Prompt injection is a tool-permission problem
The injection is not the vulnerability; the tool the injected instruction can reach is. Retrieval and fine-tuning do not mitigate it, and prototypes grant permissions generously.
6 min read
Singular State / Perspectives
Practical thinking on what to build, how to make it work, and what it takes to own it.
The injection is not the vulnerability; the tool the injected instruction can reach is. Retrieval and fine-tuning do not mitigate it, and prototypes grant permissions generously.
6 min read
The seven instruments are drawn from four independent dimensions of the same work, so they overlap instead of partitioning. Each settles one thing and leaves an untested remainder.
6 min read
The transition is caused by use, not by declaration. A real decision, a real customer, a real record — and the obligations attach retroactively to work already done.
4 min read
Two different ratios travel under one name, and a higher multiple can describe a cheaper project. No benchmark value is established, and the denominator is where the argument lives.
4 min read
A reported failure rate converts an admission into a screening filter. It only works if the denominator is disclosed, because a zero-failure portfolio is a claim about reporting.
5 min read
Recovery time and recovery point are requirements. A restore exercise measures the duration and recovered state actually achieved under defined conditions.
4 min read
Rehosting changes execution location, replatforming changes supporting services, refactoring changes internal structure, and rewriting creates another implementation.
4 min read
How automating transcription can remove an undocumented check, and how to distinguish that risk from unnecessary manual work.
3 min read
Preserving a host extract’s encoding, cutoff, completeness, and consumer semantics when introducing an API.
3 min read
Preserving a report’s data selection, calculations, dependencies, and delivered output across replacement.
3 min read
A reproducible build produces identical specified artifacts from declared inputs. Recoverable source and artifact provenance answer different questions.
4 min read
Governed retention preserves a useful system with accountable operation, evidence of recovery, and explicit triggers for reconsideration.
4 min read
Three intervention points, not three exclusive strategies — the original RAG paper already combined two of them. Diagnose the failure before choosing the technique.
5 min read
How target-side transactions change reversal from a routing operation into a data-recovery decision.
3 min read
Build cost is paid once; inference, retrieval, review and monitoring scale with use. A cheaper model bill can raise cost per accepted outcome, and the run-cost owner is absent from the approval.
4 min read
The difference between retrieving SaaS records and carrying a business process into another environment.
3 min read
Comparing a hosted application with provider-executed business work through responsibilities, exceptions, and exit.
3 min read
Running a candidate against live inputs with its outputs withheld. The word does not establish the boundary — shared caches, writable destinations and quotas escape it unless someone checked.
5 min read
Waters' name for a legacy-replacement roadmap that delivers useful capability while limiting disruption. It answers a different question from an MVP, and the two coexist in one programme.
4 min read
Construction separates practical completion from final acceptance and holds the builder liable across the gap. Four disciplines stage readiness; software handover has no equivalent structure.
5 min read
Tell us what you're working on and where you need help.