Session
Hard and Soft Guardrails for Agentic Software Engineering
An agent can only be as safe as the engineering discipline it is given. If warnings are ignored, architectural boundaries are implicit, security checks run late, and tests are optional, an agent will reproduce those weaknesses at machine speed.
This talk shows how to turn engineering standards into guardrails for agentic software development. A hard guardrail is deterministic and enforced: it fails the build, blocks the commit, or stops the agent before the damage ships, and a human verified the check itself is correct. A soft guardrail is advisory: it surfaces a warning, a hint, or a review question, and leaves the decision to an experienced engineer.
The distinction is not the tool. A type check can be soft (a warning you dismiss) or hard (a CI gate that fails the build). What makes it hard is that the rule is deterministic, it blocks automatically, and a human checked that the check is right. What makes it soft is that it leaves room for judgement.
Soft guardrails preserve the decisions that still require an engineer: whether a change is ready, whether its design fits the system, whether its evidence is enough to merge. Hard guardrails remove the mistakes that no engineer should have to catch by hand.
The craft is knowing when a soft rule has hurt enough to turn hard. When the same warning keeps getting ignored, when the same bug ships twice, you turn the suggestion into a gate. Over time, the workflow becomes harder to misuse and easier to trust.
The tools are not the main point. The team's engineering judgement is. The important step is to make that judgement explicit and executable, so the agent inherits your standards instead of your habits.
The result is an AI-assisted SDLC that lets agents move quickly without letting security, quality, or architecture silently degrade.
Juan G Carmona
Software Architect | AI Strategist | Critical & Secure Systems | Software Development Engineer at Plain Concepts
Madrid, Spain
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top