Fix It at the Cheapest Place That Can Still Correct It

Routing savings, fine-tuning decisions and self-improving loops are the same question: where does the fix live, and who can undo it. Put the fix as low as it can go, and never let a system change itself without a gate.

October 10,2026 | Estimated reading time: 17 min | 3588 words | Author: khanhnn

Before You Trust an Eval Number, Find the Useless System That Would Score Well on It

Agreement between an LLM judge and humans, and accuracy of an agent that can decline, both look like clean measurements until you ask what a useless system would score. Most of the reliability work is making the number stop rewarding the wrong thing.

October 10,2026 | Estimated reading time: 16 min | 3241 words | Author: khanhnn

Authority and Checking Decide What an Agent Can Safely Do

Prompt injection defences that try to recognise attacks lose to adaptive attackers, while designs that decide who holds authority and what can say no hold up. The same logic caps how much autonomy a loop deserves, and it explains why a human reviewer is not automatically a fix.

October 10,2026 | Estimated reading time: 13 min | 2740 words | Author: khanhnn

Agent Memory Fails Quietly, So Check It at Both Ends

Agent memory goes wrong in two places that never raise an error: an item admitted without checkable conditions, and a filtered search that quietly stops finding anything. The fix in both cases is a deterministic check placed before any ranking happens.

October 10,2026 | Estimated reading time: 17 min | 3524 words | Author: khanhnn

The Only Free Edit Is at the End of the Window

An agent loop can append for free, but changing anything earlier breaks the cache and risks the state. So the prompt layout and the compaction policy have to be designed together, and judged by cost and by the decisions that still follow.

October 10,2026 | Estimated reading time: 16 min | 3370 words | Author: khanhnn