Don't verify the agent. Verify the state. A developer building StareBrain, a pre-launch Android AI agent that requires user confirmation before executing actions, argues that verifying an agent's own success reports creates a recursive trust problem and instead proposes verifying system state directly. The approach checks ground truth outside the agent — such as whether a sent message exists in the sent folder with a timestamp after dispatch — and introduces DENIED_UNRESOLVED as a permanent first-class status for actions whose effects cannot be observed, rather than defaulting to a false success signal. Building an AI agent that confirms before it acts forced us to confront a problem we didn't expect: how do you verify that an action actually happened? The obvious answer is: check the agent's output. Ask it to confirm what it did. That's wrong. The recursive trust problem If an agent reports "done" and you verify that report with another agent, you've just added a layer without solving anything. The second agent can be wrong for the same reasons the first one was. You haven't broken the trust chain — you've extended it. Action dispatched → Agent reports: "done" → Verification agent checks: "looks done" → System reports: success ✓ Every step trusts the previous step's output. None of them look at the world. What actually works: state diff Instead of asking "what did the agent do," ask "did the system change the way we expected?" Action dispatched: "send SMS to Sarah" → Check sent folder: message present? ✓ → Compare timestamp: after dispatch? ✓ → System reports: confirmed ✓ The verification is independent of the agent. You're not asking the agent to grade its own work — you're reading a ground truth that exists outside the agent entirely. When state diff isn't possible Some actions don't leave an observable state change. For those, the honest answer isn't "success" or "failure." It's UNRESOLVED. We built DENIED UNRESOLVED as a permanent first-class status in StareBrain — not a temporary placeholder that decays into an answer, but an explicit signal that says: the action was dispatched, but we cannot confirm what happened. The confirmation screen surfaces this to the user: "You'll know if this worked" — state is observable "You might not know, and here's why" — state is not observable Why this matters for AI agents specifically An AI agent that confidently reports success on an unverifiable action is worse than one that reports nothing. Silence signals uncertainty. False confidence removes that signal entirely. The verification layer has to be outside the trust chain. State diff gets you there for most actions. UNRESOLVED handles the rest honestly. StareBrain is an Android AI agent: say what you want done, see exactly what it's about to do, confirm before anything runs. Pre-launch — waitlist https://starebrain.vercel.app/waitlist open.