Skip to main content
NIIA (Neural Intelligence Integration Architecture) is the entry point to the Mono tool stack. It gives humans and AI agents one CLI for recalling prior work, searching code and documents, driving terminal sessions, bridging MCP services, reaching other machines, and entering the operating-system control gate. Published contract: NIIA 0.9.51 (niia CLI), OpenCLIs build 2026-07-21-214037. The executing binary, installed receipt, and public CDN metadata agree on the version/build identity; the registry owns discovery copy and links.

Meet NIIA before the reference

See how one memory continues across AI CLIs; use these docs for the current command and security contract.

Start here

Run bare niia for the guide embedded in your installed binary. Use niia --version to identify the release that owns that guide.

One entry point, several owners

NIIA composes these systems; it does not erase their ownership boundaries.

Capability map

Session readers understand Claude, Codex, Grok, OpenCode, Gemini, and agy/Antigravity formats when those tools have local data available. Search indexing is explicit with niia index --sessions.

Investigate code and knowledge

niia code is the integrated façade. Use the standalone Monogram reference when you need region ranking, coupling audits, format planes, deep semantic analysis, or possibility-band worklists. Use the standalone Monoflow command reference for temporal and cross-database drills or its typed 24-command MCP surface. Use Work Wiki for the full session, intent, artifact, knowledge-DB, file-biography, and convergence command set.

Traverse the consciousness core

An exact document-name read prints the embedded document, its curated [DEEPER] edges, and—by default in 0.9.51—up to four associative neighbors as ↝ related across the core: .... The neighbor search uses the document’s curated role as its seed, excludes the document being read, and gives a flat read a route back into the wider core. NIIA_FUSION=0 suppresses only that associative line; the document, curated edges, and [NEXT] routes remain. The release also adds a build-time citation gate: every literal core NAME.md cross-citation must have a curated graph edge. The current graph has 78 typed edges and an empty exception allowlist, so prose citations cannot silently drift outside graph navigation.

Carry the work-entry promise

auto means the machine carries the entry ceremony through three hooks. manual removes only NIIA’s hooks; it does not disable NIIA or its verbs. Presets tune what is announced while preserving the witness and report-only audit boundary:
gauge classifies TRIVIAL, MODERATE, HIGH, or CLAIM work and also recognizes silent lookup, documentation, conversation, and continuation lanes. An explicit user rung always wins. Risk language still produces [CONSENT], and fan-out remains a proposal. In 0.9.51, ASCII signal words use word boundaries, so add no longer fires inside address; Korean stems remain substring-matched. Put all options before the trailing TASK text; tokens after the task are not parsed as flags. --transcript <path> supplies an ad-hoc or benchmark transcript when no hook event supplied one, allowing the later audit to inspect that witness. The command writes gauge.json under the repository’s .niia/session-order/ directory, or under a cwd-hashed home path outside Git. History is append-only, and a side-lane prompt preserves the active work rung and [NEXT] chain. Only a session id carried by hook stdin may atomically move the current pointer. A CLI --session <id> run writes that session’s witness without stealing the live pointer, while ad-hoc and static probes remain isolated. finish re-presents the promise, current Monogram sequence phase, and HIGH-work ledger reminder before writing finish.json. audit-entry writes audit-report.json and never blocks; escalation is an event, not a violation. Claude JSONL is readable today, while Codex transcript auditing is explicitly SUSPENDED until its reader ships. For a completed run whose transcript arrives only at the end, pass audit-entry --transcript <path> to perform a post-hoc audit. For a baseline arm that never ran gauge, use --no-witness --transcript <path> with an explicit assumed rung. Contract-only checks are skipped instead of being manufactured as failures; --wide-evidence must be applied to both comparison arms. NIIA 0.9.51 also serves 14 embedded flow topics directly through bare niia docs: agent flow, self-drive, terminal drive, OS control, remote estate, memory, MCP, code/git/docs, consciousness, operations, changelog, watcher, install/trust, and the topic index. The indexed document-data commands remain available as niia docs search|tree|list|peek|read|deps|rdeps|bridge|stats. Hook modes never fail the calling prompt because of an internal NIIA error: they keep exit zero, write stderr plus ~/.niia/hook-error.log, and let doctor expose the recent failure. doctor is the separate sub-second health view. It checks WAL-aware database mtimes, prefers the watcher’s own dirty-pass verdict when available, detects repeated launchd deferral, verifies all three UserPromptSubmit/SessionStart/SessionEnd hook lanes, and checks witness writability. Stale or failing rows carry a concrete [NEXT] recovery verb. The complete command map documents every option, rung, threshold, and audit class.

Close non-trivial code work as one loop

Monogram supplies where the task touches code and preserves the required order. Monograph supplies reusable mechanism knowledge. The agent still proves whether a candidate applies. sequence start auto-runs define; there is no separate sequence bind step. Exact routed entry IDs take priority. Use monograph open only when no exact candidate was routed; that command chooses the best Book for the symptom. Run finish only after the final Edit/Write, read its closing review, and make no later source mutation.

Drive terminal sessions

The health gate distinguishes a live, drivable PTY from a stale screen. Assertions time out with a non-zero exit instead of silently treating missing output as success.

Bridge MCP in both directions

Local stdio services accept scalar key=value and structured key:=JSON arguments. Remote REST accepts scalar query arguments only. MCP, JSON-RPC, session, quota, authentication, and REST failures return a non-zero shell exit; --json keeps an MCP isError payload on stdout before that exit.

Observe and control the operating system

Safe metadata reads remain available without a control grant. Screen content and write operations cross an explicit unlock boundary. NIIA keeps the authorization token; the Kernel CLI command surface performs the observation or action. For web-page DOM, JavaScript, network, and logged-in browser workflows, use MonoSurf. When a browser flow opens a native file picker or system dialog, hand that step to Kernel CLI and then return to MonoSurf for page verification.

Reach another machine

remote exec is a diagnostic surface restricted to exact now, status, and --version requests. Terminal work uses the relay surface after reachability is proven. File transfer uses an exact Headless session rather than widening the diagnostic command allowlist. Version 0.9.51 forwards Monosystem’s scoped remote-update contract. A dry-run returns openclis.update-plan.v1 without installing or requiring the target’s mutation gate. Applying an exact named scope or --all requires the target device’s upgrade gate; openclis and openclis-vault remain local-only because their keychain approval is interactive. Legacy remote upgrade means NIIA only, never all tools.

Live public contract

The 0.9.51 release has one command contract across its five published platform fragments: These counts describe different contracts. A source manifest, an installed binary, and a running MCP server are not interchangeable proof.

Release provenance and platform matrix

The public 0.9.51 build is 2026-07-21-214037. Its latest.json pointer and all five immutable platform fragments record source commit 136df47fcf77a561d1490b507f50fde0eb7afa39 with source_dirty: false. The installed macOS binary reports git 76777f610, the embedded feature-build stamp for the inline fusion change. That stamp and the release metadata’s source commit are separate provenance fields and are intentionally reported separately here. No Intel macOS archive is present in the 0.9.51 metadata. Every published fragment carries the same normalized initiate.md/SKILL.md guide pair.

Install and update

In 0.9.51, setup use openclis makes ~/.niia/bin/niia a symlink to ~/.openclis/bin/niia on Unix, so later OpenCLIs updates flow through that link. setup use monolex replaces it with a regular copy. Windows cannot use that Unix selector: setup use openclis copies the current OpenCLIs executable to $HOME\.niia\bin\niia.exe, and a regular copy is reported as monolex by the current status detector. Run the newly installed executable explicitly after each Windows update when the PATH-facing copy must be refreshed:
The 0.9.51 selector does not write a .niia-source ownership marker. Treat the Unix symlink target or the Windows copied payload itself as the evidence, and verify the active result with Get-Command niia plus niia --version.

Continue

NIIA overview

Identity, memory, and the integration model.

Complete command map

All top-level families, nested commands, gates, and ownership boundaries.

Security model

Authentication, MCP failure behavior, OS unlocks, and remote restrictions.

Claude account profiles

Save, switch, and isolate Claude Code accounts without making NIIA the credential owner.