Scope is the isolation boundary that keeps memory from leaking across contexts. Despite the name Shared Global Memory, SGM memory is not globally public — isolation is mandatory and enforced by every conforming implementation.
User
└── Organization
└── Workspace
└── Project
└── Session
└── Task
Narrower scopes are contained within broader ones. A task scope belongs to a
session, which belongs to a project, and so on up.
A record’s scope is an object naming the levels that apply. A record MUST
declare at least the levels down to where it lives; unlisted broader levels are
inherited from context.
{ "user": "alice", "project": "myproject" }
{ "organization": "acme", "workspace": "platform", "project": "api", "session": "20261010-104120" }
At minimum, a scope MUST include enough to place the record unambiguously. The
project level is the most common isolation boundary in practice.
A conforming implementation MUST enforce:
S is visible to retrievals scoped to S
or to any broader scope containing S.S MUST NOT return records in a scope
that S does not contain — including sibling projects, other users, and
other organizations.The word global in SGM’s name means shared across an agent’s own tools and
sessions — one brain, many clients. It never means world-readable. The
user scope is the top of the hierarchy, not the whole internet.
An implementation MAY support explicitly-authorized cross-scope retrieval (e.g. an org-wide search). When it does, it:
Two independent implementations MUST agree on:
user, organization, workspace, project,
session, task),They need NOT agree on the authorization mechanism, how scopes are stored, or whether they support cross-scope search at all.