Recoverability-Conditioned Concurrency Control: A Transactional Layer for Agents That Share State
Abstract
When several LLM agents write to one shared database, an agent that is rolled back after committing an irreversible step leaves the shared state quietly corrupted. The agent is not the component that failed, so prompting cannot repair it, and classical concurrency control cannot either: it was designed for transactions lasting microseconds, not for agents that think for seconds between writes. We present AC-Saga, a transactional layer for agentic systems that couples a recoverability-conditioned locking policy with a deterministic, log-based compensation engine. Each lock decision is conditioned not only on contention but on whether the operation has a deterministic inverse (its compensability) and on whether an irreversible step has already committed (its exposure), which gives per-step serializability, interference-safe semantic recoverability, and no LLM calls on the recovery path. The policy is learnable: tabular Q-learning on a sim-faithful MDP, deployed on real PostgreSQL, gives 0 catastrophic aborts across a full contention sweep, with no recovery required, where an optimistic baseline that abandons a conflicted transaction reaches 9.6 +/- 1.7% unrecoverable aborts. Of the recoverability-blind policies we evaluate, none is both safe and adaptive. Because saga sub-steps commit and release their locks, we also guard every inverse against concurrent modification, so compensation refuses rather than overwrites a concurrent committed write, which an unguarded engine destroys in 100% of interfering trials whose undo rewrites a surviving row. Deterministic compensation also beats LLM-authored compensation on correctness, tokens and latency (100%, 0 tokens, ~0 ms against 86-100% for four open models each handed the exact pre-image), and end to end the coupling reaches 100% final-state correctness at zero recovery tokens, above a recovery-blind deterministic system (79.7%) and an LLM-recovery one (98.4%). Every headline metric is measured on real PostgreSQL. We also report a negative result: the coupling buys no throughput or token advantage when locks are cheap, so what it is worth is recoverability, not efficiency.