Build a Human-Approved Memory Queue for Your AI Agent A developer outlined a five-stage human-in-the-loop pattern — Observe, Detect, Review, Promote, Record — for keeping AI agent memory from absorbing one-off remarks as durable shared knowledge. The approach flags only patterns recurring across multiple users and sessions, requires a human reviewer to see and edit the exact text before it is promoted, scopes retrieval to a memory layer and its ancestors, and logs every decision in an audit trail with a demote function for reversing stale entries. The author warns that deep review queues cause rubber-stamping and recommends raising recurrence thresholds to keep the queue small. Give an agent memory and it will cheerfully remember the wrong thing. A support rep says "just refund it" once in a frustrated chat. A flat vector store happily indexes that line, and three weeks later the agent is quoting it as company policy. The fix isn't less memory. It's putting a human between "the AI noticed something" and "this is now shared knowledge." The pattern is simple enough to build in an afternoon. Observe → Detect → Review → Promote → Record Observe: log what agents see in conversations. Detect: only flag a pattern that recurs across enough distinct people and sessions. Review: a human sees the exact text that would be saved. Promote: approved text becomes shared memory. Record: every decision goes in an audit trail. python from collections import defaultdict observations = defaultdict lambda: {"users": set , "sessions": set } def observe pattern: str, user id: str, session id: str : observations pattern "users" .add user id observations pattern "sessions" .add session id def candidates min users=3, min sessions=5 : return p for p, o in observations.items if len o "users" = min users and len o "sessions" = min sessions One frustrated rep can't poison the memory. It takes a pattern across several people. python import time, uuid queue, memory, audit log = , {}, def propose layer path: str, text: str : item = {"id": str uuid.uuid4 , "layer": layer path, "text": text, "status": "pending"} queue.append item return item def review item id: str, reviewer: str, decision: str, edited text: str = None : item = next i for i in queue if i "id" == item id if edited text: item "text" = edited text reviewer can edit before approving item "status" = decision "approved" | "rejected" if decision == "approved": memory.setdefault item "layer" , .append item "text" audit log.append {"ts": time.time , "item": item id, "reviewer": reviewer, "decision": decision, "text shown": item "text" } The reviewer sees the exact text that will be written, never a paraphrase. A summary like "agents learned a refund rule" hides the dangerous detail. Flat indexes leak. A one-branch exception "the Mumbai office waives this fee" shouldn't answer a Berlin customer's question. python def retrieve layer path: str : """Return memory from this layer and its ancestors only.""" parts = layer path.split "/" results = for i in range 1, len parts + 1 : results += memory.get "/".join parts :i , return results propose "acme/emea/berlin", "Waive late fees under €20." after approval, only acme, acme/emea and acme/emea/berlin queries can see it Approval isn't forever. Add a demote item id that removes text from memory and logs it. Knowledge that was right in January can be wrong in June. Gotchas Reviewer fatigue. If the queue is 400 items deep, people rubber-stamp. Raise the recurrence thresholds until the queue stays small and meaningful. Static vs adaptive. Uploaded documents can be indexed immediately. Only learned patterns need the queue. Don't trust the detector. It surfaces candidates, and the human decides. An agent's memory https://www.covasant.com/products/synapse should be treated like production config: changes are proposed, reviewed, versioned and reversible. What's the strangest thing your agent "learned" that you had to delete? Tell me in the comments.