Most AI agents operating on knowledge bases are glorified autocomplete engines with write permissions. They download context, guess the target, rewrite the file, and claim victory. This pattern is unsafe and prone to catastrophic drift. The developers at Doco, an open-source document workspace for human-AI collaboration, have published a rigorous six-step operational loop designed to eliminate this recklessness. The core sequence—browse, search, read, traverse, edit, watch—replaces the dangerous approach of downloading everything and guessing with a disciplined cycle of evidence gathering and verification.
The Six-Verb Execution Loop
The workflow begins with 'browse,' where the agent establishes its identity, scope, and the true IDs of the target knowledge base. It does not guess. Next, 'search' locates the current fact, requiring the agent to check for 'complete=true' in the response; if incomplete, the agent must report uncertainty rather than concluding the answer doesn't exist. The 'read' phase forces the agent to inspect the outline and surrounding blocks, using continuation cursors to avoid stitching together content from different document versions. Before any modification, the agent must 'traverse' dependencies. If a user asks to change a release window, the agent follows 'depends_on' relationships to verify if rollback plans remain valid. This step converts stale or dangling evidence into explicit uncertainty in the final report. Only then does 'edit' occur, using a stable block target and an If-Match header based on the current SHA-256 version. If a concurrent edit has occurred, the system returns a 409 Conflict, forcing a re-read. This prevents the lost update problem described in RFC 9110.
Verification Is Not Optional
The final step, 'watch,' verifies that the knowledge world has caught up. The agent checks search projections, index versions, and summary freshness using a saved changes baseline. If the change history was compacted, a 'sync_required=true' flag triggers a full synchronization. Doco’s authors emphasize that a successful HTTP 200 response is not proof of completion. The agent must read back the authoritative document to ensure the target contains the new value and adjacent blocks remain intact. "Done" is defined as an evidence report, not a status code.
Key Takeaways
- Agents should never rewrite whole documents; narrow block edits with version checks reduce blast radius and preserve concurrent changes.
- Read-only access is sufficient for high-quality answers; grant write scope only when maintenance is explicitly required.
- Derived projections like search indexes and summaries can become stale; agents must report this uncertainty rather than presenting a confident but outdated conclusion.
- The MCP tools specification supports this model by treating tools as model-controlled actions while keeping humans able to deny invocations.
The Bottom Line
This is the discipline we’ve been waiting for. If your agent isn’t checking If-Match headers and verifying search projections, it’s just guessing with high confidence. This workflow highlights a shift from simple automation to rigorous engineering, where every action is bounded by evidence and every completion is a report of verified state. Originally published on Doco.