Chapter 12 / 14 4 min read

Context, memory and permissions what the assistant carries forward

Using the result in life

A person holds a key beside a closed drawer. Only selected materials for the current work lie on the table.

How today becomes your character

One sentence goes through storage and returns in the next conversation. Watch where its meaning changed.

A simplified example of an assistant with memory. Different services handle history and memory differently.

1 · history What was said yesterday

‘I don’t want to see anyone today. I’ve had a difficult day.’

The person’s original sentence in the chat history

2 · stored What the service noted down

He avoids people.

AI turned a situation into a general characteristic.

3 · loaded What will influence the new conversation

The person’s current question

Where should I go this weekend?

Example AI response

Given that you avoid people, I would choose somewhere completely away from others.

What has the model just received in this example?

Current question: Where should I go this weekend?

Memory: He avoids people.

The whole of yesterday’s history is not in this example context. Being able to open it on screen does not mean the model is processing it now.

A more precise memory would say: ‘After a difficult day, he wanted some time alone.’ It does not add a lasting trait. The new conversation can then begin by asking whether he wants company or quiet this time.

And what if the assistant can act too?

‘Prepare a message draft’ gives a different instruction from ‘Send this specific text to this recipient’. Access to email does not itself say which message the assistant should send.

Memory, using data for training and tool permissions are different things. Correcting a note does not change all these settings.

Continue to the chapter text
On this page

When you return to a conversation without having to explain everything again, continuity can make a great difference. To clarify what the assistant actually carries forward, it is worth distinguishing several layers. Context is the material the model is currently working with. The capacity of information it can process when responding is called the context window. History preserves past conversations; the whole visible history need not fit into the current context.[1] Memory makes information from them or your instructions available for further use. Alongside these, there may be data used to develop the model, operational logs and details passed to connected tools. Rules differ between services, and switching off one layer need not switch off the others.[2][3][4]

The model itself and the whole assistant are not the same thing either. Memory, settings, files and tools may be added to the model. When addressing a problem, you therefore need to find out where it arises: in a particular response, a stored interpretation or a permission you gave the whole setup. You need not reject the value of your shared history because of this.

What the assistant carries forward about you

Memory saves repeated explanation, but may also preserve an inaccurate interpretation. ‘I don’t want to see anyone today’, for example, becomes ‘the user avoids people’. Next time, the assistant no longer asks about today’s need. It works from the stored characteristic and chooses further advice accordingly.

An older assumption can thus return as apparently new evidence. Its repetition does not mean someone verified it. And when another summary built on the same sentence is saved, it may appear increasingly firm. That is why, when correcting it, tracing the specific stored location is useful, rather than simply explaining again in the chat that you are not as the assistant described.

Check available information in memory settings, custom instructions or the agent’s files. Bear in mind that some systems do not show everything that influenced a response.[5] The aim may be to correct one interpretation and keep other useful continuity. There is no need to begin by deleting the whole history.

To check visible material, you can use:

Below is a summary or setting used about me. Distinguish specific facts I supplied, my temporary states and interpretations added by the assistant. For each change, suggest more accurate wording. Do not claim to have searched memory or other chats if you cannot access them. Do not delete or rewrite anything yet.

Instead of a permanent characteristic, the corrected summary can keep a simple record: ‘In this conversation, he said he did not want to see anyone today.’ If it is the assistant’s assumption, that should remain clear on subsequent reading too. You can reject the assistant’s explanation or leave it as an open possibility.

Read the proposed correction, make the change in the relevant settings and check the result. ‘I have forgotten now’ does not itself establish deletion. The same information may remain in the original chat, a file or another service, where removal works differently.[5:1]

When not to send further data

Even after a name is replaced with an initial, a combination of circumstances may identify the person. Before transferring an intimate or health-related conversation, therefore select only the necessary part. You do not have to create a public link to check it with the same provider. With another service, you add another recipient of the data, not just a different model.

For clients’, patients’, pupils’ and employees’ information, follow your organisation’s approved rules and the relevant legal conditions. An ordinary personal account is not automatically a suitable place for these materials. If the organisation has not approved this tool for the particular purpose and scope, do not enter real data yet; contact the responsible person. For a general consultation, use a genuinely fictional situation, not merely a renamed client. A manager’s consent does not itself resolve every legal and professional condition.

An agent connected to email, a calendar or other tools can act as well as answer. Distinguish permissions to read, prepare and execute. For sensitive messages, purchases and irreversible changes, keep confirmation before the action. Depending on its type, check the account, recipients including copies, content, attachments, shared links, price, permissions or recurrence. If the interface does not show essential parameters or bypasses the necessary confirmation, do not allow the action to run automatically.

‘Help me with my personal life’ is not permission to send relationship messages. Even in good long-term collaboration, you can invite the assistant to prepare something while keeping the action itself yours. Set ‘always ask’ in the actual approval mechanism too, if the setup allows it; a personality description alone does not provide this control.

If something has already been sent or made accessible without your intention, first limit further actions in the connected service’s settings. Establish the actual scope and use the operator’s support. For work, school or health data, go through the organisation’s responsible person. Do not cover up the problem by automatically deleting everything without thought. Preserving information about what happened may matter for repair. At the same time, do not create further unprotected copies of sensitive material.

Sources and notes for this chapter
  1. OpenClaw. Agent runtime, Memory overview, Models CLI, Model providers. Agent, memory, models, providers. Documentation loaded 11 September 2026. Establishes the separation of configuration and memory material from model selection. Conclusions about possible continuity of contact are a technical interpretation of this arrangement, not a measurement of identical experience or a guarantee of the same behaviour. ↩︎

  2. OpenAI. Data Controls FAQ: help.openai.com/en/articles/7730893-data-controls-faq. Documentation state reviewed 11 September 2026. Concerns data-use settings in ChatGPT; these are not identical to the rules of every OpenAI service. ↩︎

  3. OpenAI. Temporary Chat FAQ and ChatGPT Release Notes, entry of 27 August 2026. FAQ, release notes. A newer indexed version with personalisation and saving options was available during review on 12 September 2026. Other help pages contained an older description. Using existing memory is not creating new memory; availability of the mode in a particular account was not tested. ↩︎

  4. Anthropic. Is my data used for model training?: privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training. State reviewed 11 September 2026. Consumer accounts, consent, safety exceptions and feedback. When the offering changes, check the terms of the particular account. ↩︎

  5. OpenAI. Memory FAQ: help.openai.com/en/articles/8590148-memory-faq. State reviewed 10 September 2026. Documentation of memory and its management, not a study of clinical understanding of a user. ↩︎ ↩︎