How we build
Agents draft. A person ships. Git is the source of deploy.
The same constraint applies to client work and to this site. Anything hard to undo waits for a person. Delivery is defined in the repository. Secrets stay out of it.
Agents and human review
Specialists draft, classify, and research. A coordinator puts that work on a queue. A person approves mail, posts, spend, and other actions a client would see.
The gate is there because those actions are hard to undo. A wrong draft can be rewritten. A wrong send cannot. The Dream Team page describes the roles. The review path is the same picture.
How we talk about scope and client data is on Approach.
Text version: specialist agents do bounded work, a coordinator places it on a review queue, a person approves, and only then does an external action go out.
Defined in git
For this site, GitHub Actions is the delivery definition: one workflow checks types and builds
on every pull request; another opens a preview and updates production on merge to
main. There is no separate click-to-deploy step. A step that is not in the
repository gets skipped, and nobody can see that it was skipped.
Self-hosted pilots are defined in git for the same reason. A stack that lives only on one machine cannot be reviewed, and it cannot be rebuilt from what is written down.
Continuous integration
Text version: a change lands in git, CI runs a type check and the production build, a preview opens for the pull request, a person reviews, and merge to main updates https://ai.skeen.biz. Secrets stay out of the repository.
- Every pull request runs a type check and the production build.
- A preview deployment is opened for that pull request.
- Merge to
mainis what updates https://ai.skeen.biz. - Closing a pull request removes its preview.
The check runs. Whether the repository requires it before merge is a setting, and this page does not claim that setting is on.
Security principles
- A person approves anything external. The failure mode is an action that cannot be unsent.
- Private documents stay on systems we operate. Copying the corpus to a public model is a leak, not a draft.
- Access to systems of record is least-privilege and strongly authenticated. The connected systems are not listed here.
- Secrets stay out of code. A secret in git is a secret in history.
- This site is previewed before it is production. The public host is not where operational credentials live.
- Reviews that matter are written down, so the next person can see why a gate was there.
What stays manual
Publishing this site. Sending on behalf of the practice. Spending money. Steps where a mistake is hard to undo. Automation stops at the draft or the queue.