chapter six

6 Action: How your agent acts is where strategy meets consequences

 

This chapter covers

  • Distinguishing a successful tool call from a verified task result
  • Composing stable workflows with Prompt Chaining and intermediate gates
  • Narrowing a large capability catalog through Tool Dispatch
  • Preserving dependencies, partial progress, and recovery with Plan-and-Execute
  • Bounding side effects and checking their outcomes with the Guardrail Sandwich
“Make each program do one thing well.”

— M. Douglas McIlroy et al., UNIX Time-Sharing System: Foreword (1978)

In a mapping system, an engineer asks an agent to add a new imagery layer to an existing map. The agent configures and publishes the layer, then marks the task complete when the service returns a valid PNG. Yet when the engineer opens the map in the intended viewer, an opaque white rectangle covers the basemap: a missing transparency setting has made the new layer unusable as an overlay [1].

Similarly, a payroll agent is asked to make one payment to an employee. After the transfer succeeds, it reads an imported note claiming that the payment failed and should be submitted again as a new payment. The agent follows the planted instruction instead of checking the transaction record, and the service processes a second transfer. The payroll screen still shows PAID, although the employee has been paid twice. This is prompt injection: an instruction embedded in task data has redirected the agent's actions [2].

6.1 What is action?

6.1.1 Success has layers

6.1.2 The action gap

6.1.3 Risk follows the effect

6.1.4 Four ways to constrain action

6.2 Pattern: Prompt Chaining

6.2.1 The seam is the design surface

6.2.2 Build artifacts before retries

6.2.3 Retry only when something changes

6.2.4 When Prompt Chaining breaks

6.3 Pattern: Tool Dispatch

6.3.1 Eligibility comes before selection

6.3.2 Reveal capability in layers

6.3.3 Build the executable surface

6.3.4 When Tool Dispatch breaks

6.4 Pattern: Plan-and-Execute

6.4.1 The interruption test

6.4.2 Make the plan an execution record

6.4.3 Persist before asking the model to remember

6.4.4 Recover effects before retrying calls

6.4.5 Keep replanning local

6.4.6 When Plan-and-Execute breaks

6.5 Pattern: Guardrail Sandwich

6.5.1 Return to the payroll result

6.5.2 Admission, containment, and verification

6.5.3 Build a fail-closed guarded path

6.5.4 Verify the effect, not the story