A worked example: the discount that never was
An agent handling renewals stores a note during a call: Acme Corp is on the enterprise tier, 20 percent multi-year discount approved. Six weeks later a different session asks the agent to draft Acme's renewal quote. The agent reads the note and applies the discount.
Now the failure modes. In an ordinary vector store or key-value cache, any of these can happen and leave no trace:
- The note was mistagged at write time and actually belongs to a different customer. The agent quotes a discount Acme was never offered.
- The note was silently edited by a later run (or a bad migration) from 20 percent to 40 percent. Nobody can say when it changed or who changed it.
- The note bled across tenants: a shared embedding index returned a neighbouring organisation's record as a near match. Acme's quote is now built on another company's terms.
Each one produces a confident, fluent, wrong answer. And because the memory carries no provenance, the post-mortem is archaeology: guesswork over logs that may not even exist.
With auditable memory the same incident reads differently. The renewal quote cites the exact memory entry it used. That entry carries a receipt: written by the renewals agent, at a timestamp, under Acme's organisation scope. If someone claims the discount was 40 percent, you replay the append-only record and see the 20 percent entry, the later correction, who made it, and when. The cross-tenant read simply cannot happen, because Acme's scope never contained the neighbour's data. The argument stops being "trust me" and becomes "here is the receipt".