Engineering insights
Better questions. Safer software.
Practical guidance on AI-built software, code reviews, security and release readiness.
Fieldnote 26 · Week of 7 Sept 2026Launch readinessBefore launching an AI-built app, check access, payment failures, recovery, monitoring and rollback. Build a release decision from evidence.
Read article ↗
Fieldnote 25 · Week of 31 Aug 2026RemediationClosing a ticket and closing a risk are different activities. Here is how to make remediation reviewable.
Read article ↗
Fieldnote 24 · Week of 24 Aug 2026RemediationPlan capacity, verification and contingency so an audit produces completed improvements rather than an unfunded backlog.
Read article ↗
Fieldnote 23 · Week of 17 Aug 2026Independent assuranceUse AI review as a source of hypotheses while requiring independent expectations, reproduction and human ownership of release decisions.
Read article ↗
Fieldnote 22 · Week of 10 Aug 2026Security readinessConnect review, tests and deployment to one revision so release approval can be understood and verified later.
Read article ↗
Fieldnote 21 · Week of 3 Aug 2026Security readinessBuild consistent questionnaire answers from actual controls, evidence owners and clearly recorded gaps.
Read article ↗
Fieldnote 20 · Week of 27 Jul 2026Security readinessA practical SOC 2 readiness plan for a small SaaS team: clarify buyer requirements, scope the system and collect evidence before buying tools.
Read article ↗
Fieldnote 19 · Week of 20 Jul 2026Launch readinessSeparate inconvenient code from release-stopping risk using affected journeys, consequences and a documented acceptance decision.
Read article ↗
Fieldnote 18 · Week of 13 Jul 2026Due diligenceMake the review more useful by gathering the evidence behind your product and delivery process.
Read article ↗
Fieldnote 17 · Week of 6 Jul 2026Technical due diligencePrepare architecture, setup, deployment and decision records so an AI-built product can be maintained by someone new.
Read article ↗
Fieldnote 16 · Week of 29 Jun 2026Application securityReview dependency exposure, update paths and runtime use so package alerts become actionable engineering decisions.
Read article ↗
Fieldnote 15 · Week of 22 Jun 2026Release engineeringPrepare ownership, containment, recovery and communication steps before a customer-facing incident forces rushed decisions.
Read article ↗
Fieldnote 14 · Week of 15 Jun 2026Application securityDesign diagnostic events around safe identifiers and outcomes, then test redaction and log access before production.
Read article ↗
Fieldnote 13 · Week of 8 Jun 2026Release engineeringChoose signals that reveal broken customer journeys and give each alert a clear owner and response.
Read article ↗
Fieldnote 12 · Week of 1 Jun 2026Release engineeringReview schema changes against old and new application versions, data transformations and practical recovery options.
Read article ↗
Fieldnote 11 · Week of 25 May 2026Release engineeringTurn “backups enabled” into recovery evidence by rehearsing a restore, checking attachments and measuring the missing-data window.
Read article ↗
Fieldnote 10 · Week of 18 May 2026Release engineeringDesign retries around one business operation so interrupted requests do not create duplicate orders, jobs or payments.
Read article ↗
Fieldnote 09 · Week of 11 May 2026Release engineeringTest payment events beyond a successful checkout, including duplicate delivery, delayed processing and access changes.
Read article ↗
Fieldnote 08 · Week of 4 May 2026Release engineeringA practical test plan for AI-built apps: critical journeys, permissions, payment failures, regression checks and release evidence.
Read article ↗
Fieldnote 07 · Week of 27 Apr 2026Application securityReview upload validation, storage access, downloads and deletion as one workflow instead of checking only the file picker.
Read article ↗
Fieldnote 06 · Week of 20 Apr 2026Application securityA practical response sequence for an exposed credential: contain access, replace it, inspect use and verify the deployed fix.
Read article ↗
Fieldnote 05 · Week of 13 Apr 2026Application securityCheck Supabase permissions, public and secret keys, and cross-account access before launch—with a practical evidence checklist.
Read article ↗
Fieldnote 04 · Week of 6 Apr 2026RemediationTurn an audit backlog into a practical sequence using exposure, consequence, confidence and dependencies.
Read article ↗
Fieldnote 03 · Week of 30 Mar 2026Independent assuranceCompare source review and penetration testing by the evidence each can produce and the decision your team needs to make.
Read article ↗
Fieldnote 02 · Week of 23 Mar 2026Code auditsA useful report connects a business concern to engineering evidence and a practical next step.
Read article ↗
Fieldnote 01 · Week of 16 Mar 2026Independent assuranceDefine the product boundaries, evidence and decisions a code audit should cover before comparing proposals.
Read article ↗