Filed at birth, never inferred later
The memory is written with its class, principal, tenant, and AI-specific notice declared in the record itself — not in a policy PDF nobody can query.
Agents accumulate memory — preferences, histories, identities — and then act on it. The question that decides liability is never what the memory says. It is whether it may be used for this action, right now, on this legal basis. AgentMemorySDK makes that a filed, answerable question.
Regulators already treat agent memory as personal data — Singapore's PDPC guidance validated exactly this lifecycle. Each stage below is a decision with an evidence trail, so a deletion request or an audit is a query, not an archaeology dig.
The memory is written with its class, principal, tenant, and AI-specific notice declared in the record itself — not in a policy PDF nobody can query.
Legal basis and purpose scope attach where the data lives. When the basis changes, the record knows before the agent does.
Training, fine-tuning, inference, and action are four different questions with four different answers: ALLOW, DENY, REQUIRE_CONSENT, REQUIRE_MINIMISATION — decided when it matters, not audited after.
Sealed, tenant-scoped, replayable. The answer to "which memories did the agent act on, and was it allowed?" is one lookup.
Withdrawal routes through the same governed path as use — the erasure itself seals evidence, closing the file the way it was opened.
Honest scope: the SDK governs whether a memory may be used for an action. It does not verify the truth of what the memory contains, and it claims no regulation it has not mapped.
Your agents hold customers' data and act on it. When a regulator or a deletion request arrives, the file answers — not a scramble across vector stores.
Memory features sell; ungoverned memory features settle. The SDK gives every record a basis, a scope, and an erasure path your customers can verify.
The person your agent remembers gets what the law promises: notice at collection, a verdict at use, and a deletion that proves itself.
DSARs stop being projects. "What do you hold on me and why" is a query over filed records, not an archaeology dig across embeddings.
Training and inference get separate answers. A record consented for inference doesn't silently leak into fine-tuning — the use-type verdict distinguishes them.
Erasure becomes provable. The deletion seals its own evidence, closing the file the way it was opened.
Regulator conversations shorten. The lifecycle mirrors what guidance like Singapore's PDPC already validated — you show the file, not a policy PDF.
Sample response — illustrative names, the real shape of what the record produces on demand.
We hold 3 memory records concerning you, filed under consent for delivery-scheduling. Each records its collection notice, legal basis, and every use — 14 inference decisions, 0 training uses (denied by verdict).
All 3 records were erased today; the erasure itself is evidenced and independently verifiable. No further copies exist in scope.
Assembled by query, not by investigation.
The DSAR project. Answering "what do you hold and why" from unfiled vector stores is an engineering sprint per request; from the file it is one query.
The consent-leak incident. A record consented for inference that trains a model is a breach; the use-type verdict makes it a refused, evidenced attempt instead.
The unprovable deletion. "We deleted it, trust us" fails audits; an erasure that seals its own evidence does not.
Vector databases and memory frameworks make agents remember better — none makes the memory lawful to use. Storage is capability; the file is authority.
Data-loss tools watch content move; they cannot answer whether this use, by this agent, for this purpose, on this basis, was admissible — the verdict is the product.
The lifecycle mirrors what regulators already validated, the verdicts seal offline, and the record compounds: every filed memory makes the next audit cheaper — an asset ungoverned stores structurally cannot accrue.
KYC, support, healthcare, finance — teams whose agents hold people's data get access first. Replies come from a person at [email protected].