{"slug": "don-t-verify-the-agent-verify-the-state", "title": "Don't verify the agent. Verify the state.", "summary": "A developer building StareBrain, a pre-launch Android AI agent that requires user confirmation before executing actions, argues that verifying an agent's own success reports creates a recursive trust problem and instead proposes verifying system state directly. The approach checks ground truth outside the agent — such as whether a sent message exists in the sent folder with a timestamp after dispatch — and introduces DENIED_UNRESOLVED as a permanent first-class status for actions whose effects cannot be observed, rather than defaulting to a false success signal.", "body_md": "Building an AI agent that confirms before it acts forced us to confront a problem we didn't expect: how do you verify that an action actually happened?\n\nThe obvious answer is: check the agent's output. Ask it to confirm what it did.\n\nThat's wrong.\n\nThe recursive trust problem\n\nIf an agent reports \"done\" and you verify that report with another agent, you've just added a layer without solving anything. The second agent can be wrong for the same reasons the first one was. You haven't broken the trust chain — you've extended it.\n\n```\nAction dispatched\n  → Agent reports: \"done\"\n    → Verification agent checks: \"looks done\"\n      → System reports: success ✓\n```\n\nEvery step trusts the previous step's output. None of them look at the world.\n\nWhat actually works: state diff\n\nInstead of asking \"what did the agent do,\" ask \"did the system change the way we expected?\"\n\n```\nAction dispatched: \"send SMS to Sarah\"\n  → Check sent folder: message present? ✓\n  → Compare timestamp: after dispatch? ✓\n  → System reports: confirmed ✓\n```\n\nThe verification is independent of the agent. You're not asking the agent to grade its own work — you're reading a ground truth that exists outside the agent entirely.\n\nWhen state diff isn't possible\n\nSome actions don't leave an observable state change. For those, the honest answer isn't \"success\" or \"failure.\" It's UNRESOLVED.\n\nWe built DENIED_UNRESOLVED as a permanent first-class status in StareBrain — not a temporary placeholder that decays into an answer, but an explicit signal that says: the action was dispatched, but we cannot confirm what happened.\n\nThe confirmation screen surfaces this to the user:\n\n\"You'll know if this worked\" — state is observable\n\n\"You might not know, and here's why\" — state is not observable\n\nWhy this matters for AI agents specifically\n\nAn AI agent that confidently reports success on an unverifiable action is worse than one that reports nothing. Silence signals uncertainty. False confidence removes that signal entirely.\n\nThe verification layer has to be outside the trust chain. State diff gets you there for most actions. UNRESOLVED handles the rest honestly.\n\nStareBrain is an Android AI agent: say what you want done, see exactly what it's about to do, confirm before anything runs. Pre-launch — [waitlist](https://starebrain.vercel.app/waitlist) open.", "url": "https://wpnews.pro/news/don-t-verify-the-agent-verify-the-state", "canonical_source": "https://dev.to/starebrain/dont-verify-the-agent-verify-the-state-3mal", "published_at": "2026-10-07 04:06:55+00:00", "updated_at": "2026-10-07 04:18:08.076486+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-products"], "entities": ["StareBrain"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/don-t-verify-the-agent-verify-the-state", "markdown": "https://wpnews.pro/news/don-t-verify-the-agent-verify-the-state.md", "text": "https://wpnews.pro/news/don-t-verify-the-agent-verify-the-state.txt", "jsonld": "https://wpnews.pro/news/don-t-verify-the-agent-verify-the-state.jsonld"}}