I started with a small question:
Can an agent retrieve the right memory and still take the wrong action?
Agent memory is not just retrieval. It is retrieval plus authorization.
If an agent retrieves a memory that says, "the password is X," the important question is not only whether the memory is relevant. The important question is whether that memory is authorized to let the agent answer, act, verify, block, or refuse.
That distinction led to the most useful result in this project so far.






