A Notion knowledge base AI agents write into autonomously, governed by a protocol strict enough that every entry is dated, sourced, and undoable in two minutes.
Many writers, one protocol, one canonical base — and deliberately no write path into Tasks.
The interactive data-flow diagram is built for a larger screen.
Open the full diagram in its own tab ↗
The raw material of a finance and M&A role is conversation — dozens of hours a week of it — and almost none of it survives contact with memory. Recordings aren't the answer either: they're enormous, unsearchable in practice, and mostly not durable. What is durable is the decision, the figure, the disagreement, and the date. This is the layer that holds those, in a form an agent can query six months later and a human can verify by clicking through to the exact source.
A PARA-structured knowledge base governed by a strict write protocol, so AI agents can author into it on their own without the base degrading into duplicates and stale claims. One hub database acts as a routing table: notes, tasks and goals all relate up into it and never sideways to each other, which is the only reason Area-scoped retrieval works. Knowledge lands in a Notes database filed by what kind of knowledge it is rather than who wrote it. Every note is a container for one subject that accumulates dated entries over time, carrying a subject-only title, a subtitle holding period and status, and a rolling summary an agent reads first to decide relevance. The protocol is the actual product. Every AI touch carries three marks — an authorship flag, a robot page icon, and a dated record comment saying what changed — and every entry names its source and states how much of it was read. On top of that sit the judgment rules: compound into an existing note rather than opening a new one, flag contradictory figures with both values and both dates and never reconcile forward, cross-link only on sameness, never edit a hand-made note, never put an action item in a note. Autonomy is split by reversibility: content writes commit freely because a dated entry with a record comment is a two-minute undo, while merges, re-homing, archiving and bulk relinking are proposed and never executed. Nothing autonomous has ever written to the Tasks database.
An audit found the guardrail leaking the exact thing it documented protecting. Thirty-two AI-authored notes were audited against eight quality axes. Three quarters of them asserted a state of the world in the present tense with no as-of date, and in several cases the assertion was flatly false — one note described a cancelled deal as heading toward a letter of intent, eight days after the cancellation. Another had two speakers swapped throughout, because it had been built from an auto-generated summary whose anonymised speaker labels were resolved by guess; two quotations in it appeared in neither the transcript nor the summary. Worse, material in the absolute-exclusion category was sitting in ten locations across four notes — including one note whose own disclaimer claimed that material had been deliberately excluded. It had not been. The lesson that changed the rules generalises past this system: a control that records only its firings cannot distinguish "it held for eight weeks" from "it never triggered on the case that mattered." Silent exclusions now get a deliberate positive test against a known case every quarter.
Everything systemic traced back to a single day. The failure rate by era is the finding worth printing. Twenty-one of the thirty-two notes were generated in one day from the historical corpus, before the coverage, provenance and grounding conventions existed. Coverage statements: zero percent in that cohort, one hundred percent after it. Summary-sourced content: half that cohort, none after. The conventions were not a hypothesis under test — they were already working, and the defect was concentrated in work that predated them. That reframed the remediation from "rewrite the base" to "date-stamp and flag the pre-convention layer, then leave it": roughly 450 mechanical edits across 30 notes, each recorded in a comment, with 48 contradictions flagged and none reconciled, because an audit that picks a winner destroys the evidence there was ever a question.
A wrong constant in two reference files, propagating quietly. The Notes database type value carries one space after its emoji. Two reference documents said two spaces, and a two-space create does not warn — it hard-fails with a validation error. Every note-creation routine built from those files failed at the write, and because the failure looked like a tooling problem rather than a data problem it got re-derived, wrong, more than once. The fix was not editing the line. It was collapsing two overlapping reference files into one, verifying against every row in the live database, and then stating the finding in a durable form: zero rows carry two spaces. The original write-up said "verified against 316 rows," which was true on the day and stale a week later. A count rots; a zero does not. The same instinct now governs the write path itself, which throttles hard at roughly twenty consecutive writes with a second, server-side throttle that does not clear by waiting — the correct response there is to checkpoint, end the run and come back, not to retry.
Content writes commit freely, because a dated entry with a record comment is a two-minute undo. Merges, re-homing, archiving and bulk relinking are proposed and never executed, because they are not. Nothing autonomous has ever written to the Tasks database.
When two sources disagree on a figure, the note carries both values and both dates, and nothing reconciles them forward. One audit pass flagged forty-eight contradictions and resolved none of them — an audit that picks a winner destroys the evidence there was ever a question.
This is the store and the rules. The scheduled agent that reads every recorded conversation and writes into it is its own project: Context Engine.