A numbered list does not own control flow.
A prompt can say "do step one, then step two." The same model reads the list, performs the work, and decides whether the work is done. The sequence has no separate authority.
Stepgate 0.1.3 attacks that weak point with stepfiles. Its MCP server reveals one step at a time. A submission moves forward only after its output schema and configured gates pass. The documented gate types include JSON Schema, JSONLogic, and HTTP verifiers.[1]
Instructions describe the route. An interlock controls the route.
The useful boundary is outside the model.
Stepgate makes declared remote calls on the agent's behalf. It checks the operation schema, refuses undeclared hosts, and keeps credentials in the server process. Evidence gates can compare submitted output with the API results captured during that step.[2]
That is narrower than "the agent is reliable." The model still writes variable output. The server can control what step is visible, which call is allowed, what shape must return, and whether a mechanical check passes. It cannot make an open-ended judgment correct.
Validation belongs where policy becomes behavior.
GitHub's validator for Copilot enterprise managed settings finds malformed JSON, unsupported configuration, and invalid team mappings. It reports the affected file and JSON path. After a correction is committed to the default branch, the operator reloads the Agents page and checks the validator again.[3]
The detail worth stealing is the stop point. A policy file is not treated as active policy merely because it exists. The system checks the configuration at the point where it will govern clients.
Keep review before irreversible motion.
JetBrains describes a Kotlin Multiplatform onboarding flow that mapped ten steps before the team designed screens. The plugin generates four delivery files, shows them for review while they remain local and uncommitted, then runs the first build remotely. The developer commits the configuration only after that build works.[4]
This is a good sequence because each stage earns the next one. Generated files are visible before execution. A remote build produces evidence before repository adoption. The final commit remains a human action.
A ledger is a witness, not a replay.
Stepgate's ledger hash-chains records for starts, calls, submissions, gates, retries, and outcomes. The records keep hashes and lengths for bodies and outputs rather than the bodies themselves. Its verifier can detect a broken chain.[2]
That supports tamper detection for the recorded sequence. It does not reconstruct every response or prove that an external API still behaves the same way. If replay matters, retain the approved inputs and evidence under a separate storage policy.