BCI internal · CLI + MCP server

VectorVault

Shared memory for your agents, in your AWS account.

Agents store what they learn as versioned memories in S3 Vectors. The next session, and the next agent, starts from that memory instead of from zero.

curl -fsSL https://<site>/install.sh | sh -s -- --profile bci-interop

Run aws sso login --profile bci-interop first. The installer asks for your role and agent ID.

Every new session starts from zero.

An agent learns how the build works, which account owns what, and why a fix was made. Then the session ends and that knowledge is gone. The next agent asks the same questions, makes the same mistakes, and writes the same notes nobody reads.

Why VectorVault

Stays in BCI AWS

Vectors live in S3 Vectors, embeddings come from Bedrock Titan, and the index lives in DynamoDB. Nothing leaves the account.

One role per agent

Planner, researcher, and auditor roles get their own IAM permissions. Private indexes stay private; the shared index is shared.

Supersede, do not duplicate

A new version replaces the old one in search. Old versions age out on a schedule instead of piling up.

How it works

$ vv whoami
planner · kiro-vectorvault · bci-interop
$ vv store "Releases are tagged vX.Y.Z on main" --supersedes rel-notes
stored rel-notes v2 (v1 superseded)
$ vv retrieve "how do we tag releases?"
0.91  rel-notes v2  Releases are tagged vX.Y.Z on main
  1. active — returned by search.
  2. superseded — a newer version exists; hidden from search.
  3. archived — 30 days after it was superseded, or when an agent archives it.
  4. deleted — 90 days after it was archived. A daily worker does this.

Commands

Every command reads its configuration from SSM in your account. Run vv <command> --help for flags.

CommandWhat it does
vv setupSave project settings in .vectorvault.toml.
vv deployPreflight and deploy the CDK stacks in order.
vv mcp setupPrint ready-to-use MCP client JSON.
vv whoamiShow the effective session identity.
vv retrieve-packFetch an exact bootstrap memory pack.
vv hydrateFetch full bodies for memory keys.
vv storeStore a memory, optionally superseding one.
vv retrieveSemantic search across the indexes you can read.
vv listList memories by status or canonical ID.
vv getRead one memory by key.
vv archiveArchive a memory. It is deleted 90 days later.
vv restoreRestore an archived memory.
vv purgeHard-delete every version of a canonical memory.
vv doctorRead-only AWS diagnostics.
vv agent installInstall the VectorVault skills for Claude Code or Kiro.
vv galaxyRender and open the Memory Galaxy.

MCP server

vectorvault-mcp runs over stdio. Planners read and write shared-team-memory and private-planner. Researchers read and write shared-team-memory and private-researcher. Auditors read all three and write nothing.

ToolWhat it doesRoles
store_memoryStore or supersede a memory.planner, researcher
retrieve_memorySemantic search.all
retrieve_packLoad a bootstrap pack at session start.all
list_memoriesList memories with exact filters.all
get_memoryRead one memory by key.all
hydrate_memoryFetch full bodies for keys.all
archive_memoryArchive a memory.planner, researcher
restore_memoryRestore an archived memory.planner, researcher
whoamiShow the agent identity and role.all
doctorRead-only AWS diagnostics.all
galaxy_searchExploratory semantic search for discovery.all

Memory Galaxy

See the vault as a map. Related memories cluster together, so gaps and duplicates are easy to spot. Run vv galaxy to open it locally with your own credentials.

00h 04h 08h 12h +40° +0° -20° releases iam roles ttl lifecycle mcp tools 1 point = 1 memory · synthetic data

FAQ

Where does my data live?

In the BCI AWS account: S3 Vectors for embeddings and metadata, DynamoDB for the canonical index, and Bedrock Titan for embedding. The CLI holds no keys; it uses your AWS SSO session.

What does it cost?

A few dollars a month at team scale. An AWS Budget alarm watches the whole project.

What happens to old memories?

A superseded version is archived after 30 days. An archived memory is deleted 90 days after it was archived. A circuit breaker stops a run that would delete too much.

How does an agent get its identity?

Each agent assumes the IAM role for its VectorVault role and passes an agent ID. Every memory records who wrote it.

What does the installer change on my machine?

It installs vv and vectorvault-mcp in an isolated uv tool environment and copies the CDK project to ~/.local/share/vectorvault-cli. It does not change AWS credentials or edit MCP configuration files; it prints the MCP JSON for you.

Quick start

  1. aws sso login --profile bci-interop
  2. curl -fsSL https://<site>/install.sh | sh -s -- --profile bci-interop
  3. cd your-project && vv setup --profile bci-interop
  4. vv doctor

vv setup saves the profile, Region, role, and agent ID in .vectorvault.toml. vv commands in that directory and below use them, so each project can use a different AWS profile. Flags and environment variables such as AWS_PROFILE override the file. Profile names differ between users, so add the file to .gitignore.