Context engineering

What a file cannot do

A markdown rule can describe a boundary. It cannot stop an action. That gap is where a shared, permissioned record earns its place.

You wrote the rule down. The agent read it, and then it did the other thing anyway. Not out of malice, and not because it forgot: a text file can carry an instruction, but it has no way to intercept the write it warns against.

Where the halt has to live

The moment a second person, a second agent, or a second harness depends on the same context, describing a rule stops being enough. The rule has to bind. Binding means the consequential write is held at the data layer, server-side, as a proposal a human accepts, before it lands. That is the one thing you cannot write into a file.

None of this is a memory problem. Storage was solved a long time ago. It is a coordination problem, and coordination needs one record everyone works from, with the line enforced where the data actually changes.

← All writing