Architecture writing for the people who have to approve, deploy, and eventually own these systems — security architects, platform leads, and the engineers who inherit whatever ships.
All 27 articles
Architecture teardowns
What was built, and what each layer defends against. Implementation documentation rather than argument.
A control plane that holds no customer data, an execution plane inside your VPC, and a hypervisor boundary between agent-generated code and everything else. What each layer defends against, and what the shape costs.
Policy the model cannot read, a tool roster compiled per turn, and a rendered blast-radius diff pinned to a version token. Three checks in the execution path, and the throughput ceiling they buy.
The model writes the answer; the backend decides what it may point at. A grounding critic, marker resolution against the execution record, and why rendering a citation is a security boundary.
Schema injection collapses somewhere past a few hundred tables. A narrow probing tool set, retrieval-driven discovery, a pointer pattern for bulk results — and the three failure modes that only appear once a real catalog is behind it.
Tools split by consequence rather than by endpoint, a credential the sandbox never sees, and the two operations — pipeline triggers and stale approvals — that break a naive integration.
Role-scoped visibility breaks more dashboards than any other single cause. What the warehouses share, what they do not, and why the profiling step decides your deployment topology.
An orchestration library is not an alternative to a governed system — it is a component inside one. Twelve decisions the library leaves to you, and when owning them is the right call.
Four architectural decisions you inherit with a managed agent runtime, the one written commitment that rules it out, and why the switching cost is not where people look for it.
An assistant and a governed execution substrate are not competing for the same budget line. The boundary sits exactly where an action stops being reversible — and inheriting a permission set is not the same as intersecting one.
Many organisations should build this, and the ones who should not are identifiable by one property of the work. The demo is the first fifth; the substrate is the rest, and it cannot be retrofitted onto a prototype that already works.
They inherit governance rather than asserting it, which is why they win for analytical work inside one platform. They also stop where the warehouse stops, and most enterprise workflows do not.
Coordination frameworks solve delegation well. Delegation is also how an injected instruction escalates privilege, and agent count is a design cost rather than a capability.
The pilot worked. Eighteen months later it still is not in production. Five architectural questions decide that outcome, and all five are settled before the first line of code.
The defence and the attack share a channel, so no instruction closes the class. Four named attacks, and the architectural layers that make a successful one harmless.
Research and volume trade against each other, and every team eventually picks the losing side. The way out is to automate the research and leave the send alone.
Guessed addresses cost more than the campaign that produced them. Three escalating verification tiers, and the design decision that matters most when none of them can answer.
Deployment topology is not an infrastructure detail you settle later. It determines which data the system may touch, and it is the hardest decision to reverse.
Every demo works against twelve tables. Real catalogs have tens of thousands, and the standard approach collapses on cost, latency, and accuracy at the same time.
Most organisations can report line coverage to two decimals and cannot say which implemented behaviour nobody has written a test for. Those are different numbers.
The assertions in a decade-old suite are usually fine. What is missing is everything around them — and retrofitting that is tractable in a way rewriting is not.
Adding analysts to a forty-item queue buys a quarter of relief. The queue is long because the same dashboard is being hand-built for the eleventh time.
A dashboard nobody opens is not a design failure. It is a specification failure — it was built from the data that existed rather than the decision it serves.
The build-versus-buy framing hides the option most enterprises actually need, and the three constraints that decide it have nothing to do with engineering capacity.