Why You Need an AI Platform, Not Just AI Tools
The shadow IT of the 2010s is back, wearing a nicer jacket and calling itself 'innovation.'
A field series
Notes on the architectural decisions behind an internal AI platform for a modern, cloud-native org written up as generalized patterns, not a case study of one company. Some of this held up under real scale. Some of it we'd do differently. We're sharing both.
The shadow IT of the 2010s is back, wearing a nicer jacket and calling itself 'innovation.'
You don't pick your cloud identity provider. It picks you, sometime around when someone signed a contract you weren't in the room for.
'/prod' and '/not-prod' is not an environment strategy. It's a coin flip with a leading slash.
Somewhere, a model provider is about to rename a string you've been treating as a permanent identifier. This is your warning.
Someone deletes a 'resource.' The shared networking everyone depends on goes with it. Nobody meant for this to happen. It happened anyway.
The most secure cloud credential is the one that expires before anyone thinks to steal it.
Why your spend-tracking layer and your billing provider's cap are not the same system, and never should be
The moment budget approval becomes a forwardable link, you've lost the audit trail you thought you had
A trick that feels like it's cheating physics, and a couple of ways it will happily cheat you back
A small modeling decision that either keeps your data honest or quietly lets it drift
You already have a list of security compromises you've made. The question is whether it's written down anywhere.
Redeploying an agent shouldn't mean reintroducing yourself to everyone it knows
Nobody's watching Slack for 'my API key expired' from a robot at 3am
One almighty service account is not an identity model, it's a liability with an API
memory_enabled=true, persistent=false — congratulations, you've invented a Schrödinger's agent
If changing a timeout requires a release train, you didn't build infrastructure, you built a very slow form
It's not an agent that happens to expose tools. It's infrastructure wearing a disguise.
Your WAF has never read a system prompt, and that's the problem
What's actually running in production shouldn't require an archaeology degree
Your analytics pipeline having a bad day should be its own problem, not everyone's
A retrospective, not a victory lap