Agents Honestly
Appendices

Sources and Attribution

Every source this book leans on, and the terms it leans on them under.

Further Reading is a short curated list, the sources worth your time. This page is the other thing: the complete record of what informed the book, and the statement of how it uses material it did not write.

Everything listed here was read directly, either during the writing or as the source of a claim the text makes. Search results that were surfaced and never opened are not listed, because listing them would claim a consultation that never happened.

How this book uses other people's work

Four rules held throughout:

Findings are reported, not reproduced. Where a source measured something, the book states the measurement, names who measured it, and links to where you can check. It does not reproduce the source's tables, figures, or substantial passages.

Quotations are short and marked. Where the exact wording matters, such as a spec's normative sentence or a paper's definition, it appears in quotation marks with its origin named in the same sentence.

Every number carries its provenance. If a chapter says 15×, 41–86.7%, 125 ms, or k ≈ 60, the source is named where the number appears and linked here. Numbers the book chose for illustration are labelled illustrative, and are nobody's finding.

Specs are paraphrased, not copied. The protocol and standards chapters describe mechanisms in the book's own words, then send you to the normative text. That is deliberate: a paraphrase that disagrees with the spec is the book's error to fix, and a copy that goes stale is a trap.

Same posture as the rest of the book

These are pointers to go and check the current state, not settled facts. Specs are versioned by date and move; papers get superseded; vendor documentation changes without notice. Where a source has a version, that is the version this book read.

Trademarks

Anthropic and Claude, LangChain and LangGraph, Temporal, Vercel and the AI SDK, OpenAI, Microsoft, Google, Amazon and Firecracker, Stripe, PostgreSQL, Neo4j, Playwright, OWASP, and NIST are the marks of their respective owners.

Their use here is nominative: naming the thing under discussion, as a book about building on these systems has to. It implies no endorsement, affiliation, or sponsorship in either direction.

Licenses of the sources

Verified at the time of writing. Where a license could not be confirmed from the source itself, the row says so rather than guessing.

SourceTermsWhat that permits here
Model Context Protocol specificationApache 2.0 (with earlier MIT contributions; docs CC BY 4.0)Description and attributed quotation
A2A protocol specificationApache 2.0Description and attributed quotation
OpenTelemetry semantic conventionsApache 2.0Attribute names quoted directly
OWASP GenAI contentCC BY-SA 4.0Attributed reference; the book paraphrases rather than adapts, so no share-alike obligation attaches
NIST publicationsUS public domain, except items marked otherwiseQuotation and description, with NIST credited
W3C specifications (WCAG, ARIA, WebRTC, RDF, SPARQL)W3C Document LicenseAttributed quotation of normative text
IETF RFCsIETF Trust Legal Provisions (BCP 78)Attributed quotation, see the source for the full grant
arXiv papersPer paper, chosen by the author (CC BY, CC BY-SA, CC BY-NC-SA, CC BY-NC-ND, or the arXiv perpetual non-exclusive license)Findings reported and attributed; check the individual paper before reusing its text or figures
Vendor documentation and engineering blogsEach publisher's own termsShort attributed reference and description only
Temporal design patterns catalogNot stated at the sourceDescription and attribution only

Nothing in this book is a derivative work of a listed source. Where the book agrees with a source it says so and cites it; where it disagrees, and it does, in places, it says that too, and the disagreement is the book's own.

The sources

Models and the API surface

Retrieval and knowledge

Agent loops and graphs

Tools and workspaces

Protocols

Durable execution

Interface, accessibility, and trust

Evals

Observability

Reliability

Security

Governance and regulation

Multi-agent

Secondary sources

One entry, listed for completeness rather than because the book relies on it:

What has no source

Most of this book. The layering argument, the determinism test, the risk-tier framing, the pattern catalog and its fixed shape, the Atlas running example, the decision tables, and the failure stories are the book's own work. Where a chapter reasons rather than reports, it carries no citation, and that absence is a claim of authorship, not an omission.

The same applies to every judgment call the book records. FrameworkCheck exists precisely to mark the places where defensible implementations disagree and the book picked one. Those picks are arguments, and they are answerable to you rather than to a source.


Found something misattributed, or a source that should be credited here and isn't? That is a bug, and it is worth reporting as one.

On this page