Agent context should answer what it can and cannot know.
That should be explicit.
It can know the public notes.
It can know the public writing.
It can know the visible source trails.
It can know the stated uncertainty.
It cannot know the whole person.
It cannot know the held context.
It cannot turn a public pattern into a private claim.
The best agent context makes the boundary easier to respect.