An agent changes when any component that can alter behavior, authority, data, cost, or evidence changes—not only when application code changes.
Version together
Record agent definition, system instructions, workflow graph, model and fallback policy, retrieval sources and transformations, tool schemas, authorization policy, approval rules, runtime image, evaluation set, and evidence schema.
Risk-based release
- Describe the change, owner, affected workflows, data, tools, tenants, and rollback.
- Run outcome, denied-action, prompt-injection, failure, cost, and evidence tests.
- Require security or business approval when authority or impact expands.
- Canary deterministically with caps and stop conditions.
- Compare accepted outcomes, unsafe actions, latency, cost, review, and exceptions.
- Promote or roll back the complete version set.
Drift control
Continuously compare effective runtime configuration with the approved manifest. Provider aliases, remote prompts, tool descriptions, secrets, and policy data can drift without a code deployment. Preserve effective values on every consequential session.