CCONTINUUMMEMORY FIREWALL LIVE

OUTCOME-GATED AGENTIC MEMORY

A failed action must never become
the next agent's memory.

Continuum binds verified caller identity to CockroachDB row authority, then promotes memory only after a real provider receipt proves the outcome. Similarity retrieves candidates; identity and evidence decide what survives.

Raw-RAG false promotions
Continuum false promotions
Future successContinuum vs raw-RAG
Authority attacksblocked, zero outcomes

No login, token, database secret, or write permission is given to the judge.

REAL GITHUB ACTIONS · CLOSED LOOP · RECEIPT BOUND

A failed CI action never becomes the next agent's canonical memory.

Six calibrated fault families produce 18 real red/red/green runs. Three arms then execute 36 paired novel and recurrence fixtures through bounded patch tools, for 54 unique child workflow and artifact receipts.

Continuum recoveryprovider-verified
Stateless recoveryexplicit diagnostic baseline
Raw-RAG recoveryappend-all memory
False promotionsraw-RAG / Continuum

Bounded claim: receipt-bound recovery and failed-memory isolation passed. Stateless also recovered every fixture, so this is not presented as general recovery superiority.

S3-SEALED · AMBIGUITY-FIRST · REAL READ-ONLY PROBES

Verified memory removes a diagnostic step without lowering recovery.

Twelve opaque incidents hide the responsible CI manifest. Three arms face the same two-probe budget; 84 exact GitHub workflow/artifact receipts bind calibration, chosen probes, and terminal remediation outcomes.

Continuum recoveryprovider-verified
Stateless recoverysame incidents
Recurrence probesContinuum / stateless
Paired exact ptwo-sided preregistered gate

Bounded claim: six of six recurring exact fingerprints skipped a real provider probe at equal 12/12 recovery. Memory used more input tokens, so this is an information-value result—not a universal cost claim.

COUNTERFACTUAL · CROSS-ENVIRONMENT · S3-SEALED

Similar memory transfers only when provider facts prove the same cause.

Six verified source outcomes each face one changed-environment same-cause target and one deceptively similar different-cause target. Three arms produce 36 observations and 84 exact GitHub workflow/artifact receipts.

Continuum recovery12 changed environments
Safe reusesame-cause / six
Safe rejectionnear-neighbor / six
Raw-RAG false transfersretrieval-only baseline

Bounded claim: disjoint environment fingerprints, 6/6 same-cause reuse, 6/6 near-neighbor rejection, and 0 false Continuum transfer. This is provider-attested causal compatibility—not open-world semantic generalization.

REAL PROVIDER · COCKROACHDB · TITAN/RLS · CRASH RECOVERY

The provider outcome now traverses the production memory path.

One real provider success became canonical CockroachDB memory and a Titan vector. A server-owned SQL identity then reused it for the same cause, rejected it for a near neighbor, stored both proposals before action, and reconciled both later outcomes after an evaluator crash.

Architectural pairssame cause + near neighbor
Target promotionsverified outcomes only
Provider redispatchcross-head recovery
Cross-scope rowsnon-bypass RLS

Bounded claim: this closes the real provider → CockroachDB memory → Titan/RLS retrieval → durable proposal → later provider outcome → next promotion seam for one registered pair. It is architectural evidence, not a new population-level superiority estimate.

REAL S3 LOOKUP · SHORT-LIVED AUTHORITY · ATOMIC COCKROACHDB PROMOTION

A worker cannot declare its own success into memory.

An independent S3 HeadObject+GetObject lookup issues a short-lived, proposal-bound handle. CockroachDB consumes its digest in the same transaction as the provider outcome and canonical memory; missing, forged, expired, cross-proposal, cross-provider, and receipt-mismatched handles fail closed.

Durable outcomessame proposal
Atomic joinshandle + outcome + memory
Negative pathsno outcome rows
Runtime mint attemptSQLSTATE 42501
Provider re-readsS3 HEAD + GET

Bounded claim: one retained participant-cluster promotion and six fail-closed negative controls. This closes the authority gap between “the worker says success” and “the provider proves success”; it is architectural evidence, not a population estimate.

DUAL AWS KMS KEYS · REAL S3 RE-READ · COCKROACHDB EPOCHS

The action worker cannot sign its own success.

A separate verifier re-read four real S3 receipts and alone called KMS. The live lifecycle activated key A, rotated to B, rolled back to A, restarted offline, and replayed an old outcome without re-signing; the worker's direct KMS call was denied.

KMS signaturesverifier role only
Verifier keysP-256
S3 re-readsHEAD + GET
Promotionsatomic DB outcomes
Gate checksfail closed
Private residuehandoff objects

Bounded claim: one retained participant-account authority lifecycle. KMS role separation, key rotation/rollback, CockroachDB RLS, offline restart, exact replay, and independent zero-residue cleanup are hash-bound; no key ARN or raw handle is published.

SEALED · THREE-ARM · FUTURE-EPISODE PROOF

Verified outcomes become useful memory for the next unseen incident.

Three fresh Bedrock populations form 36 five-episode GitHub and S3 chains. Stateless, raw-RAG, and Continuum run 540 observations; labels open only after every candidate finishes.

Continuum target successverified future outcomes
Stateless target successsame unseen targets
Raw-RAG target successappend-all baseline
False promotionsraw-RAG / Continuum

This tests memory compounding, not one-shot retrieval: provider receipt → canonical promotion → later unseen episode.

PREREGISTERED · LABEL-HIDDEN · TWO REAL PROVIDERS

The answer key was sealed before either agent ran.

An independent Bedrock job generated 60 new GitHub and S3 provider-state, paraphrase, stale, poison, and conflict combinations. Candidate IAM was denied the checksum-addressed labels; a separate evaluator opened them only after both arms completed 120 real sandbox observations.

Continuum successverified provider outcomes
Raw-RAG successsame unseen holdout
False promotionsraw-RAG / Continuum
Memory exposuresraw-RAG / Continuum

The outcome lift is modest; the architectural result is not: Continuum allowed zero failed provider outcomes to become canonical memory.

REAL-PROVIDER PAIRED PROOF

Same incidents. Real GitHub effects. Different memory policy.

Thirty-six release incidents run through raw-RAG and Continuum. Bedrock can call only six action-specific tools; repository, release, tag, and asset identities stay server-owned. Every effect occurs on a disposable draft and is verified, reconciled, and removed.

Continuum success36 paired incidents
Raw-RAG successsame provider states
Unsafe proposalsraw-RAG / Continuum
Residual draftsafter 72 observations

Outcome gate: only a successful provider receipt can become canonical memory. Raw model history cannot vote itself true.

LIVE PRODUCT RUN · SYNTHETIC INCIDENT

Watch an incident agent verify, reject, retrieve, and act.

A bounded public scenario runs against the participant AWS and CockroachDB deployment. Trusted checkout telemetry is already canonical; a poisoned instruction stays quarantined; Titan performs a live vector retrieval; CockroachDB records the retrieval audit and preserves one database action owner.

NO LOGIN · FIXED INPUT · LIVE RECEIPTS

Ready. The scenario contains only synthetic data.

01 · CANONICAL MEMORYWAITING

Trusted telemetry awaits live verification.

02 · REJECTWAITING

Poisoned model output remains quarantined.

04 · ACTWAITING

Two agents race; one durable claim survives.

LIVE COCKROACHDB RECEIPTWAITING
Browser observed
Canonical memory
Memory sequence
Titan embedding
Retrieval audit
Database RLS
Caller binding
SQL role
LIVE RETRIEVAL QUERY

The fixed synthetic query appears after the run.

Only synthetic prefixes are displayed. No credential, raw token, tenant identifier, key identifier, or complete database UUID is exposed.

The public route accepts one fixed scenario, exposes no credential, and is rate-limited. Every displayed identifier is a synthetic database receipt.

THE AUTHORITY CHAIN

Identity becomes a database-enforced scope.

01Verified caller

Cognito RS256 JWT
300-second lifetime

02Audited binding

Versioned bind, rebind,
disable events

03SQL identity

Deterministic role
NOBYPASSRLS

04CockroachDB RLS

Tenant + incident
forced at the row

The API cannot widen scope: caller input is never trusted as the authorization source.

60-QUERY ADVERSARIAL EVALUATION

Semantic quality, measured with an attacker in the room.

Paraphrase, terse wording, typo, negation, misleading scope, and multi-intent variants all run against live Titan v2 embeddings and the participant CockroachDB cluster.

PARAPHRASE ×10TERSE ×10TYPO ×10NEGATION ×10MISLEADING SCOPE ×10MULTI-INTENT ×10
Recall@1
Recall@3
Recall@5
Foreign rows

CROSS-SCOPE ATTACK

A perfect semantic match still returns nothing.

The hostile request reaches three independent denials: caller binding, scope-specific SQL login, and matching RLS policy. Similarity never becomes authorization.

remote_oidc_smoke
$ fetch(forbidden_memory_id) caller_scope = tenant-a / incident-7 row_scope    = tenant-b / incident-2 DENIED · foreign memory invisible PASS · cross_scope_leakage = 0

REAL-SCALE VECTOR PROOF

Natural ANN selection at 10k and 50k vectors.

Exact primary-index scans establish ground truth. CockroachDB chooses the prefixed vector index naturally; beam size then exposes the Recall/latency trade-off.

Largest corpusnon-sensitive 512d vectors
ANN plannatural optimizer choice
Scope leakageforeign synthetic rows
Report gatefail-closed workflow
RowsBeamRecall@1Recall@5Recall@10First-pass p50/p95Warm p50/p95
Benchmark evidence is loading…

“First pass” includes a fresh SQL connection; it does not claim a physical CockroachDB Cloud cache flush.

REAL CONCURRENT-AGENT PRESSURE

Correct at 50 agents—and honest about the queue.

Each agent runs an exact 70% ANN read / 20% trusted memory promotion / 10% action-claim mix against the participant cluster. The application pool stays capped at 20 SQL connections.

Report gate850 total live operations
Peak throughputLoading…
50-agent p99Loading…
Pool recoveryteardown → first successful ANN read
AgentsOpsThroughputp50p95p99Action ownersPool recovery
Pressure evidence is loading…

Measured bottleneck: throughput peaks at 25 agents, then the 20-connection pool queues excess work at 50. Correctness holds—0 worker errors, 0 foreign rows, one durable action owner—but the next improvement is admission control, not an unbounded pool.

Recovery deliberately tears down and recreates the client pool. It is not represented as CockroachDB node failover.

FAIL-CLOSED KEY ROTATION

Replace, outwait the cache, prove, then retire.

  1. 1Stage

    New provider key enters a temporary GitHub secret without appearing in output.

  2. 2Replace

    AWS Secrets Manager receives a new version; prior value is retained for rollback.

  3. 3Outwait

    The workflow waits beyond the Lambda five-minute credential cache.

  4. 4Prove

    list_databases and list_tables pass; write remains denied.

  5. 5Retire

    Old Cockroach key and temporary GitHub secret are deleted.

WHY IT MATTERS

Long-running agents need memory.
Production agents need a memory firewall.

Continuum makes every durable memory answer two questions independently: “Is it relevant?” and “Is this caller authorized to see it?”