The Field protocol
A public overview of the Field protocol, draft v0.1 (October 2026). It describes how one person's lifelong memory can be stored by any conforming host, read by minds and businesses only through grants, and shared with other people one moment at a time.
This page is a readable summary, not the specification. Nothing here is implemented as a standard, frozen, or final. The full draft is available on request: field@jeffers-seven.com.
Principles
The objects
One person's append-only, signed, encrypted event log, plus a deterministic "fold" that turns the log into current state. Owner device keys are generated in secure hardware and never exported. Each counterparty sees a different pairwise identifier, so contexts can't be linked unless the owner links them. A Field can be exported as a bundle and imported on another host with the same result.
Recovery is designed so that losing a phone isn't losing your life's memory, and so that recovery can't be used against you. Recovery that doesn't start from one of your own devices waits 7 to 14 days, notifies every device, and can be cancelled. A separate device-held key class protects the most private spaces, which recovery can't reach by design.
Everything is an event: a signed envelope (writer, scope, key id, time, encrypted payload, signature) around a payload with a domain, type, entity, and summary. Canonical JSON (RFC 8785) and ES256 signatures, with room for post-quantum hybrids. Nothing is silently overwritten: a change supersedes an earlier event, and conflicts stay visible.
A mind (Claude, ChatGPT, Grok, Siri, your own agent) joins by a bind ceremony approved on one of your devices. Every new reader starts with a 24-hour read delay that you can see and cancel. After that, it reads only what a grant allows:
{ "type": "grant.issued",
"summary": "Specialist mind: read 'kitchen renovation', 72h",
"data": {
"grantee": "v_3f1c…",
"operator": { "kind": "vendor" },
"read": { "moments": ["m_kitchen"], "exclude": ["loc.live", "health.*"] },
"write": "propose",
"not_before": 1791746400, "expires_at": 1792005600,
"audit": "every_read",
"authorization_details_type": "fieldmemory.app/memory-grant" } }
expires_at. Expiry and revocation stop new access within 60 seconds on conforming hosts.A moment is a shared object (a trip, a wedding, a graduation) that several Fields, and guests without a Field, contribute chosen items to.
{ "type": "moment.created", "entity": "m_8Zt1",
"data": {
"title": "Lake weekend, June 2026", "kind": "trip",
"conveners": ["pw_K2…", "pw_N7…"],
"policy": { "guests": "link_held", "reshare": false, "live_location": false },
"key": { "distribution": "pairwise_wrap", "rotate_every_s": 604800 } } }
A relationship (family, friend, professional, stranger, unknown) is policy you hold about someone: what they may see, which minds may ask, and how that changes on a schedule. It stays encrypted in your Field and is never transmitted. When someone asks for something they can't have, the answer looks exactly like "nothing found."
Safety must-pass
The draft treats abuse, estrangement, minors, and death as the hard cases. Each rule is labeled C (holds by cryptography, even against a malicious host) or H (holds on hosts that follow the standard). Passing them is a separate, tested certification level.
| Area | Must-pass rules (summary) |
|---|---|
| Abuse and coercion | Relationships are never transmitted C, and denials look like "nothing found" H. A duress unlock shares only items pre-marked safe C, and duress flags hide behind a separate secret in a fixed-size store C. Live location and real-time streams are off for every relationship and grant by default C. Ending things sends nothing to the other side C. A "who can see me" screen is two taps from home H. |
| Estrangement | Each person withdraws only their own contributions; nobody can edit or delete another's C. Revocation is never described as un-sharing: what someone already saw can't be pulled back H. Objections can hide intimate or safety-sensitive items pending the author's decision H. |
| Minors | A child has their own Field from the start; guardians hold grants, not ownership. A private journal and a help-seeking space (counselors, hotlines) are under a key guardians and recovery can't reach C. At the age step the young person can rotate their Field's root alone C. Birthdates are signed and can't be quietly changed. |
| Death | Recovery and death use separate trustee sets C. A death claim waits 30 days with notices, can be cancelled, and releases only items marked for heirs first; nothing is destroyed before a second wait. Confirmed death revokes every outside grant. |
| Strangers | Age or residency proofs are offered by you, never pulled by others. Unsolicited questions, including "over 18?", always get the same empty answer H. Strangers reach you only through an introduction or a guest link you made. |
The draft states its own limit plainly: a coerced normal unlock of your phone defeats on-device protections. Field can make some things deniable and slow, not impossible, and the app should point to real safety resources rather than promise more.
What's open
These are open on purpose. If you work on any of them, we'd like to hear from you.
Interop
We're drafting proposed extensions so any agent that speaks the Personal Agent Protocol (Poppy) can redeem a Field grant. Read the proposal.
Draft v0.1, October 2026. Full draft available on request: field@jeffers-seven.com. Not a published standard.