Parallel agents get one worktree each and one owner per file
git worktree listgit status --short |wc -l # in a shared checkout, before any agent starts
Get every Fix AI Slop Code episode
The code it wrote, the code it should have written and a check, for every episode
What is going on
Two agents editing the same checkout write over each other, and neither reports an error because each one's write succeeded. Cost scales with the number of agents, not with the amount of work, when they trample and redo.
Where it bit
One night, 13 agents, $824. The collisions were the expensive part, not the work. The build-order page on this site was built in its own git worktree because the main checkout had another session's uncommitted edits on the same two files; the merge then cost one deliberate conflict resolution instead of a silent overwrite. In the video pipeline: CapCut overwrote a draft that was written while it was running, so the rule became check the process, then write.
The practice
One worktree per agent. One owner per file, named in the brief. Shared files go through one writer. Any process that also writes the file is checked before you do, with pgrep -x, because ps | grep -q inverts under pipefail and reports the opposite of the truth.
Get this check as a script you can run tonight

The coding agent never holds production credentials
An agent with a production database URL will sooner or later run a migration or a cleanup against it, so production secrets never enter its env
Keys go in headers, never in URLs
A URL is written to server logs, CDN logs, browser history and error trackers, so an API key in a query string is a key in five places
Backups the app cannot reach, and one restore you have actually done
A backup on the same account the app or an agent can delete from is not a backup, and a restore you have never run is a number you do not have
If this check came back with more than you expected, that is worth a conversation