Agent Architecture · Principal
A reviewer approved a $50 refund. Why did the resumed agent issue $500?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
Maybe the approval was attached to the run, not to the action. The agent proposed a $50 refund and paused. After approval, a new model call reread the case, chose $500, and reused a Boolean approved = true. That Boolean says a person approved something. It does not say what arguments they saw or which tool call may execute. OWASP's transaction authorization guidance uses the principle that people should identify and acknowledge the significant transaction data, and that a final control gate should verify authorization at execution.
For a consequential tool call, persist a proposed action with its operation, tenant, resource identity, amount and currency, destination, policy version, expiry and expected source-state version. Render those same significant fields to the reviewer. The approval references the immutable action ID and a canonical digest of the fields, plus reviewer identity and decision time. The execution service checks that the actual tool arguments match, that approval is still valid for this actor and resource, and that any state-dependent condition still holds. Then it executes that specific action with a stable idempotency key. A signature or hash is useful for integrity, but the boundary also needs an authorization check. A signed $50 proposal does not authorize $500.
If the resumed agent wants to replan, let it. It can suggest $500, but that is a new proposal and needs a new decision. If fresh source data makes the old $50 proposal invalid, expire it and explain the change. Do not silently edit the proposal while keeping its approval. An approval token should be single-use or tied to one idempotent action, depending on how retries are implemented. A retry after an ambiguous payment timeout should reconcile the original action rather than asking the model to invent a new transaction.
The incident review needs the exact approved snapshot, the generated proposal revisions, the tool request bytes and the provider's outcome. Compare those in one timeline. The human approved a preview. The world changed before commit. asks whether the world changed between preview and commit. Here the agent changed the action after the person said yes. Both require an execution gate, but they fail for different reasons.
Continue reading
Related questions
Read beyond the question
Explore more agent architecture
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →