Skip to content

Production hardening for unattended and side-effecting agentic runs #491

Description

@jeremymanning

Origin

Deferred from the MVP proposed as a fresh realization of #485.

Goal

Harden the experimental vertical slice for unattended and externally consequential production runs.

Scope

  • Human clarification/approval, pause/resume, plan diffs, escalation, and accepted-risk UX.
  • Policy for unattended runs and budget-exhaustion behavior.
  • Side-effect classes, approval gates, idempotency keys, duplicate completion, and compensating actions.
  • Exact/recorded-response/semantic replay levels for deterministic tools, APIs, and model calls.
  • Cost reservations, quotas, storage/network budgets, and operator alerts.
  • Plan evolution and migration of not-yet-started nodes while completed attempts remain pinned.
  • SLOs, observability, audit export, backup, and disaster recovery.

Acceptance criteria

  • Destructive/external effects cannot occur outside delegated authority and approval policy.
  • Crash/retry cannot silently duplicate a declared non-idempotent action.
  • Operators can answer what is running, blocked, uncertain, over budget, or awaiting approval.
  • Plan revisions are diffable and preserve complete lineage.
  • Unattended-run defaults and recovery procedures are documented and tested.

Metadata

Metadata

Assignees

No one assigned

    Labels

    architectureRelated to toolbox design/architectureenhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions