How AI Agent Sessions and State Work in Production
A production agent needs separate ownership for request context, run state, sessions, durable business data, approvals, and audit events.
Treat agent state as layers with different lifetimes. Sessions are working memory; your application database remains the authority for business facts.
How Ai Agent Sessions And State Work In Production
Treat agent state as layers with different lifetimes. Sessions are working memory; your application database remains the authority for business facts.
{
"run_id": "run_123",
"state": "waiting_for_approval",
"operation_id": "op_456",
"next_step": "execute"
}Separate request from session
The current user message is request state. A conversation thread is session state. Do not assume the entire session should be attached to every model request; retrieve the smallest context that preserves continuity.
Keep business facts authoritative
Subscription status, account permissions, invoice totals, and product configuration belong in the application database. The agent can read those values but should not become the source of truth.
Make approvals durable
An approval should reference an exact operation, not grant general authority. Store the operation ID, requested action, approving user, timestamp, and current state so a retry cannot silently reuse a stale approval.
Make recovery explicit
Long-running tasks can stop between tool calls. Persist enough state to resume safely, and make external writes idempotent. A resumed run should continue from the last confirmed operation rather than repeating every previous side effect.
Design retention intentionally
Temporary runs, session transcripts, debug events, and long-term memories have different retention needs. Define deletion and access rules before the system becomes a data warehouse of agent traces.
Decision table
| Metric | Value | Note |
|---|---|---|
| State | Owner | Lifetime |
| Request | API | Seconds |
| Run | Agent worker | Minutes |
| Session | Conversation store | Days |
| Business fact | Database | Durable |
| Audit event | Audit store | Durable |
Practical checklist
- Separate layers
- Re-check before writes
- Operation IDs
- Approval records
- Retention rules
Final takeaway
Build the smallest workflow that proves the customer outcome. Keep tools narrow, business state authoritative, side effects permissioned, and the runtime observable. Agent infrastructure should remove manual work without turning your application into an uncontrolled automation layer.
Model the workflow as a state machine
NEW
↓
RUNNING
↓
WAITING_FOR_TOOL
↓
WAITING_FOR_APPROVAL
↓
COMPLETEDFailure states should be explicit too:
FAILED_RETRYABLE → RETRYING
FAILED_FINAL → ALERTED
CANCELLED → CLOSEDNow every transition has an owner. For example, only the approval service can move WAITING_FOR_APPROVAL to an executable state.
Re-check before side effects
An agent may have retrieved data several seconds earlier. Before an important write, fetch the authoritative state again. This matters for balances, inventory, entitlements, permissions, and deployments.
Tenant boundaries
Every state lookup should include the tenant or user boundary.
select *
from agent_runs
where id = $1
and tenant_id = $2;A session ID is an identifier, not an authorization token.
Sources
- https://developers.openai.com/api/docs/guides/agents/running-agents
- https://platform.claude.com/docs/en/managed-agents/sessions
Putting the idea into a production workflow
The practical question behind this topic is how to turn an AI capability into a dependable product component. Start by defining the job in terms of an input, a useful transformation, and an observable outcome. Avoid designing around the model first. The model is one component inside a workflow that also includes application state, tools, permissions, retries, logging, and user feedback.
For an article about How AI Agent Sessions and State Work in Production, a useful first exercise is to write the workflow as a sequence of states. Identify what the user provides, what the model needs to know, what information must come from a trusted system, which operations can change data, and what happens when the model is uncertain. This makes hidden assumptions visible before implementation.
Separate reasoning from authority
A model can interpret a request, classify information, draft a response, or choose between allowed capabilities. It should not become the source of truth for billing, permissions, account ownership, inventory, or destructive actions. Those rules belong in application code. A useful architecture therefore has a clear boundary: the model proposes an action, a typed tool validates it, the application authorizes it, and the system records the result.
This boundary also makes testing easier. Instead of asking whether a model response sounds good, test whether the right tool was selected, whether arguments were valid, whether authorization was enforced, and whether the workflow reached the expected terminal state.
Design for failure from the beginning
AI systems fail differently from ordinary deterministic services. A response can be syntactically valid but semantically wrong. A tool can time out after the external service has already accepted the request. Retrieval can return stale information. Context can become too large. A retry can accidentally repeat a side effect.
Use explicit limits for turns, latency, token usage, and tool calls. Give side-effecting operations idempotency keys where possible. Store enough trace information to reconstruct the run without storing unnecessary private data. When the system cannot safely continue, return a useful fallback or ask for human intervention rather than silently guessing.
Build a small evaluation set
Before launch, collect representative cases rather than relying on a handful of demos. Include normal requests, ambiguous requests, missing data, malformed tool arguments, permission failures, provider errors, and adversarial inputs. Track task success, tool accuracy, latency, cost, and recovery rate. Re-run the same cases after changing the model, prompt, retrieval system, or tool schema.
A practical implementation sequence
- Define one repeatable customer job.
- Write the expected successful outcome.
- List the minimum context required.
- Expose only the tools required for that job.
- Keep authorization outside the prompt.
- Add timeouts, retry limits, and idempotency.
- Capture traces and cost per completed task.
- Create failure cases before production.
- Add a human checkpoint for high-impact actions.
- Review real runs and improve the workflow from evidence.
The goal is not to make the agent appear autonomous. The goal is to make a useful workflow reliable enough that a customer can trust its outcome. Start narrow, keep business rules deterministic, measure the complete job rather than only the model response, and expand the tool surface only when the existing workflow is demonstrably stable.
Community
What do you think?
0 comments
React to this article
Comments
Trending now
What readers are opening
Written by
Kirtesh Admute
Founder
Kirtesh Admute is the founder of IndieFounder, a platform for founders, builders, and people curious about technology. He writes about AI, startups, software, product building, and the lessons that come from building in public.
See an issue with this story?
Continue reading