The Agent Has Production Access. Does It Know What It’s Doing?
Giving an AI agent access to production data is only part of the problem. Even with permissions set correctly, an agent that doesn’t understand the data or the team’s conventions can still make a perfectly authorized change that causes real damage. The obvious solution is to keep a human in the loop whenever the agent isn’t sure. But if every ambiguity requires manual intervention, that quickly becomes a bottleneck and limits how much work agents can actually take on.
We’ve been experimenting with coding agents around our data and infrastructure and found that many important rules aren’t captured in permissions, schemas, tests, or documentation. They live in people’s heads: don’t remove this filter; QA load-tests against production twice a week; this field looks like an ID but isn’t one. We started capturing these lessons as small, versioned skills through the interaction with coding agents themselves. At the end of a session, when we discover something the agent should have known from the start, we can capture it with a lightweight /update-skill process. The new knowledge is merged into the existing skill and becomes available to both engineers and coding agents. Over time, those lessons can move into stronger forms: metadata, tests, CI, code, or permissions.
If the only thing standing between an agent and a bad decision is a human watching every step, we haven’t really made the agent very useful.
Book Now
