Skip to content
Agent Engineering Lab
Patterns

Patterns

A pattern language for shipping agentic systems. 26 entries: 21 patterns and 5 anti-patterns, of which 2 keep an established name, 18 are named here after a prior description, and 6 are proposed.

The Pattern Wheel

Position encodes use. Rings are lifecycle stage, design innermost to govern outermost. Sectors are architectural layer: capability, control, evidence. Hover a mark for its name. Click one to trace what it connects to.

The Pattern WheelFive lifecycle-stage rings, design innermost through build, evaluate, operate, to govern outermost, crossed with three layer sectors: capability, control and evidence. Twenty-six entries, each placed once, in the cell matching what it is for and when it applies.designbuildevaluateoperategoverncapabilitycontrolevidence0102030405060708091011121314151617181920212223242526
capability control evidence

Select a pattern. Hover a mark for its name, click to see what it connects to.

Each entry sits at the stage where its principal design decision gets made, its primary placement, not every stage it touches. Five of fifteen cells are empty: no catalogue entry currently has capability's evaluate, operate or govern as that primary home, or control's evaluate, or evidence's design.

Documented
A settled external name, kept unchanged, with its attribution.
Restated
An established practice with no settled name. Named here, citing the nearest prior description.
Proposed
A shape not previously described in the prior art surveyed.
Referenced
Well covered at its source. Listed and linked, never re-documented here.

Capability

What the agent can do, and how it is built.

  • 01 Earn the Complexity restated, after Schluntz and Zhang, Anthropic

    Every increment of complexity is paid for by a measured delta on an axis named in advance.

  • 02 Workflow First restated, after Schluntz and Zhang, Anthropic

    Default to a deterministic workflow; autonomy has to earn its place.

  • 04 Harness Engineering documented, Sarang Sanjay Kulkarni

    Reliability lives in the scaffolding, not the model.

  • 05 Tool/Agent Registry documented, Liu et al.

    The callable set is declared data, not whatever the runtime can reach.

Control

What constrains it at runtime.

  • 06 Approval Gate restated, after Intelligence Patterns

    Human authorization before an irreversible act, with defined timeout behaviour.

  • 07 Attenuating Delegation restated, after Birgisson et al.

    Authority never widens at any hop.

  • 08 Authority at the Call Site restated, after Saltzer and Schroeder

    The control sits where the tool call happens, not where the prompt was authored.

  • 09 Bounded Grant restated, after Microsoft

    Scope, magnitude, expiry, revocation, all four or none.

  • 10 Chokepoint Placement proposed

    Placement sets the accuracy ceiling before you pick a model.

  • 11 Capability Gate restated, after Microsoft

    Destructive actions pass a gate the model cannot argue with.

  • 13 Verdict Composition proposed

    Compose verdicts; never average scores that do not mean the same thing.

  • 14 Verifier Loop restated, after Intelligence Patterns

    A deterministic verifier checks each step against the original task.

  • 15 Fail Closed, Degrade on Exposure proposed

    You cannot un-disclose, so degradation keys on exposure, not harm family.

  • 17 Tiered Detection restated, after Viola and Jones

    Cheap on everything, expensive on the band, subject to the escalation fraction.

  • 18 Escalation Path restated, after PagerDuty

    Where a blocked case goes, and who owns it when it gets there.

Evidence

What it can prove, and how it stays honest.

  • 19 Decision Record restated, after Microsoft

    Every enforced action leaves a replayable record carrying its policy version.

  • 20 Split the Log proposed

    Three stores, three retentions, three audiences; merging them fails both ways.

  • 21 Baseline and Floor proposed

    A gate needs both, or cumulative sub-threshold drops erode recall while every release passes.

  • 22 Failure Buckets proposed

    A rubric that scores without bucketing cannot tell you what to fix.

  • 25 Shadow Before Enforce restated, after Martin Fowler

    A control records before it is allowed to act.

  • 26 The Expiring Exception restated, after Microsoft

    An exception with a mandatory expiry is a control; without one it is a hole.

Anti-patterns

Named failures. Each one names the pattern that replaces it.

  • 03 Workflow in an Agent Costume restated, after Schluntz and Zhang, Anthropic

    A fixed sequence dressed as autonomy, buying unpredictability without earning the benefit.

  • 12 The Uncalibrated Ensemble restated, after Jain, Nandakumar and Ross

    Averaging scores that were never on the same scale manufactures false confidence.

  • 16 Silent Fail Open restated, after MITRE, CWE-636

    When the control fails, the action goes through and nobody is told.

  • 23 Hallucinated Done restated, after Cemri et al. (MAST)

    The agent declares the task done with no check that it actually is.

  • 24 Rubber-Stamp Verifier restated, after Cemri et al. (MAST)

    A verifier that approves everything is not verifying anything.

Named elsewhere, not re-documented here