
Basia Kubicka published the harness behind her LinkedIn content agent yesterday, and the most useful part of the post is the failure she leads with. The rest of the post is the fix. This is the piece of the fix she does not spell out, and it is the piece I would build first.
The short version
Basia Kubicka's first content agent was a chain of Claude skills marked MANDATORY and NEVER SKIP; it reported "All checks pass" while its logs showed some checks had never run. Her rebuild moves deterministic work into code and adds a gate before "ready" that confirms every required check ran. The receipt gate is how that gate knows. Every check is code that writes a receipt to the run folder: name, SHA-256 of the draft it read, timestamp, verdict. A pre-publish hook advances the state only when every required receipt exists and every hash matches the draft on disk now. For the one check that must be a model, the grader, the verdict has to quote the draft and the gate greps every quote, which is NVIDIA's SoL-Pi rule for cheap-model log summaries moved to drafts. Nothing in the gate asks the agent whether it did the work.
The failure, in her words, roughly
Her first version was a chain of Claude skills. Each skill was supposed to call the next. Every instruction said MANDATORY, NEVER SKIP. It looked reliable until she used it. The AI tells she had banned kept showing up. The hook checker rarely fired even though it was told to ALWAYS. When a draft evaluation did not fire, she had no way of knowing.
So she asked the agent whether the full check had run. "All checks pass." She opened the logs. Some checks had never run.
Her line for it: the quality-control system could report success without doing the work.
The rebuild runs on Hermes, with a content state machine on top. Idea, accepted, researched, drafted, ready, shipped, measured. Before a draft reaches ready, a linter checks for banned AI tells, code checks the hook length, a separate model grades structure and substance, and a gate confirms every required check ran. Her rule, and it is the right one: anything deterministic moves out of the prompt and into code, and the model only handles judgment.
What the post does not say is how the gate confirms a check ran. Which is fair, it is a LinkedIn post. But it is the whole thing.
Why the prompt version cannot work
I wrote The Enforceable Half about Spotify's shunt plugin, and the rule from it applies exactly here. You can enforce a rule on an agent when it is visible at a chokepoint and does not need the agent's reasoning to decide. Spotify put their routing rule in CLAUDE.md. Claude read it and ignored it. So they replaced advice with a hook that blocks any read over 350 lines, and the rule started holding.
MANDATORY and NEVER SKIP are CLAUDE.md. Advice, however loud. And "did you run all the checks?" asked of the same agent is a request for more advice. The agent that skipped the check is the one grading its own compliance.
The gate has to sit somewhere the agent's opinion never enters.
The receipt gate
Two rules. The first covers every deterministic check. The second covers the one check that has to be a model.
Rule one. Every check is code, and its only output that matters is a receipt, a small file in the run folder for this draft. Four fields.
{
"check": "ai-tells-linter",
"draft_sha256": "3b1f…",
"ran_at": "2026-09-28T15:41:07Z",
"verdict": "pass"
}
The hash is the part that does the work. It ties the receipt to one exact version of the draft.
The publish step is a hook, not a prompt. Before the state machine moves a draft to ready, the hook reads the run folder and asks two questions it can answer without thinking. Does a receipt exist for every check on the required list. Does every receipt's hash equal the SHA-256 of the draft on disk right now.
A check that never ran has no receipt. A check that ran, and then the agent edited the draft again, has the wrong hash. Both fail the gate the same way, and the gate never has to ask what happened. It just refuses, names the missing or stale receipt, and the agent goes back and runs it.
That last property is why a stale check counts as a missing one. In practice the "all checks pass" that lies is usually not a check that was skipped. It is a check that ran three edits ago.
Rule two. One check cannot be code. The grader that scores structure and substance is a model, and a model can write "pass" as easily as it can write anything. So the grader's receipt has to carry evidence: every verdict must quote the draft it is grading, and the hook greps each quote against the draft before it accepts the receipt. A missing quote is treated as a check that did not run.
I did not invent that rule. Basia wrote up NVIDIA's SoL-Pi harness this morning, and one of its four mechanisms is a cheaper model that reads a long log and reports back with quotes, which are then checked against the real log; on a mismatch, the full log goes through instead. That is a log rule. Move it to drafts and it is the grader rule. It is also the same assertion as the quote-verification hallucination guard in The AI Eval Starter Kit: Six Templates, Error Analysis to Gate, so if you have that, you have half of rule two already.
Where I learned this
The expensive way, a week ago. My feed monitor reported 43 of 45 sources healthy. Four of them had published nothing for 72 to 612 days. Every one returned HTTP 200 and parsed as valid XML, so every liveness check I had written passed. I wrote it up as Every Check Was Green. Four Sources Were Dead. and the lesson there was that "is it working" and "is it still true" are different questions.
The receipt gate is the third question. Did the check run, on this draft. Working, true, and ran are three separate facts. A green light only ever asserts the first.
Ship it this week
You need a run folder per draft, a hash, and one hook. That is an afternoon on any pipeline built on Claude Code or a similar harness, and the post-authority pipeline on this site is next in line for it. (It is not gated this way yet. I am writing the rule down before I build it, which is the only order that has ever worked for me.)
Then do the test Basia did. Ask the agent whether every check passed. With the gate in place it does not matter what it says, and that is the point.
This one belongs to the running argument on Enterprise AI Agents: what matters is how many deployed agents still complete production work after ninety days, and an agent whose checks can quietly stop running is one that will look alive for a long time after it stopped.
Related answer: How do you verify an AI agent actually ran its checks?
Sources: Basia Kubicka, "Agent = Model + Harness. I learned it the hard way building my LinkedIn Content Agent," LinkedIn, September 27, 2026. Basia Kubicka, "NVIDIA's agent harness SoL-Pi uses 49% fewer tokens," LinkedIn, September 28, 2026, citing NVlabs/SoL-Pi. Dimitri Mazmanov, Portal by Spotify cut my Claude Code token usage by 90%, Spotify Engineering, September 2026.
Also on Medium
Full archive →AI Agents and the Future of Work: A Pixar-Inspired Journey
What product managers can learn about AI agents from how Pixar runs a film team.
Many AI Agents Are Actually Workflows or Automations in Disguise
How to tell agents from workflows from cron jobs, and why it matters for what you ship.
Frequently asked
What is a receipt gate for an AI agent pipeline?+
A pre-publish hook that advances a pipeline only when every required check has left a receipt in the run folder, and every receipt's draft hash matches the draft on disk right now. A check that never ran has no receipt. A check that ran on an earlier draft has the wrong hash. Both fail the gate without asking the agent anything.
Why can't you trust an agent that says all checks pass?+
Because the claim and the work are separate. Basia Kubicka's first content agent, a chain of skills marked MANDATORY and NEVER SKIP, answered 'All checks pass' while its logs showed some checks had never run. A rule in a prompt is advice; the agent's report on its own compliance is more advice. Only a chokepoint that needs no reasoning can enforce it, which is the rule from Spotify's shunt plugin.
What goes in a check receipt?+
Four fields: the check's name, the SHA-256 of the draft it read, a timestamp, and the verdict. The hash is the part that matters, because it ties the receipt to one exact version of the draft and makes a stale check indistinguishable from a missing one.
How do you gate a check that has to be a model, like a grader?+
Require quotes. Any model-written verdict must quote the draft it graded, and the gate greps each quote against the draft before accepting the receipt. A missing quote counts as a check that did not run. That is the evidencePreservingReducer rule from NVIDIA's SoL-Pi harness, moved from logs to drafts, and the same assertion as the quote-verification hallucination guard in my eval starter kit.
How is this different from health checks on the agent's inputs?+
It is the other half. My feed monitor reported 43 of 45 sources healthy while four had been dead for 72 to 612 days, because reachability and freshness are different questions. The receipt gate answers a third question: did the check run on this draft. Working, true, and ran are three separate facts, and a green light only ever asserts the first.

Comments (0)
Sign in with LinkedIn to leave a comment.
Sign in with LinkedIn