Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents
Abstract
Enterprise AI agents that share a memory store face two unaddressed risks: sensitive data can leak through legitimately computed results the requester could not derive, and departments can silently compute a same-named key performance indicator (KPI) through conflicting logic. Existing agent-memory systems (e.g., MemGPT, Zep, A-MEM) gate retrieval by content, ownership, and role, not derivation, missing a cached insight that embeds a forbidden column. We introduce the Analytical Memory Unit (AMU), a memory schema that attaches a full derivation (lineage) graph to every cached result, gated by a retrieval policy that serves a hit only when the requester is authorised for every column touched. Provided lineage recording is complete, we prove by construction that the policy blocks retrieval of results derived from a sensitive column outside the requester's permissions, at O(n) worst case -- a conditional design guarantee, not an empirical claim, that excludes derived features encoding sensitive information without naming their source. Eliminating measured leakage required 75-90% recorded lineage completeness, so we treat 90% as a conservative deployment target. Across six experiments, lineage-gated retrieval removes the 18.8-25.5% cross-department leakage naive content-gated memory suffers, keeping 81.5-82.6% of memory reuse at 13.8 microsecond worst-case overhead. A real-agent proof-of-concept with LLM-generated SQL is consistent with the guarantee: zero leaks over 9 round-trips, two conflicts caught automatically -- though a feasibility demonstration, not evidence of production viability. This offers a practical governance layer for shared agent memory, complementing source-layer access control and supporting EU AI Act compliance.
Community
Shared memory for AI agents has a leak that RBAC doesn't catch. A cached result like churn_rate = 0.114 can be derived from a column the requester isn't allowed to read (here, income). The value itself has no column to tag, so role- and content-based checks pass. We attach a derivation (lineage) record to every cached result. The cache serves a result only if the requester is permitted every column it touched.
Naive shared memory leaks 18.8โ25.5% of cross-department requests (synthetic and TPC-H). Lineage gating brings that to 0%, keeps 81.5โ82.6% of memory reuse, and adds at most 13.8 ยตs per lookup.
A definition hash also flags when two teams compute a "same-named" KPI with different logic.
The guarantee is conditional on complete lineage recording. We measured that 75โ90% completeness eliminates the leakage.
๐ Try the leak in your browser: https://huggingface.co/spaces/sangaraju1988/lineage-gated-memory. Pick Marketing โ churn_rate.
Accepted at IEEE Access (DOI: 10.1109/ACCESS.2026.3730363).
This is an automated message from the Librarian Bot. I found the following papers similar to this paper.
The following papers were recommended by the Semantic Scholar API
- Quipu: A Governed Bitemporal Knowledge Graph Store (2026)
- ChurnBench: A Drift-Aware Benchmark Demonstrating That Refresh Scheduling, Not Cache Age, Governs Staleness in Agentic AI (2026)
- Utility Under Attack: Agent Memory Poisoning and the Limits of Content Screening and Provenance Ranking (2026)
- AkasicMEM: Governed Enterprise Memory for Agents (2026)
- Fresh Memory, Stale Plans: Derivation Currency for Distributed LLM-Agent Memory (2026)
- Models as Governed Interfaces for AI-Native MBSE: Read-Side Adequacy and Write-Side Admissibility (2026)
- PAPC: Platform Mediation for Privacy-Propagation Externalities in AI-Mediated Workflows (2026)
Please give a thumbs up to this comment if you found it helpful!
If you want recommendations for any Paper on Hugging Face checkout this Space
You can directly ask Librarian Bot for paper recommendations by tagging it in a comment: @librarian-bot recommend
Get this paper in your agent:
hf papers read 2610.07258 Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash Models citing this paper 0
No model linking this paper
Datasets citing this paper 1
Spaces citing this paper 1
Collections including this paper 0
No Collection including this paper