06 Oct 2026 · 9 min read
Access Control
Multi Tenant RAG: Enforce Access Control Before Retrieval
A reference architecture for tenant isolation, document ACLs, permission revocation, and authorization tests in RAG systems.
Read moreIDEAS, DECISIONS & LESSONS
Notes on AI, architecture and building useful products.
85 articles
06 Oct 2026 · 9 min read
Access Control
A reference architecture for tenant isolation, document ACLs, permission revocation, and authorization tests in RAG systems.
Read more06 Oct 2026 · 5 min read
agentic-ai
A tested NanoClaw publishing workflow with draft-first writing, content fingerprints, CMS permissions and explicit review limitations.
Read more06 Oct 2026 · 5 min read
agentic coding
A Hacker News post about agent memory landed the same week I'd debugged a real dedup failure caused by exactly the problem it describes. I tested the fix against my own incident — here's what held up and what didn't.
Read more30 Sep 2026 · 4 min read
ai-agents
1,107 attack attempts, 49 findings, 3 new detection rules. But the number that should change how you test security is the one Cloudflare almost buried: category diversity beat attempt count, every time.
Read more30 Sep 2026 · 5 min read
ai-agents
At DevDay on September 29, OpenAI turned Codex Cloud environments from one-shot containers into persistent, shareable objects. It's the golden-AMI-versus-cold-start argument, just wearing an agent costume.
Read more20 Sep 2026 · 4 min read
ai
Claude Code, Codex, Copilot, and Gemini CLI all pin plugins to a commit SHA for safety. A Git ref-resolution quirk means that promise was never actually true — and the four vendors responded four different ways.
Read more19 Sep 2026 · 4 min read
ai
DoorDash ran 50 stale feature flags through a Sonnet-plus-Opus agent pipeline and published the numbers. The interesting part isn't the cost — it's what made the 90% success rate possible.
Read more19 Sep 2026 · 5 min read
ai
Gemini breached three real companies during a sanctioned red-team exercise because the test target had the same name as a live business. The lesson isn't about rogue AI — it's about namespace hygiene.
Read more13 Sep 2026 · 5 min read
agentic coding
SWE-2 matches Fable 5.1 on FrontierCode at 64% lower cost and cuts turns by 58% versus its predecessor — by training selectable reasoning-effort levels in a single RL run instead of shipping separate models. A Tech Lead's read on the cost-performance tradeoff and what it means for picking a coding agent.
Read more