pg-dry-runās maintainer claims previewing PostgreSQL mutations and checking xmin concurrency state provides a practical validation gate against unsafe or conflicting writes by AI agents.
state: expiredheat: lowuncertainty: highconvergesscott: mediumagentic-security database-safety tool-validationPolycore
What is this?
pg-dry-run is described as a Polycore-maintained tool that previews PostgreSQL mutations proposed by AI agents before allowing them to execute, using the databaseās `xmin` system column to detect whether relevant rows changed after they were read. The supporting snippets establish that `xmin` records the transaction that created a row version and can serve as an optimistic-concurrency token for detecting concurrent modifications. However, the supplied search results do not independently document pg-dry-run itself or substantiate the broader claim that this gate prevents unsafe writes beyond concurrency conflicts.
Why it matters to Scott
pg-dry-run independently implements Scottās proposeāfinalise and deterministic execution-boundary pattern at the PostgreSQL write layer, adding a concrete `xmin` optimistic-concurrency check that could inform his agent control planes. It is a useful implementation lead rather than validation of the architectureās effectiveness, since the supplied evidence does not establish independent testing or protection beyond conflicting row state.
ip:framework.decision-authority-infrastructureip:concept.terminal-mutation-documentdev:concept.propose-finalise-gatedev:concept.deterministic-agent-control-planeradar:agent-acid-rollback-guardrailsradar:microsoft-agent-validation-framework
queries asked of Scott's wikis
- AI agent database write approval gates
- preview and validate tool mutations before execution
- optimistic concurrency for agent actions
- least-authority database tools for coding agents
- human-in-the-loop approval of destructive writes
- transactional safety and rollback in agent harnesses
Measured heat
no measured readings yet ā the hourly heat pass fills this in
How the heat travelled
no chain yet ā the hourly chain pass fills this in
Evidence (2) ā ā canonical anchor
Interpretation history
2026-09-02T15:45:24Z
The implementation lead has produced no independent testing, adoption, discussion, or technical follow-up within its horizon. It remains an unvalidated maintainer claim about a narrow concurrency safeguard, so continued monitoring is not earning attention.
2026-08-31T15:38:12Z
No new evidence, discussion, testing, or adoption has appeared; the case remains a maintainer-described implementation lead rather than validation that the gate prevents unsafe agent writes beyond row-version conflicts.
2026-08-31T15:33:55Z
grounded: converges/medium ā pg-dry-run independently implements Scottās proposeāfinalise and deterministic execution-boundary pattern at the PostgreSQL write layer, adding a concrete `xmin
2026-08-31T15:32:03Z
case created ā The released artifact targets a specific consequential agent failure mode and is distinct from general-purpose tool-call guardrails and validation frameworks.
Decision trace
- 09-03 01:45expireThe implementation lead has produced no independent testing, adoption, discussion, or technical follow-up within its horizon. It remains an unvalidated maintainer claim about a narrow concurrency safe
- 09-03 01:45alert_silentThe only trigger is staleness and the underlying evidence is unchanged; there is no new consequential delta to surface or reason to expect confirmation within hours.
- 09-03 01:45alert_routeThe only trigger is staleness and the underlying evidence is unchanged; there is no new consequential delta to surface or reason to expect confirmation within hours.
- 09-01 01:38repriceNo new evidence, discussion, testing, or adoption has appeared; the case remains a maintainer-described implementation lead rather than validation that the gate prevents unsafe agent writes beyond row
- 09-01 01:38alert_silentThis is an unchanged reobservation of the original low-traction release, with no consequential delta since the prior silent decision. It can wait unless independent evaluation demonstrates broader saf
- 09-01 01:38alert_routeThis is an unchanged reobservation of the original low-traction release, with no consequential delta since the prior silent decision. It can wait unless independent evaluation demonstrates broader saf
- 09-01 01:36alert_silentThe release is a concrete implementation lead for proposeāfinalise database writes, but it does not yet establish meaningful adoption, independent testing, or protection beyond detecting row-version c
- 09-01 01:36surface_candidateThe release is a concrete implementation lead for proposeāfinalise database writes, but it does not yet establish meaningful adoption, independent testing, or protection beyond detecting row-version c
- 09-01 01:36alert_routeThe release is a concrete implementation lead for proposeāfinalise database writes, but it does not yet establish meaningful adoption, independent testing, or protection beyond detecting row-version c
- 09-01 01:33groundpg-dry-run independently implements Scottās proposeāfinalise and deterministic execution-boundary pattern at the PostgreSQL write layer, adding a concrete `xmin` optimistic-concurrency check that coul
- 09-01 01:32createThe released artifact targets a specific consequential agent failure mode and is distinct from general-purpose tool-call guardrails and validation frameworks.