Case study · our own production host

A research agent that cannot fabricate

Hallucination is usually treated as a model problem. We treat it as a data-layer problem: findings and claims live in separate append-only ledgers, every entry carries a source, and the research agent is forbidden from producing a hypothesis.

Get my free blueprint

how to stop an AI research agent fabricating sources

Stopping an AI research agent fabricating sources is a storage problem before it is a prompting problem. Require a source and URL field on every recorded finding, keep checkable claims in a separate ledger carrying explicit verification state, forbid the agent from producing hypotheses, and make an empty run a valid outcome. Under that rule our own agent has written 721 findings and 310 claims, every one carrying a source.

Observed on the studio's own production host on 27 July 2026: 721 findings and 310 separately-ledgered claims, every entry carrying a source. This is the studio's own corpus, not client research.

Measured on our own production host

Measured on our own production host — observed on Our own production host — a 19-agent Hermes fleet on one Fedora 42 VPS (4 vCPU / 15 GiB), surveyed read-only over SSH, 27 July 2026
Findings loggedEach stored with topic, body, source, URL, confidence, relevance and timestamp721
Claims ledgeredExtracted from the findings and tracked through a verification state machine310
Daily collection runsAn RSS pass at 01:30 and a GitHub pass at 01:45, each following a documented runbook2
Entries carry a sourceThe schema will not hold a finding without a source and URL100%
Skills defined for the research agent24
Sessions logged by the pattern-detection agentThe only agent allowed to interpret the corpus; the research agent may not22

Source: Our own production host — a 19-agent Hermes fleet on one Fedora 42 VPS (4 vCPU / 15 GiB), surveyed read-only over SSH. Observed .Line counts read off the two ledger files. Volume and schema discipline are evidence of the constraint holding, not of the research being valuable.

The insight: separate what you saw from what it means

Most research agents produce one blob of output that mixes three different kinds of statement: things a source actually said, things the agent inferred, and things the agent invented to make the paragraph flow. Once they are in the same paragraph you cannot tell them apart, and neither can anyone downstream.

So we split them at the storage layer, before they can contaminate each other. Two append-only ledgers with different schemas and different rules.

The two ledgers

Findings — what a source said. 721 entries at survey time. Every one carries:

topic · body · source · url · confidence · relevance · ts

Claims — checkable assertions extracted from findings, tracked through verification. 310 entries. Every one carries:

claim · topic · source_url · confidence
verification_needed · verification_outcome
extracted_at · verified_at

The two fields that make this more than bookkeeping areverification_needed and verification_outcome. A claim is not published because it was extracted — it is published because it was extracted, flagged for checking, checked, and the outcome recorded. There is a state machine here, not a text file.

Note the ratio: 721 findings produced 310 claims. Fewer than half of what the agent read survived as a checkable assertion. That gap is the discipline working.

The four hard limits

The research agent's own instructions read like a compliance document, deliberately. Verbatim:

None of that is a prompt trick. It is a mandate plus a schema that refuses malformed entries. The agent cannot fabricate because there is nowhere to put a fabrication.

Where the data comes from

Two collection runs go out every night — an RSS pass at 01:30 and a GitHub pass at 01:45 — each following a documented runbook rather than a freeform instruction. A separate collection agent covers community sources with its own runbooks per platform: Hacker News, Reddit, Lobsters, dev.to, and GitHub trending, plus procedures for sentiment analysis, trend detection, and pain point extraction.

Everything they gather lands in the same two ledgers under the same rules. There is no side channel where uncited material can enter the system.

What happens after: interpretation as a separate role

Because the researcher is forbidden from theorising, we needed something that does. A separate agent reads across the accumulated ledgers over time and looks for what the daily view cannot see: "You connect findings from this week with patterns from last month. You notice what's quiet that used to be loud, what's loud that used to be quiet, and what keeps coming back."

It carries five runbooks for different kinds of pass — a retrospective, and four styles of traversal across the corpus including a drift walk and a tangent walk. Its output feeds the approval gate, not the publishing pipeline, so an interesting pattern still has to be approved before anything is built on it.

That is the full separation: one agent that may only report what it saw, another that may only interpret, and a human gate between interpretation and action.

What this case study does not prove

What we would carry into your build

If an agent's output is going to inform a decision, the architecture matters more than the prompt. Separate observation from interpretation into different agents. Give every recorded fact a mandatory source field so an uncited claim is structurally impossible. Track verification as state rather than as prose. And make an empty run a legitimate outcome, because an agent that must produce something will invent something.

That is a data-layer answer to hallucination, and it works regardless of which model you run — or which framework. The same mandatory-source schema drops into aLangGraph state graph or into any of theCrewAI alternatives without changing shape, because the constraint lives in the store rather than in the orchestration.

If someone else is going to build it for you, this is also the thing to interrogate them about: the questions worth asking an AI agent developer start with where an uncited claim would be allowed to land.

Questions

How do you stop an AI research agent from hallucinating?

Make fabrication structurally impossible rather than discouraged. In our system every recorded finding requires a source and URL field, checkable claims live in a separate ledger with verification state, the agent is forbidden from producing hypotheses at all, and an empty run is a valid outcome. An agent under pressure to produce something will invent something — removing that pressure is the fix.

What is the difference between a finding and a claim?

A finding is what a source actually said, stored with its source, URL, confidence, relevance and timestamp. A claim is a checkable assertion extracted from findings, stored with verification_needed and verification_outcome fields so it moves through a verification state machine before anyone relies on it. Our 721 findings produced 310 claims — fewer than half survived as checkable.

Why separate the research agent from the analysis agent?

Because an agent allowed to both observe and interpret produces output where you cannot tell which is which. Ours is explicitly barred from theorising — "you produce hypotheses NEVER" — and a separate agent reads across the accumulated corpus over time to find patterns. Its output feeds a human approval gate, not the publishing pipeline.

Do confidence scores on AI agent output actually mean anything?

Only if calibration is enforced. Our research agent is instructed to tag every finding and claim and explicitly not to tag everything high, because a confidence field where every value is "high" carries no information. We enforce it as a rule rather than trusting the model to self-moderate — though we have not published a formal calibration study.

Amit Kumar

Founder of I Am Agent Man. Builds and runs production AI agents on Hermes, OpenClaw, and MCP — self-hosted, model-agnostic, with persistent memory and hard cost ceilings.

Need research you can actually cite?

Tell us what you need to know on a schedule. We'll scope the collectors, the ledger, and the verification path — free, before any invoice.

Goes straight to hello@iamagentman.com — we read every message ourselves. Prefer to answer three questions instead?Build your blueprint.

Talk to the studio

One message · reply within one business day