← Back to articlesGoverned agents

How ScrumDo gives agents context without hidden memory

App-managed context gives an agent the smallest relevant, authorized evidence set for one run, with provenance, scope, expiry, and human control visible instead of relying on an opaque memory store.

Architecture comparison between opaque vector store memory trap with ghost drift versus ScrumDo just-in-time bounded context package with zero retention

Context is assembled for work, not remembered in secret

An agent needs context to do useful work. That does not mean it should have an unlimited, invisible memory of every prior conversation. ScrumDo assembles context from the application records a person is already authorized to use: the card, accepted specification, selected customer stories, team interpretation, approved repository information, connector evidence, governance profile, and prior proof that still applies.

What belongs in a context snapshot

Context layerTypical contentsBoundary
Work recordCard, tasks, blockers, comments, accepted spec, and planTarget card and authorized related work
Human meaningCustomer stories, signifiers, product-owner interpretation, and team judgmentOnly the evidence visibility permits
Execution contextRepository ref, selected files, environment facts, and allowed skillsPinned target and approved scope
Connector contextGitHub, Sentry, Slack, or other approved tool resultsAllow-listed connector, resource, operation, and credential scope
Reusable contextAn accepted convention, decision, or verified fact saved for later workNamed owner, provenance, review state, scope, and expiry
Governance contextApprovals, proof profile, limits, and exceptionsVersion pinned to the run

Provenance prevents convenient fiction

A reusable context item with source, owner, scope, review status, and expiry

Every reusable fact needs an answer to five questions: where did it come from, who accepted it, where may it be used, when must it be reviewed, and how can it be revoked? Without those answers, a remembered statement can outlive the decision that made it true. A team renames an API, a customer policy changes, or an exception expires, yet the agent continues acting on yesterday as if it were permanent.

  • Source links distinguish observed evidence from interpretation and policy.
  • Scope prevents room context from silently becoming portfolio or organization context.
  • Expiry forces volatile facts back through review.
  • Revocation stops future use without deleting the historical explanation of prior runs.
  • Run snapshots preserve what the agent actually received, even if the live source changes later.

Context minimization is a product feature

More context is not always better. Large, contradictory context can reduce relevance, expose data unnecessarily, increase provider cost, and make review harder. The system should favor the smallest sufficient context set, show omissions that may matter, and let a person add an approved source when the agent is blocked. Retrieval should follow the user and agent permissions already in force, then apply additional governance limits rather than bypassing them.

Provider retention is a separate question

Application-managed context controls what ScrumDo sends for the run. The AI provider may have its own data-use, retention, regional, and contractual settings. An Enterprise review must examine both layers. A precise statement is therefore: ScrumDo assembles and records the authorized context it sends; the customer remains responsible for choosing and configuring a provider appropriate to its obligations.

Key terms

Context snapshot
The versioned set of authorized material assembled for one agent run.
Provenance
The source, author, time, review state, and transformations that explain where a context item came from.
Reusable context
A deliberately saved fact, decision, or convention with a defined owner, scope, approval state, and expiry.

Sources and standards context

  • NIST AI Risk Management Framework CoreNIST describes governance as a continuous, cross-cutting function and calls for documented human oversight, roles, testing, and accountability across the AI lifecycle.