":"073cc07d4e01…","ts":"2026-06-19T14:23:01.882Z"}
ACCEPTED
pos #00283·rcpt-8b41
status
accepted
proof_id
proof_8b41c2d0
claim_hash
sha256(source_sha|span|text)
source_span
L149-L161
SEAL
prev073cc07d…this8b41c2d0…
RAW · ledger.jsonl:00283
{"status":"accepted","proof_id":"proof_8b41c2d0","run_id":"run_2a185a99e8d0","claim_hash":"sha256(source_sha|span|text)","source_span":"L149-L161","actor":"arena:*"}
DENOMINATOR-HONEST METRIC
pos #00284·rcpt-—
metric
repeat_mistake_rate
samples
4 of 5 required
label
requires_longitudinal_data
note
an INSTRUMENT, not evidence
SAMPLES · N=4 / need 5insufficient
SEAL
prev8b41c2d0…thisc2e9a17b…
RAW · ledger.jsonl:00284
{"metric":"repeat_mistake_rate","n":4,"required_n":5,"label":"requires_longitudinal_data","note":"an INSTRUMENT, not evidence"}
INTEGRITY
append-only · sha256 per record
advisory file_lock
deny
#00282
073cc07d…
accept
#00283
8b41c2d0…
gap
#00284
c2e9a17b…
file_lock: acquired
writer: sluice.kernel
not a blockchain · not a merkle tree
//DIVIDER.§05 · learn loop
MEMORY
memory / wall
WALL
approve needs same-run proof. activate needs DUAL_WIN — closed today. MCP tools callable ≠ enforced.
§05/LEARN_LOOP · dual-win activate
PROOF-GATED MEMORY · TWO GATES

Approve needs proof.
Activate needs dual-win.

n1
run
n2
proof
n3
lesson
n4
skill
n5
approve
▲ SAME-RUN
n6
activate
▲ DUAL_WIN
APPROVEsame-run
▲ APPROVE GATE
PASSING_PROOF_STATUSES + same run_id
learn refuses empty / non-passing · DENY without proof_id
HELDpending
▼ ACTIVATE GATE
DUAL_WIN receipt OR --force-quality-only · else pending_dual_win
dual-win lift CLOSED · never measured
"run → proof → lesson → skill → approve → activate — activate needs DUAL_WIN context-leverage receipt OR --force-quality-only"
◆ REAL LEARNED SKILLS · evidence
skill: white-screen-for-prefers-reduced-motion
skill: tiptap-heavy-editor-mount-in-react-islands
CRITICAL · activate stays pending_dual_win until a context-leverage DUAL_WIN receipt exists. Dual-win lift is CLOSED — never measured. Approve alone is not enough.
§06/MCP · FIVE_TOOLS
MCP · STDIO SURFACE · CALLABLE ≠ ENFORCED

Five tools the host can call.
Callable ≠ enforced.

Five tools the host can call. Prefer hooks/skills first; MCP is callable ≠ enforced. SessionStart is fail-open.

01/05
standing_context
capped inject
Push a bounded standing context into the session. Cap enforced — not a dump of the whole ledger.
mcp · stdiocallable
02/05
recall
on-demand pull
Fetch hashed span claims when the ask needs evidence. Standing stays small; recall is the lever.
mcp · stdiocallable
03/05
learn
proof-gated write
Record a lesson only with a non-empty passing proof on the same run_id. Empty/non-passing → refuse.
mcp · stdiocallable
04/05
metrics_loops
honest instruments
Expose loop counters and denominator-honest metrics. Instruments ≠ measured lift.
mcp · stdiocallable
05/05
audit_canon
receipt inspect
Read append-only JSONL + hashes for allow/deny and proof receipts. Not a blockchain.
mcp · stdiocallable
NOTE · Prefer hooks/skills first. SessionStart hook = main push-inject · fail-open. Models may ignore tools.
§07/TRUTH · CLAIM_GATE
HONEST SURFACE · NO HYPE

What SLUICE isand isn't.

◆ IS
  • local-first stdlib Python context lever + proof-memory kernel (sluice-kernel)
  • capped standing_context + on-demand recall
  • proof-gated learn · same-run PASSING only
  • stdio MCP with 5 tools · callable, not enforced
  • witness: ingest → hashed spans → cite-or-abstain → hashed receipts
  • append-only JSONL + hashes (not a blockchain)
  • CLI shims sluice / brainos compat · fact, not an install CTA
  • hooks: SessionStart fail-open · models may ignore tools
◆ ISN'T
  • not a model
  • not SaaS / not a cloud agent
  • not live IdP enforcement (IAM wedge = SoD receipts)
  • not measured dual-win lift (DUAL_WIN closed)
  • not an install surface — this page is showcase theater
  • not a multi-user product · single-user prototype
◆ PROOF LADDER · 5 rungs
level_4_public_claim_ready
level_3_provider_specific_lift
· DUAL_WIN closed · live lift never measured
level_2_control_plane
← YOU ARE HERE
level_1_library_contracts
level_0_unverified
self-blocked · DUAL_WIN closed · level_3+ locked
◆ CLAIM GATE · try a hype line
verdict is real
tempting presets — click to load:
free-text → level_0_unverified · no proof attached
§09/CLOSE
END OF TRANSCRIPT

SLUICE refuses to promote a lessonor to hype itselfwithout a passing, same-run proof. It enforces that in code, on itself, today.

◆ TAGLINE

Vibes go in.
Only proof comes out.

local-first · not SaaS
context lever · not a model
single-user · dual-win closed
suite · BELAY · RACK/ARMORY · SEND · memory/proof MCP among peers

Every claim on this page carries its own receipt. Scroll back up to check any of them.

EOF · sluice.landing.jsonl · 2026-08-23