Coding agent security: what can it reach?
Coding agent security is a question about capability, not intention. Judge a connection by what it cannot reach, not by what a vendor promises.
Read moreNotes on product ownership for teams running coding agents.
Coding agent security is a question about capability, not intention. Judge a connection by what it cannot reach, not by what a vendor promises.
Read moreAgent permissions come down to one line: enough to fetch work and hand it back, and no authority to close it. Where that line sits, and how to review it.
Read moreA backlog migration that imports everything moves rows and loses reasons. Migrate the next two sprints properly and leave the archive where it is.
Read moreSolo founder coding agents do not remove a job, they collapse two. You are the product owner and the reviewer, and both want the same hour every day.
Read moreOne command, one authorisation, and you connect Claude Code to backlog items it can fetch itself — with criteria attached. Plus what to do when it drops.
Read moreAn AI feature bolted onto a tracker is not an agent-native project tracker. Four capabilities that decide it, and the ones that turn out not to.
Read more