The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Mneme Decision MCP listing page.
Mneme is an open decision and control layer for agentic software development.
It turns durable engineering decisions into agent context, deterministic enforcement, and inspectable enforcement results across AI coding agents, repositories, and CI workflows. Architecture is the first supported decision domain: Mneme prevents architectural drift by turning architectural decisions and ADRs into deterministic guardrails across coding agents, repository mutations, generated rules, and CI gates.
Where is your architecture actually enforced? Run the Architecture Audit to see which decisions are protected, which can become deterministic guardrails, and which still depend on someone remembering the rules. Try it →
Mneme is the decision layer behind that drift-prevention mechanism. It keeps recorded engineering decisions active as AI coding systems propose and modify code, instead of leaving ADRs as passive documentation.

Solid surfaces ship today; dashed surfaces are planned. Support levels per integration: integrations matrix.
Current phase: Layer 1 validation. Retrieval, enforcement, and benchmark semantics are governed by the accepted architecture and freeze record. See Current Phase before changing core behavior.
Mneme separates architectural guidance from deterministic enforcement:
The same input and governed decision state produce the same enforcement result. Mneme does not depend on an LLM judge for its core allow/warn/fail decisions.
Mneme is not a general-purpose vector store, conversational memory system, autonomous coding agent, or deployment observability platform.
Requires Python 3.11+.
Verify the CLI:
For repository development:
Mneme exposes the Decision Index over a local MCP server so MCP-capable clients can propose candidate architectural decisions and query decision state without gaining authority to change that state.
Install the optional MCP dependency:
Start the local stdio server with the proposal store enabled:
Optionally add a canonical ADR corpus. Mneme validates and precedence-resolves the corpus before the server starts; invalid or ambiguous ADR state fails closed rather than serving a degraded authority view.
The MCP surface is intentionally frozen to six tools:
decision.proposedecision.propose_batchdecision.getdecision.searchdecision.applicable_todecision.traceProposal tools create non-authoritative proposals only. Read tools query proposal and canonical decision state. MCP deliberately exposes no accept, reject, activate, supersede, exception, bypass, or trusted-evidence authority.
Human authority remains explicit through mneme decision proposals | show | accept | reject. Accepting a proposal materializes a canonical decision; it does not activate protection or run the Architecture Audit.
See ADR-027 and the v0.9.0 release notes for the authority boundary and release contract.
See where your architecture is actually protected — and where it still depends on people remembering the rules.
Mneme audits your repository and shows which architectural decisions are:
Run an audit:
For a Mneme-ready decision, validate the proposed protection before enabling it:
Then explicitly activate it:
Mneme only reports a decision as Protected after it can verify that real enforcement is in place. The full activation contract is documented in Protection Activation.
Initialize a project-local decision corpus:
Record one architectural decision:
Create a proposed input that violates it:
Run the deterministic check:
In strict mode, the prohibited YAML proposal returns a FAIL verdict and exit code 2. A compliant JSON proposal returns PASS and exit code 0.
The CLI is the common enforcement surface. Agent integrations translate their native events into the same Mneme decision and enforcement model.
mneme setup initializes Mneme in a repository without changing how the team works: it creates or detects project memory, detects supported agent environments, and reports protection readiness — all without enabling any blocking enforcement. Setup never turns warn/observe behavior into blocking behavior; activation of preventive enforcement is always a separate, explicit decision.
Optionally record an opaque Architecture Audit reference so the setup can be attributed back to a saved Audit baseline:
Setup is idempotent: rerunning it against an existing Mneme project leaves valid configuration untouched.
Mneme applies governance at the earliest reliable boundary a workflow exposes:
These boundaries are complementary. An integration only claims the surfaces that have been implemented and validated for that harness.
Decision retrieval answers: which architectural decisions are useful as guidance for this task?
Enforcement answers: does the proposed change violate a governed rule that applies here?
Those concerns are intentionally separated. See ADR-017, ADR-019, and ADR-020.
The authoritative support matrix lives in docs/integrations/README.md. The labels below are evidence levels, not interchangeable marketing terms.
| Support level | Surface |
|---|---|
| Native integration | Claude Code |
| Native integration | Claude Agent SDK |
| Native integration | Google Antigravity |
| Native integration | Codex CLI |
| Native integration | Kiro CLI 3.0 / v3 |
| Validated compatibility | Paperclip — CLI and ACP transports, no adapter required |
| Rules export | Cursor |
| CLI-based CI gate | GitHub Actions, GitLab CI |
| Experimental | OpenCode |
| Planned | Deep Agents middleware POC |
Each integration documents its actual blocking boundary, bypass paths, degraded behavior, and validation evidence. Start with the integration matrix, not assumptions based on another harness.
Mneme can compile architecture decisions into structured governance records rather than treating ADRs as passive prose.
The repository governance source of truth is .mneme/project_memory.json. The ADR import path preserves explicit source provenance where available so typed rules can be inspected and enforced consistently.
See:
Three principles govern the current mechanism:
The current Layer 1 scope, frozen surfaces, accepted amendments, experimental work, and deferred Layer 2 work are maintained in docs/architecture/current-phase.md.
Do not infer architecture from this README when a linked ADR or architecture document is more specific.
Mneme's benchmark is a regression and integrity instrument for retrieval and enforcement behavior. It is not a general model-quality benchmark.
The benchmark keeps retrieval and enforcement scoring distinct so changes cannot silently improve one surface while regressing another.
See:
More examples: mnemehq.com/demo
Before changing retrieval, enforcement, applicability, conflict handling, or benchmark semantics, read the architecture and ADRs that govern that surface.
Core behavioral changes may require the repository's charter-amendment procedure. Documentation, tooling, integrations, and examples do not automatically authorize changes to frozen behavior.
MIT. See LICENSE.