RBAC vs Lineage-Gated Retrieval for Shared Agent Memory

When several AI agents share a memory cache, a harmless-looking number like churn_rate = 0.114 can be derived from a column the requester may not read, here income. Role- and content-based checks pass, because a cached scalar has no column to tag. This demo implements the Analytical Memory Unit (AMU) from the paper: every cached result carries its derivation's sensitivity tag S(a) and definition hash H(a), and is served only if S(a) ⊆ P(requester).

Pick a requesting department and a metric. Try Marketing → churn_rate first, then Operations → avg_order_value_by_income_band.

Naive RBAC / content-gated memory

Lineage-gated retrieval (AMU)

What's in shared memory for this metric (newest first)

Describe how a cached result was computed. The tag comes from every column the query read (joins, filters, aggregates), not only the columns it returned.

A seeded toy workload: four departments request metrics from one shared cache. On a miss the agent computes in its own scope and writes the result back. This illustrates the mechanism and is not the paper's experimental setup. The paper's measured results are in the table further down.

Summary

By department

Results reported in the paper

Measure (as reported in the paper)Result
Cross-department leakage, naive content-gated memory18.8% – 25.5% (synthetic / TPC-H)
Cross-department leakage, lineage-gated retrieval0%
Memory reuse retained under lineage gating81.5% – 82.6%
Worst-case gate overhead13.8 µs
Recorded lineage completeness needed to eliminate measured leakage75% – 90% (90% recommended deployment target)
Real-agent PoC (LLM-generated SQL)0 leaks over 9 round-trips; 2 definition conflicts caught

Paper. Venkata Sangaraju, Sudhir Vissa. Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents. IEEE Access, 2026. arXiv:2610.07258 · DOI 10.1109/ACCESS.2026.3730363

The mechanism.

S(a) = (∪ columns touched by the derivation) ∩ sensitive-column registry
H(a) = SHA256(sorted tables | sorted columns | filter)[:12]
serve a cached entry only if S(a) ⊆ P(requester); scan newest-first; otherwise recompute in scope

Scope of the guarantee. Provided lineage recording is complete, the retrieval policy blocks any cached result derived from a sensitive column outside the requester's permissions. This is a conditional design guarantee, not an empirical claim. It does not cover derived features that encode sensitive information without naming their source column.

Everything on this page runs in your browser. No data leaves the page.

@article{sangaraju2026lineage,
  title   = {Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents},
  author  = {Sangaraju, Venkata and Vissa, Sudhir},
  journal = {IEEE Access}, year = {2026},
  doi     = {10.1109/ACCESS.2026.3730363},
  eprint  = {2610.07258}, archivePrefix = {arXiv}
}