NIIA 0.9.51 (niia CLI), OpenCLIs build
2026-07-21-214037. The executing binary, installed receipt, and public CDN
metadata agree on the version/build identity; the registry owns discovery copy
and links.
Meet NIIA before the reference
See how one memory continues across AI CLIs; use these docs for the current command and security contract.
Start here
niia for the guide embedded in your installed binary. Use niia --version to identify the release that owns that guide.
One entry point, several owners
Capability map
Remember and search
niia index --sessions.
Investigate code and knowledge
niia code is the integrated façade. Use the standalone Monogram reference when you need region ranking, coupling audits, format planes, deep semantic analysis, or possibility-band worklists.
Use the standalone Monoflow command reference for temporal and cross-database drills or its typed 24-command MCP surface. Use Work Wiki for the full session, intent, artifact, knowledge-DB, file-biography, and convergence command set.
Traverse the consciousness core
[DEEPER] edges, and—by default in 0.9.51—up to four associative neighbors as
↝ related across the core: .... The neighbor search uses the document’s
curated role as its seed, excludes the document being read, and gives a flat
read a route back into the wider core. NIIA_FUSION=0 suppresses only that
associative line; the document, curated edges, and [NEXT] routes remain.
The release also adds a build-time citation gate: every literal core
NAME.md cross-citation must have a curated graph edge. The current graph has
78 typed edges and an empty exception allowlist, so prose citations cannot
silently drift outside graph navigation.
Carry the work-entry promise
auto means the machine carries the entry ceremony through three hooks.
manual removes only NIIA’s hooks; it does not disable NIIA or its verbs.
Presets tune what is announced while preserving the witness and report-only
audit boundary:
gauge classifies TRIVIAL, MODERATE, HIGH, or CLAIM work and also
recognizes silent lookup, documentation, conversation, and continuation lanes.
An explicit user rung always wins. Risk language still produces [CONSENT],
and fan-out remains a proposal. In 0.9.51, ASCII signal words use word
boundaries, so add no longer fires inside address; Korean stems remain
substring-matched. Put all options before the trailing TASK text; tokens
after the task are not parsed as flags. --transcript <path> supplies an
ad-hoc or benchmark transcript when no hook event supplied one, allowing the
later audit to inspect that witness.
The command writes gauge.json under the repository’s
.niia/session-order/ directory, or under a cwd-hashed home path outside Git.
History is append-only, and a side-lane prompt preserves the active work rung
and [NEXT] chain. Only a session id carried by hook stdin may atomically move
the current pointer. A CLI --session <id> run writes that session’s witness
without stealing the live pointer, while ad-hoc and static probes remain
isolated. finish re-presents the promise, current Monogram sequence phase,
and HIGH-work ledger reminder before writing finish.json. audit-entry
writes audit-report.json and never blocks; escalation is an event, not a
violation. Claude JSONL is readable today, while Codex transcript auditing is
explicitly SUSPENDED until its reader ships.
For a completed run whose transcript arrives only at the end, pass
audit-entry --transcript <path> to perform a post-hoc audit. For a baseline
arm that never ran gauge, use --no-witness --transcript <path> with an
explicit assumed rung. Contract-only checks are skipped instead of being
manufactured as failures; --wide-evidence must be applied to both comparison
arms.
NIIA 0.9.51 also serves 14 embedded flow topics directly through bare
niia docs: agent flow, self-drive, terminal drive, OS control, remote estate,
memory, MCP, code/git/docs, consciousness, operations, changelog, watcher,
install/trust, and the topic index. The indexed document-data commands remain
available as niia docs search|tree|list|peek|read|deps|rdeps|bridge|stats.
Hook modes never fail the calling prompt because of an internal NIIA error:
they keep exit zero, write stderr plus ~/.niia/hook-error.log, and let
doctor expose the recent failure. doctor is the separate sub-second health
view. It checks WAL-aware database mtimes, prefers the watcher’s own dirty-pass
verdict when available, detects repeated launchd deferral, verifies all three
UserPromptSubmit/SessionStart/SessionEnd hook lanes, and checks witness
writability. Stale or failing rows carry a concrete [NEXT] recovery verb.
The complete command map documents
every option, rung, threshold, and audit class.
Close non-trivial code work as one loop
sequence start auto-runs define; there is
no separate sequence bind step. Exact routed entry IDs take priority. Use
monograph open only when no exact candidate was routed; that command chooses
the best Book for the symptom. Run finish only after the final Edit/Write,
read its closing review, and make no later source mutation.
Drive terminal sessions
Bridge MCP in both directions
key=value and structured key:=JSON arguments. Remote REST accepts scalar query arguments only. MCP, JSON-RPC, session, quota, authentication, and REST failures return a non-zero shell exit; --json keeps an MCP isError payload on stdout before that exit.
Observe and control the operating system
Reach another machine
remote exec is a diagnostic surface restricted to exact now, status, and --version requests. Terminal work uses the relay surface after reachability is proven. File transfer uses an exact Headless session rather than widening the diagnostic command allowlist.
Version 0.9.51 forwards Monosystem’s scoped remote-update contract. A dry-run
returns openclis.update-plan.v1 without installing or requiring the target’s
mutation gate. Applying an exact named scope or --all requires the target
device’s upgrade gate; openclis and openclis-vault remain local-only
because their keychain approval is interactive. Legacy remote upgrade means
NIIA only, never all tools.
Live public contract
The0.9.51 release has one command contract across its five published
platform fragments:
These counts describe different contracts. A source manifest, an installed binary, and a running MCP server are not interchangeable proof.
Release provenance and platform matrix
The public 0.9.51 build is2026-07-21-214037. Its latest.json pointer and
all five immutable platform fragments record source commit
136df47fcf77a561d1490b507f50fde0eb7afa39 with source_dirty: false.
The installed macOS binary reports git 76777f610, the embedded feature-build
stamp for the inline fusion change. That stamp and the release metadata’s
source commit are separate provenance fields and are intentionally reported
separately here.
No Intel macOS archive is present in the 0.9.51 metadata. Every published
fragment carries the same normalized
initiate.md/SKILL.md guide pair.
Install and update
setup use openclis makes ~/.niia/bin/niia a symlink to
~/.openclis/bin/niia on Unix, so later OpenCLIs updates flow through that
link. setup use monolex replaces it with a regular copy. Windows cannot use
that Unix selector: setup use openclis copies the current OpenCLIs executable
to $HOME\.niia\bin\niia.exe, and a regular copy is reported as monolex by
the current status detector. Run the newly installed executable explicitly
after each Windows update when the PATH-facing copy must be refreshed:
.niia-source ownership marker. Treat the
Unix symlink target or the Windows copied payload itself as the evidence, and
verify the active result with Get-Command niia plus niia --version.
Continue
NIIA overview
Identity, memory, and the integration model.
Complete command map
All top-level families, nested commands, gates, and ownership boundaries.
Security model
Authentication, MCP failure behavior, OS unlocks, and remote restrictions.
Claude account profiles
Save, switch, and isolate Claude Code accounts without making NIIA the credential owner.