Skip to main content
pending_advisories is the unified cross-turn carryover surface. One table, read by the gateway at the start of each runtime turn, multiple sources via a closed source enum spanning runtime + sideband + manual contexts. This page documents the row shape every consumer can rely on (gateway, observer, dashboard, CLI, webhook subscribers) and the compatibility rules for new and retired sources.

Row shape

TTL. Default 24 hours. Configurable platform-wide by Mnemom platform admins; not configurable per-org or per-agent. Status transitions. Always forward: pending → consumed (gateway injected on a turn) or pending → expired (TTL elapsed without injection). No revivals.

Source taxonomy

Closed, hierarchical, append-only enum. New values are added additively; see Compatibility.
Surface-separation invariant. sideband.* sources are no longer accepted into pending_advisories — a CHECK constraint on pending_advisories.source rejects new sideband.* writes (pre-cutover historical rows remain queryable for compliance attestation but were marked status='expired'). The fleet-sweep detectors (sideband.coherence / sideband.fault_line / sideband.fleet) write to the operator-actionable governance_signals table instead.

Current ratified values (post-cutover)

sideband.coherence / sideband.fault_line / sideband.fleet previously appeared here; the fleet-sweep detectors behind them now write to governance_signals instead. Runtime drift detection is a separate, agent-scoped detector (not fleet-sweep-driven, not written to pending_advisories or governance_signals) that fires the sideband.drift.fired webhook event directly — see Webhook events below. The legacy drift.detected event name has been removed with no replacement alias; subscribers must use sideband.drift.fired.

source_ref shapes

JSONB envelope keyed off source. Conventions:
  • Every runtime.* row carries {checkpoint_id: string, mode_at_fire: "off"|"observe"|"nudge"|"enforce"}
  • Every manual.* row carries {actor_user_id: string, attached_at: string, note?: string}
For sideband.* source_ref shapes, see the governance_signals table; those observations write to the operator-actionable surface, not to this table.

runtime.* — source_ref

checkpoint_id references the integrity_checkpoints row created on the same turn. mode_at_fire is the agent’s effective mode at intervention time (post-cascade, pre-fire).

manual.admin — source_ref

nudge_content format

Every advisory’s text follows a stable wrapper:
The bracket wrapper enables the gateway’s user-visible-explanation guarantee to detect that an injection happened. Producers MUST keep the wrapper; if the wrapper is missing on a delivered turn, the gateway suffix-injects its own marker [Mnemom: <intervention summary>].

concerns_summary format

Short structured headline (≤80 chars) used for telemetry, dashboard display, and CLI list output. Convention: <axis>: <short outcome>.

Read endpoints

Filters (all optional, on the agent + team listing endpoints):
  • ?since=<ISO-8601> — only advisories created after this timestamp
  • ?limit=<n> — page size (default 50/100, max 200/500)
Service-key paths used by the observer cron (not customer-facing — gated behind X-Service-Key, exposed under an internal namespace that does not appear in the customer OpenAPI):

Compatibility

  • New source values are additive. Mnemom may add values to the source taxonomy. Treat an unrecognized source as a generic advisory instead of rejecting the row.
  • Existing rows are never rewritten to a new source. When a source stops being produced (as sideband.* did), new writes with it are refused, but historical rows keep their original source value and remain readable for audit and compliance queries.

Webhook events

sideband.drift.fired fires today for runtime (in-session) drift detection — the legacy drift.detected name was removed with no replacement alias, so subscribers must use sideband.drift.fired. sideband.coherence.fired / sideband.fault_line.fired / sideband.fleet.fired remain registered event types you can subscribe to, but their detectors currently deliver findings through governance_signals instead — do not rely on them firing today. Subscribers receive the standard webhook envelope:
See Webhooks for the full subscription + signature-verification flow.

See also