---
id: PUBLIC-MODULE-INTEGRATION-2026-09-12
title: Mentaview module integration contract
status: implemented
version: 1.3.0
owner: engineering
created: 2026-09-12
updated: 2026-09-13
classification: public
normative: false
---

# Mentaview module integration contract

Updated 13 September 2026. This document describes responsibility boundaries and supported
integration surfaces, not universal feature parity, production certification or a live API on this site.

| Responsibility | Owner | Handoff |
| --- | --- | --- |
| Discover, parse and normalize sources; duplicate admission | Multimodal Ingestion | Authorized canonical Knowledge records |
| Catalogue, index, rank and open evidence | Document Retrieval / Search | Bounded source references and evidence packets |
| Review, retain, correct and forget facts; entity and navigation authority | Governed Memory | Explicitly approved scoped memory |
| Transactions, source replacement, reference safety and erasure | Persistence | Atomic writes or explicit rejection |
| Context layer order and aggregate budget | Cognitive Engine | Explicit bounded context plan |
| Tasks, events, roster and artifacts | Coordination | Validated task projections, not personal memory |
| Authentication and protocol composition | CLI, MCP and HTTP adapters | Callable module-owned operations |

## Supported chains

1. Source ingestion persists canonical records before returning a Memory-review handoff. Deferred
   recovery carries the same handoff. A pending extraction is not an empty candidate set.
2. A reviewer selects current evidence and separately promotes a Memory candidate. Neither ingestion
   nor search automatically creates an approved personal fact.
3. Source deletion selects one exact owner, retention scope and canonical source root. It refuses to
   remove retained evidence or orphan a navigation root. Another still-visible retention scope can
   keep that root available; there is no prefix wildcard or implicit cascading deletion.
4. A source replacement is atomic per source. Changing a cited source requires an explicit dependency
   lifecycle or a new source version. A batch containing multiple sources is not a global transaction.
5. Local vector maintenance plans from a single snapshot and changes only embedding fields. The
   final commit rejects a changed snapshot, including a source deleted during model execution.
   Deferred server indexing also updates only vectors on the exact PostgreSQL source originally
   read. A deleted, replaced or already-refreshed record is skipped, never recreated or overwritten;
   unknown source metadata is preserved. Aggregate counters distinguish published, failed and
   stale results, including partial progress before a later storage failure.
6. The four-layer context plan composes Memory and Search through its explicit CLI, MCP and HTTP
   entrypoints. It must not be confused with automatic use on every ordinary answer request.

Source-derived Memory approvals, discovered claims and entity registration recheck the complete
visible Knowledge snapshot at commit time. If the evidence changed after review, publication is
rejected and the reviewer must refresh. Persistence owns this atomic check; Memory still owns
candidate extraction and approval rules. Concurrent changes must not restore a deleted source or
overwrite a superseded memory. An already-present, read-only response remains an observation, not
a guarantee against later erasure.

## Interface naming

Canonical operations use their owning module: `ingestion`, `retrieval`, `memory`, `cognitive` or
`coordination`. Local maintenance commands are `repair-retrieval-index`, `rebuild-retrieval-index`
and `rebuild-retrieval-embeddings`. Earlier `memory` spellings remain compatibility aliases;
their existing output keys remain stable. They do not transfer index ownership to Memory.

Qdrant and Milvus are optional library adapters with typed scopes and bounded contracts. They are
not selectable CLI/server retrieval backends. Library tests with simulated transports do not
qualify a live provider deployment. No artificial runtime caller is added to imply otherwise.

## Deployment boundary

Firebase publishes this static site, this document and the illustrative Memory demonstrator.
It does not deploy the Rust runtime, start a PostgreSQL service, migrate a customer database or
connect the demonstrator to private Memory. Runtime capabilities require a separately configured,
authenticated deployment. A snapshot pasted into the demonstrator remains in the browser.

## Evaluation boundary

LoCoMo strict source-content retrieval scores remain unchanged after category-label correction:
91.96% overall; category 2 temporal 91.23% versus the compared MemPalace artifact's 90.76%;
category 3 open-domain 69.80% versus 69.96%. These are Search results, not Memory scores or
generated-answer accuracy. The open-domain gap is retained explicitly; no universal superiority
claim follows from aggregate benchmark leads.


## Consolidation on 13 September 2026

The current inventory reconciles all eleven public modules and twenty-nine Rust crates. Twenty-eight
crates are reachable from the supported product entrypoints; the code-assistant crate remains a
separate future contract. This dependency inventory is complemented by registered HTTP contract
checks and behavioral tests. It is not a proof that every optional backend or device is deployed.

A local Linux x86_64 smoke test exercised the actual TCP HTTP server with disposable PostgreSQL 17:
readiness, console delivery and its exact script CSP, rejected missing/invalid credentials, document
ingestion, persisted visibility for the owner and absence of visibility for another tenant. Inference
was disabled. This local check does not qualify a hosted TLS endpoint or a remote model provider.

The first Google Cloud/Podman pilot profile targets Linux x86_64 with Rust 1.97.1. Generic Linux ARM
compilation encountered an FP16 requirement in the GEMM dependency and remains unqualified. Physical
Edge/OEM targets require their own hardware campaign. The module maturity levels and external
assurance gates are unchanged by this consolidation.
