Supported
Knowledge scopes and promotion
Behavior
Scope |
Typical writer |
Typical readers |
Promotion condition |
|---|---|---|---|
|
Current runtime |
Current session |
Consolidation accepts durable value |
|
One agent role |
Same role |
Reviewed or policy-approved sharing |
|
User interaction |
Authorized user applications |
Explicit purpose and consent |
|
Team sources and agents |
Project principals |
Evidence and project policy |
|
Governed publishers |
Organization principals |
Privileged approval |
How it works
Callers define scope paths. Each principal receives explicit readable and
writable patterns. propose_promotion checks source readability and target
writability, then returns a decision record. On approval, the host creates a
new artifact linked to its origin. That new identity preserves the review boundary.
from mari_components.governance import ScopeGrant, ScopePolicy, propose_promotion
policy = ScopePolicy(
grants=(
ScopeGrant(
principal="agent:researcher",
read=("agent:researcher", "project:mari"),
write=("agent:researcher",),
),
)
)
proposal = propose_promotion(
artifact_id="finding:2406.10746",
source_scope="agent:researcher",
target_scope="project:mari",
principal="agent:researcher",
policy=policy,
)
# The proposal still requires a privileged commit or application review.
assert proposal.allowed is False
assert proposal.reason == "target_not_writable"
Apply scope filtering in every host read path before retrieval scores are
computed. Direct ID reads and graph traversal must consult the same policy.
ScopePolicy supplies decisions through allows, and storage adapters enforce
them. Patterns use case-sensitive shell-style matching.
These policy scope strings express application access rules. ScopeRef carries
tenant and space identity in shared object references. Define an explicit
mapping between the two. Include policy changes in derived retrieval
dependencies as described in dependency-aware updates.
Continue checking current access at read time, even for reusable outputs.
Measures
Case |
Expected result |
|---|---|
Unauthorized semantic match |
Excluded from the ranked candidate set |
Direct lookup of hidden ID |
Denied identically to search |
Agent-private promotion request |
Proposal returned. No visibility change |
Revoked origin |
Host uses lineage to schedule derivative review or deletion |
Papers and implementations
Governed Shared Memory for Multi-Agent LLM SystemsMem0Aegis Memory scope policyNIST access-control models
Mari defines scope decisions and promotion records. Hosts remain responsible for authentication and storage isolation.