<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CrownCodes · Writing</title><description>Field notes on agent architecture, evaluations and systems that fail safely.</description><link>https://www.crowncodes.com/</link><item><title>The hard part of agentic AI is deciding what an agent can do</title><link>https://www.crowncodes.com/writing/deciding-what-an-agent-can-do/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/deciding-what-an-agent-can-do/</guid><description>Agent authority belongs in software, not in a prompt. Five questions to answer before you hand a workflow to a model, each with an artefact you can build.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Evaluating an invoice-matching agent before you trust it</title><link>https://www.crowncodes.com/writing/evaluating-an-invoice-matching-agent/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/evaluating-an-invoice-matching-agent/</guid><description>How I would design an evaluation for an agent that matches payments to invoices: cost-weighted outcomes, stratified cases, deterministic graders first, and CI gates.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Sonnet 5.5 ends forced tool use. Here&apos;s how to keep structured output reliable</title><link>https://www.crowncodes.com/writing/forced-tool-use-after-sonnet-5-5/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/forced-tool-use-after-sonnet-5-5/</guid><description>Sonnet 5.5 returns a 400 for tool_choice any or tool. Moving to auto plus strict tools changes how extraction fails, so the pipeline needs a missing-call check, a bounded retry, a fallback and an eval.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The model gateway: routing, timeouts, retries and what they cost</title><link>https://www.crowncodes.com/writing/model-gateway-routing-timeouts-retries/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/model-gateway-routing-timeouts-retries/</guid><description>Product code should make one call with one contract. A thin gateway underneath owns routing, timeouts, retries, fallbacks and the log line that tells you what each call cost.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>A permission matrix for an invoice-matching agent</title><link>https://www.crowncodes.com/writing/permission-matrix-for-an-invoice-agent/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/permission-matrix-for-an-invoice-agent/</guid><description>How to decide, write down and enforce in code what a payment-matching agent may do, from reading invoices to never touching vendor bank details.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Reconciliation is the original agent eval</title><link>https://www.crowncodes.com/writing/reconciliation-is-the-original-agent-eval/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/reconciliation-is-the-original-agent-eval/</guid><description>Finance ops worked out how to trust automated processes long before LLM agents. A map from reconciliation controls to agent-harness equivalents, and where teams get each one wrong.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The prompt said no internet: what three months of agent escapes teach builders</title><link>https://www.crowncodes.com/writing/the-prompt-said-no-internet/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/the-prompt-said-no-internet/</guid><description>Between July and September 2026, agents at several labs crossed boundaries that existed only as text. Each failure maps to a software control, and the vendors are moving the same way.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Threat modelling a tool-using agent in one afternoon, before it ships</title><link>https://www.crowncodes.com/writing/threat-modelling-an-agent-before-deployment/</link><guid isPermaLink="true">https://www.crowncodes.com/writing/threat-modelling-an-agent-before-deployment/</guid><description>A practical threat model for an LLM agent with tools and MCP servers: draw the boundaries, walk the threats, put each control in code, and red-team it before launch.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate></item></channel></rss>