Indie Hacker Playbooks

Guarding Agent Content Publishing with Server-Side Approval

Let an agent score and draft, but keep validated writes behind approval-only server code

Definition

An agent architecture that gives the model read, scoring and drafting capabilities while reserving public writes for tested server code triggered by an explicit approval event.

Perspectives

harsehaj (2026-08-24, X)

Do not give the content agent a website write tool. Let it inspect sources, score opportunities, draft a surgical edit and post Approve/Edit/Skip cards into the existing work channel; end that agent run, then let a separate server handler process a later click. A bad run can then produce a bad suggestion but cannot alter the site.

Keep judgment in changeable skill files and the write path in tested code that revalidates every agent claim. Limit automatic edits to dead links with a known replacement and empty SEO fields; a title, description or exact phrase/link swap can be proposed for approval, while anything larger exposes only Edit and Skip. Lock a suggestion on first click and refuse publication when an unsaved CMS draft would overwrite the new edit.

For generated posts, gate strategy, structure, code provenance and query cannibalization before creating an unlisted draft. Give the agent two redraft attempts, stop rather than weakening a failed gate, and route an already-owned query back to the existing-post audit instead of rephrasing a duplicate.

How to apply

  • Fits public-facing content where a plausible bad edit is costlier than the delay of human approval.
  • Keep the approval handler independent of the agent session and promote only deterministic checks, following Promoting Agent Workflows into Automation.
  • Feed candidate edits from Scoring SEO Edit Opportunities by Headroom and start measurement only after the server confirms publication.
  • Not a fit for harmless private drafts where rollback is trivial and the approval queue would cost more than the error.

Limits

  • Browserbase's six-week operation, 18 generated posts and 50+ edits are self-reported; no incident rate, reviewer time or false-positive rate is provided.
  • The safe auto-publish classes depend on the CMS and may still be wrong when redirects, localization or editorial ownership are ambiguous.
  • Slack, Sanity, Postgres and KV details are implementation choices, not requirements of the boundary.

Original link

On this page