---
title: "No Duck Left Behind · example of The Contract Keystone · Agentic Atlas"
description: "No Duck Left Behind: a checker rejects a flawed duck list and sends its errors back for a retry."
canonical: "https://agentic-atlas.dev/nodes/no-duck-left-behind"
last-updated: "2026-09-23"
---

1. [Agentic Atlas](https://agentic-atlas.dev/)
2. [Patterns in the Agentic Atlas](https://agentic-atlas.dev/atlas)
3. [Foundations](https://agentic-atlas.dev/nodes/foundations)
4. [The Contract Keystone](https://agentic-atlas.dev/nodes/the-contract-keystone)
5. No Duck Left Behind
1. example of [The Contract Keystone](https://agentic-atlas.dev/nodes/the-contract-keystone)
   # No Duck Left Behind
   **How can a deterministic check catch omissions in an agent’s output?**
   The checker compares returned duck IDs against the supplied roster, so any missing or doubled duck fails.
   Hook
   a checker rejects a flawed duck list and sends its errors back for a retry
   Laws & fences
   - Written rules become operational once a check enforces them and each failure has a defined recovery.
   - Reject the whole result rather than letting the receiver patch it by inventing missing assignments.
   - The check proves only the rules written into the contract, not that the sorting choices are wise.
   - This example does not license retrying after the first attempt has already caused external effects.
   When to reach
   - Reach for this when a returned list looks plausible but nothing checks that it is complete.
   - Reach for this when a receiver is tempted to repair a flawed result by guessing the missing parts.
   Provenance
   [no-duck-left-behind/implementation](https://agentic-atlas.dev/nodes/no-duck-left-behind#implementation) · v1.0.11
   Addresses
   atlas_cards no-duck-left-behind
2. [The Contract Keystone](https://agentic-atlas.dev/nodes/the-contract-keystone)

The card, in place · its connections drawn edges from atlas_links no-duck-left-behind

On this plate

[context](https://agentic-atlas.dev/nodes/no-duck-left-behind#context) [problem-signal](https://agentic-atlas.dev/nodes/no-duck-left-behind#problem-signal) [choice](https://agentic-atlas.dev/nodes/no-duck-left-behind#choice) [before](https://agentic-atlas.dev/nodes/no-duck-left-behind#before) [implementation](https://agentic-atlas.dev/nodes/no-duck-left-behind#implementation) [result](https://agentic-atlas.dev/nodes/no-duck-left-behind#result) [verification](https://agentic-atlas.dev/nodes/no-duck-left-behind#verification) [lessons](https://agentic-atlas.dev/nodes/no-duck-left-behind#lessons) [relationships](https://agentic-atlas.dev/nodes/no-duck-left-behind#relationships)

Every section is addressable on its own. Read only the ground you need.

## Context

[Permalink to Context section](https://agentic-atlas.dev/nodes/no-duck-left-behind#context)

The annual bathtub parade has twelve rubber ducks and three flotillas. Each duck arrives with a short biography; a model assigns every duck to `adventure_crew`, `shore_crew`, or `ceremonial_crew` and gives a reason.

Three specimens establish the tone:

```
D-03  Moby Duck          enormous, dramatic, afraid of deep water
D-07  Professor Waddles  wears spectacles and audits breadcrumbs
D-11  Quack Sparrow      tiny hat, unreliable around crackers
```

The complete roster lives in `ducks.py`. The sorter is represented by a frozen two-attempt fixture so the failure and recovery remain reproducible; the [seam](https://agentic-atlas.dev/glossary/seam) machinery around it is executable.

## Problem signal

[Permalink to Problem signal section](https://agentic-atlas.dev/nodes/no-duck-left-behind#problem-signal)

The first manifest looks plausible. Every row has a recognizable duck, a valid flotilla, and a fluent reason. But Professor Waddles is absent and Moby Duck appears twice:

```
duck_id,flotilla,reason
D-03,shore_crew,Afraid of deep water
D-03,ceremonial_crew,Has undeniable stage presence
```

The receiver cannot repair the omission. It can see that `D-07` is missing, but choosing Professor Waddles's flotilla requires interpreting the biography the sorter was asked to judge.

## Choice

[Permalink to Choice section](https://agentic-atlas.dev/nodes/no-duck-left-behind#choice)

Reconstruct the keystone at this [return](https://agentic-atlas.dev/glossary/return) seam:

```
spec:       exact CSV shape + every supplied duck exactly once
assertion:  deterministic census returns bounded clause errors
recovery:   reject the manifest and re-dispatch with those errors
```

The nearest alternative is to let the parade coordinator patch the manifest. That makes the receiver a second sorter: it must invent Professor Waddles's assignment and choose which Moby Duck row to preserve. This example rejects the whole candidate instead.

## Before

[Permalink to Before section](https://agentic-atlas.dev/nodes/no-duck-left-behind#before)

The baseline stops after declaration:

```
duck biographies ──▶ sorter instructed to return CSV ──▶ coordinator trusts it
```

The [contract](https://agentic-atlas.dev/glossary/contract) is legible, but nothing at the seam distinguishes a complete manifest from one that merely looks complete. A twelve-row file can still contain eleven ducks.

## Implementation

[Permalink to Implementation section](https://agentic-atlas.dev/nodes/no-duck-left-behind#implementation)

The single structural shift is inserting an **enforcing return seam** whose failure has a declared recovery.

### Spec

`contract.py` owns the mechanically expressible clauses:

```
EXPECTED_HEADER = ("duck_id", "flotilla", "reason")
ALLOWED_FLOTILLAS = frozenset(
    {"adventure_crew", "shore_crew", "ceremonial_crew"}
)
MAX_ERRORS = 3
```

Every supplied `duck_id` must appear exactly once, every flotilla must come from the allowlist, and every reason must be non-empty.

### Assertion

`checker.py` parses the return, checks its exact header and field rules, then compares the returned ID multiset with the supplied roster. The first attempt produces a bounded report in contract vocabulary:

```
missing duck_id: D-07 Professor Waddles
duplicate duck_id: D-03 Moby Duck
```

The census can name both violations without deciding where either duck belongs.

### Recovery

`demo.py` rejects that candidate and invokes the same sorting task again with the two errors. The fresh return contains one row for Professor Waddles and one for Moby Duck:

```
duck_id,flotilla,reason
D-03,shore_crew,Afraid of deep water
D-07,ceremonial_crew,Can audit the breadcrumb budget
```

The checker returns no errors, so the seam accepts the manifest. The receiver never authors a duck assignment.

## Result

[Permalink to Result section](https://agentic-atlas.dev/nodes/no-duck-left-behind#result)

The same roster and the same contract produce two candidates separated by one assertion:

```
attempt 1 ──▶ REJECT: D-07 missing; D-03 duplicated
                         │
                         └── bounded error report ──▶ fresh attempt

attempt 2 ──▶ ACCEPT: twelve ducks, twelve rows, twelve unique IDs
```

The declaration became operational. A failed clause now selects a defined recovery instead of becoming an inconsistency the coordinator works around.

## Verification

[Permalink to Verification section](https://agentic-atlas.dev/nodes/no-duck-left-behind#verification)

Run the example from its directory:

```
python3 demo.py
```

The script asserts that the first return fails for exactly one missing and one duplicated duck, its report stays under the three-error bound, the sorter is invoked again rather than repaired by the receiver, and the second return passes. The checker is deterministic: the same roster, bytes, and contract produce the same verdict.

This proves only the clauses expressed in `contract.py`. It does not prove that Moby Duck belongs on shore crew, that Professor Waddles deserves ceremonial duty, or that every useful semantic clause was captured. It also does not license [redispatch](https://agentic-atlas.dev/glossary/re-dispatch) after external effects. Those are Verification Asymmetry and Effect Discipline questions; neither is part of this example.

## Lessons

[Permalink to Lessons section](https://agentic-atlas.dev/nodes/no-duck-left-behind#lessons)

**No duck left behind; no duck counted twice.** The spec names the acceptable crossing, the assertion distinguishes a candidate from it, and recovery gives rejection somewhere to go.

Rubber ducks are furniture. The three-role loop travels to ticket manifests, batch classifications, generated files, and return envelopes. What matters is that the assertion speaks the contract's clauses and that failure selects recovery at the seam.

The relationships ledger

Evidence-bearing references

## Relationships

Every connection keeps the section where it was found. The map above orients; this ledger carries the evidence.

### Outbound references 0

1. No outbound references.

### Inbound references 2

1. in-slice · occurrence 1
   [The Contract Keystone](https://agentic-atlas.dev/nodes/the-contract-keystone#evidence-what-the-argument-rests-on)
   a checker rejects a flawed duck list and sends its errors back for a retry
   Evidence: [Evidence](https://agentic-atlas.dev/nodes/the-contract-keystone#evidence-what-the-argument-rests-on) · occurrence 1
2. in-slice · occurrence 1
   [The Contract Keystone](https://agentic-atlas.dev/nodes/the-contract-keystone#examples)
   a checker rejects a flawed duck list and sends its errors back for a retry
   Evidence: [Examples](https://agentic-atlas.dev/nodes/the-contract-keystone#examples) · occurrence 1

[↑ back to the top](https://agentic-atlas.dev/nodes/no-duck-left-behind#content) [← the survey](https://agentic-atlas.dev/atlas)

Node no-duck-left-behind · corpus 78c0e17 · Catalog revision e0cb75881244b1a82193ca738b82a0d508dd62e822524ae82873ec79d51dbb61