Plan-and-Execute: Think Once, Act Many Times
In this series we've covered ReAct (reason → act → observe after every step) and Reflexion (adding self-critique between attempts). Both send the main model back into the loop on every action. Plan-and-Execute takes a different approach: do the planning up front, then execute.
How it works:
- Planner: an LLM turns the goal into an ordered list of steps.
- Executor: a smaller model or a ReAct sub-agent runs each step with tools and records the result.
- Replanner: after each step (or batch of steps), it looks at the results and either finishes, continues, or rewrites the remaining steps.

plan = planner(goal)
while plan:
result = executor(plan.pop(0), past_results)
past_results.append(result)
plan = replanner(goal, plan, past_results) # may return the answerLangGraph's plan-and-execute template is built this way. ReWOO adds variables (#E1, #E2) so a step can use an earlier step's output without another LLM call. LLMCompiler goes further and runs independent steps in parallel as a DAG.
Use Cases
- Multi-step research and reporting where you can sketch the steps in advance (gather, compare, summarize).
- Cost-sensitive pipelines: a frontier model plans and a cheap model executes.
- Security-sensitive agents: the plan is fixed before the agent reads emails, web pages or documents, so injected instructions can't add steps (control-flow integrity).
- Auditable workflows: a person can review the plan before anything runs.
Pain points
- Stale plans: the plan is only as good as what the planner knew at the start. In exploratory tasks (debugging, open-ended browsing) you end up replanning constantly, which is basically ReAct with extra overhead.
- Upfront latency and tokens: planning alone can cost 3,000–4,500 tokens before the first action runs. So expect bigger investments
- Error propagation: a bad step-1 result quietly corrupts every step after it unless the replanner catches it.
- Serial by default: the basic version runs one step at a time. You need ReWOO/LLMCompiler-style designs to run steps in parallel.
- It isn't a complete security fix: injected data can still change what goes into a planned step. You still need least-privilege tools and output filtering.

References
Del Rosario, R. F., Krawiecka, K., & Schroeder de Witt, C. (2025). Architecting resilient LLM agents: A guide to secure plan-then-execute implementations (arXiv:2509.08646). arXiv. https://arxiv.org/abs/2509.08646
LangChain. (2024, February 13). Plan-and-execute agents. LangChain Blog. https://www.langchain.com/blog/planning-agents
Wang, L., Xu, W., Lan, Y., Hu, Z., Lan, Y., Lee, R. K.-W., & Lim, E.-P. (2023). Plan-and-solve prompting: Improving zero-shot chain-of-thought reasoning by large language models (arXiv:2305.04091). arXiv. https://arxiv.org/abs/2305.04091