Everything an agent can do with moments, a person can now see and change
in the app.
- Rule editor: a moment picker beside the trigger. Catalog moments are
ticked; a named procedure's `skill.<name>` is typed and checked as the
server checks it. `moments` is always sent, so unticking the last moment
unmounts the rule.
- Settings, Moments section (General tab): for each moment, what it
means, the actions that reach it on this install (shipped ones can be
switched off, the install's own removed), how many rules are mounted on
it, and deliveries and agent opens over the window. Below that: named
procedures with mounts, switched-off defaults with Restore, and a form to
add an action.
- retrieval_telemetry.moment_usage: per moment, `delivered`, `rules`,
`opened` (agent pulls after the first delivery there; an upper bound, as
by_source is) and `last_delivered_at`. No ratio, because a mount is a
person's statement, not a ranker's guess. Guarded on its own, and also
reported in retrieval_summary as `moment_usage`.
- rulebooks.mount_counts; mounted_moments now derives from it.
- GET /api/retrieval/moments carries `mounted` and `usage` (?days=).
DELETE /moments/mappings also reads the mapping from query parameters,
since the browser's DELETE sends no body.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A rule mounted on a moment now reaches the session when an act reaches
that moment, with no semantic match involved:
- run_moment_arm on the pipeline: a lookup, not a ranked search. Each
line names the moment and the act that reached it ("at work.deliver,
reached by `git push`"), so a misfire is visible where it lands and
can be unmapped in-session. A repeat is cited, not quoted; fresh
rules are recorded surfaced under source moment_rule with the moment
in detail. No retrieval_logs row, as for the other lookups, so no
latency is persisted for this arm.
- rule_scope: a rule's home clause, moved out of semantic_search_rules
so the moment lookup scopes by the same one.
- rulebooks.rules_on_moments / mounted_moments.
- The plugin door: a catch-all PreToolUse hook (scribe_moment.sh). It
keeps /moment-tools' answer on disk for five minutes, so a call to a
tool that cannot reach a mounted rule sends nothing, and an install
that has mounted nothing sends one request per window. It shares the
rules ledger with the other arms and fails open silently.
- The MCP door: Scribe's own tools named by the shipped mappings carry
moment_rules in their response, so a client without the plugin gets
them too. The hook skips those tools. A guard pins the attach on
every one.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rule_moments (migration 0117) records which moments a rule arrives at, by
catalog name, cascading with the rule. rule_detail, the one seam every
rule door already returns through, gains moments beside system_ids: None
leaves the mounts alone, a list replaces them. get_rule and both
list_rules doors read them back, batched per page.
All five MCP rule/preference writes and the three REST ones take moments
and validate them before their create or update. An unknown name is
refused with the catalog listed and leaves no half-made rule behind; a
parity test pins that ordering on every door.
Backup v22 carries the mounts as a join table remapped through the rule
map; a real-Postgres round trip checks they land on the restored rule.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>