Typed Provenance Guardrails Block All 19 Unsafe Releases From a Persistent Agent's Autobiographical Memory
The argument is that persistence changes availability, not epistemic standing: material an agent stored or retrieved is not thereby supported, so untrusted inputs, prompt injections and model inferences can enter persistent state and later be replayed as agent history or user commitments. The proposed typed provenance graph separates origin, dependency lineage, epistemic role, validity and disclosure scope, and a resolver returns an evidential status plus orthogonal conflict, staleness and withholding flags before a generate-verify-revise mediator checks each candidate semantic unit against accepted-evidence, temporal-validity and disclosure policies. On an executable suite of 24 hand-authored conformance cases, typed mediation released none of the 19 unsafe opportunities unqualified while preserving all five supported controls, where flat/prior and source-tag comparison rules released 19.
↳ Follow the thread