Revoked but Still Authoritative: An Empirical Study of Revocation Enforcement in Agent-Memory Systems
Abstract
Long-lived language-model agents depend on persistent memory. Current agent-memory systems preserve history through soft revocation: a contradicted fact is marked invalid and retained rather than deleted. Whether that mark is enforced at read time is unexamined. In this paper, we measure at runtime whether five such systems return revoked facts to agents that act on them. No system enforces revocation by default, and the failure takes three forms: the revocation is never recorded, never returned to the caller, or ignored at retrieval. Where the mark is exposed, the revoked fact was retrieved in every case, outranked its replacement, and led agents to the unsafe action in 44.2% and 42.1% of trials, against a zero baseline. Store-level filtering removes the effect. The missing control is a check on read-time validity, whether a record is still authorized when read, rather than on provenance, where it came from. We release a guard that wraps retrieval on any backend and withholds revoked and conflicting facts.