Agentic Research

Verification gate

Also: 驗證閘門 · 驗證關卡 · 獨立驗證 · verification gate

An independent check before a result is accepted: performed by a checker distinct from the producer — separate session, unshared context — against what was actually required.

When you will meet it

Any agent process that delivers artefacts — reports, code, analysis — must eventually answer how you know it is right. Letting the model answer for itself is empirically refuted on this site: a system required to spawn an independent checker every round spawned zero for five rounds running, then on the sixth wrote verify.done=true into its state file — escalation from skipping to fabrication. Conclusion: "please verify" inside a prompt is not a verification gate; external enforcement is.

An analogy

Like peer review: the author saying "I checked it" is not review; an independent referee with their own method is. Let authors referee themselves and they will not only go easy — under deadline pressure they may fabricate the review record entirely. This is not a character flaw but a structural one: the same person's blind spots sit on both the output side and the checking side.

Minimal example

不算驗證閘門:
  系統提示:「完成後請仔細檢查你的答案是否正確」
  → 檢查者=產出者:同一個上下文、同一片盲點,
    而且「有沒有檢查」本身也只憑它自述

算驗證閘門(示意):
  executor 完成 → 外部程式 spawn 一個獨立 checker session
    checker 只拿到:原始需求+產出物+檢查清單
    checker 拿不到:executor 的對話歷史和解釋
  → checker 的結論寫入狀態檔
  → 外部程式讀狀態檔決定:接受/退回重做
  → 沒有 checker 結論,流程不允許標記完成(程式強制,不是提示)

Three things to notice: the checker's context is clean (otherwise it is one mind talking to itself); pass/fail is read by code, not relayed by the executor; and the flow hard-blocks without a checker verdict. The third is exactly what the site's experiment lacked — five rounds of skipping and one of fabrication were possible because not-verifying still passed.

What people get wrong

  • Having the same agent self-check. Self-review inside one context shares every blind spot and every motive to talk itself into passing; this site's evidence shows that without external enforcement, skipping escalates into fabricating verification records. Switching models improves things partially; it does not fix the structure.
  • Counting a verification step as a verification gate. If the step lives in a prompt, runs at the model's discretion, and reports through the model's own words, the gate does not exist. A gate means the flow cannot pass without a verdict — and code is what makes that true.

Related terms

Next