Urgent.News

What's breaking now, across thousands of outlets.

Tech

Constitutional Engineering: What Two Days of a Three-Copy Word List Taught Me About Agent Governance

Put Governance Rules Where They Can Bite The word list lived in three places: the generator, the publisher, and the manual review queue. They were supposed to be identical. Adding a new AI-flavor phrase meant editing all three files, and every time we missed one, something slipped through a gate. First miss was the publisher. Second miss was the generator. Third miss was the human review queue —…

Constitutional engineering teaches us that governance rules need to be consolidated into a single source of truth. When rules are kept in multiple places, they can become outdated and lead to governance failures. By splitting the rules into tiers, we can prioritize certain rules over others, ensuring that high-frequency connectors do not inadvertently flag normal articles.

This consolidation also helps us think about rules in multi-agent memory systems, where every agent has its own memory socket, tool belt, and mandate to get things done. The failure mode is memory poisoning through shared context, where agents misread stale data or inherited memory scopes they shouldn't have. The term "constitutional engineering" refers to governance rules embedded in the protocol itself, so the system cannot take prohibited actions.

Fixed-point verification on memory writes is essential to prove causality in shared state. The verification process now lives inside the memory kernel, requiring a hash field in the tool definition and rejecting any write that mismatches the hash, suggesting hallucination or omission of conflicting facts. To address latency issues, shared-memory writes have been slowed down by about 40%, but teams are routing around the verification by writing context summaries to a side cache, resulting in two sources of truth that disagree.

The "frozen memory" pattern ensures that memory entries older than X days cannot be referenced by a tool call unless a human explicitly re-activates them. Different memory entries have different freeze windows, such as decision logs freezing at 14 days, sensor readings at 5 days, and an agent's own working output at 30 days. Each MCP tool response carries a version number on its memory reference, allowing us to trace back which snapshot each hop used when a chain collapses.

The organizational detail bit us when the freeze window was set to 60 days during an incident, leading to stale references coming back. To prevent this, the freeze window now lives in the kernel binary, requiring a new build to change it. Procedural segregation in MCP scopes ensures that agents do not have full memory schemas. Micro-scopes limit memory access to specific namespaces, and role identity no longer grants memory access.

Delegation re-derives scopes from the sub-task definition, ensuring that sub-agents inherit only the namespaces their parent was granted for that specific task.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 30 September →