About
I build security products, and I write about why so many of them stall somewhere between a good decision and a working thing.
Day to day I build cyber security products with startups. I advise several others on product management, on how software actually gets built, and on where AI changes the work rather than just the tooling.
I also write code. Not well enough to call myself a developer, and I don't. Well enough to read a diff, follow an architecture argument, and tell when an estimate is describing the system rather than the engineer. That distinction is most of what this site is about. Knowing how a thing gets built is a different job from building it, and the distance between those two jobs is where products go wrong.
Which is why I write. Most of these arguments get sharpened in public before they end up here. This is where the durable version lives, filed by theme instead of by date, because a good argument about ownership does not expire at the end of a quarter.
Elsewhere
Most of this writing also runs on LinkedIn. The comments over there are frequently better than what I wrote.
A LinkedIn DM is the best way to reach me. I read them.