Why I built this
I run my life on an AI system I built — it schedules, files, remembers, drafts. And it kept doing something unsettling: acting on facts my life had already moved past. An old deadline. A person who had changed roles.
Nothing looked wrong — every answer cited a real note I once wrote. The notes had just stopped being true. Canon is the organ that system was missing: the part that knows when each fact was true, and refuses to act on the ones that expired.
The fix turned out to matter far beyond one personal setup. Any agent that pays, refunds, or reminds is one stale belief away from doing it to the wrong person, for the wrong amount, on the wrong date — and the message it sends will look perfectly fine.
What it gets you
Verdicts a pipeline can branch on — ALLOW / BLOCK, not a paragraph of hedging.
A receipt on every answer — the line it came from, and the line that replaced it.
Contradictions held open, not guessed away — “sources disagree” is an answer.
The case against building this
I ran this before writing code, and it belongs here as much as the pitch does — building is cheap now, so the judgment about what not to build is most of the work.
Two of my four tests, yes — every frontier model now handles them, and the site says so. The contradiction case isn’t closing, because it isn’t a knowledge gap: nothing in the file says which source outranks the other, and a bigger model can’t learn what the evidence doesn’t license.
It does — Zep and Graphiti model validity intervals well. Stores answer “what is true.” Nothing in the act path answers “may this go out.” That gap is the product.
A pipeline can’t branch on a caveat. Gemini knew the owner had changed — it wrote that underneath the draft, as prose — and drafted to him anyway. An agent takes the draft.
If a model ships a machine-readable refusal on contested facts, I retire the gate.Canon is one organ of a larger system — a local-first second brain I have run my life on for months. Ask me about the rest of it. →