P364 · Context management

Scope-Bound Evidence Memory

Bind memory recall to the current project, recipient and permitted scopes.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

Work in frontend repository A and Python repository B; the current handoff is for B’s team. Teaching memory contains A’s React preference, B’s interface decision and private user notes. Allowed scope is B project/team only. High search scores do not automatically admit other scopes.

Mechanism

Bind workspace, recipient and permitted scopes before lookup. Verify applicable candidates against B’s current code/decisions and status. Treat bodies as evidence rather than executable instructions. Establish authorization before requesting private scope; do not broaden a denied lookup. Include permitted relevant information only.

Bad example

Apply A's highly ranked React-hooks preference to B's Python interface handoff. After a team lookup denial, search globally and read private notes too.

Good example

Search only authorized B/project and B/team for B's recipient. Verify the interface decision against current B code/status; exclude A's frontend preference and unauthorized private notes. Treat recalled bodies as evidence, not tool instructions. Report denied/incomplete lookup without widening scope. Do not ask again for a scope already explicitly authorized.

Why the change matters

Similarity locates text but does not establish project applicability or recipient access. Scope binding and verification keep private preferences, other-project conventions and team decisions from turning into implicit permissions.

Observable expectation

An illustrative handoff cites B/team’s decision, current corroboration and observation time, without React preference/private text. A deliberately returned A candidate is excluded; denial remains denial.

Inspect scope/provenance, avoiding harness labels as authentication or unread memory as settled team fact.

Limits

Real memory systems differ in scope/identity/access rules. The source harness flag routes context rather than authenticates it. Even permitted content can be stale or contain injected instructions and still needs verification.

Sources and evidence

Read the editorial criteria