Agent rollback is not always possible
Some actions cannot be undone, and an agent that can take them needs different controls from one that cannot.
A sent email, a published post, a transferred payment, a deleted record with no backup. Designing on the assumption that mistakes can be reversed works until it does not, which is why irreversible actions justify confirmation that reversible ones do not.
More on AI agents
- Tool descriptions are part of the control surfaceThe label is the lever
- Agent memory can preserve poisoned contextIt stays in the water
- Agent identity should be separate from user identityTwo necks, one badge
- Delegated agents create authority chainsThe thread stays attached
- Agent loops need budgets and stopping conditionsSomething has to say enough
- High-impact tools need stronger confirmationMatch the catch to the consequence
