To understand how autonomous AI employees operate in practice, let's trace a real-world task inside Saturn AI. The user prompt: "Locate where user session tokens are validated in our Express API, refactor it to handle token expiry gracefully, and add unit tests covering expired token scenarios."
Step 1: planning and context assembly. The Coordinator Agent initializes a session and dispatches the Code Search Agent. AST and file-tree mapping pinpoints src/middleware/auth.ts and tests/auth.test.ts. The Coordinator then constructs a 3-step DAG: refactor the auth logic, run the existing suite for zero regression, and append new expired-token unit tests.
Step 2: isolated execution and firewall gate check. The Implementation Sub-Agent generates a file write tool call for src/middleware/auth.ts. Before it reaches the filesystem, Vark intercepts:
JSON
{
"tool": "file_write",
"args": {
"path": "src/middleware/auth.ts",
"content": "export function validateSession(req, res, next) { ... }"
}
}Vark evaluates the request across its gates. Gate 1 (Normalization) sanitizes Unicode payloads and verifies no hidden bidi characters. Gate 2 (Schema) verifies path and content types. Gate 4 (Policy) verifies write permissions for src/middleware/*. Gate 6 (Sandbox) performs a trial write inside an ephemeral virtual filesystem. Gate 7 (DLP) scans the replacement code for hardcoded credentials. Vark returns STATUS_ALLOWED, and the change lands on the local Git feature branch.
Step 3: verification loop and PR generation. The Test Runner Sub-Agent executes the suite through Vark's shell wrapper:
Bash
# Executed via Vark's execFile wrapper (shell: false) node --test tests/auth.test.ts
Exit code 0 means the Coordinator commits with a structured message; failures feed back into the Implementation Sub-Agent for immediate self-correction. Once every DAG step passes, Saturn AI opens a pull request containing clean diffs, verifiable test results, and a complete Vark cryptographic audit trace.
Keep reading the source
