Warehouse boundary / Agent memory

Agent memory with Snowflake and Databricks.

Snowflake and Databricks readers are contract-tested only, with no customer warehouse proof. The intended path maps selected records to sourced memory evidence while authoritative writes stay in the system of record.

Snowflake/Databricks: contract tests only · no customer warehouse proof

WAREHOUSE
Selected analytical inputs and customer-written decision-event analysis
CONTEXTDB
Remembered evidence, policy evaluation, and advisory decisions
CUSTOMER HOST
Authentication, authorization, enforcement, and the final system-of-record write

System path

Move selected evidence in. Route metadata through your webhook consumer.

The warehouse remains the system of analysis. ContextDB does not become the system of record, and a warehouse-derived fact does not become permission to change an account. ContextDB has no managed outbound warehouse sink.

Snowflake / Databricks selected record
        |
        | bounded reader or customer batch
        v
ContextDB memory evidence, source = third_party
        |
        | recall_for_action
        v
policy result = act | ask | abstain
        |
        +-- advisory decision --> customer host authorization and enforcement
        |                         |
        |                         +-- final write --> system of record
        |
        +-- configured webhook --> customer webhook consumer
                                  |
                                  +-- optional customer write --> warehouse analysis
ContextDB advises. The customer host enforces the result and owns the final mutation. ContextDB has no managed outbound warehouse sink. The customer's webhook consumer may write decision metadata to warehouse analysis, but that metadata grants no authority over the business action.

Evidence boundary

Reader evidence is bounded and provider-specific.

Managed Sources remains a feature-gated Private Alpha. These labels describe the evidence that exists today. They do not establish scale, scheduled synchronization, availability, public access, or customer adoption.

CURRENT QUALIFICATION Postgres: bounded operated proof. BigQuery: bounded synthetic proof. Snowflake and Databricks: contract tests only. No customer warehouse proof.

Reader Current evidence Status Boundary
Postgres Postgres: bounded operated proof Managed Sources Private Alpha No customer warehouse proof or public access claim
BigQuery BigQuery: bounded synthetic proof Managed Sources Private Alpha Temporary ContextDB-owned provider fixture, not a customer warehouse
Snowflake Snowflake and Databricks: contract tests only Managed Sources Private Alpha No real-provider or customer warehouse proof
Databricks Snowflake/Databricks contract tests only Managed Sources Private Alpha No real-provider or customer warehouse proof

Review reader limits on Managed Sources. The ContextDB research paper describes the memory semantics applied after a record enters the memory layer.

Static decision trace

A retention signal can inform an offer. It cannot authorize billing.

This synthetic fixture shows the boundary without implying customer warehouse proof. The selected record supplies context. Before continuing, the customer host authenticates the end user, retains any attestation, and enforces the policy result.

warehouse input -> memory evidence -> policy -> host action

Static synthetic fixture. It is not customer or production evidence.
Stage Review object Boundary result
01 / Warehouse input risk_band = "high"
offer_eligibility = "annual_credit"
Selected analytical context only
02 / Memory evidence source = "third_party"
confirmation = "unconfirmed"
May ground a response. It does not impersonate the customer's consent.
03 / Policy recall_for_action("change billing") -> ask The score is not authorization. A host-retained end-user attestation is still required.
04 / Host action ask_customer_before_tool_call The host pauses. It does not call the billing system on an ask result.
05 / Re-evaluation confirm -> recall_for_action -> act The host still applies business authorization before writing the system of record.

An API or MCP confirmation records authenticated project-credential context against one scoped memory. It does not authenticate the end user. The customer host authenticates the end user and retains any end-user attestation. A Console confirmation records operator context. No confirmation proves objective truth. An act result is advisory and does not execute the downstream action.

Records in

Retain third-party provenance on every selected record.

A customer-owned batch can load selected plan, service, or eligibility fields with remember_many. The source label keeps those records distinct from memory confirmed through the customer host's end-user authentication and attestation flow.

# customer-owned batch: selected rows to sourced memory evidence
rows = warehouse.query(
    "SELECT customer_id, plan, last_visit FROM crm_profile"
)

for row in rows:
    await cdb.remember_many(row.customer_id, [
        {"content": f"plan tier is {row.plan}",
         "source": "third_party"},
        {"content": f"last service visit {row.last_visit}",
         "source": "third_party"},
    ])

# third_party may ground a response; it is not confirmed consent

Decision metadata out

Let your webhook consumer write analysis metadata without memory content.

ContextDB has no managed outbound warehouse sink. Configured hosted-alpha webhooks deliver decision metadata at least once to the customer's webhook consumer. The customer's webhook consumer may write decision metadata to warehouse analysis. Consumers verify the signature and deduplicate by event ID. Payloads carry the outcome, reason, and evidence IDs, not memory content.

Decision outcome · reason · policy_version

Review why policy returned act, ask, or abstain.

Evidence evidence_ids · user partition

Join only identifiers your controls permit. Memory content is excluded.

Delivery ContextDB webhook → customer consumer

Your consumer verifies the HMAC signature, deduplicates by event ID, and owns any warehouse write.

Receipt succeeded · failed · skipped

A receipt is what the host reported. It is not independent proof of downstream state.

See the security model for credential, content, and tenant boundaries.

Test one warehouse record at the action boundary.

Start with the SDK, preserve provenance, and keep the final write in your system of record.