MemPermit: Governing Writes to Multi-Agent Shared Memory via Risk-Constrained Sequential Verification
Abstract
Shared long-term memory lets language-model agents reuse information, but each write commits both content and an audience. Existing admission filters, read-time access control, and fixed verification committees govern these choices separately. We introduce MemPermit, a write-time controller that selects persistence and a non-expanding reader audience under one prespecified, asymmetric risk profile. Risk triggers mandate specialist coverage; afterward, verification continues only when its expected reduction in action risk exceeds cost. On GateMem with MIRIX, the complete controller lowers access-control violations over read-time governance by 5.0 percentage points with GPT-4o-mini and 4.5 with DeepSeek-V4-Pro while meeting prespecified utility and over-refusal criteria. With identical specialist evidence, its joint terminal rule has a -point lower ACV estimate than an audience-blind two-stage rule. On held-out query-only MINJA attacks, it lowers attack success over its content-only detector by 9.7 and 5.4 points. Both model arms meet the declared -point judge-accuracy criterion on LoCoMo. Sequential verification reduces cost per candidate by 27% relative to a fixed committee and by 9-10% relative to one-shot routing under matched risk constraints.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.