Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents
Abstract
Enterprise AI agents that share a memory store run into two problems nobody has addressed: sensitive data can leak through results computed legitimately but never legitimately derivable by the requesting department, and departments can silently disagree on a metric's meaning when they compute a same-named key performance indicator (KPI) through different logic. Existing agent-memory systems (e.g., MemGPT, Zep, A-MEM) govern retrieval through content tags, ownership, and roles, but none record how a stored result was derived, so none can catch a cached insight that embeds a column the requester should not see. We introduce the Analytical Memory Unit (AMU), a memory schema that attaches a full derivation (lineage) graph to every cached result, together with a lineage-gated retrieval policy: a memory hit is served only when the requester is authorised for every column touched. Given a completeness assumption on lineage recording, we prove the policy blocks retrieval of results derived from a sensitive column outside the requester's permissions, at O(n) worst case. Across six experiments, lineage-gated retrieval removes the cross-department leakage that naive content-gated memory suffers at 18.8–25.5% of simulated retrievals, while keeping 81.5–82.6% of memory reuse, at a worst-case gating overhead of 13.8 μs. A small real-agent study using LLM-generated SQL suggests the guarantee holds on real agents, with zero leaks over 9 round-trips and two conflicts caught automatically. These results sketch a practical governance layer for shared agent memory that complements source-layer access control and supports compliance with regulation such as the EU AI Act.