Application Security Cannot Remain a Periodic Exercise
OpenAI’s Astra announcement is a capability warning. The enterprise response is a governed verification loop across code, identity, configuration and running systems.
Writing
I write about applied AI, connected products, infrastructure and the day-to-day work of technical leadership.
OpenAI’s Astra announcement is a capability warning. The enterprise response is a governed verification loop across code, identity, configuration and running systems.
Small AI-enabled teams can carry much larger delivery surfaces, but only when the organization redesigns ownership, verification, specialist access and learning around them.
A CTO reading of the 37signals cloud exit, with a practical test for deciding when managed cloud has stopped buying enough advantage to justify its permanent premium.
How we translate AWS guidance into practical controls for identity, data, tools, authorization, observability and recovery across an agentic workflow.
How I choose between cloud, owned infrastructure and a deliberate hybrid one workload at a time.
How I distribute technical judgment through strong leads while keeping cross-team decisions, interfaces and escalation clear.
How I structure support agents to investigate product evidence, use tools carefully and hand useful work to a person when the case needs one.
How to turn historical work into leakage-aware agent evaluations that test decisions, tool use, escalation and recovery as well as the final answer.
How to compare AI systems with measured human work, then set a higher standard where scale or consequence demands it.
Connected products expand the CTO boundary from software delivery to lifecycle, industrialization, field conditions and long-term system operation.