Your agent approved something before it was reviewed. So you tightened the prompt — “always review first.” A week later it deployed before the tests ran. You added another sentence. Then it happened a third time, in a way your sentences hadn’t predicted.
At some point you have to stop blaming the prompt. The prompt isn’t the problem. The problem is that your agent has no idea where it is.
An agent with no sense of place
A model call doesn’t have a location. The agent’s only sense of “where things stand” is a growing pile of conversation — and nothing in that pile authoritatively answers the two questions that matter: what step are we on? and what is allowed right now?
So the agent infers. It reads back over the transcript, forms an impression of how far along it is, and decides what to do next from that impression. Inference like that works most of the time, which is the trap — it works often enough that you ship it, and drifts often enough that it hurts.
The unglamorous fix
There’s a pattern built for exactly this, and it is not exciting. A state machine: a finite set of named states, and transitions between them, where each transition is legal only from certain states. You drew one in your first computing course. The idea is roughly 70 years old.
That’s not a strike against it. That’s the reason to use it. A state machine is something you can draw on a whiteboard, read top to bottom, diff in a pull request, and check for mistakes before it ever runs. When the thing you’re trying to govern is a probabilistic model that will surprise you, the one place you want zero surprises is the structure doing the governing.
Every move is a transition
This is the move Praxec makes. A workflow is a state machine, and every action is a transition between states. The simplest workflow has one state — that shape is just a flat list of tools, the degenerate case of the same idea. So you’re never choosing “state machine or not.” You’re choosing how many states. Zero extra states gives you a plain tool list; add states when the process has an order worth enforcing. Same kernel, same two tools facing the model either way.
Four things a state machine gives an agent — that a prompt can’t
-
A definition of “now.” The workflow has a current state, and it’s a fact, not an impression. The agent asks, and the answer is authoritative. “Now” becomes data.
-
A definition of “legal.” A transition is legal only from the states that declare it. The
approveaction isn’t discouraged early — it does not exist as a move until the workflow is in the state that offers it. At every step, the set of things the agent can do collapses to the set of things that are correct to do. -
A recorded path. Every transition advances the state and bumps a version counter. How the workflow got here is the state history, recorded as it happened, with an audit event for every step — not forensic guesswork after an incident.
-
A shared source of truth. Multiple actors — a model and a human, or two models — read and write the same state, with version checks that reject stale writes. The state machine is the coordination point they all agree on.
Stop blaming the prompt. Give the agent a place to stand.