Building Software

Engineering Fundamentals for the Agent Era

Contents Section 9, Directing Agents

Orchestration, Permissions and Guardrails

Mistakes to catch in review

  1. A CI agent given the organization-wide deploy token because scoping one to the repository was more setup, so any repository it touches can ship to production.

  2. An agent loop with no limit on steps, time or cost, running for hours.

  3. An agent that can both write a change and approve its own merge.

  4. An autonomous agent force-pushing, deleting data or sending messages without a person approving the action.

Running agents in loops and pipelines with limited permissions, budgets and approval points, so their mistakes stay small.

Topics

Agent Loops and Multi-Agent Orchestration
Planners, workers and reviewers, and when adding agents improves reliability and when it only adds noise.
Sandboxing and Least Privilege for Agents
Restricting file, network and credential access so an agent's worst possible action is survivable.
Separating Reading From Acting
Designing workflows so an agent that reads untrusted content cannot take consequential actions on its own.
Human Approval Points
Choosing which actions, such as deploys, deletions, payments and external messages, need a person, and making that approval meaningful.
Budgets, Timeouts and Kill Switches
Limits on steps, time and spend, and a reliable way to stop everything at once.
Audit Trails
Recording what each agent did, with which permissions and on whose instruction.

You understand it when you can

  • Design the minimum permission set for an agent that fixes failing tests.
  • Identify which actions in an agent workflow need human approval, and justify each one.
  • Explain how you would detect and stop an agent that is looping or overspending.

Drill

An agent workflow that triages new issues in a public issue tracker runs with a token that can push to the main branch, merge pull requests and read deployment secrets. Find the attack path from a malicious issue to a production change, and cut it with the smallest permission set that still lets the workflow do its job.

Start here

Watch

Read

Building Applications with AI Agents: Designing and Implementing Multiagent Systems

Michael Albada, 2025.

Covers how to structure single- and multi-agent systems (tools, planning, orchestration patterns) and the trade-offs of each design, including when more agents add noise instead of reliability.

Primary sources

  • Reference

    Building Effective AI Agents

    Anthropic's reference taxonomy of workflows versus agents (prompt chaining, routing, orchestrator-workers, evaluator-optimizer) and the guidance to add autonomy only when it pays for its risk.