# The permission zones

> The five levels you use to decide what your AI may rewrite and what it may not, explained one by one.

*designed version: https://illaira.com/deep-dives/permission-zones · index: https://illaira.com/llms.txt*

---

[Skip to content](#content)

[← Deep dives](https://illaira.com/deep-dives.md)

Deep dive

This is the part of the format that makes the difference between a document the AI respects and one it reworks. Every piece of memory sits inside a zone, and the zone says how much that piece is yours.

## Why they exist

Give an AI a long text and it tends to do what it does best: summarise, reorder, «improve». On a shopping list that's no problem. On a memory where you wrote who you are and how you want to be treated, it is: the day it rewrites it more smoothly, you have lost exactly the words you chose.

Zones solve it the simplest way possible: instead of hoping it behaves, you write it down. Every block of text is wrapped between an opening and a closing that say what permissions apply inside.

## How you write them

An opening on a line of its own, the content, a closing on a line of its own. Nothing else on the same line, or the program won't recognise it.

```
[P2]

## NUCLEUS 1: IDENTITY
Who you are when the conversation starts again from zero.

[/P2]
```

The levels run from 1 to 5 and don't nest: one zone must be closed before another opens. If you forget, the app tells you instead of guessing what you meant.

## The five levels

The descriptions below are the official ones, taken from the base tier Reminder: they are the same words the AI reads in the file.

1. `[P1]`

   ### Genetic memory

   Only you, and only by hand.

   The AI never touches it under any circumstance: it can ask you to change something, not do it. This is the zone of the ground rules, the ones that if they go it isn't the same AI any more. You edit it knowing full well what you're doing.
2. `[P2]`

   ### Permanent memory

   The AI doesn't modify; an explicit command from you is required.

   The sacred zone: identity, archetypes, absolute rules, symbolic events. Expected lifetime: indefinite. This is where you put the things that must still hold two years from now.
3. `[P3]`

   ### Long-term memory

   The AI may propose, not act.

   It can ask you to compress or correct, but it waits for your yes. This is the archive of what recurs: progress, goals, how your relationship works. Expected lifetime: days, weeks, the length of a project.
4. `[P4]`

   ### Short-term memory

   The AI adds freely; to delete, it asks.

   The working zone: what you're doing right now, working notes, temporary bookmarks. Expected lifetime: hours, or the current session. It empties at the end of the job with no regrets.
5. `[P5]`

   ### Volatile memory

   The AI does as it pleases.

   Scratch notes, counts, handovers from one module to another. It gets overwritten without warning: don't put anything there you want to count on tomorrow.

## How you choose

The useful question isn't «how important is this», it's «what happens if in a month I find it rewritten». If the answer is «a disaster», it goes high — 1 or 2. If it's «never mind», it goes low. Most of what you write ends up in the middle, in 3.

And it's worth knowing straight away: putting everything in [P1] isn't caution, it's giving up the help. An AI that may touch nothing can't even keep your archive tidy.

## Where they really hold: in chat, and with an agent

In a chat the model has no way to write to your files: it reads the Reminder, answers, and the file stays as it was until you touch it — or the app does, with your confirmation. There the zones are not weak: they are inert. They declare a permission over an action the model cannot perform anyway. They serve you, to know what is yours, and the app, which refuses to write outside the zone without asking the model’s opinion.

With an agent that has tools on the files the capability is real: it can open, rewrite, delete. And that is where the zones govern a real action, and where the difference between an instruction and a mechanism becomes concrete. A tag in the text is a request. A hook before the write, a list of folders the agent may write to, a read-only file: those are mechanisms. With an agent you can have both, and it pays: the zones say the meaning, the mechanism enforces it. It is the method’s best case, not its weak spot.

Then there is the part that depends on time. Today, inside the model, a zone is text it can honour or ignore — exactly the same as a system prompt, a Skill, anything you put in front of it. But agents are trained on what they meet, and a convention declared in the open is precisely what they learn best: it is very likely that over time they will handle them with ever more precision, knowing their meaning. It is not a guarantee, and we do not write it as one. It is a direction, and it is also why the Standard is published. The only way they will honour it outside the app as well is to use them: they train on what they meet, and a convention in use becomes what they expect to find.

[How an agent works with IllAIra →](https://illaira.com/agents.md) · [The Standard, in full →](https://illaira.com/documentation.md)

## When something doesn't add up

The program checks that zones are closed, that they aren't nested, and that structural content sits inside a zone rather than out in the open. When it finds a problem it says so and stops: it doesn't «fix» your file behind your back. It's the same rule that holds everywhere in IllAIra — better a clear error than a silent correction you discover three months later.

[Anatomy of a file](https://illaira.com/deep-dives/anatomy-of-a-file.md) · [Back to «How it works»](https://illaira.com/how-it-works.md)
