Settings → Vaults
Every vault on this machine is managed here: what feeds it, how much it counts when memory is searched, what nature its memories carry, how protected it is, and how it dies. The rail entry is Vaults; the page is titled Vaults and its subtitle counts your vault roots, followed by the path of the workspace folder.
There is no Save button on this page. Every control writes as soon as you confirm it, and the destructive ones ask first.
This page is about the settings. For what a vault is, see Vaults; for how a folder becomes memory, see DocWatch and Watched folders; for the vaults as you see them on the canvas, see the Vaults widget.
The header: three actions
- Watched folders (a radio glyph): Live state of every folder watched by the automatic memory. Opens the live-state panel.
- ⟲ Rebuild all, in red: Purge all memory and re-vectorize every declared folder from scratch. Opens the confirmation.
- + Vault opens the creation dialog.
When the page has nothing to show
- While the vault tree loads, the ∞ loader.
- Without a workspace: No workspace configured and Set up a Mnemosyne OS workspace via onboarding or restart the application. See Onboarding.
- With a workspace but no vault: No vault found in workspace.
- With vaults but none selected, the right column says Click on a vault to view its details.
The left column: vault tiles
The tiles are the same ones the Vaults widget shows, in a smaller size, grouped into foldable families. First Apps & cartridges (the sandbox vaults written by apps), then one group per vault type present, in a fixed order: DEV, RESEARCH, SOCIAL, PERSONAL, CREATIVE, DREAM, CUSTOM. The group names are the raw type names, in English in every language. Each group header shows a chevron, a tint dot, the name in capitals and a count. Which groups are folded is remembered between sessions.
On a tile:
- a click opens the vault's panel on the right;
- the expand chevron shows the sub-vaults in an indented band;
- the mute toggle flips the vault's RAG attention between 0 and 100. The Vaults widget on the canvas sees the change at once.
A freshly created vault is unfolded, scrolled to and flashed. The Vaults widget's "manage this vault" signpost lands on the matching panel here.
The vault panel
The right column is the same panel the Vaults widget opens as a slide-over.
Identity
- The colour dot is a native colour picker (Vault color — pick any RGB shade). It writes the vault's colour after a short pause.
- The name (for an app sandbox, the name the app declared), with the absolute path underneath.
- A 🔒 when protection is MAXIMUM (tooltip Protection: MAXIMUM).
- A type badge with the raw type, or 🧪 App sandbox.
- A description field, What this vault is for (optional)…, written when you leave it.
Status card
Shown only for provisional vaults and app sandboxes:
- ▨ Walled off: Excluded from Dream State consolidation, the neural map and federated RAG — this app's data stays isolated until YOU validate it.
- 🔓 Permanence unlocked: Feeds Dream State consolidation, the neural map and federated RAG — validated by you.
- A ? button explains the choice: Why unlock? While walled, ONLY this app reads and writes its own memory. Unlocking gives Mnemosyne access to it: your chat answers can draw on it (federated RAG), it feeds Dream State consolidation, and it appears on the neural map. Your data never leaves this machine — this is your governance call.
- The promote button takes two clicks: Unlock permanence (app sandbox) or Make permanent (provisional vault), then Confirm? within four seconds.
- Empty this vault, walled vaults only, also two clicks: the second reads n chronicles will be erased — confirm? The tooltip: Erases every chronicle in this vault and keeps the vault itself. Irreversible — nothing re-creates what is removed. It is greyed on an empty vault. The receipt reads n chronicle(s) erased or Emptying failed — see the logs. If the vault has live watched folders, an amber line warns: ⚠ Watched folders will be re-ingested at the next census. Detach them in Sources first if you want this vault to stay empty.
There is no gesture to wall a vault off again once it is unlocked or made permanent. The whole model is in App sandbox vaults.
Chips
The metrics the app declared for its tile, or n chronicles, plus the estimated RAM footprint. A value not yet measured shows …, never 0.
RAG attention
RAG attention, a slider from 0 to 100 in steps of 5 (100 by default; a vault with no stored weight counts as 100). The tooltip on the caption: How much this vault counts when memory is searched. 100% = full weight. Lower it and its results score lower against the others. At 0 the vault stops answering: it is left out of retrieval, and it keeps recording everything that arrives in it. An Off button sets 0; muted, it reads Max and sets 100.
A vault at 0 keeps ingesting what its watched folders bring. It only stops being consulted. The rule and its history are in RAG attention.
Sources
The section is open by default; its badge counts the watched folders. Under it: A vault stays empty until a folder feeds it. Attach one and its files are read, cut into chronicles and vectorised — automatically, and again whenever they change. An app sandbox says instead This vault is written by its app, not by watched folders.
With at least one source, a header shows the vault path, a live pulse with In progress… while the pipeline works, and ⟲ Rescan (Scanning… while it runs): Purges chronicles and re-ingests all files from scratch. Its receipt stays five seconds: ✓ Rescan started — n chronicles purged or ⚠ Error: followed by the reason.
Each watched folder is a row: a green or grey dot (enabled or not), the path, a chip when a spine is forced, the description when set, and three buttons:
☰opens the documents taken into memory;✎Edit watch settings (spine, rule…) reopens Configure DocWatch prefilled;×Remove source detaches the folder at once, with no confirmation.
Without a source: No source configured. Add a folder for Mnemosyne OS to auto-vectorize. The dashed Add a folder to watch… button opens the system folder picker, then Configure DocWatch.
Below the rows, when there is something to show:
- Ingestion queue: one line per folder waiting its turn, x / y files with a bar for the active one, n files — waiting for the others, and an ETA. Bulk catch-ups run one folder at a time; a single saved note never waits behind them.
- Recent Activity: the last eight events, the file name coloured by event type (detected, skipped, embedding, ingested, deleted, error), the vector dimension, the time. An error shows its message.
Documents taken in
The ☰ button opens Documents taken in for that folder: a Search a
file box, a markdown chip, and one row per file with a status chip when
it is not simply active (source gone, moved, updated, waiting for
embedding, waiting for OCR), the relative path, size and date. Sixty rows
per page, shown of total in the footer and Show more for the rest.
Clicking a row opens it on the right: a .md is rendered like a note, with a
Source / Rendered toggle, and Open in the system hands it to the
OS. A file gone from disk says The file is gone from disk. What it wrote into
this vault is still there. A file the app could not read says so (This file
could not be read: and the reason), never shows as empty, and a very long
one is clipped at 200 000 characters with a line saying so. An empty folder
reads Nothing from this folder has reached memory yet.
Spines
Folded by default. A spine is the NATURE of a memory — a note, a decision, a piece of source code. It is what lets a search prefer the right kind of thing rather than merely the right words. An app vault with nothing yet says No chronicles yet — the app hasn't written anything. The concept is explained in Chronicles and spines.
Spine Types in DB, with a ⟳ refresh (its tooltip, Refresh, is in
English) and ⚡ Reclassify: Re-derive spine types from each source file.
Chronicles with no file are left untouched. Reclassify is a two-step
button. The first click is a dry run: either Nothing to reclassify — every
file-backed chronicle already carries the right spine. or a red preview,
n chronicle(s) would change spine type, m left untouched (no source file).
This overwrites the current types and cannot be undone., with a Cancel
link; the button then reads Reclassify n — confirm, then Reclassifying…
The receipt is ✓ n/total reclassified or ⚠ Error:.
One row per spine: a colour dot, the raw spine id, its count and share, a
vectorisation bar with n/total vectorized (pct%), a native colour picker
(Change this color in the Neural Map) and ↺ (Restore the default
color). The colours live on this machine only. With nothing vectorised: No
chronicles vectorized — launch a Rescan. The footer reminds you that
Modified colors apply upon the next ↻ Reload of the Neural Map (see the
Neural Map).
Directory Rules (a disclosure whose badge counts the rules, in English):
If a path segment matches a directory name, the spine type is assigned with
priority. Example: e.g. components → FEATURE. A text field
(directory_name), a select of spines (SOURCE_CODE, ARCHITECTURE, DOCUMENT,
BUGFIX, FEATURE, SECURITY, REFACTOR, GIT_HISTORY, SESSION), + Add, and a
✕ per rule. Rules are kept on this machine and only applied by Reclassify:
After adding rules → click Reclassify to apply them to existing chronicles.
Assign spines (no re-ingestion), a collapsed disclosure whose badge counts the undoable pass(es): Every chronicle already carries its embedding, so the engine can sort them by meaning. Describe what a spine is for — that sentence becomes its prototype — then preview. Nothing moves until you confirm, and any pass can be undone. One row per spine holding chronicles or carrying a description (the rest behind Show the n empty spines / Hide the empty spines): a colour dot, the spine's name, its count, and a description field (What belongs in this spine…, saved when you leave it). Preview runs a dry run and prints a red box: n of m chronicle(s) would change spine. k stay as they are — no prototype claimed them clearly enough., with a chip per target, and when relevant n already sit on their best-matching spine — nothing to move there., n chronicle(s) live in another vector space and were not examined., n description(s) ignored: your current embedder answers in a different space than these vectors. The button then reads Move n — confirm (with a Cancel). The receipt: n chronicle(s) moved. Every pass gets an ↺ Undo n button, dated in its tooltip, whose receipt is n chronicle(s) restored. Refusals: No spine has a prototype yet — describe at least one, or pin examples. and This vault holds no vectors yet.
Reclassify rewrites spine types from file paths and cannot be undone. Assign spines sorts by meaning, previews first, and every pass can be undone. Reach for the second one first.
Governance
Folded by default.
Protection: two buttons, NORMAL and MAXIMUM (with a lock). NORMAL reads Ordinary memory: read in default-scope answers, on any route.; MAXIMUM reads Protected vault — AI agents restricted, never auto-mixed, dedicated window. The choice applies at once. Only these two levels exist: an old OPEN value is shown and treated as NORMAL. What MAXIMUM blocks, and what it does not, is in Maximum protection.
Delete vault: Permanently delete this vault. Its memory will be destroyed. The red button opens a confirmation:
- Delete "name"?
- ⚠ This destroys the vault's memory — all chronicles, embeddings and snapshots. This cannot be undone.
- A checkbox (not for app sandboxes), Also delete the document files on disk. Unticked: Your document files are kept — only Mnemosyne OS's memory of them is removed. Ticked: The folder and all its documents will be permanently erased.
- Type the vault's name to confirm: with the name in red; the match is not case-sensitive and arms the Delete vault button. Cancel closes.
Deleting a vault also removes its sub-vaults.
Left unticked, deletion removes what Mnemosyne OS remembers and leaves your documents where they are. Ticked, the watched folder itself is erased from disk.
Sub-vaults cannot be created from this panel in Settings; the Vaults widget offers + Sub-Vault.
Creating a vault
+ Vault (or Add a sub-vault from the widget) opens a dialog:
- Vault name, required, and Description (optional).
- A type grid: DEV ⚙️, RESEARCH 🔬, SOCIAL 🌐, PERSONAL 🌙, CREATIVE ✨, DREAM 💭, CUSTOM 📦 (the names are in English in every language). CUSTOM by default. The type sets the icon and the tint.
- Provisional vault, a checkbox, off by default: A scratch space: empty it in one gesture, and it stays out of default-scope answers, the neural map and the dream layer until you make it permanent.
- Cancel and Create (… while busy). An error shows inline.
Once created, the dialog becomes the attach step: "name" is created. Feed it now? A vault stays empty until a folder feeds it. Point it at one and its files are read, cut into chronicles and vectorised right away — and again whenever they change. You can also do this later, in the vault's Sources. Choose a folder… opens the folder picker, then Configure DocWatch; Later closes. If the picker cannot open: The folder picker could not open — see the logs. Nothing is attached without going through the configure-and-preview dialog. The whole walk-through is in Your first vault.
Configure DocWatch
The dialog is titled Configure DocWatch — name. It has two steps.
Step 1, the configuration:
- Folder to watch: a path field (Folder path…) and a folder button that opens the picker.
- File extensions: a comma-separated list. From the attach step the
default is
.md,.txt,.pdf,.docx,.xlsx,.csv; from Sources it is.md,.txt,.pdf,.docx,.xlsx,.ts,.tsx,.py,.json,.yaml. When image memory is on and the folder is new, the image extensions are appended to the untouched default. Under the field, one line about images, if the app knows: Images will be ignored — enable image memory in Settings to analyze them, or Images in this folder will be analyzed — vision engine ready ✓, or Image memory is on, but the engine is not installed — images will be skipped (Settings → Images). - Description (optional): What this folder holds — helps classify its files.
- Force a spine type (optional): Leave empty to classify automatically.
- Auto-approve patterns (optional):
e.g. *.md, invoices/* — comma-separated. As soon as it holds something, Maturation delay (hours) appears (24 by default) and the hint explains the standing rule: Files matching these patterns are ingested without asking, once they have stayed unchanged for 24 h. Everything else still waits for your approval. - Cancel and Scan and preview (Scanning…), greyed without a path.
Step 2, the preview: Files detected in this folder: and a list of relative paths, each with its spine chip and the reason in italics, or No file matches these extensions. Then Back or Save this watch (Saving…). Saving switches the watch on at once.
Refusals: This folder overlaps an already-watched source: path. One folder,
one watch — remove the other target first., Scan failed., Could not save
this watch. Editing an existing folder with ✎ prefills every field, and
saving replaces the whole watch.
A file whose extension is not in the list is silently left out. Images need the image extensions present and image memory switched on. Depth (3 levels) and ignore lists have no field in this dialog.
The auto-approve rule, its quarantine and how gated waves work are described in DocWatch.
Rebuild all
The header button opens a dialog:
- ⟲ Purge & rebuild all memory?
- This permanently purges the vectorized memory of all n vault(s) and re-indexes every declared folder from scratch, re-checking spine types. It can take a while on large folders. Your source files are never touched.
- Cancel / Purge & rebuild.
While it runs: Rebuilding memory…, Vault current/total — name, a progress bar and n chronicles re-vectorized so far. Clicking outside is ignored. At the end: Done — n chronicles re-vectorized across m vault(s). and Close, or Rebuild failed: with the reason.
It rescans every vault in turn, roots and sub-vaults, and it no longer resets attention weights: a muted vault keeps recording, so the rebuild reaches it. This is the gesture the AI & Models page asks for after a change of embedding model.
The promise is that your source files are untouched. Chronicles that no folder can regenerate (facts extracted from conversations, what an agent ingested directly) are purged with the rest and are not rebuilt.
Watched folders: live state
The header's Watched folders button opens Watched folders — live state, with a ⟳ Refresh button.
- Reading watcher state… while it reads. If the engine is down: The DocWatch engine is not running — nothing is being watched., or DocWatch engine failed to start: with the reason. Without any watch: No vault has a watched folder.
- One block per vault, with a live dot. When a catch-up wave runs, a box reports it: Counting candidates…, Awaiting your decision, Catch-up in progress, Catch-up in progress (slowed), with x / y files, a bar, n files/min, an ETA and n error(s).
- One line per folder: the path, a state badge (⏸ Disabled, ✕ Path not found, ● Watching, ◌ Recovery pending (≤ 60s)), chips for Depth and the extensions, ⏸ n deferred (dated in its tooltip) when files wait for your approval, ⚖ auto-approve rule (tooltip Standing rule: patterns — quarantine n h), and the last event as type · file · time or No event this session.
Elsewhere
Encryption at rest of the vault databases is not on this page: it is on the Backup page. How the chat picks which vaults answer is set from the chat itself and reflected in the attention slider above.
Traps
- Attention 0 mutes answering, never recording.
- Rebuild all, Rescan and Reclassify destroy vectors or spine types and cannot be undone. Assign spines is the reversible alternative.
- Remove source (
×) is immediate, with no confirmation. - Emptying a walled vault does not detach its folders; they re-ingest at the next census.
- Unlocking permanence, or making a provisional vault permanent, is one-way.
- Deleting a vault needs its name typed; the checkbox erases the folder on disk.