Free framework
Agents need operating contracts, not just prompts.
An agent responsible for ongoing work needs more than instructions. Six fields, each with a worked example of the version that fails and the version that holds. Published in full — there is nothing to download and no email gate.
- Goal
- Trigger
- State
- Boundary
- Evidence
- Owner
The six fields
Fill these in before the agent runs unattended.
The bad column is not a straw man. It is what most agent definitions look like in practice, because a prompt feels like it covers these and does not.
Goal
What does done look like, stated so someone else could check it?
Not this
Keep the CRM tidy.
This
Every opportunity closed in the last 24 hours has a stage, an amount and a close reason.
Trigger
What starts the work, and what must already be true?
Not this
Runs continuously.
This
Hourly, only when the nightly sync finished without errors.
State
What may it remember between runs, and for how long?
Not this
Full conversation history, indefinitely.
This
Last processed record id and the last run's failures, for 30 days.
Boundary
What can it reach, enforced as permissions rather than asked for in a prompt?
Not this
Has the integration user's standing API key.
This
Read opportunities, write stage and close reason. No delete, no export, no email.
Evidence
What must exist afterwards to show the work was actually done?
Not this
A log line saying success.
This
The changed record id, its before and after values, and the policy decision that allowed it.
Owner
Which named person is accountable when it goes wrong?
Not this
The platform team.
This
A named individual, with a named deputy, reviewed quarterly.
The other four lines
Most contracts stop one field too early.
The six fields above describe what the agent does. These describe what happens when it goes wrong, which is the part that gets written after the incident instead of before it.
- Stop condition: what makes it halt rather than retry — and the retry budget before that point.
- Recovery behaviour: what happens to work already in flight when it halts.
- Escalation: who is told, through which channel, and within what time.
- Review: when the contract itself is re-examined, because permissions rot.
Enforcement architecture
- Scope
- Identity
- Access
- Action
- Stop
A boundary written in a prompt is a request. A boundary written as a permission is a boundary. Where the two disagree, the permission is the only one that holds when the agent reads something it should not have trusted.
If you cannot fill in the owner field with the name of one person, the agent is not ready to run unattended.
Filled it in and found gaps?
That is what it is for. The Agent Readiness assessment turns those gaps into an inventory, a blast-radius ranking and a hardening plan with owners.