Tại Sao Autonomous Agent Dễ Gây Runaway Cost Và Rủi Ro?
Hầu hết team deploy agent mạnh (Fable-class, Gemini advanced) với kỳ vọng productivity tăng vọt. Thực tế: một background agent long-running có thể fan-out thành hàng chục tool calls, retry loops, và unintended side-effects trước khi user biết. Bill tăng đột biến. Action sai (gửi email nhầm, modify data sai scope). Không có audit trail rõ ràng khi sự cố xảy ra.
Vấn đề cốt lõi không phải intelligence của model. Mà là: autonomous execution + consequence-bearing actions + thiếu control plane. Chat agent fail-safe vì user ở trong loop từng bước. Background agent chạy detached — sai một lần là hậu quả nhân lên.
Autonomous + consequence-bearing actions + detached run = rủi ro nhân lên. Chat agent có user trong loop từng bước; background agent cần policy engine, scoped identity, sandbox, full audit và human steer/approval gates cho high-impact trước khi scale.
Governance Layer Thực Sự Cần Những Thành Phần Nào?
Governance cho agent khác governance cho model API thông thường. Cần ít nhất:
- Policy & rule engine (what actions allowed, scope, rate limit, data boundary)
- Identity & authz cho agent (sub-account, least privilege, không dùng user credential trực tiếp)
- Sandbox / runtime isolation (network egress control, tool allowlist)
- Observability + audit log đầy đủ (mọi tool call, decision, state change)
- Human steer / approval gates cho high-impact actions (gửi tiền, thay đổi config prod, gửi comms ra ngoài)
- Cost cap + timeout per task / per user
Microsoft vừa open source Agent Governance Toolkit với policy enforcement sub-ms, zero-trust identity, sandboxing. Dấu hiệu cho thấy đây là lớp bắt buộc, không phải nice-to-have.
- 1Classify & RoutePhân loại stakes + chọn specialist hay frontier
- 2GovernApply policy, scope identity, set cap/timeout
- 3ExecuteBackground harness (Ona-style) hoặc embedded (AG-UI)
- 4Steer & VerifyApproval gate hoặc post-review + compensation
- 5Audit & LearnLog đầy đủ, outcome measure, improve router/prompt
Background Agent Khác Embedded Agent Và Chat Agent Như Thế Nào?
- Chat agent: user trong loop, low blast radius, dễ rollback bằng conversation.
- Embedded / Generative UI agent (AG-UI style): agent tác động trực tiếp state app trong context user đang nhìn, nhưng vẫn có UI affordance để user thấy và sửa ngay.
- Background / Persistent agent (Ona, Gemini Spark): chạy khi user offline, stateful, consequence dài hạn. Cần governance mạnh nhất.
Nhiều team nhầm lẫn deploy background agent như chat agent — thiếu guard, thiếu steer point, thiếu compensation logic.
- User trong loop từng bước
- Blast radius thấp, dễ sửa ngay
- Phù hợp exploration & low-stakes
- Dễ deploy, ít infra cần
- Chạy detached, stateful, long-running
- Cần governance chặt (policy, sandbox, audit)
- Outcome: 4× productivity, 83% PR co-author (Ona cases)
- Chỉ dùng khi có compensation + steer path rõ
Pattern Production: Router + Governed Harness + Persistence + Steer Points
Pattern đang chứng minh hiệu quả:
- Classifier/router đầu vào phân loại task (low-stakes / medium / high-consequence / long-horizon).
- Default: specialist rẻ/fast (Mellum2 local, Haiku, cached) + heavy prompt cache.
- Escalate chỉ khi cần: frontier model qua governed harness (Ona-style hoặc Bedrock AgentCore với guardrails).
- Background execution chỉ cho task có clear success criteria + compensation path.
- Persistence layer cho memory cross-session + cross-device (như CopilotKit Enterprise).
- Explicit steer: user interrupt, approval step, hoặc post-execution review cho critical.
Kết quả thực tế từ case study Ona: 4× productivity increase, 83% PRs co-authored bởi agent trong một số deployment — nhưng chỉ khi có governance primitives đầy đủ.
Mellum2 cho subtask nhanh/rẻ, Fable/Spark cho judgment sâu. Giá trị thực đến từ khả năng kiểm soát (policy + human gate + audit) và persistence (memory cross session) chứ không phải model nào 'thông minh' hơn. Router + governed harness là lớp tạo margin và an toàn.
Nên Và Không Nên Làm Gì Khi Triển Khai Background Agents?
Nên:
- Bắt đầu với harness có governance built-in (hoặc tự build control plane) trước khi cho agent chạy detached.
- Đo lường outcome (task hoàn thành đúng, effort saved, error rate) chứ không chỉ token burn.
- Thiết kế human-in-loop muộn nhưng có (approval hoặc easy rollback).
- Dùng specialist model cho đa số subtask, frontier chỉ cho judgment phức tạp.
Không nên:
- Bật default autonomous cho mọi workflow chỉ vì model mới mạnh.
- Dùng user credential cho agent action (luôn sub-account + scoped permission).
- Bỏ qua cost cap và observability vì 'chạy thử nghiệm' — production incident sẽ đắt hơn nhiều.
Governance không làm chậm agent. Nó làm agent có thể scale mà không làm sụp hệ thống hoặc ngân sách.