Agents Get Replaced. The Doctrine Is the Product. A developer rebuilt a 19-agent orchestration system into a new "agentic-os" and audited 100 rules from the old system against it, finding 29 already present, 35 partial, and 36 missing — mostly enforcement rules the previous system had turned into hooks. The ported doctrine, including fail-closed hooks that deny on empty, malformed, or unreadable input, blocked an out-of-territory file write from the developer's own session. The developer argues agent rosters change with each model generation while the list of recurring mistakes changes far more slowly. Earlier today a session in my own system tried to write a file outside its territory. A hook denied it before the write happened, and the session couldn't override itself: the bypass is an environment flag the hook process reads, not something the agent can set. It had to hand the work back. That hook is less than a week old. The rule behind it is much older than the system it's running in. I moved from multiagent-system — a 19-agent orchestration setup I'd been running for months — to agentic-os, a rebuild, for three reasons: so the system had memory and a record of everything, so I could work faster, and to get closer to loops between agents. For now I still review every loop myself. A human is in the loop. After migrating I reviewed the initial agents, modified them, and reused a lot of doctrine from the old system. The reason is simple: the AI was making mistakes again that the old design had already had to correct. So I audited it. On 2026-09-27 I took 100 rules from multiagent-system and checked each one against agentic-os. 29 were already there, 35 were partial, 36 were missing. The 36 defined the work, and they were mostly enforcement: rules the old system had turned into hooks, and this one still carried as text. The roster was replaced; the doctrine was ported by subtraction, keeping what corrects a known error and dropping the rest. A rule is the record of an error the system already paid for once. Agents change with each model generation. The list of mistakes a model tends to repeat changes much more slowly. Four rows of that inventory: | Row | Rule | |---|---| | A01 | Hard-block advisory advisory = 0% enforcement | | B01 | The orchestrator is the only invoker | | C01 | The auditor is independent, anti-self-grading | | D24 | Deterministic signal before an LLM judge | A01 and B01 are marked present in agentic-os: three fail-closed hooks, and the invoke tool blocked in the frontmatter of every subagent. A01 comes from What Advisory Rules Actually Do in an Agent Loop https://dev.to/lexosi/what-advisory-rules-actually-do-in-an-agent-loop-bke . The measured result in the earlier system was "all 9 blocked tool-calls across 7 runs, 4 via explicit logged override, 0 unauthorized writes". Those numbers belong to multiagent-system. What carried over is the rule they justify: a prompt that politely asks is not a boundary. The other two are the same instinct. The author never grades its own work. If a script can answer the question, the script answers before a model does. None of this came from an AI course. It came from running live products https://dev.to/lexosi/ten-years-directing-live-products-before-i-knew-it-was-called-product-management-225f , where one person owns the schedule, builders don't sign off their own builds, and a metric beats an opinion. Only the workers changed. Each of the three guards was built the same way, and the order is in the commit log. The test went in first, failing, with the hook absent — 3 of 12 red for territory, 2 of 13 for protected paths, 2 of 7 for the stop gate. Then the hook, and the same suites green: 12 of 12, 13 of 13, 7 of 7. Committing a red test is the point. A gate that has never been seen denying anything is a gate nobody has tested — it is indistinguishable, from the outside, from a gate that always says yes. The deny path is the one that has to be boring. Empty input, malformed input, an agent not in the config, an unreadable config file, any unhandled exception: all of them deny. The failure mode of a verification layer should be refusal, not silence. The session that got denied this morning was mine, doing research for this article. The rule that stopped it was ported from a system that no longer runs. Agents get replaced. The doctrine is the product.