Skip to content

Add two agent-era principles: autonomy follows risk, reason broadly execute narrowly - #128

Open
joshdougall wants to merge 1 commit into
mainfrom
josh/principles-agent-autonomy
Open

joshdougall wants to merge 1 commit into
mainfrom
josh/principles-agent-autonomy

Conversation

@joshdougall

Copy link
Copy Markdown

Description

Adds two principles the handbook already relies on but never states. Both are restatements of
existing design, so nothing an agent may do changes.

Autonomy follows risk is what the ten gates already implement, and what agent-era-invariants.md
summarises as "agents have wide latitude inside the gates". The gates page opens with mechanics
rather than rationale, so a reader meeting a situation the list does not cover has nothing to reason
from, though that page calls itself "a floor, not a ceiling". This gives the floor a reason, and says
outright that accountability is the one thing that does not scale.

Reason broadly, execute narrowly is the genuinely absent idea. Nothing in operating-model/,
invariants/ or workflows/ states that agents should hold wider read access than write access,
though it is the assumption behind read-only review tooling and query-only data access.

Placed with the other how-we-work entries rather than appended as an AI section. Only the first is
added to the testable list; the second describes how access is granted rather than something CI can
check.

Issues

Closes: none.

Both are restatements, not proposals. Nothing an agent may do changes.

"Autonomy follows risk" is what the ten gates already implement, and what
agent-era-invariants.md summarises in one line as "agents have wide latitude
inside the gates". The gates page opens with mechanics rather than rationale,
so someone meeting a situation the list does not cover has a list to
pattern-match against and no principle to reason from. That page admits as
much: the gate list is "a floor, not a ceiling". This gives the floor a
reason. It also says outright that accountability is the thing that does not
scale, which the collaborator statement establishes but the principles page
never repeats.

"Reason broadly, execute narrowly" is the one genuinely absent idea. Nothing
in operating-model/, invariants/ or workflows/ states that agents should hold
wider read access than write access, though it is the assumption behind
read-only review tooling and query-only data access. It is framed here as a
safety mechanism rather than a concession, because narrow read access causes
the failure modes the collaborator statement already names: the change that
ignores an existing caching layer, or reimplements logic that exists
elsewhere.

Placed after "Standards lead to better code" rather than appended, so they
read as part of how we work rather than a bolted-on AI section. Only
"Autonomy follows risk" is added to the testable list, mapped to the gates.
"Reason broadly, execute narrowly" describes how access is granted rather
than something CI can check, so forcing it into either bucket would
overclaim.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying engineering-handbook with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0c95871
Status: ✅  Deploy successful!
Preview URL: https://0883514d.engineering-handbook-8f2.pages.dev
Branch Preview URL: https://josh-principles-agent-autono.engineering-handbook-8f2.pages.dev

View logs

@guglez guglez left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@majidkhan07 majidkhan07 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM :)

Comment thread PRINCIPLES.md

- **Standards lead to better code.** Use a systematic approach to ensure that code is of high quality. This involves using established practices and tools to create software that is easy to read, test, maintain, and extend. Standards should be encouraged, or enforced where necessary, through established processes such as code reviews. These standards should always be documented, and automated wherever possible.

- **Autonomy follows risk.** Agents have wide latitude inside the gates, and that latitude is widest where mistakes are cheap and reversible. As consequence and blast radius grow, so does the verification and approval required before an action runs. What does not scale is accountability: an engineer owns an agent-assisted change at every point on that curve. Judge an action by what it touches and what undoing it would cost, not by how difficult it was to produce.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super complex construct. "Latitude", "blast radius" - too many allegories.

Comment thread PRINCIPLES.md

- **Autonomy follows risk.** Agents have wide latitude inside the gates, and that latitude is widest where mistakes are cheap and reversible. As consequence and blast radius grow, so does the verification and approval required before an action runs. What does not scale is accountability: an engineer owns an agent-assisted change at every point on that curve. Judge an action by what it touches and what undoing it would cost, not by how difficult it was to produce.

- **Reason broadly, execute narrowly.** Agents should generally have more access to observe, analyse and propose than they have to mutate. Wide read access is what prevents the expensive failure modes, the change that ignores an existing caching layer or reimplements logic that already exists three directories away, so narrowing it makes the work worse rather than safer. Write access is where the cost of being wrong actually lands, so it stays deliberately smaller than the reasoning that informs it.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- **Reason broadly, execute narrowly.** Agents should generally have more access to observe, analyse and propose than they have to mutate. Wide read access is what prevents the expensive failure modes, the change that ignores an existing caching layer or reimplements logic that already exists three directories away, so narrowing it makes the work worse rather than safer. Write access is where the cost of being wrong actually lands, so it stays deliberately smaller than the reasoning that informs it.
- **Reason broadly, execute narrowly.** Agents need enough context to understand the work and avoid missing or duplicating existing solutions. Let them read relevant code and documentation, while keeping changes within the approved scope. Access to secrets and other sensitive information still requires approval.

Comment thread PRINCIPLES.md

- **Standards lead to better code.** Use a systematic approach to ensure that code is of high quality. This involves using established practices and tools to create software that is easy to read, test, maintain, and extend. Standards should be encouraged, or enforced where necessary, through established processes such as code reviews. These standards should always be documented, and automated wherever possible.

- **Autonomy follows risk.** Agents have wide latitude inside the gates, and that latitude is widest where mistakes are cheap and reversible. As consequence and blast radius grow, so does the verification and approval required before an action runs. What does not scale is accountability: an engineer owns an agent-assisted change at every point on that curve. Judge an action by what it touches and what undoing it would cost, not by how difficult it was to produce.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- **Autonomy follows risk.** Agents have wide latitude inside the gates, and that latitude is widest where mistakes are cheap and reversible. As consequence and blast radius grow, so does the verification and approval required before an action runs. What does not scale is accountability: an engineer owns an agent-assisted change at every point on that curve. Judge an action by what it touches and what undoing it would cost, not by how difficult it was to produce.
- **Autonomy follows risk.** Agents can act independently within agreed limits. Actions that could cause more harm or are harder to undo need more checking and approval. A human remains responsible for every agent-assisted change.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants