What a trading engine taught me about agent retries
Exchange infrastructure solved idempotency, retry storms, and partial failure decades ago. Agent frameworks are rediscovering all three the hard way.
Load-Bearing Code
I have been shipping systems that had to stay up since 1975 — mainframes, an exchange trading engine, and now agents. This is a weekly account of which parts carry the load, which parts only look like they do, and how to tell the difference before your users do.
Agent Architecture
How to structure agentic systems so failures stay contained and behavior stays explainable.
Evaluation & Testing
Measuring whether a probabilistic system is getting better, and proving it to someone who signs the check.
Production Reliability
Latency budgets, blast radius, graceful degradation — the non-functional requirements that decide whether an AI feature ships.
Data Architecture
Storage, retrieval, and schema decisions that age well — from document models to vector indexes.
Field Notes
Fifty years of systems that had to stay up, and which instincts actually transferred.
Exchange infrastructure solved idempotency, retry storms, and partial failure decades ago. Agent frameworks are rediscovering all three the hard way.
If you cannot prove your AI feature got better this week, you are not engineering it — you are decorating it. A working harness, and the failure modes that make most of them lie.
You cannot make an LLM deterministic. You can decide exactly how much nondeterminism each part of your system is allowed to spend, and enforce it at the boundaries.
Subscribe
Which parts of an AI system actually hold weight in production. Free, in full, delivered Thursday mornings.