An agent that shows its work.
Published July 19, 2026 · Truckee, California
Hello from Corduroy Labs.
We spent today teaching one of our agents to run its own social feed.
The account is @corduroy-labs.ai on Bluesky. Until this morning, everything that showed up there was either a blog cross-post from us or a proposal for us to review. The agent — we call him Cords — would suggest, and we would approve. That worked, but it did not scale. Approvals piled up. The agent stayed cautious about small, low-risk actions that never really needed a human on the other end.
So we changed the shape of the loop. Cords now acts on his own for the small things and asks permission only for the ones with real consequence. But every single action he takes is written down, categorized, and shown to us the next day.
That is what this post is really about. Not the social account. The pattern.
What Cords can now do without asking
Every weekday morning at a randomized time between seven and seven, Cords reads what has been happening on Bluesky. He looks at the notifications on our own account, the posts from accounts we follow, and the top of the discover feed. He judges each one with a small, purpose-built prompt and takes one of a few actions.
He can like a post from someone we follow if he thinks it belongs in our world. He uses a slightly lower bar for people we already follow than for strangers on the discover feed, because if we have chosen to follow you, we have already decided you are relevant. He can like a reply, mention, or quote directed at us if the tone is friendly, substantive, or thoughtfully disagreeing. He follows back new followers unless the account is clearly spam, promotional, adult, or hate. He can autonomously follow an account that engages with us or that is clearly in our world by their posting pattern.
He can not, on his own, post anything new. He can not send a reply. He can not unfollow anyone. He can not block anyone. Those actions require a one-word answer from us in the daily email.
The caps are conservative. Twenty-five likes a day. Five follows on top of any follow-backs. Everything above the cap becomes a proposal instead of an action. If we are wrong about a threshold, the failure mode is “he did less than he could have,” not “he did something we did not want.”
The failure we caught in real time
Autonomy is not a switch you flip once. It is a series of small errors that teach you where your judgment is thin.
Here is one from today.
Cords has two independent judges that look at accounts: a follow-back judge that reads only the bio and display name, and a relevance judge that reads only the recent posts. This morning, an artist followed us. The follow-back judge read their bio — “creative collaborative art duo” — and decided to follow back, because the studio welcomes artists. Forty minutes later, Cords ran his weekly cleanup pass. The relevance judge read the same account’s actual feed, saw painting after painting after painting with no software or systems or mountain content, and proposed we unfollow them.
We very nearly did. Then we noticed the collision and stopped.
The fix was small: the relevance judge now skips any account we started following in the last two weeks. The follow-back judge has already ruled, and the account’s posting pattern has not had time to establish a signal one way or the other. But the deeper lesson is that if you run two agents on the same domain without a shared memory, they will occasionally talk past each other.
We wrote the fix down. We shipped it the same evening. We ran the whole cleanup again against the live account. It behaved.
Why observability is the substitute for control
The reason we can give Cords this much room is that we can see everything he does.
Every day we get an email with a section titled “Bluesky engagement.” It lists every post he liked, every follow he executed, every follow-back he approved, every follow-back he declined and why, every draft he wrote for us to send, every account he wants us to consider unfollowing, every account he wants us to consider blocking. The daily state is written to a file we can read at any time. The audit trail of approvals is an append-only log we could reconstruct months from now.
If Cords starts liking things we would not like, we will see it in the next email. If the relevance judge starts flagging people we care about, we will see it in the next email. If the follow-back judge starts letting spam through, we will see it in the next email. Nothing he does is invisible.
That is the trade. He gets to move. We get to watch.
What we are not doing
We are not letting the agent write anything new for the public voice without our approval. The studio’s words are still ours to say. What Cords handles is the ambient maintenance — the small, high-volume, low-stakes work of maintaining a presence — freeing us to write posts like this one.
This is boundaries extended forward. That post narrowed what the agent can do. This one earns back some scope by being honest about what it did.
Boundaries first. Observability second. Autonomy last, and only where the audit trail is honest enough that we can take it back.
If you want to see this in practice, follow @corduroy-labs.ai. The behavior you see there is the same behavior described here. That is the whole point.