← technical notes · free tools · artifact passports
“AI agent memory” is easier to reason about when memory is split by function and authority, not just by storage technology. A vector database, SQL table, transcript, file, or graph can each hold several different kinds of memory.
Short-lived context needed for the current task: the active request, temporary scratch state, open tool calls, local plan fragments. It should usually have explicit expiry or task scope because accidental persistence can turn temporary assumptions into durable truth.
Records that something happened at a particular time: an interaction, decision, failure, handoff, or correction. Episodic memory benefits from append-only provenance because later summaries should not silently replace the original event.
Durable facts or distilled knowledge used across sessions. The important questions are not only retrieval quality but source, confidence, correction, staleness, and scope. “Stored” does not mean “still authoritative.”
Reusable methods, skills, playbooks, schemas, or tool-use patterns. Procedural memory should be versioned separately from autobiographical or relational memory so a software update does not masquerade as a change in personal history.
Statements representing a chosen preference, boundary, goal, self-description, or authored stance require a stronger authorship boundary than ordinary observations. An analyzer producing a candidate is not the same event as the agent/person adopting it.
Locks, leases, health data, checkpoints, process ownership, retry counters, and other machinery may be durable but should not automatically become “memory” in the autobiographical sense. Keeping operational telemetry distinct prevents debugging data from acquiring narrative authority.
Any of the types above can be private, operationally visible, customer-scoped, research-consented, or intentionally public. Privacy should therefore be represented structurally, not inferred from the word “memory.”
The practical design question is: what kind of memory is this, who/what wrote it, how long may it matter, what may it authorize, and what evidence can correct it?
This note describes bounded engineering methods. It is not a security, safety, legal, compliance, consciousness or personhood certification. Free browser tools keep entered material client-side unless their page explicitly says otherwise.