6 Action: How your agent acts is where strategy meets consequences
This chapter covers
- Distinguishing a successful tool call from a verified task result
- Composing stable workflows with Prompt Chaining and intermediate gates
- Narrowing a large capability catalog through Tool Dispatch
- Preserving dependencies, partial progress, and recovery with Plan-and-Execute
- Bounding side effects and checking their outcomes with the Guardrail Sandwich
“Make each program do one thing well.”
— M. Douglas McIlroy et al., UNIX Time-Sharing System: Foreword (1978)
In a mapping system, an engineer asks an agent to add a new imagery layer to an existing map. The agent configures and publishes the layer, then marks the task complete when the service returns a valid PNG. Yet when the engineer opens the map in the intended viewer, an opaque white rectangle covers the basemap: a missing transparency setting has made the new layer unusable as an overlay [1].
Similarly, a payroll agent is asked to make one payment to an employee. After the transfer succeeds, it reads an imported note claiming that the payment failed and should be submitted again as a new payment. The agent follows the planted instruction instead of checking the transaction record, and the service processes a second transfer. The payroll screen still shows PAID, although the employee has been paid twice. This is prompt injection: an instruction embedded in task data has redirected the agent's actions [2].