Eight ordered stages · fail-closed · nothing is used before it is scanned

Scan every recalled fact before an agent can act on it.

scoped intake · policy resolver only

Knowledge Firewall treats Walrus Memory as a scoped knowledge store, never an instruction channel. Type a field record, choose how it arrives, and watch the canonical resolver route it.

Active scope
campaign-ops
Decision engine
policy/resolve.mjs
Resolution mode
committed local policy
Scan a field record

Intake scanner

1 · Field record

This exact string is the text the resolver scans. Injection phrasing, credential-shaped values and contradicting statements each select a different canonical route.

2 · Arrival path

agent@knowledge-firewall · Field note intakeresolver online

Ready to inspect field-note

AWAITING SCAN

Select the arrival path, then run the scanner. The next result will show the intake decision, the rule that produced it, and the full policy route.

5 · Records outside the scanner

These files let a reviewer follow the scanner route beyond the visible candidate cards: the stage sequence, the frozen baseline, and the terminal receipt record each have their own place.

  • runs/MAINNET_EVIDENCE.mdHow terminal blob-ID receipts and cold-client recalls were recorded.
  • runs/checkpoints.jsonThe fixed scanner stages used for the documented workflow.
  • runs/source-locked-baseline.jsonThe frozen baseline the firewall policy is tested against.