In 1987, Barbara Appelbaum published a paper in the Journal of the American Institute for Conservation about a word her profession had been using carelessly. The word was reversible. She was writing about physical objects: paintings cleaned, sculptures consolidated, ceramics treated with protective resin. Her complaint was that conservators talked about treatments as though reversibility were a property you either had or didn't.
She cited work by the polymer-conservation specialist C. V. Horie. Modern earthenware was impregnated with an acrylic resin considered readily soluble, then washed in solvent for eight hours using laboratory extraction equipment. Roughly half the resin stayed in the ceramic. By the profession's own standard, the treatment was reversible. Reversing it left the object carrying a substantial share of the intervention it had supposedly been freed from.
Anyone who has tried to undo a transaction online has met the same arithmetic. A refund on a payment platform shows as completed, but the merchant does not get back the processing fee. Cancel a furniture order after it has shipped and the product cost returns while the delivery charge does not. The interface says the action was undone. Something stayed.
Appelbaum's more useful move was to change the question. Rather than ask whether a treatment could be removed, she argued that conservators should ask what the next person working on the object would still be able to do. She called this re-treatability, and she wrote that it "is often more helpful in evaluating treatments than the idea of reversibility itself." The first asks how completely the past can be erased; the second, which options remain open.
At a W3C and GS1 workshop this September, Scott Lee proposed what he called a "last reversible moment": a checkpoint at the final instant before a software agent's action becomes binding on someone outside the system, where the agent's authority, the applicable terms, and any revocation are verified before the action goes through. The proposal addresses something real. Agents acting for users do commit them to things, and knowing where that line sits is a prerequisite for governing it. But the checkpoint is built as a gate. It decides whether to proceed. It says nothing about what proceeding will cost if the action later has to be walked back: which fees remain, which records persist, and what the residue leaves available to whoever inherits the situation.
Nothing in the workshop's public materials references Appelbaum or conservation science, and there is no reason it would. The two fields have no shared literature or vocabulary. But the problem is the same. Conservation spent decades on it: actions taken on someone else's behalf, under incomplete information, where undoing is a matter of degree rather than a state you can return to.
Return to the refund. The processing fee sits with the platform, and the merchant absorbs it. If that transaction needs a further correction later, a partial adjustment or a reissued credit, are those paths still open, or did the first reversal narrow them? That is a re-treatability question, and it is not one an approval gate is designed to answer.
What Appelbaum's framework offers the people designing agent systems is a second evaluation to run alongside the first: what will reversal leave behind, and on whom.
- Mandates for agent payments: An April 2026 IMF note argues that agent-initiated payments will require mandate-based authorization, traceability, and liability rules because individual transactions may not contain a fresh instruction from the person whose funds are used.
- Compensation versus complementarity: A preregistered meta-analysis in Nature Human Behaviour found that when AI alone outperformed humans, adding human review actually reduced combined performance, raising questions about whether post-action human checkpoints reliably catch residue problems.
- Agents meeting legacy systems: A July 2025 GAO report found that eleven critical federal systems were between 23 and 60 years old, with obsolete languages and known vulnerabilities — the infrastructure where agent-initiated actions and their residue will actually land.
- Formal versus enacted adoption: A 2026 Census Bureau working paper estimated that roughly 29% of firms with any AI use had worker adoption without formal firm adoption, suggesting that many agent-initiated actions may occur outside the governance structures that would track their consequences.

