Technical Writing
Tech Blog
Cloud security, identity, infrastructure, and research. Deep dives, tools, and practical guidance.
What The Entra Fudge?! Tenant Restrictions v1 Doesn't Mean What You Think It Means
Tenant Restrictions v1 can block access to unapproved Entra tenants while still allowing Microsoft consumer accounts unless a second header is injected into a different authentication endpoint.
We Automated Dave: Security Debt at Machine Speed
The recent wave of agent sandbox escapes is being treated as something fundamentally new. Mostly, it is not. We spent decades accumulating security debt, brittle trust, overprivilege and accidental reachability. Agents are making the exploration of those decisions cheap, persistent, parallel and very, very fast.
Prompting Was Never the Control Plane
AADLC started as a way to stop coding agents rediscovering the same truths every session. The evidence now points somewhere bigger: cARL as durable agent governance, CopeLimit and cARRIE as the FinOps feedback loop, Headroom as the optimisation layer, and cARLy Gates as a possible CI control for delegated cognition.
Beyond The Door #1: The Illusion Of The Locked Door
We keep acting like doors are portals into trust and expected good behaviour. That was never true, but has never been more dangerous an assumption than it is now.
The Repository Is The New Package
The next generation of supply chain attacks aren’t targeting packages. They’re targeting repositories. The June 2026 Azure Functions incident may be a glimpse into what that future looks like.
FinOps for Delegated Cognition: GitHub Boiled the Frog Backwards
GitHub's AI Credits rollout wasn't really a pricing story. It was a change-management story, an observability story, and perhaps the first glimpse of FinOps for delegated cognition.