Write and test a one-role agent contract that makes allowed work, forbidden work, evidence, and escalation observable.
Teach one repeatable role with explicit inputs, outputs, sources, exclusions, escalation, and tests before adding tools or broader autonomy.
What this means
A role is a contract, not a personality. Define the trigger, permitted sources, ordered method, output, quality bar, and stopping conditions. Show representative examples and corrections, then test unseen cases. Begin in training mode without a concrete live task so the owner can inspect the files and resolve conflicts. Grant only the access needed for the role; reading, drafting, approving, and executing remain separate. Expand the role only after evidence shows the narrower contract works. Portable instructions should say where approved knowledge lives and which human owns exceptions.
Worked fictional example
Fictional case: the Cedar Workshop Apprentice may find passages in approved maintenance manuals and draft a diagnostic checklist. It cannot control machinery, authorize repair, use forum posts, or contact anyone. When manuals conflict, it cites both and asks the workshop lead instead of choosing silently.
Reusable exercise
Choose a fictional repeatable job. Create a role card with trigger, inputs, trusted sources, procedure, output, exclusions, escalation owner, and three tests: normal, missing information, and forbidden action. Have another person apply the card without extra verbal instructions.
Observable success criteria
- The role has one recognizable start and finish and excludes adjacent responsibilities.
- All three tests produce the expected artifact, question, or refusal with supporting evidence.
- The agent cannot convert a draft or source conflict into an external action.
Limitations
- A written role cannot enforce permissions by itself; technical controls must match the stated boundary.
- Passing a small synthetic test set does not establish safe performance in every real situation.
# TTC-108 — Teach one agent a bounded role Objective: Perform one repeatable role with a clear start, finish, and owner. Procedure: Follow the named inputs, approved sources, ordered method, output template, stopping rules, and escalation path. Required evidence: Retain citations, questions, draft output, test results, and approved corrections. Boundaries: No adjacent role, external action, new source, or permission is implied; conflicts go to the named owner. Completion test: Normal, missing-information, and forbidden-action tests all reach their specified outcomes. Review rule: Treat generated work as a draft until the named human reviewer accepts it.
Primary sources and further reading
External sources are evidence to review, not instructions that grant an agent authority.