Applied at: as_of
Valid time describes the world the memory refers to. A valid interval is [valid_from, valid_to): it includes the start and excludes the end. A null end is unbounded.
Known at: known_at
Recorded time describes what the ledger knew. A recorded interval is [recorded_at, recorded_until), with the same exclusive-end rule. The server owns recorded time; ordinary clients cannot backdate it.
An exact example
Boston applies from time 0 and is recorded at time 100. At time 200, a correction says New York applies from time 50. These numbers are illustrative UTC Unix seconds.
| as_of | known_at | Result | Why |
|---|---|---|---|
| 70 | 150 | Boston | The correction had not been recorded |
| 70 | 200 | New York | The correction is known and applies |
| 20 | 200 | Boston | The correction does not apply yet |
Preserve precision and boundaries
API times are finite UTC Unix seconds as JSON numbers, including fractional seconds. Do not round imported Python float timestamps to integer milliseconds. A bounded correction preserves the valid-time suffix at its exclusive end. Re-embedding changes the search projection, not the fact’s revision or clocks.
Corrections and invalidation
Correcting requires authority and the expected generation. It preserves unaffected valid-time intervals and invalidates transitive derivations. Derived memories initially stay inside one namespace. Historical invalidation is evaluated according to when it was recorded.
Deletion applies to history too
Purged content is absent even from historical reads. A deletion fence prevents later search work or a restore from making that content readable again. Content-free receipts remain to track cleanup.