Built for AI that handles things that matter
When the data is privileged, the actions have consequences, and the auditors are real, a vector database with a chat wrapper isn't enough. These are the use cases where governed memory stops being a feature and becomes the product.
The memory of a set or a firm
The research services answer "what is the law." What they cannot hold is what your set or firm knows: the opinions, skeletons, pleadings and notes on how a particular tribunal treats a particular point, which walk out of the door with the people who wrote them. Yohanun holds that as a corpus with graded authority, supersession instead of decay, and a citator, so every answer cites the items that grounded it and the weight of each.
And it holds it behind real walls. Matters are compartments; clearances live in a platform-owned ledger; a grant across two adverse matters is refused by the conflict graph; a member's own notes return only to that member; an answer grounded in privileged material inherits the privilege. When someone leaves, custody transfers with one ledger entry. When a matter closes and the client requires erasure, a governed purge destroys the material and leaves a receipt.
For a set of chambers, over a hundred independent practitioners routinely instructed on opposite sides of the same dispute, this is the difference between an AI system that can be adopted and one that cannot. That deployment is Irenaeus, and its walkthrough runs today on synthetic material. A second profile of it serves a representation unit or a law clinic, where a case outlives the volunteer on it: the work stays with the case, and the person taking over reads a brief.
The Wall in Action
Agent fleets with boundaries
Deploy a team of AI agents where each has private memory, all share house knowledge, and none can act beyond its mandate. Each agent's memory is owner-walled in the same store; shared knowledge is a custody grant, not a copy.
Mandates give each agent an explicit action limit: commit freely below the line, escalate to a human above it. Retire an agent and transfer its memory custody to a successor with one ledger entry.
This isn't hypothetical: we run our own multi-project engineering agents on exactly this architecture, every day.
A Mandate, Not a Prompt
# Agent asks to act
POST /api/access/authorize-action
{ "action": "issue_refund", "amount": 180 }
# Under its €250 mandate → allowed, audited
{ "decision": "allow" }
# Over the line → escalates to a human queue
{ "action": "issue_refund", "amount": 4800 }
{ "decision": "escalate",
"escalation_id": "esc_91…" }
# No mandate, no unit match → never silently allowed.
# Commits fail closed.
Grounded experts on a governed corpus
Some domains, such as law, theology, medicine and standards, have authoritative sources with different weights. An expert system there can't just retrieve "similar text." It has to answer from the corpus, carry each source's authority grade into the answer, cite everything, and refuse to freelance beyond what the sources support.
Yohanun powers this as a two-layer architecture: a shared, curated corpus everyone reads, plus a private per-user layer (their documents, their history, their threads) walled by ownership in the same gate. The expert knows the field and remembers you.
Two Layers, One Gate
The same primitives, other domains
Labeled memory, cleared principals, mandates, audit, and outcome learning compose into whatever your domain calls its version of "trust."
Healthcare
Patient context that only returns to cleared roles, with a per-read audit trail, enforcement your compliance team can verify on every single read, not attest to once a year.
Financial Services
Chinese walls between desks, spending mandates on agent actions, and an immutable record of who saw what and who approved what.
Enterprise Copilots
Company-wide assistants where HR memory doesn't surface in engineering chats, departmental walls enforced in retrieval, not requested in prompts.
Customer Operations
Agents that remember every customer across channels, act within refund/discount mandates, and escalate the rest to humans, with the audit trail built in.
Personal Assistants
Assistants that build understanding over months. Memory that decays like memory, owned by the user, portable across whatever model runs it.
DevOps & Incident Response
Systems that remember past incidents, learn which fixes actually worked via outcome feedback, and know exactly which actions need a human sign-off.
What does trust look like in your domain?
Tell us your use case and constraints and we'll map them onto the platform's primitives and show you exactly what's enforced where.