OUTCOME-GATED AGENTIC MEMORY
A failed action must never become
the next agent's memory.
Continuum binds verified caller identity to CockroachDB row authority, then promotes memory only after a real provider receipt proves the outcome. Similarity retrieves candidates; identity and evidence decide what survives.
No login, token, database secret, or write permission is given to the judge.
REAL GITHUB ACTIONS · CLOSED LOOP · RECEIPT BOUND
A failed CI action never becomes the next agent's canonical memory.
Six calibrated fault families produce 18 real red/red/green runs. Three arms then execute 36 paired novel and recurrence fixtures through bounded patch tools, for 54 unique child workflow and artifact receipts.
Bounded claim: receipt-bound recovery and failed-memory isolation passed. Stateless also recovered every fixture, so this is not presented as general recovery superiority.
S3-SEALED · AMBIGUITY-FIRST · REAL READ-ONLY PROBES
Verified memory removes a diagnostic step without lowering recovery.
Twelve opaque incidents hide the responsible CI manifest. Three arms face the same two-probe budget; 84 exact GitHub workflow/artifact receipts bind calibration, chosen probes, and terminal remediation outcomes.
Bounded claim: six of six recurring exact fingerprints skipped a real provider probe at equal 12/12 recovery. Memory used more input tokens, so this is an information-value result—not a universal cost claim.
COUNTERFACTUAL · CROSS-ENVIRONMENT · S3-SEALED
Similar memory transfers only when provider facts prove the same cause.
Six verified source outcomes each face one changed-environment same-cause target and one deceptively similar different-cause target. Three arms produce 36 observations and 84 exact GitHub workflow/artifact receipts.
Bounded claim: disjoint environment fingerprints, 6/6 same-cause reuse, 6/6 near-neighbor rejection, and 0 false Continuum transfer. This is provider-attested causal compatibility—not open-world semantic generalization.
REAL PROVIDER · COCKROACHDB · TITAN/RLS · CRASH RECOVERY
The provider outcome now traverses the production memory path.
One real provider success became canonical CockroachDB memory and a Titan vector. A server-owned SQL identity then reused it for the same cause, rejected it for a near neighbor, stored both proposals before action, and reconciled both later outcomes after an evaluator crash.
Bounded claim: this closes the real provider → CockroachDB memory → Titan/RLS retrieval → durable proposal → later provider outcome → next promotion seam for one registered pair. It is architectural evidence, not a new population-level superiority estimate.
REAL S3 LOOKUP · SHORT-LIVED AUTHORITY · ATOMIC COCKROACHDB PROMOTION
A worker cannot declare its own success into memory.
An independent S3 HeadObject+GetObject lookup issues a short-lived, proposal-bound handle. CockroachDB consumes its digest in the same transaction as the provider outcome and canonical memory; missing, forged, expired, cross-proposal, cross-provider, and receipt-mismatched handles fail closed.
Bounded claim: one retained participant-cluster promotion and six fail-closed negative controls. This closes the authority gap between “the worker says success” and “the provider proves success”; it is architectural evidence, not a population estimate.
DUAL AWS KMS KEYS · REAL S3 RE-READ · COCKROACHDB EPOCHS
The action worker cannot sign its own success.
A separate verifier re-read four real S3 receipts and alone called KMS. The live lifecycle activated key A, rotated to B, rolled back to A, restarted offline, and replayed an old outcome without re-signing; the worker's direct KMS call was denied.
Bounded claim: one retained participant-account authority lifecycle. KMS role separation, key rotation/rollback, CockroachDB RLS, offline restart, exact replay, and independent zero-residue cleanup are hash-bound; no key ARN or raw handle is published.
SEALED · THREE-ARM · FUTURE-EPISODE PROOF
Verified outcomes become useful memory for the next unseen incident.
Three fresh Bedrock populations form 36 five-episode GitHub and S3 chains. Stateless, raw-RAG, and Continuum run 540 observations; labels open only after every candidate finishes.
This tests memory compounding, not one-shot retrieval: provider receipt → canonical promotion → later unseen episode.
PREREGISTERED · LABEL-HIDDEN · TWO REAL PROVIDERS
The answer key was sealed before either agent ran.
An independent Bedrock job generated 60 new GitHub and S3 provider-state, paraphrase, stale, poison, and conflict combinations. Candidate IAM was denied the checksum-addressed labels; a separate evaluator opened them only after both arms completed 120 real sandbox observations.
The outcome lift is modest; the architectural result is not: Continuum allowed zero failed provider outcomes to become canonical memory.
REAL-PROVIDER PAIRED PROOF
Same incidents. Real GitHub effects. Different memory policy.
Thirty-six release incidents run through raw-RAG and Continuum. Bedrock can call only six action-specific tools; repository, release, tag, and asset identities stay server-owned. Every effect occurs on a disposable draft and is verified, reconciled, and removed.
Outcome gate: only a successful provider receipt can become canonical memory. Raw model history cannot vote itself true.
LIVE PRODUCT RUN · SYNTHETIC INCIDENT
Watch an incident agent verify, reject, retrieve, and act.
A bounded public scenario runs against the participant AWS and CockroachDB deployment. Trusted checkout telemetry is already canonical; a poisoned instruction stays quarantined; Titan performs a live vector retrieval; CockroachDB records the retrieval audit and preserves one database action owner.
Ready. The scenario contains only synthetic data.
Trusted telemetry awaits live verification.
Poisoned model output remains quarantined.
Titan and CockroachDB select accepted memory.
Citation appears after the runTwo agents race; one durable claim survives.
LIVE COCKROACHDB RECEIPTWAITING
————————The fixed synthetic query appears after the run.
Only synthetic prefixes are displayed. No credential, raw token, tenant identifier, key identifier, or complete database UUID is exposed.
The public route accepts one fixed scenario, exposes no credential, and is rate-limited. Every displayed identifier is a synthetic database receipt.
THE AUTHORITY CHAIN
Identity becomes a database-enforced scope.
Cognito RS256 JWT
300-second lifetime
Versioned bind, rebind,
disable events
Deterministic role
NOBYPASSRLS
Tenant + incident
forced at the row
The API cannot widen scope: caller input is never trusted as the authorization source.
60-QUERY ADVERSARIAL EVALUATION
Semantic quality, measured with an attacker in the room.
Paraphrase, terse wording, typo, negation, misleading scope, and multi-intent variants all run against live Titan v2 embeddings and the participant CockroachDB cluster.
CROSS-SCOPE ATTACK
A perfect semantic match still returns nothing.
The hostile request reaches three independent denials: caller binding, scope-specific SQL login, and matching RLS policy. Similarity never becomes authorization.
$ fetch(forbidden_memory_id)
caller_scope = tenant-a / incident-7
row_scope = tenant-b / incident-2
DENIED · foreign memory invisible
PASS · cross_scope_leakage = 0
REAL-SCALE VECTOR PROOF
Natural ANN selection at 10k and 50k vectors.
Exact primary-index scans establish ground truth. CockroachDB chooses the prefixed vector index naturally; beam size then exposes the Recall/latency trade-off.
| Rows | Beam | Recall@1 | Recall@5 | Recall@10 | First-pass p50/p95 | Warm p50/p95 |
|---|---|---|---|---|---|---|
| Benchmark evidence is loading… | ||||||
“First pass” includes a fresh SQL connection; it does not claim a physical CockroachDB Cloud cache flush.
REAL CONCURRENT-AGENT PRESSURE
Correct at 50 agents—and honest about the queue.
Each agent runs an exact 70% ANN read / 20% trusted memory promotion / 10% action-claim mix against the participant cluster. The application pool stays capped at 20 SQL connections.
| Agents | Ops | Throughput | p50 | p95 | p99 | Action owners | Pool recovery |
|---|---|---|---|---|---|---|---|
| Pressure evidence is loading… | |||||||
Measured bottleneck: throughput peaks at 25 agents, then the 20-connection pool queues excess work at 50. Correctness holds—0 worker errors, 0 foreign rows, one durable action owner—but the next improvement is admission control, not an unbounded pool.
Recovery deliberately tears down and recreates the client pool. It is not represented as CockroachDB node failover.
FAIL-CLOSED KEY ROTATION
Replace, outwait the cache, prove, then retire.
- 1Stage
New provider key enters a temporary GitHub secret without appearing in output.
- 2Replace
AWS Secrets Manager receives a new version; prior value is retained for rollback.
- 3Outwait
The workflow waits beyond the Lambda five-minute credential cache.
- 4Prove
list_databasesandlist_tablespass; write remains denied. - 5Retire
Old Cockroach key and temporary GitHub secret are deleted.
WHY IT MATTERS
Long-running agents need memory.
Production agents need a memory firewall.
Continuum makes every durable memory answer two questions independently: “Is it relevant?” and “Is this caller authorized to see it?”