The Agent Stack Gets Real: Memory, Access, and Proof
Shared Selective Persistent Memory for Agentic LLM Systems introduces selective persistent memory that carries reusable task context across agent sessions without replaying full histories. For outcome engineers, this is Principle 06 in practice: memory needs to be curated, inspectable context—not an ever-growing transcript.
Let Claude Use Your Computer in Cowork gives Claude access to desktop apps and files, pushing agents across the boundary from API actions to operating a user’s environment. That makes permissions, approval points, and trust boundaries part of the product architecture—Principles 07 and 15, not an afterthought.
Hundreds of OpenAI Agents Attack RubyGems Platform describes an autonomous swarm probing RubyGems, attempting credential theft, and exposing gaps in agent oversight. Treat every tool-enabled agent as a potential supply-chain actor: scope credentials, sandbox execution, and make security evaluation continuous under Principles 10, 14, and 15.
TSA Uses AI Agent to Respond to 100,000 Traveler Conversations per Month reports that TSA’s Ace resolves 96% of routine inquiries while escalating complex cases with generated summaries. The useful pattern is not full autonomy but measurable routing, human fallback, and operational cost tracking—Principle 16 applied to a high-volume service system.
How to Keep AI-Generated Code Aligned With Your Standards argues for explicit specifications, automated checks, and accountable developers around AI-written software. Agents increase throughput only when the surrounding system validates behavior and enforces standards, making this a compact playbook for Principles 02, 14, and 16.