22 September 2026 / Agent operations / 8 chapters

Write down each external action on its own

From Recovering an automated workflow after a partial failure

When a case enters the workflow, give it a stable identifier and keep that identifier across every attempt. That way an operator can find the whole history, including the original input and any later correction. Each new execution attempt gets its own identifier too, linked back to the case.

Then record the steps that have their own effects. Here, preparing the proposal, getting approval, creating the external record and sending the notification are all separate. The write can succeed while the notification fails, and a single "failed" flag on the case throws away what you'd need to restart in the right place.

For an external action, I'd record:

  • What the operation is meant to do, and which destination account or environment it targets.
  • The approved input version, plus a protected reference to the request.
  • A stable operation identifier, and separate identifiers for each attempt.
  • When dispatch started and what response came back, if any.
  • The destination's record or request identifier.
  • The latest result you've seen and how you checked it.

Write the intended operation to durable storage before you send anything, so if the worker dies after sending, the next one knows an attempt might have happened. Add later observations to the history instead of overwriting it. Replace the original timeout with a "success" label and nobody can tell later why recovery was needed.

A database transaction can protect related local changes, but it normally can't wrap a remote API call and your local completion record into one atomic operation. There's always a gap where the remote change succeeds and the local update doesn't. You need a way to look into that gap, and the saved operation identifier is what you'll use to do it.

Keep sensitive payloads in storage with proper access controls and retention, and have the operational record point at them. Copying the whole source document into every log entry makes access and deletion harder and gives the operator far more text than they need.

All articles