Dry-run by default
The one rule that lets me hand real work to an autonomous system and walk away: nothing writes to the outside world until I say so, and everything it does, it can undo.
By Andrew J. Pyle
The scary part of building a system that acts on its own is not the acting. It is the writing: the moment a script stops reading state and starts changing it.
So I made a rule, and I made it the default rather than the exception. Anything that writes to an outside system previews first, only acts on an explicit flag, and can always be undone. It is the small, unglamorous pattern that makes it safe to walk away.
01READ, DO NOT WRITE
The default is show me
The scary part of building a system that acts on its own is not the acting. It is the writing: the moment a script stops reading state and starts changing it. A redirect goes live. A page gets de-indexed. A config reloads on a production box.
So I made a rule, and I made it the default rather than the exception. Every tool that mutates external state has the same shape. Run it with no flags and it touches nothing. It reads the current state, computes the change, and shows you exactly what it would do.
Anything that writes to an outside system is a proposal first. The default is show me, not do it.
02THE APPLY FLAG
Acting is an explicit verb
Action is never implicit. To actually write, you pass an explicit apply flag. That one required flag is a small piece of friction, placed exactly where friction belongs: between I think this is right and this is now live in production.
# Preview: reads state, shows the diff, writes nothing.
tool update-redirects
# Act: the explicit flag is the only way to write.
tool update-redirects --apply03THE REVERT FLAG
Everything has an undo
Because every apply writes a backup first, every apply has an inverse. A revert flag restores the pre-change state from the snapshot the tool took. This is not a manual recovery improvised after the fact under pressure. It is built into the tool before it ever writes.
The order matters: snapshot, then write. If the snapshot is taken as part of the apply, the undo always exists, even for the change you did not expect to need to reverse.
04TRUST, NOT SMARTS
Why this is the whole game for autonomy
People assume the hard part of an autonomous system is making the agent smart. In my experience the hard part is making its actions safe enough that you will actually let it act.
A brilliant agent I cannot trust with production is useless. A modest one that previews, requires an explicit yes, and can always undo gets to do real work.
05NEXT STEPS
Make it the default
- Take one tool that writes to the outside world and make no-flags mean preview.
- Require an explicit apply flag to actually write. No implicit action.
- Snapshot before every write, and add a revert that restores it.
- Make this the shape every new tool copies, not a thing you remember to add.