Conversation memory should keep durable preferences and unresolved task state that are relevant to future turns, with provenance and expiry. It should not silently elevate a past instruction above a new user request, or carry private records into unrelated tasks. Summaries can omit qualifiers and change meaning, so verify material commitments against the original turn or a structured state store before acting. Keep external effects, approval receipts, and object IDs in application state rather than relying on model recollection. A user correction should update the active task and invalidate conflicting summaries.
Conversation memory: retain decisions without retaining every private detail
Decision in practice
A customer-support assistant handled three claims for the same business account. Its memory records that the user prefers a compact status report and that case CL-719 remains open. It does not retain full claim documents, bank details, or a prior temporary approval as permanent authority. On a later turn, the user asks about CL-842; the assistant retrieves that case only and does not mix in CL-719's payout amount. If the account owner revokes access to an attachment, the memory stores the revocation marker and the attachment is excluded from future context.
Keep: preferred report format; open case ID CL-719; last verified status time.
Discard: bank account, full attachment text, expired approval.
On new case: load current authorization and case-specific evidence.
Correction: invalidate conflicting summary before the next action.Performance and operating cost
A shorter memory lowers token cost and leakage exposure but may require an extra retrieval when the user resumes old work. Measure context bytes retained, stale-state errors, and unauthorized carryover across cases. A structured memory field is easier to delete or expire than a free-form transcript summary. Retention must follow the product's data policy, not a prompt that asks the model to forget. Review access controls on the underlying store as part of the workflow.
Common Mistakes
- Do not treat an old approval as permanent permission.
- Do not carry sensitive case facts into an unrelated request.
- Do not use a summary as the sole record of an external effect.
Connected lessons
- Prompt Engineering
- Prompt patterns
- Prompt context: separate instructions from retrieved material
- Tool calls: validate intent and arguments before an external effect
- Tool loops: set budgets, state checks, and a stopping condition
- Multimodal prompts: separate what an image shows from what it suggests
- Project: defend a retrieval and action workflow
- Prompt design decisions
Next decision
Check whether the right facts reached the workflow and whether the result is safe at its destination.
Continue with: Conversation checkpoints: resume from verified state.
Continue with: Memory prompts: confirm intent before durable writes.
