Home / Articles / Practical notes: Feature Stores Spent a Decade Killing Temporal Leakage in ML.

This article is published in English.

Practical notes: Feature Stores Spent a Decade Killing Temporal Leakage in ML.

Operable walkthrough of Practical notes: Feature Stores Spent a Decade Killing Temporal Leakage in ML.: contracts, checks, and drop-in code slots for teams shipping this pattern.

2004 words

The following notes reconstruct a practical path around “Feature Stores Spent a Decade Killing Temporal Leakage in ML. AI Agent Memory Just Brought It Back.”. Emphasis stays on contracts, checks, and drop-in code placeholders rather than motivational framing. When working through the Overview stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

What feature stores actually guarantee, and why it took a decade to earn

The What feature stores actually stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

The acquisitions: the industry betting the puck is headed here

The The acquisitions the industry stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

Why vector-backed agent memory doesn’t inherit any of it

The Why vector-backed agent memory stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts. The Why vector-backed agent memory stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

The fix is an architecture decision, not a vendor decision

For the The fix is an stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

"""Naive vs. point-in-time-safe vector retrieval, mirroring feature-store
discipline. index.query() stands in for any vector DB client's metadata filter."""

from dataclasses import dataclass
from datetime import datetime, timedelta
from typing import Optional

@dataclass
class MemoryRecord:
    id: str
    text: str
    score: float
    event_timestamp: datetime  # when the fact became true, not when written
    metadata: dict

class FakeVectorIndex:
    """Mock vector DB client, so this example runs standalone."""
    def __init__(self, records: list[MemoryRecord]):
        self._records = records
    def query(self, vector: list[float], top_k: int = 5,
              filter: Optional[dict] = None) -> list[MemoryRecord]:
        results = self._records
        if filter and "event_timestamp" in filter:
            lte = filter["event_timestamp"].get("$lte")
            if lte is not None:
                results = [r for r in results if r.event_timestamp <= lte]
        return results[:top_k]  # mocked as already sorted by cosine distance

def naive_retrieve(index: FakeVectorIndex, query_embedding: list[float], top_k: int = 5):
    """Similarity only - no notion of 'as of when'."""
    return index.query(vector=query_embedding, top_k=top_k)

FRESHNESS_SLA = timedelta(hours=24)  # agent-memory-grain freshness window

def as_of_retrieve(index: FakeVectorIndex, query_embedding: list[float],
                    as_of: datetime, top_k: int = 5,
                    freshness_sla: timedelta = FRESHNESS_SLA) -> list[MemoryRecord]:
    """Point-in-time-filtered retrieval: only records true as of `as_of`
    (mirrors a feature store's join), then a staleness check before
    anything enters agent context."""
    candidates = index.query(
        vector=query_embedding,
        top_k=top_k * 3,  # over-fetch since staleness filtering happens after
        filter={"event_timestamp": {"$lte": as_of}},
    )
    fresh_enough = []
    for record in candidates:
        age = as_of - record.event_timestamp
        if age > freshness_sla:
            record.metadata["stale"] = True  # down-rank, don't silently drop
            record.metadata["age_hours"] = round(age.total_seconds() / 3600, 1)
        fresh_enough.append(record)
    fresh_enough.sort(key=lambda r: (r.metadata.get("stale", False), -r.score))
    return fresh_enough[:top_k]

if __name__ == "__main__":
    now = datetime(2026, 3, 15, 14, 30)
    stale_note = MemoryRecord(
        id="note-104", text="customer verified, low risk", score=0.94,
        event_timestamp=now - timedelta(days=150), metadata={},
    )
    fresh_note = MemoryRecord(
        id="note-889", text="high-velocity escalation flagged for review", score=0.91,
        event_timestamp=now - timedelta(minutes=10), metadata={},
    )
    index = FakeVectorIndex([stale_note, fresh_note])  # pre-sorted by similarity score
    top_naive = naive_retrieve(index, query_embedding=[0.0], top_k=1)[0]
    print(f"naive top hit: {top_naive.id!r} score={top_naive.score} "
          f"age_days={(now - top_naive.event_timestamp).days}")
    top_as_of = as_of_retrieve(index, query_embedding=[0.0], as_of=now)[0]
    print(f"as_of top hit: {top_as_of.id!r} score={top_as_of.score} "
          f"stale={top_as_of.metadata.get('stale', False)}")
naive top hit: 'note-104' score=0.94 age_days=150
as_of top hit: 'note-889' score=0.91 stale=False

Trade-offs: what as_of filtering costs

For the Trade-offs what asof filtering stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

When not to bother

For the When not to bother stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness. For the When not to bother stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

The real stakes, beyond one payments company

When working through the The real stakes beyond stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node.

Sources

When working through the Sources stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node.

Operational checklist

For the Operational checklist stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state.

Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

Write a short runbook: how to rotate keys, how to drain the queue, how to roll back the last ingest.

Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

Before promoting the stack, freeze versions, capture a golden transcript for the critical path, and confirm rollback steps. Shared environments need rate limits, tenancy checks, and a clear owner for secret rotation. Prefer boring reliability over clever one-off demos.

Batch note for bf903bce4a0b: keep provider keys out of the repo, set a per-session token ceiling, and store transcripts next to the eval fixtures so later model swaps stay comparable.

When working through the hardening note 0 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 0/949: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 1 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Hardening detail 1/949: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 2 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline.

Hardening detail 2/949: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 3 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments.

Hardening detail 3/949: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 0 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

Hardening detail 0/968: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 1 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 1/968: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.