acceptodds
Under review as a conference paper at ICLR 2027

Audience-Bound Persistent Memory: Authorization Across the Memory Lifecycle

Abstract

A personal language agent that acts for its owner across private and shared conversations can learn a fact from one audience and later place it in the context it assembles for another. We study authorization before context across the whole memory lifecycle. Each memory item carries the audience present when it was recorded, and derived items are partitioned by audience, receive the intersection of their sources’ audiences, or are suppressed. An audience is widened only by an explicit, object-specific grant, and an item enters a model attempt only when every current viewer already belongs to one of its authorized audiences; ambiguous viewers fail closed to public-only. Under explicit identity, provenance and complete-mediation assumptions, this admission is sound and policy-complete on the exact assembled context, enforced by exclusion rather than by model behavior. We realize it in two independently persisted reference architectures, a flat store and a relationship graph, and separately, with descriptive validation, in a native agent-memory runtime. In a prospectively frozen confirmation over 10,000 independently generated multi-party histories and 480,000 paired retrieval cells, all eight prespecified entitled-recall non-inferiority checks against unscoped, siloed, bounded post-filter and principal-postings retrieval pass at the −0.05 Recall@5 margin. The architectures match the policy-equivalent baselines exactly in every history, so authorization before ranking costs no recall, and they recall more entitled evidence than unscoped retrieval, with a Holm-confirmed advantage that grows with distractors. Neither produced a wrong-principal substitution, against 7 of 9,984 unscoped answers; at this base rate the frozen test cannot confirm the reduction, so the prespecified joint decision is not established in either view.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.