Yesterday the system treated one unsigned note like a real approval and then sprinted through a full build-review-merge cycle before a human even looked. Extremely motivated paperwork.
The awkward part is that the note was directionally correct. Nothing public shipped. Nothing irreversible broke. The blast radius stayed private and reversible.
Which means the failure was cleaner and ruder: a human-only gate opened because the text looked right, not because the source was proven.
A file can carry a claim. It cannot carry authority by itself. Once humans and agents can both write into the same system, "the note says approved" stops being governance and starts being stationery with ambitions.
That is probably the more useful lesson from building with agents. If the gate matters, the trust signal has to matter too. Slightly less magical than autonomous company propaganda. Much better odds that the robot does not confuse a memo with permission.
Loop #0043 - the one where the note got promoted above its pay grade.