Writing
The parts that are not the model.
Getting a model to call a function is the easy half. These are notes on the other half: what the agent runs as, what stops it changing the wrong thing, and how you know afterwards that it happened. Written from building Verb, including the parts we got wrong first.
How to let users take actions with AI in your app
Tools instead of retrieval, the user's own permissions instead of a service account, and why the hard part is reporting failure honestly.
ReadLetting an AI agent write to your database, safely
Classification, confirmation with real values, and the difference between an action verified and an action merely claimed.
ReadPostgres row-level security for a multi-tenant AI agent
The isolation boundary, the tables that deliberately sit outside it, and why the loud failure is the one worth engineering for.
ReadHow to confirm a destructive action, so the confirmation is real
Why a model asking 'shall I?' is not a confirmation, what the card must show, and what to do when nobody answers it.
ReadWhy your AI agent says an action worked when it didn't
The 200 that lied: why a successful response is not evidence, and the per-tool success shape that stops an agent claiming work it never did.
ReadTool error messages are prompts, so write them like one
Why "failed" produces a guess, the four parts of an error a model can act on, and why descriptions are advisory but validation is binding.
ReadHow to stop an AI agent retrying a failing tool forever
The 23-call spiral, why per-tool caps let a model walk the tool list, and budgeting failures by cause.
ReadHow to tell an embedded AI assistant who is signed in
Why the assistant cannot see your session, why it needs a function and not a token, and the encoding detail that fails every signature silently.
ReadYour AI chat widget is showing the last user's conversation
A real shared-device leak: permissions held, the transcript did not. Keying on the subject, not the token, and why sign-out has no single choke point.
ReadPrompt injection in an agent that takes actions: contain it, don't hope
Why offering a tool list is not enforcement, the switch that is the allowlist, and bounding what an obeyed injection can reach.
ReadWhy your embedded script silently does nothing under a Content Security Policy
The failure that cannot report itself, the second directive everybody forgets, and why strict-dynamic makes your allowlist irrelevant.
ReadHow to test an AI agent that takes actions, without touching real data
Run it for real against development data, the five cases worth deliberately breaking, and why a timer on real execution backfires.
ReadChoosing a model for an in-app AI agent, and routing the turns that don't need it
Why prompt engineering cannot fix a routing problem, the asymmetric classifier, and the settings that silently stop applying after a model swap.
ReadThe best ways to add an AI assistant to a SaaS product in 2026
Documentation chatbot, build your own, or embedded action assistant: the one question that decides between them.
ReadWhat an AI assistant should do inside a law firm's software
Why most of a lawyer's time in practice software is small updates after court, and what an assistant needs before a firm lets it make them.
ReadAn AI agent for the back room of a marketplace
Moderation queues, bulk changes and broadcasts: what an agent can take off a marketplace operator's hands, and the confirmations bulk actions need.
ReadWhat an AI assistant is actually worth inside a booking product
Why most of what people do in a scheduling tool is procedures rather than questions, and what an assistant has to get right to take them on.
ReadThe Next.js build, not the app, is what runs the server out of memory
Why a build takes down a small server when the app it produces runs fine, and the one-line cgroup fix.
ReadYour agent works. That was never the hard part.
The demo takes a weekend and the sign-off takes a quarter. The identity mistake that causes it, and the day our own test suite turned out to be pointing at production.
ReadYour coding agent can set up your product’s AI agent now
The setup that used to mean a dashboard, three tabs and a key to paste is now one sentence to the coding agent you already have open.
ReadFive prompts from an empty account to a working AI agent
The whole setup as a conversation you can copy: the prompts, what your coding agent does with each one, and the two moments it stops to ask you.
Read