Memory & knowledge
An agent with no memory is a goldfish with API keys. But the naive fixes each fail: stuffing the context window doesn't scale, dumping turns to a blob isn't recallable, and bolting on a vector database ignores that memory has owners. OAP gives an agent an authorized, searchable store with a knowledge-graph layer — it remembers within reason.
How it works
Memory is three layers: durable storage, ranked search (structured filters, full-text, and vector
similarity, fused and re-ranked), and a knowledge-graph layer that extracts entities and facts. Two kinds
of recall coexist: query is boolean filtering ("everything tagged X"), search is scoring ("what's most
relevant to this").
Every read and write is authorized per subject through the same SpiceDB graph as everything else — reading is session membership, writing and deleting are the creator's — so memory isn't a shared bucket. And the transcript, authorization decisions, and audit records are an append-only, cryptographically signed, tamper-evident log you can verify offline. Durable outputs — rendered reports, pages, charts — are a first-class thing of their own, with their own section: see Artifacts.
Go deeper
- Storage, search & the knowledge graph — the three-layer stack and how recall works.
- Facts & observations — durable knowledge attached to resources, not just to a transcript.
- Per-subject authorization — how the memory store is gated by the same graph as tools.
- The tamper-evident audit log — append-only, signed records and
oap audit verify.