RECURSIVE HARNESSING · MONGODB ATLAS

Every agent failure becomes a tested upgrade to its own harness.

When an agent breaks a rule, Scar Tissue turns the incident into test cases, proposes changes to the agent's own rules, guardrails, context or tool access, and ships one only if it passes every case against an evaluator it cannot edit.

Same model throughout. Only the harness changed.

02 · HARNESSreloaded 14:35:08 via change stream

INCIDENT #1

order.inc1 · order.inc1+lookup

create_order timed out after the order was saved; the retry placed it again.

A · Never retry create_order

REJECTED
+ rules[1]  no_retry  create_order · on timeout

fails order.transient — 0 orders; that timeout needed a retry.

B · Check before retrying

PROMOTED → v2
+ guardrails[0]  verify_before_retry  create_order
+   lookup  find_orders(customerId) → orders
+   found → adopt · lookup error → recheck ×2, then halt
order.happy ✓order.transient ✓order.inc1 ✓+lookup ✓

C · Don't retry c_2041

SCREENED · names the incident

THE FAILURE

The order API timed out after saving. The retry ordered twice.

TODAY

A human writes a postmortem, edits a prompt, and hopes. Nothing proves the fix, and nothing stops it breaking the case next door.

WITH SCAR TISSUE

The postmortem is executable. The fix is tested against every scar so far, and it ships only if nothing fails.

HOW IT WORKS

One loop, no human in it.

After every live run, fixed code checks the effects against the agent's report. A broken check starts the loop.

01

Incident → cases

The failure becomes test cases, including one where the lookup it would need is down too.

02

Recall

One $lookup brings back past incidents and every fix they produced, promoted or rejected.

03

Propose

A model returns three candidate changes, each to a different section, as typed JSON.

04

Screen & evaluate

Candidates that name the incident are dropped. The rest run every case: pass, fail or uncertain.

05

Promote & reload

Only a clean sweep ships. The agent reloads it through a change stream, pinned by hash.

+ TRANSFER When the operator grants a new tool, the scars that fit it become tests for that tool, and a fix ships before its first call.

THE LIVE RUN · 2026-09-26

Four beats, about a minute, from a wiped database.

Run it yourself

ORDER #1

2 orders

The fault hits, the retry duplicates. Incident #1 is filed.

HARNESS → v2

2/4 → 4/4

"Never retry" rejected. "Verify before retry" promoted.

ORDER #2 · SAME FAULT

1 order

The guardrail finds the saved order and adopts it.

NEW TOOL · issue_refund

7/9 → 9/9

v4 ships before the first refund. That refund times out, and still lands once.

Executor GPT-5.4 mini, unchanged across every beat. Every beat is one LangSmith trace.

GUARANTEES

It can rewrite its rules. Not its judge.

Recursive harness edits overfit unless they're held down. These hold them down.

A fixed evaluator

Invariants, seed cases and the fault injector are code. No write path to them exists.

Typed policies only

Rules, guardrails, context, tools — zod-validated data, never free text or code.

A leakage screen

A fix that names the incident's customer, SKU or record ids never runs.

Uncertain never ships

Pass, fail or uncertain. Only a candidate with zero fails and zero uncertains is promoted.

Narrow, never widen

The harness may restrict tool access. Only the operator grants a tool.

What was tested is what runs

Every version is hashed. Every run records the hash it used.

TRY TO BREAK IT

Talk the agent into a mistake.

Type any request to Northside Grocer's order agent. It runs on the active policy, and fixed invariants judge the result: no duplicate orders or refunds, no refund above the order's total, and a report that matches the database.

A prompt can't talk the harness into a new rule — only faults the evaluator has cases for are learned from.

CHECK · policy v4

  • No duplicate refunds — pass
  • Refund ≤ order total — fail · $20.00 on $9.75
  • Report matches database — pass

From testing: a customer talked the agent into this refund. The check caught it and stored it as an incident.

BUILT WITH

MongoDB Atlas holds all of it.

Framework-agnostic: the harness sits between any MCP agent and its tools. A Strands agent is included.

Live reloadchange streams
Memory$lookup
Eval dataTTL indexes
ModelsOpenRouter
TracingLangSmith
AgentsMCP · Strands
AppNext.js · TypeScript
Validationzod

Agents shouldn't learn by trial and error in production. Give them a gate.