Featured story
I gave my agents a veto. Here is what it cost me.
One of the shortest things I wrote last August was an amendment I dropped into a policy agents were already drafting while I typed. Eleven words: financial figures are never shared publicly, no exception clause.
It was the easiest sentence to write and the hardest to keep, and I knew it while I was writing it. The premise of how I work is that I am not the person reading every page -- the pages go out while I am asleep. A rule I merely state is worth nothing at three in the morning. The only rule worth anything is one that runs. That gap, between a rule you announce and a rule that executes, is the subject of this chapter.
A rule is not a control
Every organization that grows past its founder settles on the same answer. Purchase approval thresholds. Two signatures over a certain amount. Segregation of duties, so whoever approves an invoice is not whoever pays it. Nobody calls those guardrails. They are called controls, and every executive knows why they exist -- not because staff are dishonest, but because judgment applied by a busy person, under pressure, at volume, is not a reliable safety mechanism. Controls are how you delegate without abdicating.
What is new is only the speed. A control a person performs runs at the speed of that person. A control software performs runs at the speed of the work. When the work happens at two in the morning across a fleet of agents, that difference stops being an efficiency and becomes the only version that functions.
So the policy I opened with is not really a document. It is a specification for a set of machines. Routine work publishes with no human in front of it, provided every claim traces to a verified record, carries no customer detail or dollar figure, and passes the machine checks. A genuinely new kind of claim goes to review first. Anything touching a customer, a security detail, or a comparison comes to me, always. Behind all of it: a ratification loop the next morning, a pause control I can press at any time, and tripwires that freeze an entire class of publishing the moment certain defects appear.
Machine gates in front. Human judgment behind. A brake I can always reach.
The corner I decided not to cut
The easy path, and the one most people take first, is to define autonomy as compliance: the agent does what it is told, just faster and more of it.
The gap I saw is that unqualified compliance is not safety -- it relocates the failure. A slow, careful operation fails by being too slow: annoying, visible, survivable. A fast, compliant one fails by being wrong, quickly, at volume, in public, while you sleep -- a much larger problem wearing the costume of productivity.
So the capability worth paying for is not "does what it is told." It is "declines when the record does not support it." Refusal became a first-class feature rather than a bug to route around -- an uncomfortable thing to build, because you are deliberately constructing something that will one day tell you no when you are certain you are right.
Such a thing is worth having only if it holds three properties at once. It fails closed -- if the check cannot run, the answer is no, not "probably fine." It binds its author, because a gate exempting whoever built it is theater. And it separates durable authority from chat authority: anything can claim to be me in conversation, so a decision counts only once recorded where it can be checked later.
The gate that watches for money, and the one that caught me
The first chapter of this series ended on a publish that stopped itself because the record of what was shipping no longer matched what actually gets built. The gate treated that failure as information about the world, not an obstacle to the task. Two more gates aim squarely at my eleven-word rule.
The one that watches for money. Every rendered public page passes a build-time check before it ships, failing the build on a dollar amount, commercial terms in their commercial sense, customer and seat counts, internal tool names, or any contact address not explicitly approved. Nothing is allowed by default. It never cleans anything up; it detects, reports, and stops the build.
That check has never once fired on a real page, and I want to be precise about what that proves, because "we have never had an incident" is the most over-claimed sentence in business. It proves nothing. What proves the guard works is a fixture seeded on purpose with the violations it must catch, accepted only when the guard fails the build. The quiet record is what I hope for. The planted fixture is what I trust.
The one that caught me. A companion rule says a public claim may never assert stronger evidence than its record supports -- enforced at build time, not in a style guide. Push a claim one rank above what its lineage carries and it refuses to compile. And the classifier assigning each shipped claim its evidence badge fails closed in one direction: an unrecognized status never resolves to "Verified." It resolves to "Evidence pending."
I got to watch that work on my own words. I had stated plainly that we have model and vendor fallbacks for everything AI-related across our products, and I believed it. The verification pass went product by product and found it true in two of them, confirmed in code -- and absent in the other two, where a single vendor and a single model sat with no fallback at all. The claim did not publish the way I said it. It was cut down to the products where it was actually built, with the gap left in the record in plain sight. Nobody enjoys that. But the pressure on any claim is always upward, and a gate like this makes the lazy path the honest one.
The part nobody puts in the brochure
Gates cost speed and produce false alarms. Both are real, and a chapter that skipped them would be the exact kind of highlight reel this series exists to avoid.
My favorite is the stupidest. A work-tracking gate refused a piece of work because a trigger word appeared exactly once -- inside the sentence I had written to explain that the work did not involve that thing. The mitigation tripped the gate.
The most expensive near-miss was subtler. A validation check rejected a model's output for obeying the instructions it had been given: the instructions said a certain field could be left empty in that case, and the checker inspected the field before ever reaching that case. The automatic response was already escalating toward a costlier model -- which would have paid real money to fail the identical check for the identical reason. The gate was wrong, and the system was about to comply with it harder, at a premium.
None was free. But look at how each was resolved, because the pattern is the whole answer. A scanner that produced thirty-two findings, twenty-four of them false, was narrowed until the same run produced eight and zero -- and the regression test written to hold it there was observed failing against the old version before anyone accepted it. A fix to the check that strips secrets introduced a false alarm of its own, and was narrowed to demand an actual payload rather than a keyword.
Not one was fixed by making the gate quieter about the thing it was built to catch.
Fail closed on truth. Fail open on ceremony. Where a gate protects something real -- a secret, a customer, a number that must never appear -- it stops the world and stays stopped. Where it is merely enforcing a rule's clumsy first draft, the rule gets fixed. The money check deliberately does not flag the ordinary engineering senses of words like "pipeline" and "margin," and a test exists whose only job is to prove it stays quiet on a page-layout margin. That test looks trivial. It is not. A gate that cries wolf gets ignored, then disabled, then removed. You do not pay down the cost of gates by making them tolerant. You pay it by making them exact.
The trade I made on purpose
Skip all this and nothing dramatic happens -- that is the danger. A number that should never have been public sits on a page. A claim reads slightly stronger than the file behind it. No alert, no outage, no red screen. It sits there being wrong in front of the people whose trust you wanted, and by the time anyone mentions it they have drawn their conclusion.
So let me name the easier path plainly: no gates, just good intentions and a review pass when something feels risky. It is faster every day except one.
What I gave up is real -- shipping the instant I decide something is fine. Some mornings now begin with a build that stopped over something I would have waved through, and some of those stops are the gate being wrong. I pay that every week. What I bought makes the rest of this operation possible: work publishes while I sleep, because the things that must never happen are enforced by something that does not get tired, does not get excited about a deadline, and does not make exceptions for me.
What to take to your own work
Five things, none requiring any particular technology.
Write controls, not rules. Ask of every rule you have: what actually happens if someone simply does not follow it? If the answer is "nothing, until much later," it is a wish, not a control.
Make your gates bind their author. Any exemption for whoever wrote the rule, for the founder, or for the urgent case removes most of the value. Point your own controls at your own work first.
Separate durable authority from chat authority. Decisions that matter should count only in a form that can be verified after the fact. Anyone can claim anything in a conversation -- and increasingly, so can anything.
Fail closed on truth, fail open on ceremony. Never weaken a protection to buy back convenience; fix the clumsy rule instead.
Treat every false alarm as a precision bug, never as a reason to lower the bar. A guard that gets ignored is worse than no guard, because it also gave you the feeling of being covered.
Build something that can tell you no. Then, when it does, check whether it is right before you override it. Mine has been right nearly every time -- including the times it was correcting me.
Evidence: The publication class policy described here is active and in force, with its classes, machine-gate criteria, morning ratification loop, pause control, defect-class tripwires, revocation clause, and never-share-financials amendment recorded in docs/technology-portfolio/publication-class-policy-v1.md (Sections 1-4, 6-7). The build-time public-page check, its fail-closed and nothing-allowed-by-default behavior, and its deliberate distinction between the commercial and technical senses of a term were read directly in docs/technology-portfolio/factory/renderer/moat_guard.py; its planted-fixture catch tests and its false-positive regression guard in docs/technology-portfolio/factory/tests/test_danstolts_site_deltas.py. That check has no recorded live violation to date -- every recorded run is a PASS, which is why the claim above rests on the planted fixtures, not on the quiet record. The claim-ceiling enforcement is in docs/technology-portfolio/factory/tests/test_claim_boundary_guard.py; the evidence-badge classifier that fails closed to "Evidence pending" and never to "Verified" is in docs/technology-portfolio/factory/renderer/render.py. The narrowed fallback claim is docs/resume-hub/claims-ledger.md row C-40, verified in two products and recorded as not-found in two others. The false alarms (a trigger word matched inside its own mitigating sentence; a validation rule that rejected output for obeying its own instruction while escalating model cost; 32 findings with 24 false positives, corrected to 8 with zero, its regression test observed failing before acceptance; a redaction fix that introduced and then narrowed its own false positive) are recorded in docs/technology-portfolio/completed-discovery-runs.md (Runs 1C, 1F), docs/technology-portfolio/validation/run-2n-e2e-cro-charter/README.md, docs/technology-portfolio/validation/run-2i-secret-safety/SECRET-SAFETY-TEST.md, and docs/resume-hub/proof-pages/fail-closed-secret-and-pii-redaction-gate.md. The stale-manifest refusal and the guard-catches-its-own-author case carry from this series' first chapter, docs/stories/a-day-in-the-life-with-an-agent-workforce.md. Evidence class: active written policy plus a directly-read build-time test suite and internal operating record; verified 2026-08-25. Full record: docs/technology-portfolio/publication-class-policy-v1.md and docs/resume-hub/claims-ledger.md (rows C-18, C-40).