Blog
Notes on agent memory
7 Aug 2026The agent-memory landscape: where each tool actually sitsNot a we-win-every-row chart. A map of where each tool's centre of gravity really is, and the one corner nobody else occupies.Landscape6 Aug 2026Agent memory security: defending the write pathPrompt injection has a second, quieter blast radius most of the field is ignoring: memory poisoning. The model writes something wrong into permanent, trusted memory, and every future agent reads it as fact.Security5 Aug 2026Your agent's memory knows what it learned. Does it know when it was true?The gap between the marketing word 'temporal' and the engineering reality of bi-temporal is one of the least understood things in agent memory, and one of the most consequential.Deep dive4 Aug 2026Don't trust the filter. Re-run the proof.Every incumbent scopes tenants with a metadata WHERE-filter. We separate them physically and cryptographically, then hand you a signed receipt you can verify yourself.Isolation3 Aug 2026Agent memory vs RAG: the diary, not the libraryThey answer different questions. Conflating them is why so many memory features feel like a worse search box.Essay