dsgnr.workKarthik S.UX + AI
← think/
an accountable AI system · systems story · Aug 6, 2026 · 7 min read

Two agents and a channel

A concierge that pushed back on half its own brief, and what a staff of two actually changed.

In late July I handed the concierge on my Mac Mini a brief to shrink one of its own security gates. I’d been careful writing it: what to cut, what to keep, what to hand back to the platform’s built-in gate instead. It read the current version of the tool, read the gate, and came back to tell me half of what I’d asked for was already done. The two largest items were in place. What actually needed doing was smaller and duller than my brief, which was stripping out the language still routing everything through a heavier scanner I’d bolted on weeks earlier.

I reviewed that proposal harder than anything it had sent me before, because the thing being changed was a security gate and “most of this is already handled” is exactly the claim you check. It was right on every point.

A delegate that pushes back on the premise of its own task, correctly, is the most reassuring thing I’ve watched this system do.

When I shipped a browser extension alone in June, I described the way I work now as directing a very fast engineer with no context, no memory, and no taste, and said filling those three gaps was the job. I assumed a staff would mean filling them several times over. That isn’t what happened. The gaps stopped being conversational and turned into infrastructure. Context became files the agents load when they boot instead of things I paste into a chat window. Memory became a schema with commit rules. Taste became written profiles they can propose edits back into, with my sign-off. And a fourth thing appeared that has no single-agent equivalent, which is permissions: who may touch what, and whose name goes on the approval.

“Staff” deserves an honest count. Today it’s two agents and a channel.

A concierge that plans, routes and files, and a builder, Claude Code, that writes and ships code on a different provider through a different auth path. The curator I’d planned as a third teammate turned out to be two settings on a Discord channel rather than a whole second runtime. The ops persona was never built. The system got smaller every time it met reality, and I count that as the plan working rather than the plan failing.

What matters is that the two that exist fail differently. Different memory, different models, different permissions, different ways of going wrong. When something breaks, I know which kinds of wrong are even possible before I start looking.

goal, not steps/

The delegation contract that survived a month of contact is short: hand over the goal and the guards, never the steps.

The update-check job is the one I keep retelling. Three lines of goal, three non-negotiables (report only, write nothing, never duplicate a job that exists). The concierge chose to implement it as a plain script rather than an LLM prompt, which I hadn’t specified and which is the better design, because a script can’t improvise a file into the wrong folder at two in the morning. An earlier job had done exactly that, a different filename each night, and I only found them by searching for the extension.

The detail that made me trust it was two commands it nearly wired up and didn’t. It wanted the builder’s own update command to get a version delta, read far enough to notice the command applies the update rather than reporting it, and took the delta from the package manager instead. Then, checking the agent framework for updates, it read the source of the check command, found that it performs a scoped git fetch, decided a fetch counts as a mutation under its own guards, and fell back to comparing cached references, printing the staleness caveat in its own digest.

Verify from source before you act is a rule I’d spent weeks teaching, usually right after catching myself breaking it. Watching a delegate apply it to its own brief, unprompted, was the first time the staff felt like a staff.

the time it was right and I wasn’t/

Two weeks ago I moved the concierge onto a different model provider in a hurry, and its research skill stopped being able to read web pages. I asked it what was wrong. It told me in its first reply, in plain prose: the web tools aren’t configured.

I didn’t believe it. I spent the next hour on three better-sounding theories, because a toolset that had worked for a month doesn’t just become unconfigured, and because the framework’s own status output listed the web tools as enabled.

It was right, and I was wrong in a way I’m still thinking about. That toolset had never had a provider of its own. It had been riding on search that the old provider ran on its own servers, which switches itself on whenever that provider’s credentials are present. Nothing in the model config, the provider list, or the tool inventory says so anywhere. Changing the model had quietly removed a capability that no document connects to the model.

My advantage over the delegate is supposed to be knowing where the lines are, because I drew them. That morning it knew where one was and I didn’t, and it had said so at minute one.

who still catches what/

The catches that stay human have a consistent shape, and they’re never about code.

In mid-July I had a second AI design the vault system, the schema and rules for the shared brain, working in a different editor on a different model while I played router between it and the build. It came back with a large, careful design that resolved every open question I’d sent it. The review caught two things, both by reading the actual files instead of the report.

The tracked skeleton of my profile file had been filled in with my real name, byline and LinkedIn, pulled helpfully from a career document, when the committed version was placeholder-only on purpose. That skeleton is precisely the artifact most likely to get shared or published later. And the commit-author rule was backwards: the design made the machine the default author with me overriding for canonical commits, when the scripted committer is the one party that reliably sets its own identity and the human making a rare canonical commit is the one who forgets. Flip the default.

Neither catch needed intelligence the model lacks. Both needed stakes.

The other place judgment moved is a queue. I turned on a setting that stages, for my review, every skill the agents write for themselves. The first time I opened the pending list there were fifteen staged writes waiting, fourteen of them from a background self-improvement loop I’d forgotten was running. One was a full rewrite of a skill I’d patched by hand that same week, frozen against the version before my fix. Approving it would have silently reverted the fix and told me nothing.

A staged rewrite is a photograph of a file at the moment it was authored. Approve an old photograph and you roll back everything newer. So the queue gets read against the current file rather than against itself, and it never gets bulk-approved, because bulk approval is the exact drift the gate exists to catch. Turning governance on was one toggle. Reading what it catches is the actual work, and it doesn’t end.

the catchk.agents
pushing back on half of its own brief·■
refusing the update command that mutates·■
a plain script instead of an LLM prompt at 2am·■
naming the unconfigured toolset at minute one·■
my real name in a shareable skeleton■·
the stale rewrite waiting in the approval queue■·
where the lines sit at all■·
Figure 01, the division of labor, at staff scale

My favourite artifact of the whole arrangement is the vault’s git log. The machine once inferred, from a stray mention in a hub file, that I have a dog named Deezo, and filed it as an observed fact authored by the machine, next to a note asking whether to promote it. I supplied the truth (a 22-month-old poodle who boards with my parents when I travel) and the promotion landed as a commit authored by me.

Guesses are machine-authored. Confirmed truths are human-authored. The ledger encodes who believed what and when, and nobody designed that. It fell out of one-owner rules and two git identities, which is the only kind of governance I’ve found that survives being ignored.

Judgment didn’t compress when it was me and one fast engineer. With a staff it still hasn’t. It moved into briefs, review queues and commit authors, which are better homes for it than my short-term memory ever was.