Jeffrey Aven
Maintainer
StackQL Studios
Query before mutation: guardrail patterns for agents that touch production infrastructure
Query before mutation: guardrail patterns for agents that touch production infrastructure
Covered in the session:
- Why plan-and-apply was always a human safety mechanism: a person reads the plan, notices something is off, and stops the apply - and why this quietly disappears the moment an agent is the operator
- Query before mutation as the foundational pattern: requiring agents to establish current state from the live environment before any write, and why reasoning from stale context is the root cause of most agent-inflicted damage
- Idempotent assertions over imperative commands: expressing changes as desired state the agent can safely retry, rather than one-shot operations that compound when repeated
- Policy gates that work without a human: encoding the judgement a reviewer would have applied as machine-checkable rules at the interface, not in a document
- Blast radius controls: scoping agent credentials and mutation surfaces so the worst case is bounded, including read-only by default with explicit mutation grants
- What went wrong on the way here: real examples of agent behaviour against live cloud environments that motivated each pattern, including failures the patterns would not have caught
- A demo of an agent operating against real infrastructure with these guardrails active, including a blocked mutation and the recovery path
Attendees will leave with a practical guardrail checklist for any agent that can modify infrastructure, ordered by which controls give the most protection for the least effort.