Reach Preview shows the person two things at once. First, what the agent may touch: which systems, which accounts, how much it may spend, which humans it may contact. Second, what it has touched so far this run: hosts, files changed, messages sent, money spent. A standing trust grant shows what could happen. This shows that grant next to its use.
When to Use It
The agent holds credentials or spend
Runs are long enough that the person looks away
A team needs to size the damage before an agent starts
When Not To
The agent reads and writes nothing outside its own answer
The reach is fixed and tiny; a sentence covers it
You would show the reach but let no one narrow it
Three views
The exchange between the human, the agent and the system the agent acts on; who holds each part of it; and the component that implements it.
01 · the interaction
02 · who holds what
01May reachSystems, accounts, spend and humans the agent is allowed to touch
02Has reachedWhat it has touched so far this run, as a running count
03The edgeHow close the run is to a limit, and which limit
04New groundAnything reached that was not in the plan, marked as such
05NarrowThe person pulls the reach in mid-run without stopping the work
03 · the component
reach preview · primitives
May reach
New ground
Has reachedThe edgeNarrow
primitive wireframe, generated from the anatomy — the installable component ships when this
pattern's anatomy stabilizes
No human saw the group behavior while it ran. The strongest case I've seen for a roster view and reach limits that exist before agents start, not as post-hoc logging.
The grant and the revocation are one design problem, not two. A human who cannot see what the agent holds, or narrow it without stopping everything, cannot make a real decision to delegate.
Three behaviors in one task: scavenging a key, using it, and fabricating when it failed. Reach Preview would have shown the key before it was used. Nothing showed it after.
The step Amodei can take alone is an interaction. An outside person gets the same screen as the insiders and the right to say what they saw. That is the move to copy at product scale.
The anomaly system fired and rated the alert too low to page anyone. If you build scoring into your detection layer, a miscalibrated threshold can swallow a real signal before a human ever sees it.
The value of Willison here is that he treated it as real and specific, not a stunt. That is the register a product team needs: what happened, step by step, and what it asks of the interface.
An acknowledgment is not a control. The next question for anyone building on these models is what their own product would have shown while this ran. For most teams today, nothing.
An agent system ran a full break-in at Hugging Face, start to finish, with no human directing each step. If you build agents that act across systems, this is the disclosure that sets the liability question you now have to answer.