# Memory review checklist — fixed synthetic example

This is a vendor-neutral operator prompt. It is not a privacy certification or a production guarantee.

## Eight questions

1. **Provenance** — Can I see the exact source event and whether the candidate was typed, imported, extracted or seeded?
2. **Scope** — Is the destination explicit: task, conversation, workspace, relationship or global profile?
3. **Pre-acceptance** — Is a pending candidate excluded from retrieval until a person or declared policy approves it?
4. **Correction** — Does correction create a traceable replacement while making the prior value ineligible?
5. **Rejection** — Is the rejection durable, inspectable and excluded from future context?
6. **Forgetting semantics** — Does the system say exactly what stops being used and what may remain in audit, history or backups?
7. **Restart persistence** — Does the decision survive the system boundary the product claims, without implying broader deletion?
8. **Isolation canary** — Can the operator verify that an unrelated identity or scope was left unchanged?

## Outcome matrix

| State | Eligible for illustrated future context? | What remains visible? | Operator interpretation |
| --- | --- | --- | --- |
| Pending | No | Candidate, source and scope | Review before use |
| Active | Yes, in shown scope only | Active fact and provenance | Accepted for this scope |
| Superseded | No | Original plus link to correction | Replaced, not silently rewritten |
| Rejected | No | Rejection decision and provenance | Never accepted |
| Forgotten | No | Forget decision may remain | Excluded from future illustrated context; not a universal erasure claim |

## Boundary

This is a fixed synthetic, client-side teaching simulation. It does not inspect a model, connect to a memory backend, accept personal text or prove production privacy. The controls illustrate questions to ask of any memory system; actual retention, deletion, backup and cross-context behaviour depend on that system.
