Scope keys
The keys memories are partitioned by.flow_idPartitions per Flow. Every run using that Flow shares the same memories.thread_idPartitions per conversation. Usually paired withflow_idso each conversation keeps its own memories.user_idPartitions per user. Memories accumulate separately for each user.- Custom key Beyond those three, any value sent along with the call can be a key. For example,
org_id.
thread_id and the caller supplies user_id.
That means a custom key has to use exactly the name the call sends. If the caller sends org_id, put org_id in the custom key. Putting in organization_id, which the call doesn’t send, means no scoping happens.
With no keys at all, the space is global and every run shares one store.
Combining scope keys
Scope keys can be combined, and the combination becomes a single unit of storage. Usingflow_id and thread_id together makes one conversation the unit of storage; adding user_id on top stores separately per user even within the same conversation. The more keys you add, the smaller the unit of storage.
Pick one of the following in the memory space settings. The first four are presets holding common combinations.
- Session
flow_idandthread_id - User long-term
user_id - Flow shared
flow_id - Global No keys
- Custom combination Select whichever of
flow_id,thread_id, anduser_idyou need, and create custom keys to combine alongside them.
Access control
Where scope partitions storage, access control governs reads. It limits who can reach this memory space and decides which items to show them. Partition key (personalize) Pick a single value as the basis and callers see only the items matching their own value of it. Leave it blank and everyone sees the same items. Choose fromNone, Per user (user_id), Per org (org_id), and Per client (client_id), or type in a custom claim.
Requires (gates) Block access itself with a condition. A call that doesn’t pass can’t read this memory space. Each rule takes the form param + operator (in / eq) + a list of allowed values. Clicking Admins only creates the rule user.permission in admin, owner right away, and + Rule adds more conditions. With several conditions, all must pass for access.
How to debug
If an Agent’s answer mixes in memories from another scope, check the following.- Look at the memory operations in the trace. Every read and write is logged with its scope.
- Find items written at a broader scope than intended.
- In the Access section of the memory space’s Settings tab, confirm the partition key and required permissions are set the way you intended.