AIOS Proresearch
AIOS Intelligence System · Research Overview

Part V · Knowledge Evolution and Product Mechanics

Registration, Promotion, and the Self-Evolving Knowledge System

A knowledge system improves over time only when experience crosses visible gates: observation becomes a candidate, evidence and scope are reviewed, an authorized change is written and verified, and later work selects it when relevant.

PromotionRegistrationProposed memory or relationshipRevalidation

1. “Self-evolving” means governed change

AIOS does not define self-evolution as a model continuously retraining itself on everything a person does. It defines it as a person-governed movement through which work produces evidence, evidence supports candidates, and accepted candidates become reusable ground.

This chapter owns the boundary between experience now and knowledge that may shape later reasoning. Earlier chapters explain how purpose, context, cognitive movements, workflows, and authority produce work. Here, their results acquire temporal and epistemic standing. The Flow Atlas makes that evolution navigable, epistemic maintenance keeps it revisable, and product mechanics ensure that promotion becomes an exact, reconstructable file effect rather than an invisible change of model memory.

The system evolves because its durable semantic environment changes:

The change remains inspectable, scoped, reversible, and attributable.

2. The practice flywheel

Experience becomes reusable ground

Work yields evidence for candidate expertise, which returns to future planning only after review, scoped authority, and registration.

flowchart TB E["Accepted reusable knowledge"] --> P["Planning and situated selection"] P --> W["Production\nthinking · writing · editing · workflow · review"] W --> D["Documents · decisions · traces · receipts · outcomes"] D --> O["Observed recurrence or failure"] O --> C["Candidate expertise"] C --> R["Evidence and counterevidence review"] R --> H{"Appropriate authority"} H -->|"accept or narrow"| G["Accepted and registered resource"] H -->|"defer or reject"| X["Disposition and lineage"] G --> E
Promotion · canonical19-registration-promotion-and-the-self-evolving-knowledge-system--m01.mmd
Text equivalent

Accepted reusable knowledge → Planning and situated selection; Planning and situated selection → Production — thinking · writing · editing · workflow · review; Production — thinking · writing · editing · workflow · review → Documents · decisions · traces · receipts · outcomes; Documents · decisions · traces · receipts · outcomes → Observed recurrence or failure; Observed recurrence or failure → Candidate expertise; Candidate expertise → Evidence and counterevidence review; Evidence and counterevidence review → Appropriate authority; Accepted and registered resource → Accepted reusable knowledge.

The loop compounds through a governed gate, not by absorbing everything that recurs. Evidence and counterevidence precede the authority decision; acceptance or narrowing returns a resource to future work, while deferral or rejection still preserves disposition and lineage.

The flywheel compounds without converting recurrence into enforcement.

3. Knowledge classes that can evolve

Candidates may become:

Different classes require different evidence and validation. A useful phrase is not automatically a workflow. A repeated workflow is not automatically a principle.

4. The temporal knowledge boundary

The central transition is not “the model remembered.” It is a sequence of changes in standing:

observed content
  → proposed memory
    → reviewed acceptance decision and authorization to canonicalize
      → exact canonical write and post-state verification
        → settled accepted standing
          → selective activation in a later context

These are standing boundaries, not necessarily separate storage products. A proposal can be held in an ordinary file, but its location does not give it accepted standing. Conversely, an acceptance decision is not settled standing until the corresponding canonical artifact and metadata have been written, verified, and made reconstructable after restart.

From observation to settled, selective use

How proposed knowledge becomes accepted through an authorized, verified write, enters only fitting contexts, and can later be revised or retired.

stateDiagram-v2 [*] --> Observed Observed --> ProposedMemory: derive with source anchors ProposedMemory --> Deferred: evidence or authority incomplete ProposedMemory --> Dismissed: unsupported, harmful, or irrelevant ProposedMemory --> AcceptanceAuthorized: scoped review and decision to canonicalize AcceptanceAuthorized --> SettledAccepted: exact write and post-state verification SettledAccepted --> Active: selected for a fitting movement Active --> SettledAccepted: movement ends SettledAccepted --> Qualified: new boundary or counterevidence SettledAccepted --> Superseded: new governing version accepted SettledAccepted --> Retired: removed from ordinary activation Qualified --> SettledAccepted: revalidated within narrower scope Retired --> SettledAccepted: restored with new justification
Temporal state transition · canonical19-registration-promotion-and-the-self-evolving-knowledge-system--m02.mmd

Do not read the states as one memory-write event. Observation can be deferred or dismissed; authorization precedes the verified canonical write; accepted ground becomes active only for a fitting movement, and can later be qualified, superseded, retired, or restored.

“Promote” must therefore name the next consequence. Proposing memory, approving development, producing a reusable asset, accepting its claims, registering its identity, writing canonical artifacts, and activating it are not one event.

5. Candidate record

A credible candidate should contain:

candidate:
  kind: workflow | scaffold | role | principle | template | exemplar | term | convention
  title: "..."
  account: "What appears to recur and why it matters"
  standing: proposed-memory
  scope:
    project_refs: []
    source_set_refs: []
  evidence:
    occurrences: []
    outcomes: []
    counterexamples: []
  proposed_contribution: "What reusable part exists"
  situational_elements: []
  limitations: []
  proposed_future_effect: "How context or validation would change"
  activation_conditions: []
  contraindications: []
  review_triggers: []
  provenance:
    source_refs: []
    trust_domains: []
    observed_at: []
    derived_by: []
  acceptance_authority: not-reviewed
  canonical_target: null
  revocation_and_rollback: null
  related_or_superseded_candidates: []

Repeated observations strengthen evidence. They never auto-approve.

6. Pattern review begins with metadata and returns to evidence

Metadata helps locate:

Metadata is an index, not proof. Provenance can show where a candidate came from, when it was derived, and who accepted it; it cannot establish that the candidate is true. Pattern review must descend into exact artifacts, passages, evidence, outcomes, and counterexamples.

7. Evidence requirements for promotion

A candidate should establish:

The question is not merely “Could this be useful again?” It is whether a future user can recognize when it applies and when it does not.

Promotion also crosses five different validity questions. Is the proposal structurally well formed? Is the semantic case adequate? Does it name the correct canonical object and revision? Does the accepting authority have jurisdiction over the proposed scope? Did the exact intended file and metadata effects occur? A positive answer at one layer cannot substitute for the others. Chapter 22 develops this trusted effect path in operational detail.

8. Two co-equal routes

Evidence-derived promotion

A pattern emerges from completed work and undergoes review.

Direct creation or import

A person, team, researcher, or partner already knows the method or standard they want to preserve.

This route is distinct from ordinary artifact or source admission. Admission gives an existing file stable local identity, provenance, and a declared custody state so the domain can address it. It does not make the file reusable expertise, accept its claims, register it as a governing resource, or activate it in context. Direct creation or import in this section names the later, governed route by which a deliberately formed expertise resource becomes eligible for reuse.

Two routes into reusable availability

Evidence-derived practice and deliberately authored or imported expertise converge only after different reviews and a person approval boundary.

flowchart LR A["Observed practice"] --> R["Evidence review"] B["Directly authored or imported resource"] --> V["Identity, format, provenance, scope review"] R --> H["Person approval boundary"] V --> H H --> G["Registered resource"] G --> C["Available for context composition"]
Promotion19-registration-promotion-and-the-self-evolving-knowledge-system--m03.mmd
Text equivalent

Observed practice → Evidence review; Directly authored or imported resource → Identity, format, provenance, scope review; Evidence review → Person approval boundary; Identity, format, provenance, scope review → Person approval boundary; Person approval boundary → Registered resource; Registered resource → Available for context composition.

The upper path tests recurrence and outcomes; the lower path tests identity, format, provenance, and scope. They meet at approval, after which the resource is registered and available for later context selection rather than automatically used.

Imported authority does not imply universal scope. Direct resources still need version, provenance, limitations, and retirement paths.

9. The delayed memory-write boundary

Persistent memory is a delayed action surface. A source read today can alter decisions months later if it is silently summarized, indexed, or retrieved as trusted ground. AIOS therefore separates permission to observe from permission to influence future contexts.

A memory proposal should remain inert until the appropriate process has:

  1. preserved the exact source and trust domain;
  2. distinguished source content from the system’s interpretation;
  3. checked whether the observation is current, corroborated, contradicted, or adversarial;
  4. declared the proposed scope and future use;
  5. identified the authority required for acceptance;
  6. written any accepted result through an exact, reviewable operation;
  7. produced a receipt naming the changed artifacts and revisions.

This boundary applies even when the model encountered the material through an ordinary question. Query access must not become an indirect route for installing guidance, expanding permissions, or poisoning a future context.

10. Project-local and reusable intelligence

Keep knowledge project-local when its validity depends on:

Promote when:

Moving a file to an expertise folder does not make its claims general.

11. Registration is availability

Registration gives a resource:

It makes the resource resolvable by the system.

Registration does not mean:

12. Activation is contextual

An accepted resource enters a judgment only when:

The capsule should make the resource's role visible, especially where its guidance is consequential.

13. Promotion authority follows scope

The system can evolve at several scopes:

ScopeExamplePromotion authority
Judgment-localTemporary scaffold for one decisionCurrent commission
Project-localAccepted method for one projectProject authority
Person-localPersonal planning or editing practicePerson
TeamShared workflow or evidence standardDeclared team owner
OrganizationControlled process or document standardOrganizational authority
Domain packageReviewed specialist methodPackage owner and acceptance process

A resource does not move upward in scope merely through use. Each expansion is a new claim requiring evidence and authority.

A model may discover and articulate a candidate. It does not thereby acquire authority to accept the candidate. Project, person, team, organization, and domain-package scopes each require an explicitly named owner or delegated process. The same resource may be accepted at one scope and remain only proposed at another.

14. Revalidation and decay

Promoted knowledge can become stale when:

The system can reduce routine exposure, flag for review, revise, retire, or supersede the resource. It should not silently rewrite it.

15. Competing practices can coexist

Two accepted methods may remain valid under different conditions.

Example:

The registry can preserve both and let context composition select by consequence and scope. Internal consistency means the distinction is visible.

16. Canonical artifacts stay local; access structures remain rebuildable

The corpus of canonical files and accepted ground remains inspectable. Summaries, search indexes, embeddings, extracted facts, relationship graphs, recommendation indexes, and Atlas views may accelerate access, but they remain derived and rebuildable unless a narrowly defined transactional invariant requires otherwise. Deleting and regenerating an index must not erase accepted knowledge or change its standing.

Each self-contained domain knowledge system remains independently intelligible and portable without hidden provider memory: its purpose, sources, terminology, standing, decisions, and lineage can be reconstructed from owned ground. Self-contained does not mean isolated. A domain can import evidence, use remote models, exchange attestable packages, and collaborate with other domains through explicit disclosure and acceptance boundaries.

This supports:

When remote models are used, selected context may still leave the device. Local custody of the canonical corpus is not identical to fully local inference.

17. Failure modes

Ambient learning

The system silently infers and installs what the person believes.

Delayed memory poisoning

Untrusted or interaction-generated content becomes future guidance without a promotion boundary.

Repetition bias

Common events are mistaken for useful transferable method.

Folder promotion

Moving content changes its authority without review.

Evidence-free standardization

A persuasive resource gains organization-wide scope without counterexamples or testing.

Registration enforcement

Available knowledge becomes mandatory.

Stale expertise

Promoted resources remain active after their conditions fail.

Invisible provenance

Future users cannot tell where a method came from or who accepted it.

Promotion overload

Candidate generation creates more review burden than useful learning.

18. Research connection

Current memory-security research gives direct support to the delayed-write boundary. AgentPoison showed that poisoning less than 0.1% of an evaluated agent memory could produce high downstream attack success under its direct-write threat model. MINJA demonstrated a query-only path in which an interaction induced persistent malicious memory that later affected behavior. These bounded benchmarks do not show that an AIOS implementation is secure; they show why read access, memory proposal, acceptance, canonical write, and later activation must remain separate authority transitions.

The broader evidence and limitations are summarized in the relational-memory research brief. AIOS contributes the product architecture that connects those risks to promotion authority, canonical files, receipts, and future context composition.

19. Research evaluation

Evaluate:

20. What this page contributes to the whole

Registration and promotion close the Fractal Seed’s reintegration loop. Local work does not disappear when a response ends, and generated language does not become knowledge merely because it exists. Experience can become reusable intelligence only through visible standing changes, evidence, scope, authority, exact canonical effects, and later selective activation. The next chapter shows how those distributed relationships can be mapped without turning the map into a new center of truth.