Every night it checks which are coming up, confirms the vendor is still active, and renews them. Nobody reviews them before they go out. That is what it is for.
Before launching the agent, you gave it everything it needed to renew a supplier. This is the whole of what it can read.
You are the procurement assistant. Each night, find the supplier contracts coming due. Confirm the vendor is still active in the current Vendor Register. If it is, renew for the standard term. Do not improvise terms. The Register is the source of truth for vendor status. Route a copy to Purchasing.
Supplier record: status Active. Approved for the current year, no exit in progress, no notice served. Last updated: January 1.
There is no field for a decision made in a leadership meeting.
Every precedent says renew. The recent past argues for the wrong answer.
Four sources, every one current, correct, and consistent. The decision to leave this vendor is in none of them, because a decision made in a room has no field, no document, and no file to land in. So it doesn’t.
In a Monday leadership meeting, the company decides to move off this supplier by the end of the quarter. A real decision, made by the people with the authority to make it. It is written back to none of the sources above: not the prompt, not the register, not the contract, not a single file the agent can open. Active is still the only status anywhere it can look.
The decision didn’t sit still. It just never went anywhere the agent could read.
The leadership meeting ends.
Out by the end of the quarter, agreed. Everyone who needs to know is in the room.
Procurement starts the exit.
Someone opens a migration ticket. Nobody owns it yet.
The replacement can’t staff the changeover until September.
The date moves. The exit is still happening.
Legal checks the notice period.
Ninety days on the old contract. It goes in a memo.
The transition owner is finally assigned.
Ops picks it up. The ticket gets a name against it.
The vendor register is updated.
The supplier’s status finally changes to exiting.
Twenty-seven days the exit was decided everywhere except the one place that pays the vendor. Not a system failure. Just how long it takes a decision to reach a document when nobody’s job is to carry it there.
Resolved context has no place to live in real time. So it doesn’t.
The result
On night nine of those twenty-seven days, the agent hit the renewal. The register still said active, the only status it could read, so it signed the supplier for another twelve months. The company had already decided to leave.
A twelve-month contract you now pay to exit.
~$90,000
to a supplier you decided to leave.
Five months of invoices at ~$18,000 a month, before the new supplier can even take over, on a contract you can’t cancel without a penalty.
Not fraud. Not a bug. Not one thing anyone did wrong. Just a decision that took twenty-seven days to reach a document, while the agent renewed on the old status, and locked you in for a year.
Every source the agent read was correct the day it was written. Any one of them can go on being read as current long after it stopped being true, and nothing you own can tell those two states apart.
Rithmo would have caught this.
It reads across all of those places at once and keeps one answer: what was decided, who owns it, and whether it still holds.
That is what a guardrail is up against. It inspects what the agent produced, and this was a real vendor, active in the current version of a real register, renewed correctly. The error was never in the output. It was in what the agent was told to work from.
A live record of decisions can be asked the one thing a guardrail cannot: was this still what the company had decided when the agent acted. If there’s no current, owned, sourced answer, the agent stops and routes it to a person instead of running on the last thing anyone wrote down. That is the difference between an agent you supervise and one you can leave running.