Agent Architecture · Principal
The agent approved an action on account 42. Why did it hit a new account 42?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
The number 42 may be the same while the thing it names has changed. Imagine a legacy system that reuses local numeric account IDs after deletion. The agent prepared a change for account 42, a human approved it, and the workflow waited overnight. In between, the old account was deleted and the ID was assigned to a different account. A resume that fetches by ID and blindly applies the approved change can be perfectly idempotent and still change the wrong object.
At preparation, bind the approval to an object incarnation, not just a display ID. That could be an immutable provider ID, a generation ID that changes on recreation, or a version and immutable subject identity checked together. The tool must enforce the expected incarnation in the same operation that makes the change. An earlier GET followed by an unconditional POST leaves a race. HTTP's If-Match condition and DynamoDB's conditional version update illustrate conditional writes, though the actual API must expose a validator that distinguishes a recreated object. A simple version counter reset to 1 on recreation could suffer the same ID-reuse problem.
If the condition fails, stop the action, fetch the current object and ask for a fresh decision. Do not silently reinterpret yesterday's approval against today's object. Log the approved subject, expected incarnation, action parameters and the condition failure without dumping private account data. A test should delete and recreate an object between approval and execution, and another should update the original object without replacing it. Those may need different review policies, but neither should accidentally pass an unconditional write.
If the provider offers only update(id) and can reuse IDs, we cannot guarantee the binding by adding more reasoning in the agent. Put the write behind an adapter that can perform an atomic check, ask the provider for a stronger API, or withhold that delayed action. The human approved a preview. The world changed before commit. addresses changed values before commit. This is a stronger identity problem: the target itself has been replaced.
Continue reading
Related questions
Read beyond the question
Explore more agent architecture
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →