Blog·Learning

Multi-Tenant Agent Memory: Scoping, Authorization, and Isolation

Design tenant and user scopes, enforce access on every path, and test memory isolation, deletion, caches, and background jobs.

By Shardul Mane·5 min read

Multi-Tenant Agent Memory: Scoping, Authorization, and Isolation

Multi-tenant agent memory needs authorization on every read and write, plus a stable scope attached to the data. A container tag or namespace helps select the right memory. It is not a substitute for checking which tenant and user the caller may access.

A useful test is simple: give two tenants similar conversations and the same local user ID. A request authenticated for tenant A must never return tenant B's context, even if the query is a better semantic match for B's data.

Does every tenant need a separate memory database?

Not necessarily. A shared store with enforced authorization and scoped queries can support logical separation. Separate databases or deployments may be appropriate when contractual boundaries, recovery requirements, or resource isolation demand them. A namespace alone establishes neither access authorization nor dedicated capacity.

Decide whether memory belongs to one person, a team, or a whole tenant before choosing the storage boundary. For shared knowledge sources, the connector permissions guide explains why permission changes must reach retrieval. The lifecycle guide covers what to verify when a tenant or user leaves.

Derive scope on the server

Resolve tenant membership and user identity from a trusted session or service identity. Then map that pair to the memory scope. Do not accept an arbitrary container identifier from a browser request and pass it through using a privileged API key.

For example, an application could maintain this mapping:

authenticated tenant + authenticated user → application-owned scope ID

An opaque identifier avoids embedding email addresses or other personal details in keys. The important property is a stable, unambiguous mapping, not a particular string format.

When using Supermemory's AI SDK integration, containerTag selects the memory scope and customId identifies the conversation document. Keep the scope stable across sessions that should share memory. Give distinct conversations distinct document identifiers.

Enforce the boundary at every entry point

Operation Required check
Write or import Caller may add data to the resolved scope
Search or profile lookup Caller may read that scope before retrieval runs
Fetch by document ID The document belongs to an allowed scope
Update, delete, or export Permission covers both the object and the operation
Background processing Job retains the original authorized scope
Cache lookup Cache key includes the relevant tenant and permission context

Stamping a tenant ID at ingestion does not make an unscoped read safe. Filtering only after results enter the model prompt is too late. Apply the access constraint before returning context to the agent.

Separate personal and shared knowledge deliberately

Some information belongs to one user; some belongs to a team. A support agent might need a customer's ticket history and the company's shared troubleshooting guide. Authorize these sources separately and preserve their provenance when combining them.

Do not infer permission from similarity or from the agent's requested task. “Search all customer tickets” is a request, not an authorization grant. Likewise, switching agent roles should not automatically grant access to another team's memory.

When membership changes, check what happens to sessions, caches, queued jobs, and previously retrieved context. Revoking access in the source application is useful only if downstream retrieval reflects the change within an understood interval.

Choose physical separation for a stated requirement

Logical isolation can use a shared database with enforced authorization. Dedicated databases or deployments provide different failure boundaries and operating costs. Neither architecture removes the need for application authorization and correct credential handling.

Evaluate separation against the actual requirement: customer-managed infrastructure, region restrictions, workload isolation, credential boundaries, or recovery procedures. Avoid treating a separate index as proof that infrastructure is dedicated; that depends on the implementation.

Test isolation with adversarial examples

Use a small synthetic dataset that you can inspect without exposing customer data. Include:

  1. Two tenants with the same local user ID and different private facts.
  2. A request that supplies another tenant's container ID.
  3. A direct document lookup for an object outside the caller's scope.
  4. A cache hit following a tenant switch in the same browser session.
  5. A queued write processed after the user's access was revoked.
  6. A shared document whose access is removed after ingestion.
  7. A retry that accidentally loses its original scope.

Check returned objects and the final model input, not just the answer. A model failing to mention leaked data does not mean the retrieval boundary held.

Treat deletion as a lifecycle operation

Supermemory documents a container deletion endpoint for a container and its associated documents and memories, restricted to organization owners and administrators. Your application must also handle copies it controls, such as exported transcripts, caches, and logs.

Pause or invalidate pending ingestion that could recreate deleted content. After deletion, check document retrieval, memory search, profile retrieval, and cached responses within the system's documented processing behavior.

Measure noisy-neighbor effects separately

Correct authorization does not guarantee fair use of shared resources. A large ingestion job can compete for capacity even when it cannot read another tenant's data.

Measure per-tenant ingestion lag, errors, retrieval latency, and resource consumption during a concurrent load test. Consider quotas, scheduling, and workload separation where the results justify them. A global average can hide a poor experience for a smaller tenant.

The release criterion is evidence: the intended scopes work, forbidden scopes fail, and background paths preserve the same rules. Keep those tests when changing SDKs, introducing new tools, or adding a connector.

For the related implementation, see Supermemory with TanStack Start: A Server-Side Memory Boundary.

To evaluate Supermemory in your application, start a two-tenant pilot using fictional records. Apply your authorization checks to both write and retrieval paths, then run the cross-tenant and deletion cases above before adding real customer data.

  1. An update to supermemoryWe've discontinued the supermemory company brain and Nova. Everyone who was charged has been refunded, our MCP and plugins continue to run, and we're going all in on the memory engine.
  2. Scaling Conversations: How Adapta Grew Usage Without Losing ContextAdapta added Supermemory as a persistent memory layer so every conversation keeps its context — letting the team scale usage without losing the thread.
  3. How Chatarmin Ditched RAG and Went Memory-Only with SupermemoryChatarmin replaced a heavy RAG pipeline with Supermemory's memory layer — cutting average AI response time from 40s to 12s and token usage by 40–50%.
  4. SMFS: making agentic retrieval 55% cheaper AND more accurateWe launched SMFS.ai (Supermemory Filesystem) a few weeks ago, with a simple bet: We can redesign the filesystem specifically for agents, with special files, structures, and commands that it can use for it's tasks. Today, SMFS is used by hundreds of companies to power their agents.
  5. Introducing Dynamic Dreaming: supermemory now connects the dots, for you.Dreaming is magical. TLDR: We're launching Dynamic Dreaming in supermemory today, which automatically works if you're using supermemory in any way - API, OpenClaw, Hermes agent, etc.
  6. Dear reader, we just made supermemory insanely cheap... the Context CloudWhen I first started building supermemory, I had one goal: To build the best memory system for AI. I would talk to customers, and find out that memory was not the only thing they needed - They were all setting up 7-8 different vendors at the same time.
  7. Introducing @supermemory/tools v2.0.0Today we're releasing v2.0.0. This release unifies the API across all agents sdk integrations from AI SDK to Mastra, makes conversation identity a first-class concept, and ships with memory saving on by default.
  8. Solving the Precision-Recall Tradeoff: Search Result AggregationWhen you're building memory for AI, search is your foundational layer. The way search generally works is straightforward: the user defines a query, and then sets a limit (top-K) on how many search results they want returned. Usually, this is set to 10 or 20.
  9. OpenClaw Memory Problems: Why It Forgets and How to Fix It (2026)TLDR: Today, we are releasing a new version of our openclaw plugin - https://github.com/supermemoryai/openclaw-supermemory. This post is going to be a bit technical, so bear with me (or bookmark for later!) In this post, I will talk about what we do about OpenClaw memory, and how we fix it.
  10. Stateful Coding Agents with Memory: Build Long-Running Agents (2026)We built a plugin for Claude Code and OpenCode that gives your coding agent persistent memory. It remembers your preferences, learns your codebase, and never loses context mid-conversation. The result is an agent you can run for months without starting over.
  11. Clawd / Molt bot's memory SUCKS. We gave it supermemory.I'm the founder of supermemory. Clawd/Molt bot is blowing up right now, with many, many use cases. I set it up, too, and have been using it through telegram. TLDR: just go to https://supermemory.ai/docs/integrations/clawdbot to set up supermemory for your clawd bot.
  12. Catch up with our UNFORGETTABLE Launch WeekOver the last year, one belief has guided almost everything we’ve built at Supermemory AI becomes meaningfully useful only when it remembers. Memory shouldn’t be something developers rebuild from scratch. It shouldn’t be fragile, expensive, or trapped inside a single tool.
  13. Empowering the Next Generation of Founders: Supermemory Startup ProgramIf there’s one thing we’ve learned while building Supermemory, it’s that most startups don’t fail because they didn't build features; they fail when infrastructure slows them down, or they built too slow.
  14. Building code-chunk: AST Aware Code ChunkingAt Supermemory, we're building context engineering infrastructure for AI. A huge part of that is dealing with code: ingesting repos, understanding structure, and making it searchable. The problem is that most code chunking solutions are terrible. We built code-chunk to fix this.
  15. Supermemory raises $3 million with the best memory engine for LLMsToday, I am excited to announce our first funding round to accelerate our mission of building an interoperable, scalable and reliable memory for LLMs and agents. Memory is one of the hardest challenges in AI right now.
  16. Mem0 vs Supermemory: Why Scira SwitchedScira AI moved its production memory layer from Mem0 to Supermemory. This is what failed, what improved, and how the team evaluated the two systems.
  17. Never Record Again: How Montra Uses Supermemory to Rethink Video CreationCampbell Baron, the founder of Montra, has been making videos since he was twelve. By thirteen, he was already doing brand work. Today, he’s betting on a very different future for creators: a world where recording is the exception, and most videos are generated from scratch.
  18. Unified Memory That Works Where You Work: Your Second Brain With SupermemoryHi everyone, I’m Dhravya, the founder of Supermemory. I want to start with a little story behind why this product means so much to me. You can also skip straight to what it is and how it works below.
  19. Supermemory just got faster on PlanetScaleWhat is Supermemory? Supermemory completes the missing part of the LLM puzzle: memory. Just as memory is crucial for human intelligence, it's essential for truly intelligent AI systems.
  20. Faster, smarter, reliable infinite chat: Supermemory IS context engineering.People are obsessed with prompts and prompt engineering. Sure, what you say is important, but what the model knows when you say it is the difference between a stateless text generator and an intelligent AI system. In short, context is the most crucial component.
  21. We solved AI API interoperabilityOne API to rule them all, One spec to find them, One library to bring them all and in the TypeScript, bind them. When we were building the the Infinite Chat API, initially, we only supported the OpenAI format. This was fine, until a lot of our customers started asking, asking for more.
  22. The Wow Factor of Memory - How Flow Used Supermemory To Build Smarter, Stickier ProductsOverview: Flow is a note-taking app built around a bold vision: to create a more personal, context-aware writing experience powered by AI. At the heart of this mission is memory.
  23. The UX and technicalities of awesome MCPsLast month, we launched the Supermemory MCP, mostly to test our own infrastructure and get some initial traction. It blew up. To my absolute surprise, the initial launch itself got half a million impressions (!!!). Then, we launched and got #2 on ProductHunt too.
  24. Architecting a memory engine inspired by the human brainLanguage is at the heart of intelligence, but what truly powers meaningful interaction is memory — the ability to accumulate, recall, and contextualize information over time. Large Language Models (LLMs) have mastered language, but memory remains their Achilles’ heel.