Nice architecture. Treating memory like reviewed code (not raw cache) is the right direction. The draft→promote split plus supersession links makes failures diagnosable instead of silently persistent. Curious if you’ve benchmarked contradiction-rate reduction or wrong-action rate before/after trust-gated promotion.