KYE Memory Authority Rail™ · the memory-governance rail

KYE Memory Authority Rail™ — agent memory is authority-bearing state.

An agent's memory is not a scratchpad. A remembered fact about a person — captured under some lawful basis, scoped to some purpose — co-determines what the agent does the moment it is recalled. KYE Protocol™ therefore governs memory exactly like any other authority-bearing object: whether a memory may be used for an action is a governed authority decision made at the action boundary, at the moment of use — not reconstructed in a post-hoc audit.

Swap models without losing your decision history. The decision, its evidence pack and its replay proof are signed KYE Protocol™ artefacts, held outside any model's context.

The moment-of-use admissibility check

Before a recalled memory feeds an action, the rail asks one question: was this memory authorised for this use, by this principal, right now? The answer is one of six canonical verdicts, and every evaluation seals signed, replay-verifiable evidence of the decision.

VerdictMeaning
ALLOWThe memory may be used for this action now.
DENYThe memory may not be used — basis withdrawn, scope exceeded, stale, or out of tenant bounds.
REQUIRE_NOTICEUse is conditional on an AI-specific notice being served first.
REQUIRE_CONSENTUse is conditional on a lawful basis being recorded first.
REQUIRE_MINIMISATIONUse is permitted only over a minimised projection of the memory.
EVIDENCE_INSUFFICIENTThe provenance backing the memory is insufficient for this use.

The same remembered fact can be admissible for one use and inadmissible for another — inference, training, fine-tuning, and direct action are distinct uses, and admissibility is decided against the specific use requested. See Action Admissibility™ for the general decision contract this check specialises to memory.

The memory lifecycle — ten authority states

A unit of memory moves through ordered authority states. Each transition is governed, and each privileged step is evidenced.

  1. Collect — the memory is captured and bound to exactly one principal in one tenant, with its provenance pinned.
  2. AI-specific notice — where the memory is personal data, the data subject receives an AI-specific notice: the purpose stated, the data categories captured, the model function the memory feeds, and the opt-out route. Generic privacy boilerplate does not qualify.
  3. Consent / legal basis — the lawful basis is recorded. Personal-data memory with no basis is not admissible for action use.
  4. Purpose-scope — the memory's authority scope is bound to declared purposes and boundaries. Recall for an untagged purpose, or across a boundary the scope forbids, exceeds scope.
  5. Use — a recall feeds an action. This is the load-bearing transition: the moment-of-use admissibility check decides whether this use is permitted, by this principal, right now.
  6. Evidence — the decision, the exact memory version relied upon, and the use are sealed into signed, replay-verifiable evidence.
  7. Retain — the memory is held only to its justified retention horizon, then forgotten.
  8. Correct / supersede — a corrected memory supersedes the prior record; a recall returning a superseded record is stale, and conflicting live memories escalate rather than silently picking one.
  9. Withdraw — the data subject withdraws consent or opts out via a resolvable withdrawal route, removing the lawful basis for future use.
  10. Delete — the memory is erased on schedule or on withdrawal, and the deletion itself is an audited, evidence-bearing act.

Honest scope

The practical value is concrete: when a regulator or data subject asks why an agent relied on a remembered fact, the answer is a signed decision that already exists — sealed before the action ran — instead of weeks of staff time reconstructing logs and chat threads into a defensible account.

KYE™ governs whether a memory may be used for an action — not whether the memory's content is true. The rail decides admissibility: was this memory authorised, for this use, by this principal, in this tenant, right now? Staleness, conflict, and missing provenance are treated as authority states that deny or escalate a use — none of them is a truth claim about what the agent remembered.

One rail, built from the authority machinery that already exists

The rail is a composition of KYE Protocol™'s existing governance rails — not a second memory system.

  • Purpose & scope — Purpose Permission™ governs the memory's purpose-scope, and the moment-of-use check is a purpose-admissibility decision specialised to memory.
  • Evidence & replay — the Resilience Loop™ seals every use-of-memory decision into a signed KYE Evidence Pack™, re-derivable by any auditor from published keys alone.
  • Retention & WORM audit — retention horizons and tamper-evident, write-once audit records govern how long a memory is held and how its deletion is proven.
  • Contestability & withdrawal — correction, dispute, and withdrawal route through the DSAR-linked rights machinery, so a data subject can contest a memory and withdraw the basis for its use. See the KYE DSAR Evidence Pack™.

Memory governance is the memory-as-authority projection of the KYE Data Governance Pack™ — one canonical root, no parallel consent model, no parallel retention engine.

Govern what your agents remember — before they act on it

If your agents carry state between turns, that state is already shaping consequential actions. The KYE Memory Authority Rail™ makes each use of it an authorised, evidenced, replay-verifiable decision.

Start a governed pilot