Governance
Protection and reliable writes
Preserve authorship, access and history, including when the backend fails.
Protection before mutation
Protected and critical entries reject agent edits or removal. Reading and editing have distinct dimensions; portfolio tags do not expand access. Suspected injection content is retained for inspection but does not enter context automatically.
Durable intent first
The spool records content and metadata on disk before attempting the write. An external drainer checks the hash, looks for duplicates and tries the API or CLI. Backend unavailability leaves the item pending; exhausted attempts require review. This depends on available disk and a configured drainer.
Confirmation requires a real ID
pending means recorded intent, done includes the confirmed entry_id, and failed retains items for review. None of these states permits inventing an ID. A created or duplicate response from the idempotent API identifies the stored entry; a local file alone does not prove a backend write.
python scripts/orkmind_drain.py --status