Skip to content

feat(context): multi-user vault visibility policy #86

Description

@Svagtlys

Description

With 2+ humans in one session, vector-search scoping of vault_items.user_id risks cross-user context injection: whose vault items are eligible for a session's assembled context? Record as a known constraint now; design when multi-user sessions enter scope.

Why

The shipped schema scopes vault items to a single user_id, which is unambiguous for the 1-user + 1-agent shape. Multi-human sessions make the injection policy ambiguous — a wrong default leaks one user's vault contents into another user's context.

Scope

  • Design decision (ADR) for vault visibility in multi-user sessions
  • Injection-time filter policy in the Context Manager when built
  • Tests once a multi-user path exists

Not blocked; design when multi-user enters scope. Spec: .agents/specs/2026-09-13-vector-db-schema-orm-design.md (Follow-up issues, item 2).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions