// blog

Writing

Notes on software engineering, side projects, and building for the web.

#ai-agents#operations

AI Inference Regions Turn Privacy Into Routing Logic

Fresh Vercel and GitHub controls show AI governance moving into per-request region, client, workflow, and approval decisions.

Read ->
#ai-agents#operations

Long-Running Agents Need Checkpoint Contracts

Claude Opus 5 in Copilot, mobile agent fixes, and stateless MCP shift agent risk from launch approval to mid-run control.

Read ->
#operations#developer-tools

Work Taxonomies Should Preserve Overlap

GitHub's new multi-select fields and agent automation controls make queue taxonomy an execution boundary, not admin decoration.

Read ->
#security#reliability

File Upload Pipelines Are Becoming Edge-Controlled Workflows

Vercel's latest Blob WAF and workflow-duration updates show uploads need edge policy, async processing, and evidence trails.

Read ->
#ai-agents#operations

Agent Work Intake Is a Control Surface

Fresh GitHub updates move agents into Issues, Linear, Mobile, and MCP. Design intake rules before autonomous work spreads across queues.

Read ->
#ai-agents#operations

Spend-Capable Agents Should Leave Purchase Receipts

Vercel MCP purchases and installable agent extensions make spending a tool permission. Treat purchase authority as audited product surface.

Read ->
#ai-agents#operations

Agent Model Routing Is Now Operational Design

Fresh Copilot and Vercel updates show AI teams need routing rules for model choice, cost, latency, and approval boundaries.

Read ->
#ai-agents#operations

AI Credit Pools Require Chargeback Design

GitHub's AI credit pool controls make Copilot spend easier to allocate, but only if teams separate license-funded usage from metered overage.

Read ->
#developer-tools#reliability

Code Quality Gates Start as Evaluate-Mode Experiments

GitHub Code Quality is GA with dashboards, coverage gates, APIs, and AI autofix. Roll it out as measured policy, not a blanket blocker.

Read ->
#ai-agents#developer-tools

Review Agents Work Best in Testable Review Environments

Copilot code review now reads branch instructions, setup files, and runner policies. Treat review context as executable infrastructure.

Read ->
#ai-agents#analytics

Copilot Metrics Should Measure Repository Outcomes

GitHub's fresh Copilot metrics updates make AI work visible by repo, app, and mobile fix path. Turn usage into outcome review.

Read ->
#operations#developer-tools

Operational Questions Belong in Project Views

Fresh GitHub and Vercel updates show queues, cache writes, and Slack agents becoming queryable operating surfaces.

Read ->
#ai-agents#security

Runtime Credentials Change the Shape of Agent Risk

Fresh GitHub, Vercel, and Cloudflare updates show secrets, connectors, and flag CLIs becoming operational control planes.

Read ->
#security#developer-tools

Dependency Cooldowns Turn Update Speed Into a Policy

Dependabot's default cooldown changes dependency updates from pure freshness work into release-risk routing for small teams.

Read ->
#security#ai-agents

Copilot Security Reviews Move Risk Left Into the Workstream

GitHub's new security-review command and agentic autofix make security work earlier, but only if teams capture evidence.

Read ->
#security#operations

Security Alert Names Should Trigger Response Playbooks

GitHub's clearer detector names and AI scanning updates show why alert labels should route action, not just decorate queues.

Read ->
#developer-tools#ai-agents

Repository Overviews Should Expose Operating Boundaries

Copilot can now summarise unfamiliar repos. Make those summaries safer by documenting owners, risk zones, and contribution limits.

Read ->
#security#ai-agents

Prompt Injection Scans Deserve Triage Rules

CodeQL prompt-injection detection turns AI app security into review work. Route findings by exploit path, not scanner severity alone.

Read ->
#developer-tools#operations

Pull Request Dashboards Should Encode Release Risk

GitHub's new PR dashboard and Code Quality targeting make review queues more useful when they sort by business risk, not noise.

Read ->
#ai-agents#observability

AI Coding Telemetry Belongs in Operations

GitHub's new Copilot controls make agent activity observable and enforceable. Route that telemetry into incident, cost, and release processes.

Read ->
#ai-agents#accessibility

Accessibility Trees Make Browser Agents Testable

Browser agents are getting semantic page views. Use accessibility trees to test what they can understand before they act.

Read ->
#cro#reliability

Feature Flags Get Safer With Targeting Diffs

Vercel Flags segments are now scriptable from the CLI. That makes rollout targeting reviewable, but only if teams diff it like code.

Read ->
#performance#seo

Vary Caching Depends on Clear Content Contracts

Cloudflare Cache Rules now honor Vary. That helps multilingual and format-aware pages, but only if teams control variant keys.

Read ->
#ux#accessibility

Pointer Events Expose Weak Interaction Contracts

Pointer Events Level 3 is now a W3C Recommendation. Treat touch, pen, and mouse behaviour as a funnel contract, not browser trivia.

Read ->
#ai-agents#operations

Agent Runs Are Only Useful With Audit Trails

Vercel Agent Runs and GitHub Copilot usage metrics show why AI work needs inspectable logs, not just accepted diffs.

Read ->
#deployment#automation

Deploy Dry Runs Turn Into Release Contracts

Vercel dry-run deploys and service bindings are useful, but teams need explicit release contracts before agents ship.

Read ->
#security#operations

Secret Leaks Demand Public Surface Monitoring

GitHub and Vercel updates show why small teams need to watch public leaks, stale credentials, and project-level security drift together.

Read ->
#ai-agents#operations

Agent Work Starts With Cost Budgets

Vercel and GitHub's latest agent pricing changes make token spend an operating metric, not an accounting surprise.

Read ->
#security#developer-tooling

Dependabot Works Better With Explicit Registry Contracts

GitHub's .npmrc change is a useful reminder: dependency automation should use named registry rules, not inferred package-manager state.

Read ->
#ai-agents#operations

Agent Deploys Start With Permission Budgets

Vercel's Ship 2026 announcements show a practical pattern for coding agents: scoped identities, temporary access, and measurable deploy risk.

Read ->
#ai-agents#developer-tooling

Copilot Model Choice Works Best With Routing Rules

GitHub's latest Copilot changes make model choice and adoption reporting an operations problem, not a preferences menu.

Read ->
#ai-agents#analytics

AI Coding Metrics Fall Apart Without Denominators

GitHub's new Copilot merge totals are useful only when teams compare them against review quality, risk, and delivery context.

Read ->
#automation#reliability

Workflows Break Less With Recovery Contracts

Cloudflare's rollback-handler update is a useful reminder: business automations need explicit recovery paths, not just retry buttons.

Read ->
#analytics#vercel

Analytics Get Safer With Command-Line Checks

Vercel's new CLI Web Analytics query is a useful pattern: make performance and conversion checks repeatable, not dashboard archaeology.

Read ->
#security#operations

Credentials Deserve a Real Kill Switch

Fresh GitHub, Vercel, and Cloudflare updates point to the same operator lesson: scope credentials tightly and rehearse revocation before an incident.

Read ->
#ai-agents#vercel

AI SDK 7 Makes UI Contracts Matter

Vercel shipped AI SDK 7 with typed messages, resumable streams, and MCP tools. Treat the upgrade as an agent UI contract, not a package bump.

Read ->
#cro#research

Diary Studies Beat Funnel Guesswork

NN/g’s fresh diary-study incentive guide is a reminder: before changing a checkout or quote funnel, watch what customers do over time.

Read ->
#operations#ai-agents

AI Agents Run Better With Operator Guardrails

Fresh NN/g, Cloudflare, and GitHub updates show agentic workflows moving into real operations. Treat them as systems, not clever prompts.

Read ->
#analytics#operations

AI Tool Spend Deserves Product Analytics

Recent Stripe and GitHub data show AI spend is becoming measurable. Operators should track AI tools like product usage, not software overhead.

Read ->
#seo#marketing

AI Search Rewards Situation-Specific Landing Pages

Fresh AI search research points to a practical SEO shift: build pages around the situation buyers describe, not just the keyword they type.

Read ->
#web-platform#cro

Native Select Styling Changes Form UX

Safari 27 is adding customizable select support. Form-heavy sites should test native styling before reaching for custom dropdown JavaScript.

Read ->
#email#marketing

Email Authentication Is Now Operator Work

Cloudflare made DMARC Management generally available. Small teams should treat SPF, DKIM, and DMARC as deliverability infrastructure, not DNS trivia.

Read ->
#analytics#seo

Bot Traffic Is Now an Analytics Problem

Bots and AI agents are becoming normal website traffic. Operators need cleaner analytics, crawler policy, and separate metrics for machine visitors.

Read ->
#security#reliability

Security Scans Belong in Designed Delivery Pipelines

Cloudflare scaled Security Insights 10x without new hardware. The builder lesson is to treat audits and scanners as pipelines, not cron jobs.

Read ->
#ai-agents#github

Copilot Code Review Works Better With Firm Guardrails

GitHub added org runner controls, content exclusion, and larger custom instructions to Copilot code review. Treat that as review infrastructure, not decoration.

Read ->
#ai-agents#web-platform

WebMCP Turns Websites Into Agent-Ready Workflows

Chrome is testing WebMCP so websites can expose structured tools to browser agents. Here is what builders should do before agents start using their UI.

Read ->
#ai-policy#anthropic

The Fable 5 Recall Shows the AI Export Problem

Anthropic launched Fable 5, then suspended it after a US export-control directive. The useful lesson is about governing model capability, not one jailbreak.

Read ->
#better-fetch#web-scraping

Better Fetch vs. 10 Web Scraping APIs

A deep dive comparing Better Fetch to ScrapingBee, ScraperAPI, Zyte, Bright Data, Firecrawl, Scrapfly, Apify, Browserless, Browserbase, and Jina Reader — on pricing, billing model, and what they cost when JavaScript and anti-bot kick in.

Read ->
#ai-agents#vercel

AI SDK Harnesses Make Agents Swappable

Vercel is adding HarnessAgent to AI SDK 7. The practical lesson is that agent runtimes are becoming app infrastructure, not just CLI tools.

Read ->