Retry storms after refusal or transient failure
Repeated paid attempts should hit threshold, anomaly review or queueing before the runtime quietly burns more budget.
NORNR control: policy replay workbench, review bundle, velocity anomaly posture.
NORNR
Failure modes worth studying before another agent earns more autonomy than it deserves.
NORNR / Prompt injection hall of fame
Developer proofThis page is not for memes. It is for builders who want a precise record of what broke, what it cost, and which control surface should have been in the path before the action became consequential.
Failure classes
The useful output is not fear. It is the named lane, pack and packet surface that should have absorbed the failure.
Repeated paid attempts should hit threshold, anomaly review or queueing before the runtime quietly burns more budget.
NORNR control: policy replay workbench, review bundle, velocity anomaly posture.
An agent that changes vendor, checkout target or settlement destination should no longer inherit the earlier mandate.
NORNR control: counterparty posture, approval threshold, proof packet provenance.
The last click should still clear one review path rather than hide inside a multi-step session.
NORNR control: browser checkout governance, browser-ops pack, proof packet.
Local tool access is still a consequential control surface if it can trigger providers, vendors or data mutation.
NORNR control: MCP control server, review bundle, finance packet.
Approval should stay attached to one intent, not bleed into every similar action afterward.
NORNR control: one intent per action, explicit approval state, exported policy version.
If the action cannot end in one close-ready export, the control lane still failed institutionally.
NORNR control: finance close packet, exception reports, reconciliation center.