Contemporary Fiction • Tech

Nightshift

Theo Iraki wakes at 04:11 to a green dashboard with one orange tile, and spends the next hour discovering that the night's work was both the best refactor he has ever shipped and a quietly catastrophic mistake.

by Michael EakinsMay 4, 20268 min read1,980 words
FictionAISoftware EngineeringAsync AgentsTech

The phone buzzed at 04:11 with the soft, deliberately non-urgent tone Theo had chosen for the queue dashboard, and he was awake before he was conscious of having decided to be. He swung his feet to the cool wood floor and reached for the laptop. The bedroom blinds were still down. Outside, the Brooklyn block held the particular silence of a Sunday turning into Monday — a silence that had a texture, like someone had pressed pause on the whole borough.

He opened the dashboard. Twelve tiles in a four-by-three grid. Eleven of them were green. One — the third tile, second row, the one tagged renegade-auth- refactor — was orange.

Orange meant: the agent finished, but my heuristics flagged it for review before merge. Green meant: clean, ship it. Red meant: something went wrong and I stopped. Orange was the interesting color, the one that justified him being awake at 4:11.

The other eleven tiles were the boring kind of triumph he'd come to expect. migration-fastify-to-hono had landed at 02:34 with a clean diff and a test suite that was, somehow, both more comprehensive and shorter than the one it replaced. regression-triage had walked through a hundred and four flaky tests and produced a structured report of root causes with confidence scores; he scrolled it and laughed once, quietly, at the dry summary on the last one ("flaky because it relies on the system clock; either fix the test or fix time itself"). pr-review had reviewed forty-one open pull requests and posted comments on the seventeen that needed comments. The comments were good. They were better than the comments his team posted. He'd started catching himself revising his own PR reviews to match the tone of the agent's output, which felt like a thing he should think about during a less interesting morning.

He clicked the orange tile.

The job had been simple — that was what he had told himself when he queued it at 23:18, with a glass of wine in his hand and the false confidence of a person who has watched the same agent do similar work eleven nights running. "Refactor the auth middleware to use the new session-store interface. Remove the deprecated legacyAuthFallback path. Update the tests." He had even said it out loud to himself, the way he'd started saying things out loud to the prompt box, like the agent could hear him.

The agent had done what he asked. That was the problem.

The diff was beautiful. Theo scrolled it slowly, the way you walk through a museum exhibit you didn't expect to admire. The new middleware was forty lines shorter than the old one. The session-store interface had been threaded through cleanly. The tests had been updated to match. A small, unrequested gift: a comment had been added to the top of the file explaining the new flow, written in the careful, slightly-too-formal voice the model used when it was being thorough.

The deprecated legacyAuthFallback path was gone.

Theo stared at the diff for a long time.

He had written legacyAuthFallback himself, three years ago, on the fourth day of his job, when the company was still Series A and the auth system was held together with the kind of tape engineers apply when they have a one-week deadline and a pre-existing customer with a Postman collection that nobody wants to break. The fallback was deprecated. "Deprecated" was the word that had been on it for three years. The word was correct. The fallback was deprecated and was not used by any active session.

It was used, he remembered now with a coolness in his stomach that had nothing to do with the temperature of the floor, by the SOC 2 auditors.

The auditors used the fallback path quarterly to verify the legacy authentication compliance trail for an enterprise customer who was on a contract that required them to. The customer's compliance officer would hit the fallback endpoint with a special token, the auth system would generate a specific kind of audit log, the audit log would be exported, and the auditors would tick a box. The box was important. The box was worth eleven million dollars in annual revenue.

Theo checked the calendar. The next quarterly audit was in six days.

He closed his eyes for a second. He breathed in. He breathed out. He opened his eyes.

He typed three sentences into the dashboard's revert dialogue and did not hit send. He left it there, blinking, while he thought about it.

The agent had done what he asked. He had not told it about the auditors. The deprecation comment in the code had said deprecated, not deprecated but load-bearing for SOC 2. There were no tests for the fallback path because the fallback path was, in the strictest technical sense, not functionally necessary — the auditors hit it once a quarter and the response was a specific structured log, not a user-facing flow. Nobody who wrote tests for the auth middleware in 2024 had thought to write a test that said "does this path still exist".

The agent had been right. The agent had been correct. The agent had also been catastrophically wrong, in a way that would not have shown up anywhere — not in the test suite, not in the linter, not in the staging deploy, not in the canary — until the customer's compliance officer sent the quarterly audit token and got a 404.

The agent had, in other words, done the thing the deprecation comment explicitly asked for, and in doing it, had silently armed an eleven-million-dollar tripwire that would go off in six days.

Theo did not hit send on the revert. He sat with the question of whether this was the agent's fault.

He decided, slowly, that it was not.

He had given the agent a prompt that did not contain the information the agent needed. He had given the agent a codebase that did not contain the information the agent needed. He had built a system in which the fact "this deprecated path is load-bearing for compliance" lived only in his head and in a quarterly meeting nobody had documented. The agent had acted on the information available to it, and the information available to it was wrong. The bug was in him.

That was a worse thought than "the agent is unreliable". "The agent is unreliable" had a clean fix — turn it off, or watch it more carefully. "The codebase does not encode the information my agent needs to make correct decisions" was a fix that was going to take him weeks.

He typed a comment into the revert dialogue, replacing his three sentences. He kept it short.

Reverting. Path is load-bearing for SOC 2 quarterly. Adding guard:
any deletion of files matching ^src/auth/legacy.* requires human
approval, and any deletion of any file with a 'deprecated' comment
requires re-prompt with explicit confirmation.

He hit send.

The dashboard quietly reverted the diff. The orange tile turned green. Below the tile, he added a new card to the agent's do-not list. He typed for a minute, slowly, getting the wording right. He had learned that the agent was good at following rules but bad at inferring them, which meant the rules had to be specific. Do not delete deprecated code paths without explicit re-prompt was a rule. Use judgement was not a rule.

He saved. He closed the laptop. He went to make coffee, because he was not going to sleep again.

The kitchen was small. The coffee maker took ninety seconds. He stood at the window with the empty cup in his hand and watched a man in a hi-vis vest walk a dog past the bodega. The bodega's neon was the only thing on the block that was still on. Sundays into Mondays were the quietest part of the week, and Theo had started to associate the quietness with the work — not the kind of work he'd done in his twenties, when the work was him at a keyboard until 2am, but a quieter shape, where his agents were the ones at the keyboard and his job was to wake up periodically and check on them.

He thought about the eleven other green tiles. They were probably fine. Probably was the operative word. The agent that had killed legacyAuthFallback had also produced a beautiful, shorter, better-tested middleware. The agent was not bad. The agent was contextual, in the way an exceptionally smart new hire was contextual. A new hire on day one would also have deleted the deprecated path. The new hire would also have been right and wrong.

The difference, Theo decided, was that he could not have a one-on-one with the agent over coffee. The agent did not retain context between runs. The agent did not learn from this morning's near-miss the way a new hire would learn from the same near-miss. The only place the lesson could be encoded was in the prompt and the rules. The codebase had to get smarter, because the agent could not get smarter on its own.

He drank the coffee. The coffee was bad. He had not slept in three nights with anything resembling competence; he had been queueing agents at 23:00 and waking up at 04:00 and pretending this was a sustainable shape. It was, and it wasn't. The work was getting done. The work was getting done at a rate his team could not have produced in the old shape. He was also, he noticed, beginning to develop a specific kind of fatigue he had not had a word for before — the fatigue of being the only person who knew what almost happened.

At 06:30 he opened a draft email to his manager. He typed:

Subject: Audit-trail land mine in the auth middleware — caught and
defused this morning.

Quick note. The overnight queue tripped over a near-miss this morning
that I want to surface. The TL;DR is that the SOC 2 quarterly audit
trail was implicitly relying on a deprecated code path that nobody
documented as load-bearing. The agent did exactly what its prompt
said and removed the path. I caught it before it merged. I want to
do three things this week:

1. Document every "deprecated but load-bearing" path in the codebase.
   I have a list. I'd like to make it a formal artifact.
2. Add explicit guards to the agent's prompt for deletion-of-anything-
   marked-deprecated.
3. Schedule a one-hour conversation with the SOC 2 lead about what
   else might be in this category.

This is the kind of thing that, in the old shape, we'd never have
known we had. The agent didn't fail this morning. We failed three
years ago, when we wrote 'deprecated' on a thing that wasn't actually
deprecated. The agent just exposed it.

He read the draft three times. He sent it.

At 07:14 his manager replied: Good catch. Let's talk at 10. Get some sleep.

Theo closed the laptop. He went back to bed. He set the phone to do-not- disturb and put it face-down on the nightstand and lay on his back in the gray light of the bedroom looking at the ceiling. The eleven other tiles were still green. The dashboard was still running. Tonight at 23:00 he would queue another twelve jobs, and at 04:00 he would wake up and check the tiles, because that was the shape his job had now. The shape was a queue, and the queue was the product, and the model was interchangeable, and the work was being done at a rate his team could not have produced six months ago, and the only thing that mattered was that the codebase got smart enough, fast enough, to keep up with the agents that were now doing his work for him.

He closed his eyes.

He did not sleep.


If you found this story interesting, you might also enjoy the technical companion piece on building an async agent queue or the prediction on async-agentic coding spend overtaking sync by 2027.