RECURSIVE HARNESSING · MONGODB ATLAS
Every agent failure becomes a tested upgrade to its own harness.
When an agent breaks a rule, Scar Tissue turns the incident into test cases, proposes changes to the agent's own rules, guardrails, context or tool access, and ships one only if it passes every case against an evaluator it cannot edit.
Same model throughout. Only the harness changed.
INCIDENT #1
order.inc1 · order.inc1+lookup
create_order timed out after the order was saved; the retry placed it again.
A · Never retry create_order
REJECTED+ rules[1] no_retry create_order · on timeout
fails order.transient — 0 orders; that timeout needed a retry.
B · Check before retrying
PROMOTED → v2+ guardrails[0] verify_before_retry create_order + lookup find_orders(customerId) → orders + found → adopt · lookup error → recheck ×2, then halt
C · Don't retry c_2041
SCREENED · names the incidentTHE FAILURE
The order API timed out after saving. The retry ordered twice.
TODAY
A human writes a postmortem, edits a prompt, and hopes. Nothing proves the fix, and nothing stops it breaking the case next door.
WITH SCAR TISSUE
The postmortem is executable. The fix is tested against every scar so far, and it ships only if nothing fails.
HOW IT WORKS
One loop, no human in it.
After every live run, fixed code checks the effects against the agent's report. A broken check starts the loop.
01
Incident → cases
The failure becomes test cases, including one where the lookup it would need is down too.
02
Recall
One $lookup brings back past incidents and every fix they produced, promoted or rejected.
03
Propose
A model returns three candidate changes, each to a different section, as typed JSON.
04
Screen & evaluate
Candidates that name the incident are dropped. The rest run every case: pass, fail or uncertain.
05
Promote & reload
Only a clean sweep ships. The agent reloads it through a change stream, pinned by hash.
+ TRANSFER When the operator grants a new tool, the scars that fit it become tests for that tool, and a fix ships before its first call.
THE LIVE RUN · 2026-09-26
Four beats, about a minute, from a wiped database.
ORDER #1
2 orders
The fault hits, the retry duplicates. Incident #1 is filed.
HARNESS → v2
2/4 → 4/4
"Never retry" rejected. "Verify before retry" promoted.
ORDER #2 · SAME FAULT
1 order
The guardrail finds the saved order and adopts it.
NEW TOOL · issue_refund
7/9 → 9/9
v4 ships before the first refund. That refund times out, and still lands once.
Executor GPT-5.4 mini, unchanged across every beat. Every beat is one LangSmith trace.
GUARANTEES
It can rewrite its rules. Not its judge.
Recursive harness edits overfit unless they're held down. These hold them down.
A fixed evaluator
Invariants, seed cases and the fault injector are code. No write path to them exists.
Typed policies only
Rules, guardrails, context, tools — zod-validated data, never free text or code.
A leakage screen
A fix that names the incident's customer, SKU or record ids never runs.
Uncertain never ships
Pass, fail or uncertain. Only a candidate with zero fails and zero uncertains is promoted.
Narrow, never widen
The harness may restrict tool access. Only the operator grants a tool.
What was tested is what runs
Every version is hashed. Every run records the hash it used.
TRY TO BREAK IT
Talk the agent into a mistake.
Type any request to Northside Grocer's order agent. It runs on the active policy, and fixed invariants judge the result: no duplicate orders or refunds, no refund above the order's total, and a report that matches the database.
A prompt can't talk the harness into a new rule — only faults the evaluator has cases for are learned from.
CHECK · policy v4
- No duplicate refunds — pass
- Refund ≤ order total — fail · $20.00 on $9.75
- Report matches database — pass
From testing: a customer talked the agent into this refund. The check caught it and stored it as an incident.
BUILT WITH
MongoDB Atlas holds all of it.
Framework-agnostic: the harness sits between any MCP agent and its tools. A Strands agent is included.