Engineering
Observe first: why Shadow Mode comes before enforcement
Before a workflow can enforce a permission boundary, teams need to understand the actions their agents request—and the limits of observation.
Gated · · 2 min read
Start with the requests
An agent workflow often looks simple in a diagram and more complicated in practice. An instruction becomes a series of tool calls, retries, reads, and writes. Before deciding which calls need approval, it helps to inspect the actual actions a workflow produces.
Shadow Mode is a way to learn about those actions without making observation an execution path. The useful output is a record a person can review: what was requested, which resource it targeted, and how it related to the intended task.
Observation is not protection
A recorded decision does not, by itself, stop an action. Enforcement requires a trusted path that receives the request and respects the result before using provider authority. If the agent has an independent credential, it can act outside that path.
This distinction is especially important during a pilot. A team should be able to say which actions it observes, which actions it controls, and which actions remain outside the boundary. Treating these as separate sets makes gaps easier to find.
Use a narrow evaluation loop
Start with one non-critical workflow and inspect representative requests. Compare the observed action with the task a human intended. Review mismatches, missing context, and repeated observations before expanding coverage.
An evaluation should include awkward cases as well as expected ones: a changed target, an unexpected environment, or a retry of the same action. Those cases help test whether a decision record remains understandable when the workflow is less tidy than the demo.
Move toward an explicit boundary
When a workflow moves from observation toward enforcement, keep permission and execution distinct. The policy result says what is permitted. Human authorization supplies approval when required. The provider result shows what actually happened.
Gated’s private preview focuses on a narrow GitHub branch workflow in non-critical repositories. That small scope gives us a concrete boundary to examine before asking teams to rely on broader coverage.