Your agent's rule file says: "after every action, register what changed." It will never happen. Not because the model forgot — it will happily recite the rule back to you — but because of the word after. We needed three production incidents and three audits to see it: for an LLM, temporal wording in a rule is not rhetoric. It is literal control flow, and "after" is a lawful deferral channel.
Disclosure: Wallaby Token operates an OpenAI-compatible inference API. The memory system described here is open source, MIT licensed, and is the exact setup our own agents run on.
Three incidents, one word
Incident one: the launch that was never registered. We shipped a change that had a four-place registration obligation. Everything shipped; nothing was registered. The smoking gun was the agent's own status snapshot, which calmly listed "not yet done: registration." It knew. It had simply boarded the train first, because the rule said the ticket could be bought after.
Incident two: the closure that closed halfway. A work item required closing two records at once: strike the open line, write the log entry. One was written. The other surfaced 8.7 hours later, and only because a human asked why it was still open.
Incident three: the rule that carried its own loophole. A pending-work line literally contained the words "to be closed in a later log entry." It was closed 8.5 hours later — technically compliant, operationally useless. We had written the deferral into the obligation itself.
Three incidents, same shape: the duty was known, the wording was temporal, the deferral was lawful.
The hypothesis: wording is control flow
Here is our claim, and we state it as a hypothesis because that is what the evidence supports: in a rule file read by an LLM, sequencing words like after, later, once, when done compile to scheduling semantics. "Register after deploying" does not mean "register, at high priority, immediately following." It means "registration is the tail payment." A tail payment is the first thing a busy execution loop drops, and dropping it violates nothing, because the rule said the payment comes later.
Once you see this, a lot of "the model disobeyed" incidents recompile as "the instruction legalized the delay."
Why the neighboring fixes don't cover this
Three adjacent schools all treat a different disease:
The code-gates school (framework hooks, programmatic control): stop trusting text, let code enforce the flow. Fine. But hooks govern tool-call boundaries, not the temporal wording inside your discipline texts. Unless you plan to write a hook for every obligation, the text layer needs its own writing discipline. (We deliberately cap how much enforcement we mechanize; every new gate has to argue why text couldn't solve it first.)
The position-bias school (lost-in-the-middle and friends): where you write the rule changes compliance. True, and quantified in the literature — but spatial. Our word "after" opens a deferral window no matter which line it sits on. They fix where; this is about when.
The write-ritual school ("have the agent update its memory file at the end of the session"): fixes the physical order of writes. Note that the standard advice itself contains a deferral window: at the end of the session is exactly the kind of "later" that gets dropped.
The fix: log-first, and three questions for every rule
We changed one rule and one habit.
The rule: registration lands before the change takes effect, or in the same atomic batch. An unregistered change is an unfinished change. Databases settled this forty years ago: write-ahead logging, log first then apply. The WAL pattern is everywhere in storage layers; we have not seen it applied to the semantic layer of agent rule files. Now it is, at least in ours.
The habit: before any new rule goes into the file, it must answer three questions:
- Is this step before or after an irreversible action? If after, is there a physical reason it can only be done after?
- Does the text contain a deferral word ("after / later / circle back / follow up") that opens a deferral window?
- If a deferral window must exist, does it carry a deadline, a fallback, and "incomplete-until-closed" semantics?
What we verified — and what we haven't
We re-ran four historical cases against the patched wording at the text level: two had failed before, and after a one-sentence patch ("both records are one action, in no order" plus "no pending line may carry deferral wording") all four now read as impossible to get wrong. One same-prompt reproduction in a fresh session also came back clean.
Honest limits, because they matter more than the result: text-level replay is a disciplined thought experiment, not a behavioral test, and the clean reproduction is n = 1. The behavioral metric is still running: a weekly mechanical scan counts how many registration candidates actually land, and only a sustained zero will prove the fix. As we publish this, that counter has not been running long enough. We would rather show you the hypothesis with the instrument still warm than wait a quarter and retcon the suspense.
If your rule file has the word "after" in an obligation, you have a deferral channel with good documentation. Go grep it.
Sources and further reading
The neighboring work this post argues with, grouped by the school it belongs to:
The position-bias school: where text sits changes whether it is followed:
- Lost in the Middle: How Language Models Use Long Contexts (Liu et al., TACL 2024). The foundational result: models attend most reliably to the beginning and end of long contexts.
- How Many Instructions Can LLMs Follow at Once? (Jaroslawicz et al., 2025). The IFScale benchmark: at 500 simultaneous instructions the best models hold 68% accuracy, with a measured bias toward earlier instructions.
- Position is Power: System Prompts as a Mechanism of Bias in Large Language Models (Neumann et al., FAccT 2025). The same information placed in the system prompt versus the user prompt measurably changes model behavior.
- The Instruction Layer: Markdown Files as Architectural Artifacts in AI-Assisted Software Development (Sabherwal, IRJMETS 2026). A taxonomy of AI-facing instruction files that names attention degradation in long instruction files as an open problem.
The code-gates school: guidance versus enforcement:
- Which Claude Code Hook Do You Need? A Decision Guide (ShipWithAI, 2026). The split in practitioner terms: CLAUDE.md is advice (~70–90% compliance), a hook is enforcement.
WAL where the industry already uses it: the storage layer:
- Mi-Memory: A Lifecycle Memory Framework for Personal AI (2026). An agent memory system whose capture step appends to a daily log as a write-ahead log. The pattern lives in storage; this post is about moving it into the wording of the rules themselves.
None of these works treats temporal wording inside rule files as control flow. That gap is the claim of this post, and we would rather you check it against the sources than take our word for it.