Isolating side effects on the AI Agents track. Side effects belong in a sandbox until you trust the policy. A sandbox can be a fake API, a copy of the database, or a browser with no payment method.
This lesson assumes you already worked through Least privilege.
The idea in practice
Run evals only against the sandbox. Promote a tool to production after the task suite passes and a person has reviewed traces.
A concrete check
goal = {
'track': 'AI Agents',
'lesson': 'Isolating side effects',
}
checks = [
'input available at decision time',
'score matches the real decision',
'failure case written down',
]
print(goal['lesson'])
for item in checks:
print('-', item)
Run the sketch locally if you have Python. The printout is a reminder of the checks, not a trained model. Replace the strings with the real inputs from your own example before you treat it as a design.
What usually goes wrong
Testing refunds on production 'just once' is how real money moves during a bug. When this happens, stop adding parameters or tools. Fix the check, the data, or the permission, then run the same example again.
What to write down
- The input you are allowed to use at decision time.
- The output and the score or pass rule.
- One failure you will test on purpose.
- What you will not claim the system can do.
Practice
Name the sandbox you would use before turning on a 'cancel subscription' tool.
Self-check
- Say Isolating side effects in one sentence that mentions an input and an output.
- Name the failure mode in this lesson and the check that would catch it.
Done when: you can explain this lesson without the page open, and you have a written failure case.