Map every memory to a source and purpose.
Before revocation can work, each retained fact needs lineage: the message, page, file, or user reply that created it, plus the purpose described at the time.
Create user-facing memory cards.
Translate technical records into short memory cards: what the agent remembers, where it came from, when it was stored, and what it affects.
Add reply verbs to every sensitive reuse.
When memory appears in a new context, let the user reply with keep, narrow, expire, delete, or ask why. Avoid open-ended prompts when a structured verb will do.
Update the policy store immediately.
A revocation reply should update memory scope, expiry, and future routing rules. The agent should not ask again in the same broken way tomorrow.
Write a receipt users can inspect later.
Store what changed, who changed it, what source evidence was shown, and which future actions are now blocked or narrowed.