Understand drift
Drift is a difference between intended and observed state or behavior. The first question is what changed; the next is whether the change matters for this task and authority.
Explore environment controlDrift has more than one shape.
- Configuration, tools and models
- An active client may load a different profile, tool revision or supported model setting than the one approved for its project.
- Identity, permission and policy
- A grant can be revoked, a role changed or a policy revised while an approval or task is in progress.
- Instructions, behavior and workflow
- An agent may follow stale instructions, take a new path through tools or produce an outcome outside the intended task.
- Cost, data and knowledge
- Usage can exceed an expected bound, retrieval can reach a different source, or context can carry content into the wrong audience.
- Outcomes
- The observed pattern of errors, escalations, refunds or successful resolutions may change from the intended distribution, even when a single task appears plausible.
Compare intended state with what the runtime shows.
Suppose a team approves a project profile with a reviewed tool revision and a staging-only connection. A supported client starts with an older tool and a personal account. The saved profile shows intent; the observed client and connection show a mismatch. Resolve the exact artifact and account binding before claiming the project environment is restored.
For a refund, permission or policy drift may change the allowed action after an earlier review. Re-evaluate material inputs and current scope at the qualified effect boundary. A lost provider response is a separate execution uncertainty: reconcile the original operation before retry.
Make the response proportional.
Detect
Collect the intended revision and observed state with provenance; identify what is unknown.
Classify
Separate configuration repair from permission or policy changes, behavior review and uncertain effects.
Decide
Warn, require review or enforce only where the integration supports that control mode.
Verify
Read back the resulting state or reconcile the original effect, then retain the evidence and relevant revision.
Detection is not universal visibility.
The platform can reason only over connected sources and qualified observations. An installed artifact is not proof that a client loaded it. An inventory does not discover every unconnected shadow agent. A post-action signal can support investigation without claiming it prevented the effect.