π Day 141 β A Human Memory Layer: The RAG Vault My Agents Write and I Read Anywhere
π Topic
Setting up an Obsidian vault, synced to my iPhone, as the human-readable memory layer for the local agent system.
π― Goal
Make agent knowledge durable and reviewable: agents write structured notes to defined routes, and I can read everything from my phone.
π What I Did
I documented and wired up the RAG vault: an Obsidian vault that acts as the human memory layer on top of the agentsβ file-based memory. Agents route their outputs β audit notes, report drafts, operational summaries β into specific inbox folders with frontmatter tags, following written rules in an agent index. I ran smoke tests to confirm routed capture lands in exactly the right paths, and because the vault syncs to the iPhone, the whole systemβs memory is reviewable from anywhere.
Main areas covered:
- Obsidian vault as human-readable agent memory
- routed capture into inbox folders by category
- frontmatter metadata for source and route
- written rules governing what agents may write
- smoke tests verifying capture paths
- iPhone sync for review from anywhere
π Key Cybersecurity Connections
An agent-writable knowledge base is a data governance problem. Write rules are an access policy, routed paths are a controlled interface, and the no-secrets rule matters doubly when the vault syncs to a phone. Reviewability is what turns agent memory from a black box into an audit trail.
π Investigation Questions
- What are agents allowed to write, and where is that defined?
- Could a confused agent write outside its approved routes?
- Is anything sensitive syncing to the phone?
- Can I attribute every note to the agent and task that produced it?
- What happens if the vault and the agentsβ file memory disagree?
π¨ Detection Opportunities
Potential monitoring ideas:
- notes written outside approved inbox routes
- notes missing source or route metadata
- secret-like strings appearing in vault files
- unexpected volume spikes in agent-written notes
- sync conflicts as a tampering or drift signal
Example:
project=rag-vault
change_type=agent_written_note
risk_area=uncontrolled_knowledge_capture
triage=verify_route_metadata_and_content_policy
π§ MITRE ATT&CK Techniques
Possible mappings depending on confirmed behavior:
- T1565 β Data Manipulation
- T1530 β Data from Cloud Storage
- T1119 β Automated Collection
πΊ Visual Investigation Diagram
Agent output
β Routing rules
β Vault inbox folders
β iPhone sync
β Human review anywhere
β Challenges
The challenge was defining boundaries before convenience took over. It is tempting to let agents write anything anywhere; then the vault becomes a landfill nobody audits.
π What I Learned
I learned that memory design is trust design. Deciding what agents may remember, where they may write it, and who reviews it is the same exercise as scoping any systemβs data flows.
β‘ Next Steps
- Keep the agent write rules short and enforced
- Periodically scan the vault for secret-like content
- Review the inbox folders on a regular schedule
- Extend routed capture to new task families carefully
π§ Reflection
This was useful because it made the invisible visible: everything my agents learn or produce now lands somewhere I can read, question, and correct β even from my phone.
π§© Lessons Learned
What worked
Written write-rules and routed inbox folders from the start.
What broke
Early notes with duplicated headers and loose formatting.
Why it broke
The capture templates were newer than the agents using them.
Fix / takeaway
Version the templates with the rules, and smoke-test the routes.
π Skill Progression Context
This supports my cybersecurity progression because governed data flows, audit trails, and reviewable automation are core to how organizations keep AI systems accountable.
π TL;DR
My agents keep a diary; I set the rules and read it anywhere.
