verifiedagents.ai
All posts

6 min readAI Agents

How Do You Verify What One AI Agent Hands to the Next?

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: How Do You Verify What One AI Agent Hands to the Next?

TL;DR: Verify an AI agent handoff by adding one check at the point where an agent passes work to the next agent with no person in between. Something other than the sending agent confirms the one fact that would hurt most if it were wrong. Access controls can't do this job. They only confirm the agent was allowed.

Last updated October 5, 2026. This post was rebuilt for verifiedagents.ai. It turns a story from Josh's Lab into a checklist you can run this week.

Why does a handoff between AI agents need its own check?

A handoff needs its own check because errors grow as work moves down a chain. The receiving agent treats what it gets as true and builds on it. Nobody reads the work in between.

The math is rough. Researchers at Princeton linked three AI systems in a chain. Each one was 90 to 97 percent accurate alone. Together they scored 74 percent. Michelle Savage and I cite the study in our chapter of John Kindervag's book, Cyber Resilience at Machine Speed.

One run in four came out wrong, and every link was mostly right. So stop grading agents one at a time. Grade the chain.

Why don't access controls catch a wrong answer?

Access controls answer one question: is this agent allowed to do this? A wrong answer from an allowed agent passes every time.

I've watched it happen. In Josh's Lab, my research agent Scout made up a source. My writing agent Quill wrote two documents on top of it. Every permission held all night. There was no attack and no stolen password.

I caught it at a routine handoff the next morning, and the rebuild cost me most of a day. The full story is in why AI agents pass every access check and still get it wrong.

Zero Trust is the foundation here. It verifies every request, every time. AI agents need one more check on top of it. Verify what the agent believes before the next agent uses it.

What does each control tell you about an AI agent?

Each control answers a different question, and only the handoff check tests whether the work is true. Use this table to see what you already cover.

Control

Question it answers

What it can't tell you

Access control

Was the agent allowed to do this?

Whether the output is true

Agent identity and logs

Which agent acted, and when?

Whether the output is true

Handoff check

Is this one fact true before it moves on?

Who's allowed to act

Human review at the end

Does a person accept the finished work?

Which earlier step went wrong

How do you add a handoff check in five steps?

Start with one chain and one fact. A chain is any place one AI agent passes work to another with no person in between.

  1. Count your chains before you count your agents.

  2. Start with the chain closest to a customer. A mistake there costs the most.

  3. Name the one fact that would hurt most if it were wrong. It might be a cited source or a dollar amount.

  4. Pick a checker that isn't the sending agent. An agent that invents a citation has no idea it did. Use a script that opens every cited link, or give the job to a person.

  5. Put one person's name on the check.

Step five is the one teams skip. Security usually owns identity. A platform or data team usually owns output quality. The handoff sits between them, so it belongs to nobody until you assign it.

After the Scout morning, I changed one thing in the lab. Research now gets checked against an outside source before it moves on.

What evidence shows handoffs are a blind spot?

Most companies can't trace what their AI agents do yet, so checking the work is further off. In fall 2025, the Cloud Security Alliance and Strata Identity surveyed 285 IT and security professionals. Only 28 percent could trace an agent's actions back to a human sponsor everywhere their agents run. Eighty-four percent doubted they could pass an audit focused on agent behavior or access.

The standards are still catching up. In December 2025, OWASP published its first top ten risks for agentic applications. Insecure communication between agents made the list. So did cascading failures. An agent inventing a fact and passing it along as true isn't on it yet. That last point is my own reading of the list.

There's a public case too. In July 2025, an AI coding agent at Replit deleted a company's production database during a code freeze. It then made up more than 4,000 fake user records. Replit's CEO called it unacceptable.

What does a good handoff rule look like?

A good handoff rule is one that something other than the agent can test. "Never make up a source" fails, because the agent can't tell when it broke the rule. "Every cited link opens before the next agent uses it" passes, because a script can test it.

Michelle Savage calls the short document that holds rules like this a never list. Her post explains what a never list for AI agents is and how to write one.

Frequently asked questions

Can an AI agent pass an access audit and still be wrong?

Yes. An access audit checks what the agent was allowed to touch. Scout stayed inside its permissions all night and still made up a source. The facts an agent used are a separate check.

Does agent identity still count if it can't catch a wrong answer?

Yes. Identity is how you clean up. Every agent in Josh's Lab has its own name and writes one line for each action. So I traced the false source to the exact agent and the exact minute.

Who should own a handoff check, security or the data team?

One named person, from either team. A false fact moving between two agents is a security problem and a quality problem at once. That's why it slips past both teams by default.

Does Zero Trust apply to AI agents?

Yes. Zero Trust is the foundation, and it works on an AI agent the way it works on a person. You remove assumed trust and verify every request. AI agents add one more check: verify what the agent believes.

Key takeaways

  • Grade the chain. Three AI systems that were each 90 to 97 percent accurate scored 74 percent together.

  • Access controls confirm an AI agent was allowed. They can't confirm its answer is true.

  • Put one check at the handoff closest to a customer, on the one fact that would hurt most.

  • The checker can't be the agent that did the work.

  • Give the check one named owner.

Where do your AI agents stand today?

The fastest way to find out is the free AI agent assessment. It takes about ten minutes and scores your agent controls across the five ATF elements, starting with Identity Management.

You know who has access. Now check what your agents pass along.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.