Every “remember this” operation in a multi-user environment raises the question: remember it for whom? In a MAMU, or multi-agent, multi-user system, that question has to be answered with explicit visibility and promotion rules.
Working thesis: Privacy and sharing need explicit visibility classes and controlled promotion paths.
Why this matters for AI agents
An AI agent does not work from organizational reality directly. It works from the instructions, tools, memory, retrieved material and task state that reach its context window. That makes context selection part of the system architecture rather than a cosmetic prompt decision.
For one-off assistance, an imperfect context set may produce an inconvenient answer. For long-running or tool-using agents, the same weakness can persist across steps, be written into memory, propagate to another agent, or influence an external action. The engineering target is therefore not maximum information. It is sufficient, current and applicable information for the task at hand.
This is also why raw retrieval metrics tell only part of the story. A system can retrieve text that is semantically relevant yet still be wrong for the current project, user, environment or point in time. Conversely, an important constraint may have low lexical similarity to the user’s request but still be essential to safe execution.
A concrete example
A confidential management conversation may imply a project deadline change that can be shared without exposing the personnel information behind it.
A practical architecture
- Private. Keep the stage contract explicit so inputs, outputs and metadata remain inspectable.
- Project shared. Compose the smallest useful task-specific set and retain why each item was selected.
- Team shared. Compose the smallest useful task-specific set and retain why each item was selected.
- Candidate knowledge. Turn evidence into a reviewable candidate without silently increasing its authority.
- Approved knowledge. Keep the stage contract explicit so inputs, outputs and metadata remain inspectable.
Design principles
-
Classify visibility at write time and re-check at read time.
-
Propagate restrictions to summaries.
-
Support deletion and update, not only append-only recall.
-
Keep provenance, lifecycle state and permissions attached as context moves across tools and handoffs.
-
Evaluate context quality against the task outcome, not only similarity scores or token counts.
How AuzzurA approaches this
AuzzurA treats memory as one input to a broader context workflow. Memory can preserve experience, while people still need a clear path to review, scope and reuse what becomes trusted team knowledge.
Questions to ask before implementing this pattern
- What exactly are we persisting: raw source, memory, candidate knowledge or approved knowledge?
- Who owns an item, and who can change its status?
- How is scope represented across organization, team, project, environment, user, agent and task?
- How do we know when an item is stale, superseded or in conflict?
- Can we reconstruct which context reached a participant during a specific run?
- What learning from the run should return to shared context, and what review is required before reuse?
These questions tend to outlast individual model, vector-store and graph-engine choices because they define the organizational semantics around those components.
Sources and further reading
- AIM: A Privacy-Aware Interoperable Memory Framework for Multi-Agent Multi-User LLM Systems
- Collaborative Memory: Multi-User Memory Sharing in LLM Agents
- Governed Shared Memory for Multi-Agent LLM Systems
One team. One workflow. One governed loop.
Test AuzzurA with a single agent workflow in 2–4 weeks.