Human-verified, signed memory sharing between separate SAGE brains: partitioned
hash-chained audit journal (roster + per-domain sub-chains), origin-signed items,
two-party (owner + controller) domain admission, selective-sync consent, signed
controller rotation / member removal / rejoin with anti-entropy reconciliation, and
per-token MCP signing identities.
Security-hardened before release via adversarial multi-agent review:
- Controller epoch rotation now revokes a rotated-out controller's domain-admission
authority via per-domain head-seq re-attestation (mint / re-add / re-widen /
resurrect all blocked), without breaking legitimate cross-epoch back-fill (H-1).
- member_activate cannot resurrect a removed/left member; consent and owned-domain
rows are retired on removal.