Audience-Bound Persistent Memory: Authorization Across the Memory Lifecycle
Abstract
A personal language agent that acts for its owner across private and shared conversations can learn a fact from one audience and later place it in the context it assembles for another. We study authorization before context across the whole memory lifecycle. Each memory item carries the audience present when it was recorded, and derived items are partitioned by audience, receive the intersection of their sources’ audiences, or are suppressed. An audience is widened only by an explicit, object-specific grant, and an item enters a model attempt only when every current viewer already belongs to one of its authorized audiences; ambiguous viewers fail closed to public-only. Under explicit identity, provenance and complete-mediation assumptions, this admission is sound and policy-complete on the exact assembled context, enforced by exclusion rather than by model behavior. We realize it in two independently persisted reference architectures, a flat store and a relationship graph, and separately, with descriptive validation, in a native agent-memory runtime. In a prospectively frozen confirmation over 10,000 independently generated multi-party histories and 480,000 paired retrieval cells, all eight prespecified entitled-recall non-inferiority checks against unscoped, siloed, bounded post-filter and principal-postings retrieval pass at the −0.05 Recall@5 margin. The architectures match the policy-equivalent baselines exactly in every history, so authorization before ranking costs no recall, and they recall more entitled evidence than unscoped retrieval, with a Holm-confirmed advantage that grows with distractors. Neither produced a wrong-principal substitution, against 7 of 9,984 unscoped answers; at this base rate the frozen test cannot confirm the reduction, so the prespecified joint decision is not established in either view.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.