MemoryGuard
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MemoryGuardshow memory history for the last hour"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Let agents write without turning shared memory into an unreviewed pile. MemoryGuard organizes each write, preserves the evidence behind changes, and keeps governance decisions reversible.
No account. No remote server. No telemetry. Memory stays local.
What's New in v0.7.1
v0.7.1 closes the migration and desktop lifecycle gaps found after the V2-only cutover:
One-command migration: after upgrading the Python package, run
memoryguard upgrade. The bare command uses the canonical user data home, migrates and verifies bindings, groups, memory, rules, history, and sources, activates V2, then removes only the successful migration backup batch.memoryguard upgrade --previewis the zero-write inspection path.One canonical control workspace: bare
memoryguard gui,doctor,mcp-status,hooks,groups, and storage commands all use the same user-level data home, independent of the terminal's current directory.Recovered Agent and Group control: migrated bindings and groups remain editable; discovered but unbound Agents can enable a personal memory layer. Discovery exposes registered product/profile surfaces without guessing every directory on the machine or reading source bodies.
Real projection engines: the build dialog lists only executable local Agent CLIs such as Cursor Agent and Codex. A selected CLI runs the governed extraction/enrichment pipeline inside the tracked task; deterministic mode is labeled honestly. There is no synthetic
host skillengine.Reliable start/cancel: one active build is allowed per trusted scope. Durable task IDs survive reloads, stale owners recover safely, cancellation stops owned CLI children, and every terminal/error path restores the neuron page instead of leaving
starting / 0%spinning.Unified governance: canonical rules, memory deduplication, compaction, knowledge references, and bounded context injection preserve identity, policy, priority, audience, scope, provenance, and evidence. Graphify stays integrated as an optional metadata provider behind MemoryGuard CodeGraph; it is not a separate MemoryGuard package.
History, Governance, and Knowledge UI repaired: raw History sessions now open through the real SafeBridge/native V2 path, governance activity shows the responsible Agent instead of
Unknown Agent, and/knowledgeis again a full V2 bookshelf/detail experience instead of a JSON debug page.Clearer governance visualization: dominant automatic decisions collapse into readable groups, while the neuron graph uses a tighter level-aware layout and root-outward soft signal bands instead of projectile-like particles.
Final local regression: 1884 passed / 0 failed across 205 test files. See the v0.7.1 release record.
Related MCP server: GroundMemory
What's New in v0.7.0 (V2-only; published 2026-08-12)
v0.7.0 is V2-only. Local release acceptance passed and the release was published to GitHub and PyPI on 2026-08-12. MemoryGuard owns the CodeGraph boundary; Graphify is an optional extraction provider, not a second MemoryGuard runtime or a separate MemoryGuard package. The boundary and evidence below describe the release. The Graphify result is a real full-repository export/projection result, not a claim that upstream Graphify's full-repository test suite passed.
V1 runtime physically retired: production entrypoint import closure has no V1 runtime/store modules.
V1_ACTIVEis a migration starting state, not a runnable fallback. Legacy formats are readable only undermemoryguard.migration; every other entrypoint fails closed withv2_upgrade_required. V1 data and migration backups remain rollback/audit evidence, never V2 runtime write targets.V2 control planes: Memory, Evidence, History, Source, Binding, and Group are V2-native boundaries. Memory atoms and evidence/decision receipts are separate from raw conversation History; authorized Source files/folders are separate from runtime state; trusted Agent Bindings select the governing Group.
Canonical governance: canonical reconciliation folds rules into
shared_baseline,agent_overlay, andproject_overlaybundles, keeps durable source links, verifies parity, activates the canonical read path, then shadows old duplicates for recovery. V2 automatic organization performs exact/semantic duplicate detection inside one share group and records deduplicated, superseded, conflicted, or quarantined outcomes. Rule duplicate scans produce governed merge proposals; merge and supersede decisions keep evidence, scope, idempotency, and undo receipts.Cross-agent same-group governance: all members of one trusted
share_group_idparticipate in the same bounded candidate and governance view; another group cannot enter it. Agent identity remains in provenance.Knowledge files and folders: a selected folder becomes a governed book and selected files become traceable documents. Content Plane owns source bodies; Knowledge stores metadata/references, supports re-ingest, remove/restore/ purge, and requires explicit review before memory candidates are accepted.
GUI Agent and Group control: the native GUI discovers Agent names and instances, records source selections, lists bindings, binds members to shared or personal groups, checks drift, and can leave or dissolve a group. Group changes commit receipts and system outbox events transactionally.
GUI builds and process cleanup: projection, Knowledge, import, history, maintenance, release, and compatibility work use durable V2
TaskRunstatus. Status survives reload, cancellation is cooperative and bounded, and owned background workers/process cleanup must finish before shutdown.CodeGraph / Graphify: MemoryGuard owns the trusted, body-free CodeGraph adapter and projection. Graphify is an optional extraction provider that supplies metadata-only exports; it is not a separate MemoryGuard runtime or package. CodeGraph preserves source role, provenance, source maps, revisions, tombstones, and outbox state, and exposes bounded query/path/explain/affected operations with production-only filtering.
Security and rollback: unknown/corrupt state, missing scope, invalid provenance, reparse paths, unsafe metadata, and stale idempotency fail closed. Public receipts redact source bodies and paths; governance/audit/outbox records retain decisions. Release rollback restores a Content Plane blob and held occurrence through a scoped receipt rather than trusting an unbound backup path.
Local release acceptance evidence:
1761 / 1761, with no skip or xfail; V1 retirement + CodeGraph15 / 15; Graphify focused checks3 / 3; canonical reconciliationACCEPTED; RuleMerge46 / 46; v3.227 / 27. The real full-repository Graphify export/projection covered486 files / 11672 nodes / 38714 edges → 11667 canonical symbols / 38714 edges; query/path/ affected passed and failure atomicity was0throughout.Final packaging evidence: clean wheel
206 files,legacy bad=0; isolated package, CLI, and MCP all reported0.7.0; desktop help passed.
Local release acceptance passed. v0.7.0 was published to GitHub and PyPI on 2026-08-12. These Graphify results cover the focused checks and the real full-repository export/projection only; they do not claim upstream Graphify's full-repository tests passed. See the v0.7.0 release record.
v0.6.2 compatibility baseline
The Python 3.10 SQLite correction remains part of the v0.7.0 upgrade baseline:
Memory, Evidence, and Content schema preflights inspect a private copy of the
SQLite main file plus -wal/-shm companions, and physical no-write checks do
not observe or checkpoint the live database. The historical release note is
preserved at docs/releases/v0.6.2.md.
Major V2 refactor in v0.6.0
v0.6.0 was a production data-plane refactor, not a storage-only upgrade:
Authoritative V2 domains: Memory, Rules, Evidence, Content, Runtime, Projection, Assets, CodeGraph, Skills, and System state are separated into explicit SQLite domains with governed boundaries.
Explicit cutover:
V1_ACTIVE → V2_BUILDING → V2_READY → V2_ACTIVEis fail-closed; V2 never silently falls back to legacy stores or dual-writes after READY/ACTIVE.Lossless migration: frozen-source preparation uses coherent SQLite online backups, validates source/target evidence, rechecks live-source drift, and preserves V1 data plus migration backups for rollback.
Native routing: MCP, CLI, GUI, and Hook surfaces are classified explicitly; the release closed the 233-surface cutover with 138 implemented routes, 95 retired routes, and zero neutral/blocker routes.
Governed intelligence: Rule lifecycle and RuleMerge, extraction/enrichment, External MCP import, provider control-plane, conversation history, Knowledge Library, and GUI governance all use the V2 evidence and decision paths.
Operational evidence: Reference Audit, per-domain SQLite health, guarded maintenance, rollback evidence, and safe unbound diagnostics are part of readiness and operations.
Why MemoryGuard
Persistent memory solves storage. It does not solve governance.
When several coding agents write into the same context, records become duplicated, stale, contradictory, over-broad, or unsafe to reuse. MemoryGuard sits between coding agents and their shared memory to keep that context usable.
Without governance | With MemoryGuard |
Notes accumulate without a canonical state | Writes are classified, deduplicated, superseded, or surfaced as conflicts |
A correction silently destroys the old value | Evidence and supersede chains preserve what changed and why |
Tokens and credentials can remain active | Sensitive-looking content is quarantined from active memory |
Every write needs manual approval | Agents write normally; people review exceptions and outcomes |
Raw chat logs leak into future context | Conversation history remains a separate, explicitly read evidence archive |
System architecture
%%{init: {"theme":"base","themeVariables":{"background":"#071521","fontFamily":"Arial, sans-serif","fontSize":"14px","primaryTextColor":"#EEF4F8","lineColor":"#557287","edgeLabelBackground":"#071521","clusterBkg":"#0A1A29","clusterBorder":"#27445A"},"flowchart":{"htmlLabels":true,"curve":"basis","nodeSpacing":32,"rankSpacing":48,"padding":14}}}%%
flowchart TB
Hosts["CODING-AGENT HOSTS<br/>Claude Code · Codex · Cursor · TRAE "]:::host
Gateway["LOCAL INTEGRATION<br/>MCP stdio · redirect rules · lifecycle hooks "]:::gateway
subgraph Core["GOVERNANCE CORE "]
direction LR
Identity["TRUST<br/>identity · scope "]:::core
MemoryAPI["MEMORY<br/>governed I/O "]:::active
Rules["RULES<br/>scope · assignment "]:::rule
HistoryAPI["HISTORY<br/>search · timeline "]:::history
Security["SAFETY<br/>validate · quarantine "]:::danger
Identity --> MemoryAPI
Identity --> Rules
Identity --> HistoryAPI
MemoryAPI --> Security
end
subgraph Stores["LOCAL GOVERNED STORES "]
direction LR
SharedDB[("V2 DOMAIN STORES<br/>Memory · Rules · Evidence · Content ")]:::store
HistoryDB[("HISTORY STORE<br/>isolated conversations ")]:::historyStore
AuditDB[("RECOVERY STORE<br/>versions · receipts · backups ")]:::store
end
Bootstrap["BOUNDED CONTEXT BOOTSTRAP<br/>mandatory rule pack · relevant recall "]:::bootstrap
Control["HUMAN CONTROL<br/>CLI · desktop governance console "]:::surface
Hosts --> Gateway --> Identity
MemoryAPI --> SharedDB
Rules --> SharedDB
HistoryAPI --> HistoryDB
Security --> AuditDB
SharedDB --> Bootstrap
Control --> Identity
classDef host fill:#12243A,stroke:#38D5C8,color:#EEF4F8,stroke-width:1.4px;
classDef gateway fill:#0D3338,stroke:#38D5C8,color:#EEF4F8,stroke-width:2.4px;
classDef core fill:#12243A,stroke:#557287,color:#EEF4F8,stroke-width:1.4px;
classDef active fill:#0D383A,stroke:#38D5C8,color:#EEF4F8,stroke-width:2px;
classDef rule fill:#3B2C18,stroke:#F3B562,color:#EEF4F8,stroke-width:1.8px;
classDef history fill:#102F45,stroke:#73C7F5,color:#EEF4F8,stroke-width:1.8px;
classDef danger fill:#3A2028,stroke:#EA6A6A,color:#EEF4F8,stroke-width:1.8px;
classDef bootstrap fill:#EEF4F8,stroke:#38D5C8,color:#071521,stroke-width:2.4px;
classDef store fill:#0B1624,stroke:#7F96A8,color:#EEF4F8,stroke-width:1.4px;
classDef historyStore fill:#102436,stroke:#73C7F5,color:#EEF4F8,stroke-width:1.4px;
classDef surface fill:#EEF4F8,stroke:#38D5C8,color:#071521,stroke-width:2px;
style Core fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
style Stores fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
linkStyle default stroke:#557287,stroke-width:1.4px;Quick start
1. Install
python -m pip install agent-memguardFor the desktop governance console:
python -m pip install "agent-memguard[gui]"2. Authorize the current project
memoryguard source add .3. Connect or repair your coding agent
Global provider configuration is rebuilt from the real binding in the canonical user data home. The command is idempotent and removes superseded MemoryGuard project-level overrides after a successful global takeover.
# Repair one provider
memoryguard provider repair claude
memoryguard provider repair codex
memoryguard provider repair cursor
memoryguard provider repair trae
# Repair every detected provider
memoryguard provider repair allRestart the host after installation, then verify the integration:
memoryguard doctor
memoryguard mcp-status
memoryguard hooks status --provider allLaunch the desktop console:
memoryguard guimemoryguard-gui . remains available for desktop shortcuts. A bare
memoryguard gui always opens the canonical user-level control directory
(default %LOCALAPPDATA%\MemoryGuard on Windows), so running it from a project
or from C:\Windows\System32 cannot silently switch databases.
MEMORYGUARD_WORKSPACE is an explicit operator override; an explicit
memoryguard gui <project-path> or memoryguard gui --workspace <project-path>
selects a specific workspace.
It does not remember a previously selected project or open a folder picker.
On Windows, memoryguard gui detaches the native window from the terminal, so
closing PowerShell does not close the GUI.
Provider-specific setup and behavior:
Upgrade
MemoryGuard currently upgrades through Python's package manager:
python -m pip install --upgrade agent-memguard
memoryguard --version
memoryguard doctorIf you installed the GUI extra, keep it during the upgrade:
python -m pip install --upgrade "agent-memguard[gui]"There is no package self-update command. The package manager is the
authoritative package-upgrade path; memoryguard upgrade below is the explicit
workspace migration flow, not a package updater.
Upgrade an existing V1 data home
Upgrade the package, then run the verified migration. No workspace, data-home, apply, or confirmation arguments are required for the normal user-level data home:
python -m pip install --upgrade agent-memguard
memoryguard --version # 0.7.1
memoryguard upgrade
memoryguard doctorThe command prepares V2, validates the frozen and live source evidence,
migrates Agent/Group control, activates only after all gates pass, and removes
only the backup batch belonging to that successful migration. Re-running it on
V2_ACTIVE is idempotent. For a zero-write report, use:
memoryguard upgrade --previewAdvanced explicit workspace/data-home options remain available for operators managing an isolated installation. A failed gate stays non-active and preserves its evidence; successful activation does not keep a redundant migration backup.
Existing pre-V2 workspaces: explicit V2 cutover
v0.6.0 never auto-activates an existing workspace. Upgrade the package first, then use the packaged operator CLI:
# Read-only manifest status
memoryguard-v2 status -w .
# Build a frozen-source V2 shadow and stop at V2_READY
memoryguard-v2 prepare -w . --apply
# Activate only after the prepare result is V2_READY / ready=true
memoryguard-v2 activate -w . --confirm V2_ACTIVEThe prepare step uses coherent SQLite online backups, preserves V1 and
migration-backups, and rechecks live-source drift before READY. Activation
performs another fresh drift check before changing the manifest. Do not delete
legacy V1 data or migration backups as part of the upgrade.
Knowledge Library
The desktop console can turn a selected folder or file set into one governed local knowledge library. Source files remain where they are; MemoryGuard stores the searchable index in its user data home instead of copying a runtime database into every source project. Knowledge metadata never becomes a second source-body store.
Capability | Current behavior |
File/folder ingestion | Add a folder as a book or selected files as documents |
Structure | Parse documents, preserve chapter/section context, and create traceable chunks |
Retrieval | Full-text search, optional embeddings, and a layered knowledge graph |
Natural synchronization | Re-ingest changed files; a partial or failed scan does not silently remove previously indexed content |
Lifecycle | Move a book to the library trash, restore it, or explicitly purge its recovery snapshot |
Memory candidates | Preview evidence-backed candidates before accepting them into governed long-term memory |
Open the desktop console and choose Knowledge Library. Remote embedding or model-backed indexing is opt-in and requires explicit authorization; local full-text retrieval remains available without sending source text to a remote provider.
Write and governance lifecycle
%%{init: {"theme":"base","themeVariables":{"background":"#071521","fontFamily":"Arial, sans-serif","fontSize":"14px","primaryTextColor":"#EEF4F8","lineColor":"#557287","edgeLabelBackground":"#071521","clusterBkg":"#0A1A29","clusterBorder":"#27445A"},"flowchart":{"htmlLabels":true,"curve":"basis","nodeSpacing":30,"rankSpacing":42,"padding":14}}}%%
flowchart TD
subgraph Intake["01 · INTAKE "]
direction LR
Write(["Memory write "]):::entry
Scope["Resolve identity<br/>scope · audience "]:::core
Validate{"Authorized? "}:::decision
Reject["Reject<br/>no persistence "]:::danger
Write --> Scope --> Validate
Validate -- NO --> Reject
end
subgraph Organize["02 · ORGANIZE "]
direction TB
Secret{"Sensitive? "}:::decision
Quarantine["Quarantine<br/>outside active set "]:::danger
Compare["Classify · compare<br/>governed records "]:::active
Relation{"Relationship "}:::decision
New["NEW<br/>create active record "]:::result
Duplicate["DUPLICATE<br/>merge provenance "]:::result
Correction["CORRECTION<br/>supersede old record "]:::rule
Conflict["CONFLICT<br/>preserve both sides "]:::danger
Secret -- YES --> Quarantine
Secret -- NO --> Compare --> Relation
Relation --> New
Relation --> Duplicate
Relation --> Correction
Relation --> Conflict
end
subgraph Govern["03 · GOVERN "]
direction LR
Receipt[("Evidence event<br/>version receipt ")]:::store
Review["CLI or desktop review "]:::surface
Action["Correct · merge<br/>restore · delete "]:::rule
Snapshot["Reversible<br/>snapshot "]:::active
Receipt --> Review --> Action --> Snapshot
end
Validate -- YES --> Secret
Quarantine --> Receipt
New --> Receipt
Duplicate --> Receipt
Correction --> Receipt
Conflict --> Receipt
classDef entry fill:#EEF4F8,stroke:#38D5C8,color:#071521,stroke-width:2.4px;
classDef core fill:#12243A,stroke:#557287,color:#EEF4F8,stroke-width:1.5px;
classDef decision fill:#0D3338,stroke:#38D5C8,color:#EEF4F8,stroke-width:2px;
classDef active fill:#0D383A,stroke:#38D5C8,color:#EEF4F8,stroke-width:2px;
classDef result fill:#12243A,stroke:#38D5C8,color:#EEF4F8,stroke-width:1.6px;
classDef rule fill:#3B2C18,stroke:#F3B562,color:#EEF4F8,stroke-width:1.8px;
classDef danger fill:#3A2028,stroke:#EA6A6A,color:#EEF4F8,stroke-width:1.8px;
classDef store fill:#0B1624,stroke:#7F96A8,color:#EEF4F8,stroke-width:1.4px;
classDef surface fill:#EEF4F8,stroke:#38D5C8,color:#071521,stroke-width:2px;
style Intake fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
style Organize fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
style Govern fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
linkStyle default stroke:#557287,stroke-width:1.4px;The console is not an approval queue. Agents keep moving. MemoryGuard records the outcome and exposes the evidence needed to correct it later.
What you can govern
Signal | Governance action |
Duplicate or stale memory | Inspect the canonical record and supersede chain; restore an earlier version when needed |
Conflicting memories | Keep both visible until the conflict is resolved deliberately |
Secrets, tokens, or credentials | Quarantine the record so it cannot enter active shared memory |
Incorrect automatic organization | Correct, merge, lock, restore, or roll back with evidence |
Multiple coding agents | Bind agents to one shared group while preserving source identity and scope |
Mandatory rules | Assign rules to an Agent, project, provider, runtime role, or shared group |
Rules and history stay separate
MemoryGuard deliberately keeps governed long-term memory and raw conversation history on different paths.
Surface | Purpose | Context behavior |
Rules and habits | Preferences, procedures, corrections, facts, projects, and scoped mandatory rules | Mandatory rules use a bounded independent budget; ordinary records are recalled when relevant |
Conversation history | Local raw-evidence archive with owner and shared-group access controls | Never enters bootstrap automatically; raw text is read only through explicit history tools |
Neuron graph | Navigation and governance over memory, rules, projects, agents, and sessions | History nodes contain safe metadata and summaries, not raw chat content |
History retrieval is progressive: search results, then a bounded timeline, then an explicitly selected turn or session. Extracting from history creates a preview first; it does not silently write a long-term memory.
%%{init: {"theme":"base","themeVariables":{"background":"#071521","fontFamily":"Arial, sans-serif","fontSize":"14px","primaryTextColor":"#EEF4F8","lineColor":"#557287","edgeLabelBackground":"#071521","clusterBkg":"#0A1A29","clusterBorder":"#27445A"},"flowchart":{"htmlLabels":true,"curve":"basis","nodeSpacing":30,"rankSpacing":42,"padding":14}}}%%
flowchart LR
subgraph HistoryPath["CONVERSATION EVIDENCE "]
direction TB
Archive[("Raw local history ")]:::historyStore
Search["Search summaries "]:::history
Timeline["Bounded timeline "]:::history
Read["Explicit turn or session "]:::history
Preview["Evidence-backed<br/>extraction preview "]:::history
Confirm["Explicit acceptance "]:::surface
Isolation["NO AUTOMATIC<br/>BOOTSTRAP PATH "]:::barrier
Archive --> Search --> Timeline --> Read --> Preview --> Confirm
Archive -.-> Isolation
end
subgraph GovernedMemory["GOVERNED LONG-TERM MEMORY "]
direction TB
Mandatory["Scoped mandatory rules "]:::rule
Assignments["Agent · project<br/>role · group scope "]:::core
RulePack["Mandatory-rule<br/>budget "]:::budget
Ordinary["Facts · preferences<br/>projects · procedures "]:::memory
Recall["Task-relevant<br/>recall budget "]:::budget
Context["BOUNDED CONTEXT PACKET "]:::context
Mandatory --> Assignments --> RulePack --> Context
Ordinary --> Recall --> Context
end
HistoryPath ==>|GOVERNED WRITE | GovernedMemory
classDef rule fill:#3B2C18,stroke:#F3B562,color:#EEF4F8,stroke-width:1.8px;
classDef core fill:#12243A,stroke:#557287,color:#EEF4F8,stroke-width:1.4px;
classDef memory fill:#0D383A,stroke:#38D5C8,color:#EEF4F8,stroke-width:1.8px;
classDef budget fill:#12243A,stroke:#38D5C8,color:#EEF4F8,stroke-width:1.6px;
classDef context fill:#EEF4F8,stroke:#38D5C8,color:#071521,stroke-width:2.4px;
classDef history fill:#102F45,stroke:#73C7F5,color:#EEF4F8,stroke-width:1.6px;
classDef historyStore fill:#102436,stroke:#73C7F5,color:#EEF4F8,stroke-width:1.6px;
classDef surface fill:#EEF4F8,stroke:#73C7F5,color:#071521,stroke-width:2px;
classDef barrier fill:#3A2028,stroke:#EA6A6A,color:#EEF4F8,stroke-width:2px;
style GovernedMemory fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
style HistoryPath fill:#081827,stroke:#27445A,stroke-width:1px,color:#EEF4F8
linkStyle default stroke:#557287,stroke-width:1.4px;Supported hosts
Host | Integration | Current boundary |
Claude Code | Global MCP binding, redirect rules, user-level lifecycle Hook | Verified takeover path |
Codex | Global MCP binding, redirect rules, user-level lifecycle Hook | Verified takeover path |
Cursor | Global MCP binding, redirect rules, user-level lifecycle Hook | Verified takeover path |
TRAE | MCP binding and redirect rules | No verified Hook seam; reported as a fallback instead of full takeover |
Provider status is reported honestly as redirected, observed, operational, or unsupported. MemoryGuard does not claim it can disable every host's native memory when the host exposes no reliable integration point.
Architecture
Layer | Responsibility |
Evidence & Content | Authorized sources, immutable evidence, content-addressed blobs/occurrences, source manifests, and conversation archives |
Memory & Rules | Scoped memory atoms, revisions, bindings, rule definitions, decisions, evidence links, and compensating governance operations |
Runtime & Projection | Bounded working context, scenario/profile projections, CodeGraph, Assets, and Skills metadata |
Cutover & Governance | Four-state manifest, native MCP/CLI/GUI/Hook routing, Reference Audit, maintenance, provider adapters, and rollback evidence |
V2 uses separate authoritative SQLite domains rather than one shared-memory
database. The runtime reads and writes V2 only after the manifest reaches
V2_ACTIVE; V2_BUILDING and V2_READY never silently fall back or dual-write.
Evidence remains traceable without being treated as automatically trusted memory.
Privacy and safety
MemoryGuard runs as a local MCP stdio server.
All governed data stays local unless you explicitly authorize a remote model or embedding operation.
The Knowledge Library database uses
MEMORYGUARD_HOMEor the platform user data directory, so a selected source folder does not receive its own knowledge database.V2 authoritative workspace state is separated under
.memoryguard/into explicit Memory, Rules, Evidence, Content, Runtime, Projection, Assets, CodeGraph, Skills, and System domains; History, Source, Binding, and Group control are V2-native surfaces. Legacy V1 artifacts are preserved as local rollback/audit evidence after cutover and are no longer the active V2 runtime write path; onlymemoryguard.migrationmay read them.Source scanning is read-only by default.
Mutating governance paths use validation, explicit scope, provenance, and reversible state.
Quarantined records stay outside active shared memory.
Raw conversation history is never injected into bootstrap automatically.
Shared-group history access follows current active membership and does not grant deletion rights over another Agent's source.
CLI
The installed memoryguard command exposes these top-level operations:
Command | Purpose |
| Run a read-only audit and generate a report |
| Open the latest interactive report |
| Explain evidence and risk for a finding |
| List, add, remove, or preview authorized sources |
| Scan authorized sources and build the coverage ledger |
| Diagnose V2 manifest, domain availability, and native coverage |
| Inspect V2 MCP/backend health; tenant counts require a bound Agent scope |
| Install, inspect, pause, repair, or remove host Hooks |
| Inspect or repair global provider integrations |
`storage audit | report` |
`storage sweep | compact` |
| Inspect governed group state |
| Launch the interactive governance console |
| Launch the trusted desktop executor |
The old V1 plan, apply, verify, undo, import, and gc workflows may
remain parseable as explicit retired compatibility surfaces, but are not a V1
runtime path. Under V2_ACTIVE they return a stable retired result instead of
writing through a legacy store. Legacy data input is accepted only by the
explicit memoryguard.migration upgrade flow.
Run memoryguard --help or memoryguard <command> --help for the live command
reference.
MCP API
The MCP server exposes tools for:
governed memory read, search, write, update, delete, and status;
bounded context bootstrap with mandatory-rule isolation;
rule creation, feedback, merge governance, undo, and scope statistics;
Agent binding and shared-group inspection;
source scanning, graph projection, import previews, and build planning;
external MCP discovery and import;
document extraction previews and candidate acceptance;
conversation-history search, timeline, explicit read, export, deletion, and extraction preview;
provider installation and host-agent enrichment.
Use MCP tools/list as the source of truth for the exact tool set supported by
the installed version.
Project links
Roadmap
Current release line: v0.7.1 keeps the V2-only runtime boundary and closes the one-command migration, Agent/Group recovery, executable projection-engine, durable cancellation, and unified context-governance lifecycle. Local full regression passed at
1810 / 1810.Acceptance boundary: the Graphify evidence is the focused
3 / 3result plus the real full-repository export/projection described above. It does not claim that upstream Graphify's full-repository test suite passed.Next after release: broader CodeGraph/Skills ingestion, more operator-friendly maintenance reports, and additional migration observability. Long-term records are not retired merely because they are old.
Later: team and enterprise capabilities only after validated demand.
Contributing
Issues and pull requests are welcome. Read CONTRIBUTING.md before submitting a change. Pull requests require agreement to the CLA.
License
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenanceMCP-native, local-first memory for coding agents that turns real sessions into reusable decisions, gotchas, and domain knowledge.173MIT
- Alicense-qualityBmaintenanceAn MCP-native, local-first memory server that gives AI agents persistent, structured memory across sessions and tools, enabling them to maintain identity and context without reconfiguration.3MIT
- Alicense-qualityDmaintenanceLocal-first AI memory layer with hybrid retrieval and brain-inspired namespaces. Enables agents to save, search, and manage memories directly via MCP tools.5MIT
- Flicense-qualityCmaintenanceA local-first MCP server that manages developer memory for coding agents, enabling shared project context, permissions, and audit trails across different agents.1
Related MCP Connectors
Shared, governed long-term memory for AI agents across tools and sessions via MCP and REST.
Private-by-default, local-first memory/context/task orchestrator for MCP apps and agents.
Shared long-term memory vault for AI agents with 20 MCP tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/irisxc4/memoryguard'
If you have feedback or need assistance with the MCP directory API, please join our Discord server