Operating a Fleet of Coding Agents
Building verifiable trust around workloads that write your code.
An agent that can edit files, run shell commands, and call APIs is not an assistant. It is an untrusted workload with production access, and "be careful" is not a control. You move trust out of the model and into the environment: instruction files, guards, evals, a knowledge substrate. But the environment is built from artifacts that go stale, drift, and lie exactly the way the agent does.
So the operator's real artifact is one turn deeper: the verification loop that keeps the environment honest, the discipline of turning the same suspicion you aimed at the agent back onto every control you built to contain it. Fourteen chapters, system by system, bypass by reproduced bypass, with the work shown so you can argue with it.
Fourteen chapters, read in order. New here? The essay series is the shorter way in.
Contents
- Preface 3 min
- Part I · The Reframe and the Loop
- The Untrusted Workload 10 min
- The Map and the Territory 11 min
- The Guard That Enumerates Loses 15 min
- The Dossier Was Already Wrong 10 min
- The Measurement That Lied 12 min
- The Flywheel 14 min
- Part II · The Fleet
- The Control Plane 10 min
- Two Harnesses, One Floor 8 min
- Peers, Not Owners 10 min
- The Knowledge Substrate 7 min
- Context Is the Budget 8 min
- Part III · In Public
- The Auditor Audits Itself 11 min
- Proof You Can Hand a Stranger 10 min
- The Operator's Artifact 10 min
- Afterword 3 min
- Colophon 2 min
The series essays map to the book: Ulysses Pacts in Software deepens Chapter 2, Sermons vs. Instruments deepens Chapter 3, The Coordination Platform You Don't Need deepens Chapter 9, The Subtraction Dividend deepens Chapter 10, and We Rigged Our Own Benchmark deepens Chapter 12.
Want the next one? New work (the book, the essays, the field notes) lands in the feed. Point your reader there to follow along.