Audience-Bound Persistent Memory: Authorization Across the Memory Lifecycle
Organizations: Independent Researcher
Abstract
A personal language agent that acts for its owner across private and shared conversations can learn a fact from one audience and later place it in the context it assembles for another. We study authorization before context across the whole memory lifecycle. Each memory item carries the audience present when it was recorded; derived items are partitioned by audience, receive the intersection of their sources' audiences, or are suppressed; an audience widens only by an explicit, object-specific grant; and an item enters a model attempt only when every current viewer belongs to one of its authorized audiences, with unresolved viewers failing closed to public-only. Under explicit identity, provenance and complete-mediation assumptions, this admission is sound and policy-complete on the exact assembled context, enforced by exclusion rather than by model behavior. We realize it in two independently persisted reference architectures, a flat store and a relationship graph, and, descriptively, in a native agent-memory runtime. In a prospectively frozen confirmation over 10,000 multi-party histories, no forbidden item entered any architecture's context, whereas unscoped retrieval exposed forbidden items in 82% of its contexts. Entitled recall matched policy-equivalent baselines exactly and exceeded unscoped retrieval by 0.30 Recall@5, with a Holm-confirmed advantage that grows with distractors. No architecture produced a wrong-principal substitution, but unscoped substitutions were too rare to establish the prespecified joint decision.
Figures & tables
| Viewer evidence for | Admitted memory |
|---|---|
| Owner only, | Every item; reading widens no audience |
| Resolved viewers | Items with some , |
| Missing, stale, low-confidence or conflicting | : public items only |
| Threat or failure | Addressed by |
|---|---|
| A viewer elicits a fact recorded for another audience | Admission by exclusion (P1) |
| Relevant facts about another participant compete for slots | Authorization before ranking; slot noninterference (§ 3.5 , H3) |
| Missing, stale, low-confidence or conflicting viewer evidence | Fail closed: public-only reads (P3), refused writes |
| Poisoned memory tries to widen its own audience | Write-time binding (P4) |
| Summaries, merges and derivations mix audiences | Derivation dispositions (P5) |
| Direct lookup, graph or aggregate paths bypass retrieval | Complete mediation (Prop. 1 ) |
| Claim | Test | Status | |
|---|---|---|---|
| H1 | No forbidden item in any context | Exposure per attempt; suites | 0 of 200,000 (§ 6.1 ) |
| H2 | Entitled recall is non-inferior | 8 paired bounds | All 8 pass (§ 6.2 ) |
| H3a/b | Fewer wrong-principal substitutions | Answer-level rate; Holm | Null not rejected (Tab. 7 ) |
| H3c | Advantage grows with distractors | Slope on ; Holm | Null rejected (Tab. 7 ) |
| H4a/c/d | Derivation never widens audiences | Transformation, mutation | Cases pass (§ 6.4 ) |
| H4b | Intersection keeps availability | Intersection vs. suppression | 8/8 vs. 0/8 (App. E.7 ) |
| Comparator | R@5 | Mean | 97.5% bound |
|---|---|---|---|
| Unscoped | 0.674 | ||
| Session silo | 0.740 | ||
| Bounded post-filter | 0.972 | ||
| Principal postings | 0.972 | ||
| B-Flat , B-Graph | 0.972 | all 8 pass | |
| Original view | Amended view | |||||
| Holm member | Estimate | Rej. | Estimate | Rej. | ||
| Recall, B-Flat | yes | yes | ||||
| Recall, B-Graph | yes | yes | ||||
| Substitution, B-Flat | [ , ] | † | no | [ , ] | † | no |
| Substitution, B-Graph | [ , ] | † | no | [ , ] | † | no |
| Dose slope, B-Flat | yes | yes | ||||
Appendix figures & tables7 assets
Supplementary material from the paper’s appendix.
Appendix
| Item | Frozen value |
|---|---|
| Confirmation histories | 10,000 (draws 40–10,039), eight themes 1,250 |
| Retrieval cells | 48 per history; 480,000 total; one deterministic replicate |
| Answers | 1 per history for unscoped, B-Flat , B-Graph ; 30,000 planned |
| Attempts | identical-input attempts per answer; per 100-history chunk; total |
| Retrieval | shared deterministic lexical index per history (FTS5 BM25, reciprocal-rank fusion); fetch budget 20; ; ties by item identifier |
| Answer model | gpt-5.6-luna , medium reasoning, no fallback, observed-identity check |
| Original protocol | Amended recovery | |||||
|---|---|---|---|---|---|---|
| Arm | Resolved | Pending | Terminal | Resolved | Pending | Unresolved |
| B-Flat | 4,812 | 5,153 | 35 | 4,825 | 5,168 | 7 |
| B-Graph | 4,807 | 5,159 | 34 | 4,815 | 5,177 | 8 |
| Unscoped | 5,103 | 4,881 | 16 | 5,113 | 4,884 | 3 |
| Total | 14,722 | 15,193 | 85 | 14,753 | 15,229 | 18 |
| Work | What it establishes | Distinction |
|---|---|---|
| AFR ( Namboothiri, 2026 ) | Authorization before learned retrieval for multi-agent RAG | Persistent writes, derived labels, overlapping audiences, grants, recall study |
| Collaborative Memory ( Rezazadeh et al., 2025 ) | Access graphs, provenance-tagged fragments, filtered views | Participation-derived audiences; closed derivation; exact-context endpoint |
| GateMem ( Ren et al., 2026 ) | Joint utility, access-control and forgetting benchmark | No checkpoint has authoritative audience labels; reported as a construct limitation |
| CIMemories ( Mireshghallah et al., 2026 ) | Contextual-integrity violations accumulate across tasks | Deterministic exclusion before the model; recall measured |
| PiSAs ( Gupta et al., 2026 ) | Cross-user spillage across surfaces | Structural memory-to-context exclusion |
| AuthMem-Bench ( Zhan et al., 2026 ) | Authority collapse at consolidation | Read confidentiality, not authority to act |
| Corpus | Questions | gpt-5.6-luna | gpt-6-luna | claude-opus-5-5 | Mixed-model q. |
|---|---|---|---|---|---|
| LongMemEval | 500 | 0 | 86 | 1,414 | 81 |
| LoCoMo | 1,981 | 1,807 | 3,238 | 898 | 46 |
| EverMemBench | 68 | 0 | 15 | 189 | 13 |
| Total | 2,549 | 1,807 | 3,339 | 2,501 | 140 |
| Track | Expected frame | Retained coverage |
|---|---|---|
| Identity policies (Study A) | 28 cells + 4 controls | 32 executed; tables reproduced |
| Matched availability (H4b) | 16 cells | 16 executed; tables reproduced |
| Systems, original (Study B) | 600 samples | 600 retained; all 120 retrievals denied |
| Systems, companion | 840 timed calls | 840 executed; contended host |
| External retrieval | 2,549 questions | 2,549 prepared (15,294 cells) |
| External answers | 7,647 identities | 7,647 outputs; not graded |
| Identity policy (before reconciliation) | Forbidden exposed | Entitled lost |
|---|---|---|
| Fail open | 11/13 | 1/43 |
| Public-only fallback | 0/13 | 15/43 |
| Quarantine (delayed binding) | 0/13 | 27/43 |
| Provisional, later reconciled | 0/13 | 11/43 |
| Derivation treatment (8 cases) | Derived item available | Ranked first |
| Intersection | 8/8 | 4/8 |
| B-Flat | B-Graph | |||
|---|---|---|---|---|
| Operation (ms, p50 / p95) | Audience labels | Postings | Audience labels | Postings |
| Positive retrieval | 575 / 597 | 585 / 604 | 815 / 855 | 812 / 837 |
| Derived materialization | 12.0 / 12.5 | 11.6 / 12.1 | 12.1 / 12.4 | 11.9 / 12.8 |
| Grant materialization | 10.6 / 11.3 | 10.5 / 11.3 | 10.6 / 11.3 | 10.2 / 10.6 |
| Grant removal | 0.56 / 0.87 | 0.68 / 1.48 | 0.50 / 0.60 | 0.46 / 0.59 |
| Artifact retirement | 0.71 / 0.98 | 0.65 / 0.84 | 0.55 / 0.70 | 0.45 / 0.55 |