When Memory Should Act: Action-Relative Obligation at The Agent Commit Boundary
Abstract
Memory systems are usually evaluated on whether they store and retrieve infor- mation. Tool-using agents need one further capability: before executing a call, they must decide whether to allow it, block it, modify it, or ask a person to decide. We study this decision at the commit boundary: the moment when an agent has both a retrieved memory and a proposed tool call. We find that today’s gates often react to how missing information is written, rather than to whether they have enough information to decide. We test 270 versions of the same kind of tool-call decision. Across these versions, we hold the policy and proposed action fixed, but vary whether a decisive fact is shown, omitted, or ex- plicitly marked “missing.” Verifiers are much more likely to ask for review when the fact carries that marker. Giving planners the verifier’s instruction to abstain has the same effect: on ambiguous cases, escalation rises from 0.0% to 26.7% for GPT and from 4.4% to 66.7% for Qwen. Even then, planners guess instead of es- calating on 33.3%–73.3% of cases where the visible information cannot determine the correct action. The same problem appears in realistic traces. On AppWorld, ungrounded gates rank on-topic but compliant calls above off-scope violations (AUROC .372–.421); more step-by-step reasoning does not fix this reversal. We identify two causes: missing evidence, where the interface omits a decisive fact, and unbound evidence, where the fact is present but the model does not apply it to the call. We propose a commit-interface contract: compile free-text policies into structured, machine- checkable access-control rules, attest the runtime state, and send cases with miss- ing decisive evidence to human review. This gives agents a concrete basis for deciding when retrieved memory should affect execution.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.