All articles

  1. Governance & security

    The confident wrong answer is worse than missing evidence

    A governance report told us a site had external sharing disabled. The site permitted anonymous links. Nothing was broken: a correct API returned a default value for a property it had never populated, and the default happened to be the safest word in the enum. Here is the mechanism, the code that reproduces it, Microsoft's own documentation of it, and the discipline that catches the whole class.

    ·7 min read

    Keep reading →
  2. Migrations

    SharePoint 2016, 2019, Subscription Edition and Online: what actually changes

    2016 and 2019 both end support on 14 July 2026. Subscription Edition has no end date and cannot be bought outright. Online has features the others will never get, and Subscription Edition has two that are usually listed as impossible. A practical comparison, with the licensing that decides it.

    ·17 min read

    Keep reading →
  3. Development & automation

    We are still measuring engineers by the part that got automated.

    In 2025 DORA threw out its own scoreboard. The low, medium, high and elite tiers that the industry had quoted for a decade were replaced by seven team archetypes across eight measures. That is not a methodology footnote. It is the most used measurement framework in software admitting that the instruments no longer read the thing that decides whether a system survives.

    ·9 min read

    Keep reading →
  4. AI & agents

    One agent is an integration. A hundred is a governance problem.

    Agents got production identities before they got a stable way to record what they did. Microsoft Entra Agent ID is generally available, with sponsors and expiry dates. The OpenTelemetry conventions for agent traces are still experimental. That gap is not a detail: it decides what you can responsibly put into production this year, and it turns an AI question into a governance one.

    ·10 min read

    Keep reading →
  5. AI & agents

    Agents decide. Code executes. Knowing the line is the job.

    The promise is that agents replace applications. In the systems we build, they do not. An agent is very good at understanding a request, weighing options and choosing a tool. It is the wrong place for a payment, a tax rule or a permission check. This is where the line falls, and why putting it in the wrong place is expensive.

    ·7 min read

    Keep reading →
  6. AI & agents

    AI solved syntax. It did not solve judgement.

    Three independent measurements, taken between 2025 and 2026, all point the same way: AI-generated code passes over 95% on syntax and 55% on security, and that second number has not moved in two years. The part you write got cheap. The part you decide did not.

    ·4 min read

    Keep reading →
  7. AI & agents

    What to put in order before switching Copilot on

    Copilot does not create permission problems. It makes the ones already there findable, and you no longer need to know what you are looking for.

    ·2 min read

    Keep reading →

Categories

Send us a message

Email