Session
Same loop, different rules: swapping an agent's trust policy without the agent knowing
Two string fields decide how our AI agent's tool calls get from "the model wants to" to "it happened". Set the gate to defer_all and the resolver to human, and every consequential call stops and waits for the business owner. A dev session runs pass_all and auto, and the same loop with the same agent goes straight through. The agent can't read those fields and doesn't know they exist.
That last bit isn't obvious, and it's where I'd expect an argument. I'll walk through what we actually built: the seams we cut, and why the code that launches a run picks the policy while the agent never gets to. Also the places we left as single algorithms, because a seam there would have bought us nothing and cost us tests. Ours failed open once with every unit test green. If you have a seam like that in your own harness, what would tell you it's still connected?
Jenia Barabanov
Engineering Guild Lead @ Honeybook
Valencia, Spain
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top