Self-editing memory
Shipped in v3-alpha (Beta). Inspired by Letta/MemGPT but bounded by RBAC and audit. Interfaces may still change before 3.0 stable.
The autonomy v2 doesn’t give
In v2, only an extraction pipeline writes to memory. The agent itself can’t fix a typo, retract a wrong fact, or strengthen a strategy that just worked. v3 lets the agent edit its own memory — with hard guardrails.
The tool surface
{
name: "memory_self_edit",
description: "Edit your own memory. Use to correct errors, update outdated info, or strengthen important memories.",
inputSchema: {
action: "append" | "replace" | "strengthen" | "weaken" | "forget" | "reflect",
target: string, // fact_id, "profile", or "strategy:{id}"
content?: string, // new content for append/replace
reason: string, // MANDATORY — appears in the audit log
}
}Self-reflection cycle
Trigger: every 10 sessions OR explicit /self/reflect call
1. Review recent session outcomes (last 10 collapses)
2. Identify patterns:
- What strategies worked? → strengthen
- What strategies failed? → weaken + create alternative
- What facts were contradicted? → update
- What knowledge is missing? → flag for acquisition
3. Update memory worth scores
4. Optionally rewrite profile summary
5. Log reflection as an Episode (for next time)Safety guardrails
interface SelfEditPolicy {
// Allowed scopes
allowEdit: ("own_facts" | "own_strategies" | "own_profile")[];
// Require approval
requireApproval: ("delete_fact" | "edit_entity" | "change_decision")[];
// Rate limits
maxEditsPerSession: number; // default: 5
maxDeletesPerDay: number; // default: 3
// Audit
requireReason: boolean; // default: true (mandatory)
// Rollback window
editGracePeriod: number; // seconds before edit is permanent
}API surface
POST /v1/memory/self/edit Agent edits own memory
POST /v1/memory/self/reflect Trigger self-reflection
GET /v1/memory/self/profile Computed profile summaryWhy mandatory reason
Every self-edit creates an audit row. Reasons make it possible to diff “what the agent thought it was doing” against the actual effect. Most debugging of agent regression in production comes from this trail.
See also
- MCP
memory_self_edit - Agent RBAC & namespaces — the permission model
- Self-editing as governance — Worth changes after self-edits