Posts
Independent essays on AI-native work patterns, agent infrastructure, and what actually works when running agents as real tools.
-
Most Enterprises Are Chasing AI Autonomy Before Defining the Outcome
Executives are asking how autonomous their AI should become before defining the outcome, workflow, authority, evidence, and recovery model. Autonomy belongs to workflows, not enterprises.
-
One Agent Credential Pattern, From Solo Builder to Enterprise
Updated:1Password holds credentials; OAuth/OIDC scopes M2M clients. Adding users changes identity and vault policy, not the protected APIs.
-
Scope the 1Password Vault, Then Scope the Token
Updated:A purpose-specific 1Password vault and read-only service account bound an always-on agent box to five secrets and blocked writes as configured.
-
1Password op run Makes Vault-Backed Credentials Tool-Transparent
Updated:At process launch, op run resolves 1Password references into ordinary environment variables, so CLIs and MCP servers need no vault-specific code.
-
A Never-Say List Is the Fingerprint of an AI Voice
Updated:Writing samples teach cadence. Corrections and mode-specific never-say lists encode the rejected choices that make an AI voice distinctive.
-
Docs-as-Code as a Knowledge Distribution Stack
Updated:Markdown, Git, llms.txt, and MCP create human and agent read paths from one source, while AI-mediated pull requests remove Git fluency from writing.
-
Encode Workflow Failure Modes, Not Only Successes
Updated:A leaked folder name exposed a safety-check gap. Encoding that failure class in the workflow makes it visible in every downstream run.
-
The MCP Proxy, Live: 206 Tools in 2,100 Tokens
Updated:A live MCP proxy reduced startup context from about 217,000 to 2,100 tokens across 206 tools. Most sessions now run from a ten-tool always-on set.