Field
Draft v0.1 · design only · will change

The Field protocol

SMTP for memory.

A public overview of the Field protocol, draft v0.1 (October 2026). It describes how one person's lifelong memory can be stored by any conforming host, read by minds and businesses only through grants, and shared with other people one moment at a time.

This page is a readable summary, not the specification. Nothing here is implemented as a standard, frozen, or final. The full draft is available on request: field@jeffers-seven.com.

Principles

Seven rules the rest follows.

  • 01One Field per person, for life. The memory belongs to the person, not the app, the host, or any assistant.
  • 02Any conforming host. A host stores and serves a Field; it is not the Field. You can move hosts without the old host's cooperation.
  • 03Grants travel, data doesn't. Minds and businesses read through scoped, expiring, audited grants, never a copy of the whole Field.
  • 04Side by side, never merged. In a shared moment, each person's contributions stay theirs, attributed, and withdrawable only by them.
  • 05Relationships are private and one-sided. How you label someone stays in your Field and is never sent to them.
  • 06Reuse before invent. OAuth, DPoP, Rich Authorization Requests, W3C Verifiable Credentials, passkeys, and MCP wherever they fit. New schema only for moments and the consent grammar.
  • 07Say what the math enforces. Every safety rule is labeled C cryptographic (holds even against a malicious host) or H host-trust (holds on hosts that follow the standard).

The objects

Five things the protocol defines.

1. The Field

One person's append-only, signed, encrypted event log, plus a deterministic "fold" that turns the log into current state. Owner device keys are generated in secure hardware and never exported. Each counterparty sees a different pairwise identifier, so contexts can't be linked unless the owner links them. A Field can be exported as a bundle and imported on another host with the same result.

Recovery is designed so that losing a phone isn't losing your life's memory, and so that recovery can't be used against you. Recovery that doesn't start from one of your own devices waits 7 to 14 days, notifies every device, and can be cancelled. A separate device-held key class protects the most private spaces, which recovery can't reach by design.

2. Events

Everything is an event: a signed envelope (writer, scope, key id, time, encrypted payload, signature) around a payload with a domain, type, entity, and summary. Canonical JSON (RFC 8785) and ES256 signatures, with room for post-quantum hybrids. Nothing is silently overwritten: a change supersedes an earlier event, and conflicts stay visible.

3. Minds and grants

A mind (Claude, ChatGPT, Grok, Siri, your own agent) joins by a bind ceremony approved on one of your devices. Every new reader starts with a 24-hour read delay that you can see and cancel. After that, it reads only what a grant allows:

{ "type": "grant.issued",
  "summary": "Specialist mind: read 'kitchen renovation', 72h",
  "data": {
    "grantee":  "v_3f1c…",
    "operator": { "kind": "vendor" },
    "read":     { "moments": ["m_kitchen"], "exclude": ["loc.live", "health.*"] },
    "write":    "propose",
    "not_before": 1791746400, "expires_at": 1792005600,
    "audit":    "every_read",
    "authorization_details_type": "fieldmemory.app/memory-grant" } }
  • Expiring by default. Every non-owner grant has an expires_at. Expiry and revocation stop new access within 60 seconds on conforming hosts.
  • Who runs the mind matters. Each grant records an operator: you, a vendor, or another person. A mind someone else runs is treated as that person: shorter grants (7 days at most), their relationship limits, and never live location.
  • Every read is logged as an audit event in your Field.

4. Moments

A moment is a shared object (a trip, a wedding, a graduation) that several Fields, and guests without a Field, contribute chosen items to.

{ "type": "moment.created", "entity": "m_8Zt1",
  "data": {
    "title": "Lake weekend, June 2026", "kind": "trip",
    "conveners": ["pw_K2…", "pw_N7…"],
    "policy": { "guests": "link_held", "reshare": false, "live_location": false },
    "key": { "distribution": "pairwise_wrap", "rotate_every_s": 604800 } } }
  • Never merged. Contributions live in each contributor's own Field and are re-wrapped to the moment key. Hosts must not merge, dedupe across people, or rewrite someone else's items.
  • Guests by link. People without a Field can join by an expiring invite link; their contributions wait for a convener's approval by default.
  • Quiet leaving. Moment keys rotate on a routine schedule with jitter, so leaving doesn't announce itself. The draft is honest about the limit: Field can make leaving look quiet, but it can't hide that you stopped showing up.

5. Relationships

A relationship (family, friend, professional, stranger, unknown) is policy you hold about someone: what they may see, which minds may ask, and how that changes on a schedule. It stays encrypted in your Field and is never transmitted. When someone asks for something they can't have, the answer looks exactly like "nothing found."

  • Schedules let access change over time, such as a child's Field loosening from a parent's at set ages.
  • Introductions need both sides to say yes, and neither learns who the other is first. Introductions to minors need a guardian, and introducers are rate-limited.
  • Places and businesses get capabilities, not identity: a hotel issues a room capability as a W3C Verifiable Credential bound to your pairwise key for that hotel, and you present it. Nobody can query your Field for facts about you.

Safety must-pass

No relationship or moment feature ships until these hold.

The draft treats abuse, estrangement, minors, and death as the hard cases. Each rule is labeled C (holds by cryptography, even against a malicious host) or H (holds on hosts that follow the standard). Passing them is a separate, tested certification level.

AreaMust-pass rules (summary)
Abuse and coercionRelationships are never transmitted C, and denials look like "nothing found" H. A duress unlock shares only items pre-marked safe C, and duress flags hide behind a separate secret in a fixed-size store C. Live location and real-time streams are off for every relationship and grant by default C. Ending things sends nothing to the other side C. A "who can see me" screen is two taps from home H.
EstrangementEach person withdraws only their own contributions; nobody can edit or delete another's C. Revocation is never described as un-sharing: what someone already saw can't be pulled back H. Objections can hide intimate or safety-sensitive items pending the author's decision H.
MinorsA child has their own Field from the start; guardians hold grants, not ownership. A private journal and a help-seeking space (counselors, hotlines) are under a key guardians and recovery can't reach C. At the age step the young person can rotate their Field's root alone C. Birthdates are signed and can't be quietly changed.
DeathRecovery and death use separate trustee sets C. A death claim waits 30 days with notices, can be cancelled, and releases only items marked for heirs first; nothing is destroyed before a second wait. Confirmed death revokes every outside grant.
StrangersAge or residency proofs are offered by you, never pulled by others. Unsolicited questions, including "over 18?", always get the same empty answer H. Strangers reach you only through an introduction or a guest link you made.

The draft states its own limit plainly: a coerced normal unlock of your phone defeats on-device protections. Field can make some things deniable and slow, not impossible, and the app should point to real safety resources rather than promise more.

What's open

Questions the draft doesn't settle yet.

These are open on purpose. If you work on any of them, we'd like to hear from you.

  • ?Death with no instructions. Should a Field default to sealed, with members keeping what they already had?
  • ?Minors. Default ages for each step, what "help-seeking" covers in different places, and how two guardians break a tie.
  • ?Duress. Whether to add a full decoy profile and a silent alert to a safety contact.
  • ?Read delay vs. same-day use. A 24-hour delay protects a seized phone but breaks same-day hotel check-in. One option exempts grants that read only a profile you pre-marked as presentable.
  • ?Who enforces the recovery delay. A quorum of trustees, a time-lock, or the host (which is only host-trust).
  • ?Group keys. MLS (RFC 9420) is the candidate for moments in v1.
  • ?Conversation import. Mapping to the Data Transfer Initiative's conversation-history schema.
  • ?A second, independent host. The protocol isn't real until someone other than us runs it and passes the conformance suite.

Interop

Built to meet Poppy.

We're drafting proposed extensions so any agent that speaks the Personal Agent Protocol (Poppy) can redeem a Field grant. Read the proposal.

Draft v0.1, October 2026. Full draft available on request: field@jeffers-seven.com. Not a published standard.