Pimp My IDE / Garage dispatch
Back to garage
September 27, 2026 | agents / runbooks / enforcement

A runbook is advice until the next step can stay locked.

Ordered prose can tell an agent what to do. It cannot prove which route the agent took, block an invalid output, or keep a credential away from the model.

The take. Put sequence, checks, retries, and records outside the model. Keep judgment with the agent. Give permission to machinery that can refuse bad state.

A numbered list does not own control flow.

A prompt can say "do step one, then step two." The same model reads the list, performs the work, and decides whether the work is done. The sequence has no separate authority.

Stepgate 0.1.3 attacks that weak point with stepfiles. Its MCP server reveals one step at a time. A submission moves forward only after its output schema and configured gates pass. The documented gate types include JSON Schema, JSONLogic, and HTTP verifiers.[1]

Instructions describe the route. An interlock controls the route.

The useful boundary is outside the model.

Stepgate makes declared remote calls on the agent's behalf. It checks the operation schema, refuses undeclared hosts, and keeps credentials in the server process. Evidence gates can compare submitted output with the API results captured during that step.[2]

That is narrower than "the agent is reliable." The model still writes variable output. The server can control what step is visible, which call is allowed, what shape must return, and whether a mechanical check passes. It cannot make an open-ended judgment correct.

Validation belongs where policy becomes behavior.

GitHub's validator for Copilot enterprise managed settings finds malformed JSON, unsupported configuration, and invalid team mappings. It reports the affected file and JSON path. After a correction is committed to the default branch, the operator reloads the Agents page and checks the validator again.[3]

The detail worth stealing is the stop point. A policy file is not treated as active policy merely because it exists. The system checks the configuration at the point where it will govern clients.

Keep review before irreversible motion.

JetBrains describes a Kotlin Multiplatform onboarding flow that mapped ten steps before the team designed screens. The plugin generates four delivery files, shows them for review while they remain local and uncommitted, then runs the first build remotely. The developer commits the configuration only after that build works.[4]

This is a good sequence because each stage earns the next one. Generated files are visible before execution. A remote build produces evidence before repository adoption. The final commit remains a human action.

A ledger is a witness, not a replay.

Stepgate's ledger hash-chains records for starts, calls, submissions, gates, retries, and outcomes. The records keep hashes and lengths for bodies and outputs rather than the bodies themselves. Its verifier can detect a broken chain.[2]

That supports tamper detection for the recorded sequence. It does not reconstruct every response or prove that an external API still behaves the same way. If replay matters, retain the approved inputs and evidence under a separate storage policy.

Interactive makeover / sequence control

Runbook pawl bench

Traditional purpose replaced: tick a checklist and trust the same actor to declare completion. Better version: select four enforceable clauses, see where the route stops, and copy a review card that keeps missing runtime evidence visible.

Set the four pawls

Each checkbox selects one clause for a procedure template. The shaft advances only through a contiguous prefix. A later clause cannot cover a missing earlier one.

Runbook control clauses

No clause is selected. The procedure route is open at Context.

Procedure review card0 / 4 SELECTED

Copy the lock specification

This card defines what an implementation must enforce. It does not run a stepfile or attach a ledger.

What completion means. Four selected clauses produce TEMPLATE STRUCTURE READY. Real readiness still needs an implementation, procedure hash, tests, ledger location, and human-stop rule.

Sources and limits

Open the source log
  1. Stepgate repository and README, read September 27, 2026. The repository describes ordered stepfiles, gates, credential handling, and hash-chained ledgers. The npm registry reported version 0.1.3. The garage ran npx -y stepgate --list and received the bundled catalog.
  2. Stepgate, "How Stepgate works", read September 27, 2026. It documents current-step disclosure, call routing, evidence, retry rules, egress checks, ledger contents, and stated limits.
  3. GitHub Changelog, "Enterprise managed settings in-product validator", published September 25 and read September 27, 2026. It documents the validator's checks and correction flow.
  4. JetBrains, "Designing the Kotlin Multiplatform and TeamCity Integration", published September 24 and read September 27, 2026. It documents the ten-step design map, local review of generated files, remote first build, and developer-controlled commit.
  5. Hacker News discussion for Stepgate, item ID verified through the Hacker News API on September 27, 2026. The thread had no comments when read, so it is a discovery route rather than supporting evidence.

Source boundary. Stepgate's architecture and guarantees are project claims checked against its documentation, package metadata, CLI catalog, and public source tree. The garage did not run a credentialed end-to-end stepfile. The pawl bench is a teaching control. It drafts a review structure and does not enforce an agent run.