Welcome to Verity Discussions! #19
athenanewsapi
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Welcome 👋
Verity is an open-source, permission-aware memory layer for multi-tenant agents. It exists to do one job well: when many customers, teams, or users share a single memory store, an agent should never be able to recall something the current caller isn't allowed to see.
The short version of how: the permission check is compiled into the retrieval query itself as a mandatory pre-filter, not a prompt rule and not a post-retrieval filter. Permissions aren't hand-tagged either, they're inherited from the source systems (Google Drive, SharePoint/Entra, Salesforce, and more). A row you can't see is never a candidate in the first place, and if your scope can't be resolved, recall returns nothing. Fail-closed by construction.
This space is for:
Before you trust it, read the honest limits. HONESTY.md (./HONESTY.md) is the list of what Verity does not do yet, kept deliberately blunt. SPEC.md (./SPEC.md) is the build contract, and where implementation reality contradicts the spec, the spec gets amended in the open rather than quietly ignored. It's v0.1: it works, it's young, and the leak numbers are currently self-graded against sentinels I planted, not a third-party audit. I'd rather you know that going in.
Longer writeup of the failure mode that started all this: https://runverity.io/writing/agent-memory-leaks-permissions.html
Introduce yourself, ask anything, or tell me where it falls over. Glad you're here.
All reactions