Free field guide · Book II
This field guide is the full story of how we run AI agents as production software: the contract that feeds them, the gate that authorizes them, the failure paths designed for them, and the discipline that lets a security finding dispatch its own fix.
The complete guide: the self-healing loop, the day it broke, the work contract, the Health Code, designed failure, verification, observability, memory, the new attack surface, and the 24-question scorecard.
How it starts
A security scanner finds a vulnerable dependency. Nobody reads the alert, because nobody has to: the finding becomes a validated work order, passes an authorization gate that recognizes a security finding as its own justification, and a sandboxed runner opens the pull request.
The only human in the loop is the one with the most leverage: the reviewer who merges. This guide is everything that makes that loop safe to run.
The problem this guide solves
Anyone with an API key can rent the capability. The operation is the part you have to build. If your agents write code, run jobs, or touch production today, run this test against your own setup:
Inside the guide
Who this is for