A specialist task packet is a narrow contract, not a vague role label. It names the exact question, input artifact versions, permitted tools, read or write authority, required evidence identifiers, output schema, deadline, and uncertainty language. Do not assume the specialist can see the controller's private history, another agent's findings, or a newer repository snapshot. Pass only the context it needs and record what was sent. Tool permissions must be enforced by the runtime, because text such as 'read only' cannot disable a write-capable tool. An agent should return a concise finding with claim, evidence, limits, and unresolved questions; the controller should retain the raw trace for audit.
Specialist task packets: scope evidence and authority explicitly
Operational case
The parcel incident controller sends three packets based on snapshot PK-214. Telemetry may read metric series and log counts but may not change alerts. Release review may inspect commit RC-47 and configuration diffs but may not deploy or revert. Customer review may read redacted support tags, not account details. A poorly scoped task says 'investigate and fix the outage'; the release specialist then suggests a rollback as if it had operational permission. The revised packet asks it to report changed settings and possible mechanisms only. A production action requires a separate operator decision after the evidence is reconciled.
Agent: release-review. Snapshot: PK-214; release: RC-47.
Question: Which config values changed, and how might they affect errors?
Tools: read-only diff and release metadata. No deploy, revert, or ticket write.
Return: claim ID, cited artifact IDs, observed fact, hypothesis, uncertainty.
Stop: one diff pass or 45 seconds; report incomplete work.Performance and operating cost
For K specialists, packet preparation and merge overhead grows at least O(K), while careless context duplication can multiply token use by K. A bounded packet reduces irrelevant reads and makes the returned claims easier to verify. Version identifiers are cheap compared with investigating why one agent used pre-release metrics and another used post-release config. The controller must validate the response schema and check runtime tool scope; the model's declaration that it obeyed a permission rule is not an access-control record.
Common Mistakes
- Do not give a specialist an open-ended 'fix it' task when it only owns read-only analysis.
- Do not assume agents share conversation history or artifact versions.
- Do not mistake a prompt's tool restriction for runtime enforcement.
Connected lessons
- Prompt engineering applications
- Prompt Engineering
- Tool calls: validate intent and arguments before an external effect
- Prompt envelopes: separate task, evidence, input, and output contract
- Evidence IDs: make generated claims auditable against supplied records
- Specialist agents: prove that delegation earns its cost
- Parallel agents: isolate state and assign one writer
- Specialist synthesis: merge claims, not fluent summaries
- Specialist workflows: bound retries and review the full trace
- Project: coordinate a parcel-platform incident review
- Specialist-agent coordination decisions
