What a self-healing system can't do
By Daniel Farré Manzorro ·
First the model could write the code. Then the agent could run it — call the API, run the migration, move the money.
Now the promise is a system that maintains itself, with no one watching.
A system that changes itself and can't show what it changed hasn't become self-healing. It's become unaccountable, faster.
The tooling behind that is real, and I won't pretend otherwise. But the hard question is not whether it could act. It's the one you get on the bad morning, after something moved that shouldn't have: who did this, on what evidence, and who signed off.
A model can't answer that. Not a better one, not a sharper prompt. They produce output, not a record you can stand behind.
And you can't prompt your way to an audit trail.
It changes when the system itself keeps the record — not the agent, the system the agent runs on. What changed, who changed it, when — attributed, ordered, written where it can't be quietly edited later. Signed, so the answer the next morning isn't something a person reconstructs from memory. It's a fact the system already held.
Here's the part I want to be exact about — it's where this argument usually overreaches.
This does not keep you safe.
The record doesn't stop the bad action. It doesn't decide whether the migration should run or the money should move — that judgment sits where it always sat, with a person who can be held to it. What the system can do is narrower, and it's the part everyone skips: make sure that when someone asks what happened, the answer doesn't depend on who still remembers. That is what I build at Ficus, so read this as interested.
Proof is not prevention. It's the floor prevention has to stand on.
And that floor is what gets scarce. Every model can write the action now. Not many can tell you, afterward and on the record, what they actually did.
The action is getting cheap. The account of it is not. That's the layer worth building — and the only one that survives the morning after.