DEV Community

imokokok
imokokok

Posted on

An AI trading agent paused. Can you tell why?

Imagine an agent preparing an ETH to USDC swap. It cannot complete its price check, so it pauses.

Six months later, an auditor finds an empty price field. What happened?

Perhaps the agent retrieved quotes, but too few met its freshness or independence requirements. Perhaps a provider timed out and the quotes were never retrieved. Those are different events, yet a nullable field makes them look the same.

I would model the outcomes explicitly:

type PriceCheckResult =
  | {
      kind: "passed";
      policyId: string;
      evidenceDigest: string;
    }
  | {
      kind: "insufficient_evidence";
      policyId: string;
      reasonCodes: string[];
    }
  | {
      kind: "retrieval_failed";
      policyId: string;
      source: string;
      errorCode: string;
    };
Enter fullscreen mode Exit fullscreen mode

The policyId matters because “insufficient” is a judgment against a particular set of requirements. The same observations might pass one policy and fail another. A reviewer needs the policy that applied at decision time, not just the agent’s final verdict.

I would keep this assessment separate from two later records: what exact action the user authorized, and what execution was observed. A valid price check does not authorize a transaction. A transaction hash alone does not explain the decision or the authorization that preceded it.

This separation guides my work on Insight for oracle evidence and PriorSeal for EVM authorization and execution evidence.

How do you preserve policy context in an audit trail: a full snapshot, an immutable reference, or both?

Top comments (0)