Story How it works Tests Insights Whitepaper What's next Download Author Contact
← Back to Insights
Reflection

Three kinds of memory, and only one my AI is allowed to touch.

Published August 19, 2026

For months, the default has been enough. I hand any model — Claude, GPT, DeepSeek — a memory that remembers facts about me and my work, and it just works. That was the whole point of building EIDARA: stop re-explaining myself every session.

But I’ve hit a ceiling. Remembering facts is table stakes now. To get to the next level I need the system to hold procedures too — reusable, well-built ways of doing things I can hand to any model. Skills, in the language the field has settled on. And the moment I went to add them, I ran into a question I’d been avoiding: a memory system looks like one thing, but it’s actually three. Mixing them up is what creates the mess.

What I know, who I am, how things get done

Three layers, and they behave nothing alike.

The first is what I know — facts. A supplier raised prices. A course starts in October. Someone changed jobs. Facts arrive constantly, loose and out of order, in the middle of a conversation. There are too many, and they change too fast, to route each one past a human. So the AI curates them itself. It has to.

The second is who I am — my agents. Not a job title; a way of working. “This is how my bookkeeping gets done: my spreadsheet, my bank, my judgment about what counts as a business expense.” These barely change, and when they do it’s because I decided to change how I work. The AI does not touch them. (An agent, to me, is just a document — but it’s my document.)

The third is how something gets done — skills. A procedure. “This is how you close a month.” “This is how you build an expense report.” They change rarely, and only when someone who knows better improves them.

Here’s the line that separates the last two, and it’s the whole article in one sentence: you download procedures; you never download identity. A closing-the-books skill works for anyone on earth. An agent knows which spreadsheet is mine and which judgment call is mine. The skill is generic and travels; the agent is mine and stays.

Who gets to write

This isn’t a taxonomy for its own sake. It settles the only question that matters once you let an AI tend its own memory: who has permission to write.

Facts are a stream. If I have to approve each one, the system dies of friction. Identity and procedure are the opposite. If a local model “improves” them on its own every night, one day you open your way of working and don’t recognize it — and you can’t say when it stopped being yours. Same files, from the outside. Completely different rules about who may edit them.

Rules get broken. Geography doesn’t.

So how do I stop the AI from one day deciding to polish a procedure I never asked it to touch?

The weak answer is to write a rule: don’t edit the skills. That holds until someone rewrites a component, or a new model reads the rule a little differently. Rules depend on everyone reading and respecting them, forever.

The strong answer is to put it out of reach. The part of the system that tidies memory only ever looks inside one place. Anything outside it is invisible — not forbidden, just not somewhere it looks. I have proof this works: the system’s own code has lived right next door for months, and it has never been touched. No rule prevents it. It’s simply outside. Skills go there too — beside the code, reachable by any AI that consults the library, out of reach of the one that tidies memory.

And to be clear, this isn’t “the AI is dangerous.” The local model that sorts my facts is good at its job: read a hundred loose facts, decide where each one goes, every hour, forever. Let it. I just don’t want it also weighing in on a procedure written by someone who knows more than it does. That’s not distrust; it’s division of labor. Nobody thinks it’s strange that the intern files the archive and doesn’t rewrite the quality manual.

The format lives in the door

A library of procedures turns into a dump in three weeks — everyone uploads their own thing, half-duplicated, no format, no note on what it’s for. I’ve watched it happen in shared folders my whole working life. Who enforces the format when the thing uploading is a different AI every time?

Nobody has to. The format lives in the door. Every AI reaches my memory through the same small set of moves — see what’s in the library, open one, add one, retire one, delete one for good — and each move carries its own instructions, read at the moment of connecting. It already works this way for facts: when a model goes to save one, the door tells it the rules before it can. Skills enter the same way. If a skill is missing what it needs, it doesn’t get in.

Three things fall out of that. It doesn’t matter which AI — today’s or next year’s, they all cross the same door and learn the same rules. Nobody has to be trained: change the format in the door and every model knows on its next connection. And order stops depending on discipline, which is the one thing that has never worked in any shared folder in history.

One decision I made on purpose: adding a skill is always triggered by a person, never on the AI’s initiative. A skill is a set of instructions the AI will then follow. A system that downloads instructions and starts obeying them on its own is exactly what I don’t want happening while I sleep.

And a subtler one. I first designed a review queue — the AI proposes, I approve. Then I admitted I was never going to read those files, so a review button would be theater, not control. Worse than no control, because it looks like some. So I moved the check to what I can actually judge: not whether the text is well-formed, but whether I just said “save that as a procedure.” A machine checks the text — format, size, and above all that it holds no personal data or credentials, the mechanical version of if it only serves one person, it isn’t a skill. I check the moment. You approve the moment, not the text.

What comes next

Skills are the next layer of EIDARA, and they arrive the way everything here has: not as a feature bolted on, but as a decision forced by hitting a limit. Facts taught the system to remember. Agents taught it who it’s working for. Skills teach it how the work is actually done — without ever letting it rewrite the how on its own.

We are still working on this. Every week it’s a little closer to the thing I want it to be.

— Javier

EIDARA v2 is free. SUPER DARA is what comes next.


See the full roadmap →

Keep reading

Eight things I do now that my AI remembers me The afternoon three rival AIs started talking