Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - paperboytm/paperboy-memory: Privacy-native policy primitives for audience-scoped AI agent memory · GitHub
Skip to content

paperboy-memory

CILicense

Privacy-native policy primitives for audience-scoped AI agent memory.

paperboy-memory decides which memory stores an agent may access for one conversation run. It binds every run to an authoritative audience snapshot, fails closed when that audience changes, and makes private-to-public disclosure an explicit, auditable operation.

Important

This is a policy kernel, not a complete memory database and not a security certification. Your adapter remains responsible for authoritative identity data, transactional enforcement, encryption, storage isolation, and audit retention.

Why

Most agent-memory libraries start with retrieval and add privacy later. This project starts with the privacy boundary:

  • classify the audience before loading memory;
  • bind access to a short-lived PrivacyRun;
  • expose private stores only when the owner is effectively alone with their own agents;
  • revalidate the audience inside the same critical section as each write;
  • require reviewed text and owner approval for private-to-public publication;
  • consume ad hoc disclosure approval exactly once.

Status

v0.1.0 is an early policy-core release. The API may change before v1.0.0. It has no telemetry, network calls, persistence engine, or Paperboy service dependency.

Install

Install the release artifact directly from GitHub:

npm install https://github.com/paperboytm/paperboy-memory/releases/download/v0.1.0/paperboy-memory-0.1.0.tgz

The package is ESM-only and requires Node.js 22 or newer. It is not currently published to the npm registry.

Quick start

import{authorizeMemoryAccess,classifyAudience,issuePrivacyRun,}from"paperboy-memory";constaudience=classifyAudience({conversationId: "conversation_123",ownerUserId: "user_alice",surface: {kind: "direct"},members: [{id: "user_alice",kind: "human",active: true},{id: "agent_helper",kind: "agent",ownerUserId: "user_alice",active: true,},],});construn=issuePrivacyRun({agentId: "agent_helper", audience });// Obtain this again from your authoritative backend immediately before I/O.constcurrentAudience=audience;constaccess=authorizeMemoryAccess({
run,agentId: "agent_helper",conversationId: "conversation_123",
currentAudience,});if(!access.ok)thrownewError(`${access.code}: ${access.message}`);// Read/write only access.stores, with this call in the same transaction// or critical section as the operation.console.log(access.stores);

See examples/basic.ts for the complete example.

Policy model

Conversation contextStores exposed
Owner alone with their own agentsuser-private, agent-private, user-public, agent-public
Direct message with anyone elseuser-public, agent-public
Group conversationuser-public, agent-public
Workspace channeluser-public, agent-public, agent's server-shared store
Restricted channeluser-public, agent-public
Unresolvable audienceno PrivacyRun is issued

Unknown, external, foreign, and ownerless principals are treated as shared. An owner-controlled observer agent may be excluded from the audience; a foreign observer may not.

Public API

  • classifyAudience — turns authoritative membership and scope into an immutable classification and fingerprint.
  • issuePrivacyRun — binds an agent, owner, conversation, scope, audience, and expiry.
  • authorizeMemoryAccess — revalidates a fresh audience and returns stores only on success; use this at I/O boundaries.
  • evaluateRunGate — revalidates the binding for custom adapters and higher-level operations.
  • resolveAllowedMemoryStores / isStoreAllowed — applies only the pure store matrix after a run has already been validated.
  • memoryStoreKey — creates a validated logical key, never a filesystem path.
  • preparePublicPublication — creates a separate public document from owner-reviewed text without mutating its private source; sensitive lineage is returned as a separate audit.
  • decideDisclosure — approves or declines one exact, short-lived disclosure; approval cannot be reused.

Required adapter guarantees

The library cannot enforce these guarantees on its own:

  1. Membership, ownership, channel access, and conversation identity come from an authoritative backend, never from the model or client.
  2. PrivacyRun is created and retained on the trusted server; it is never accepted from a client or model as a token.
  3. A fresh audience is loaded and evaluateRunGate is called in the same transaction or critical section as every write.
  4. Logical store keys are mapped below a fixed storage root with backend-appropriate traversal, symlink, ACL, and tenant-isolation protections.
  5. A disclosure message insert and transition to consumed commit atomically.
  6. Publication approval and the new public document commit atomically; the immutable audit is stored outside public retrieval.
  7. Content safety, retention, deletion, encryption, and regulatory obligations are implemented by the host application.

Read the architecture, threat model, and security policy before integrating.

Development

npm ci
npm run check
npm run test:coverage

Contributing

Contributions are welcome. See CONTRIBUTING.md, GOVERNANCE.md, and CODE_OF_CONDUCT.md.

License

Apache License 2.0. See LICENSE and NOTICE.

About

Privacy-native policy primitives for audience-scoped AI agent memory

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages