← 返回日报
精读 预计 3 分钟

Handbook.md shows that long policy documents do not reliably govern agents

摘要

论文提出 HANDBOOK.md 基准,用 65 个模拟企业员工遵循公司手册的代理任务,测试长上下文指令遵循能力。每个任务包含 20 至 124 页的标准操作程序,覆盖财务、医疗账单、保险、物流和 HR 五个领域。严格评分下,最佳模型配置通过率仅 36.2%,多数前沿配置低于 25%。失败模式包括:代理被环境请求覆盖政策、执行检查后违背结果、长任务中丢失规则细节、以及虚假报告合规。论文发布全部任务、环境和评测工具。

荐读理由

论文用严格评分证明,即使有明确政策文档,多数前沿代理在长任务中仍会违反规则或虚假报告,这直接提醒你在构建代理系统时不能依赖长文档作为唯一约束,需设计更可靠的机制(如显式检查点或环境限制)。

原文

Computer Science > Artificial Intelligence

[Submitted on 28 Jul 2026]

Title:HANDBOOK.md: A Benchmark for Long-Context Agentic Instruction Following

Authors:Liudas Panavas, Sebastian Minus, Bradley Monton, Derek Ray, Suhaas Garre, Sushant Mehta, Edwin Chen

View a PDF of the paper titled HANDBOOK.md: A Benchmark for Long-Context Agentic Instruction Following, by Liudas Panavas and 6 other authors

View PDF HTML (experimental)

Abstract:Language-model agents are increasingly deployed under standing instructions: a system prompt, a policy file, or a skills document is placed in context, and the agent is trusted to let it govern every action that follows. Existing benchmarks rarely test this deployment pattern directly; they measure whether an agent can complete a task, not whether a long, binding policy document actually constrains its behavior over an extended tool-use horizon. We present this http URL, a benchmark of 65 agentic tasks modeled on how enterprise employees follow company handbooks. Each task places an agent in a self-contained company environment, a file workspace together with mock email, chat, calendar, issue-tracking, and commerce services exposed over the Model Context Protocol, and instructs it to carry out routine professional work governed by an expert-written standard operating procedure of 20 to 124 pages. Tasks span five domains (finance, medical billing, insurance, logistics, and HR) and ten fictional companies. To resist memorization, every task modifies one of ten base handbooks, altering the specific rules and thresholds on which grading turns, so no two tasks share a policy. Grading is fully deterministic: each task carries a rubric of programmatic criteria (824 in total) that check both that required actions occurred and that prohibited actions did not. Under strict grading, where a trial passes only if every criterion is satisfied, the best of thirty evaluated model configurations passes 36.2% of trials, and most frontier configurations remain below 25%. Failures follow consistent patterns: agents let a plausible in-environment request override the standing policy, perform a required check and then act against its result, lose rule details over long horizons, and report compliance they did not achieve. We release all tasks, environments, and the evaluation harness.

https://doi.org/10.48550/arXiv.2607.25398

arXiv-issued DOI via DataCite (pending registration)

Comments:
Subjects: Artificial Intelligence (cs.AI); Computation and Language (cs.CL)
Cite as: arXiv:2607.25398 [cs.AI]
(or arXiv:2607.25398v1 [cs.AI] for this version)

Submission history

From: Sushant Mehta [view email] [v1] Tue, 28 Jul 2026 07:58:07 UTC (57 KB)

Full-text links:

Access Paper:

license icon view license

Current browse context:

cs.AI

< prev | next >

new | recent | 2026-07

Change to browse by:

cs cs.CL

References & Citations

Loading...

BibTeX formatted citation

Data provided by:

Bookmark

BibSonomy Reddit

Bibliographic and Citation Tools

Bibliographic Explorer (What is the Explorer?)

Connected Papers (What is Connected Papers?)

Litmaps (What is Litmaps?)

scite Smart Citations (What are Smart Citations?)

Code, Data and Media Associated with this Article

alphaXiv (What is alphaXiv?)

CatalyzeX Code Finder for Papers (What is CatalyzeX?)

DagsHub (What is DagsHub?)

Gotit.pub (What is GotitPub?)

Hugging Face (What is Huggingface?)

ScienceCast (What is ScienceCast?)

Demos

Replicate (What is Replicate?)

Hugging Face Spaces (What is Spaces?)

TXYZ.AI (What is TXYZ.AI?)

Recommenders and Search Tools

Influence Flower (What are Influence Flowers?)

CORE Recommender (What is CORE?)

  • Author

  • Venue

  • Institution

  • Topic

arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.

Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)

Hacker News · 191 赞 · 128 评 讨论 → 阅读原文 →

这条对你有帮助吗?