When should an agent memory be scoped per-session, per-user, or globally?
answer
- narrowest scope that still works
- scope decided at write time
- blast radius grows with the tier
- common across users is not universal
- partition key, not a filter
basics
~20 sDefault to the narrowest scope that makes the memory useful: session for task state, user for anything personal or account-specific, global only for knowledge that is true for everyone. Scope is decided at write time and enforced as a hard partition, because a wrong global memory affects every user.
solid answer
~60 sTreat scope as a required field on every memory, chosen when it is written, not as a ranking hint applied later. Three tiers cover most systems. **Session scope** holds task state that should die with the conversation — the current plan, intermediate results, a one-off preference like "answer briefly today". **User scope** holds anything that should greet the person next time: preferences, account context, history-derived facts. **Global or organization scope** holds knowledge true regardless of who is asking — a deployment runbook, an internal glossary, a company policy. The default is the narrowest tier that makes the memory useful, because blast radius scales with scope: a wrong session memory spoils one conversation, a wrong global memory misleads everyone. Promotion between tiers should be evidence-driven and usually reviewed — a pattern seen once is a session observation, seen repeatedly for one user it becomes a user fact, and it becomes global only when it is verified as generally true rather than merely common. Enforce scope as a partition key so a query cannot cross tenants, not as a filter you might forget.
go deeper
Know that memories carry a scope and that personal facts belong to a user rather than to everyone. Be able to give an example that clearly belongs in each of session, user and global.
Explain why scope is assigned at write time and enforced structurally, and describe what actually goes wrong at each tier when it is set too wide — from one spoiled conversation to a fact that misleads every user.
Show the promotion path with an explicit evidence bar, and separate the multi-tenant organization tier from a true global one as a security boundary. Bring up deletion and retention before you are asked.
Own the governance question: who is allowed to promote a memory to a tier that affects everyone, what review that requires, and how a bad promotion is revoked without rebuilding the store. Be willing to argue that a global tier should not exist at all in some products.
## Scope is a property of the memory, not of the query The single most useful framing: every stored memory carries the scope it was written at, and that scope determines who can ever see it. If scope is only applied at read time as a filter, then every new read path is an opportunity to forget it — and forgetting it once means one user's private fact surfaces in another user's session. Making scope a partition key, so that a query without a scope simply cannot return rows, converts a discipline problem into a structural one. ## The three common tiers **Session scope.** State belonging to the conversation or task in progress: the plan, tool results, a temporary instruction such as "keep answers short for now". It should expire with the session. The mistake here is promoting transient instructions into durable preferences — an agent that permanently believes you want terse answers because you once said so in a hurry is a familiar annoyance. **User scope.** Facts about a specific person or account that should persist: language, units, role, plan tier, recurring goals, things learned from past sessions. This is the tier most agent products actually need, and the tier with the strictest privacy obligations, since it is personal data with retention, export and deletion requirements attached. **Global or organization scope.** Knowledge that is true independent of who is asking: a runbook, a schema description, a policy, a shared glossary. In multi-tenant systems this usually splits again — organization scope shared within one customer, and a true global tier shared across all of them. The distinction matters because customer-specific knowledge escaping to a global tier is a data-leak incident, not a quality regression. Agent scope is a fourth tier worth mentioning in multi-agent systems: knowledge belonging to one specialist role rather than to any user. ## The promotion path Memories should move outward through tiers only as evidence accumulates, and the bar should rise at each step. A single observation in one session is exactly that — an observation. Repeated across several sessions for the same user, it becomes a candidate user fact; the repetition is the evidence that it reflects a stable preference rather than a moment. Promotion beyond the user to organization or global requires a different kind of justification entirely: not "many users do this" but "this is true regardless of user". Frequency across users is weak evidence, because it can encode a majority preference as a universal rule and quietly degrade service for the minority. In practice, promotion into a global tier is where human review belongs. It is cheap to review because it is rare, and the cost of getting it wrong is paid by every user simultaneously. ## Blast radius and reversibility Size the guardrails by blast radius. A wrong session memory costs one conversation and dies on its own. A wrong user memory costs one person and persists until corrected, which is why users should be able to see and delete what the agent believes about them. A wrong global memory costs everyone and is the case worth engineering against: provenance recorded on write, a review step before promotion, and the ability to revoke a single promoted memory without rebuilding the store. ## Demotion, expiry and deletion Scope is not only a widening path. Facts can narrow, too — knowledge that turns out to be team-specific should drop out of the global tier rather than being patched with exceptions. And scope determines deletion semantics: a user-scoped memory must be removable when that user is deleted, which is much harder if their facts have already been folded into a global summary. That is a concrete reason to keep tiers physically separate rather than merging them for retrieval convenience. ## What interviewers are listening for They want to hear that you would not write everything at the widest tier because it is convenient, that you can articulate the promotion evidence bar, that you treat scope as enforced structure rather than a hint, and that you have thought about deletion and multi-tenancy before being asked. Saying plainly that a global memory tier is optional — that many successful agent products ship with session and user scope only — signals judgment rather than architecture-for-its-own-sake.
- What evidence would justify promoting a user-scoped fact to a global tier?Evidence that it is true independent of the user, not that many users share it. A verified runbook step or a schema fact qualifies; "most users prefer terse answers" does not, because that encodes a majority preference as a universal rule and degrades service for everyone else. Because the cost of a wrong global memory is paid by every user at once, that promotion is normally worth a human review step.
- How does user-scoped memory interact with a deletion request?It has to be removable, which is straightforward while the facts sit in their own scoped rows and much harder once they have been folded into a shared summary or a global aggregate. That is a concrete architectural reason to keep tiers physically separate rather than merging them for retrieval convenience, and to record provenance so you can trace which derived artifacts a deleted fact contributed to.
- Where does an organization tier fit between user and global in a multi-tenant product?It holds knowledge shared inside one customer — their runbooks, terminology, internal policies — and it is usually the more important of the two wide tiers. The distinction from global is a security boundary, not a convenience: customer knowledge reaching a cross-tenant global tier is a data-leak incident rather than a quality regression, so the two should be different partitions with different promotion paths.
saying these in an interview costs you the question
- Writes every learned fact at the widest scope for convenience
- Applies scope only as a read-time filter instead of a partition
- Promotes a one-off instruction into a permanent user preference
- Treats popularity across users as proof a fact is universal
- Assumes every agent product needs a global memory tier