Open work
altme.org
altme.org is a separate initiative: a person’s own memory, held as theirs, portable between applications, granted to an assistant by consent and withdrawn the same way. A draft protocol at version 0.1, published for comment, and a reference implementation its authors describe as not yet production-grade. No adoption to report, and nothing measured.
- Protocol
- Draft v0.1, for comment
- Implementation
- Reference
- Adoption
- None
- Licence
- Open
altme.org not yet published
A separate initiative. The draft and the reference implementation are published there, not here; this page states the intent and the obligations, and describes no system.
Where the work stands
Draft, reference, and nothing claimed
altme.org is at the stage of a draft protocol, version 0.1, published as a request for comments, alongside a reference implementation whose authors describe it as not yet production-grade, with hardening work outstanding. Neither is finished. Nothing about either has been measured.
- Protocol Draft · for comment
- A request for comments. It has the standing any document has before anyone has agreed to it, which is none.
- Reference implementation Not production-grade
- The reference implementation is described by its own authors as not yet production-grade, with hardening work still outstanding. It is not something to depend on, and no performance of any kind is claimed for it.
- Adoption None
- Nobody outside this initiative has implemented it. Nothing here should be read as a claim about who is using it.
- Measurement None
- Nothing on this page reports a measurement, a trial or a result. Where a claim about learning appears, it is marked as a position and should be read as one.
The test
A standard that only its author can implement is not a standard. It is a product with a specification attached.
Three things settle whether that is more than a preference: the licence, custody, and survival. Why this is published openly when the rest is not.
The argument, in five parts
Why a person’s memory should be theirs
Every assistant you use forms some picture of you. It has to; it cannot be useful otherwise. What you can establish from where you sit is less than what it holds: that something is retained, that you were not asked for it, and that you cannot take it with you.
Three things are wrong with that, and none is repaired by making the picture better. It is thin, because what one application has reason to learn about you is a small part of what is true about you. It is silent, because at no point did anyone ask. And it is not yours, because you can neither see it, nor move it, nor end it.
The asymmetry is worth stating exactly. You are the only party present in every one of these conversations and the only party who carries nothing across them. Each one begins again, and the cost of beginning again is paid by you, in repetition.
A picture a person cannot inspect cannot be corrected by that person, and a wrong inference does not merely persist, it compounds, because what comes later is built on what came before. So the argument here is not primarily about privacy. It is about who is permitted to be the continuous thing, and who is permitted to correct the record.
PrepGraph’s own products are among the applications this criticism is aimed at. Whatever they hold about a learner is not the learner’s to inspect, to move or to end today, and the demands set out below are ones we do not currently meet.
- The picture is thin
- What one application learns about you is shaped by what that application is for. Nothing joins the fragments, so no assistant meets the whole person, and the person is the only one who could join them. A test: ask an assistant something that depends on what you explained to a different one last month.
- Nothing was ever granted
- Context accumulates without a moment at which anyone asked and you agreed. Consent should be an event, not a condition of signing up. A test: name the moment at which you agreed. If there was no moment, nothing was granted, whatever the terms of service record.
- You cannot correct it
- You cannot see what is held, so you cannot say that it is wrong. Errors about you are kept where you cannot reach them. A test: ask what happens to a decision already taken on the strength of a record you were never shown.
What is being proposed
A draft open protocol, at version 0.1, published as a request for comments. Its subject is a memory that belongs to the person rather than to an application, and what an assistant should have to observe in order to be let near one.
It standardises one thing: the terms on which an agent is granted access to a memory belonging to somebody else, namely the person. It does not standardise what a memory is for, what an assistant ought to conclude from one, or what makes one good. A protocol that answered those would be answering questions it has no standing to answer.
Existing open work has settled how an agent reaches context that belongs to a service. Nothing settles how an agent reaches context that belongs to the person, on that person’s terms and revocably. The draft is about the second question and takes no position on the first.
What follows are the obligations the draft is trying to place on whoever holds a person’s memory. They are written as demands a person, or a school buying on a child’s behalf, could put to any supplier and expect a straight answer to. They are the whole of the proposal at this level; how such obligations would be met is not described here and will not be.
- The memory is the person’s
- Not an account record held on a person’s behalf by whoever is currently serving them, but theirs, with the application in the position of a guest. A guarantee in a document is only as strong as the implementations that keep it. A draft cannot enforce itself, which is the reason for the section below.
- Access is scoped
- A person should be able to let an assistant have some of what is held about them, for a purpose stated in advance, rather than all of it as the price of using anything. A test: ask a supplier what their application can still do when it is given less. If the answer is nothing, nothing was scoped.
- Access is revocable
- A person should be able to end a grant they made, and ending it should be an ordinary act rather than an exceptional one. The hard part: what has been read has been read. Revocation after the fact is an open problem for any design of this kind, and we have no answer to it we would defend.
- The memory is portable
- A person should be able to take their memory out and put it somewhere else, including into a system built by a competitor, without the incumbent having a say. A test: an export that can only be re-imported into the system that produced it is not portability.
- The person can see it
- What is held about a person should be visible to that person, in terms they can read. Legibility is part of the obligation, not a courtesy on top of it. A record disclosed in a form nobody can read satisfies the letter and defeats the point.
Why this is published openly when the rest is not
A property that publishes no methods is publishing a protocol in full. The two are different kinds of thing, and the difference is the point of this section.
A protocol is an agreement, and an agreement with one party to it is not an agreement. The obligations above become obligations only when somebody answerable to nobody here can implement them, and a person can move between the two implementations without asking either.
The interior is not published and will not be. The research on academic intelligence, and the way anything at PrepGraph is built, remain unpublished. We publish the interface and withhold the interior, and would rather say that plainly than let the openness of the one imply an openness of the other.
Our interest should be named as well. We would rather build on an interface we do not own than own one that nobody else uses. Whether that is more than a preference is settled by three things, none of which a reader should take on this page’s word. The licence, which travels with the draft and is not restated here: it is worth nothing unless it lets anyone implement, extend or fork the work, including into a product that competes with ours, without asking us. Custody: the draft is held today by the company that wrote it, which is the wrong place for it to stay, and no body outside the company has yet agreed to take it. Survival: if this company does not last, what has been published should remain implementable by whoever wants it, and nothing beyond that can honestly be promised.
What it has to do with learning
A learner’s context is the clearest case of something that should not sit inside one vendor. What a student has understood, where they stalled, the misconception they have carried for two years, the language they think in before answering in another one: today that belongs to whichever platform happened to observe it.
What moves with an Indian student is the mark. Marks transfer between schools, boards and tutors; they are the one portable artefact in the system, and they are a late scalar that cannot say what a student should do next. A teacher who inherits a section of fifty-odd in April receives last year’s marks and almost nothing about how they came about. The compressed summary travels and the understanding does not. That is backwards.
A learner should be able to carry their own context across a change of teacher, platform, medium or school. That is a position, not a result, and we are not in a position to present it as one.
- The question
- Does a learner who carries their own context across a transition get met at the right level sooner than a learner who begins again? The question is asked about one learner across one change of teacher or school, not about a cohort and not about a platform. Stated as a question because it cannot honestly be stated as a finding. No result is published here.
- What would falsify it
- If transitions go no better with carried context than without, portability is a case about a person’s rights over what is held about them and not a case about learning, and it should then be argued only on those grounds. That would not make the protocol wrong. It would make one of the arguments for it wrong, which is a different thing.
- Who holds the grant
- For a school-age child the grant is exercised by an adult, usually a parent or a school. A memory that is the person’s is, for a minor, administered by somebody else, and the person it describes is the one party in the room without a say in it. The draft does not resolve this. Every design we have considered either gives a child a power they cannot yet use or gives an institution a power over a child it should not have.
- The risk we have not solved
- A record that follows a child through school can harden into a label, and a portable memory is also a portable dossier. Visibility, scope and revocation reduce this and do not close it. A school should be able to ask any supplier what a child’s record says about them in five years’ time, and who can still read it then. The draft has no answer to that yet.
Status, and what it is not
altme.org is at the stage of a draft protocol, version 0.1, published as a request for comments, alongside a reference implementation whose authors describe it as not yet production-grade, with hardening work outstanding. Neither is finished. Nothing about either has been measured.
It is not ratified. No standards body has taken it up, no organisation other than the one that wrote it stands behind it, and nothing about it has been certified by anybody. There is no adoption to report, and this page would rather say so than describe interest as though it were uptake. The draft will change, the reference implementation will change with it, and anything built against either should expect to break.
Comments are invited where the draft is published. The useful ones are not corrections of wording. They are the ones that say a guarantee is stated wrongly, or that no honest implementation could keep it, or that the whole shape is wrong and a simpler design reaches the same promises to a person. If somebody else’s design achieves these guarantees more simply, the right outcome is that this draft is abandoned in favour of it. That outcome would be a success, and it is worth writing down now, while it is still cheap to mean it.
- Draft, not standard
- A request for comments. It has the standing any document has before anyone has agreed to it, which is none. Read it as a proposal about obligations, not as a specification you can rely on.
- No adoption claimed
- Nobody outside this initiative has implemented it. Nothing here should be read as a claim about who is using it. When that changes it will be reported as a fact with names attached, or not reported.
- No stability guarantee
- The reference implementation is described by its own authors as not yet production-grade, with hardening work still outstanding. It is not something to depend on, and no performance of any kind is claimed for it. Expect breaking change without notice while the draft is open.
- Not a product
- This is a separate initiative and nothing on this page is an offer of anything to anyone. No system is described here, ours or anyone else’s. Where our own products appear above, it is to place them among the ones the argument is aimed at.
Separate initiative
Where the draft is published
altme.org is a separate initiative. This page states its intent and the guarantees it is trying to make. It describes no system, and that absence is deliberate rather than incidental.
altme.org not yet published
The domain is held and the work described on this page exists. Nothing is published at that address yet, so it is named here rather than linked — a page arguing for openness should not be the one shipping a dead link.
What a useful comment is
The draft is published as a request for comments. The most useful comment is one saying that a guarantee is wrong, or that no honest implementation could keep it.
Continue
The same question, asked about a learner
The obligations above are stated on behalf of a person. What one of them would have to mean for a learner — and what would still be missing — is the subject of the memory page.