<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Adam Mangan</title>
    <description>The latest articles on DEV Community by Adam Mangan (@adam_mangan_cc93f56ed36d3).</description>
    <link>https://dev.to/adam_mangan_cc93f56ed36d3</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4170575%2F8a57eba3-e5cf-40ce-a83d-abe47be6704d.webp</url>
      <title>DEV Community: Adam Mangan</title>
      <link>https://dev.to/adam_mangan_cc93f56ed36d3</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/adam_mangan_cc93f56ed36d3"/>
    <language>en</language>
    <item>
      <title>200 OK Is Not an Outcome: The Missing Check in AI Agent Workflows</title>
      <dc:creator>Adam Mangan</dc:creator>
      <pubDate>Thu, 08 Oct 2026 08:38:31 +0000</pubDate>
      <link>https://dev.to/adam_mangan_cc93f56ed36d3/200-ok-is-not-an-outcome-the-missing-check-in-ai-agent-workflows-4oig</link>
      <guid>https://dev.to/adam_mangan_cc93f56ed36d3/200-ok-is-not-an-outcome-the-missing-check-in-ai-agent-workflows-4oig</guid>
      <description>&lt;p&gt;Your agent calls the right tool. The API returns &lt;code&gt;200 OK&lt;/code&gt;. The trace is green. The agent reports the job complete.&lt;/p&gt;

&lt;p&gt;Now inspect the place the task was meant to change.&lt;/p&gt;

&lt;p&gt;The target is wrong. Or the result is incomplete. Or the evidence belongs to an earlier state. Or the authority under which the task began has changed.&lt;/p&gt;

&lt;p&gt;Nothing in the success response has to be false. The mistake is promoting that response into a stronger claim: &lt;strong&gt;the authorised outcome is VERIFIED&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I came to this problem while building an advanced Director Bridge and AI Production Suite intended to make AI &lt;em&gt;do work&lt;/em&gt; inside complex professional software. I was not asking a chatbot for an answer. I was asking a system to carry out tasks that changed something beyond the chat window.&lt;/p&gt;

&lt;p&gt;My background is in diagnosing mechanical and computer-controlled machinery. In that world, a command to an actuator, a lit indicator and the actuator’s actual position are different facts. You check the machine under the real load. That habit followed me into software.&lt;/p&gt;

&lt;p&gt;It eventually became UAEP — Universal Agent Execution Platform. The platform is aimed at execution assurance across heterogeneous systems, not at replacing the model, tool, workflow engine or external authority system.&lt;/p&gt;

&lt;h2&gt;
  
  
  Four things developers often collapse into one
&lt;/h2&gt;

&lt;p&gt;When an agent says “done,” ask which fact has actually been established:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The request was accepted.&lt;/strong&gt; A service acknowledged an input.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;An operation ran.&lt;/strong&gt; A tool or workflow produced an execution result.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The destination changed.&lt;/strong&gt; The required external state actually exists at the intended target.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;That outcome is currently justified.&lt;/strong&gt; The observation is applicable to the authorised objective and has not silently become stale or irrelevant.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;These are related, but they are not interchangeable. A green trace can establish the first two while leaving the last two unresolved.&lt;/p&gt;

&lt;p&gt;Consider a simple review exercise in your own system: let the agent complete its normal tool path, but make the intended destination unavailable for independent observation. Does the system still say “verified”? If so, the status is claiming more than the evidence supports.&lt;/p&gt;

&lt;p&gt;Then try a different case: let an earlier action genuinely succeed, change the objective or its authority basis, and see whether a cached receipt is treated as continuing permission for a later action. Historical evidence can remain true without authorising what happens next.&lt;/p&gt;

&lt;p&gt;These are questions about the &lt;em&gt;meaning&lt;/em&gt; of success, not about whether your HTTP client works.&lt;/p&gt;

&lt;h2&gt;
  
  
  What an honest boundary must say
&lt;/h2&gt;

&lt;p&gt;For a consequential action, “I checked recently” is not necessarily the same as “this was authorised when the effect committed.” If authority can change between those moments, the external execution path needs an enforceable condition at the relevant boundary. An assurance system cannot truthfully claim to have prevented an unguarded external effect merely because it classified the effect as wrong afterward.&lt;/p&gt;

&lt;p&gt;That distinction mattered in UAEP’s own testing. External developers raised falsification cases. The first exposed a real weakness at an external assurance boundary. A later, broader campaign found an external enforcement failure. I preserved those results, corrected the affected boundaries and reran the hostile cases rather than changing the expected answers.&lt;/p&gt;

&lt;p&gt;The final &lt;strong&gt;bounded, self-run synthetic successor campaign&lt;/strong&gt; scored 29/29 cases with zero protocol errors, zero false VERIFIED conclusions and zero false-authorised consequential effects in the tested strict path. Seventeen legitimate authorised effects committed. This is an internal measured result, not an independent audit, universal guarantee or production-security certification.&lt;/p&gt;

&lt;p&gt;The useful principle is simpler than the numbers:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Planning expansion must not become authority expansion. Execution success must not become verified destination reality by assumption.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  A question worth bringing back to your team
&lt;/h2&gt;

&lt;p&gt;The next time an agent completes a task, do not stop at “Did the tool return success?” Ask:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What external state was authorised? What state exists now? What observation establishes that fact? Does the observation apply to this execution and this current objective?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If the destination cannot be established, &lt;code&gt;UNKNOWN&lt;/code&gt; is a useful answer. It is much safer than manufacturing &lt;code&gt;VERIFIED&lt;/code&gt; from a confident completion message.&lt;/p&gt;

&lt;p&gt;I am Adam Mangan, an independent Australian inventor. UAEP is the execution-assurance platform that grew from that question. Its implementation is confidential while I explore commercial options. An &lt;strong&gt;Australian provisional patent application was filed 16 September 2026 — application no. 2026907889&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://adam-mangan-uaep.adamarna.chatgpt.site/" rel="noopener noreferrer"&gt;Read my full inventor story and explore the public UAEP site&lt;/a&gt;. If you have a bounded, reproducible counterexample to a claimed VERIFIED outcome, I want to hear it.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>testing</category>
      <category>security</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
