Positions
Where I've got to. Revised when the ground moves rather than when the calendar does.
The essays on this site carry dates for a reason. Each one is a snapshot of what I thought in a particular month, and I would rather leave them that way than quietly edit them into being right later.
This page is the other half of that arrangement. It holds what I currently think, assembled out of those pieces and rewritten whenever something changes my mind. It is not a summary of the writing. It is a set of positions I am prepared to defend today, each one pointing back at the piece that earned it, and it is wrong in places I cannot yet see.
The claim underneath the others
Everyone working with these models has arrived at the same conclusion: context is what makes the difference. Give a model enough of what you have and what you are actually trying to do and it performs. Starve it and it guesses fluently. The more careful version of that view adds a second requirement, that the context be shared, so two people asking the same question of the same system get equivalent answers instead of two private ones.
Both are right. Neither is new.
The same was always true between people. We never had to say it out loud, because shared context was never good and nobody noticed. It was continuously and invisibly repaired.
Every organisation I have worked in ran on a shared understanding that was ambiguous, incomplete and quietly contradictory. It held together because people patch it constantly and for free. Someone unsure asks the person next to them. Someone hedges until the next standup. Someone reads a room and infers the thing nobody said. Thousands of small negotiations a day, none of them written down, all of them mending the model before anyone notices it was torn.
I now think most of the failures I have spent a career on are cases of that repair being absent, too slow, or mistaken for an insult.
This is the position most of the rest of the page hangs from. It is also the newest one, so treat it accordingly.
Severity and blast radius are different questions
“Is this insecure?” and “what breaks if I fix it?” are answered by different instruments, and we have spent thirty years building only the first.
A correct finding can still take down the thing it was meant to protect, because the confidence attached to the finding gets spent as though it were confidence about the fix. Those are not the same confidence. Until the second instrument exists, and is trusted the way the first one is, every remediation is a bet with a stake you cannot see.
Earned in Right Finding, Wrong Fix.
Controls belong in the path itself, not in a gate across it
If safety has to be applied by each person, it gets applied unevenly and resented. If it is inherited by standing on the path, it is applied everywhere and noticed nowhere. The aim is not a faster checkpoint. It is a road built so that the checkpoint has nothing left to find.
The corollary matters more than the principle. The golden path has to be the lowest-friction way to do what people actually need. A safe path that is slower than the unsafe one is a signal, not a control.
Earned in Compliance as an Inherited Property.
Being checked is not the same as being judged
The safe way to review work separates two things that usually arrive together: the objective claim you can check, and the subjective one that is a matter of taste. Gate on the first. Offer the second as advice the builder can decline. Send them down one channel and the taste contaminates the fact, the fact gets argued, and the whole thing lands as a verdict on the person.
Held apart, the check turns impersonal. Everything is checked, always, the newcomer’s work and the veteran’s alike, because the check is the floor and the floor has no exceptions. Read that way, being checked stops being a judgement on you and becomes closer to the weather.
Earned in The Second Hard Part.
The failure mode is agreement, not confusion
When two minds share a word and unpack it differently, the dangerous outcome is not that they disagree. It is that they agree, proceed, and find the gap much later and much further downstream.
Confusion announces itself. False agreement does not. Which is why I have stopped treating “we’re aligned” as evidence of anything.
Earned in Darmok, Brown M&Ms, and the Bandwidth of Meaning.
Trust is the dial that sets how much you check
Trust is less a feeling about a source than a setting: it governs how much compression you will accept without verifying.
Turn it up and you allow more meaning per word and check less. Turn it down and you demand things spelled out. A source earns the dial by marking the edge of what it knows, saying plainly when it does not know, and saying where it would start looking. That last part is most of it. Certainty you cannot separate from guessing is worth very little, because the “I don’t know” is what makes the “I do know” worth acting on.
This one runs through most of the essays without being the subject of any of them. It is the thread I am currently pulling.
The next three are not downstream of the claim this page hangs from. They come from the same body of work and I hold them just as firmly, but they stand on their own.
When both sides hold the same tools, the edge is the channel
When capability is cheap and roughly equal on each side, the capability stops being the advantage. What is left is the coupling between the two automated systems: how the other side’s machine takes in signal, what it trusts, and where its intake sits open. A defender that learns continuously from an open channel can be taught by anyone who takes the trouble to understand the channel, and that is a property of the design, not a defect in it.
This is the trust dial seen from the outside. A source you cannot verify is a source that can be fed.
Earned in The Botnet With One Member.
The valuable move is classifying the problem, not solving it
As each layer of the work gets absorbed, what is left over is judgement about which problems belong to the machine, which stay human, and which the machine should be kept away from entirely. That classification is worth more than any single attempt at a solution, because it decides whether to attempt one at all. It also takes more than one discipline to make, which is why the work migrates to the people who sat in the gaps between fields rather than to the specialists at the centre of any one.
Earned in Three Abstraction Shifts in One Career.
Write down only what gets stronger as the models improve
The ground under this work moves every few months, so the only sane thing to codify is the part that does not depend on the ground. The test for any pattern or piece of received wisdom is one question: does it get stronger or weaker as the models improve? If it gets weaker, it was a workaround for a limitation someone is being paid to remove, and writing it down is a bet against the roadmap. If it gets stronger, it was describing something structural, and it is worth the ink. What has survived every shift so far was never really about the model: typed contracts, observability, reproducibility, provenance, clarity.
Earned in 1994.
What I am least sure about
Each of these threatens one of the positions above, and I would rather say so than let the page read as settled.
The claim underneath the others is the weakest thing here. It is weeks old, I have not tried hard to break it, and its likely failure is being too accommodating: a frame that explains everything and therefore predicts nothing. Ask me what it rules out and I do not have a confident answer yet.
The trust dial has a hole in the middle of it. I can describe how an automated system loses the right to be trusted once it learns from inputs nobody controls. I cannot describe the repair. A source earns the dial back by marking the edge of what it knows, and I do not know what that move looks like for a machine that cannot reliably tell when it is guessing.
And the page as a whole rests on something I should be suspicious of: that these really are one failure seen at four scales, rather than four separate things I have pattern-matched into a family because the resemblance is satisfying. The test I use elsewhere is whether a connection does work or merely feels profound. This one has done some work. Not yet enough to be safe.
Where this goes
The same failure shows up at scales I have not written about yet. Across a whole company, where a mission statement is meant to decompress the same way in every head and mostly does not. Between a person and a machine, where the repair that held all of it together is simply absent. The organisational scale, a request for review landing as a verdict on the person, was on this list when I first wrote the page; it became The Second Hard Part, which is the page working the way it is supposed to.
Those are the next pieces. When they exist this page will change, and the version you are reading will have been wrong in ways I will try to say out loud rather than quietly correct.