Two AI agent books connected by code and risk loops for production AI agents

The agent runbook needs a buyer's question

AI agent teams often ask whether the demo worked. Buyers, auditors, and production owners ask a harder question: can we trust the run when authority, evidence, and rollback are visible?

July 17, 2026 · 5 min · 950 words · Thomas De Vos
Read The agent runbook needs a buyer's question
Two books, one operating stack: Claude Code in production and bounded enterprise AI autonomy

The agent diff and the agent boundary belong in the same conversation

Claude Code review packets and enterprise agent security are often treated as separate problems. They are two parts of the same operating stack: evidence for the work, boundaries for the authority.

July 14, 2026 · 5 min · 1059 words · Thomas De Vos
Read The agent diff and the agent boundary belong in the same conversation
A production review path for AI agents: task, authority, evidence, and approval

Before the agent gets more access, write the review path

Teams keep asking whether an AI agent is ready for more autonomy. A better question is whether the review path is clear enough before the next permission is added.

July 13, 2026 · 5 min · 1038 words · Thomas De Vos
Read Before the agent gets more access, write the review path
A prompt box outside a production control plane with identity, scope, approvals, logs, revocation, and review

The prompt is not the control plane

A good prompt can shape agent behavior, but production teams need a control plane around identity, tool scope, approval, logs, revocation, and review.

July 12, 2026 · 4 min · 852 words · Thomas De Vos
Read The prompt is not the control plane
A production agent loop with task boundary, narrow tools, stop button, receipt, and human approval

Agent autonomy needs a stop button and a receipt

Production AI agents need a fast way to stop action and a plain receipt after every meaningful run. Without both, autonomy becomes trust without evidence.

July 11, 2026 · 5 min · 960 words · Thomas De Vos
Read Agent autonomy needs a stop button and a receipt
A workflow showing pilot AI agent access reviewed with evidence before it is renewed or expired

AI agent access should expire before it becomes hidden authority

Agent permissions that helped a pilot can become hidden production authority. Put expiry, renewal evidence, and removal paths around AI agents before access drifts.

July 9, 2026 · 6 min · 1141 words · Thomas De Vos
Read AI agent access should expire before it becomes hidden authority
Cover of Architect the Agent: The CCA-F Certification Guide

CCA exam preparation: think in boundaries, not product features

For the Claude Architect exam, product knowledge helps, but boundary judgment matters more: tool scope, context provenance, permissions, review, and recovery.

July 8, 2026 · 3 min · 519 words · Thomas De Vos
Read CCA exam preparation: think in boundaries, not product features
A diagram showing the risky handoff between an AI agent demo and production use

The agent demo is not the risk. The handoff is.

AI agent demos fail quietly when teams hand them to real workflows without scope, authority, evidence, and rollback. This is where Claude Code practice and enterprise agent security meet.

July 8, 2026 · 5 min · 874 words · Thomas De Vos
Read The agent demo is not the risk. The handoff is.
A Claude Code workflow that starts with a narrow task, widens permissions, and needs a permission budget before production use

Claude Code permission drift is how safe agent workflows become unsafe

Claude Code can start with a narrow task and end up with broad tool access. Treat permission changes like production changes: log them, review them, and tie them to rollback.

July 7, 2026 · 5 min · 1053 words · Thomas De Vos
Read Claude Code permission drift is how safe agent workflows become unsafe

Why CCA-F wrong answers sound tempting

The hardest CCA-F distractors are often almost right. Learn to spot the architectural boundary they quietly cross.

July 6, 2026 · 2 min · 386 words · Thomas De Vos
Read Why CCA-F wrong answers sound tempting