
All articles/Author
David Booth
Watching the watchers: monitoring your CI/CD pipelines, branch protection and repo hygiene
Most organisations monitor production closely and barely monitor their delivery tooling. Someone sets up a nightly build or a branch protection rule and confirms it works that day. After that, nobody looks at it again…
Coding agents in a production .NET shop: what holds up
We have been running Claude-style CLI coding agents against production .NET code for long enough to have opinions that survived contact with a client's release schedule. This post, part of our Practical AI in DevOps…
#coding-agents#dotnet#code-review#developer-productivity#ai-engineering
One small team, 100+ automated checks: anatomy of an AI-assisted monitoring platform
A backup job that has not run for eleven days will not send you an email. Neither will a TLS certificate with nineteen days left on it. The failures that cost our clients money are almost never the loud ones; they are…
Practical AI in DevOps: the series
Most of what gets written about AI in DevOps is written by people selling AI in DevOps. This series is our attempt at something more useful: a running account of what we actually run, what it costs us, and where it…
When AI must not act alone: human-in-the-loop patterns for security automation
Most of the AI security work we do for clients ends up hinging on one question: what is this thing allowed to do on its own at 3am on a Sunday? Everything else follows from the answer. Model choice, prompt design, which…
#human-in-the-loop#security-automation#ai-governance#audit-trail#soc-operations
Cloud posture on autopilot: continuously auditing AWS, Azure and Microsoft 365
Most of the cloud security incidents we get called into have nothing to do with a novel exploit. Someone opened a security group to 0.0.0.0/0 for a vendor's remote session and never closed it. A storage account got…
#cloud-security#microsoft-365#azure#aws#configuration-drift#continuous-compliance
