Get started
Security & GovernanceMemoryEvidenceProvenance

Auditable AI agent memory: a mistagged memory is a decision made on a lie

If an agent stores a fact and later acts on it, that fact is now infrastructure. Most agent memory cannot say who wrote it, when, or whether it has changed. A worked example of auditable memory, the protocols that make it provable, and what exists today.

Adam Cowles1 October 20266 min read
Concentric layered rings of stacked records sealed with a faint chain-link motif, cyan and violet over near-black

If your agent stores a fact and later acts on it, that fact is now infrastructure. And most agent memory today cannot answer three basic questions: who wrote this, when, and has it changed since. A memory that can be silently edited, mistagged, or quietly borrowed from another customer is not a convenience. It is a decision made on a lie, with no way to prove otherwise after the fact.

Auditable AI agent memory closes that gap by design. Every read and every write is witnessed, the record is append-only so it cannot silently change, and each tenant's memory is isolated so nothing bleeds across organisations. Below is the worked example, the primitives underneath, and an honest account of which parts exist today.

What auditable memory actually means

Three properties, none of them optional:

  • Witnessed writes. When an agent stores a fact, a receipt is produced: what was written, by which agent, at what time. The fact and the proof of the fact travel together.
  • Immutability by construction. Memory is append-only. You do not edit history, you add to it. A correction is a new entry that supersedes the old one, and the old one is still visible. Nothing is silently overwritten.
  • Per-org isolation. Tenant A's agent cannot read, and cannot be contaminated by, tenant B's memory. Isolation is enforced at storage, not asked for politely at query time.

"Provable memory" is the sum of these: you can hand a third party the memory record and a verifier, and they can confirm what was known, when, without trusting your database and without you being in the room.

A worked example: the discount that never was

An agent handling renewals stores a note during a call: Acme Corp is on the enterprise tier, 20 percent multi-year discount approved. Six weeks later a different session asks the agent to draft Acme's renewal quote. The agent reads the note and applies the discount.

Now the failure modes. In an ordinary vector store or key-value cache, any of these can happen and leave no trace:

  • The note was mistagged at write time and actually belongs to a different customer. The agent quotes a discount Acme was never offered.
  • The note was silently edited by a later run (or a bad migration) from 20 percent to 40 percent. Nobody can say when it changed or who changed it.
  • The note bled across tenants: a shared embedding index returned a neighbouring organisation's record as a near match. Acme's quote is now built on another company's terms.

Each one produces a confident, fluent, wrong answer. And because the memory carries no provenance, the post-mortem is archaeology: guesswork over logs that may not even exist.

With auditable memory the same incident reads differently. The renewal quote cites the exact memory entry it used. That entry carries a receipt: written by the renewals agent, at a timestamp, under Acme's organisation scope. If someone claims the discount was 40 percent, you replay the append-only record and see the 20 percent entry, the later correction, who made it, and when. The cross-tenant read simply cannot happen, because Acme's scope never contained the neighbour's data. The argument stops being "trust me" and becomes "here is the receipt".

The primitives that make it provable

Quox is a self-hosted, evidence-first control plane for AI agents, and provable memory is built on the same open protocols that witness every other agent action:

  • AEE wraps each action in a structured envelope, so a memory write is a first-class, inspectable event rather than an opaque database call.
  • AOCL defines the control layers around that action, including an L3 policy gate (should this write be allowed) and an L8 verify step (did it happen as claimed).
  • VOLT is the append-only ledger: SHA-256 hash-chained entries, Ed25519 signatures, and RFC 3161 timestamps. This is what makes history immutable and tamper-evident, not merely "we try not to overwrite things".
  • WARD produces content-free witness receipts, so you can prove a write occurred, and when, without the receipt itself leaking the contents of the memory. There is more on that design in the WARD documentation.

Because these are open protocols and the deployment is self-hosted (Docker, per-org isolation, human-in-the-loop approvals for sensitive actions), the audit trail is yours and verifiable on your own infrastructure, not a log you rent and hope is honest.

What exists today, and what is planned

Being precise here matters more than sounding finished.

Shipped and verifiable now: the four protocols above are published and open. And quoxproof is a live package on PyPI: offline-verifiable, Ed25519-signed receipts for tool calls, which is exactly the receipt shape that a witnessed memory write produces. You can install it and check a receipt today, without a Quox account.

In build: the memory layer that applies these primitives end to end lives in Brain2, the knowledge store side of the platform. Quox is pre-launch, so treat the fully witnessed, per-org memory product as the direction the architecture is built toward rather than a finished thing you can buy this afternoon. The protocols are real and shippable to cite. The polished memory surface on top of them is still coming.

We say this plainly because the whole point of auditable memory is not overclaiming. A memory you cannot verify is worse than no memory, because it is trusted.

Where memory meets knowledge

Auditable memory is one layer. How you prove a write happened without trusting the vendor, and whether a durable store is worth the trouble over a chat window that forgets, are the neighbouring questions. On the witnessing side, why AI evidence needs an independent witness covers what a content-free receipt buys you over a tamper-evident log alone. If you are still deciding whether persistent memory earns its keep, why second brains are useful makes that case.

The short version: give an agent a memory, and you have given it authority. Auditability is how you make sure that authority is earned, one receipt at a time.