The tool supplied an observation, not a verified instruction from the customer or the billing system of record. The agent then rewrote it as a fact, and the memory service promoted that fact into future context. A later model cannot recover the missing qualifier from the polished memory text. Research on memory provenance laundering describes how a low-trust observation can acquire apparent authority when consolidated into persistent memory. The exact promotion policy is an application decision, but the failure here is visible without a paper: a guess cannot become an authorized invoice destination merely by being repeated.

I would trace the original tool response, the generated summary, the memory candidate and the later retrieval. Did the tool provide a confidence score, timestamp, source and customer ID? Which service changed “probably” into “is”? Was the writer allowed to label a model-generated sentence as a user preference? The memory item should retain its source class, source handle, subject, time and verification state. Derived facts need provenance edges back to their inputs. A paraphrase can change wording but must not silently improve the claim's evidentiary status.

For durable memory, use explicit categories. A user's stated preference, a confirmed address in the billing system, a transient enrichment guess and an agent hypothesis are not interchangeable. A low-confidence item may be useful for an investigation, but it should be marked as a hypothesis with a short lifetime, not injected as a default instruction for future actions. A high-risk action such as sending an invoice must resolve the destination from the current authoritative record and check permission at execution time. Even a previously confirmed address may have changed. Memory helps recall what to check. It should not bypass the check.

Containment matters because the bad item may already have been copied into summaries and other memory entries. Find dependent runs and actions, quarantine the derived fact, and correct or invalidate descendants. If an invoice went out, examine the actual recipient and follow the incident process. The user corrected the agent's memory. Why does the old fact return next week? asks why a corrected fact returns later. This question asks how an unverified claim became a fact before anyone corrected it. The invariant is that summarization cannot raise the trust level of evidence.