Article chapter 03 of 08
Give each agent its own isolated workspace
Run each implementation in its own branch or worktree from a named commit, so one agent's half-done edits can't leak into another's and the reviewer has a stable base to compare against. Write the starting commit into the task or the pull request.
Keep the agent's permissions tight. Most coding tasks need read and write access to the repository and permission to run local checks. They probably don't need production credentials, the ability to publish packages, deployment access or the right to merge. If a test needs an external service, give the agent a scoped test environment or a fixture instead of a broad credential copied off someone's laptop.
Make the environment reproducible: repository instructions, setup commands and the same verification entry points continuous integration uses. If it installs an unexpected dependency, regenerates a lockfile or edits local configuration, that should show up in the diff and come with an explanation.
Ask the agent to stop and check in when the task boundary moves. Say it finds it needs a schema migration the task never mentioned, or a change to a shared API contract, or it turns up a security issue, or a baseline test is already failing so it can't verify anything. The right next step might be to revise the task, tell another owner or open a separate issue. If it quietly widens the patch instead, the eventual review takes much longer.
Limit how much concurrent work happens in the same area. Separate worktrees stop files getting mixed up, but they do nothing about two changes that conflict in meaning. Two agents can each change the same data contract and both pass happily on their own branch. An ownership view or task board showing which files, modules and contracts are in motion helps here.
When an agent finishes, keep the worktree until review starts or the final checks can be reproduced elsewhere, and don't rely on anything uncommitted. The pull request should hold the complete intended change, with no file it needs left sitting only in the agent's workspace.