# Sequence verification: skipped and out-of-order steps in automation

> Markdown mirror for AI agents, generated 2026-10-03 from the live page.
> Canonical: https://agenticrail.nz/sequence-verification/
> Site context: https://agenticrail.nz/llms.txt

# Sequence verification

The vocabulary of skipped and out-of-order steps in automated processes, AI agents included, defined in one place.

**Sequence verification is checking, at each step of an automated process, that the step is the one an order declared in advance says comes next, and keeping a record of each check that a party outside the process can examine.** It answers a question ordinary monitoring does not ask. Monitoring asks whether the system is up and whether each call succeeded. Sequence verification asks whether the right steps ran, in the right order, and whether that can be shown to someone who was not there.

The terms below are used loosely across engineering, operations, audit and AI writing, and several of them name the same failure from different sides. Each is defined as precisely as it can be, with the informal ones marked as informal.

## The category

### Sequence verification

Checking, at each step of an automated process, that the step is the one an order declared in advance says comes next, and keeping a record of each check that a party outside the process can examine. It needs two things that most systems lack: an order stated before the run, and a record not written by the process being checked.

### Sequence enforcement

Sequence verification that acts. A step presented out of the declared order is refused before it runs, rather than found afterwards. The difference is timing: verification after the fact can establish that something went wrong; enforcement at the step stops it, and records the refusal.

### Declared step order

The list of steps a process must follow, fixed before the run starts. It is the reference every other term on this page depends on. Without it a step cannot be called missing, early or late, because nothing said where it belonged. It also settles who decides the order: in a well-governed process it is the organisation, set in advance, and never the software carrying the process out.

### Sequential logic (SLP-8)

SLP-8 is the sequential logic protocol behind AgenticRail: a declared order of steps, each evaluated before it runs, with every decision signed and linked to the one before it. The name comes from its default eight-step order; any order can be declared in its place, and one step is a valid sequence.

## The failures

### Out-of-order execution

A step running before a step it depends on has completed. In conventional automation it usually comes from concurrency: parallel workers, message queues that do not preserve order, a retried step landing after the one it should have preceded. In an AI agent it can also come from a choice, because the agent decides its own route. Either way the step itself typically succeeds, which is why the fault is found downstream.

### Skipped step

A required step that never ran. It is the hardest failure in this list to detect, because a step that never ran writes no log entry. A record of everything that did run is complete, internally consistent and wrong, and nothing in it marks the gap. A skipped step can only be seen against a declared order that said it should have been there.

### Procedural hallucination

An AI agent skipping, reordering or fabricating a step required by a stated procedure, and reporting the task complete. The defining feature is the report: the claim of completion is in the output, and the completion is not. The skipped step underneath it is an omission, a silent failure; what makes it a hallucination is the report that the procedure was followed. It is named for the obligation that was not met, not for anything happening inside the model. Set out in full in [what procedural hallucination is in agentic workflows](https://agenticrail.nz/blog/procedural-hallucination-agent-skipped-steps/).

### Race condition

A defect where the outcome depends on the relative timing of operations that run concurrently. It is a standard term in computing and one of the most common causes of out-of-order execution in automated systems. A race condition lives in the system that has it, and only changing that system removes it. What a gate in front of each step can do is turn a lost race into a refused, recorded step instead of a silent wrong order.

### Execution drift

*Informal; not an established term.* Used for a running process gradually diverging from its intended order as volume and concurrency grow: rare at fifty runs a day, routine at fifty thousand. It names the trend rather than any single failure, and the single failures underneath it are the out-of-order and skipped steps above.

### Process desynchronization

*Informal.* The components running one process losing agreement about which of its steps have happened, so that one acts on a state another has not reached. A billing service charging for an account that the provisioning service has not yet created is the usual example.

## Why they hide

### Liveness versus correctness

In operations, liveness is whether a service is up and responding, and it is what health checks and uptime monitoring measure. Correctness is whether the right steps ran in the right order. A step run out of order returns success, so it reads as healthy on every dashboard. (In the formal sense used in distributed systems, liveness means that something good eventually happens and safety means that nothing bad happens. Step order is a safety property, which is the other reason liveness monitoring does not see it.)

### Silent failure

A failure that reports success: every call returns a success status, such as HTTP 200, while the process it belongs to has gone wrong. Silent failures surface late, at an audit, a reconciliation or a customer complaint, because nothing raised an error at the time.

## The controls

### Replay

The same step presented a second time, whether by an attacker, an automatic retry or a duplicate message. A sequence control refuses it, typically by requiring a value used only once per step (a nonce). Replay here means the refused repeat. It does not mean re-running an execution to reproduce it.

### Idempotency

The property that performing an action more than once has the same effect as performing it once. It makes a duplicate harmless. It does not establish order: an idempotent step that runs before its predecessor is still out of order, it is just out of order once.

### Sealing

Closing a sequence when its final declared step completes, so that no further step is accepted into it. A sealed sequence is finite, so it can be hashed whole, archived and cited as one object. Where each record is linked to the one before it by hash, a sealed sequence cannot be reopened or altered without leaving a detectable break.

### Conformance checking

A technique from business process auditing and process mining: declare the process model in advance, then compare a recorded event log against it, and the comparison reports what is missing or out of order. It is sequence verification after the fact. It finds a missing step only if that step would have been an event in the log, and it reports a fault once the step has already been skipped.

### Orchestration

Running a process through a component that makes the declared order the only available path, such as a workflow state machine or a durable execution engine. It is the right first move and it works. Its account of what happened is still its own record, written by the system that ran the process, so it enforces order without producing evidence that a third party can check independently.

### Workflow automation

Software carrying out the steps of a business process without a person between them. The term covers scheduled jobs, scripts and pipelines, no-code and low-code workflows, robotic process automation (software robots that operate applications through their user interfaces), and AI agents. They share the failures above. AI agents add one: a component that decides its own route.

### Independent record

A record of what a process did, produced by something other than the process itself and checkable without trusting the party that ran it. It is the same principle as segregation of duties: the part doing the work is not the part certifying that the work was permitted. A record written by the system under examination can be accurate, but it cannot be independent.

## Where AgenticRail sits

AgenticRail is sequence enforcement with an independent record. Each step of a process, whether it is run by an AI agent, a script, a scheduled job or a no-code workflow, is presented to the gate before it runs. The gate checks it against the declared order and returns `ALLOW` or `DENY`. Out-of-order steps, repeated steps and steps after the seal are refused, and every decision is written as an Ed25519-signed receipt, hash-linked to the one before it, that anyone can verify offline against published keys.

Two limits, stated plainly. It does not remove race conditions or fix the systems that have them: it refuses the step that arrives out of turn. And it only sees the steps that are presented to it, so a step that bypasses the gate entirely is not refused; it is the absence of its receipt, against the declared order, that shows it. For callers that read only the HTTP status, a refusal can be returned as HTTP 409 by adding `?deny_status=409` to the request, so a flow stops on its own. The rest is on [the product page](https://agenticrail.nz/product/) and in [the documentation](https://agenticrail.nz/docs/).

## Further reading

[The Completeness Specification](https://agenticrail.nz/spec/completeness/) — the eight requirements that separate an evidence-grade enforcement record from an ordinary log.

[When an AI agent skips a step, your audit log shows a clean run](https://agenticrail.nz/blog/ai-agent-skipped-steps-audit-logs/) — the skipped-step problem worked through.

[Orchestration versus enforcement](https://agenticrail.nz/blog/agent-orchestration-vs-enforcement/) — what each produces, and why they are not substitutes.

[Questions](https://agenticrail.nz/faq/) — including whether this works for automation that is not AI.

He toi whakairo, he mana tangata
