I build agent systems and the security primitives they need — signet, mache, cloister, rosary. This is where I write about why.

  1. the map8 parts · updated

    Five things you can verify about an agent you cannot predict — and the layer built for each.

  2. cloister3 parts · updated

    A tool's reach, cut down to what it was granted — first the credential, then the whole process.

  3. rosary4 parts · updated

    The orchestrator, in movements: the methodology, then the architecture it cost to learn.

  4. ley-line2 parts · updated

    The content-addressed substrate underneath — and the falsification ladder that decided what belongs on top of it.

  5. mache3 parts · updated

    Code as structured data — what a codebase becomes when the filesystem understands it.

  • Eighteen Months of Claude Code

    I started using Claude Code in February 2025. This is what the work looks like now — with the repositories public, so you can check every claim against the commit history instead of taking my word for it.

    9 min read · recent

  • Caveman Speak Optimizes the Wrong Variable

    Dropping the articles does save tokens — by deleting the cheapest ones in the language. Meanwhile the plain summary costs less than the dense one, and the files written for agents were carrying the least.

    7 min read

  • It Only Sounds Like Philosophy

    Strip the idioms off everything on this site and what's left isn't an opinion. It's a pile of unglamorous decisions made earlier than you'd like, and it costs more up front than the thing it replaces.

    15 min read

all writing →