White Tree stores what your organization decided, not just what it wrote down: as causally linked, authority-scoped records your agents query at runtime. Dúnedain is the harness that captures and serves them inside the tools you already run.
Claude, Cursor, Copilot, your own agents: anything that speaks MCP gets the White Tree tools. Authority rides on the connection: an agent can only recall what its scope allows, and every read leaves a receipt.
{
"mcpServers": {
"whitetree": {
"url": "https://memory.acme.whitetree.dev/mcp",
"auth": { "type": "oauth", "scope": "commercial/pricing:recall" }
}
}
}
No forms, no knowledge-management chores. Dúnedain extracts decision trajectories from the work itself, runs PII through Strider, our redaction pipeline with a full audit trail, and writes to the record under explicit authority.
# the harness rides alongside, it does not replace sources: - slack: { channels: [deals-*, eng-*] } - github: { orgs: [acme-inc] } - jira: { projects: [PRICE, PLAT] } - salesforce: { objects: [Opportunity, Case] } extraction: mode: trajectories # decisions, not documents pii: strider # redaction-aware, audit-trailed authority: receipts: always
A recall returns the judgement: the call that was made, the alternatives that lost, what the world said back. Context assembly drops from reprocessing an archive to loading one thread, and the token bill falls with it.
import { WhiteTree } from "@whitetree/sdk"; const wt = new WhiteTree({ deployment: "acme" }); const thread = await wt.recall({ question: "Why did we choose usage-based pricing for APAC?", as: "agent:sdr-07", // authority checked on every read scope: "commercial/pricing", }); thread.decision; // the call, who made it, on what basis thread.alternatives; // what lost, and why thread.outcome; // what the world said back thread.receipt; // verifiable proof this recall happened
{
"id": "traj_01JD84QK7R",
"question": "Reprice the APAC enterprise tier?",
"evidence": ["slack:C0421/p1718329", "sheets:fin-model-v12"],
"alternatives": [{
"option": "Flat 8% uplift", "status": "rejected",
"why": "churn risk in AU mid-market cohort"
}],
"decision": {
"call": "Usage-based, $2k floor",
"by": "human:mtaylor", "at": "2026-03-14T09:12+10:00",
"authority": "commercial/pricing"
},
"action": ["jira:PRICE-214", "salesforce:cpq-3941"],
"outcome": { "observed": "2026-06-30", "result": "NRR +6pts" },
"revision": null,
"time": { "valid": "2026-03-14/..", "belief": "2026-03-14/.." },
"receipt": "sha256:9f2c81d0"
}
The unit of storage is the whole thread: question, evidence, alternatives, decision, action, outcome, revision, causally linked. Not rows. Not chunks. Not embeddings with metadata bolted on.
Two clocks on every record: when it was true in the world, and when the company believed it. So "what did we know when we decided?" is a query parameter, not a forensic project:
// what did we believe when we signed the deal? const then = await wt.recall({ question: "APAC pricing position", asOf: { belief: "2026-03-14" }, });
Agents never touch storage. Every call runs through the Dúnedain runtime, where authority, expiry and revocation are checked before anything moves, and every operation emits a receipt.
whitetree.recallThe thread for a question: decision, alternatives, outcome, provenance. Authority-scoped.
whitetree.searchGoverned search across trajectories. Results are filtered by what the caller may inherit, not post-hoc.
whitetree.traceFull lineage of a decision, from first evidence to latest revision, with every authority hop.
whitetree.captureWrite a decision into the record: append-only, linked to what it revises, evidence attached.
whitetree.actExecute an action in an external system under authority the runtime can prove.
whitetree.grantDelegate scoped, expiring authority to another agent, with a verifiable delegation chain.
The trajectory model is logical, not physical. The memory your agents see is identical in every deployment; only the perimeter changes.
Per-company isolated deployment on our infrastructure. Fastest start; your memory is never shared and never trains anything.
The engine and the harness inside your cloud account. Your keys, your network boundary, our operations tooling.
Fully private deployment for regulated estates: air-gapped options, Strider redaction at the boundary, every receipt auditable on your side.
Claude
ChatGPT
Codex
Copilot
Gemini
Cursor
Slack
Jira
Salesforce
Workspace
Notion
ZendeskTen design partner slots. Real deployments, agreed success criteria.
Talk to the team