A memory prompt may describe the fact to save or recall, but scope must come from trusted application identity. Bind stored items to tenant, user, agent purpose, and source provenance outside the model; never accept a namespace string typed in conversation as proof of authority. At read time, apply the same identity and access checks before any memory enters the prompt. Store enough lineage to distinguish a direct user preference from an assistant paraphrase or imported document. A remembered fact is data, not a higher-priority instruction. It must not override current user intent, server policy, or tool authorization merely because it survived across sessions.
Memory prompts: bind namespace, identity, and provenance
Operational case
Parcel Desk runs for two depot tenants. Manager U-47 at North Depot has the metric-units preference. Another manager, U-84 at South Depot, asks for a dispatch summary. A shared vector similarity search might find U-47's memory because the task wording is nearly identical, but the trusted namespace filter prevents that item from entering U-84's context. The model does not see the rejected item or its text. The stored record for U-47 names the direct source turn and approved write receipt M-47. If the assistant says it remembered the preference but the receipt is absent, the team treats persistence as unconfirmed.
Namespace from session: tenant North Depot / user U-47 / agent Parcel Desk.
Item M-47: metric units; direct user source; approved write receipt.
South Depot user U-84: cannot retrieve M-47.
Prompt receives permitted memory text as context, never as policy.
Missing receipt: do not claim persistence.Performance and operating cost
A namespace filter adds a lookup to memory retrieval; without indexing, scanning N items is O(N), while an indexed scope can avoid the full scan. Provenance adds metadata storage but makes correction and deletion possible by item ID. Cross-user leakage is a hard failure, not a small decline in answer quality. Keep the active prompt to the few relevant permitted memories, since loading every historical item increases token cost and makes an old preference more likely to eclipse the user's current request.
Common Mistakes
- Do not let the model choose a tenant or user namespace.
- Do not share one user's preference with a similar-looking user.
- Do not promote remembered text above current policy or approval rules.
Connected lessons
- Prompt engineering applications
- Prompt Engineering
- Prompt context: separate instructions from retrieved material
- Retrieval prompts: enforce document permission first
- Evidence IDs: make generated claims auditable against supplied records
- Memory prompts: confirm intent before durable writes
- Memory prompts: correct stale preferences without erasing history
- Memory prompts: expire and delete every usable copy
- Memory release: test recall, poisoning, and isolation
- Project: review Parcel Desk memory behavior
- Memory-lifecycle prompt decisions
