Part IV - Controlled AI workflows and agents

Multi-step work introduces saved state, retries, permissions, partial failure, and effects outside the program. Fixed workflows use predefined steps and routing rules. In an agent loop, a model selects the next action from the available tools using the current state and observations. Both designs need controls on execution and stopping.

Each step needs defined inputs, checks on its result, and a way to record progress. Retrying an operation must not accidentally repeat its effects. Permissions, approval checks, and time and cost limits control what may run. These safeguards also apply when the system plans work, runs code in a restricted environment, uses a shared protocol to connect tools run by separately managed services, transfers tasks between agents, or saves information for later use.

Chapter 8 compares chains, routes, parallel branches, feedback loops, and approval checks. Chapter 9 examines one tool-using agent and repeated trials. Chapter 10 covers planning, restricted code execution, shared tool connections, and retrieval recovery. Chapter 11 examines agent handoffs and information reused across sessions. These are design choices for different requirements, not required upgrades.

Four chapter panels for Chapters 8 to 11 show predefined routes and joined worker results; model proposals checked and executed by application code with observations and final outcomes; planning, restricted code, retrieval recovery, and a shared MCP protocol interface; and checked handoffs with distinct memory roles, retrieval eligibility, and deletion cleanup. Hosts and clients appear on one side of the MCP format group and MCP servers on the other, linked by gray compatibility spokes. The panels are design choices without a mandatory progression.
Figure 1: The four chapters group workflow controls, agent actions, planning and tool connections, and memory rules by responsibility. Gray MCP spokes show compatibility with shared protocol messages, not a central deployed server or a runtime call graph.

Chapters in this part