Method

What Breaks If You Remove a Plane

Answer capsule

Red First published nine planes for every agent - a member of staff made of software - on 11 August 2026: Soul, Knowledge, Skills, Capabilities, Listeners, Connections, Surfaces, Heartbeats, Guardrails. That list only holds if taking any one of them away, from an agent specified to use it, breaks the job or makes the output worse. This piece runs that test, and records why the nearest neighbouring plane is not a replacement.

Built from the last job they shipped

Most people building an agent have never seen our nine planes model (unless they have been an avid reader here which may be unlikely). They build from what they already know how to do: a prompt, a model, a couple of tools, perhaps a chat window. It is the last job they shipped, done again, tweaked and perhaps improved. That's a perfectly normal implementation plan.

We published our agent parts list in The Anatomy of an Agent S1. It's our anatomical description of the required elements to build an agent. Until someone puts that list in front of a builder, the missing planes are not cuts. They are questions that were never explicitly asked. Some, perhaps most will be handled in the build. But there will often be gaps, blank spaces in our nine planes. These gaps are unlikely to show up during the build. Blanks become visible in failure modes over time.

Some of those blanks are the right call for a first version. Anthropic's advice is to start with the simplest system that works S2, and that advice is sound. A credit controller that only drafts a reminder for a person to send is a skateboard. It is not yet the colleague that watches the ledger, sends on a timetable, and escalates at day thirty. You build the skateboard and iterate towards the car. What the anatomy asks is that you write which planes are on the skateboard, and which wheel comes next.

The cost of not writing them is the same whether the gap came from not knowing or from a first version left unnamed. The live ledger is not memory. The tool is not the procedure. The clock is not the sensor. Mail leaving is not a workplace. The agent still runs. The job is thinner than the hire implied, and nobody can see which organ was meant to come next.

An agent, on our definition, is a member of staff made of software S1. You would not take on a credit controller who had never been told the handbook existed, and call that week one. You would write what they know today and what they will be trained on. The planes are that list.

Take one plane away. Does the job survive?

We created a simple test to challenge our own thinking about the nine planes. Is it overengineered, is it necessary, is there a simpler, neater way. So, take one plane away from an agent that was specified to use it. If the job breaks, or the output gets worse than having the plane, the plane had to be there. The loss does not have to be universal. A workaround does not defeat it. A newly created limitation is not a pass.

A missing plane can mean three different things.

  • None. The job does not need it, and you wrote that down. This agent does not watch a queue, does not send mail, does not move unless asked.
  • Not yet. The skateboard. V1 drafts, a person sends, the heartbeat comes in the next pass. Also written down.
  • Unasked. Nobody put the question, or a neighbour is standing in for the organ. That is the case the test is for. A blank answer is still an answer S1. An unasked one is the decision made by accident.

A neighbour can carry a first version. It is not a replacement. Put the work on the plane that was meant to do it.

Soul → Guardrails. A deny-list is not an identity. Banning threats does not decide collect-versus-relationship, house voice, or duty of care. Soul says who this is. Guardrails say what it may not do.

Knowledge → Connections. A live read is today's state, not a maintained base or a memory of past exchanges. It adds outage, drift, and inconsistent retrieval that a stable, consistently retrieved base does not carry. Nothing compounds.

Skills → Capabilities. Tools are equipment. A procedure is training. Two agents can hold the same hands; only one knows the month-end pack. "Give it more tools" is the standard fix for an agent that was never trained for the job S1.

Capabilities → Connections. A pipe without declared hands sits idle, or acts through implied tools nobody listed. Reach is not permission to act. The connection is whose credentials; the capability is what those credentials may invoke.

Listeners → Heartbeats. A clock poll is delayed perception. It misses what happens between ticks - the Friday evening enquiry, the stock-out at four. Watching a signal is not waiting for the next scan.

Connections → Capabilities. Hands without a named, revocable identity either fail at the boundary or fire under someone else's login. A tool list is not a pipe, and it is not an identity you can revoke in one place.

Surfaces → Connections. Mail leaving is not a workplace. Sending is not where a person reviews, approves, corrects, or lands an escalation. An outbound connection delivers work; it does not let people work with it.

Heartbeats → Listeners. An event trigger is react-to-signal, not a declared timetable. Recurring duties - the seven o'clock cash position, the Friday sweep - still wait if no event fires. On-demand is an assistant.

Guardrails → Capabilities. Not granting a tool is not a policy. It does not escalate, it does not disclose, and it does not name who may change the agent. A missing credit-note button is not a day-thirty handoff.

Russell and Norvig's 1995 definition still sits underneath: an agent perceives through sensors and acts through effectors S4. Listeners are the sensor half. Capabilities are the effector half. Drop either, and you have not simplified an agent. You have built something else and kept the word.

Nine removals, nine thinner jobs

Apply that test to each plane in turn. The scenes below are illustrations of jobs a small business already runs. They are not real clients (obviously), and they make no performance claims.

Soul

Identity, doctrine, and tone go unset. Two agents with the same tools become interchangeable. Priorities and register drift.

  • Credit control and customer success share the same ledger access. One should collect firmly; the other should protect the relationship. Without Soul they chase or soothe at random.
  • A marketing agent loses house voice and banned phrases. Drafts leave the brand, and lines like "guaranteed" or a competitor swipe ship in the first pass.
  • An HR onboarding agent has no stated duty of care. It chases a missing passport photo in the same register it would use for a disciplinary warning.

Knowledge

Stable, maintained facts and compounding memory are gone. Every turn is a blank slate or a live read with its own failure modes.

  • A service desk forgets the last three tickets. The fourth call starts from zero and the customer restates the outage history.
  • A credit controller does not remember the first two reminders. The third note restates terms the customer already answered.
  • An HR onboarding agent does not know the handbook or where each starter has got to. It re-sends the full pack instead of chasing the one missing document.

Skills

Named procedures are gone. Order, contents, timing, and register become a gamble on each run.

  • Finance month-end has no written pack procedure. One run misses accruals; the next includes the wrong entities; the output does not match last month.
  • A sales quote follow-up sequence is improvised. Some quotes get three notes in a week; others go cold.
  • Credit-control cadence (seven days before, due date, then seven, fourteen, twenty-one) collapses into one generic chase with no per-step register.

Capabilities

The hands are gone. The thing can talk and cannot act. It is a chatbot.

  • An invoicing agent cannot raise a draft invoice. It describes what the invoice should say; someone still keys it.
  • A procurement agent cannot raise a supplier order below the threshold. It writes a recommendation the buyer retypes.
  • A credit controller cannot send from the mailbox or flag an account. It narrates the aged debt and nothing moves.

Listeners

It no longer perceives the business. It sees only what a person types.

  • A sales agent is not watching the shared inbox. The Friday evening enquiry sits until Monday, when someone pastes it in.
  • An operations agent is not watching stock. The reorder point is crossed and the fitter finds the shelf empty.
  • A credit controller is not watching the ledger or the mailbox. Invoices age out and replies sit unread until the owner asks.

Connections

Named, revocable reach into company systems is gone. Actions fail, or they happen under someone else's login.

  • A bookkeeping agent has no named identity in the accounting package. Entries look like the bookkeeper's, and you cannot revoke the agent without revoking the person.
  • A scheduling agent has no calendar connection. It proposes times it cannot write - or it writes with the owner's full calendar rights.
  • A credit controller has no mailbox of its own. Reminders go from the owner's personal address, or they do not go.

Surfaces

The place people work with it is gone. Review, approval, and correction have nowhere to happen.

  • The finance director has no month-end review panel. Drafts exist; approvals have no workplace; the pack is locked blind.
  • The warehouse has no morning pick list on the wall screen. The stock agent is running; the floor cannot see the work.
  • Credit control has no Monday aged-debt panel and no per-account thread. The owner cannot review a chase or land an escalation.

Heartbeats

Unprompted scheduled action is gone. Recurring duties wait for someone to type.

  • No seven o'clock cash-position summary. The owner opens the day without the number.
  • No Friday pipeline sweep. Stalled deals sit until someone remembers to ask.
  • No first-of-the-month contract notice scan. Notice windows close before anyone is told.

Guardrails

Bounds, escalation, disclosure, and who may change the agent are gone. It becomes an experiment. Gartner's inadequate risk controls is this plane missing in the wild S3.

  • A credit controller issues a credit note, agrees a payment plan, or skips the day-thirty handoff to the owner.
  • A marketing agent publishes the week's posts instead of drafting them for approval.
  • Nobody is named as the only person who may change the agent. It rewrites its own brief in production.

The credit-control agent from the anatomy essay is the cleanest single walk-through, because the other eight entries stay as written S1. Remove Soul and it may apologise, threaten, or sound like customer success. Remove Knowledge and the third reminder does not know the first two; a live ledger read still cannot remember a conversation. Remove Skills and the seven / due / fourteen / twenty-one cadence becomes a gamble. Remove Capabilities and it can only talk about the debt. Remove Listeners and it waits for the owner to paste an invoice. Remove Connections and it cannot read the ledger or send from the mailbox under its own name. Remove Surfaces and the reminders may still leave, while the Monday panel and the per-account thread are gone, so review and escalation have no workplace. Remove Heartbeats and there is no eight o'clock scan, no Friday aged-debt run, no month-start statements, unless someone types. Remove Guardrails and it may issue the credit note, agree the plan, skip day thirty, or edit its own brief.

In every case the thing that remains can still produce tokens. That is not the test. The test is whether the job you hired it for is still the job.

None and not-yet are answers. Unasked is not

For an owner, the test is a buying question before it is a design one. Before you sign for anything sold as an agent, ask for the nine answers in writing. A first version may say not yet against half of them. That is a skateboard you can inspect and you can choose an iterative approach if that is right for you. A page that never asks the questions, or that treats a neighbour as the finished organ, is the gap we've identified. A genuine vendor can still produce the page. A rebranded chatbot cannot.

For a build, write the nine. Empty is allowed when the job does not need that organ. Not yet is allowed when you are iterating towards the next one. Say so, on the page, before the thing starts work. What is not allowed is never asking, or calling the neighbour good enough and stopping there. It will bite you later. Value compounds when Knowledge is maintained. Risk is governable when Guardrails and Connections are named. Cost stays inside an envelope when Capabilities and Heartbeats are declared. Those are the same three properties Gartner named as cancellation causes, missing S3.

Every agent we ship inside RedOS carries all nine planes declared before it starts work, including the ones whose honest answer is none, and the ones whose honest answer is not yet. The declaration is visible on one screen. That is the discipline, not a longer prompt.

An agent is still nine written answers. The ones that were never asked are the ones that change the job when you finally need them. Write them, including none and not yet, before the thing starts work.

Sources

  1. S1 Tier 1 · primary red-press-piece
    The Anatomy of an Agent
    Red Press · Mike Jones · 11 August 2026
    A blank answer is still an answer - it means the decision was made by accident.
    Supports Nine planes declared 11 August 2026; occupational definition; blank answer is still an answer; credit-control one-page illustration; job-description mapping
  2. S2 Tier 1 · primary company-disclosure
    Building effective agents
    Anthropic · Erik S., Barry Zhang · 19 December 2024
    dynamically direct their own processes
    Supports Workflow vs agent distinction; advice to start with the simplest system that works - used as a legitimate first version, written as not-yet, not as an unasked plane
  3. S3 Tier 1 · primary analyst-press-release
    Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027
    Gartner · Gartner Newsroom (analyst: Anushree Verma) · 25 June 2025
    are early stage experiments or proof of concepts
    Supports Inadequate risk controls as a named cancellation cause - Guardrails missing in the wild
  4. S4 Tier 1 · primary research-paper
    Fully Autonomous AI Agents Should Not Be Developed
    arXiv (2502.02649) · Margaret Mitchell, Avijit Ghosh, Alexandra Sasha Luccioni, Giada Pistilli · 2025-02
    Supports Compiled canonical definitions: Russell & Norvig 1995 sensors/effectors - Listeners as the sensor half, Capabilities as the effector half

If you want those nine written for your own agents, a Red Brief is where that starts.