Ground the conversation
recall returns relevant scoped context. It can include a
wish or tentative detail that helps the agent respond.
relevance for conversation
Trust review
ContextDB separates useful conversational context from evidence allowed to support a booking, refund, plan change, or record mutation. The policy and its executable evals are public.
memory → policy decision → host enforcement
This page documents current ContextDB action policy and host enforcement. For a vendor-neutral threat model covering memory writes, retrieval, actions, and erasure, read the AI agent memory security guide.
API and MCP identify the authenticated project credential, not the end
user named by user_id. ContextDB records that caller and
project context against one scoped memory. The customer host
authenticates the end user and retains any end-user attestation.
Console operator confirmation records operator context. None of these
records certifies that the statement matches the outside world.
project credential | operator + scoped memory + timestamp = confirmation record
Two retrieval paths
The agent can use relevant memory to continue a conversation while withholding that same memory from a consequential tool call.
recall returns relevant scoped context. It can include a
wish or tentative detail that helps the agent respond.
relevance for conversation
recall_for_action evaluates action-relevant evidence
under policy and returns act, ask, or
abstain.
evidence × policy → advisory outcome
The outcome is advice to the integration. ContextDB does not block a tool call by itself. The customer host must enforce the decision before any external side effect.
Action decision trace
This synthetic trace combines the fields a reviewer needs to inspect
an ask. It is an explanatory fixture, not customer data.
POST /v1/recall_for_action
{
"kind": "action_evaluation",
"decision_id": "synthetic-decision",
"outcome": "ask",
"reason": "action-relevant memory awaits confirmation",
"evidence_ids": [],
"pending_confirmation_ids": ["synthetic-memory"],
"policy_version": "default",
"request_id": "synthetic-booking-review"
}
ask → host does not execute → collect attestation → evaluate again
The host behavior shown here is an integration requirement. ContextDB records the advisory outcome, but it cannot enforce code inside the customer's agent host.
Policy matrix
Action relevance is necessary but not sufficient. The policy also evaluates source, confidence, corroboration, confirmation, slot class, contest state, and injection state.
| Evidence state | Action treatment | Qualification |
|---|---|---|
confirmed |
Eligible as trusted evidence | Caller/project or operator context is recorded. Confirmation is not end-user authentication or objective truth. |
corroborated |
Eligible when the class threshold is met | The policy requires independent corroboration for the slot class. |
user_stated |
Eligible only through the first-party shortcut | Confidence must meet policy, and excluded health, legal, and identity classes remain stricter. |
contested or injection_suspect |
Never trusted for action | The evidence may not authorize the external side effect. |
| Unknown slot | Ask or abstain by default | The first-party shortcut is disabled for unknown classes by default. |
Confirmation is one policy signal, not the only path to
act. Contested or otherwise untrusted evidence cannot
support act.
Read the public
trust policy
for the implemented rule definitions.
Host enforcement
ContextDB returns and stores the decision. The customer host checks it before calling the booking, billing, account, or workflow tool.
outcome == "act"
The host may continue under its own business rules.
outcome == "ask"
The host pauses the tool call, authenticates the end user, and retains any attestation before confirming one scoped memory.
outcome == "abstain"
The host does not run the action without another authorized path.
POST /v1/receipts
The receipt stores what the host reported. It is not independent proof that downstream state changed.
Public proof
Trust correctness lives in the public SDK. A behavior change lands with a public eval instead of a private Cloud patch.
VerifyBeforeAct, PII-before-embed, injection rendering,
and verifiable forgetting.
Current non-claims
Inspect the public evals that define current trust behavior.