Rollback paths for AI agents
Design for reversal
Prefer draft states and pending approvals before final posts.
Compensating transactions where true undo is impossible.
Clear ownership for reopening cases.
Incidents
Runbooks: how to pause the agent, freeze writes, and reprocess from last good state.
Practice them. First use should not be a real outage.
Draft then commit
Prefer draft states and explicit commit steps for high-impact writes. Many bad outcomes never need reverse if they never committed.
Where commit is immediate, define compensating actions and who can run them.
Pause switches
A single kill switch to pause agent writes should exist and be tested. Unknown location of the switch is not a control.
In practice
Map the workflow on a whiteboard before you open a framework: inputs, systems of record, humans, and irreversible writes. If that map is fuzzy, the agent will encode the fuzz.
Pick ten to fifty real historical cases as an eval set. Include the ugly ones. Run the agent offline against them until critical fields and hard rules are acceptable. Only then connect write tools.
Ship with a pause switch, a human queue, and a weekly review of override reasons. Promote repeated overrides into rules. That loop is how production systems improve—not another prompt brainstorm.
Common failure modes
- Treating a demo on clean samples as readiness for production volume.
- One shared service account with broad write access across systems.
- No owner for the exception queue, so failures pile up as noise.
- Changing prompts and models without regression gates on real cases.
- Measuring only model latency or thumbs-up, not completed-case cost and audit completeness.
What good looks like after ninety days
The first workflow is boring: stable override rate, known failure modes, operators who trust the queue. Config changes go through review. Traces answer "what happened to this case?" without archaeology.
At that point you can add a second document type or a second agent role. Expanding before the first path is boring is how programs stall with five half-built pilots.
Frequently Asked Questions
Does versioning prompts count as rollback?
Only for future runs. Data side effects need their own recovery plan.
How small should write scopes be?
Small enough that a bad batch is recoverable within your SLA.