acceptodds
Under review as a conference paper at ICLR 2027

Governing Persistent Agent State with Provenance-Aware Recall and Promotion

Abstract

An agent can block an unsafe report while retaining the contaminated state that produced it. Later sessions may reuse that state as evidence or turn it into a procedure. This paper studies what must remain valid across such transformations. A governance layer separates integrity risk, epistemic trust, and disclosure sensitivity, propagates unresolved source constraints at every write, and rechecks inherited verification evidence before reuse. The analysis gives a compositional ancestry invariant and a reuse model in which verification error can be shared across many downstream uses. This distinction matters empirically. On DRSC-Bench, 240 research tasks spanning three sessions, governance attains utility 0.74, Silent Trust Promotion (STP) 0.03, and Cross-Session Contamination (CSC) 0.02, compared with 0.72, 0.31, and 0.24 for ungoverned retrieval. Disabling the promotion gate raises STP to 0.15 and CSC to 0.09 while Unsafe Export (UE) remains 0.01 at the reported precision. Persistence-matched baselines, a ten-session extension, and controlled lineage interventions support the same conclusion: safe output does not certify safe persistent state. The formal guarantees require complete governed dependencies and sound certificates; lineage omission and semantic verification error remain outside that guarantee.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.