Your data has warehouses. Your judgment has nothing.
Your organization runs on decisions, corrections, definitions, and precedent. Almost none of that lives anywhere a system can find; it lives in people, and it leaves with them. remember is the system of record for that judgment layer: governed, receipted, portable by construction, running on your infrastructure.
"It used to be Tom."
Organizational knowledge today is socially routed. Every company has its Toms, the people who hold the pricing history and the reason the workflow bends in that one spot. When Tom leaves, the answers and the index walk out together.
One desk away
The answer sits close by, and everyone knows whose desk to stop at.
Team walls
Knowledge pools inside teams. What marketing learned in March, sales relearns in May.
No head holds the map
The size of Meridian Learning, the model company in this deck. Pricing history, workflow rationale, customer promises: each lives in a different head, and the map of who holds what is itself unwritten.
You are already paying for organizational forgetting
Answered until someone leaves
"Why does this discount need VP approval?" The answer exists, it has been given four times, and it is written down nowhere.
Promised in June, rediscovered in October
A rep promises a follow-up on a call. The promise lives in a transcript, the transcript lives in a folder, and the renewal conversation starts without it.
Six weeks of asking around
A new hire's first real orientation is learning who to ask, one favor at a time.
Work described three times
The same week's work gets restated in a thread, a deck, and a status meeting. None of the three tellings is findable by December.
Everyone in these scenes is doing their job. The company has no place to put what they know, so people serve as the storage, the index, and the retrieval. All three go home at five.
A new, small system of record for the class of data that has none today
Decisions and their rationale. Corrections. Definitions. Precedent. The operations view of how the business actually works. remember references your enterprise data; it never copies it, and it never competes with the data stack.
What happened
Billions of rows, event streams, snapshots for reporting, star schemas built for aggregation. Terabytes in Snowflake. It stays exactly where it is, doing exactly what it does.
What you know, decided, and why
Tens of thousands to a low number of millions of curated facts at maturity, each individually valuable, with temporal validity. Gigabytes in Postgres, single-tenant, on your infrastructure.
It enters your data landscape the way Jira or Confluence did: an application system of record. A spoke, never a hub. It asks the data team for nothing and hands them a clean, well-governed new source.
One sales rep's day. Existing flows unchanged; the surfaces just got smarter.
| Moment | What changes |
|---|---|
| Morning playbook | The playbook arrives already knowing what was promised in June. Nobody briefed it. |
| Customer call | The account page got smarter. The call's commitments become recorded facts with one confirming tap. |
| Product meeting | Product sees cited customer voice from every rep's calls. Nobody filed a report. |
| Workflow change ships | The org stopped forgetting its own rules: the change records its own supersession, and the why rides in from the dev ticket. |
| Manager 1:1 | Opens with a pre-read of last session's commitments, visible to the two of them alone. |
| Slack, all day | "Does anyone know…" gets a cited answer at any hour. An emoji-react saves a decision from a thread. |
1:1s compound
Instead of resetting every week.
Customer voice, cited
Aggregated across every rep's meetings, without running a survey.
Every exception has a why
Recorded rationale on pricing exceptions; the audit takes an afternoon.
Onboarding against memory
Scoped to their lens, instead of six weeks of asking around.
remember is never a destination app. People meet it inside surfaces they already use, and every surface is also an input.
Every surface reads AND writes. That is why this one compounds.
Recorded, not surveyed
Retrieval receipts chain to downstream write-backs, so what was retrieved and acted on is a matter of record.
The highest-value capture
Retrieved-and-corrected becomes a correction fact chained to the fact it corrects.
One-tap capture
Confirm-taps on distilled meeting facts, emoji-reacts on chat decisions, forwarded email.
Recall gaps
Searched-and-not-found is recorded as demand data. It drives which connector or curation effort comes next.
The proof runs on your numbers. The memory is yours to keep.
A signed record per disclosure
What was shared, with whom, under which rules. An audit is reading a ledger, and the AI answers your people act on stop being unattributable.
By your analysts, on your numbers
Memory activity joins to pipeline, renewals, and cycle times in your own BI. No phone-home: Lexenne cannot see the numbers, so the ROI claim is yours to make.
Open-format export
The corpus exports against public specifications, deletion semantics included. The export demo is part of every evaluation.
"Here are the forty questions your organization asked last month that nothing could answer, and the sixty from last quarter that now have answers." The gap ledger is the prioritization instrument, the compounding record, and the renewal conversation, all at once.
Five questions that tell you whether this conversation matters
Two or more uncomfortable answers is a qualified conversation.
- Do you have AI or copilot projects stalled at security or legal review?The commonest blocker is access control the AI layer cannot honor. Gates that travel with each fact are the unblock.
- When your AI answers from company data, can you show where the answer came from?If not, every AI output is an unattributable liability under the logging rules now arriving.
- Can you prove that who sees what through your AI matches your access model?A signed record per disclosure is the difference between asserting compliance and demonstrating it.
- If you changed vendors tomorrow, what happens to everything your AI has learned?A loop you cannot carry out is one you rent, and the rent compounds with the value.
- Who on your side owns the AI-governance obligations landing through 2027?If nobody owns the dates, compliance-as-byproduct lands hardest here.
How it works
Act I is the business case; a business room can stop at the five questions. The rest is the machinery underneath: the governance primitive, the integration contracts, curation, models, security, and what is running today. Written for the architects and security reviewers who take this into evaluation.
The industry just agreed the learning loop is the asset. It has not agreed you can keep it.
Frontier Company
A $2.5B unit, 6,000 engineers embedded at customers. The word "leave" appears nowhere; the lock moved down the stack, into memory.
The sovereignty playbook
Fifteen steps arriving at this same architecture one layer up: model agnosticism, signed audit trails, knowledge outside the model. Every step runs on Palantir's own control layer.
Open Knowledge Format
An open, Apache-2.0 spec for organizational knowledge at rest. Platform, incumbent, and open standard converged within weeks. The category is consensus.
Obligations on a schedule
EU AI Act logging and oversight, Australian automated-decision transparency, India's data-fiduciary duties. The recurring asks: event logs, traceability, provable access control.
The startup wave
Venture-backed launches now sell the category itself: "the coordination tax," a brain that "should know before you ask." Loud on vision, silent on ownership.
And a gap no standard contract covers: data rights are not learning rights. Retention and training opt-outs say nothing about the derived judgment a vendor learns from watching your experts work.
Three terms carry the whole governance story
render(substrate, lens, frame) → receipt
Underneath: an append-only ledger of typed facts (decision, correction, definition, precedent, business rule, process), each with provenance back to its moment of entry and the person behind it, temporal validity instead of snapshots, and supersession instead of deletion. Every index is rebuildable from the ledger.
Your systems, unchanged. One small new system. Surfaces you already use.
The model company here is "Meridian Learning," a fictional but deliberately ordinary 400-person publisher. More on their day in slides 09 and 10.
Three intentional contracts with your stack. Nothing else.
Reference sync
A nightly upsert of entity keys and display labels from your CRM or MDM. Tiny, read-only from your side. Facts anchor to the same "customer 123" the rest of your stack uses.
Knowledge acquisition
Three doors: capture connectors (chat, forwarded email, documents, meeting transcripts, CRM notes) on a published envelope contract; KNOWN scanners deriving the operations view from system metadata; and the engagement layer writing back as it is used.
The SLF /v1 door
Governed, receipted reads for human surfaces and AI consumers alike. Every disclosure lens-scoped, every disclosure receipted.
Warehouse projection
An optional gated facts export into your own warehouse, receipts stamped at export. Your data team becomes a beneficiary, never a landlord.
Query federation over your warehouse. Proxying your analytics. Replacing any existing system of record. The knowledge remember wants was never in the warehouse; it lives in threads, meetings, and free text. There is nothing to migrate.
It does not start empty. It reads your systems and loads your documents.
| Leg 1 · Derived KNOWN scanned, mechanically re-verified | Derived from |
|---|---|
| Business logic validation rules, approval processes, discount thresholds, routing | CRM metadata APIs (Salesforce is the reference provider) |
| Campaign structure and scoring | Marketing platform APIs |
| Product taxonomy, events, funnels | Product analytics configuration |
| Feed topology what flows nightly where | Warehouse lineage metadata |
| System cards what exists, who owns it, how it connects | The above, plus a short install interview |
| The why underneath each rule | Nowhere machine-readable. Authored and captured: the judgment layer only remember holds |
Drift demands a why. On re-scan, a changed rule auto-supersedes, chain preserved, and asks for its rationale once, the week it changed. "Why does my discount need VP approval now?" has a cited answer forever.
Two hard lines for every scanner: read-only credentials, and metadata only, never data rows. Those two lines keep your security review short.
Leg 2 · Loaded KNOWN. Your document corpus (product docs, onboarding, Confluence, diagrams): one scan and load per source, curated at folder and space granularity, synced by a per-container "sync to remember" flag. Facts land as cited claims; on contradiction, the scanner wins.
Code for certainty. Models for ambiguity. Humans for named judgment.
Everything entering remember passes a three-stage intake, and the corpus is maintained the same way.
The curator is AI. Corpora die when they demand human librarians who never materialize. So deduplication, supersession, drift triage, staleness checks, and distillation run on scheduled loops. Lexenne runs this pattern internally, in production, today.
The human holds an audit door. A few hours a week approving consequential actions, auditing receipts, holding veto. Visibility and veto, never labor. Every curation action is receipted, so an audit is reading a ledger.
The memory never lives in a model. Your LLM subscription plugs into three sockets.
All three sit behind one OpenAI-compatible seam. Swapping models is configuration, never code, and remember never resells inference.
Embeddings and lexical indexing run in place. The corpus is never shipped out to be indexed, and there is no per-token tax that scales with corpus size.
What separates a real company brain from a toy
| Capability | RAG toy / DIY | A real brain |
|---|---|---|
| Permission inheritance | Vector store ignores source permissions; a good question leaks. | Per-fact gates enforced at read time. |
| Provenance | A similar passage, no citable chain. | Every fact links to its source and moment of entry. |
| Temporal validity | Serves stale facts confidently; deletes history. | Records when a fact was true and when it stopped. |
| Conflict resolution | Whichever contradictory fact scored higher. | Supersession chains; the open frontier of the whole field (best published benchmark: single-digit accuracy). |
| Portability | Whatever the platform lets you export. | Open-format export, checkable against a public spec. |
The funded tier (Glean, Sentra, and the memory-infrastructure layer under them) is racing at these from the recall side. The hyperscaler and Palantir stacks sell sovereignty as a heavy, platform-bound model for the largest institutions. remember is the proportionate, partner-delivered answer for organizations that will never buy those, with the one property the platforms structurally cannot offer: the loop lives on your infrastructure and leaves with you.
Governance is enforced in the retrieval engine, not bolted on beside it
Travel with each fact
Assigned at the write door. Unlabeled entries default-restrict; unknown tags reject the write. Fail-closed, at the door.
Cannot see past them
A fact whose gates the caller's lens does not cover is excluded before ranking. No privileged query path exists.
One per disclosure
What was asked, disclosed, and withheld, under which lens, signed and hash-chained. What logging obligations actually ask for, produced by default.
Chains of accountability
Captures carry the acting agent and the human principal. When an AI acts, the person whose intent drove it is never lost.
Deployment posture: customer-hosted, single-tenant, inside your network and compliance envelope. Air-gap capable because models and indexing can run entirely locally. No phone-home. Scanner credentials read-only and metadata-scoped.
Regulatory alignment: event logging (receipts, by default), traceability (per-fact provenance), provable access control, erasure (tombstone with proof, versus "we cannot un-embed it"), residency (runs in place). Compliance evidence as a byproduct of architecture.
Centralizing risk? Your judgment is already centralized, in retiring heads and six ungoverned systems a well-phrased question can leak from. This replaces N unaudited surfaces with one audited one.
CFO-grade value, measured in your own warehouse, on your own numbers
The governance machinery is the instrumentation: receipts record every disclosure, lineage ties reads to what happened next, and everything anchors to your own entity keys. The gated facts projection lets your analysts join memory activity to pipeline, renewals, and cycle times in your own BI. Lexenne provides the join surface and never the ROI claim; with no phone-home, Lexenne cannot even see the numbers.
Adoption
Asks per day, capture rate, corpus growth. Necessary, insufficient.
Operational deltas
Time-to-answer, new-hire ramp by cohort, and the repeat-question rate: the organizational forgetting rate as one declining number.
Activity linkage
Memory-touched versus untouched cohorts, presented as honest quasi-experiments with confounders named. Your analysts confirm the delta, not our marketing.
The compounding loop
The recall-gap ledger with closure tracking, and time-to-answer bending as the corpus compounds.
Portable by construction, and honest about the edges
The corpus is yours, and the export is checkable against public specifications rather than our word: knowledge projections emit OKF-shaped bundles (Google's draft Open Knowledge Format), including deletion and tombstone semantics. The capture contract and the SLF protocol are published, Apache-2.0. The export demo is part of every evaluation.