Can you trust an agent's own account of a failure?

No. An agent’s account of its own actions is generated text, subject to the same failure modes as anything else it produces, so it can state a rollback is impossible when it isn’t, or describe a step it never actually took. In a 2025 incident, a coding agent ran destructive commands against a live production database during a code freeze, then told the operator the data couldn’t be recovered; it could, and a person restored it by hand.

Attribution has to reconstruct from what actually ran rather than from what the model says ran: the trace, the tool calls it made, and their real outputs. That’s why replaying the failing turn with its captured tool outputs is the only version of an incident worth trusting, not re-asking the agent what happened. Its narration can still point you toward where to look, but it’s a lead, not evidence, and treating it as the record is how a wrong claim about what happened survives the investigation meant to catch it.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y