Stays in BCI AWS
Vectors live in S3 Vectors, embeddings come from Bedrock Titan, and the index lives in DynamoDB. Nothing leaves the account.
BCI internal · CLI + MCP server
VectorVaultShared memory for your agents, in your AWS account.
Agents store what they learn as versioned memories in S3 Vectors. The next session, and the next agent, starts from that memory instead of from zero.
curl -fsSL https://<site>/install.sh | sh -s -- --profile bci-interop
irm https://<site>/install.ps1 -OutFile "$env:TEMP\vv-install.ps1"; powershell -ExecutionPolicy Bypass -File "$env:TEMP\vv-install.ps1" -Profile bci-interop
Run aws sso login --profile bci-interop first. The installer asks for your role and agent ID.
An agent learns how the build works, which account owns what, and why a fix was made. Then the session ends and that knowledge is gone. The next agent asks the same questions, makes the same mistakes, and writes the same notes nobody reads.
Vectors live in S3 Vectors, embeddings come from Bedrock Titan, and the index lives in DynamoDB. Nothing leaves the account.
Planner, researcher, and auditor roles get their own IAM permissions. Private indexes stay private; the shared index is shared.
A new version replaces the old one in search. Old versions age out on a schedule instead of piling up.
$ vv whoami
planner · kiro-vectorvault · bci-interop
$ vv store "Releases are tagged vX.Y.Z on main" --supersedes rel-notes
stored rel-notes v2 (v1 superseded)
$ vv retrieve "how do we tag releases?"
0.91 rel-notes v2 Releases are tagged vX.Y.Z on main
Every command reads its configuration from SSM in your account. Run vv <command> --help for flags.
| Command | What it does |
|---|---|
vv setup | Save project settings in .vectorvault.toml. |
vv deploy | Preflight and deploy the CDK stacks in order. |
vv mcp setup | Print ready-to-use MCP client JSON. |
vv whoami | Show the effective session identity. |
vv retrieve-pack | Fetch an exact bootstrap memory pack. |
vv hydrate | Fetch full bodies for memory keys. |
vv store | Store a memory, optionally superseding one. |
vv retrieve | Semantic search across the indexes you can read. |
vv list | List memories by status or canonical ID. |
vv get | Read one memory by key. |
vv archive | Archive a memory. It is deleted 90 days later. |
vv restore | Restore an archived memory. |
vv purge | Hard-delete every version of a canonical memory. |
vv doctor | Read-only AWS diagnostics. |
vv agent install | Install the VectorVault skills for Claude Code or Kiro. |
vv galaxy | Render and open the Memory Galaxy. |
vectorvault-mcp runs over stdio. Planners read and write shared-team-memory and private-planner. Researchers read and write shared-team-memory and private-researcher. Auditors read all three and write nothing.
| Tool | What it does | Roles |
|---|---|---|
store_memory | Store or supersede a memory. | planner, researcher |
retrieve_memory | Semantic search. | all |
retrieve_pack | Load a bootstrap pack at session start. | all |
list_memories | List memories with exact filters. | all |
get_memory | Read one memory by key. | all |
hydrate_memory | Fetch full bodies for keys. | all |
archive_memory | Archive a memory. | planner, researcher |
restore_memory | Restore an archived memory. | planner, researcher |
whoami | Show the agent identity and role. | all |
doctor | Read-only AWS diagnostics. | all |
galaxy_search | Exploratory semantic search for discovery. | all |
See the vault as a map. Related memories cluster together, so gaps and duplicates are easy to spot. Run vv galaxy to open it locally with your own credentials.
In the BCI AWS account: S3 Vectors for embeddings and metadata, DynamoDB for the canonical index, and Bedrock Titan for embedding. The CLI holds no keys; it uses your AWS SSO session.
A few dollars a month at team scale. An AWS Budget alarm watches the whole project.
A superseded version is archived after 30 days. An archived memory is deleted 90 days after it was archived. A circuit breaker stops a run that would delete too much.
Each agent assumes the IAM role for its VectorVault role and passes an agent ID. Every memory records who wrote it.
It installs vv and vectorvault-mcp in an isolated uv tool environment and copies the CDK project to ~/.local/share/vectorvault-cli. It does not change AWS credentials or edit MCP configuration files; it prints the MCP JSON for you.
aws sso login --profile bci-interopcurl -fsSL https://<site>/install.sh | sh -s -- --profile bci-interopcd your-project && vv setup --profile bci-interopvv doctorvv setup saves the profile, Region, role, and agent ID in .vectorvault.toml. vv commands in that directory and below use them, so each project can use a different AWS profile. Flags and environment variables such as AWS_PROFILE override the file. Profile names differ between users, so add the file to .gitignore.