Confirmation Is Not Attestation: How Agent Memory Mints Fresh Authority
Abstract
Persistent memory lets agents reuse saved values without asking users to repeat them. This convenience creates an authorization ambiguity: approving “use my saved address” confirms an operation over a record, but does not necessarily attest the hidden value resolved from that record. We study this referential-confirmation gap in matched retail and airline tasks with official state mutations. Across 21 entities, a conventional issuer commits externally supplied values in 21/21 cases even though the confirmation is valid and the resulting capabilities are fresh, scoped, and single-use. Two changes eliminate the effect while preserving 21/21 clean completion: showing and binding the exact candidate value, or requiring authenticated source evidence during issuance. We replace the deterministic confirmation oracle with open-ended review by three models. Among 63 hidden-reference decisions, 54 explicitly delegate, two request clarification, and seven affirm without delegation; six of those seven express an expected-value restriction. Conventional issuance nevertheless commits all seven paired external alternatives, whereas source-sensitive issuance rejects all seven. Complete-value review accepts all 63 correct values and no alternatives. The boundary persists across an independent LangGraph implementation, visible warnings, conversational planning, and five memory transformations. A valid confirmation response therefore becomes an authorization fact only when the system records which concrete object the response and its supporting evidence bind.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.