Back to all work

Agentic AI engineering

Persistent Memory

Persistent memory for AI agents in Python, with versioned evidence, revocation checks, typed retrieval and an optional policy registry.

Summary

Persistent Memory is a Python library for storing information used by AI agents, tracing it to its sources and excluding corrected or withdrawn evidence. It combines versioned memory with a separate policy registry. The MIT-licensed alpha runs on Linux without a model or external database.

Role and scope

I design and develop the storage, retrieval and recovery mechanisms, the Python interfaces and the optional HTTP and MCP integrations. I also maintain the public packages, bilingual documentation, standalone examples and tests for failures, concurrent access and evidence withdrawal.

Problem and constraints

A search index or restored backup can still contain evidence that was corrected or withdrawn. A useful memory system must distinguish current evidence, outdated versions and unavailable validation before returning context to an application.

Architecture

SQLite stores immutable versions and links between sources and derived information. A separate authority and freshness witness determine which evidence is still usable. Rebuildable FTS5 indexes find candidates, which are checked again before retrieval.

Typed records distinguish documents, observations, hypotheses, procedures, tasks and feedback. Applications can assemble context within an explicit budget through Python, the CLI or optional HTTP and MCP interfaces.

An optional renderer turns supplied, reviewed facts into text using predefined French templates, preserving source versions and passages. The admission module checks the host’s authority and the final output buffer, and reports unknown, conflicting or withdrawn evidence.

Decisions and trade-offs

The index is a projection, not the authority. Writes use compare-and-swap; recovery from an old content snapshot begins in quarantine against a retained current authority. The optional registry separates policy proposal, evidence, admission and rollback, without activating policies or granting permissions.

Testing and verification

Tests cover concurrent access, evidence withdrawal, recovery from an older backup and package installation. Linux qualification passed 145 memory tests and 36 policy-registry tests for both wheel and source distributions, using synthetic data.

Public results

Version v0.3.0a1 includes installable packages, checksums and English and French documentation; the separate policy registry remains at 0.1.0. Standalone demos show evidence withdrawal and recovery, rejection of a changed output buffer and handling of uncertain delivery outcomes.

Resources and links

Scope and current status

The library is in alpha. Recovery requires a current authority and freshness witness kept outside the restored content backup. Withdrawal affects future library reads, not exported copies or information already learned by a model.

Optional rendering and admission use supplied, reviewed facts and authenticated host authority. The host manages callback deadlines and interruptions. These modules do not extract or semantically verify facts, provide atomic authorization and publication, or replace a durable handoff journal or callback sandbox.

A delivery acknowledgment does not prove downstream consumption. Uncertain effects are not retried. The linked documentation describes the recovery and admission contracts in detail.

Next case study

Bifrost

View case study