Skip to content

Free framework

Agents need operating contracts, not just prompts.

An agent responsible for ongoing work needs more than instructions. Six fields, each with a worked example of the version that fails and the version that holds. Published in full — there is nothing to download and no email gate.

  1. Goal
  2. Trigger
  3. State
  4. Boundary
  5. Evidence
  6. Owner

The six fields

Fill these in before the agent runs unattended.

The bad column is not a straw man. It is what most agent definitions look like in practice, because a prompt feels like it covers these and does not.

01

Goal

What does done look like, stated so someone else could check it?

Not this

Keep the CRM tidy.

This

Every opportunity closed in the last 24 hours has a stage, an amount and a close reason.

02

Trigger

What starts the work, and what must already be true?

Not this

Runs continuously.

This

Hourly, only when the nightly sync finished without errors.

03

State

What may it remember between runs, and for how long?

Not this

Full conversation history, indefinitely.

This

Last processed record id and the last run's failures, for 30 days.

04

Boundary

What can it reach, enforced as permissions rather than asked for in a prompt?

Not this

Has the integration user's standing API key.

This

Read opportunities, write stage and close reason. No delete, no export, no email.

05

Evidence

What must exist afterwards to show the work was actually done?

Not this

A log line saying success.

This

The changed record id, its before and after values, and the policy decision that allowed it.

06

Owner

Which named person is accountable when it goes wrong?

Not this

The platform team.

This

A named individual, with a named deputy, reviewed quarterly.

The other four lines

Most contracts stop one field too early.

The six fields above describe what the agent does. These describe what happens when it goes wrong, which is the part that gets written after the incident instead of before it.

  • Stop condition: what makes it halt rather than retry — and the retry budget before that point.
  • Recovery behaviour: what happens to work already in flight when it halts.
  • Escalation: who is told, through which channel, and within what time.
  • Review: when the contract itself is re-examined, because permissions rot.

Enforcement architecture

  1. Scope
  2. Identity
  3. Access
  4. Action
  5. Stop

A boundary written in a prompt is a request. A boundary written as a permission is a boundary. Where the two disagree, the permission is the only one that holds when the agent reads something it should not have trusted.

If you cannot fill in the owner field with the name of one person, the agent is not ready to run unattended.

Filled it in and found gaps?

That is what it is for. The Agent Readiness assessment turns those gaps into an inventory, a blast-radius ranking and a hardening plan with owners.