Procedural Editing: Closed-Loop Repair of SOP Violations in Tool-Use LLM Agents
Abstract
Standard Operating Procedures (SOPs) govern tool-use workflows by specifying which actions are permitted, under what conditions, and in what order. A single skipped check, premature tool call, or early termination can therefore invalidate an otherwise plausible outcome. Such failures are natural targets for model editing: an SOP checker can localize the first divergent decision and provide the context, emitted action, and required replacement. However, we identify two reasons why traditional model editing transfers poorly to agent trajectories. First, reasoning agents act from a decision state that includes their generated rationale; consequently, an edit can achieve perfect teacher-forced rewrite accuracy yet leave the live action unchanged. Second, correcting one decision rarely repairs an entire trajectory, because the agent may diverge again downstream. We formulate procedural editing as closed-loop, trajectory-level repair and introduce PACE (Procedure-Aware Closed-loop Editing). PACE optimizes corrections at the recorded decision state, reruns the agent after every update, converts each new divergence into the next edit, and strengthens a correction when execution returns to the identical failing state. Across 119 SOPBench incidents, two Qwen3 models, and both scaffolds, PACE achieves the highest or tied-highest SOP success in all four settings, reaching 0.50-0.51 under ReAct and 0.52-0.66 under function calling. It retains 0.81-0.86 of previously passing tasks, while preserving general-capability.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.