Inspiration
AI agents are becoming capable of taking increasingly consequential actions, but most agent systems still blur two very different concepts: memory and authority.
A past incident, a similar embedding, or a previously approved action can be useful context — but it should never silently become permission to execute.
BOSAI Agent Memory Control Plane was built around one rule:
Memory informs proposals. Memory never authorizes execution.
What it does
BOSAI is a governed agentic-memory system for operational incidents.
The control flow is:
Observe → Retrieve Memory → Propose → Policy Check → Human GO → Execute → Readback → Evidence
CockroachDB acts as the persistent system of record for both:
- transactional memory: missions, proposals, approval permits, service state, and execution receipts;
- semantic memory: vector-indexed operational memory events.
For a new operational condition, BOSAI retrieves the most relevant historical incidents using CockroachDB vector search. That memory can influence a proposed action, but deterministic policy and a scoped, single-use Human GO permit remain the authority boundary.
The public judge demo is deliberately read-only: it replays verified evidence from the live CockroachDB proof rather than performing consequential production mutation in the browser.
How we built it
The project uses a dedicated CockroachDB Cloud database with six application tables:
missionsmemory_eventsproposalsapproval_permitsservice_stateexecution_receipts
memory_events contains a native VECTOR(3) operational vector. The three dimensions represent latency pressure, error pressure, and dependency-risk pressure.
A live nearest-neighbour proof uses the target vector [0.8, 0.7, 0.6].
CockroachDB ranks:
INCIDENT-2024-ALPHA—[0.75, 0.65, 0.55]— cosine distance ~0.000039INCIDENT-2024-BETA—[0.1, 0.2, 0.9]— cosine distance ~0.328616
This retrieval is explicitly non-authoritative:
MEMORY_AUTHORITY=falseVECTOR_AUTHORITY=falseLLM_AUTHORITY=false
The governance core is deterministic Python. It enforces Human GO for consequential execution, single-use permits, scope and mission binding, expiry checks, replay protection, and fail-closed readback verification.
The current automated suite passes 35/35 tests.
CockroachDB tools
Cloud Managed MCP Server
CockroachDB Cloud Managed MCP is configured against the project cluster in read-only mode. It provides a structured, auditable interface for inspecting persistent memory without widening the control-plane authority boundary.
Distributed Vector Indexing
CockroachDB native vector indexing powers semantic retrieval over historical operational memory. Transactional and semantic memory stay in one consistent database rather than requiring a separate vector store.
AWS integration
Amazon S3 is the live AWS evidence boundary used by the project. The dedicated bucket has public access blocked, versioning enabled, and AES-256 encryption.
The repository also contains a bounded Python 3.12 AWS Lambda readback runtime and a Linux-compatible deployment package. Live Lambda deployment is not claimed complete. The new AWS account currently has a concurrency quota constraint under AWS review, so BOSAI records that boundary explicitly instead of weakening its guardrails.
For the hackathon submission, Amazon S3 is the AWS service claimed as live and meaningfully integrated.
Governance model
BOSAI deliberately separates intelligence from authority.
A retrieved memory can affect a recommendation. It cannot approve itself. A model cannot issue its own authority. A vector match cannot become a permit.
Only deterministic policy plus an explicit Human GO can authorize a consequential transition.
Challenges
The hardest part was not implementing vector search. It was designing the boundary around it.
We had to ensure that semantic similarity never became implicit authorization, denied actions could not mutate service state, permits could not be replayed, readback mismatches failed closed, and database or AWS credentials never entered source control.
The Lambda quota constraint became another governance test: rather than silently changing the intended deployment boundary simply to make a demo look complete, BOSAI failed closed and documented the constraint.
What we learned
Persistent agent memory becomes much more useful when it is treated as part of a control system rather than as an unbounded context window.
CockroachDB is especially valuable here because transactional state and semantic vector memory can coexist in the same operational system of record.
The central lesson is simple:
An agent may remember why something worked before. That does not mean it has permission to do it again.
What's next
The next step is extending the same governed-memory model to longer-running operational workflows while preserving deterministic authority, explicit Human GO, durable evidence, verified readback, and fail-closed execution.
Built With
- amazon-web-services
- aws-iam
- aws-lambda-runtime
- cockroachdb-cloud
- cockroachdb-cloud-managed-mcp-server
- cockroachdb-distributed-vector-indexing
- github
- psycopg
- pytest
- python
Log in or sign up for Devpost to join the conversation.