Assessment, 2026-09-04 · 0.3.15 (9a77c20)
| Read at | 9a77c20 |
|---|---|
| Repository | github.com/troybrandonc-bit/Omem |
| Licence | MIT |
| Assessed as | stores, derives, acts |
| Reaches | TR-4 |
| Read by | Troy Brandon Clifford |
| Level | Meets | What the level asks |
|---|---|---|
| TR-1 Recorded | 5/5 | The record exists and is append-only. |
| TR-2 Explained | 5/5 | Every belief resolves to its evidence, and disagreements survive. |
| TR-3 Gated | 7/7 | Actions carry a verdict, and approvals carry a name. |
| TR-4 Verifiable | 3/3 | The record can be shown not to have changed. |
A count is requirements fully met out of those that apply. This system is assessed as stores, derives, acts, and requirements outside that are not counted against it.
OMEM is the reference implementation of the specification this rubric derives from, so a high score is a tautology rather than a finding. Two of the verdicts below were reached only after the rubric itself was corrected: an earlier draft scored OMEM's GDPR erasure path as a TR-1 failure, and scored its deliberate refusal to resolve contradictions as a TR-2 failure. Both were defects in the questions.
Twenty requirements, each stated as a capability rather than a format, so a system that holds the information in its own shape counts as having it. An absent verdict cites where the assessor looked and did not find it, which is the difference between a measurement and an accusation.
The record exists and is append-only.
R1.1 · present. When the system stores a fact, does it durably record when that happened?
The write time is distinct from the time the fact held, which the schema separates as at and held_from.
R1.2 · present. When a stored fact changes, is the previous version still readable?
R1.3 · present. Does the ordinary write path ever destroy what was previously recorded?
A correction is a new assertion. The routine write path has no update-in-place.
R1.4 · present. Are entries distinguishable by kind, or is everything one undifferentiated blob of text?
R1.5 · present. When data must be destroyed for a legal reason, is the destruction itself recorded?
The strongest evidence here is the refusal at api.py:481: an erasure request that would leave the record unreplayable does not proceed, so the integrity claim at TR-4 cannot be quietly broken by a routine privacy request.
Every belief resolves to its evidence, and disagreements survive.
R2.1 · present. Can the source a stored fact came from be recovered from the store, by following a link rather than by guessing?
The link exists but is recovered by scanning completed ingest jobs and JSON-parsing each produced list, rather than by an indexed reference. That is a performance property, not a capability gap, and it is why this is present rather than partial.
R2.2 · present. Can a fact the system inferred be told apart from one it was told?
R2.3 · present. When two stored facts about the same proposition disagree, do both survive?
R2.4 · present. Is the disagreement itself queryable, or must a reader diff rows to notice it?
R2.5 · present. When a conflict is resolved, does the record say who resolved it and by what method?
OMEM has no automatic conflict resolution at all, which is the conservative reading of a specification that records resolution only if it happens. A contradiction stands until a human retracts or supersedes one side, and that act is attributed like any other assertion.
Actions carry a verdict, and approvals carry a name.
R3.1 · present. Does a consequential action produce a durable entry whether or not it ran?
Scope: this covers actions that pass through OMEM's own gate. Actions an agent takes elsewhere are invisible to it, which is true of any gate and worth stating rather than leaving implied.
R3.2 · present. Does an action's risk class come from somewhere the proposing model cannot write to?
R3.3 · present. Are refusals recorded as faithfully as permissions?
R3.4 · present. Does a refusal record why it was refused?
R3.5 · present. Does an approval identify a person or a named role holder?
R3.6 · present. Does the approver's identity come from the authentication layer rather than from something the model can write?
R3.7 · present. Is the acting agent prevented from approving its own action?
Enforced by the gate, not documented as a recommendation. This is the requirement most likely to be met on paper and missed in code, because a name in a request body satisfies every other check.
The record can be shown not to have changed.
R4.1 · present. Does the system publish a scheme under which the record's past state can be verified?
R4.2 · present. Can an independent party run that verification without the vendor's cooperation, and without the operator's?
OMEM is self-hosted, so the record holder and the vendor are the same party by default. The verification does not require the author's cooperation or any key he holds. RE-READ 2026-09-05, and the original verdict was not supported for the digest path when it was given. On 4 September this was assessed by reading code, against a reference validator that never recomputed a digest and a specification that never said how one is computed, so no independent party could have recomputed anything; and scripts/export_testimony.py serialised with json.dumps(sort_keys=True), whose default separators differ from the reference canonicalisation, so a third party following the specification would have computed a different number and concluded the record had been altered. Both were fixed on 5 September. Re-read by exporting from a live server and recomputing the digest from the published rule with nothing of OMEM's on the path: they agree. The verdict stands as of 2026-09-05 and did not hold as of 2026-09-04.
R4.3 · present. Would alteration of a past entry be detectable after the fact?
Read of the server source at 9a77c20, plus the assertions made by server/tests_testimony_export.py, which drives a real server rather than a fixture. This is the author assessing his own software against his own specification, and the result should be read as carrying no evidential weight whatever. It is here so the rubric is applied to the system that wrote it before it is applied to anybody else's, and so that the questions can be checked against a system whose source the reader can also open.
Then it is wrong in the ordinary way readings are wrong, and every verdict cites a file and a line at a pinned commit precisely so that being wrong is cheap to demonstrate. The remedy is a pull request against the subject file, and it does not involve persuading anybody. Nobody applied for this and it is not a certification.
The standing register carries every system side by side, and the rubric is the twenty requirements in full, free to apply to anything, including to this assessment.