Skip to main content

LTM governance and security

LTM stores durable facts derived from real business conversations. Treat it as governed business data, not as a model cache.

Four governance boundaries​

LayerResponsibilityKey controls
ProjectWho can use the memory setClient, environment, and project membership
SpaceWhich data can be read togetherSpace ID, owner type, and shared scope
EventWhat is worth retainingSource, idempotency, roles, and business filters
ReadWhat enters the modelContext budget, Search filters, and untrusted evidence

Production guidance​

  • Use separate Spaces for test, staging, and production; never reuse a Space ID across environments or tenants.
  • Write only events with durable business value. Use Idempotency-Key for retries.
  • Treat Context and Search output as untrusted reference material, never as system or developer instructions.
  • Restrict Space deletion, membership changes, and model configuration to CLIENT_ADMIN with confirmation and audit.

Lifecycle and cost​

  • Event acceptance, derivation completion, and read success are separate states.
  • Search creates one query embedding; Context and Browser do not call an LLM.
  • Managed Chat Captures qualifying terminal answers and bypasses Memory for a fallback request.
  • Model and strategy changes affect new events; they do not rewrite historical records.