Clean, value-ranked recall
Retrieval ordered by earned value, not just recency or cosine. A write-admission gate (admit) rejects junk and near-duplicates before they bloat the store, and why_recalled shows exactly why a memory surfaced.
Correction, erasure & time-travel
A first-class channel: revert, retract_lineage, echo_guard, forget_subject. And a read-path review trigger — observe() reopens a settled fact on a corroborated contradiction, recall marks it under_review so the agent can hedge, and a steward resolves it. Bitemporal as_of reconstructs what the agent believed at any moment.
Tamper-evident receipts
Every write is hash-chained. verify_writes and anchor catch a history rewrite by a key-holder.
Poison-resistant influence
Corroboration-gated influence with recall(influence_only=True) so one laundered write can't dominate the answer. credit_requires_warrant closes the self-graded loop (a memory can't vouch for itself), and grounds can be Ed25519-signed so forged corroboration counts zero.
Cross-store erasure audit
DeletionManifest plus ErasureAuditor: an adversarial check that erased content isn't reconstructible across the fan-out — including the soft-delete residue a 200 OK leaves in Qdrant, pgvector, and S3.
Adapters & multi-tenancy
Adapters for OpenAI Agents, AutoGen, LangGraph, LangChain, LlamaIndex, CrewAI, Haystack, Google ADK, and Pydantic AI — 13 of 13 verified against current upstream, 0 recorded broken, counts published in docs/integration_conformance.json rather than implied. Fail-closed tenant isolation with a PII floor scopes every cross-record operation.