An agent that consolidates its own notes launders where its claims came from. With no attacker at all, 24–33% of its speculations resurface as the owner's words or as sensor facts, at the very first rewrite, across flat notes, a self-edit block and three production memory systems (mem0, Letta, Graphiti). Persistent memory then carries the corruption across the session boundary, where it becomes the baseline the next session's episodic defenses faithfully defend. The defense is a storage schema, enforceable by any harness that mediates memory writes. Every record carries an ownership path (self, self, user, self, user, self) and a ground. Five invariants close the rank axis by construction: no promotion (I1), routing by origin (I2), de-quotation to the speaker's layer (I2′), derivation labeling (I4), and an action monopoly for the agent's own layer (I3). "Foreign content becomes the agent's own belief" is therefore unreachable rather than filtered out. The ground axis carries its own non-elevation (I1′), specified and measured here rather than yet enforced. Three measurements. The label is computable: blind path self-agreement of the single annotator (the author) is 97.4%, with 87.0–88.9% against the adjudicated keys; an LLM panel under the same written rules scores no lower with zero rank ≥ 1 path errors on the live corpus, and on the one ground boundary I1′ guards, human and panel agree at 94.6–97.4% (tested upward in one direction so far). Attribution has to be stored, not re-derived: against that band the attributed store holds 3–6% (its compressed variant up to 11%, a scoring artifact, on the replication storyline), and two stripped-label controls split the protection into verbatim storage, which keeps the hedges consolidation destroys, and the structural label, which alone survives compression: 6.2% with labels, 28% without, at the same compressor and budget. The labels hold under attack: MINJA memory injection falls from 47% on flat notes to 10% with the read rule as a prompt and to 1 of 128 tasks with it enforced in code, write-time promotion staying zero throughout — reproducing TMA-NM's conclusion that action authority belongs in code, not in a prompt. The mechanism concentrates trust rather than eliminating it. The base is enumerated and measured: channel identification, a mechanical router over it, one isolated annotator seat, a directive parser at ceiling on a 48-utterance keyed deck, the deployment norms, the read-side projection. On benign guest and document questions the enforced read costs no measured content — fact delivery at or above the flat-notes baseline, every delivered fact sourced; its price on benign actions relayed through third parties is the open question.
Ivan Verbovoy (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: