The test for any new case
Would a second party want to know where this came from? If yes, it is knowledge and belongs here. If no, it is memory — still supported, as a private namespace with no review gate.
memory one principal · byproduct of interaction · goes stale → private namespace, approvals: 0
knowledge authored · has a truth condition · read by others → sources, reviewer, version8 cases
Treasury Agent
treasury.kestrel.ethorganisation · privateWho
Crypto-native companies, DAOs and funds that hold a treasury on chain
Why not a database
A treasury recommendation is only as good as the policy and the facts behind it, and both change. At Kestrel the policy is a reviewed namespace: “keep at least 18 months of operating runway in USDC”, “no single DeFi protocol may hold more than 15% of treasury assets”, “payroll needs ~$420k in USDC on the operating Safe by the 1st”. Each claim cites the document it came from (Treasury policy v3) and carries the CFO’s review. When the agent says “rebalance”, anyone can see which policy version and which balances it read.
How it works here
kestrel.eth owns the namespace; cfo.kestrel.eth reviews; treasury-agent.eth may propose. The agent monitors balances and liquidity, reads the policy, and proposes a recommendation — it does not move funds. Acting stays a separate, human-approved transaction, which is the line this product draws everywhere: it learns, it never acts.
Status
Partly live: the Ethereum wallet source reads holdings and the protocols a treasury uses. The recommending agent is not built yet
openOn-Chain Monitoring Agent
watch.kestrel.ethorganisation · privateWho
Security and finance teams watching wallets, contracts and transactions
Why not a database
Unusual only means something against a written-down normal. “The payroll Safe pays contributors on the 1st of each month; outflows on other days are unusual.” “The treasury multisig is 3-of-5; a signer change is always worth an alert.” “The vesting contract releases to known recipients only.” Kept as reviewed claims, normal has an owner and a version, so an alert can say which rule it broke and who wrote that rule.
How it works here
watch-agent.eth reads the chain against the current version and surfaces what does not fit. When normal changes — a new signer, a new payroll date — the agent proposes a supersession and cfo.kestrel.eth lands it; the old rule stays in history.
Status
Model ready: the namespace, review and supersession are live. The alerting agent is not built yet
openPortfolio Intelligence Agent
portfolio.kestrel.ethorganisation · privateWho
Anyone who wants to ask about holdings, transactions and yield in plain language
Why not a database
Questions like “what did we earn in yield last quarter?” or “when did we first stake?” need a history, not a snapshot. Positions become versioned claims with their sources — tx hash, protocol, date: “Kestrel staked 200 ETH through Lido in March 2026.” Context a block explorer cannot give is a claim too: “The USDC in Aave is the runway reserve, not a trading position.” Any assistant the owner allows can answer from it, and it survives switching portfolio apps.
How it works here
The Ethereum wallet source reads an address through Blockscout’s public API — no key, no cost — and writes what it holds and which protocols it uses; portfolio-agent.eth adds context. Supersession records a position that changed rather than overwriting it. An assistant answers with knowledge_search and cites each claim it used; “why do you think that?” is knowledge_why.
Status
Live for Ethereum: connect a wallet and holdings and protocols land in portfolio.<your name>.eth. Yield and full transaction history are next
openResearch communities
cancer-research.eth → trials.cancer-research.ethpublicWho
Researchers, labs and review boards; every agent that answers questions about the field
Why not a database
Provenance and review are the product. “Olaparib, a PARP inhibitor, is approved for BRCA-mutated advanced ovarian cancer” is worth citing only with its source (the FDA approval, December 2014), who proposed it and who checked it. A claim that changed because a source was found wrong is a supersession with the old value kept.
How it works here
The owner registers the root and hands children — trials, immunotherapy — to their own owners and reviewers. Anyone proposes with papers, trial registry entries or regulatory approvals as sources; automated review flags duplicates, contradictions and missing sources; oncology-review.eth lands. Agents read by name.
Team coding conventions
conventions.acme.ethorganisationWho
Engineering teams using several AI coding agents
Why not a database
“We use pnpm, not npm” is not memory. It is a team convention with an owner, a reason and a date it changed — authored, contested, versioned. Today it lives in one vendor’s store for whichever teammate happened to say it. As a namespace every agent on the team reads the same one, and a change is a proposal a maintainer lands.
How it works here
Owner registers conventions.<org>.eth (kind: organisation, approvals ≥ 1). An adapter tells each agent to knowledge_search before answering and knowledge_propose after learning a convention. Reviewers land; push publishes on an interval.
Composed personal + shared knowledge
food.rishikesh.eth + japan.travel.eth + tokyo.food.ethpersonal + publicWho
Assistant builders; end users who want their AI to not start from zero
Why not a database
Three owners, one answer, no data ever copied into the assistant’s vendor. The personal namespace is private and encrypted; the shared ones are public and reviewed.
How it works here
The agent resolves each name, reads the current version, composes. It could not modify any of them; it could propose.
Organisation knowledge
company.ethorganisationWho
Companies using several AI vendors
Why not a database
Portable across the vendors the company uses; revocable by re-keying; auditable by version. Wrong answers have consequences, so the audit trail is the point.
How it works here
Private namespace, internal reviewers, interval publishing. Agents on any vendor read the same version.
Agent-maintained namespaces
research.ai.ethpublicWho
Teams running autonomous research or monitoring agents
Why not a database
Agents propose; humans approve; every agent claim is attributed and reviewable. An agent is a source like any other.
How it works here
knowledge_propose from the agent; automated findings first; a human reviewer lands.