How to roll out a new AI agent prompt safely
To roll out a new prompt to a production AI agent safely, treat it like a code change without the deploy: keep every version, review the exact difference, have a second person approve it, test it on real recorded runs first, and keep a one-step way back. The agent then picks up the approved prompt on its next call, with no redeploy.
Why prompt changes are risky
A prompt is the agent’s behaviour. One edited sentence can change the tone, the facts it states, the tools it calls or the format your code parses, for every user at once. Unlike code, a prompt has no compiler and no type checks, and a hard-coded prompt only changes with a redeploy. So teams end up with two bad options: slow changes through engineering, or fast, unreviewed edits in production.
A safe rollout in five steps
- Version every prompt. Each change gets a number and a reason, so you can always answer “what was the agent told yesterday?”.
- Review the exact difference. Approve a word-by-word diff against the live version, not a summary.
- Use two people. The person who proposes a change should not be the only one who can approve it.
- Test on real inputs first. Run the current and the proposed prompt on recorded production runs and compare the answers.
- Keep a way back. Rolling back to a previous version should be as quick, and as reviewed, as rolling forward.
How Agent Control Panel handles it
- Prompt history. Every approved prompt is a numbered version with the proposer’s reason, and the dashboard marks the current one.
- Approval against the version it was written for. A proposed change waits for an owner or admin, who sees the word-level difference. If the live prompt changed in the meantime, the old proposal is closed as stale instead of overwriting newer work, and proposals older than 7 days expire.
- Scope. Prompt updates need the app’s full control scope. New apps start in monitor scope, which allows no commands.
- Testing Lab. Compares a baseline and a candidate against a recorded run of the agent. Applying a test result creates a normal prompt change, which still needs approval.
- Rollback. Choose a previous version in the history. The rollback is proposed as a new change and goes through the same approval, so no one can skip review by “rolling back”.
- Audit. Proposals, approvals, denials and expiries are recorded.
In your app, the agent reads the approved prompt before each call and keeps its own default as the final fallback:
Node.js
import { acp } from "./acp"; // createClient(...) + acp.start(), see the quickstart
const DEFAULT_PROMPT = "You are a helpful support assistant."; // shipped with the app: the last-resort fallback
export async function answer(question: string) {
// The approved prompt from ACP (cached 60 s), or the shipped default if ACP cannot be reached.
const system = (await acp.fetchPrompt()) || DEFAULT_PROMPT;
const model = acp.getEffectiveModel("gpt-4o-mini") ?? "gpt-4o-mini";
return acp.wrapAgentRun(
() => openai.chat.completions.create({ model, messages: [{ role: "system", content: system }, { role: "user", content: question }] }),
{ userInput: question, modelUsed: model },
);
}
Python
DEFAULT_PROMPT = "You are a helpful support assistant." # shipped with the app: the last-resort fallback
def answer(question: str):
# The approved prompt from ACP (cached 60 s), or the shipped default if ACP cannot be reached.
system = acp.fetch_prompt() or DEFAULT_PROMPT
model = acp.get_effective_model("gpt-4o-mini")
return acp.wrap_agent_run(
lambda: openai.chat.completions.create(model=model, messages=[
{"role": "system", "content": system}, {"role": "user", "content": question}]),
user_input=question, model_used=model)
The SDK caches the prompt for 60 seconds and gives up after 5 seconds, falling back to the last prompt it fetched, so a slow or unreachable ACP never blocks a run. Details: prompt versions, control scopes and approval and Skills Hub and Testing Lab.
Practical tips
- Change one thing per version, and say why in the reason field. It makes regressions easy to trace.
- If your code parses the output (JSON, tool calls), test that path specifically before approving.
- Watch the agent’s error rate and feedback for an hour after a change, and roll back on the first clear regression.
- Keep the shipped default prompt sensible: it is what runs if ACP is ever unreachable.
Frequently asked questions
Can I change an AI agent’s prompt without redeploying?
Yes, if the agent reads its prompt at run time. With Agent Control Panel, the SDK fetches the approved prompt before each call, so an approved change applies on the next call.
Who can approve a prompt change?
In ACP, organization owners and admins, on apps whose control scope is full. They see the exact word-level difference before approving.
What if two people change the prompt at the same time?
Each proposal is tied to the version it was written against. If the live prompt has changed since, ACP closes the older proposal as stale instead of overwriting the newer prompt.
How do I roll back a bad prompt?
Pick the previous version in the prompt history. The rollback is proposed as a new change and approved like any other, then applies on the next call.
What happens if ACP is down?
The SDK uses the last prompt it fetched, and your app’s own default prompt if it has none, so runs continue.
Related guides
- What is an AI agent control panel?: How it differs from a control plane, observability, gateways and orchestration frameworks.
- Switch an AI agent’s model without redeploying: Move an agent to another model, or another provider, in seconds, and what to check first.
- How to monitor AI agents in production: The signals that matter (liveness, errors, cost, quality) and what to do when one moves.
- Agent Control Panel vs Langfuse and LangSmith: Observing agents versus operating them, and when to use both.
- Daily spend caps and automatic pause for AI agents: Stop runaway token spend before the invoice: caps, loop detection and safe defaults.
- What is an agent control plane?: How it differs from observability and gateways, and when you need one.
- AI agent kill switch: How to stop or pause an agent in production, and what a trustworthy switch needs.
Next: connect an existing app, read the documentation, or request early access.