The cheapest agent incident is the one found in a preview environment with test accounts. A production-readiness review should exercise both the happy path and every boundary that is supposed to stop unsafe behavior.
Contract and validation checks
- Pin every action to a published id, version, and hash.
- Test required, malformed, and unknown arguments.
- Confirm effect, risk reason, scopes, host, and quota family.
- Verify deprecated versions remain resolvable and immutable.
Policy and approval checks
- Prove no action executes before policy returns a decision.
- Test explicit block, auto-allow, single approval, and quorum paths.
- Confirm suspended agents and revoked connections fail closed.
- Attempt to lower an in-flight threshold and verify it remains pinned.
- Expire a pending action and prove it cannot execute afterward.
Execution and recovery checks
- Simulate worker retries and prove only one claim executes.
- Force an upstream mismatch and verify false success is rejected.
- Exercise compensation for a reversible action.
- Place a failed job in dead letters and replay from a verified step.
- Verify every transition appears in the signed ledger chain.
Ship with explicit unknowns
If an app host, quota mapping, verifier, or inverse is incomplete, label the capability honestly and keep the risky path unavailable. Pakkawork does not describe a connection as executable until its operational support exists.
Frequently asked
Should production readiness include real Google accounts?
Use dedicated test tenants and principals with non-sensitive data. The goal is to exercise real OAuth, hosts, quotas, and verification without risking production information.
What is the minimum smoke test?
Search and describe a contract, request a read, request an approval-gated write, approve it, verify the result, inspect the ledger, and revoke the connection.