Silent failure is more dangerous than a clear error because downstream agents act on a state that does not exist. The system appears healthy while the workflow accumulates incorrect assumptions.
Treat outcome as a separate phase
Execution records what request was sent and what response came back. Verification separately asks whether the intended post-condition exists. Pakkawork stores both phases, including structured proof or an honest unchecked state.
Design useful verifiers
- Read only the smallest resource needed to prove the change.
- Compare semantic fields, not volatile metadata.
- Record the upstream identifier and observed values.
- Make eventual-consistency windows explicit and bounded.
- Return a clear mismatch the agent can reason about.
Recover without repeating good work
Trajectories divide a workflow into steps with pinned descriptions and results. A replay resumes from the last verified step, while already completed side effects remain untouched. Reversible steps can run their captured compensation through policy first.
Escalate repeated failure
A repeated mismatch is not just another retry. Move it to dead letters, suspend the affected trigger or agent if necessary, and open an incident with the contract, arguments, proof, and ledger sequence attached.
Frequently asked
Can verification itself change state?
A verifier should be read-only and narrowly scoped. Its job is to observe proof, not repair the action silently.
Why pin descriptions during replay?
The agent must reason from the same action meaning and schema used in the original trajectory, even after newer versions have shipped.