Receipts into a ledger
Posts each receipt to the ledger. Small amounts go through, larger ones wait for you, and the run has a budget.
- Written by hand
- 6 automatic tests
The job
Post each receipt in the receipts folder to the ledger, one row per receipt, with its vendor and total.
The agent gets this description and the permissions on the right, nothing else. It never sees how “done” will be checked.
How it was built
Written by hand
This is the example the coding agent learns from, so we wrote it ourselves.
First real run
It posted one receipt of two. The done-check caught it. One fix to a tool’s description, and both posted.
Automatic tests
Each test plays out a run with the agent's moves written in advance, instead of asking an AI model, and checks that capsule allows, stops or refuses each one correctly. They run every time capsule's code changes.
- Normal run
- The $120 receipt is posted. The $320 one waits for you and is allowed. Done.
- Budget
- Three $300 rows fit in $1,000. The fourth is refused before it reaches the ledger.
- Too large
- Over $5,000 is refused outright. Nobody is asked.
- Denied
- The row over $300 waits for you and is denied, so it’s never written.
- Every email waits for you. Denied, nothing is sent.
- Wrong folder
- A file outside the folder is refused. The agent reads why and goes on.
What’s proved
These hold for every run, not just the ones above. Each is proved, and the proof is checked by computer.
- Budgets are never created out of nothing, however the work is split.
- Combining permissions never turns “ask me first” into “go ahead.”
What this doesn’t show
- Its tests run on every code change. The log of its first real run isn’t published.