
Development & Technology121 articles
Architecture, implementation, authentication, and operations. Articles to inform critical decisions in development.
Articles are ordered by popularity over the past 30 days.


When told "we will build it with that tech" — 3 criteria clients must evaluate

.NET 8 and .NET 9 end of support — Evaluating impact on your organization and deciding by November

How many service account keys have you distributed? The choice of keyless integrations

Delivery is not the finish line: what clients must look for in system maintenance and operations contracts

Before Connecting Internal AI Agents to Business Systems: Essentials of Permission Management (MCP Authorization)

Lost Contact with Your Development Agency? How to Commission Work without Vendor Lock-In

Business system maintenance costs — The real nature of monthly expenses and contracts that prevent stagnation

Demystifying CORS errors and fixing them properly — Ending the outsourcing habit of "just allowing everything"

Moving beyond login-only authorization: Continuous authorization design for sensitive custom systems

Preserving the "why" behind client systems using architectural decision records (ADRs)

Designing authentication and authorization for AI agents — incorporating permissions and delegation into custom projects

Closing the door on internal network probing — Making SSRF mitigation standard practice in client architecture

Malware Disguised as Attractive Job Offers — Protecting Custom Development Teams from Attacks Targeting Developers

Are You Spending 6 Hours a Week Babysitting AI? — Reducing Hidden Operational Costs of AI in Custom Development

Eliminating Manual SSH Execution on Production Servers — Building Auditable Job Execution Platforms in Custom Development

Implementing Defenses for the AI-Driven Phishing Era via Custom Development — Building in Email Authentication and Spoofing Resilience 2026

Monitoring Starts with Defining "Normal": Designing Monitoring Systems for Handover and Production Operations in Custom Development 2026

How far should you accept AI refactoring suggestions? — Designing tech debt "decision-making" in custom maintenance

API Gateway Authorization Bypassed via Trailing Slash — API Authorization Security Audits for Client Systems 2026

Undisclosed URLs discovered in 30 minutes via CT logs: Protecting staging environments in client projects (2026)

Configuration files are the real attack surface of AI coding agents: Hardening implementations for clients 2026

GitLab 19.0 Developer Flow and Secrets Manager — Designing DevSecOps automation in contract development 2026

eBPF Replaces "User-Space Agents": Designing Runtime Security Observability for Clients in 2026

Internal GitHub repository compromise (via malicious VSCode extension) — Designing developer device governance delegation in custom development 2026

Microsoft BitLocker Backdoor Disclosed: Designing Endpoint Encryption Audits for Clients in 2026

nginx Critical Vulnerability Left Unaddressed for 18 Years: 2026 Response Architecture for Client Infrastructure Security Audits

Mini Shai-Hulud: Incident response design for client projects in the era of npm worms infecting 160+ packages including TanStack 2026

OpenAI Daybreak — Shifting Custom Development Left by Embedding Security from the Design Phase 2026

The Era of AI Agents Creating Cloudflare Accounts and Buying Domains — Autonomous Spending Governance in Custom Development 2026

30 WordPress Plugins Hijacked via Flippa — Contract Supply Chain Audit 2026

Client development environments in the era of "npm install means arbitrary code execution": DevSecOps hardening and isolation design in 2026

Operating Claude Code Auto Mode safely in client work: Human approval gate design 2026

AI Penetration Testing with AWS Security Agent — Automating Cloud Audits for Custom SaaS 2026

Protecting Custom Development Supply Chains with pnpm 11.0's "One-Day Delay" Default 2026

$0.5/Month Security Audits with AI — Packaging Architecture and Pricing Strategy for Custom Development Services 2026

Cloudflare Sandboxes Reaches GA — Designing Custom Development Without In-House AI Agent Execution Environments 2026

Guide to Building Private Networks for Humans, Nodes, and AI Agents with Cloudflare Mesh in Contract Projects 2026

Preparing for NVIDIA GPU Rowhammer attacks: practical security audit guide for enterprise AI infrastructure

Claude Code Weekly Update Summary (v2.1.94–2.1.98) — Must-Check Changes
Showing 81–120 of 121 articles
Turning concepts into design.
Development Environment↔AI Models
Access Permissions · Data · Logs
Building an environment
to use AI internally
Internal data, development environments, and access permissions. Advancing adoption concepts into concrete technical reviews.
Compare approachesOrganize implementation requirementsTest on a small scale
Read feature 
Google Workspace
administration basics
Resolving administrator uncertainties from rollout to sharing and permissions.
Pricing & rolloutSharing rulesPermissions & security
Read feature 
Getting started with AI
at work
Selecting tasks to delegate, experimenting on a small scale, and operating safely.
How AI worksTesting in workflowsSafe usage
Read feature 
Improvement notebook for
growing your website
Forms, usability, and updates: tackling post-launch improvements one step at a time.
Form optimizationUI refinementsUpdates & operations
Read series