# Monday checklist — harness, not a bigger model

Use this after you can name the task, the tools, and the check that marks it done.

- [ ] Write the task contract: objective, allowed paths or tools, prohibited operations, evidence required before "done".
- [ ] Run at least one deterministic check outside the model (test, typecheck, schema, or a second read of the business record).
- [ ] Confirm high-impact tools (push, deploy, refund, cancel, inventory, PII) do not exist for the agent until an approval id is present.
- [ ] Treat issue text, web pages, and tool output as untrusted. Do not put them in the same channel as system instructions.
- [ ] Cap iterations and wall-clock time in code or in AgentCore invoke limits. Do not rely on AWS Budgets as a hard stop.
- [ ] Log run id, model id, tool name, redacted arguments, token counts, and outcome. Leave raw prompts and secrets out.
- [ ] If a tool call might have mutated remote state, reconcile before retry.
- [ ] On AgentCore Harness: customer IAM role, Gateway Cedar for writes, eval suite, Browser and Code Interpreter off unless that task needs them.
- [ ] On Strands harness: move session and memory off `./.agent` before you leave a laptop, and do not ship the default shell against orders or payments.
- [ ] Add one regression case for the last verifier failure before you turn that failure into a permanent rule.
