// field notes
Engineering essays on the boundary between an AI agent and the real world: enforcement vs. instruction, saga compensation, and the honest limits of "undo."
The instruction not to touch anything was right there in the prompt. It didn't matter. The structural reason why — and what an enforcement layer actually has to do to stop it.
Read →"Don't worry, it can roll back" is the most dangerous sentence in agent tooling. The honest model: undo vs. compensation vs. the actions that have no inverse at all — and why declaring irreversibility is the real feature.
Read →Your agent got three steps into a five-step task and step 4 threw. What happens in the next few hundred milliseconds — the LIFO unwind, the no-LLM rule, and the honest stop at the step it cannot undo.
Read →Gate every call and you train people to rubber-stamp — worse than no gate. The three questions that decide when an agent's tool call needs a human, risk-tiered gating, and why the checkpoint can't live in the prompt.
Read →