NTH

Quipu: A Governed Bitemporal Knowledge Graph Store

AuthorsSteve Brown

August 20, 2026 3 min read
Watch on YouTube
The one-line take

Quipu is a knowledge-graph store designed to ensure that agent-written facts are admitted, trusted, time-stamped, and auditable by construction.

Key results

0
Gated planted defects

The gated Census store retained 0 of 6 planted defects.

6
Ungated planted defects

The ungated control retained 6 of 6 planted defects.

7
Composition probes upheld

All 7 of 7 lattice composition probes upheld the non-widening contract.

512
DEMM-Bench property judgments

Content-level evidence reconstruction answered 512 of 512 property judgments.

87.5%
Container-presence overclaim

Container-presence baselines overclaimed by up to 87.5% of cases.

What the paper found

Quipu is a single-file, embeddable knowledge-graph store designed for agent-written data, replacing four permissive defaults with strict enforcement: writes pass a gate evaluated against the pending post-state; data, trust labels, verdicts, policies, and validation rules are bitemporal; named-graph authority composes through a non-widening lattice; and the governance specification, trace, and signed verdicts live inside the store, making audit a deterministic query. Its append-only EAVT log supports assert, retract, and tombstone operations, while Ed25519-signed verdicts preserve even denied writes after rollback. In the seeded Census benchmark, the gated store retained 0 of 6 planted defects, compared with 6 of 6 for the ungated control, and all 7 of 7 composition probes upheld the lattice contract. Historical replay re-derived 50 of 50 satisfied verdicts under the rules active at decision time, while 6 of 6 denials verified their rules-in-force. Against DEMM-Bench, content-level evidence reconstruction answered 512 of 512 property judgments with PSA 1.0 and overclaim 0.0, whereas container-presence baselines overclaimed by up to 87.5%. An agent study using Claude models found that every label and vocabulary refusal was corrected in one revision across 12 of 12 trials, although an authority gap exposed missing policy coverage rather than a storage failure.

Original abstract

Agents now write knowledge graphs, but knowledge-graph stores still carry defaults set when humans curated them: accept writes now and clean later, keep one time axis or none, treat every writer's facts as equally trustworthy, and leave governance to dashboards and middleware. These four defaults are individually convenient and jointly untenable under agent workloads. We present Quipu, an embeddable store that inverts all four: no fact enters except through a gate whose predicates evaluate the pending post-state; data, trust labels, verdicts, and the rules themselves are bitemporal; named graphs are the unit of authority and trust, composed under a lattice whose one invariant is that composition never widens; and the governance specification $Σ$, the trace, and signed verdicts are facts in the store they govern, making the audit $T \models Σ$ a query. We evaluate with Census, a deterministic multi-writer lifecycle whose single seeded run scores every research question against planted ground truth: the gated store ends with 0 of 6 planted defects versus 6 of 6 ungated; all 7 composition probes uphold the lattice contract; 50 of 50 satisfied verdicts re-derive faithfully as of their instant while all 50 would be misreported under a latest-only rule set; and the SARC reference checker agrees with the in-store audit verdict-for-verdict, differing only on coverage semantics. A recorded trace from a governed writer surfaces a live enforcement gap the audit names with its remediation. On DEMM-Bench, an external decision-evidence sufficiency benchmark, a content-only reading of the exported records answers all 512 property-level governance questions correctly with zero overclaim under all eight degradation conditions, while container-presence baselines overclaim on up to 87.5% of them -- and the run surfaced, and led us to close, a gap in what a denial's verdict attests.

Read the original paper

More in Graph Learning

Browse all 32 papers →
02Graph Learning

GraphWrit3R: End-to-End 3D Scene Graph Writing

Luka Milivojevic, Nikola Popovic, Sayan Deb Sarkar, Sebastian Koch, Iro Armeni, Luc Van Gool, Danda Pani Paudel

GraphWrit3R turns 3D spatial data into open-vocabulary scene graphs using multimodal encoders and an LLM, without requiring ground-truth object annotations at inference.

Read analysis