A simplified sketch looks like this:

def run_task(goal, user):
    ctx = start_context(goal, user)
    while ctx.open_steps:
        intent = planner.propose_next(ctx)
        intent = policy.enforce_intent(intent, ctx)
        call = tool_router.bind(intent, ctx)
        result = call.execute(idempotency_key=ctx.step_key)
        checks = verifier.run(intent, result, ctx)
        ctx = commit_step(ctx, intent, result, checks)
        if checks.requires_approval:
            ctx = wait_for_approval(ctx)
    return ctx.outcome



This structure keeps authority in the supervisor. It keeps tool permissions narrow. It gives operations teams a single place to enforce policy and observe behavior.

Operational practices that keep agents stable

I use a short set of practices when teams want agents to run safely in production.