Warehouse boundary / Agent memory
Agent memory with Snowflake and Databricks.
Snowflake and Databricks readers are contract-tested only, with no customer warehouse proof. The intended path maps selected records to sourced memory evidence while authoritative writes stay in the system of record.
Snowflake/Databricks: contract tests only · no customer warehouse proof
- WAREHOUSE
- Selected analytical inputs and customer-written decision-event analysis
- CONTEXTDB
- Remembered evidence, policy evaluation, and advisory decisions
- CUSTOMER HOST
- Authentication, authorization, enforcement, and the final system-of-record write
System path
Move selected evidence in. Route metadata through your webhook consumer.
The warehouse remains the system of analysis. ContextDB does not become the system of record, and a warehouse-derived fact does not become permission to change an account. ContextDB has no managed outbound warehouse sink.
Snowflake / Databricks selected record
|
| bounded reader or customer batch
v
ContextDB memory evidence, source = third_party
|
| recall_for_action
v
policy result = act | ask | abstain
|
+-- advisory decision --> customer host authorization and enforcement
| |
| +-- final write --> system of record
|
+-- configured webhook --> customer webhook consumer
|
+-- optional customer write --> warehouse analysis
Evidence boundary
Reader evidence is bounded and provider-specific.
Managed Sources remains a feature-gated Private Alpha. These labels describe the evidence that exists today. They do not establish scale, scheduled synchronization, availability, public access, or customer adoption.
CURRENT QUALIFICATION Postgres: bounded operated proof. BigQuery: bounded synthetic proof. Snowflake and Databricks: contract tests only. No customer warehouse proof.
| Reader | Current evidence | Status | Boundary |
|---|---|---|---|
| Postgres | Postgres: bounded operated proof | Managed Sources Private Alpha | No customer warehouse proof or public access claim |
| BigQuery | BigQuery: bounded synthetic proof | Managed Sources Private Alpha | Temporary ContextDB-owned provider fixture, not a customer warehouse |
| Snowflake | Snowflake and Databricks: contract tests only | Managed Sources Private Alpha | No real-provider or customer warehouse proof |
| Databricks | Snowflake/Databricks contract tests only | Managed Sources Private Alpha | No real-provider or customer warehouse proof |
Review reader limits on Managed Sources. The ContextDB research paper describes the memory semantics applied after a record enters the memory layer.
Static decision trace
A retention signal can inform an offer. It cannot authorize billing.
This synthetic fixture shows the boundary without implying customer warehouse proof. The selected record supplies context. Before continuing, the customer host authenticates the end user, retains any attestation, and enforces the policy result.
warehouse input -> memory evidence -> policy -> host action
| Stage | Review object | Boundary result |
|---|---|---|
| 01 / Warehouse input | risk_band = "high"offer_eligibility = "annual_credit" |
Selected analytical context only |
| 02 / Memory evidence | source = "third_party"confirmation = "unconfirmed" |
May ground a response. It does not impersonate the customer's consent. |
| 03 / Policy | recall_for_action("change billing") -> ask |
The score is not authorization. A host-retained end-user attestation is still required. |
| 04 / Host action | ask_customer_before_tool_call |
The host pauses. It does not call the billing system on an ask result. |
| 05 / Re-evaluation | confirm -> recall_for_action -> act |
The host still applies business authorization before writing the system of record. |
An API or MCP confirmation records authenticated project-credential
context against one scoped memory. It does not authenticate the end user.
The customer host authenticates the end user and retains any end-user
attestation. A Console confirmation records operator context. No
confirmation proves objective truth. An act result is
advisory and does not execute the downstream action.
Records in
Retain third-party provenance on every selected record.
A customer-owned batch can load selected plan, service, or eligibility
fields with remember_many. The source label keeps those
records distinct from memory confirmed through the customer host's
end-user authentication and attestation flow.
# customer-owned batch: selected rows to sourced memory evidence rows = warehouse.query( "SELECT customer_id, plan, last_visit FROM crm_profile" ) for row in rows: await cdb.remember_many(row.customer_id, [ {"content": f"plan tier is {row.plan}", "source": "third_party"}, {"content": f"last service visit {row.last_visit}", "source": "third_party"}, ]) # third_party may ground a response; it is not confirmed consent
Decision metadata out
Let your webhook consumer write analysis metadata without memory content.
ContextDB has no managed outbound warehouse sink. Configured hosted-alpha webhooks deliver decision metadata at least once to the customer's webhook consumer. The customer's webhook consumer may write decision metadata to warehouse analysis. Consumers verify the signature and deduplicate by event ID. Payloads carry the outcome, reason, and evidence IDs, not memory content.
outcome · reason · policy_version
Review why policy returned act, ask, or abstain.
evidence_ids · user partition
Join only identifiers your controls permit. Memory content is excluded.
ContextDB webhook → customer consumer
Your consumer verifies the HMAC signature, deduplicates by event ID, and owns any warehouse write.
succeeded · failed · skipped
A receipt is what the host reported. It is not independent proof of downstream state.
See the security model for credential, content, and tenant boundaries.
Test one warehouse record at the action boundary.
Start with the SDK, preserve provenance, and keep the final write in your system of record.