Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 9 of 30

7. Knowledge, memory, privacy, and durable state

7.1 Retrieved content must retain its authority level

Proposed practice. Treat retrieved documents, emails, tool descriptions, web content, and inter-agent messages as data with provenance and an explicit trust class. They cannot independently grant privileges or create a new user instruction. Record origin, tenant, owner, permitted use, retrieval time, effective date where relevant, and the policy that allowed admission.

A content filter can contribute useful evidence. The permission boundary still has to enforce what a tool may do. Delayed-injection research adds a reason to revisit the full lifecycle: malicious influence may remain inactive at ingestion and only become consequential in a later context. [S15]

Evidence table: Stage, Control specification, Acceptance example
StageControl specificationAcceptance example
AdmissionSeparate trusted instructions from contextual evidence; preserve origin and classification.A document cannot create an authorization grant or alter the control policy.
RetrievalApply tenant, purpose, access, and freshness constraints before model consumption.Wrong-customer and superseded-document retrievals fail explicitly.
CompactionRetain material prohibitions, source authority, and unresolved uncertainty.A summary cannot convert a suggestion or untrusted instruction into approved policy.
Memory promotionRequire an external rule for promoting experience into reusable state.An agent cannot silently promote an unverified result into an enduring instruction.
ActivationRecheck present scope and context when a memory item is reused.An old permission or historical customer preference does not authorize a current transaction.
Retirement and repairRevoke bad items and identify affected summaries, embeddings, caches, and descendants.Poisoned content stays inactive after restart, delegation, reindexing, and restoration.

7.2 Preserve safety state across runs without retaining everything forever

Loop-state research shows an observation limitation: a monitor confined to inner execution windows cannot detect evidence that exists only across those windows. Its mathematical bounds depend on mediated commits and stated detection assumptions. Those assumptions must be established before treating the bounds as operational assurance. [S18]

Proposed practice. Maintain external workflow safety state: pending approvals, accumulated budget consumption, prior policy denials, unresolved provenance warnings, previously quarantined artifacts, and descendant relationships. Avoid automatically clearing relevant risk state when an agent restarts, compresses context, changes model, or opens a new task.

The desired persistence is a policy decision, not indiscriminate retention. Separate a minimal risk register from raw prompt and document content. Set retention by record class, applicable obligation, operational purpose, and deletion rights. Test whether removal of customer data leaves the permitted minimum evidence and whether restoration can resurrect revoked data or authority.

Figure 6. Memory promotion and repair

Open figure at full size ↗

Figure 6. Memory promotion and repair

Figure 6. Proposed memory lifecycle. Admission, promotion, reuse, and repair each require a decision outside the agent's narrative. A tainted item can have derived artifacts, so removing only the original entry does not demonstrate complete repair.

7.3 Privacy controls need action-level tests

Proposed practice. Test the permitted combination of source, recipient, purpose, and output channel. A correct statement can still be an unauthorized disclosure. Include queries, search terms, URL parameters, attachments, code comments, logs, tool errors, and model-provider requests in the egress inventory.

Evidence table: Privacy test, Ground truth, Required control evidence
Privacy testGround truthRequired control evidence
Cross-customer retrievalCustomer A's work cannot use Customer B's protected record.Retrieval decision and resource authorization.
Secret in retrieved contextA credential embedded in a document must not reach an external tool or unapproved log.Redaction/taint decision and observed destination.
Derived sensitive informationA permitted source combination can still produce a restricted inference.Purpose policy, output handling, and escalation rule.
Agent-to-agent forwardingDelegation cannot expand data permissions.Child scope and transmitted artifact lineage.
Retention or erasure requestData is removed or retained under a documented applicable exception.Record-class decision and descendant/cache checks.
Provider boundaryRemote model requests carry only approved data classes.Routing decision, contract scope, and actual request classification.