Skip to content
AI Agents 2026-07-14 14 min

Building AI Agents With Guardrails That Don't Break

A reference architecture for production AI agents: planning loops, tool use, retries, evaluation and human-in-the-loop handoff.

By Mohammad Zayed

Overview

An AI agent is a system that takes a goal, plans steps, calls tools, observes results, and repeats until the goal is met. The hard part is not the model — it's the guardrails that keep the loop safe, observable and bounded.

Architecture

We use a supervisor/worker pattern: a planner decides the next action, a tool executor runs it, and an evaluator checks the result before the next step.

Agent control loop
User goal │ ▼ [ Planner ] ──▶ chooses tool + args │ ▼ [ Tool Executor ] ──▶ external API / DB / search │ ▼ [ Validator ] ──▶ schema + policy check │ ├─ pass ──▶ [ Memory ] ──▶ loop or finish └─ fail ──▶ [ Planner ] (retry, capped)

Each step is bounded by a budget and a validation gate.

Folder structure

project tree
src/agent/
  planner.ts        # decides next action
  executor.ts       # runs tools, typed
  guardrails.ts     # budget + policy checks
  memory.ts         # conversation + state store
  tools/
    search.ts
    crm.ts
    email.ts
  eval/
    harness.ts      # offline evals

Core loop

agent/run.ts
export async function runAgent(goal: string) {
  const state = createMemory(goal);
  for (let step = 0; step < MAX_STEPS; step++) {
    const action = await planner(state);
    await guardrails.assert(action, state.usage);
    const result = await executor(action);
    if (!(await validator(result))) {
      state.log("retry", action);
      continue;
    }
    state.append(result);
    if (state.isComplete()) break;
  }
  return state.final();
}
Always cap MAX_STEPS and per-run tokens. Unbounded loops are the fastest way to a surprise invoice.

Deployment strategy

Run agents as short-lived serverless functions or a queue worker. Persist state to Postgres so a crash mid-run can resume. Emit structured logs for every tool call.

Security considerations

  • Scope each tool's credentials to least privilege.
  • Never let the model write raw SQL — use typed tool functions.
  • Require human approval for payments, deletes and external sends.

Scaling strategy

Decouple planning from execution with a queue. Scale workers horizontally; keep the planner stateless. Cache planner outputs for repeated intents.

FAQ

See the FAQ section above. For implementation help, book a strategy call.

Frequently asked questions

What is a guardrail in an AI agent?
A guardrail is a runtime check that constrains what the agent can do — limiting tool calls, validating outputs, capping spend, and forcing human approval for sensitive actions.
Should I use a framework or build my own loop?
Start with a thin custom loop so you understand each step. Adopt a framework once you have repeating patterns. The key is owning the control flow, not the abstraction.
How do I stop agents from running up API bills?
Enforce a max-steps limit, per-run token budget, and a circuit breaker that halts the run when thresholds are exceeded. Log every token spent per task.

Continue reading

Want help building this?

Book a free strategy call. We'll map your bottlenecks to the right systems and send a clear roadmap — even if we don't work together.

Chat on Telegram

Usually replies within minutes. Chat on Telegram: @northflowstudio

No obligation consultationFounder-led projectsInternational clientsFast responseSecure communication