{"slug": "agents-get-replaced-the-doctrine-is-the-product", "title": "Agents Get Replaced. The Doctrine Is the Product.", "summary": "A developer rebuilt a 19-agent orchestration system into a new \"agentic-os\" and audited 100 rules from the old system against it, finding 29 already present, 35 partial, and 36 missing — mostly enforcement rules the previous system had turned into hooks. The ported doctrine, including fail-closed hooks that deny on empty, malformed, or unreadable input, blocked an out-of-territory file write from the developer's own session. The developer argues agent rosters change with each model generation while the list of recurring mistakes changes far more slowly.", "body_md": "Earlier today a session in my own system tried to write a file outside its\n\nterritory. A hook denied it before the write happened, and the session\n\ncouldn't override itself: the bypass is an environment flag the hook process\n\nreads, not something the agent can set. It had to hand the work back.\n\nThat hook is less than a week old. The rule behind it is much older than the\n\nsystem it's running in.\n\nI moved from multiagent-system — a 19-agent orchestration setup I'd been\n\nrunning for months — to agentic-os, a rebuild, for three reasons: so the\n\nsystem had memory and a record of everything, so I could work faster, and to\n\nget closer to loops between agents. For now I still review every loop\n\nmyself. A human is in the loop.\n\nAfter migrating I reviewed the initial agents, modified them, and reused a\n\nlot of doctrine from the old system. The reason is simple: the AI was making\n\nmistakes again that the old design had already had to correct.\n\nSo I audited it. On 2026-09-27 I took 100 rules from multiagent-system and\n\nchecked each one against agentic-os. 29 were already there, 35 were partial,\n\n36 were missing. The 36 defined the work, and they were mostly enforcement:\n\nrules the old system had turned into hooks, and this one still carried as\n\ntext. The roster was replaced; the doctrine was ported by subtraction,\n\nkeeping what corrects a known error and dropping the rest.\n\nA rule is the record of an error the system already paid for once. Agents\n\nchange with each model generation. The list of mistakes a model tends to\n\nrepeat changes much more slowly.\n\nFour rows of that inventory:\n\n| Row | Rule | \n|---|---|\n| A01 | Hard-block > advisory (advisory = 0% enforcement) | \n| B01 | The orchestrator is the only invoker | \n| C01 | The auditor is independent, anti-self-grading | \n| D24 | Deterministic signal before an LLM judge | \n\nA01 and B01 are marked present in agentic-os: three fail-closed hooks, and\n\nthe invoke tool blocked in the frontmatter of every subagent. A01 comes from\n\n[What Advisory Rules Actually Do in an Agent\nLoop](https://dev.to/lexosi/what-advisory-rules-actually-do-in-an-agent-loop-bke).\n\nThe measured result in the earlier system was \"all 9 blocked tool-calls\n\nacross 7 runs, 4 via explicit logged override, 0 unauthorized writes\". Those\n\nnumbers belong to multiagent-system. What carried over is the rule they\n\njustify: a prompt that politely asks is not a boundary.\n\nThe other two are the same instinct. The author never grades its own work.\n\nIf a script can answer the question, the script answers before a model does.\n\nNone of this came from an AI course. It came from [running live\nproducts](https://dev.to/lexosi/ten-years-directing-live-products-before-i-knew-it-was-called-product-management-225f),\n\nwhere one person owns the schedule, builders don't sign off their own\n\nbuilds, and a metric beats an opinion. Only the workers changed.\n\nEach of the three guards was built the same way, and the order is in the\n\ncommit log. The test went in first, failing, with the hook absent — 3 of 12\n\nred for territory, 2 of 13 for protected paths, 2 of 7 for the stop gate.\n\nThen the hook, and the same suites green: 12 of 12, 13 of 13, 7 of 7.\n\nCommitting a red test is the point. A gate that has never been seen denying\n\nanything is a gate nobody has tested — it is indistinguishable, from the\n\noutside, from a gate that always says yes.\n\nThe deny path is the one that has to be boring. Empty input, malformed\n\ninput, an agent not in the config, an unreadable config file, any unhandled\n\nexception: all of them deny. The failure mode of a verification layer should\n\nbe refusal, not silence.\n\nThe session that got denied this morning was mine, doing research for this\n\narticle. The rule that stopped it was ported from a system that no longer\n\nruns.\n\nAgents get replaced. The doctrine is the product.", "url": "https://wpnews.pro/news/agents-get-replaced-the-doctrine-is-the-product", "canonical_source": "https://dev.to/lexosi/agents-get-replaced-the-doctrine-is-the-product-5f27", "published_at": "2026-10-05 09:10:20+00:00", "updated_at": "2026-10-05 09:22:10.731146+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "developer-tools"], "entities": ["multiagent-system", "agentic-os"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/agents-get-replaced-the-doctrine-is-the-product", "markdown": "https://wpnews.pro/news/agents-get-replaced-the-doctrine-is-the-product.md", "text": "https://wpnews.pro/news/agents-get-replaced-the-doctrine-is-the-product.txt", "jsonld": "https://wpnews.pro/news/agents-get-replaced-the-doctrine-is-the-product.jsonld"}}