{"version":"2.1.283","anchor":"resume-records-its-source-session-forked-skills-and-agents","canonical_anchor":"account-memory-mcp-server-can-set-how-much-subagents-may-do","heading":"Subagents limited in what they can do with account memory","tier":"notice","area":"Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/resume-records-its-source-session-forked-skills-and-agents","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Subagents limited in what they can do with account memory\n\nAccount memory servers can now set whether subagents get full, read-only or no access, and by default only the main agent can change memory\n\n**Unclear.** It is not clear what the new record or the passed permission mode changes for you in practice.\n\n**What**\n\nAn account memory server is an MCP server, a plug-in tool provider, that stores things Claude remembers about you across sessions. Subagents are helper agents Claude starts to handle part of a task. They now have restricted access to that memory.\n\n- The server can advertise an experimental capability named `anthropic\/memory`. Its `subagent_memory` field can be `all`, `read_only` or `none`, and `subagent_note` can hold up to 4096 characters. If several servers set it, the most restrictive value wins.\n\n- A value that cannot be read counts as `none`.\n\n- If no server sets it, the mode is `read_only`.\n\n- The tools handed to a subagent are filtered by a new `subagentMemoryMode`. Tools from the memory server are removed unless they are on a read-only list, and `none` removes them all.\n\n- Forked slash commands and observer agents now pass the current permission mode as `subagentMemoryMode` when their tools are chosen.\n\n- A subagent, teammate, fork or backgrounded query that tries to change account memory is refused. The message says only the session's main agent can change it, and asks it to say in its reply what should be saved.\n\n- Subagents no longer see the memory server's resources, and reading one directly fails with a message pointing them to the server's tools.\n\n- Separately, `--resume` now records the source session's `sourceSessionId` and `transcriptPath`.\n\n**Why**\n\nHelper agents can no longer freely rewrite what Claude remembers about you. Changes to account memory go through the main agent, and the memory server decides how much subagents may read.\n\n- Area: Sessions\n- Names: `--resume`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 4\/5"}