---
title: "Agentic Travel Transaction Safety"
description: "Agent loop, retry ve tool invocation kaynaklı duplicate booking/payment riskini idempotency, transaction guards ve UNKNOWN-aware recovery ile yönetin."
slug: "agentic-travel-transaction-safety"
translationKey: "architecture-agentic-travel-transaction-safety"
locale: "tr"
type: "guide"
category: "architecture"
tags: ["agentic-travel","idempotency","duplicate-transaction","booking","payment"]
publishedAt: "2026-09-27"
updatedAt: "2026-09-27"
reviewedAt: "2026-09-27"
technicalVerifiedAt: "2026-09-27"
codeExampleStatus: "illustrative"
---

AI agent'lar plan yeniden çalıştırabilir, tool retry yapabilir veya aynı intent'i farklı execution path'lerinden tekrar çağırabilir. Bu nedenle **agentic transaction safety'nin temeli idempotency + explicit side-effect guards** olmalıdır.

## Side-effect boundary

Read ve write tool'ları ayırın:

```text
READ:
search
retrieve
quote
status

WRITE:
book
capture
cancel
refund
exchange
modify
```

WRITE tool'ları ekstra guard gerektirir.

## Idempotency key

```text
purchaseIntentId + operation + version
```

Örnek:

```text
book:pi_123:v1
capture:pi_123:v1
cancel:bk_456:v1
```

## Agent retry kuralı

Agent tool error gördüğünde otomatik olarak write retry yapmamalıdır.

```text
SUCCESS -> return result
FAILED_AUTHORITATIVE -> policy-based retry/new version possible
UNKNOWN -> reconcile, do not repeat side effect
```

## Duplicate transaction prevention

Koruma katmanları:
- persistent idempotency store,
- unique constraint,
- provider idempotency mapping,
- single active attempt,
- UNKNOWN retry block,
- request hash,
- manual override audit.

## Payment/booking separation

Agent "payment captured" sonucunu "trip booked" diye yorumlamamalıdır. Canonical transaction completion ancak gerekli booking/payment/document state'leri uyumlu olduğunda oluşur.

## Replacement booking guard

İlk booking UNKNOWN iken agent alternatif booking açmak istiyorsa:
1. authoritative lookup,
2. HITL checkpoint,
3. duplicate-risk warning,
4. new purchase intent/version
gereklidir.

## Tool contract

Write tool response en az:
- operationId,
- status,
- terminal boolean,
- providerReference,
- retrySafe,
- reconciliationRequired
alanlarını dönmelidir.

## Failure modes

- LLM aynı tool'u iki kez çağırır,
- orchestration timeout sonrası retry,
- tool success response agent'a ulaşmaz,
- provider success/local persist fail,
- payment ve booking divergence,
- replay edilmiş plan eski authorization ile çalışır.

## Observability

- duplicate side-effect blocked,
- UNKNOWN write attempts,
- repeated tool-call count,
- idempotency conflict,
- reconciliation-required count,
- agent plan replay count.

## Production checklist

- read/write tool classification,
- persistent idempotency,
- UNKNOWN-aware retry,
- terminal flag,
- reconciliation tool,
- separate payment/booking states,
- HITL for replacement booking,
- audit of all write attempts.
