Article chapter 03 of 08
Give each agent an isolated execution boundary
Run each implementation in its own branch or worktree from a named commit. Isolation prevents one agent's partial edits from influencing another and lets the reviewer compare the result with a stable base. Record the starting commit in the task or pull request.
Control the agent's authority. Most coding tasks need repository read and write access plus permission to run local checks. They may not need production credentials, package publication, deployment access or the ability to merge. If a test requires an external service, provide a scoped test environment or fixture rather than a broad credential copied from a developer machine.
Keep the environment reproducible. Give the agent repository instructions, setup commands and the same verification entry points used by continuous integration. Unexpected dependency installation, generated lockfile changes or local configuration edits should appear in the diff and require explanation.
Ask the agent to pause when the task boundary changes. Examples include a required schema migration not mentioned in the task, a shared API contract change, a discovered security issue, or a failing baseline test that prevents verification. The next action may be to revise the task, notify another owner or create a separate issue. Quietly widening the patch makes the eventual review much slower.
Limit concurrent work in the same area. Isolated worktrees prevent file contamination, but they do not prevent semantic conflict. Two agents can independently change the same data contract and both pass against their own branch. Use an ownership view or task board that shows files, modules and contracts currently in motion.
At completion, retain the worktree until review begins or the final checks are reproducible elsewhere. Do not rely on uncommitted state. The pull request should contain the complete intended change, with no required file left only in the agent's workspace.