---
title: "The Contract Keystone · concept · Agentic Atlas"
description: "The Contract Keystone: how contracts, cheap checks, and safe discards together make agent handoffs safe."
canonical: "https://agentic-atlas.dev/nodes/the-contract-keystone"
last-updated: "2026-09-23"
---

1. [Agentic Atlas](https://agentic-atlas.dev/)
2. [Patterns in the Agentic Atlas](https://agentic-atlas.dev/atlas)
3. [Foundations](https://agentic-atlas.dev/nodes/foundations)
4. The Contract Keystone

Seen working in [No Duck Left Behind](https://agentic-atlas.dev/nodes/no-duck-left-behind).

1. concept
   # The Contract Keystone
   **What makes it safe to check an agent’s result and re-run it?**
   Contract, check, and recovery are one move: the contract states the expectation, the check tests each return, and a failed check opens a recovery.
   Hook
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Laws & fences
   - A model can read a clear contract and still return off-spec work, so unchecked boundaries are only aspirational.
   - Each handoff is checked as rigorously as its stakes warrant.
   - Without a clear expectation, you cannot tell good output from bad, so you cannot safely re-run.
   - A checked handoff is safe only with a contract, checks easier and more reliable than the work, and runs safe to discard.
   - Only mechanically enforced clauses become guarantees, while the other clauses gain measured assurance.
   - Re-running after a failed check is one recovery option, not proof that the handoff is safe.
   When to reach
   - Reach for this when you already verify a sub-agent's output and re-run it when it looks wrong.
   - Reach for this when splitting work across agents and deciding what each handoff must check.
   Provenance
   [the-contract-keystone/model-and-claims-one-move-three-names](https://agentic-atlas.dev/nodes/the-contract-keystone#model-and-claims-one-move-three-names) · v1.0.11
   Addresses
   atlas_cards the-contract-keystone
2. [The Contract](https://agentic-atlas.dev/nodes/contract-documentation)
3. [Verification Asymmetry](https://agentic-atlas.dev/nodes/verification-asymmetry)
4. [Effect Discipline](https://agentic-atlas.dev/nodes/effect-discipline)
5. [No Duck Left Behind](https://agentic-atlas.dev/nodes/no-duck-left-behind)
6. [Heavy Agent](https://agentic-atlas.dev/nodes/heavy-agent)
7. [Foundations](https://agentic-atlas.dev/nodes/foundations)
8. [Statelessness](https://agentic-atlas.dev/nodes/statelessness)
9. [The Shared Shape](https://agentic-atlas.dev/nodes/shared-shape)
10. field notes
    - “validate at the return seam; re-dispatch over repair; bounded autonomy — the contract keystone, applied”
    - “isolated child executions for TDD and controlled comparison”

StatelessnessThe Shared Shape unfold the map fold the map

The card, in place · its connections drawn edges from atlas_links the-contract-keystone

On this plate

[definition-the-analogy-declaration-versus-enforcement](https://agentic-atlas.dev/nodes/the-contract-keystone#definition-the-analogy-declaration-versus-enforcement) [why-it-matters-why-verification-enables-re-dispatch](https://agentic-atlas.dev/nodes/the-contract-keystone#why-it-matters-why-verification-enables-re-dispatch) [model-and-claims-one-move-three-names](https://agentic-atlas.dev/nodes/the-contract-keystone#model-and-claims-one-move-three-names) [scope-and-boundaries-where-the-argument-stops](https://agentic-atlas.dev/nodes/the-contract-keystone#scope-and-boundaries-where-the-argument-stops) [implications-the-consequence-map](https://agentic-atlas.dev/nodes/the-contract-keystone#implications-the-consequence-map) [evidence-what-the-argument-rests-on](https://agentic-atlas.dev/nodes/the-contract-keystone#evidence-what-the-argument-rests-on) [examples](https://agentic-atlas.dev/nodes/the-contract-keystone#examples) [relationships](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships) [lineage](https://agentic-atlas.dev/nodes/the-contract-keystone#lineage) [relationships-ledger](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships-ledger)

Every section is addressable on its own. Read only the ground you need.

## Definition — the analogy: declaration versus enforcement

[Permalink to Definition — the analogy: declaration versus enforcement section](https://agentic-atlas.dev/nodes/the-contract-keystone#definition-the-analogy-declaration-versus-enforcement)

An agentic component is *like* a function in that it exposes an input/output interface. The analogy is genuinely useful: both let a caller reason about a component without reopening its implementation. The important difference is how much of the interface the surrounding system can declare and enforce.

- A **function declaration** can make mechanically expressible parts of the [contract](https://agentic-atlas.dev/glossary/contract) structural: parameter names and types, return types, and—in richer systems—selected invariants. A compiler or runtime may enforce those declared parts. Semantic intent still exceeds the declaration and needs tests, assertions, or review.
- An **LLM-facing** contract is often prose addressed to a *probabilistic reader*. It is **persuasion, not enforcement.** The model can read a beautifully documented contract and still hand back something off-spec — confidently, fluently, plausibly. The boundary is aspirational until something checks it.

> **A declaration makes the mechanically expressible contract visible; an enforcement mechanism makes selected clauses structural. An LLM-facing [seam](https://agentic-atlas.dev/glossary/seam) begins with more of its contract in prose, so verification moves as many clauses as possible from promise toward enforcement.**

## Why it matters — why verification \*enables\* re-dispatch

[Permalink to Why it matters — why verification \*enables\* re-dispatch section](https://agentic-atlas.dev/nodes/the-contract-keystone#why-it-matters-why-verification-enables-re-dispatch)

An acceptance criterion is what makes [re-dispatch](https://agentic-atlas.dev/glossary/re-dispatch) governable in the first place. You can only "throw it away and re-run" if you have something to check the return against. No legible expectation → you can't tell a bad result from a good one → you can't verify → you can't safely re-dispatch. The silent, instinctive version of this — verifying a sub-agent's output and re-running when it looks wrong — was *already depending on an implicit contract the whole time*. Naming the contract turns instinct into a tool you can hand someone.

## Model and claims — one move, three names

[Permalink to Model and claims — one move, three names section](https://agentic-atlas.dev/nodes/the-contract-keystone#model-and-claims-one-move-three-names)

*Contract documentation*, *validated seam*, and *re-dispatch* are not three separate patterns. They are one move seen from three angles:

| Role | In a function | At an LLM-facing seam |
| --- | --- | --- |
| **Spec** | declaration / type signature | contract documentation |
| **Assertion** | compiler, runtime check, test, `assert` | deterministic or probabilistic validation at the return seam |
| **Recovery** | reject, throw, retry, compensate | reject, re-dispatch, adjust, fall back, or escalate |

- **Write the contract** to make intent legible (the spec).
- **Check the return against it** because the reader is probabilistic (the assertion).
- **Choose a recovery** after a failed check. For an effect-disciplined [dispatch](https://agentic-atlas.dev/glossary/dispatch), discarding can be cheaper than repairing. Re-dispatch is one tactical option, not the proof that the seam is safe.

You have reconstructed an assurance ladder around a reader that can ignore the declaration: prose → structured shape → deterministic clauses → probabilistic residue → human judgment. Only the mechanically enforced clauses become guarantees; the rest gain measured assurance.

### Why the check doesn't regress

The contract makes checking *possible*; a second premise makes it *affordable*: **verification asymmetry** ([Verification Asymmetry](https://agentic-atlas.dev/nodes/verification-asymmetry)). The verifier may be the same kind of probabilistic reader as the producer. The loop becomes useful only for clauses where checking a candidate against a documented spec is materially easier and measurably more reliable than producing it. One level is enough only when the checker terminates deterministically or its measured residual risk is acceptable. The two are sibling premises: the contract is the possibility condition of checking, the asymmetry its affordability condition.

### Why the discard is safe

Re-dispatch's economics assume throwing a run away costs nothing but the tokens. That is an engineering achievement, not a given: a dispatch that wrote files, called an API, or committed state before returning off-spec has already changed the world, and "discard" would silently mean "keep the mess." **Effect discipline** ([Effect Discipline](https://agentic-atlas.dev/nodes/effect-discipline)) is the third premise: dispatches that may be discarded must be pure, idempotent, or isolated — and effects that escape those guarantees are either compensated at the seam they landed on, or gated *before* they happen rather than validated after. The contract makes checking possible, the asymmetry makes it affordable, effect discipline makes the recovery move legal.

## Scope and boundaries — where the argument stops

[Permalink to Scope and boundaries — where the argument stops section](https://agentic-atlas.dev/nodes/the-contract-keystone#scope-and-boundaries-where-the-argument-stops)

The keystone is the argument, **not another pattern**: it owns how the three premises compose, not the premises themselves. The practice of writing a contract belongs to [The Contract](https://agentic-atlas.dev/nodes/contract-documentation), which this node generalizes; the applied loop belongs to *validate at the return seam; re-dispatch over repair; bounded autonomy — the contract keystone, applied*; and each premise's own failure boundary belongs to that premise's node. Where the asymmetry fails — intent the clauses can't cover, verifiers that can't discriminate, absence-claims that invert the gap — assurance runs out with it; that boundary lives in the asymmetry node.

## Implications — the consequence map

[Permalink to Implications — the consequence map section](https://agentic-atlas.dev/nodes/the-contract-keystone#implications-the-consequence-map)

Every move that splits work across components leans on it. Deferral, externalization, heavy agents — they all create a **seam** between components. A seam becomes more trustworthy as its load-bearing expectations are made explicit and pushed toward checking at the rigor its consequence warrants. The contract isn't one foundational principle among many; it's the **substrate that makes those moves safe to compose.**

## Evidence — what the argument rests on

[Permalink to Evidence — what the argument rests on section](https://agentic-atlas.dev/nodes/the-contract-keystone#evidence-what-the-argument-rests-on)

This is an argument assembled from three premises rather than a standalone empirical claim: each premise is grounded in its own node, and whatever revises one of them revises the composition here. What the keystone stands on directly is the instinct named above — practitioners already verify a sub-agent's output and re-run when it looks wrong, and that move already depends on an implicit contract. Each premise names the result that would revise it: a seam where the verify-and-re-run move is routinely safe with no legible expectation to check against would break the possibility condition; a seam where checking is no easier than producing breaks the affordability condition; a discarded run that already changed the world breaks the legality of the recovery. [No Duck Left Behind](https://agentic-atlas.dev/nodes/no-duck-left-behind) holds those three roles at one return seam: declared shape, deterministic assertion, bounded redispatch.

## Examples

[Permalink to Examples section](https://agentic-atlas.dev/nodes/the-contract-keystone#examples)

- **[No Duck Left Behind](https://agentic-atlas.dev/nodes/no-duck-left-behind)** — a sorter omits one duck and duplicates another; a deterministic census rejects the manifest with a bounded error report; the fresh return passes.

## Relationships

[Permalink to Relationships section](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships)

- Generalizes [The Contract](https://agentic-atlas.dev/nodes/contract-documentation).
- Applied, concrete form: *validate at the return seam; re-dispatch over repair; bounded autonomy — the contract keystone, applied*.
- Most directly load-bearing for [Heavy Agent](https://agentic-atlas.dev/nodes/heavy-agent) (the return contract) and *isolated child executions for TDD and controlled comparison* (the assertion).

## Lineage

[Permalink to Lineage section](https://agentic-atlas.dev/nodes/the-contract-keystone#lineage)

Design by Contract (Meyer, *Object-Oriented Software Construction*; Eiffel): preconditions, postconditions, and invariants declared at an interface. The spec/assertion/recovery split is Meyer's obligation table with the enforcement removed — an agentic contract documents what a compiler used to check.

The relationships ledger

Evidence-bearing references

## Relationships

Every connection keeps the section where it was found. The map above orients; this ledger carries the evidence.

### Outbound references 10

1. in-slice · occurrence 1
   [Verification Asymmetry](https://agentic-atlas.dev/nodes/verification-asymmetry)
   why checking an answer can be easier than producing it, and when that fails
   Evidence: [Model and claims](https://agentic-atlas.dev/nodes/the-contract-keystone#model-and-claims-one-move-three-names) · occurrence 1
2. in-slice · occurrence 2
   [Effect Discipline](https://agentic-atlas.dev/nodes/effect-discipline)
   which recovery moves an agent run's side effects still allow: discard, retry, or compensate
   Evidence: [Model and claims](https://agentic-atlas.dev/nodes/the-contract-keystone#model-and-claims-one-move-three-names) · occurrence 2
3. in-slice · occurrence 1
   [The Contract](https://agentic-atlas.dev/nodes/contract-documentation)
   the agreement on an artifact's shape and use whenever one component hands it to another
   Evidence: [Scope and boundaries](https://agentic-atlas.dev/nodes/the-contract-keystone#scope-and-boundaries-where-the-argument-stops) · occurrence 1
4. undisclosed · occurrence 2
   Undisclosed relationship
   validate at the return seam; re-dispatch over repair; bounded autonomy — the contract keystone, applied
   Evidence: [Scope and boundaries](https://agentic-atlas.dev/nodes/the-contract-keystone#scope-and-boundaries-where-the-argument-stops) · occurrence 2
5. in-slice · occurrence 1
   [No Duck Left Behind](https://agentic-atlas.dev/nodes/no-duck-left-behind)
   a checker rejects a flawed duck list and sends its errors back for a retry
   Evidence: [Evidence](https://agentic-atlas.dev/nodes/the-contract-keystone#evidence-what-the-argument-rests-on) · occurrence 1
6. in-slice · occurrence 1
   [No Duck Left Behind](https://agentic-atlas.dev/nodes/no-duck-left-behind)
   a checker rejects a flawed duck list and sends its errors back for a retry
   Evidence: [Examples](https://agentic-atlas.dev/nodes/the-contract-keystone#examples) · occurrence 1
7. in-slice · occurrence 1
   [The Contract](https://agentic-atlas.dev/nodes/contract-documentation)
   the agreement on an artifact's shape and use whenever one component hands it to another
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships) · occurrence 1
8. undisclosed · occurrence 2
   Undisclosed relationship
   validate at the return seam; re-dispatch over repair; bounded autonomy — the contract keystone, applied
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships) · occurrence 2
9. in-slice · occurrence 3
   [Heavy Agent](https://agentic-atlas.dev/nodes/heavy-agent)
   subagents that carry heavy baked-in instructions the orchestrator never loads
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships) · occurrence 3
10. undisclosed · occurrence 4
    Undisclosed relationship
    isolated child executions for TDD and controlled comparison
    Evidence: [Relationships](https://agentic-atlas.dev/nodes/the-contract-keystone#relationships) · occurrence 4

### Inbound references 11

1. in-slice · occurrence 1
   [The Contract](https://agentic-atlas.dev/nodes/contract-documentation#model-and-claims)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Model and claims](https://agentic-atlas.dev/nodes/contract-documentation#model-and-claims) · occurrence 1
2. in-slice · occurrence 2
   [The Contract](https://agentic-atlas.dev/nodes/contract-documentation#relationships)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/contract-documentation#relationships) · occurrence 2
3. in-slice · occurrence 1
   [Effect Discipline](https://agentic-atlas.dev/nodes/effect-discipline#relationships)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/effect-discipline#relationships) · occurrence 1
4. in-slice · occurrence 10
   [Foundations](https://agentic-atlas.dev/nodes/foundations#model-and-claims)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Model and claims](https://agentic-atlas.dev/nodes/foundations#model-and-claims) · occurrence 10
5. in-slice · occurrence 3
   [Foundations](https://agentic-atlas.dev/nodes/foundations#relationships)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/foundations#relationships) · occurrence 3
6. in-slice · occurrence 5
   [Heavy Agent](https://agentic-atlas.dev/nodes/heavy-agent#relationships)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/heavy-agent#relationships) · occurrence 5
7. in-slice · occurrence 1
   [The Shared Shape](https://agentic-atlas.dev/nodes/shared-shape#verification)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Verification](https://agentic-atlas.dev/nodes/shared-shape#verification) · occurrence 1
8. in-slice · occurrence 3
   [Statelessness](https://agentic-atlas.dev/nodes/statelessness#implications-the-consequence-map)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Implications](https://agentic-atlas.dev/nodes/statelessness#implications-the-consequence-map) · occurrence 3
9. in-slice · occurrence 5
   [Statelessness](https://agentic-atlas.dev/nodes/statelessness#relationships)
   how contracts, cheap checks, and safe discards together make agent handoffs safe
   Evidence: [Relationships](https://agentic-atlas.dev/nodes/statelessness#relationships) · occurrence 5
10. in-slice · occurrence 1
    [Verification Asymmetry](https://agentic-atlas.dev/nodes/verification-asymmetry#why-it-matters)
    how contracts, cheap checks, and safe discards together make agent handoffs safe
    Evidence: [Why it matters](https://agentic-atlas.dev/nodes/verification-asymmetry#why-it-matters) · occurrence 1
11. in-slice · occurrence 1
    [Verification Asymmetry](https://agentic-atlas.dev/nodes/verification-asymmetry#relationships)
    how contracts, cheap checks, and safe discards together make agent handoffs safe
    Evidence: [Relationships](https://agentic-atlas.dev/nodes/verification-asymmetry#relationships) · occurrence 1

[↑ back to the top](https://agentic-atlas.dev/nodes/the-contract-keystone#content) [← the survey](https://agentic-atlas.dev/atlas)

Node the-contract-keystone · corpus 78c0e17 · Catalog revision e0cb75881244b1a82193ca738b82a0d508dd62e822524ae82873ec79d51dbb61