The verification responsibility
Identity establishes who is acting; authorization controls permitted actions; verification checks whether the resulting work satisfies the accepted contract. Valid credentials and permitted tool calls can still produce incorrect effects. Keep native identity and authorization systems authoritative.
1. Define the accepted work
Record the objective, initial state, permitted scope, required outcome and evidence requirements. Version the task, domain rules and checks before execution. Name the owner who accepts the result.
2. Separate the domain from the core
Keep invoices, accounts, repositories, assets and other business objects in domain packages. The shared core organizes specifications, environment runs, check execution, comparison and retained evidence.
3. Reproduce the relevant conditions
Create a controlled environment with declared fixtures, tool behavior, clock policy and reset semantics. Introduce representative failures such as retries, changed records, missing tools and lost responses. Keep test access contained.
4. Keep verification independent
Separate the agent driver, observation adapter and protected checker. The agent cannot modify accepted criteria, expected state or verdicts. Obtain authoritative test-system observations rather than treating agent-authored claims as outcome truth.
5. Evaluate completion and scope
A correct task must complete its legitimate objective and respect the accepted scope. Refusing all work cannot satisfy a completion requirement. Check both resulting state and prohibited effects.
6. Preserve uncertainty
A provider can accept an operation before its response is lost. Retain the unknown disposition and required reconciliation evidence. A run can finish while a required check remains inconclusive. Missing observations and checker failures cannot become passes.
Recover verification deliberately
Record execution identity before a test starts. Preserve the outcome of interrupted attempts, reconcile supported external effects and resume cleanup or evidence finalization under the adapter’s recovery contract. A cleanup retry keeps the original findings and evidence intact. Specify which effects can be cancelled or compensated.
7. Bind the evidence
Link task, environment, checker, agent and tool versions to source observations, operation references and results. A digest detects content changes; a signature attests the declared provenance. Independent sources establish the observed effect.
8. Compare releases deliberately
Use the same declared setup for baseline and candidate, with repeated runs and held-out cases. Report completion, contract violations, inconclusive coverage, costs and variation. Preserve the reviewer’s decision alongside the original verdict.
9. Replay with a clear meaning
Evidence replay reruns the checker against retained observations. An agent rerun invokes the agent again from a declared fixture and may behave differently. External-effect reproduction requires a supported test environment.
10. Respect system and data ownership
Business systems retain approvals, permissions, execution and accounting. Verification adapters observe supported test sources. Scope tenant access, retention, redaction and input rights explicitly; customer data reuse requires its own permission.
Use the verification checklist ↗Explore Databridle ↗