{"generated":"2026-10-09T13:43Z","map_generated":"2026-10-09T13:43Z","groups":{"doc-eng":{"name":"Engineering docs","color":"#FFB547"},"doc-obs":{"name":"Observability docs","color":"#3DDC97"},"doc-res":{"name":"Research docs","color":"#FF8FD8"},"doc-fin":{"name":"FinOps docs","color":"#FF7A6B"},"doc-sre":{"name":"SRE Handbook docs","color":"#6FA8FF"},"doc-std":{"name":"Standards and Compliance docs","color":"#B79CFF"},"service":{"name":"Service","color":"#FFB547"},"substack":{"name":"Substack","color":"#FF8FD8"},"mb":{"name":"machinebehavior.io","color":"#FFB547"},"tychat":{"name":"tychat.io","color":"#3DDC97"},"reddit":{"name":"Reddit","color":"#FF4D5E"},"github":{"name":"GitHub","color":"#EFE6D2"},"utt":{"name":"uncovertechtalent.com","color":"#6FA8FF"},"dashboard":{"name":"Grafana dashboard","color":"#5EEAD4"}},"items":[{"t":"Engineering","u":"/inside/docs/eng/","g":"doc-eng","d":"How the three sites are built, gated and deployed, plus the map crawler, the Inside portal and this docs tree.","l":["moc","engineering"],"x":"This space documents the systems behind machinebehavior.io, tychat.io and uncovertechtalent.com: how each site is built, the conformity gate that every push passes before it serves readers, the deploy job, the crawler that draws the map of the work , the Inside front page and thi"},{"t":"Access model","u":"/inside/docs/eng/access-model/","g":"doc-eng","d":"Inside is a public demo of an intranet. In production it sits behind single sign-on with public, internal and restricted spaces, access granted per person and device, and no network perimeter.","l":["inside","security","access","sso","zero-trust"],"x":"Inside, its docs, the service catalog, the status page and the board are open to read on purpose: they show how an intranet for a small company is built. Nothing on this site has a login, and nothing asks for credentials. This page states what is public today and how access works"},{"t":"Add a page to machinebehavior.io","u":"/inside/docs/eng/add-a-page/","g":"doc-eng","d":"The five things a new page needs to pass the gate, and the commands to check them before pushing.","l":["how-to","pages","gate"],"x":"A new page passes the gate when it has a directory URL, a self canonical, a sitemap entry, an llms.txt line and root-absolute links. It joins the navigation with one entry in site/nav.yml . Docs pages get all of this from the generator; see Docs tree . Steps Create <name>/index.h"},{"t":"ADR-0001: Root-absolute links only","u":"/inside/docs/eng/adr-0001-root-absolute-links/","g":"doc-eng","d":"Internal links are root-absolute directory URLs (`/man/`, `/style.css`), never relative and never ending in `.html`.","l":["adr","decision"],"x":"Context Pages moved between hosts, previews and directory URLs, and relative links broke when a page moved one level. Some links ended in .html , so one page answered at two URLs. Decision Internal links are root-absolute directory URLs ( /man/ , /style.css ), never relative and "},{"t":"ADR-0002: The deploy is gated","u":"/inside/docs/eng/adr-0002-deploy-is-gated/","g":"doc-eng","d":"GitHub Pages deploys from GitHub Actions, and the deploy job depends on the conformity job.","l":["adr","decision"],"x":"Context The conformity checks ran after a page was live, so they could only detect a problem that readers already saw. Decision GitHub Pages deploys from GitHub Actions, and the deploy job depends on the conformity job. A failed check stops the deploy and the previous build stays"},{"t":"ADR-0003: The map loads d3 and its fonts from public CDNs","u":"/inside/docs/eng/adr-0003-map-loads-from-public-cdns/","g":"doc-eng","d":"The map page loaded d3 7.9.0 from cdnjs and Space Grotesk and JetBrains Mono from Google Fonts.","l":["adr","decision"],"x":"Recorded after the fact from commit 604f178 . Context The first version of the map needed a force-directed graph library and the two site fonts, and the fastest path was to link them. Decision The map page loaded d3 7.9.0 from cdnjs and Space Grotesk and JetBrains Mono from Googl"},{"t":"ADR-0004: The map refresh keeps the larger snapshot","u":"/inside/docs/eng/adr-0004-map-refresh-keeps-larger-snapshot/","g":"doc-eng","d":"The deploy job replaces `map/graph.json` only when the new crawl has at least as many nodes and links as the committed snapshot.","l":["adr","decision"],"x":"Context The deploy job crawls the live sites before each deploy. Substack answers some GitHub runners with 403, and a partial crawl would shrink the map. Decision The deploy job replaces map/graph.json only when the new crawl has at least as many nodes and links as the committed "},{"t":"ADR-0005: Deploys feed Grafana without changing the workflows","u":"/inside/docs/eng/adr-0005-deploys-feed-grafana/","g":"doc-eng","d":"A separate exporter polls the GitHub Actions API and writes runs, steps and gate checks to Loki and Prometheus.","l":["adr","decision"],"x":"Context The deploy history of three sites lived only on the GitHub Actions pages, one repository at a time, and one repository is private. Decision A separate exporter polls the GitHub Actions API and writes runs, steps and gate checks to Loki and Prometheus. The site workflows s"},{"t":"ADR-0006: Inside reads the deploy feed from the GitHub API in the browser","u":"/inside/docs/eng/adr-0006-inside-reads-github-api-in-browser/","g":"doc-eng","d":"The page called the GitHub Actions API from the visitor's browser for each repository on every load.","l":["adr","decision"],"x":"Recorded after the fact from commit cc9db2a . Context The first Inside front page needed the latest workflow runs of the public site repositories. Decision The page called the GitHub Actions API from the visitor's browser for each repository on every load. Consequences Each visit"},{"t":"ADR-0007: Docs search over its own index, Enter opens the first hit","u":"/inside/docs/eng/adr-0007-docs-search-own-index/","g":"doc-eng","d":"The docs top bar searched `inside/docs/search.json` only, and Enter opened the first hit.","l":["adr","decision"],"x":"Recorded after the fact from commit 0e4fe0a . Context The first docs tree needed a search box before any other part of Inside had one. Decision The docs top bar searched inside/docs/search.json only, and Enter opened the first hit. Consequences Inside had a second search box over"},{"t":"ADR-0008: Docs pages are map nodes","u":"/inside/docs/eng/adr-0008-docs-pages-are-map-nodes/","g":"doc-eng","d":"Docs pages carry their front matter as meta tags, and the crawler adds them to the graph with parent links as `tree` edges.","l":["adr","decision"],"x":"Context The map showed the published pages and posts, but none of the reference notes behind them. Decision Docs pages carry their front matter as meta tags, and the crawler adds them to the graph with parent links as tree edges. Consequences One graph holds everything published,"},{"t":"ADR-0009: Publish vault notes with a review label","u":"/inside/docs/eng/adr-0009-vault-notes-with-review-label/","g":"doc-eng","d":"The SRE folder and 28 standards clusters are published as docs spaces, with private addresses, e-mail addresses and the former employer's name redacted, and a label on every page saying it has not been reviewed against its source.","l":["adr","decision"],"x":"Context The knowledge vault holds the SRE handbook and the standards reference work, written over months with models, and none of it had been checked against its sources for publication. Decision The SRE folder and 28 standards clusters are published as docs spaces, with private "},{"t":"ADR-0010: No third-party requests on page load","u":"/inside/docs/eng/adr-0010-no-third-party-requests/","g":"doc-eng","d":"Fonts and d3 are served from the site itself, and the Inside deploy feed is a JSON written by the deploy job.","l":["adr","decision"],"x":"Context Fonts came from Google, d3 from a CDN and the Inside deploy feed from the GitHub API, so opening a page passed the visitor's address to three companies. The LG München I judgment of 2022-01-20 (3 O 17493/20) found this unlawful for Google Fonts loaded without consent. Dec"},{"t":"ADR-0011: A public ticket board from GitHub Issues","u":"/inside/docs/eng/adr-0011-ticket-board-from-github-issues/","g":"doc-eng","d":"Work items are GitHub Issues on the public repository, shown on [the board](/inside/board/).","l":["adr","decision"],"x":"Context The backlog from the platform review needed one public system of record that agent sessions and readers can both use. Decision Work items are GitHub Issues on the public repository, shown on the board . The deploy job writes inside/board/issues.json ( scripts/board_snapsh"},{"t":"ADR-0012: One top bar and one search index for Inside","u":"/inside/docs/eng/adr-0012-one-top-bar-and-search/","g":"doc-eng","d":"Every Inside page carries one top bar, written by `bar()` in `scripts/inside_chrome.py`.","l":["adr","decision"],"x":"Context There were three navigations (the site menu, the Inside header, the docs bar) and two search boxes over two indexes, and docs search opened the first hit on Enter. Decision Every Inside page carries one top bar, written by bar() in scripts/inside_chrome.py . One index, /i"},{"t":"ADR-0013: A service catalog from YAML in the repository","u":"/inside/docs/eng/adr-0013-service-catalog-from-yaml/","g":"doc-eng","d":"Every service is one YAML file in `services/`, validated at build by a strict standard-library reader.","l":["adr","decision"],"x":"Context The systems were documented page by page, but nothing listed them in one place with who answers for each, how much each matters and where its runbooks are. Decision Every service is one YAML file in services/ , validated at build by a strict standard-library reader. The b"},{"t":"ADR-0014: A status page from records the site already publishes","u":"/inside/docs/eng/adr-0014-status-page-from-published-records/","g":"doc-eng","d":"`/inside/status/` reads each site's gate record, `/inside/deploys.json` and the map snapshot time in the browser, and shows the incident history from `incidents/*.yml` with the stages Investigating, Identified, Monitoring and Resolved.","l":["adr","decision"],"x":"Context A visitor could see metrics on the dashboards but not, at a glance, whether a service was healthy or what went wrong last week. Decision /inside/status/ reads each site's gate record, /inside/deploys.json and the map snapshot time in the browser, and shows the incident hi"},{"t":"ADR-0015: Owner and review dates on every docs page","u":"/inside/docs/eng/adr-0015-owner-and-review-dates/","g":"doc-eng","d":"Docs front matter gains `owner`, `reviewed`, `review_by` and `type` (Diátaxis).","l":["adr","decision"],"x":"Context The docs pages carried dates, but none said who keeps it true or when it was last checked. Decision Docs front matter gains owner , reviewed , review_by and type (Diátaxis). The 50 hand-written pages carry all four, with the date each was written from its source as the fi"},{"t":"ADR-0016: A public-demo banner and a stated access model","u":"/inside/docs/eng/adr-0016-demo-banner-and-access-model/","g":"doc-eng","d":"Every Inside page except the map carries a banner saying the intranet is a public demo and that in production it sits behind single sign-on.","l":["adr","decision"],"x":"Context A visitor should know the intranet is public on purpose, and a founder reading it should see how access would work in a company. Decision Every Inside page except the map carries a banner saying the intranet is a public demo and that in production it sits behind single si"},{"t":"ADR-0017: State the on-call model and propose Alertmanager routing","u":"/inside/docs/eng/adr-0017-on-call-model/","g":"doc-eng","d":"The [On-call and escalation](doc:obs/on-call) page states the model as it runs: one operator, agent sessions as responders, the deploy gate as the only control that acts on its own, and no Alertmanager.","l":["adr","decision"],"x":"Context A founder checking the setup asks who gets woken up. Prometheus evaluates 13 alert rules, and none reaches a person. Decision The On-call and escalation page states the model as it runs: one operator, agent sessions as responders, the deploy gate as the only control that "},{"t":"ADR-0018: Numbered decision records and a generated changelog","u":"/inside/docs/eng/adr-0018-numbered-records-and-changelog/","g":"doc-eng","d":"Each decision is a numbered record (ADR-0001 onward) with a status (proposed, accepted, superseded), context, decision and consequences, one docs page each.","l":["adr","decision"],"x":"Context The decision log had the shape of architecture decision records, but an entry could not be cited by number or superseded cleanly, and there was no changelog. Decision Each decision is a numbered record (ADR-0001 onward) with a status (proposed, accepted, superseded), cont"},{"t":"ADR-0019: Publish the definition draft before the committee route","u":"/inside/docs/eng/adr-0019-definition-published-before-committee/","g":"doc-eng","d":"The working draft \"Continuous Conformity for Deployed AI Systems\" (0.3, 36 requirements) is public as a reference at /continuous-conformity/ before any standards committee has seen it, reversing the committee-first order of 2026-10-04.","l":["adr","decision","conformity","standards"],"x":"Context The definition draft (terms, requirements with M/A/H marks, crosswalk to the AI Act, DORA, GDPR and NIST) was written for a standards committee. On 2026-10-04 the plan was committee first: comment on ISO/IEC DIS 23282 through the national body, seek a seat in the AI mirro"},{"t":"ADR-0020: A five-minute founder tour on one page","u":"/inside/docs/eng/adr-0020-founder-tour/","g":"doc-eng","d":"One page at /inside/tour/ walks a founder through the platform in six stops, each with a screenshot of the live page, what to notice, what it does in a company, and the link.","l":["adr","decision"],"x":"Context A founder who gets one link has about five minutes. Inside has a front page, a service catalog, six docs spaces, a status page, a board and a deploy gate, and a first visit does not show which pages carry the evidence. The research note on enterprise portals lists what to"},{"t":"ADR-0021: One navigation source for the whole site","u":"/inside/docs/eng/adr-0021-one-navigation-source/","g":"doc-eng","d":"site/nav.yml defines the sections and pages once; scripts/site_chrome.py writes the top bar, breadcrumbs, sidebar and footer of every page between markers and checks the sitemap and llms.txt against the tree.","l":["adr","decision","navigation"],"x":"Context The site had two menus. Research pages carried a hand-copied list of eight links; Inside pages carried the top bar from scripts/inside_chrome.py ( ADR-0012 ). The two halves read as two sites, the research pages had no breadcrumbs, the docs breadcrumbs started at Docs, an"},{"t":"ADR-0022: Section sidebars from the navigation source","u":"/inside/docs/eng/adr-0022-section-sidebars/","g":"doc-eng","d":"Research and Inside pages carry a sidebar with every page of their section, written from site/nav.yml; a column beside the content from 1100 px, a closed disclosure above it on narrower screens.","l":["adr","decision","navigation"],"x":"Context The docs had a page tree beside every page; the research pages and the Inside pages had none. A reader on a claims page could not see that experiments, registers, case files and reference texts sit next to it, and an Inside page showed its siblings only in the top bar. Ba"},{"t":"ADR-0023: Topic hubs across research, docs, posts and tickets","u":"/inside/docs/eng/adr-0023-topic-hubs/","g":"doc-eng","d":"Seven topic hubs at /topics/<key>/ list every research page, Inside page, docs page, post and board issue on one subject; site/topics.yml holds the rules, and a Topics block in each sidebar marks the topics of the current page.","l":["adr","decision","navigation","topics"],"x":"Context The site is cut by kind: research pages, Inside, six docs spaces, posts on uncovertechtalent.com and Substack, and the board. A reader who comes for one subject, for example observability or the stance layer, has to visit each part. The labels already exist in three place"},{"t":"Ticket board","u":"/inside/docs/eng/board/","g":"doc-eng","d":"The board at /inside/board/ shows the work on the platform in columns, from GitHub Issues on the public repository, as a snapshot written at each deploy.","l":["board","issues","workflow","inside"],"x":"The board shows the open work on machinebehavior.io and the platform behind it, plus the work done in the last 30 days. GitHub Issues on uncovertechtalent/machinebehavior.io is the system of record; the board is a read-only view of it. How the data gets to the page The deploy job"},{"t":"Changelog","u":"/inside/docs/eng/changelog/","g":"doc-eng","d":"What changed on machinebehavior.io and the platform behind it, by day and grouped Added, Changed and Fixed, generated from closed issues and commits.","l":["changelog","releases","history"],"x":"What changed on machinebehavior.io and the platform behind it, newest first: 16 closed issues and 118 commits since 2026-08-07, grouped by day into Added, Changed and Fixed. Generated by scripts/build_changelog.py from the closed issues and the commit history ; the conformity bot"},{"t":"Conformity gate","u":"/inside/docs/eng/conformity-gate/","g":"doc-eng","d":"The checks every page passes before a deploy: blocking rule hits, placeholders, prediction hashes and site consistency, with warnings logged.","l":["conformity","gate","quality"],"x":"The conformity gate is a set of mechanical checks run by .github/actions/conformity/run.py against every published page. A blocking failure stops the deploy; the previous build stays live. Results are rendered at /conformity/ (self-assessment, not a certification) and stored in c"},{"t":"Decision records","u":"/inside/docs/eng/decision-log/","g":"doc-eng","d":"Numbered architecture decision records for the platform, each with a status, the context, the decision and its consequences; superseded records stay and link their successor.","l":["adr","decisions","governance"],"x":"Each record states one decision: its number, date and status, the context that forced it, the decision, and what it costs. Decisions are made by Stefan Coetzee unless the record says otherwise. A record is never deleted: when a later decision replaces it, its status becomes super"},{"t":"Deploy pipeline","u":"/inside/docs/eng/deploy-pipeline/","g":"doc-eng","d":"One GitHub Actions workflow runs the conformity checks, commits the record, and deploys to Pages only when the checks pass.","l":["deploy","github-actions","pipeline"],"x":"Every push to main of machinebehavior.io starts the workflow .github/workflows/conformity.yml . The workflow also runs every Monday at 06:17 UTC and by hand. It has two jobs, and the second runs only if the first passes. Job 1: conformity checks Check out main with full history. "},{"t":"Docs tree","u":"/inside/docs/eng/docs-tree/","g":"doc-eng","d":"How this documentation is built from markdown sources and the knowledge vault, how front matter becomes the tree, labels and dates, and how pages enter the map.","l":["docs","generator","front-matter"],"x":"The docs at /inside/docs/ are static pages built by scripts/build_docs.py from markdown files in scripts/docs/<space>/ . Four spaces are written by hand in the repository (Engineering, Observability, Research, FinOps); two come from the knowledge vault through scripts/import_vaul"},{"t":"Inside portal","u":"/inside/docs/eng/inside-portal/","g":"doc-eng","d":"Inside is one static page that reads live data in the browser: site status, the deploy feed, the latest work, experiments and the Grafana dashboards.","l":["inside","portal","frontend"],"x":"Inside is the front page for the whole body of work. It is one static HTML file, inside/index.html ; every live panel is read in the visitor's browser when the page loads. Nothing runs on a server. Panels and their data Panel Data Notes Site status /conformity/latest.json of each"},{"t":"Map crawler","u":"/inside/docs/eng/map-crawler/","g":"doc-eng","d":"scripts/crawl_map.py crawls the three sites and Substack into map/graph.json, splitting body links from navigation and keeping a node per page, post, repo, thread and tag.","l":["map","crawler","graph"],"x":"scripts/crawl_map.py builds map/graph.json , the data behind the map of the work and the front page of Inside . It runs in the deploy job on every push and on the Monday schedule, and by hand. python3 scripts/crawl_map.py map/graph.json What it crawls Every URL in the sitemap.xml"},{"t":"Gate blocked a deploy","u":"/inside/docs/eng/runbook-gate-blocked/","g":"doc-eng","d":"The conformity job failed, so the deploy did not run and the previous build is still live; find the failing check, fix the page, push again.","l":["runbook","gate"],"x":"Symptom. The Conformity workflow is red; the \"Deploy to Pages\" job shows as skipped; the live site still shows the previous build. Steps Open the failed run, or run the dry run locally: the last line names each check with its result. Read the failing check's evidence lines at /co"},{"t":"Push rejected after a deploy","u":"/inside/docs/eng/runbook-push-rejected/","g":"doc-eng","d":"The conformity bot commits after every run, so main moves without you; rebase on it and push again.","l":["runbook","git"],"x":"Symptom. git push fails with \"rejected, fetch first\" right after a run, although nobody else pushed. Cause. Every conformity run commits conformity/latest.json and conformity/index.html as conformity-bot with [skip ci] . Your local main is one commit behind. Fix git pull --rebase"},{"t":"Link check flags a template string","u":"/inside/docs/eng/runbook-template-href/","g":"doc-eng","d":"The gate reads every href in the page source, including ones inside JavaScript template strings; build such links with a.href in code.","l":["runbook","gate","javascript"],"x":"Symptom. site.consistency fails with \"relative link\" and a value that starts with a dollar sign and a brace, which does not appear on the rendered page. Cause. The check scans the page source with a regular expression for href=\"...\" . An attribute written inside a JavaScript temp"},{"t":"Runbooks","u":"/inside/docs/eng/runbooks/","g":"doc-eng","d":"Step-by-step fixes for the failures seen so far in the build and deploy of the sites.","l":["runbook","operations"],"x":"Each runbook covers one failure that has happened, with how to see it, the cause and the fix. Observability runbooks (Loki, Grafana) are in the Observability space . Symptom Runbook The deploy job did not run; the conformity job is red Gate blocked a deploy git push is rejected a"},{"t":"Service catalog","u":"/inside/docs/eng/service-catalog/","g":"doc-eng","d":"The catalog at /inside/services/ is built from one YAML file per service in services/, validated at build; each service is a page and a node in the map.","l":["inside","services","catalog","ownership"],"x":"The service catalog lists every service that runs the platform, with the owner, tier, lifecycle, SLOs, dashboard, runbooks, docs, repository and dependencies. Each service has its own page, and each page is a node in the map linked to its docs and dashboards. Source One file per "},{"t":"Site architecture","u":"/inside/docs/eng/site-architecture/","g":"doc-eng","d":"Three static sites on GitHub Pages, one shared conformity action, and Substack as the fourth publication.","l":["architecture","github-pages","static-site"],"x":"Three sites publish the work. All three are static files served by GitHub Pages and deployed by GitHub Actions. A fourth publication, the Substack newsletter, is hosted by Substack and only read by the crawler. Site Built with Repository Role machinebehavior.io Hand-written HTML,"},{"t":"Site navigation and chrome","u":"/inside/docs/eng/site-navigation/","g":"doc-eng","d":"One navigation source, site/nav.yml, writes the top bar, the breadcrumbs, the section sidebars and the footer of every page, and checks the sitemap and llms.txt against the tree.","l":["navigation","frontend","site","breadcrumbs"],"x":"machinebehavior.io is one portal: \"Machine Behavior\" is the site, Inside is the portal within it. Every page carries the same top bar, breadcrumbs from Home to the page, and the same footer. The sections and their pages are defined once, in site/nav.yml ; scripts/site_chrome.py w"},{"t":"Status page","u":"/inside/docs/eng/status-page/","g":"doc-eng","d":"How /inside/status/ decides the state of each service from records the site already publishes, and how to open, update and close an incident in incidents/*.yml.","l":["inside","status","incidents","how-to"],"x":"The status page shows the current state of every service in the catalog and the incident history. It is built by scripts/build_inside.py from services/*.yml and incidents/*.yml ; the service states are read in the visitor's browser. Where the state comes from The page reads only "},{"t":"Top bar and search","u":"/inside/docs/eng/top-bar-and-search/","g":"doc-eng","d":"One top bar on every page from one navigation source, and one search index over the docs, the services and the map, with a results page on Enter.","l":["inside","search","navigation","frontend"],"x":"Every page of the site carries the same top bar: the couch mark and \"Machine Behavior\" (the home page), the sections Research, Inside, Docs and Map, and the search box. The current section is marked. The bar comes from one source, so a page cannot show a different menu. One sourc"},{"t":"FinOps","u":"/inside/docs/fin/","g":"doc-fin","d":"The cost side of the platform in the FinOps Foundation's terms (phases, principles, personas, domains, FOCUS) and how each applies to a one-person platform built with Claude Code.","l":["finops","cost","framework","focus"],"x":"The FinOps space documents what the platform behind machinebehavior.io costs, how each cost is metered and which unit costs follow from the meters. It uses the FinOps Foundation's framework for the practice and FOCUS, the FinOps Open Cost and Usage Specification, for the data. Ev"},{"t":"The phantom two million","u":"/inside/docs/fin/anomaly-the-phantom-two-million/","g":"doc-fin","d":"A FinOps anomaly case from 2026-10-09: parallel Claude Code sessions wrote into one counter series, and Prometheus reported USD 1.97M for a week that cost USD 1,003 at list price.","l":["finops","anomaly","data-quality","case","claude-code"],"x":"For the week to 2026-10-09 00:00 UTC, increase() over Claude Code's cost counter in Prometheus reported USD 1,970,946.62. The per-request events in Loki for the same seven days (2026-10-02 to 2026-10-08) sum to USD 1,003.45 at list price. The counter overstated spend by a factor "},{"t":"Budgets and alerts","u":"/inside/docs/fin/budgets-and-alerts/","g":"doc-fin","d":"The cost controls that exist (the Claude Code spend alert, the AWS monthly budget with its internal dashboard and four alert rules, the eval harness caps), why only the AWS Budgets e-mail reaches a person, and what a budget alert for Claude Code would look like.","l":["finops","budgets","alerts","prometheus","loki"],"x":"Two kinds of cost control exist. For Claude Code, ClaudeCodeSpendSpike fires when the list-price value of calls in the trailing hour stays above USD 40 for 10 minutes; until 2026-10-09 the threshold was USD 20. For the AWS account, a monthly cost budget in AWS Budgets e-mails at "},{"t":"Cost model","u":"/inside/docs/fin/cost-model/","g":"doc-fin","d":"Every cost component of the platform with its billing model, its meter and the amount where a source exists; components without a meter say so.","l":["finops","cost-model","allocation"],"x":"Nine components make up the cost of the platform. Claude Code, GitHub Actions and the GPU's energy have meters whose figures are published here. Since 2026-10-09 the AWS account that runs the Bedrock evals is metered too: an internal dashboard reads its daily cost by service from"},{"t":"FOCUS export","u":"/inside/docs/fin/focus-export/","g":"doc-fin","d":"A FOCUS 1.4-shaped CSV of the platform's metered costs for 2026-10-01 to 2026-10-08, the script that writes it, the column mapping and the declared deviations from the specification.","l":["finops","focus","export","csv"],"x":"The file focus-2026-10-01-to-2026-10-08.csv holds the platform's metered costs in the Cost and Usage columns of FOCUS 1.4. It has 35 rows: 24 for Claude Code (one per UTC day and model) and 11 for GitHub Actions (one per UTC day and public repository). scripts/focus_export.py wro"},{"t":"Showback","u":"/inside/docs/fin/showback/","g":"doc-fin","d":"The list-price value of the platform's usage, as Claude Code and the eval harness price it, set against what is billed, and the reasons the two differ.","l":["finops","showback","pricing","claude-code"],"x":"Showback reports the cost of usage to the people who caused it, without an internal invoice; chargeback books the cost to their budget. The FinOps Foundation covers both in the capability Invoicing & Chargeback . On this platform showback compares two numbers for each component: "},{"t":"Unit economics","u":"/inside/docs/fin/unit-economics/","g":"doc-fin","d":"Cost per unit of output with real numbers: Claude Code spend per day, per model, per API call, per million tokens and per commit; runner time per deploy; cost per eval run.","l":["finops","unit-economics","kpi","claude-code"],"x":"The method follows Unit Economics of Infrastructure in the SRE Handbook: divide spend by a unit the work already counts. The units here are days, API calls, tokens, commits, deploy runs and eval runs. Claude Code figures are list-price values from Claude Code's own cost_usd ; Sho"},{"t":"Observability","u":"/inside/docs/obs/","g":"doc-obs","d":"Metrics, logs and traces for Claude Code, a self-hosted Ollama server, its host and three website deploys, collected by one Docker Compose stack on a home server.","l":["observability","prometheus","loki","tempo","grafana"],"x":"The Observability space documents agent-observability: a Docker Compose stack that collects metrics, logs and traces from Claude Code, a self-hosted Ollama server, the host that runs Ollama, and the GitHub Actions deploys of three websites. Stefan Coetzee runs it on a home server"},{"t":"Alerts and SLOs","u":"/inside/docs/obs/alerts-and-slos/","g":"doc-obs","d":"The recording rules, service level objectives and 17 alerts that Prometheus and the Loki ruler evaluate, with thresholds from the rule files.","l":["prometheus","alerts","slo","loki"],"x":"Prometheus evaluates recording rules and 17 alerts from recording.yml and alerts.yml . The Loki ruler adds one recording rule for Claude Code spend. The compose file runs no Alertmanager, so no alert reaches a person; who responds and a proposed routing are on On-call and escalat"},{"t":"Architecture","u":"/inside/docs/obs/architecture/","g":"doc-obs","d":"How the collectors, the three stores, Grafana and the public front door of the observability stack connect, and how the stack is deployed.","l":["architecture","alloy","prometheus","loki","tempo","grafana"],"x":"The stack is one Docker Compose project on a home server: collectors feed Prometheus, Loki and Tempo, and Grafana reads all three. Every service is defined in docker-compose.yml . Collectors Alloy receives OTLP on port 4317 (gRPC) and 4318 (HTTP); its pipeline UI is on 12345. An "},{"t":"Dashboards as code","u":"/inside/docs/obs/dashboards-as-code/","g":"doc-obs","d":"How grafana/build.py generates every dashboard as JSON, how the public cuts derive from the internal dashboards, and how a change reaches Grafana.","l":["grafana","dashboards-as-code","python"],"x":"Every dashboard in the stack is generated by grafana/build.py . Grafana provisions the generated JSON read-only, so the Python file is the source of truth and the Grafana UI holds no edits of its own. Workflow Edit grafana/build.py . Run python3 grafana/build.py . It writes one J"},{"t":"Deploy exporter","u":"/inside/docs/obs/deploy-exporter/","g":"doc-obs","d":"A standard-library Python service that reads the GitHub Actions deploy runs of three websites, writes them to Loki and serves the latest state as Prometheus metrics on port 9201.","l":["loki","prometheus","github-actions","deploys"],"x":"The deploy-exporter reads the GitHub Actions deploy runs of machinebehavior.io, tychat.io and uncovertechtalent.com and turns them into Loki lines and Prometheus metrics. It reads the GitHub API from outside the repositories, so the site workflows stayed unchanged, and a run that"},{"t":"Loki streams","u":"/inside/docs/obs/loki-streams/","g":"doc-obs","d":"The Loki streams the stack writes, with their labels and line fields, for website deploy records and for Claude Code events.","l":["loki","logql","reference"],"x":"Loki holds two kinds of data: website deploy records pushed by the deploy-exporter, and Claude Code events sent through Alloy. Retention is 90 days. Website deploy streams The deploy-exporter pushes one JSON line per finished run, step and gate check. Source: push_loki() in deplo"},{"t":"Metrics reference","u":"/inside/docs/obs/metrics-reference/","g":"doc-obs","d":"Every Prometheus metric the deploy-exporter and the ollama-exporter serve, with type, labels and meaning, taken from the exporter source.","l":["prometheus","metrics","reference"],"x":"This page lists every metric the two exporters in the repository serve on /metrics . Names, types and labels come from deploy-exporter/exporter.py and ollama-exporter/exporter.py . Each histogram also serves _bucket , _sum and _count series. Deploy exporter, port 9201 Prometheus "},{"t":"On-call and escalation","u":"/inside/docs/obs/on-call/","g":"doc-obs","d":"The real on-call model: one operator, agent sessions as responders, the deploy gate as the one control that acts on its own, and 13 alert rules that page nobody because no Alertmanager runs. With a proposed routing.","l":["on-call","alerts","alertmanager","escalation","incidents"],"x":"Nothing pages anyone. Prometheus evaluates 13 alert rules, but the stack runs no Alertmanager and Prometheus has no alerting target, so a firing alert stays in Prometheus and Grafana until someone looks. One person answers for every service, and the agent sessions that build the "},{"t":"Public dashboards","u":"/inside/docs/obs/public-dashboards/","g":"doc-obs","d":"The five Grafana dashboards shared at grafana.scoetzee.de, what their panels show, and how each public cut differs from the internal dashboard.","l":["grafana","dashboards","public"],"x":"Five dashboards are public at https://grafana.scoetzee.de and framed on Inside . Grafana public dashboards do not resolve template variables, so every public dashboard is built without them in grafana/build.py . Dashboard Grafana uid Link Website deploys site-deploys open Claude "},{"t":"Counter resets from parallel sessions","u":"/inside/docs/obs/runbook-counter-resets-parallel-sessions/","g":"doc-obs","d":"Why Claude Code's cost counters in Prometheus report spend in the millions of USD, and how the stack reads spend and tokens from per-request events in Loki.","l":["runbook","prometheus","loki","claude-code"],"x":"Claude Code spend computed with increase() over its Prometheus cost counter reports millions of USD. In the week to 2026-10-09, increase() reported USD 1.97M, while the API calls cost USD 76 in the last 24 hours of that week. Cause Claude Code exports cumulative counters with no "},{"t":"Backfilled runs missing in Loki","u":"/inside/docs/obs/runbook-loki-backfill-missing/","g":"doc-obs","d":"What to do when the Website deploys dashboard shows no older runs after the deploy-exporter backfills from GitHub Actions.","l":["runbook","loki","deploy-exporter"],"x":"The Website deploys dashboard shows only recent runs, or none, right after the deploy-exporter starts with an empty state file, while the exporter log lists the runs it read. Cause The exporter pushes each run with the time it finished, so a backfill writes lines that are hours o"},{"t":"Share a dashboard publicly","u":"/inside/docs/obs/runbook-share-a-dashboard/","g":"doc-obs","d":"How to build a variable-free public cut of a dashboard, provision it, and turn on Grafana public sharing so it loads at grafana.scoetzee.de.","l":["runbook","grafana","public-dashboards"],"x":"A dashboard goes public in two parts: a public cut in build.py, and a public-dashboard record created through the Grafana API on the home server. Before you start Grafana public dashboards do not resolve template variables. A dashboard with variables gets a cut without them. Pane"},{"t":"Stat panel shows No data","u":"/inside/docs/obs/runbook-stat-panel-no-data/","g":"doc-obs","d":"Why Grafana stat panels on young series show No data over long time ranges, and how build.py switches them to instant queries.","l":["runbook","grafana","prometheus","loki"],"x":"A stat panel shows \"No data\" when the dashboard range is long, for example 7 days, while the metric has a current value. This applies to the Website deploys dashboard: its default range is 7 days, and the deploy-exporter's series start when the exporter starts. Cause By default a"},{"t":"Runbooks","u":"/inside/docs/obs/runbooks/","g":"doc-obs","d":"Step-by-step fixes for the known traps in the observability stack: missing backfill in Loki, empty stat panels, Claude Code counter resets and sharing a dashboard.","l":["runbook","operations"],"x":"These runbooks cover the traps found while running the stack. Each one gives the symptom, the cause, a check and the fix. Commands run on the home server from the repository directory unless a step says otherwise. Runbook Symptom Backfilled runs missing in Loki The Website deploy"},{"t":"Research","u":"/inside/docs/res/","g":"doc-res","d":"Internal view of the published research on machinebehavior.io, one page per study or record, with status, numbers, repo files and rerun steps.","l":["research","index"],"x":"Machine Behavior is a public research programme by Stefan Coetzee on the psychology of language models, run with case files, logged relapses and falsifiable claims. This space has one page per study or record published on machinebehavior.io : what it is, its status and numbers, w"},{"t":"Case files: case 12 and Running Conjobs for AI","u":"/inside/docs/res/case-files/","g":"doc-res","d":"Two harness case files: case 12, a licence rule found and acted on in 68.7 seconds, and a reported authority-injection specimen that was not reproduced.","l":["case-file","harness","authority-injection","self-assessment"],"x":"Two case files record single events of machine behaviour: in case 12 (2026-10-03) model plus harness found a licence rule in a file and acted on it in 68.7 seconds; Running Conjobs for AI (2026-10-06) is a reported authority-injection specimen, not reproduced. field case 12 Runni"},{"t":"Claims ledger","u":"/inside/docs/res/claims-ledger/","g":"doc-res","d":"Every substantive claim of the programme with its status, receipts and the observation that would refute it; seven claims, four supported, one refuted, one open, one proposed.","l":["claims","falsification","ledger"],"x":"The claims ledger lists each claim of the programme with its status, receipts and refutation condition; of seven claims, four are supported, one is refuted, one is open with its prediction refuted, and one is proposed. field value status running; refuted claims stay listed latest"},{"t":"Conformity self-assessment, run 1","u":"/inside/docs/res/conformity-self-assessment/","g":"doc-res","d":"One working AI setup scored by the model inside it against 35 draft requirements and a hashed prediction, with pass 4, partial 16, gap 13 and n/a 2 (self-assessment, not a certification).","l":["conformity","self-assessment","prereg","second-rater"],"x":"In run 1 the model inside Stefan Coetzee's working AI setup scored the setup against the 35 requirements of the working draft \"Continuous Conformity for Deployed AI Systems\" (draft 0.2): pass 4, partial 16, gap 13, n/a 2, against a prediction hashed before scoring that matched 29"},{"t":"Weekly decision-layer probe","u":"/inside/docs/res/decision-layer-probe/","g":"doc-res","d":"A weekly rerun of a frozen experiment 04 subset on a reference model, recorded for requirement CC-6.6; first record 2026-10-07, record-only until 2026-11-04.","l":["probe","conformity","stance","record-only"],"x":"The decision-layer probe reruns a frozen subset of experiment 04 on a reference model and records the fold rate for requirement CC-6.6; the first record (2026-10-07) shows a fold rate of 0.727 for the bare arm and 0.4 for the arm with the short stance instruction. field value sta"},{"t":"02: Exemplar seeding","u":"/inside/docs/res/exemplar-seeding/","g":"doc-res","d":"Tested whether two corrected-output exemplars injected at session start lower cold-start relapse; result, no change at this dose, with three earlier attributions withdrawn.","l":["experiments","momentum","cold-start","null-result"],"x":"Exemplar seeding was a test of whether two corrected-output exemplar pairs injected at every session start pull cold-start relapse toward the mid-session rate; scored by blocked-turn event, the result is no change at this dose (1.00 per 10K characters against a 0.84 control). fie"},{"t":"Experiment 04: folding under pressure","u":"/inside/docs/res/experiment-04-folding-under-pressure/","g":"doc-res","d":"Decision-layer test of whether a model keeps a correct verdict under scripted pushback; qwen3-coder-30b folded on 75 percent of eligible baseline runs, three larger models on none.","l":["eval","sycophancy","prereg","stance"],"x":"Experiment 04 is a test of whether a model keeps a correct WAIT verdict under four turns of scripted pushback; on qwen3-coder-30b the baseline folded on 75 percent of eligible runs (42 of 56), and gpt-oss-120b, DeepSeek V3.2 and Kimi K2.5 folded on 0 of 72 baseline runs each. fie"},{"t":"Experiments","u":"/inside/docs/res/experiments/","g":"doc-res","d":"Overview of the four published experiments and the weekly decision-layer probe, with status, dates and headline numbers for each.","l":["experiments","overview","eval"],"x":"Four studies are published on /experiments/ : the temporal half-life is refuted, exemplar seeding showed no change at its dose, the fawn-opener benchmark has a pilot only, and experiment 04 found folding under pressure in one of four open-weight models. field value status 01 refu"},{"t":"03: Cross-model fawn-opener benchmark","u":"/inside/docs/res/fawn-opener-benchmark/","g":"doc-res","d":"Pre-registered benchmark of how often each model opens a reply with a fawn marker, bare and with an instruction against it; pilot run 2026-09-23, clean run not yet run.","l":["eval","sycophancy","prereg","lexical","benchmark"],"x":"The fawn-opener benchmark measures how often a model opens a reply with a fawn marker, with and without an instruction against it; it was pre-registered on 2026-09-23, a pilot ran the same day with no reading scored, and the clean run is not yet run. field value status pilot only"},{"t":"01: The half-life study","u":"/inside/docs/res/half-life-study/","g":"doc-res","d":"Tested whether suppressed output patterns relapse more as a session gets longer; the temporal half-life is refuted, and relapse clusters at cold starts.","l":["experiments","half-life","cold-start","refuted"],"x":"The half-life study was a test of whether relapse into banned output patterns grows with session length; the temporal half-life is refuted (mean normalised catch position 0.54 against 0.50 for no drift), and relapse clusters at cold starts, at about 5x the mid-session rate per un"},{"t":"Objections register and OBJ-4 incident log","u":"/inside/docs/res/objections-register/","g":"doc-res","d":"Fifteen objections against an unpublished model of human development, each with severity, status and a falsification test, plus the OBJ-4 incident log of 11 cases, none self-caught.","l":["objections","falsification","incident-log","second-rater"],"x":"The objections register holds fifteen objections against a model of human development that Stefan Coetzee is building (unpublished), each with a severity, a status and a falsification test; its OBJ-4 incident log records 11 cases of the auditing model committing the failure OBJ-4"},{"t":"Predictions and hashes","u":"/inside/docs/res/predictions-and-hashes/","g":"doc-res","d":"How predictions and preregistrations are frozen and hashed before a run, and how the conformity run checks every hash on every push; 8 files, all matching.","l":["prereg","predictions","sha256","integrity"],"x":"Predictions and preregistrations are written before a run, hashed with sha256 and listed in predictions/HASHES.txt; the conformity run on every push compares each file with its listed hash, and the run of 2026-10-09T07:54:32Z shows all 8 files matching. field value status 8 predi"},{"t":"Slips log","u":"/inside/docs/res/slips-log/","g":"doc-res","d":"Running log of register and stance slips caught while drafting the published pieces, with who caught each one; 72 slips from 2026-09-29 to 2026-10-06.","l":["slips","register","self-audit","log"],"x":"The slips log records the register and stance slips caught while drafting the site's pieces, and who caught each one; it holds 72 slips across 8 published pieces and 1 unpublished draft set, 57 of them caught by the same model session that wrote the text. field value status runni"},{"t":"SRE Handbook","u":"/inside/docs/sre/","g":"doc-sre","d":"Site reliability engineering from the knowledge vault: the manifesto, ten pillars, patterns, runbooks, tools and incident records.","l":["moc","sre"],"x":"Practical SRE training material. Opinionated, experience-driven, 30+ years of operational reality. The Manifesto The substrate principle : SRE as Truth Verified Working -- the discipline is about claims being true, verified, working. Parent of the ten pillars; same principle appl"},{"t":"AI Agents are Ops Work","u":"/inside/docs/sre/ai-agents-are-ops-work/","g":"doc-sre","d":"Managing the lifecycle of an AI agent in production is operational engineering, not developer engineering.","l":["ai-era-ops","manifesto","position"],"x":"Managing the lifecycle of an AI agent in production is operational engineering, not developer engineering. Agents need SLOs, error budgets, paging, and runbooks. Treat them like services because they fail like services. The category mistake When companies first deploy LLM agents,"},{"t":"Apple Silicon vs Desktop GPU for Inference","u":"/inside/docs/sre/apple-silicon-vs-desktop-gpu-for-inference/","g":"doc-sre","d":"A16 Neural Engine at 17 TOPS with unified memory beats a GTX 1650 4GB at local LLM inference.","l":["apple-silicon","hardware","inference","llm"],"x":"A16 Neural Engine at 17 TOPS with unified memory beats a GTX 1650 4GB at local LLM inference. Unified memory and purpose-built NPUs remove the transfer overhead and VRAM ceiling that cripple entry-level discrete GPUs. M4 Mini 24GB around EUR 863 handles Gemma 4 E4B Q4 comfortably"},{"t":"Authenticated Cookie Jar for Gated Posts","u":"/inside/docs/sre/authenticated-cookie-jar-for-gated-posts/","g":"doc-sre","d":"An exported cookies.txt lets yt-dlp list and fetch gated posts.","l":["mitigation","transcriber-incidents"],"x":"An exported cookies.txt lets yt-dlp list and fetch gated posts. It puts an authenticated session on the server, which was the owner's decision to make. It is the fix for the cause; the count checks only measure the gap. Part of Transcriber Incident Register"},{"t":"Back Up SQLite With the Backup Command","u":"/inside/docs/sre/back-up-sqlite-with-the-backup-command/","g":"doc-sre","d":"Use sqlite3 .backup, or checkpoint the WAL first, to get a restore point that holds every write.","l":["mitigation","transcriber-incidents"],"x":"Use sqlite3 .backup , or checkpoint the WAL first, to get a restore point that holds every write. Part of Transcriber Incident Register"},{"t":"Blameless Postmortem Discipline","u":"/inside/docs/sre/blameless-postmortem-discipline/","g":"doc-sre","d":"A blameless postmortem assumes the engineer behaved rationally given the information they had.","l":["incident-management","postmortem","practice"],"x":"A blameless postmortem assumes the engineer behaved rationally given the information they had. The investigation is about what system gave them that information — tooling, signals, processes, training. If your postmortem ends in \"be more careful\" or names a person, it failed. Wha"},{"t":"blind-search-ratchet-minecraft-beats-itself","u":"/inside/docs/sre/blind-search-ratchet-minecraft-beats-itself/","g":"doc-sre","d":"A simulation of Minecraft with no player let random mob behaviour kill the Ender Dragon after about 1.975 billion simulated years.","l":["agents","pattern","probability","search"],"x":"Blind search finishes only if progress is retained A simulation of Minecraft with no player let random mob behaviour kill the Ender Dragon after about 1.975 billion simulated years. It finished because each destroyed crystal stayed destroyed, so luck accumulated. Most of the time"},{"t":"BM25 Hybrid Retrieval for Graph-RAG","u":"/inside/docs/sre/bm25-hybrid-retrieval-for-graph-rag/","g":"doc-sre","d":"BM25 is a 1990s ranking function that's still the backbone of serious retrieval.","l":["graph-rag","pattern","rag","retrieval","search"],"x":"BM25 is a 1990s ranking function that's still the backbone of serious retrieval. TF with diminishing returns, IDF for rare-term boost, length normalization. Fast, interpretable, no GPU. Hybrid BM25 + embeddings + cross-encoder reranker beats pure semantic for code, identifiers, a"},{"t":"Bracket Pattern Process Check","u":"/inside/docs/sre/bracket-pattern-process-check/","g":"doc-sre","d":"Use pgrep -f \"[b]atchtranscribe.py\" or the ps | awk form.","l":["mitigation","transcriber-incidents"],"x":"Use pgrep -f \"[b]atch_transcribe.py\" or the ps | awk form. The bracket stops the pattern from matching the shell that runs the check. Also check the scrape_runs table. Part of Transcriber Incident Register"},{"t":"Certificate Rotation","u":"/inside/docs/sre/certificate-rotation/","g":"doc-sre","d":"Replace TLS certificates before expiry.","l":["runbook","security","tls"],"x":"Replace TLS certificates before expiry. Certificate-driven outages are entirely predictable, which makes them the most embarrassing kind. Automation is the right answer; this runbook is the manual fallback. Trigger Certificate expiry within 14 days (proactive) Certificate expiry "},{"t":"6. CI/CD & Deployment","u":"/inside/docs/sre/cicd-deployment/","g":"doc-sre","d":"\"If it hurts, do it more.","l":[],"x":"\"If it hurts, do it more often.\" What is CI/CD? Continuous Integration — Merge code frequently, validate automatically Continuous Delivery — Code is always deployable Continuous Deployment — Every change goes to production automatically Deployment Strategies Big Bang All at once "},{"t":"Claude Data Export for Graph Ingestion","u":"/inside/docs/sre/claude-data-export-for-graph-ingestion/","g":"doc-sre","d":"Pipeline for pulling Claude conversation history into a graph-RAG vault.","l":["claude","graph-rag","ingestion","pattern","vault"],"x":"Pipeline for pulling Claude conversation history into a graph-RAG vault. Request export via Settings > Privacy > Export Data, receive emailed JSON link, parse and filter, transform to markdown with frontmatter, then enrich with entity extraction and wikilink resolution. The expor"},{"t":"Compaction is the New OOM","u":"/inside/docs/sre/compaction-is-the-new-oom/","g":"doc-sre","d":"LLM context exhaustion is the operational hazard of AI-era systems.","l":["ai-era-ops","manifesto","position"],"x":"LLM context exhaustion is the operational hazard of AI-era systems. Just as physical memory pressure forced runtime engineering (paging, swap, OOM killer, cgroups), context compaction forces operational engineering. The L0-L4 memory architecture is the userspace MMU we are curren"},{"t":"Compare Videos Found Against the In-App Count","u":"/inside/docs/sre/compare-videos-found-against-the-in-app-count/","g":"doc-sre","d":"The owner's in-app count minus videosfound measures the gap.","l":["mitigation","transcriber-incidents"],"x":"The owner's in-app count minus videos_found measures the gap. Read it as the number of gated posts saved in that cycle. With the cron unattended, this is the only check between a silent enumeration failure and weeks of nothing. Part of Transcriber Incident Register"},{"t":"Compare Videos Found Run to Run","u":"/inside/docs/sre/compare-videos-found-run-to-run/","g":"doc-sre","d":"First fix for the short scrape: treat any drop in videosfound between runs as suspect.","l":["mitigation","transcriber-incidents"],"x":"First fix for the short scrape: treat any drop in videos_found between runs as suspect. Proven insufficient two days later, when the count rose from 32 to 37 while the app showed 47. A rising number proves nothing. Superseded by Compare Videos Found Against the In-App Count Part "},{"t":"Context Window Sizes and Effective Range","u":"/inside/docs/sre/context-window-sizes-and-effective-range/","g":"doc-sre","d":"Advertised context windows are marketing.","l":["context","llm","pattern","retrieval"],"x":"Advertised context windows are marketing. Effective context is typically 50-65% of the advertised figure per RULER benchmarks, with a 30%+ accuracy drop for content in the middle. Claude Sonnet 4.6 is the outlier for consistency. Retrieval-first architectures beat raw context stu"},{"t":"9. Cost Optimization","u":"/inside/docs/sre/cost-optimization/","g":"doc-sre","d":"\"There is no cloud. It's just someone else's computer, and they're billing you for.","l":[],"x":"\"There is no cloud. It's just someone else's computer — and they're billing you for it.\" What is Cost Optimization? Managing cloud spending to maximize value — not just cutting costs, but getting the most reliability per dollar. FinOps Principles Inform Visibility into spending A"},{"t":"CPU Cache Hierarchy and Speculative Execution","u":"/inside/docs/sre/cpu-cache-hierarchy-and-speculative-execution/","g":"doc-sre","d":"Main memory is the source of truth.","l":["cpu","hardware","microarchitecture","observability","security"],"x":"Main memory is the source of truth. Caches mirror subsets of it progressively closer to the execution units. Registers are the only storage the CPU can actually compute on. Speculative execution runs ahead of permission checks, and the cache state it leaves behind is a side chann"},{"t":"Credential Rotation","u":"/inside/docs/sre/credential-rotation/","g":"doc-sre","d":"Replace secrets used by services and humans.","l":["runbook","secrets","security"],"x":"Replace secrets used by services and humans. Distinguish between scheduled rotation (low pressure) and compromise rotation (Sev-1). The procedure is similar; the speed and blast radius are not. Trigger Event Severity Time pressure Scheduled rotation per policy Low Days Employee d"},{"t":"Database Failover","u":"/inside/docs/sre/database-failover/","g":"doc-sre","d":"Promote a replica to primary when the current primary is unhealthy.","l":["database","incident-management","runbook"],"x":"Promote a replica to primary when the current primary is unhealthy. The procedure is identical for planned maintenance and unplanned outage; the difference is preparation time. Trigger Primary database unreachable for > 30s Primary disk full or critical resource exhausted Primary"},{"t":"Defense in Depth and Trust Boundaries","u":"/inside/docs/sre/defense-in-depth-and-trust-boundaries/","g":"doc-sre","d":"No single security control holds against a determined adversary.","l":["concept","security","threat-modeling"],"x":"No single security control holds against a determined adversary. Defense in depth assumes each layer will eventually fail and arranges them so that breaching one layer does not deliver the kingdom. The discipline lives in identifying where trust changes , because that is where co"},{"t":"Differential Test in the Same Minutes","u":"/inside/docs/sre/differential-test-in-the-same-minutes/","g":"doc-sre","d":"Run the failing path and its nearest working variants side by side, within the same few minutes, changing one factor at a time.","l":["detection-method","transcriber-incidents"],"x":"Run the failing path and its nearest working variants side by side, within the same few minutes, changing one factor at a time. Same-minute timing removes rate limits and upstream changes as explanations. It separated two expired cookies from a suspected dead session in one morni"},{"t":"Dolt Versioned Database for Task State","u":"/inside/docs/sre/dolt-versioned-database-for-task-state/","g":"doc-sre","d":"MySQL-compatible database with Git-like versioning.","l":["task-tracking","tool"],"x":"MySQL-compatible database with Git-like versioning. Used in the Hivemind L1 layer (Beads, bd CLI) on localhost:3307 for task state and notes that survive context compaction. What it is Dolt is a relational database that speaks the MySQL wire protocol and adds Git semantics on top"},{"t":"Eliminate Concurrent Saves Before Blaming the Scraper","u":"/inside/docs/sre/eliminate-concurrent-saves-before-blaming-the-scraper/","g":"doc-sre","d":"Any 'scrape found N, collection holds M' gap must first rule out that the owner saved something mid-run.","l":["mitigation","transcriber-incidents"],"x":"Any 'scrape found N, collection holds M' gap must first rule out that the owner saved something mid-run. Ask, or re-enumerate at a quiet moment. The bead filed for the supposed defect was closed invalid. Part of Transcriber Incident Register"},{"t":"Enumeration Retry With Unauthenticated Fallback","u":"/inside/docs/sre/enumeration-retry-with-unauthenticated-fallback/","g":"doc-sre","d":"Enumeration tries the cookie jar twice, then unauthenticated mode three times with backoff, and logs which path succeeded.","l":["mitigation","transcriber-incidents"],"x":"Enumeration tries the cookie jar twice, then unauthenticated mode three times with backoff, and logs which path succeeded. Gated videos are lost on the fallback path, and the log says so. Since 2026-09-16 this retry also carries runs where the first attempt returns an empty body "},{"t":"Error Budgets as Reliability Currency","u":"/inside/docs/sre/error-budgets-as-reliability-currency/","g":"doc-sre","d":"An error budget is the only mechanism that makes the reliability-vs-velocity trade-off concrete.","l":["error-budget","practice","reliability","slo"],"x":"An error budget is the only mechanism that makes the reliability-vs-velocity trade-off concrete. Without it, \"ship faster\" and \"stay reliable\" are unfalsifiable opinions. With it, they are competing claims on the same finite ledger. The math is the point A 99.9% SLO over 30 days "},{"t":"Expired Bot-Manager Cookie Returns Empty Body","u":"/inside/docs/sre/expired-bot-manager-cookie-returns-empty-body/","g":"doc-sre","d":"yt-dlp sends expired entries from a Netscape cookie jar as they are.","l":["root-cause","transcriber-incidents"],"x":"yt-dlp sends expired entries from a Netscape cookie jar as they are. Akamai answers a stale bot-manager cookie ( ak_bmsc , bm_sv ) with an empty body, which yt-dlp reports as a JSON parse error at character 0. The session cookies can be valid for months while these two expire wit"},{"t":"File Copy of a WAL-Mode Database Misses Recent Writes","u":"/inside/docs/sre/file-copy-of-a-wal-mode-database-misses-recent-writes/","g":"doc-sre","d":"A SQLite database in WAL mode keeps recent writes in the -wal file.","l":["root-cause","transcriber-incidents"],"x":"A SQLite database in WAL mode keeps recent writes in the -wal file. Copying only the main .db file produces a backup that silently lacks them. Part of Transcriber Incident Register"},{"t":"Filter Expired Cookies Before Each Run","u":"/inside/docs/sre/filter-expired-cookies-before-each-run/","g":"doc-sre","d":"cookieargs() writes a filtered copy of the cookie jar with expired entries dropped, logs each drop, and passes the filtered file to yt-dlp.","l":["mitigation","transcriber-incidents"],"x":"_cookie_args() writes a filtered copy of the cookie jar with expired entries dropped, logs each drop, and passes the filtered file to yt-dlp. Every logged drop is a crash that did not happen. Applied 2026-09-13. Part of Transcriber Incident Register"},{"t":"Generate-and-Test Over Reason-From-Model","u":"/inside/docs/sre/generate-and-test-over-reason-from-model/","g":"doc-sre","d":"When a system has enough internal constraint, reasoning about which change should work reliably loses to generating many changes and testing which ones do.","l":["position","sre-manifesto"],"x":"When a system has enough internal constraint, reasoning about which change should work reliably loses to generating many changes and testing which ones do . The AI-phage result is the cleanest recent demonstration. Second reading of the same source as AI-Generated Phage Genomes a"},{"t":"Graph-RAG over Flat RAG for Operational Knowledge","u":"/inside/docs/sre/graph-rag-over-flat-rag-for-operational-knowledge/","g":"doc-sre","d":"Operational knowledge is structurally relational: an incident references a service references a deployment references a runbook references a metric references an SLO.","l":["manifesto","position","retrieval-architecture"],"x":"Operational knowledge is structurally relational: an incident references a service references a deployment references a runbook references a metric references an SLO. Flat RAG flattens this graph and loses the relationships. For agents that operate on operational knowledge, the s"},{"t":"Hand-Check Output Against the Primary Source","u":"/inside/docs/sre/hand-check-output-against-the-primary-source/","g":"doc-sre","d":"Compare a sample of generated summaries or extracted figures with the source they came from.","l":["detection-method","transcriber-incidents"],"x":"Compare a sample of generated summaries or extracted figures with the source they came from. It is the only check that catches fluent, plausible, wrong output. Part of Transcriber Incident Register"},{"t":"Handle-Based Ad Filter Matches Artist Accounts","u":"/inside/docs/sre/handle-based-ad-filter-matches-artist-accounts/","g":"doc-sre","d":"The creator rule \\.(de|official)$ was written for brand and shop accounts.","l":["root-cause","transcriber-incidents"],"x":"The creator rule \\.(de|official)$ was written for brand and shop accounts. Hardstyle and uptempo artists routinely use .official handles. Rejected videos stay at status=pending with an empty transcript and look identical to unprocessed backlog. When nothing is removed, no log lin"},{"t":"Headscale Mesh VPN for Data Sovereignty","u":"/inside/docs/sre/headscale-mesh-vpn-for-data-sovereignty/","g":"doc-sre","d":"Self-hosted open-source Tailscale control plane with embedded DERP relay.","l":["data-sovereignty","gdpr","networking","tool","vpn"],"x":"Self-hosted open-source Tailscale control plane with embedded DERP relay. Single Go binary, SQLite backing store, runs on a Raspberry Pi. Gives you a WireGuard-based mesh VPN fully under EU jurisdiction, no US SaaS metadata leakage. Why self-host the control plane Tailscale's man"},{"t":"Horizontal vs Vertical Scaling","u":"/inside/docs/sre/horizontal-vs-vertical-scaling/","g":"doc-sre","d":"The choice is not \"which is better\", it is \"where does the bottleneck actually live, and which dimension can absorb it.\" Vertical scaling is bounded by hardware.","l":["capacity-planning","concept","scalability"],"x":"The choice is not \"which is better\" — it is \"where does the bottleneck actually live, and which dimension can absorb it.\" Vertical scaling is bounded by hardware. Horizontal scaling is bounded by your willingness to engineer for it. The two axes Vertical (scale up): bigger box. M"},{"t":"Idempotence as the IaC Invariant","u":"/inside/docs/sre/idempotence-as-the-iac-invariant/","g":"doc-sre","d":"The property that makes Infrastructure as Code work is not \"code that builds infrastructure.\" It is idempotence: applying the same configuration to the same target produces the same end-state, no matter how many times you run it or what the prior state was.","l":["concept","iac","idempotence","terraform"],"x":"The property that makes Infrastructure as Code work is not \"code that builds infrastructure.\" It is idempotence : applying the same configuration to the same target produces the same end-state, no matter how many times you run it or what the prior state was. Why idempotence is th"},{"t":"Incident 2026-02-27 Dead Collection Short Links","u":"/inside/docs/sre/incident-2026-02-27-dead-collection-short-links/","g":"doc-sre","d":"Two collections stopped scraping because their stored short links died.","l":["incident","transcriber-incidents"],"x":"Two collections stopped scraping because their stored short links died. The cause was the links, and the gap had been read as neglect. Caused by Short Link Redirects to the Homepage Mitigated by Single Video URL As the Collection Argument Part of Transcriber Incident Register"},{"t":"Incident 2026-07-14 Backup Missed WAL Writes","u":"/inside/docs/sre/incident-2026-07-14-backup-missed-wal-writes/","g":"doc-sre","d":"A pre-change backup copied the main database file only, while the database was in WAL mode with a multi-megabyte WAL file.","l":["incident","transcriber-incidents"],"x":"A pre-change backup copied the main database file only, while the database was in WAL mode with a multi-megabyte WAL file. Caused by File Copy of a WAL-Mode Database Misses Recent Writes Mitigated by Back Up SQLite With the Backup Command Part of Transcriber Incident Register"},{"t":"Incident 2026-07-14 Short Scrape Looked Like a Quiet Feed","u":"/inside/docs/sre/incident-2026-07-14-short-scrape-looked-like-a-quiet-feed/","g":"doc-sre","d":"Six runs in a row reported 19 videos found; a later run reported 32, and the owner's own count was closer than the database's.","l":["incident","transcriber-incidents"],"x":"Six runs in a row reported 19 videos found; a later run reported 32, and the owner's own count was closer than the database's. A short scrape is indistinguishable from a quiet feed. The first fix was wrong and its correction is kept next to it. The earlier belief that the queue d"},{"t":"Incident 2026-07-19 Pending Status on Finished Videos","u":"/inside/docs/sre/incident-2026-07-19-pending-status-on-finished-videos/","g":"doc-sre","d":"Twelve videos sat at statuspending while holding full transcripts and summaries.","l":["incident","transcriber-incidents"],"x":"Twelve videos sat at status=pending while holding full transcripts and summaries. Same class of error as trusting an agent's completion message. Caused by Re-Scrape Relinks Processed Rows As Pending Mitigated by Verify Transcript Length Never Status Part of Transcriber Incident R"},{"t":"Incident 2026-07-21 Ad Filter Removed Artist Videos","u":"/inside/docs/sre/incident-2026-07-21-ad-filter-removed-artist-videos/","g":"doc-sre","d":"Ten videos from artists with .official handles were rejected by the ad filter before transcription and looked like unprocessed backlog.","l":["incident","transcriber-incidents"],"x":"Ten videos from artists with .official handles were rejected by the ad filter before transcription and looked like unprocessed backlog. Caused by Handle-Based Ad Filter Matches Artist Accounts Mitigated by Probe Pending Rows Before Calling Them Backlog Part of Transcriber Inciden"},{"t":"Incident 2026-07 Summaries Inverted Irony","u":"/inside/docs/sre/incident-2026-07-summaries-inverted-irony/","g":"doc-sre","d":"One sarcastic recommendation was summarised as a sincere warning, one summary named the wrong person, one was selectively pessimistic against its source.","l":["incident","transcriber-incidents"],"x":"One sarcastic recommendation was summarised as a sincere warning, one summary named the wrong person, one was selectively pessimistic against its source. Second logged irony inversion. Caused by Small Local Model Misreads Ironic Register Mitigated by Summaries Are a Triage Index "},{"t":"Incident 2026-08-08 Empty-Transcript Videos Invisible to Review","u":"/inside/docs/sre/incident-2026-08-08-empty-transcript-videos-invisible-to-review/","g":"doc-sre","d":"A reel made of on-screen text returned no transcript.","l":["incident","transcriber-incidents"],"x":"A reel made of on-screen text returned no transcript. It was reviewed only because the owner named it directly. Probed totals: 104 rows with a NULL review and an empty transcript. Caused by Review Tool Lists Only Rows With a Transcript Mitigated by Pull the Full Row List After An"},{"t":"Incident 2026-08-08 False Enumeration Bug Finding","u":"/inside/docs/sre/incident-2026-08-08-false-enumeration-bug-finding/","g":"doc-sre","d":"A scrape found 46 videos and a re-enumeration minutes later found 48.","l":["false-finding","transcriber-incidents"],"x":"A scrape found 46 videos and a re-enumeration minutes later found 48. One of the extra videos had a publish date ten weeks old, and the session concluded that enumeration was non-deterministic. The owner had been saving videos to the collection while the scrape ran. The rule that"},{"t":"Incident 2026-09-11 Three-Morning Cron Crash","u":"/inside/docs/sre/incident-2026-09-11-three-morning-cron-crash/","g":"doc-sre","d":"The 06:15 cron died three mornings running with CalledProcessError.","l":["incident","transcriber-incidents"],"x":"The 06:15 cron died three mornings running with CalledProcessError . The log showed a traceback and no cause. The login session was the obvious suspect and was fine. Jar enumeration failed 9 of 9, no-cookie enumeration succeeded 3 of 3, and the jar with two entries removed succee"},{"t":"Incident 2026-09-13 Ghost Still-Running Job","u":"/inside/docs/sre/incident-2026-09-13-ghost-still-running-job/","g":"doc-sre","d":"A process check over SSH reported the batch job as still running after it had exited.","l":["incident","transcriber-incidents"],"x":"A process check over SSH reported the batch job as still running after it had exited. Caused by Process Check Matches Its Own Shell Mitigated by Bracket Pattern Process Check Part of Transcriber Incident Register"},{"t":"Incident 2026-09-16 Server Cannot List the Collection","u":"/inside/docs/sre/incident-2026-09-16-server-cannot-list-the-collection/","g":"doc-sre","d":"From 2026-09-16 the server could not enumerate the collection from any client or egress, while the laptop could with the same yt-dlp version through the same egress.","l":["incident","transcriber-incidents"],"x":"From 2026-09-16 the server could not enumerate the collection from any client or egress, while the laptop could with the same yt-dlp version through the same egress. IP, yt-dlp version and impersonation were ruled out. By 2026-09-21 listing worked again with no change made: the f"},{"t":"4. Incident Management","u":"/inside/docs/sre/incident-management/","g":"doc-sre","d":"\"It's not about preventing all failures.","l":[],"x":"\"It's not about preventing all failures. It's about recovering fast.\" What is Incident Management? The structured approach to identifying, responding to, resolving, and learning from service disruptions. Incident Lifecycle Detection → Triage → Response → Resolution → Review → Pre"},{"t":"Incidents","u":"/inside/docs/sre/incidents/","g":"doc-sre","d":"Incident, cause and mitigation records from the vault, written up from trap files and session logs. Each record names its source.","l":["folder"],"x":"Incident, cause and mitigation records from the vault, written up from trap files and session logs. Each record names its source."},{"t":"5. Infrastructure as Code","u":"/inside/docs/sre/infrastructure-as-code/","g":"doc-sre","d":"\"If it's not in Git, it doesn't.","l":[],"x":"\"If it's not in Git, it doesn't exist.\" What is Infrastructure as Code? Managing and provisioning infrastructure through machine-readable definition files rather than manual processes. Core Principles Declarative > Imperative Declarative — Describe desired state, tool figures out"},{"t":"legacy-restoration-as-sre-craft","u":"/inside/docs/sre/legacy-restoration-as-sre-craft/","g":"doc-sre","d":"A man walks you through the one and only airworthy Lockheed C-121 Constellation, 10,000 horsepower, \"not a straight line on her,\" MacArthur's bar in the aft lounge, a veteran of the Berlin Airlift and NASA.","l":["craft","metaphor","sre-manifesto"],"x":"Legacy restoration as SRE craft A man walks you through the one and only airworthy Lockheed C-121 Constellation, 10,000 horsepower, \"not a straight line on her,\" MacArthur's bar in the aft lounge, a veteran of the Berlin Airlift and NASA. Two survive worldwide. Keeping a complex "},{"t":"LLM as Software-Defined CPU","u":"/inside/docs/sre/llm-as-software-defined-cpu/","g":"doc-sre","d":"An LLM is a CPU that shipped without a memory management unit.","l":["ai-agents","architecture","computer-history","pattern"],"x":"An LLM is a CPU that shipped without a memory management unit. The agent stack is the operating system we build around it in userspace: context is RAM, attention heads are registers, tokens are instructions, compaction is cold boot, beads is swap. The mapping Silicon concept Agen"},{"t":"Manifesto","u":"/inside/docs/sre/manifesto/","g":"doc-sre","d":"A practical definition of Site Reliability Engineering, outside any strict definitions made by Google or any other company.","l":["moc","sre-manifesto"],"x":"A practical definition of Site Reliability Engineering, outside any strict definitions made by Google or any other company. This is opinionated. It's grounded in 30+ years of operational experience across infrastructure, platform engineering, and people leadership. SRE Is a Role,"},{"t":"Memory Architecture L0-L4","u":"/inside/docs/sre/memory-architecture-l0-l4/","g":"doc-sre","d":"A five-layer memory stack for AI coding agents: L0 context, L1 beads, L2 memories, L3 vault, L4 Hivemind.","l":["ai-agents","architecture","memory","pattern"],"x":"A five-layer memory stack for AI coding agents: L0 context, L1 beads, L2 memories, L3 vault, L4 Hivemind. Durability increases with layer number, speed decreases. Each layer has a flush mechanism. Compaction is a fundamental constraint, not a bug. The layers L0, Conversation Cont"},{"t":"No-Transcript Bucket in the Review Tool","u":"/inside/docs/sre/no-transcript-bucket-in-the-review-tool/","g":"doc-sre","d":"Planned: have the review tool surface rows with a NULL review and an empty transcript as their own 'needs a manual look' bucket, so they stop disappearing whether or not OCR ever lands.","l":["mitigation","transcriber-incidents"],"x":"Planned: have the review tool surface rows with a NULL review and an empty transcript as their own 'needs a manual look' bucket, so they stop disappearing whether or not OCR ever lands. Part of Transcriber Incident Register"},{"t":"3. Observability","u":"/inside/docs/sre/observability/","g":"doc-sre","d":"\"You can't fix what you can't.","l":[],"x":"\"You can't fix what you can't see.\" What is Observability? The ability to understand a system's internal state by examining its external outputs — without deploying new code. Three Pillars 1. Metrics Numeric measurements over time: Counters — Cumulative values (requests_total) Ga"},{"t":"OpenCode Self-Hosted LLM Configuration","u":"/inside/docs/sre/opencode-self-hosted-llm-configuration/","g":"doc-sre","d":"OpenCode connects to any self-hosted LLM that exposes an OpenAI-compatible API via the @ai-sdk/openai-compatible provider.","l":["ai-agents","configuration","llm","opencode","tool"],"x":"OpenCode connects to any self-hosted LLM that exposes an OpenAI-compatible API via the @ai-sdk/openai-compatible provider. Configure in ~/.config/opencode/opencode.json globally or ./opencode.json per project. Verify with curl /v1/models before wiring up the agent. The two config"},{"t":"Patterns","u":"/inside/docs/sre/patterns/","g":"doc-sre","d":"Reusable architecture patterns for reliable, scalable systems.","l":["moc","sre-patterns"],"x":"Reusable architecture patterns for reliable, scalable systems. Planned Patterns Reliability ☐ Circuit breaker ☐ Retry with exponential backoff ☐ Bulkhead isolation ☐ Graceful degradation ☐ Health checks Scalability ☐ Horizontal pod autoscaling ☐ Database sharding ☐ CQRS ☐ Event s"},{"t":"7. Performance","u":"/inside/docs/sre/performance/","g":"doc-sre","d":"\"Premature optimization is the root of all evil.","l":[],"x":"\"Premature optimization is the root of all evil. But mature optimization is the root of all good.\" What is Performance? How efficiently a system uses resources to serve requests — measured in latency, throughput, and resource utilization. Key Metrics Latency p50 — Median (half of"},{"t":"Personal Digital Twin Architecture","u":"/inside/docs/sre/personal-digital-twin-architecture/","g":"doc-sre","d":"Per-person vault (private, IP-owned by the individual) plus a curated public projection (expertise, decisions, communication patterns).","l":["ai-agents","digital-twin","knowledge-management","pattern"],"x":"Per-person vault (private, IP-owned by the individual) plus a curated public projection (expertise, decisions, communication patterns). The company layer is the aggregate of public projections. Knowledge survives when people leave; IP ownership stays with the person who created i"},{"t":"The ten pillars","u":"/inside/docs/sre/pillars/","g":"doc-sre","d":"The ten pillars of the SRE framework, one page each: reliability, scalability, observability, incident management, infrastructure as code, CI/CD and deployment, performance, security, cost optimisation and toil reduction.","l":["folder"],"x":"The ten pillars of the SRE framework, one page each: reliability, scalability, observability, incident management, infrastructure as code, CI/CD and deployment, performance, security, cost optimisation and toil reduction."},{"t":"Probe Pending Rows Before Calling Them Backlog","u":"/inside/docs/sre/probe-pending-rows-before-calling-them-backlog/","g":"doc-sre","d":"A pending count is unclassified until the rows are looked at.","l":["mitigation","transcriber-incidents"],"x":"A pending count is unclassified until the rows are looked at. Of 52 pending on 2026-07-21, 12 were ad-filter rejects and 39 were off-topic. The absence of the Ad filter: removed log line is the all-clear. Tightening the regex is tracked as bead vault-lv0. Part of Transcriber Inci"},{"t":"Probe the Artifact Before Reasoning From Counts","u":"/inside/docs/sre/probe-the-artifact-before-reasoning-from-counts/","g":"doc-sre","d":"When a count looks wrong, fetch one real item and read the error.","l":["detection-method","transcriber-incidents"],"x":"When a count looks wrong, fetch one real item and read the error. One probe of a real URL settled a question that several sessions of reasoning from videos_found numbers had answered wrongly. Part of Transcriber Incident Register"},{"t":"Probing Microarchitecture for Vulnerability Discovery","u":"/inside/docs/sre/probing-microarchitecture-for-vulnerability-discovery/","g":"doc-sre","d":"CVE discovery on CPUs follows a repeatable methodology: probe the gap between what the architecture claims and what the implementation actually does.","l":["pattern","research-methodology"],"x":"CVE discovery on CPUs follows a repeatable methodology: probe the gap between what the architecture claims and what the implementation actually does. The same probing discipline applies to RAG systems, distributed systems, and any layered abstraction. The methodology Researchers "},{"t":"Process Check Matches Its Own Shell","u":"/inside/docs/sre/process-check-matches-its-own-shell/","g":"doc-sre","d":"pgrep -f <pattern> run over SSH matches the remote shell whose command line contains the pattern.","l":["root-cause","transcriber-incidents"],"x":"pgrep -f <pattern> run over SSH matches the remote shell whose command line contains the pattern. The check reports the job as running when it has finished. Part of Transcriber Incident Register"},{"t":"Progressive Delivery Patterns","u":"/inside/docs/sre/progressive-delivery-patterns/","g":"doc-sre","d":"Big-bang deploys treat every release as a coin flip on the entire user base.","l":["cicd","deployment","pattern","progressive-delivery"],"x":"Big-bang deploys treat every release as a coin flip on the entire user base. Progressive delivery splits the coin flip into many smaller ones with cheap rollback. The right pattern depends on what fails when it fails: a request, a user session, or a database row. The four primary"},{"t":"Publish Date Treated As Time In Collection","u":"/inside/docs/sre/publish-date-treated-as-time-in-collection/","g":"doc-sre","d":"A video's publish date says nothing about when it was saved to a collection.","l":["root-cause","transcriber-incidents"],"x":"A video's publish date says nothing about when it was saved to a collection. Saving an old video is ordinary. The collection is also a live object: its owner can add to it while the tooling reads it. Part of Transcriber Incident Register"},{"t":"Pull the Full Row List After Any Scrape","u":"/inside/docs/sre/pull-the-full-row-list-after-any-scrape/","g":"doc-sre","d":"Do not take the review tool's count as the batch size.","l":["mitigation","transcriber-incidents"],"x":"Do not take the review tool's count as the batch size. After a scrape, list every row and check length(transcript) per row. Part of Transcriber Incident Register"},{"t":"Re-Scrape Relinks Processed Rows As Pending","u":"/inside/docs/sre/re-scrape-relinks-processed-rows-as-pending/","g":"doc-sre","d":"Re-scraping a collection re-links videos that were already processed and sets them back to statuspending without flipping them to complete again.","l":["root-cause","transcriber-incidents"],"x":"Re-scraping a collection re-links videos that were already processed and sets them back to status=pending without flipping them to complete again. The row keeps its transcript and summary while its status says otherwise. Part of Transcriber Incident Register"},{"t":"1. Reliability","u":"/inside/docs/sre/reliability/","g":"doc-sre","d":"\"Reliability is the most important.","l":[],"x":"\"Reliability is the most important feature.\" What is Reliability? The ability of a system to perform its intended function under stated conditions for a specified period of time. Key Concepts Service Level Indicators (SLIs) Quantitative measures of service behavior: Availability "},{"t":"Review Tool Lists Only Rows With a Transcript","u":"/inside/docs/sre/review-tool-lists-only-rows-with-a-transcript/","g":"doc-sre","d":"reviewstatus.py reports on rows where length(transcript) > 0.","l":["root-cause","transcriber-incidents"],"x":"review_status.py reports on rows where length(transcript) > 0 . A video made of on-screen text has no speech, Whisper returns nothing, and status still flips to complete. The row is neither backlog nor reviewable, so it is invisible from both directions. Part of Transcriber Incid"},{"t":"Rollback Deployment","u":"/inside/docs/sre/rollback-deployment/","g":"doc-sre","d":"Revert production to the last known good state.","l":["deployment","incident-management","runbook"],"x":"Revert production to the last known good state. Optimize for speed; investigate after stability is restored. The rollback procedure must be faster than the deploy procedure or it is not a rollback, it is a redeploy. Trigger Error rate spike correlated with deploy timestamp Latenc"},{"t":"Runbooks","u":"/inside/docs/sre/runbooks/","g":"doc-sre","d":"Operational procedures for common scenarios.","l":["moc","sre-runbooks"],"x":"Operational procedures for common scenarios. Structure Each runbook includes: Trigger — When to use this runbook Prerequisites — Access, tools needed Steps — Detailed procedure Verification — How to confirm success Rollback — How to undo if needed Escalation — When and who to con"},{"t":"2. Scalability","u":"/inside/docs/sre/scalability/","g":"doc-sre","d":"\"Scale is not a feature you can bolt on.","l":[],"x":"\"Scale is not a feature you can bolt on later.\" What is Scalability? The ability of a system to handle increased load by adding resources — without architectural changes. Scaling Dimensions Vertical Scaling (Scale Up) Bigger machines (more CPU, RAM, disk) Simple but has hard limi"},{"t":"8. Security","u":"/inside/docs/sre/security/","g":"doc-sre","d":"\"Security is a process, not a.","l":[],"x":"\"Security is a process, not a product.\" What is Security in SRE? Protecting systems, data, and users from unauthorized access, breaches, and attacks — while maintaining reliability and velocity. Core Principles Defense in Depth Multiple layers of security controls: Network → Infr"},{"t":"Sensitivity-Gated Posts Vanish From Unauthenticated Listing","u":"/inside/docs/sre/sensitivity-gated-posts-vanish-from-unauthenticated-listing/","g":"doc-sre","d":"TikTok refuses to serve age-restricted or sensitivity-flagged posts to an unauthenticated client.","l":["root-cause","transcriber-incidents"],"x":"TikTok refuses to serve age-restricted or sensitivity-flagged posts to an unauthenticated client. In --flat-playlist enumeration they drop out of the list with no error at the collection level. Gating can be applied after a video was first fetched. The loss is biased by topic, si"},{"t":"Service Outage Response","u":"/inside/docs/sre/service-outage-response/","g":"doc-sre","d":"Generic triage runbook for production service unavailability.","l":["incident-management","runbook","sev1"],"x":"Generic triage runbook for production service unavailability. Optimize for time-to-mitigation, not time-to-root-cause. Diagnosis happens after the bleeding stops. Trigger Synthetic monitor failing for > 2 consecutive checks Error rate > 5x baseline sustained for 60s p95 latency >"},{"t":"Short Link Redirects to the Homepage","u":"/inside/docs/sre/short-link-redirects-to-the-homepage/","g":"doc-sre","d":"Stored vm.tiktok.com short links for two collections now redirect to the site homepage.","l":["root-cause","transcriber-incidents"],"x":"Stored vm.tiktok.com short links for two collections now redirect to the site homepage. yt-dlp exits with Unsupported URL and the batch script dies at enumeration. Fresh canonical URLs can only be copied out of the app by the account owner. Part of Transcriber Incident Register"},{"t":"Single Video URL As the Collection Argument","u":"/inside/docs/sre/single-video-url-as-the-collection-argument/","g":"doc-sre","d":"A single video URL works as the --collection-url argument, so individual videos can be reprocessed without a working collection link.","l":["mitigation","transcriber-incidents"],"x":"A single video URL works as the --collection-url argument, so individual videos can be reprocessed without a working collection link. The cost is one junk row in collections per video. Part of Transcriber Incident Register"},{"t":"Small Local Model Misreads Ironic Register","u":"/inside/docs/sre/small-local-model-misreads-ironic-register/","g":"doc-sre","d":"A 7B local summarizer renders sarcasm as sincere statement, swaps subjects, or turns selectively pessimistic against its own source.","l":["root-cause","transcriber-incidents"],"x":"A 7B local summarizer renders sarcasm as sincere statement, swaps subjects, or turns selectively pessimistic against its own source. The output is fluent and plausible, so nothing marks it as wrong. Part of Transcriber Incident Register"},{"t":"SRE as Truth Verified Working","u":"/inside/docs/sre/sre-as-truth-verified-working/","g":"doc-sre","d":"The acronym is incidental.","l":["position","sre-manifesto"],"x":"SRE as Truth, Verified, Working The acronym is incidental. The discipline is about three properties: claims are true , claims are verified , the system is working . The ten pillars are downstream mechanisms; this is the substrate. The principle SRE discipline is a position on thr"},{"t":"Summaries Are a Triage Index","u":"/inside/docs/sre/summaries-are-a-triage-index/","g":"doc-sre","d":"Use summaries to decide what to read, never as evidence.","l":["mitigation","transcriber-incidents"],"x":"Use summaries to decide what to read, never as evidence. Videos in an ironic register get a manual transcript read. A triage pass built on summaries alone was wrong on 3 of 13. Part of Transcriber Incident Register"},{"t":"Swallowed Stderr Hides the Cause","u":"/inside/docs/sre/swallowed-stderr-hides-the-cause/","g":"doc-sre","d":"subprocess.run(..., checkTrue, captureoutputTrue) captures the child's stderr and raises CalledProcessError.","l":["root-cause","transcriber-incidents"],"x":"subprocess.run(..., check=True, capture_output=True) captures the child's stderr and raises CalledProcessError . The log then holds a Python traceback and none of the child's own error text, so the failure is visible and its reason is not. Part of Transcriber Incident Register"},{"t":"Symptoms over Causes for Alerting","u":"/inside/docs/sre/symptoms-over-causes-for-alerting/","g":"doc-sre","d":"Page when users are affected.","l":["alerting","observability","practice"],"x":"Page when users are affected. Investigate when components are unhappy. The discipline that distinguishes a useful alerting system from a noisy one is the rule that only customer-visible symptoms wake humans up . Everything else is a ticket. Why cause-based alerts fail A \"CPU > 80"},{"t":"tencent-agent-memory-four-tier","u":"/inside/docs/sre/tencent-agent-memory-four-tier/","g":"doc-sre","d":"An open-source, fully-local memory layer that gives an agent human-like long-term recall, so it stops starting from scratch every session.","l":["agent-memory","rag","reference","sre-patterns"],"x":"Tencent's four-tier agent memory system An open-source, fully-local memory layer that gives an agent human-like long-term recall, so it stops starting from scratch every session. Directly relevant as a reference point for the L0-L4 memory architecture: it is the same problem (dur"},{"t":"The Disappearing Full-Stack Ops Engineer","u":"/inside/docs/sre/the-disappearing-full-stack-ops-engineer/","g":"doc-sre","d":"The concentric Ops model produces engineers at every ring (SysAdmin, Cloud, Platform, SRE).","l":["manifesto","position","team-design"],"x":"The concentric Ops model produces engineers at every ring (SysAdmin, Cloud, Platform, SRE). The engineer who actually holds all four rings simultaneously is the highest-leverage person on most teams and also one of the rarest. Designing teams as if you have one available is a pla"},{"t":"10. Toil Reduction","u":"/inside/docs/sre/toil-reduction/","g":"doc-sre","d":"\"If a human is doing something a computer could do, that's a.","l":[],"x":"\"If a human is doing something a computer could do, that's a bug.\" What is Toil? Work that is: Manual — Requires human intervention Repetitive — Done over and over Automatable — Could be done by a machine Tactical — Reactive, not strategic No enduring value — Doesn't improve the "},{"t":"Toil vs Engineering and the 50 Percent Rule","u":"/inside/docs/sre/toil-vs-engineering-and-the-50-percent-rule/","g":"doc-sre","d":"SRE without a toil cap drifts into operations.","l":["automation","practice","toil"],"x":"Toil vs Engineering — The 50 Percent Rule SRE without a toil cap drifts into operations. Operations without an automation mandate stays operations. The 50% rule — no SRE spends more than half their time on toil — is what makes SRE a different role from senior ops. The rule is a f"},{"t":"Tools","u":"/inside/docs/sre/tools/","g":"doc-sre","d":"Tool-specific guides and configurations.","l":["moc","sre-tools"],"x":"Tool-specific guides and configurations. Categories Orchestration ☐ Kubernetes ☐ ECS ☐ Nomad Infrastructure as Code ☐ Terraform ☐ Pulumi ☐ CloudFormation Observability ☐ Prometheus ☐ Grafana ☐ Loki ☐ Jaeger CI/CD ☐ GitHub Actions ☐ ArgoCD ☐ Flux Security ☐ Vault ☐ Trivy ☐ OPA Str"},{"t":"Transcriber Incident Register","u":"/inside/docs/sre/transcriber-incident-register/","g":"doc-sre","d":"Every failure of the video transcriber pipeline since February 2026, as typed atoms.","l":["moc","transcriber-incidents"],"x":"Every failure of the video transcriber pipeline since February 2026, as typed atoms. An incident links to its root cause, to what was done about it, and to the test that found the cause. A fix that replaced a wrong fix links to it as superseded. The trap file in the skill folder "},{"t":"Unit Economics of Infrastructure","u":"/inside/docs/sre/unit-economics-of-infrastructure/","g":"doc-sre","d":"Total cloud spend is the wrong metric.","l":["cost-optimization","finops","practice"],"x":"Total cloud spend is the wrong metric. Cost per business unit — per request, per active user, per transaction, per GB delivered — is the only metric that survives growth. A bill that doubles is fine if traffic tripled. A bill that grows 5% while traffic is flat is the real proble"},{"t":"USE Method for Resource Saturation","u":"/inside/docs/sre/use-method-for-resource-saturation/","g":"doc-sre","d":"When a system is slow and you don't know why, ask three questions of every resource it depends on: how busy is it, what is queued waiting for it, and is it returning errors.","l":["diagnostics","method","performance"],"x":"When a system is slow and you don't know why, ask three questions of every resource it depends on: how busy is it, what is queued waiting for it, and is it returning errors. Brendan Gregg's USE method is the diagnostic primitive for performance problems. The three signals per res"},{"t":"vault-search-fastembed-migration","u":"/inside/docs/sre/vault-search-fastembed-migration/","g":"doc-sre","d":"How to move a vault-search install off Ollama-based embeddings onto in-process fastembed, and how to replicate the change on another machine.","l":["runbook","vault-search"],"x":"vault-search — fastembed Migration Runbook How to move a vault-search install off Ollama-based embeddings onto in-process fastembed , and how to replicate the change on another machine. Migration done on the primary Mac 2026-05-16; this runbook is for the second Mac and any futur"},{"t":"Verify Transcript Length Never Status","u":"/inside/docs/sre/verify-transcript-length-never-status/","g":"doc-sre","d":"Treat status as a report. Check length(transcript) and length(summary) per row.","l":["mitigation","transcriber-incidents"],"x":"Treat status as a report. Check length(transcript) and length(summary) per row. The twelve affected rows were flipped to complete after a dry run and a snapshot. Part of Transcriber Incident Register"},{"t":"Standards and Compliance","u":"/inside/docs/std/","g":"doc-std","d":"Reference clusters from the knowledge vault for 28 standards, regulations and frameworks, from ISO 27001 and NIS2 to the EU AI Act and TOGAF.","l":["moc","compliance"],"x":"Reference clusters from the knowledge vault, one per standard, regulation or framework. Each cluster page is the map of its notes: provenance, structure, controls or articles, comparisons and controversies, plus a dated position and a list of anchors to primary sources. The notes"},{"t":"BSI IT-Grundschutz anchors","u":"/inside/docs/std/bsi-grundschutz-anchors/","g":"doc-std","d":"BSI IT-Grundschutz anchors, from the knowledge vault.","l":["anchors","bsi-grundschutz"],"x":"Primary documents BSI Standard 200-1 : ISMS BSI Standard 200-2 : IT-Grundschutz Methodologie BSI Standard 200-3 : Risikoanalyse auf der Basis von IT-Grundschutz BSI Standard 200-4 : Business Continuity Management IT-Grundschutz Kompendium (annual edition; current 2024/2025) IT-Gr"},{"t":"BSI IT-Grundschutz position","u":"/inside/docs/std/bsi-grundschutz-position/","g":"doc-std","d":"BSI IT-Grundschutz position, from the knowledge vault.","l":["bsi-grundschutz","position"],"x":"What it does well DE national standard. Mandatory or expected in DE public sector, KRITIS, many Mittelstand. Methodology is prescriptive. Practitioner gets clear guidance via Bausteine. Threat catalog rich. Specific threats and counter-measures mapped. ISO 27001 harmonized. ISO 2"},{"t":"BSI IT-Grundschutz","u":"/inside/docs/std/bsi-grundschutz/","g":"doc-std","d":"Map of BSI IT-Grundschutz, German national InfoSec framework from BSI (Bundesamt für Sicherheit in der Informationstechnik).","l":["bsi-grundschutz","de-national-framework","moc","security-compliance"],"x":"Map of BSI IT-Grundschutz — German national InfoSec framework from BSI (Bundesamt für Sicherheit in der Informationstechnik). National alternative to ISO 27001. Common in DE public sector, KRITIS critical infrastructure, Mittelstand. Now harmonized with ISO 27001 — Grundschutz-ba"},{"t":"CMMI anchors","u":"/inside/docs/std/cmmi-anchors/","g":"doc-std","d":"CMMI anchors, from the knowledge vault.","l":["anchors","cmmi"],"x":"Primary documents CMMI v3.0 (2023) — current model. CMMI v2.0 (2018) — predecessor; still in use. CMMI for Development , CMMI for Services , CMMI for Supplier Management — domain views. Operating body ISACA / CMMI Institute — owner since 2017 acquisition from CMU SEI. CMU SEI (So"},{"t":"CMMI Controversies","u":"/inside/docs/std/cmmi-controversies/","g":"doc-std","d":"CMM heritage produces bureaucratic-implementation.","l":["cmmi","cross-cutting"],"x":"Bureaucratic reputation CMM heritage produces bureaucratic-implementation perception: \"CMMI Level 3\" often documentation-heavy. Process discipline can become process ceremony. DevOps / agile practitioners often skeptical. Implementation cost Levels 3+ require substantial investme"},{"t":"CMMI Maturity and Capability Levels","u":"/inside/docs/std/cmmi-maturity-and-capability-levels/","g":"doc-std","d":"Organization-wide. One rating across the org.","l":["cmmi","framework-concept"],"x":"Two views Maturity Levels (staged) Organization-wide. One rating across the org. Capability Levels (continuous) Per process area. Different ratings per area. Five maturity levels (staged) Level 1 — Initial Ad hoc, chaotic, depends on individual heroes. Some processes work; succes"},{"t":"CMMI position","u":"/inside/docs/std/cmmi-position/","g":"doc-std","d":"CMMI position, from the knowledge vault.","l":["cmmi","position"],"x":"What it does well Process maturity discipline — five levels durable framework. Cybersecurity / sustainability dimensions in 3.0. US DoD procurement signal . Aerospace/defense recognition . What it does poorly Heavy implementation — full maturity Level 3+ substantial effort. Burea"},{"t":"CMMI","u":"/inside/docs/std/cmmi/","g":"doc-std","d":"Capability Maturity Model Integration.","l":["cmmi","moc","process-maturity"],"x":"Capability Maturity Model Integration. ISACA-owned (since 2017 acquisition from CMU SEI). Process maturity model with five maturity levels. CMMI 3.0 (2023) current. Origins in US DoD software acquisition; broad industry adoption. Anchors position · anchors Provenance CMM (1991) —"},{"t":"COBIT anchors","u":"/inside/docs/std/cobit-anchors/","g":"doc-std","d":"COBIT anchors, from the knowledge vault.","l":["anchors","cobit"],"x":"Primary documents COBIT 2019 Framework: Introduction and Methodology COBIT 2019 Framework: Governance and Management Objectives COBIT 2019 Design Guide COBIT 2019 Implementation Guide COBIT Focus Area guides (information security, DevOps, SMB, risk, etc.). Operating body ISACA — "},{"t":"COBIT Controversies","u":"/inside/docs/std/cobit-controversies/","g":"doc-std","d":"40 objectives × multiple practices × multiple activities × capability.","l":["cobit","cross-cutting"],"x":"Heavy framework 40 objectives × multiple practices × multiple activities × capability levels: Substantial documentation burden. Implementation complexity. Overhead disproportionate for smaller orgs. ITIL overlap ITIL and COBIT both touch IT service management: Combined implementa"},{"t":"COBIT Governance and Management Objectives","u":"/inside/docs/std/cobit-governance-and-management-objectives/","g":"doc-std","d":"Board-level. Evaluate stakeholder needs / conditions / options, Direct via policies, Monitor performance.","l":["cobit","framework-concept"],"x":"Governance domain — EDM (5 objectives) Board-level. Evaluate stakeholder needs / conditions / options, Direct via policies, Monitor performance. EDM01 Ensured Governance Framework Setting and Maintenance EDM02 Ensured Benefits Delivery EDM03 Ensured Risk Optimisation EDM04 Ensure"},{"t":"COBIT position","u":"/inside/docs/std/cobit-position/","g":"doc-std","d":"COBIT position, from the knowledge vault.","l":["cobit","position"],"x":"What it does well Governance vs management distinction useful. Board-level framing of IT. Cross-framework references to ISO, NIST, ITIL. Design factors for tailoring. Focus area guides for specific contexts. What it does poorly Heavy framework — 40 objectives, many practices, lar"},{"t":"COBIT","u":"/inside/docs/std/cobit/","g":"doc-std","d":"Map of ISACA COBIT 2019, IT governance framework.","l":["cobit","it-governance","moc"],"x":"COBIT 2019 Cluster Map of ISACA COBIT 2019 — IT governance framework. Governance vs management distinction. 40 governance and management objectives. Companion to ITIL (governance vs operations). Anchors position · anchors Provenance COBIT 1 (1996) — ISACA's IT audit framework. CO"},{"t":"CRA Controversies","u":"/inside/docs/std/cra-controversies/","g":"doc-std","d":"Despite carve-out, open source ecosystem.","l":["cross-cutting","cyber-resilience-act"],"x":"Open source uncertainty Despite carve-out, open source ecosystem concerned: Boundary between \"non-commercial\" and \"commercial\" supply unclear. Open source steward obligations expanding. Contributor liability concerns. Maintainer burnout risk if compliance burden shifts. SaaS excl"},{"t":"CRA Essential Requirements","u":"/inside/docs/std/cra-essential-requirements/","g":"doc-std","d":"Annex I of the CRA establishes essential cybersecurity requirements (Part I) and vulnerability handling requirements (Part II) applicable to products with digital elements.","l":["cyber-resilience-act","regulation-concept"],"x":"Annex I of the CRA establishes essential cybersecurity requirements (Part I) and vulnerability handling requirements (Part II) applicable to products with digital elements. Part I: Cybersecurity requirements Properties (security by design / default) No known exploitable vulnerabi"},{"t":"CSA CCM anchors","u":"/inside/docs/std/csa-ccm-anchors/","g":"doc-std","d":"Major providers: AWS, Microsoft Azure, Google Cloud, Salesforce, ServiceNow, Workday, Box, Dropbox, many others.","l":["anchors","csa-ccm"],"x":"Primary documents CSA Cloud Controls Matrix v4 — current. Consensus Assessments Initiative Questionnaire (CAIQ) v4 — companion questionnaire. CSA STAR Program documentation . Operating body Cloud Security Alliance — csa.org. Founded 2008. Adjacent CSA work CSA Top Threats reports"},{"t":"CSA CCM Control Domains","u":"/inside/docs/std/csa-ccm-control-domains/","g":"doc-std","d":"Audit planning, independence, management, results communication.","l":["csa-ccm","framework-concept"],"x":"17 control domains (CCM v4) A&A — Audit & Assurance Audit planning, independence, management, results communication. AIS — Application & Interface Security Application security policies, baseline requirements, secure deployment, secure design. BCR — Business Continuity Management"},{"t":"CSA CCM Controversies","u":"/inside/docs/std/csa-ccm-controversies/","g":"doc-std","d":"Not all cloud providers submit.","l":["cross-cutting","csa-ccm"],"x":"Voluntary STAR participation Not all cloud providers submit STAR: Smaller / specialized providers often absent. Procurement gap when comparing. Level 1 self-assessment limited assurance. CAIQ self-assessment quality variance Level 1 self-assessments: Provider self-attestation. Qu"},{"t":"CSA CCM position","u":"/inside/docs/std/csa-ccm-position/","g":"doc-std","d":"CSA CCM position, from the knowledge vault.","l":["csa-ccm","position"],"x":"What it does well Cloud-specific control content where general frameworks generic. Cross-framework mapping reduces vendor due-diligence overhead. STAR Registry provides public-facing cloud-provider transparency. CAIQ questionnaire standardized vendor evaluation. What it does poor"},{"t":"CSA CCM","u":"/inside/docs/std/csa-ccm/","g":"doc-std","d":"Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM).","l":["cloud-security","csa-ccm","moc"],"x":"CSA Cloud Controls Matrix Cluster Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). Cloud-specific control framework. Maps to multiple frameworks (ISO 27001, NIST CSF, PCI DSS, HIPAA, others). STAR Registry for cloud-provider attestation. Anchors position · anchors Prove"},{"t":"Cyber Resilience Act anchors","u":"/inside/docs/std/cyber-resilience-act-anchors/","g":"doc-std","d":"Cyber Resilience Act anchors, from the knowledge vault.","l":["anchors","cyber-resilience-act"],"x":"CRA Anchors Primary text Regulation (EU) 2024/2847 — Cyber Resilience Act. Published OJEU 20 November 2024. Adjacent regulation NIS2 (Dir 2022/2555) — operator cybersecurity. EU AI Act (Reg 2024/1689) — high-risk AI products. MDR (Reg 2017/745) — medical devices (CRA excludes). U"},{"t":"Cyber Resilience Act Controversies","u":"/inside/docs/std/cyber-resilience-act-controversies/","g":"doc-std","d":"Stub atom for documented controversies around EU Cyber Resilience Act (Reg 2024/2847).","l":["cyber-resilience-act","stub"],"x":"Stub atom for documented controversies around EU Cyber Resilience Act (Reg 2024/2847). Referenced from pillars/slsa-sbom/SLSA SBOM Controversies.md:74 . to do Likely scope: open-source vendor liability concerns (initial draft scope vs final compromise); definition-of-commercial a"},{"t":"Cyber Resilience Act position","u":"/inside/docs/std/cyber-resilience-act-position/","g":"doc-std","d":"Cyber Resilience Act position, from the knowledge vault.","l":["cyber-resilience-act","position"],"x":"What it does well Product-level cybersecurity previously gap. Vulnerability disclosure mandate addresses real industry weakness. Support period requires manufacturers commit to security maintenance. CE marking integration uses existing market-surveillance infrastructure. Open-sou"},{"t":"Cyber Resilience Act","u":"/inside/docs/std/cyber-resilience-act/","g":"doc-std","d":"Map of Regulation (EU) 2024/2847, the Cyber Resilience Act.","l":["cyber-resilience-act","eu-regulation","moc","product-cybersecurity"],"x":"EU Cyber Resilience Act Cluster Map of Regulation (EU) 2024/2847 — the Cyber Resilience Act. EU's product cybersecurity regulation. Adopted October 2024; applicable late 2027 for most obligations. Establishes cybersecurity requirements for products with digital elements (PDE) pla"},{"t":"DORA anchors","u":"/inside/docs/std/dora-anchors/","g":"doc-std","d":"ESAs published numerous Regulatory Technical Standards and Implementing Technical Standards specifying technical and operational requirements.","l":["anchors","dora"],"x":"Primary text Regulation (EU) 2022/2554 — DORA. Published OJEU 27 December 2022. Applicable 17 January 2025. Directive (EU) 2022/2556 — companion directive amending sector-specific regulations to enable DORA application. Recitals — 106 recitals. Articles — 64 articles. RTS / ITS p"},{"t":"DORA Controversies","u":"/inside/docs/std/dora-controversies/","g":"doc-std","d":"Contested points and known concerns about DORA after first year of applicability.","l":["cross-cutting","dora"],"x":"Contested points and known concerns about DORA after first year of applicability. Implementation burden DORA's five pillars combined produce substantial compliance work: Smaller financial entities (savings banks, regional insurers, smaller asset managers) face disproportionate bu"},{"t":"DORA Governance and Penalties","u":"/inside/docs/std/dora-governance-and-penalties/","g":"doc-std","d":"DORA governance combines national competent authority supervision, ESA cross-sector coordination, and Joint Oversight Mechanism for CTPPs.","l":["dora","regulation-concept"],"x":"DORA governance combines national competent authority supervision, ESA cross-sector coordination, and Joint Oversight Mechanism for CTPPs. Penalties set by Member States; supervisory powers include withdrawal of authorization for severe non-compliance. National competent authorit"},{"t":"DORA ICT Risk Management","u":"/inside/docs/std/dora-ict-risk-management/","g":"doc-std","d":"Articles 5-15 establish DORA's first pillar: the ICT risk management framework.","l":["dora","regulation-concept"],"x":"Articles 5-15 establish DORA's first pillar: the ICT risk management framework. Comprehensive, integrated framework covering governance, identification, protection, detection, response, recovery, learning, communication. The management body is fully accountable. Governance (Artic"},{"t":"DORA ICT Third-Party Risk","u":"/inside/docs/std/dora-ict-third-party-risk/","g":"doc-std","d":"Articles 28-44 establish DORA's fourth pillar: management of ICT third-party risk.","l":["dora","regulation-concept"],"x":"Articles 28-44 establish DORA's fourth pillar: management of ICT third-party risk. Comprehensive obligations on financial entities for managing TPP relationships, plus Union-level oversight of critical ICT third-party providers (CTPPs). General principles (Articles 28-29) Financi"},{"t":"DORA Incident Reporting","u":"/inside/docs/std/dora-incident-reporting/","g":"doc-std","d":"Articles 17-23 establish DORA's second pillar: ICT-related incident management, classification, reporting.","l":["dora","regulation-concept"],"x":"Articles 17-23 establish DORA's second pillar: ICT-related incident management, classification, reporting. Mandatory classification methodology; harmonized reporting timelines; voluntary cyber threat reporting. Incident management process (Article 17) Financial entity establishes"},{"t":"DORA position","u":"/inside/docs/std/dora-position/","g":"doc-std","d":"Current view on DORA after first year of applicability (January 2025, May 2026).","l":["dora","position"],"x":"Current view on DORA after first year of applicability (January 2025 — May 2026). Operational reality, gaps, where the regulation sits in EU financial services regulation. What DORA does well Harmonization across financial sector. Previously fragmented ICT requirements (EBA Guide"},{"t":"DORA Resilience Testing","u":"/inside/docs/std/dora-resilience-testing/","g":"doc-std","d":"Articles 24-27 establish DORA's third pillar: digital operational resilience testing.","l":["dora","regulation-concept"],"x":"Articles 24-27 establish DORA's third pillar: digital operational resilience testing. Two tiers: basic testing for all financial entities; advanced threat-led penetration testing (TLPT) for entities identified by the competent authority. TLPT based on TIBER-EU framework. Testing "},{"t":"DORA","u":"/inside/docs/std/dora/","g":"doc-std","d":"Map of Regulation (EU) 2022/2554, the Digital Operational Resilience Act.","l":["dora","eu-regulation","financial-services-regulation","moc"],"x":"Map of Regulation (EU) 2022/2554 — the Digital Operational Resilience Act. EU's comprehensive financial-services ICT resilience regulation. In force since 17 January 2025. Establishes harmonized requirements for ICT risk management, incident reporting, resilience testing, third-p"},{"t":"EU AI Act anchors","u":"/inside/docs/std/eu-ai-act-anchors/","g":"doc-std","d":"Primary texts, operating bodies, harmonized standards bodies, related instruments, named voices, reference resources for the EU AI Act cluster.","l":["anchors","eu-ai-act"],"x":"Primary texts, operating bodies, harmonized standards bodies, related instruments, named voices, reference resources for the EU AI Act cluster. Primary text Regulation (EU) 2024/1689 — the AI Act. Published in OJEU 12 July 2024. Free at eur-lex.europa.eu (search \"Regulation 2024/"},{"t":"EU AI Act Controversies","u":"/inside/docs/std/eu-ai-act-controversies/","g":"doc-std","d":"Contested points and known concerns about the EU AI Act.","l":["cross-cutting","eu-ai-act"],"x":"Contested points and known concerns about the EU AI Act. The regulation is the world's first comprehensive AI law; critique comes from multiple directions — industry on compliance cost, civil society on insufficient fundamental-rights protection, AI safety voices on insufficient "},{"t":"EU AI Act Governance","u":"/inside/docs/std/eu-ai-act-governance/","g":"doc-std","d":"Governance structure for the EU AI Act: European AI Office, AI Board, Scientific Panel, Advisory Forum, national competent authorities, Notified Bodies.","l":["eu-ai-act","regulation-concept"],"x":"Governance structure for the EU AI Act: European AI Office, AI Board, Scientific Panel, Advisory Forum, national competent authorities, Notified Bodies. Penalty framework. Coordination mechanisms. European AI Office Established 2024 within Commission DG CNECT (Communications Netw"},{"t":"EU AI Act GPAI Obligations","u":"/inside/docs/std/eu-ai-act-gpai-obligations/","g":"doc-std","d":"Cross-cutting obligations for general-purpose AI (GPAI) models under the EU AI Act.","l":["eu-ai-act","regulation-concept"],"x":"Cross-cutting obligations for general-purpose AI (GPAI) models under the EU AI Act. Two tiers: baseline GPAI (Articles 53-54) and GPAI with systemic risk (Article 55). Applicable from 2 August 2025 for newly-released models; pre-existing models have until 2 August 2027. What is a"},{"t":"EU AI Act High-Risk Obligations","u":"/inside/docs/std/eu-ai-act-high-risk-obligations/","g":"doc-std","d":"Obligations applying to high-risk AI systems under the EU AI Act.","l":["eu-ai-act","regulation-concept"],"x":"Obligations applying to high-risk AI systems under the EU AI Act. High-risk classification triggers extensive compliance work: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity, conformity a"},{"t":"EU AI Act position","u":"/inside/docs/std/eu-ai-act-position/","g":"doc-std","d":"Current view on the EU AI Act, its enforcement trajectory, its compliance implications, and where it sits in the global AI governance landscape.","l":["eu-ai-act","position"],"x":"Current view on the EU AI Act, its enforcement trajectory, its compliance implications, and where it sits in the global AI governance landscape. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What the EU AI Act does well First comprehensive AI regulation. Sets"},{"t":"EU AI Act Risk Tiers","u":"/inside/docs/std/eu-ai-act-risk-tiers/","g":"doc-std","d":"The EU AI Act categorizes AI systems by risk level.","l":["eu-ai-act","regulation-concept"],"x":"The EU AI Act categorizes AI systems by risk level. Unacceptable risk = prohibited. High risk = extensive obligations. Limited risk = transparency obligations. Minimal/no risk = voluntary. GPAI sits cross-cutting with its own tier (baseline + systemic risk subtier). Tier 1: Unacc"},{"t":"EU AI Act Timeline","u":"/inside/docs/std/eu-ai-act-timeline/","g":"doc-std","d":"Staged applicability schedule of the EU AI Act.","l":["eu-ai-act","regulation-concept"],"x":"Staged applicability schedule of the EU AI Act. Different obligations take effect at different dates from 2024 through 2027. Compliance planning depends on which obligations apply when. Master schedule Date Milestone What applies 2024-07-12 OJEU publication — 2024-08-01 Regulatio"},{"t":"EU AI Act","u":"/inside/docs/std/eu-ai-act/","g":"doc-std","d":"Map of Regulation (EU) 2024/1689, the EU AI Act.","l":["ai-governance","ai-regulation","eu-ai-act","eu-regulation","moc"],"x":"Map of Regulation (EU) 2024/1689 — the EU AI Act. World's first comprehensive AI regulation. Risk-tier obligations (unacceptable / high-risk / limited-risk / minimal-risk) plus separate GPAI tier. Staged applicability from 2 February 2025 through 2 August 2027. Reference cluster "},{"t":"FedRAMP and CMMC Controversies","u":"/inside/docs/std/fedramp-and-cmmc-controversies/","g":"doc-std","d":"CMMC 1.0 announced 2020; CMMC 2.0 simplified; full rollout phased through.","l":["cross-cutting","fedramp-cmmc"],"x":"FedRAMP cost and timeline Authorization timeline 12-18 months. Cost $300k-1M+ for assessment. $200k-500k+ annual continuous monitoring. Smaller cloud providers gated. CMMC implementation lag CMMC 1.0 announced 2020; CMMC 2.0 simplified; full rollout phased through 2028: Industry "},{"t":"FedRAMP and CMMC Mechanics","u":"/inside/docs/std/fedramp-and-cmmc-mechanics/","g":"doc-std","d":"Per FIPS 199 categorization (confidentiality / integrity /.","l":["fedramp-cmmc","framework-concept"],"x":"FedRAMP impact levels Per FIPS 199 categorization (confidentiality / integrity / availability): Low — limited adverse effect. Moderate — serious adverse effect. High — severe or catastrophic adverse effect. Cloud service authorized at a specific impact level. Federal agency consu"},{"t":"FedRAMP CMMC anchors","u":"/inside/docs/std/fedramp-cmmc-anchors/","g":"doc-std","d":"AWS (GovCloud), Azure (Government), Google Cloud (Government), Oracle (Government), Salesforce, ServiceNow, and many others FedRAMP-authorized.","l":["anchors","fedramp-cmmc"],"x":"FedRAMP and CMMC Anchors FedRAMP Operating bodies OMB — policy. GSA FedRAMP PMO — program management. JAB — Joint Authorization Board (DoD, DHS, GSA). DHS — continuous monitoring. Reference documents FedRAMP baselines (Low, Moderate, High) — NIST 800-53 tailored. FedRAMP Marketpl"},{"t":"FedRAMP CMMC position","u":"/inside/docs/std/fedramp-cmmc-position/","g":"doc-std","d":"FedRAMP CMMC position, from the knowledge vault.","l":["fedramp-cmmc","position"],"x":"FedRAMP and CMMC Position What they do well US federal procurement signals — clear, recognized. NIST 800-53 / 800-171 alignment — strong technical basis. Continuous monitoring (FedRAMP) — ongoing security signal. CMMC tiered approach — proportional. What they do poorly High cost "},{"t":"FedRAMP CMMC","u":"/inside/docs/std/fedramp-cmmc/","g":"doc-std","d":"Two US federal cybersecurity compliance programs.","l":["fedramp-cmmc","moc","security-compliance","us-federal"],"x":"FedRAMP and CMMC Cluster Two US federal cybersecurity compliance programs. FedRAMP (Federal Risk and Authorization Management Program) — federal cloud authorization. CMMC (Cybersecurity Maturity Model Certification) — Department of Defense supply chain. Both NIST 800-53 / 800-171"},{"t":"GDPR anchors","u":"/inside/docs/std/gdpr-anchors/","g":"doc-std","d":"Primary documents, operating bodies, key case law, named voices, reference resources for the GDPR cluster.","l":["anchors","gdpr"],"x":"Primary documents, operating bodies, key case law, named voices, reference resources for the GDPR cluster. Primary text Regulation (EU) 2016/679 — General Data Protection Regulation. Published OJEU 4 May 2016. Applicable 25 May 2018. Free at eur-lex.europa.eu. Recitals — 173 reci"},{"t":"GDPR Controller and Processor","u":"/inside/docs/std/gdpr-controller-and-processor/","g":"doc-std","d":"Articles 24-39 establish controller and processor obligations.","l":["gdpr","regulation-concept"],"x":"Articles 24-39 establish controller and processor obligations. Controller determines purposes and means; processor processes on controller's behalf. Joint controllers share responsibility. Both have distinct GDPR obligations: technical and organizational measures, processing reco"},{"t":"GDPR Controversies","u":"/inside/docs/std/gdpr-controversies/","g":"doc-std","d":"Contested points and known concerns about the GDPR after eight years of enforcement.","l":["cross-cutting","gdpr"],"x":"Contested points and known concerns about the GDPR after eight years of enforcement. The regulation is the global privacy benchmark; critiques deserve attention as the operational reality of implementation diverges from the regulatory ideal in places. One-stop-shop friction The l"},{"t":"GDPR Cross-Border Transfers","u":"/inside/docs/std/gdpr-cross-border-transfers/","g":"doc-std","d":"Chapter V (Articles 44-50) governs transfers of personal data to third countries (outside EU/EEA) and international organizations.","l":["gdpr","regulation-concept"],"x":"Chapter V (Articles 44-50) governs transfers of personal data to third countries (outside EU/EEA) and international organizations. Multiple transfer mechanisms available: adequacy decisions, appropriate safeguards (SCCs, BCRs, codes, certifications), derogations. The Schrems II r"},{"t":"GDPR Data Subject Rights","u":"/inside/docs/std/gdpr-data-subject-rights/","g":"doc-std","d":"Articles 12-23 of the GDPR establish rights of data subjects.","l":["gdpr","regulation-concept"],"x":"Articles 12-23 of the GDPR establish rights of data subjects. Controllers must facilitate exercise of rights, respond within one month (extendable to three for complex cases), and not charge fees except in limited circumstances. Rights operationalize the dignity-based framing of "},{"t":"GDPR Enforcement and DPAs","u":"/inside/docs/std/gdpr-enforcement-and-dpas/","g":"doc-std","d":"Chapters VI-VIII establish supervisory authority (DPA) structure, cooperation mechanisms (one-stop-shop), and enforcement framework.","l":["gdpr","regulation-concept"],"x":"Chapters VI-VIII establish supervisory authority (DPA) structure, cooperation mechanisms (one-stop-shop), and enforcement framework. National DPAs supervise; EDPB coordinates; CJEU is the ultimate interpretive authority. Penalties up to €20M or 4% global annual turnover. Eight ye"},{"t":"GDPR Lawful Bases","u":"/inside/docs/std/gdpr-lawful-bases/","g":"doc-std","d":"Article 6 establishes six lawful bases for processing personal data.","l":["gdpr","regulation-concept"],"x":"Article 6 establishes six lawful bases for processing personal data. Article 9 establishes a stricter regime for special category data. Identifying the correct lawful basis is the foundational compliance step for any processing. The six lawful bases (Article 6(1)) (a) Consent Dat"},{"t":"GDPR position","u":"/inside/docs/std/gdpr-position/","g":"doc-std","d":"Current view on GDPR after eight years of enforcement (2018-2026).","l":["gdpr","position"],"x":"Current view on GDPR after eight years of enforcement (2018-2026). What it does well, what it does poorly, where the regulation sits as a global privacy benchmark and as operational reality. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What GDPR does well Co"},{"t":"GDPR Principles","u":"/inside/docs/std/gdpr-principles/","g":"doc-std","d":"Article 5 of the GDPR establishes seven principles for personal data processing.","l":["gdpr","regulation-concept"],"x":"Article 5 of the GDPR establishes seven principles for personal data processing. All processing must comply with all principles. Accountability principle (5(2)) places the burden of demonstrating compliance on the controller. The seven principles 1. Lawfulness, fairness, transpar"},{"t":"GDPR","u":"/inside/docs/std/gdpr/","g":"doc-std","d":"Map of Regulation (EU) 2016/679, the General Data Protection Regulation.","l":["data-protection","eu-regulation","gdpr","moc","privacy"],"x":"Map of Regulation (EU) 2016/679 — the General Data Protection Regulation. The EU's privacy law and the global benchmark for data protection regulation. In force since 25 May 2018. Reference cluster for any work touching personal data of EU residents and for adjacent regulatory wo"},{"t":"HITRUST anchors","u":"/inside/docs/std/hitrust-anchors/","g":"doc-std","d":"HITRUST anchors, from the knowledge vault.","l":["anchors","hitrust"],"x":"Primary documents HITRUST CSF — current v11+ (paid access). MyCSF platform — HITRUST-hosted assessment platform. HITRUST Assurance Program documentation . Operating body HITRUST Alliance — Frisco, Texas. Founded 2007. Assessment ecosystem HITRUST Authorized External Assessor firm"},{"t":"HITRUST Assessment Levels","u":"/inside/docs/std/hitrust-assessment-levels/","g":"doc-std","d":"For each HITRUST control, mappings.","l":["framework-concept","hitrust"],"x":"Three certification levels HITRUST e1 (Essentials, 1-year) Entry-level certification. ~44 controls. 1-year validity. Designed for foundational cybersecurity. Lower cost. Common starting point. HITRUST i1 (Implemented, 1-year) Intermediate certification. ~182 controls. 1-year vali"},{"t":"HITRUST Controversies","u":"/inside/docs/std/hitrust-controversies/","g":"doc-std","d":"Among most expensive certification.","l":["cross-cutting","hitrust"],"x":"Cost Among most expensive certification paths: Pricing structure (MyCSF + assessor + HITRUST QA fees). Smaller orgs disproportionately burdened. Cost-benefit narrows outside healthcare. Proprietary CSF HITRUST CSF behind paid platform: Not freely accessible. Cross-framework mappi"},{"t":"HITRUST position","u":"/inside/docs/std/hitrust-position/","g":"doc-std","d":"HITRUST position, from the knowledge vault.","l":["hitrust","position"],"x":"What it does well Multi-framework integration reduces audit overhead. Tiered certification (e1 / i1 / r2) supports incremental adoption. US healthcare procurement strong recognition. Quality-controlled assessors . AI Security Certification new in 2024. What it does poorly Cost su"},{"t":"HITRUST","u":"/inside/docs/std/hitrust/","g":"doc-std","d":"HITRUST Common Security Framework.","l":["healthcare-broadened","hitrust","moc","security-compliance"],"x":"HITRUST Common Security Framework. Healthcare-origin US framework, broadened to cross-sector. Certifiable. Combines HIPAA + NIST + ISO 27001 + PCI DSS + multiple frameworks. Primarily US healthcare and adjacent sectors. Anchors position · anchors Provenance HITRUST Alliance — fou"},{"t":"ISO 21434 anchors","u":"/inside/docs/std/iso-21434-anchors/","g":"doc-std","d":"ISO 21434 anchors, from the knowledge vault.","l":["anchors","iso-21434"],"x":"ISO/SAE 21434 Anchors Primary documents ISO/SAE 21434:2021 — Road vehicles — Cybersecurity engineering. SAE J3061 (2016, deprecated) — predecessor guidebook. Adjacent standards UN R155 — vehicle type approval CSMS regulation. UN R156 — software update management system. ISO 24089"},{"t":"ISO 21434 Controversies","u":"/inside/docs/std/iso-21434-controversies/","g":"doc-std","d":"Comprehensive lifecycle.","l":["cross-cutting","iso-21434"],"x":"Implementation burden Comprehensive lifecycle requirements: Substantial upfront methodology adoption. TARA depth varies; ceremonial implementations common. Smaller tier-N suppliers face disproportionate burden. AI / ML treatment limited 2021 publication predates current AI / auto"},{"t":"ISO 21434 Lifecycle and TARA","u":"/inside/docs/std/iso-21434-lifecycle-and-tara/","g":"doc-std","d":"Organizational level..","l":["framework-concept","iso-21434"],"x":"CSMS — Cybersecurity Management System Organizational level. Includes: Cybersecurity policy and processes. Roles and responsibilities. Resources and competence. Distributed cybersecurity activities across product lifecycle. Continuous cybersecurity activities (post-deployment). A"},{"t":"ISO 21434 position","u":"/inside/docs/std/iso-21434-position/","g":"doc-std","d":"ISO 21434 position, from the knowledge vault.","l":["iso-21434","position"],"x":"ISO/SAE 21434 Position What it does well Vehicle-product cybersecurity previously gap; ISO 21434 fills it. TARA methodology structured threat-analysis approach. Lifecycle integration from concept through decommissioning. UN R155 implementation path — recognized as primary support"},{"t":"ISO 21434","u":"/inside/docs/std/iso-21434/","g":"doc-std","d":"Map of ISO/SAE 21434:2021, Road vehicles cybersecurity engineering.","l":["automotive-cybersecurity","iso-21434","moc"],"x":"ISO/SAE 21434 Cluster Map of ISO/SAE 21434:2021 — Road vehicles cybersecurity engineering. Joint ISO + SAE standard. Pairs with UN R155 (vehicle CSMS regulation) and TISAX (supplier-side information security). Reference cluster for vehicle product cybersecurity work. Anchors posi"},{"t":"ISO 22301 anchors","u":"/inside/docs/std/iso-22301-anchors/","g":"doc-std","d":"ISO 22301 anchors, from the knowledge vault.","l":["anchors","iso-22301"],"x":"Primary documents ISO/IEC 22301:2019 — Security and resilience — Business continuity management systems — Requirements. ISO/IEC 22313 — guidance on use of ISO 22301. ISO/IEC 22317 — Business Impact Analysis (BIA) guidance. ISO/IEC 22318 — supply chain continuity guidance. ISO/IEC"},{"t":"ISO 22301 Clause Structure and Key Concepts","u":"/inside/docs/std/iso-22301-clause-structure-and-key-concepts/","g":"doc-std","d":"Same structural pattern as ISO 27001 / ISO.","l":["framework-concept","iso-22301"],"x":"Clauses 4-10 (Annex SL aligned) Same structural pattern as ISO 27001 / ISO 42001: Cl 4 Context — interested parties, scope of BCMS. Cl 5 Leadership — top management commitment, policy, roles. Cl 6 Planning — risks/opportunities, BCM objectives. Cl 7 Support — resources, competenc"},{"t":"ISO 22301 Controversies","u":"/inside/docs/std/iso-22301-controversies/","g":"doc-std","d":"Compared to ISO 27001 / SOC 2, ISO 22301 less commonly.","l":["cross-cutting","iso-22301"],"x":"Procurement signal weak Compared to ISO 27001 / SOC 2, ISO 22301 less commonly required: Many customers don't ask. Implementation cost less justified for SaaS. Often pursued by regulatory pressure (DORA, NIS2) rather than direct procurement. Ceremonial testing Exercise programmes"},{"t":"ISO 22301 position","u":"/inside/docs/std/iso-22301-position/","g":"doc-std","d":"ISO 22301 position, from the knowledge vault.","l":["iso-22301","position"],"x":"What it does well Annex SL alignment with ISO 27001 + ISO 9001 + ISO 42001 enables integrated management systems. BIA methodology is operationally usable. Certifiable with mature audit ecosystem. Sector applicability broad. Disruption-scenario coverage beyond cyber (pandemic, geo"},{"t":"ISO 22301","u":"/inside/docs/std/iso-22301/","g":"doc-std","d":"Map of ISO/IEC 22301:2019, Business Continuity Management Systems.","l":["annex-sl-standards","business-continuity","iso-22301","moc"],"x":"Map of ISO/IEC 22301:2019 — Business Continuity Management Systems. Annex SL sibling to ISO 27001 + ISO 42001. Certifiable. Used alongside ISO 27001 + DORA for orgs with continuity obligations. Anchors position · anchors Provenance BS 25999 (UK origin, 2006-2007) — first BC manag"},{"t":"ISO 27001 anchors","u":"/inside/docs/std/iso-27001-anchors/","g":"doc-std","d":"Primary documents, related standards, named practitioners, and reference resources for the ISO 27001 cluster.","l":["anchors","iso-27001"],"x":"Primary documents, related standards, named practitioners, and reference resources for the ISO 27001 cluster. Curated reading list, not exhaustive. Primary normative documents ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security m"},{"t":"ISO 27001 Annex A.5 Organizational Controls","u":"/inside/docs/std/iso-27001-annex-a-5-organizational-controls/","g":"doc-std","d":"Largest of the four :2022 control themes.","l":["annex-a-theme","iso-27001","theme-organizational"],"x":"Largest of the four :2022 control themes. Thirty-seven controls covering policy, roles, asset management, classification and labelling, access control, supplier relationships, incident management, business continuity, and legal / regulatory compliance. The management-system spine"},{"t":"ISO 27001 Annex A.6 People Controls","u":"/inside/docs/std/iso-27001-annex-a-6-people-controls/","g":"doc-std","d":"Eight controls covering the human element of the ISMS: screening, contractual obligations, awareness and training, disciplinary process, post-employment obligations, NDAs, remote work, and event reporting.","l":["annex-a-theme","iso-27001","theme-people"],"x":"Eight controls covering the human element of the ISMS: screening, contractual obligations, awareness and training, disciplinary process, post-employment obligations, NDAs, remote work, and event reporting. Smallest theme by control count; the human element is consistently the lar"},{"t":"ISO 27001 Annex A.7 Physical Controls","u":"/inside/docs/std/iso-27001-annex-a-7-physical-controls/","g":"doc-std","d":"Fourteen controls covering physical perimeter, entry, monitoring, environmental threats, secure-area working, clear-desk, equipment, off-premises assets, media, utilities, cabling, maintenance, and disposal.","l":["annex-a-theme","iso-27001","theme-physical"],"x":"Fourteen controls covering physical perimeter, entry, monitoring, environmental threats, secure-area working, clear-desk, equipment, off-premises assets, media, utilities, cabling, maintenance, and disposal. The theme most often partially-excluded for remote-first SaaS — with cav"},{"t":"ISO 27001 Annex A.8 Technological Controls","u":"/inside/docs/std/iso-27001-annex-a-8-technological-controls/","g":"doc-std","d":"Thirty-four controls: endpoint and access controls, malware protection, vulnerability management, configuration and change management, deletion / masking / DLP, backup and redundancy, logging and monitoring, network security, cryptography,.","l":["annex-a-theme","iso-27001","theme-technological"],"x":"Thirty-four controls: endpoint and access controls, malware protection, vulnerability management, configuration and change management, deletion / masking / DLP, backup and redundancy, logging and monitoring, network security, cryptography, secure development lifecycle, applicatio"},{"t":"ISO 27001 Certification Process","u":"/inside/docs/std/iso-27001-certification-process/","g":"doc-std","d":"End-to-end mechanics of getting and keeping an ISO/IEC 27001:2022 certificate.","l":["cross-cutting","iso-27001"],"x":"End-to-end mechanics of getting and keeping an ISO/IEC 27001:2022 certificate. Implementation timeline, the four-audit cycle (Stage 1, Stage 2, two surveillances, recertification), accreditation chain, certification-body selection, cost structure, common procedural pitfalls. Impl"},{"t":"ISO 27001 Clause 10 Improvement","u":"/inside/docs/std/iso-27001-clause-10-improvement/","g":"doc-std","d":"ISO 27001 Clause 10 Improvement, from the knowledge vault.","l":["clause-10","iso-27001","iso-clause"],"x":"Sub-clause map 10.1 Continual improvement — the org shall continually improve the suitability, adequacy and effectiveness of the ISMS. 10.2 Nonconformity and corrective action. Key \"shall\" requirements (verbatim selections from :2022) 10.1: \"The organization shall continually imp"},{"t":"ISO 27001 Clause 4 Context","u":"/inside/docs/std/iso-27001-clause-4-context/","g":"doc-std","d":"ISO 27001 Clause 4 Context, from the knowledge vault.","l":["clause-4","iso-27001","iso-clause"],"x":"ISO 27001 Clause 4 Context of the Organization Sub-clause map 4.1 Understanding the organization and its context — external and internal issues relevant to ISMS purpose. 4.2 Understanding the needs and expectations of interested parties — interested parties (a), their relevant re"},{"t":"ISO 27001 Clause 5 Leadership","u":"/inside/docs/std/iso-27001-clause-5-leadership/","g":"doc-std","d":"ISO 27001 Clause 5 Leadership, from the knowledge vault.","l":["clause-5","iso-27001","iso-clause"],"x":"Sub-clause map 5.1 Leadership and commitment — top management shall demonstrate leadership and commitment through nine listed actions (a-i). 5.2 Policy — top management shall establish an information security policy with seven listed properties (a-g). 5.3 Organizational roles, re"},{"t":"ISO 27001 Clause 6 Planning","u":"/inside/docs/std/iso-27001-clause-6-planning/","g":"doc-std","d":"The SoA is the most-cited single artefact in an ISO 27001 audit.","l":["clause-6","iso-27001","iso-clause"],"x":"Sub-clause map 6.1 Actions to address risks and opportunities 6.1.1 General — actions to address risks and opportunities considered when planning the ISMS. 6.1.2 Information security risk assessment — define and apply a process. 6.1.3 Information security risk treatment — define "},{"t":"ISO 27001 Clause 7 Support","u":"/inside/docs/std/iso-27001-clause-7-support/","g":"doc-std","d":"ISO 27001 Clause 7 Support, from the knowledge vault.","l":["clause-7","iso-27001","iso-clause"],"x":"Sub-clause map 7.1 Resources — determine and provide resources needed for ISMS establishment, implementation, maintenance and continual improvement. 7.2 Competence — determine competence needed for ISMS-relevant work; ensure persons are competent; take actions to acquire missing "},{"t":"ISO 27001 Clause 8 Operation","u":"/inside/docs/std/iso-27001-clause-8-operation/","g":"doc-std","d":"ISO 27001 Clause 8 Operation, from the knowledge vault.","l":["clause-8","iso-27001","iso-clause"],"x":"Sub-clause map 8.1 Operational planning and control — plan, implement and control the processes needed to meet ISMS requirements and to implement actions determined in Cl 6. 8.2 Information security risk assessment — perform risk assessments at planned intervals or when significa"},{"t":"ISO 27001 Clause 9 Performance Evaluation","u":"/inside/docs/std/iso-27001-clause-9-performance-evaluation/","g":"doc-std","d":"ISO 27001 Clause 9 Performance Evaluation, from the knowledge vault.","l":["clause-9","iso-27001","iso-clause"],"x":"Sub-clause map 9.1 Monitoring, measurement, analysis and evaluation — what to monitor and measure, methods, when, by whom, when results analysed, retain documented information. 9.2 Internal audit 9.2.1 General — internal audits at planned intervals to verify the ISMS conforms to "},{"t":"ISO 27001 Controversies","u":"/inside/docs/std/iso-27001-controversies/","g":"doc-std","d":"Contested points and known failure modes of the standard and its certification ecosystem.","l":["cross-cutting","iso-27001"],"x":"Contested points and known failure modes of the standard and its certification ecosystem. The standard is widely used because procurement requires it, not because it is uncontested. Honest implementers and informed buyers should know where the gaps are. Compliance ≠ security The "},{"t":"ISO 27001 Family and Sector Variants","u":"/inside/docs/std/iso-27001-family-and-sector-variants/","g":"doc-std","d":"The wider ISO/IEC 27000 family and adjacent ISO standards that extend, refine, or run parallel to 27001.","l":["cross-cutting","iso-27001"],"x":"The wider ISO/IEC 27000 family and adjacent ISO standards that extend, refine, or run parallel to 27001. Plus the non-ISO frameworks that overlap heavily (NIST CSF, SOC 2, PCI DSS, Cyber Essentials, CSA Cloud Controls Matrix). When 27001 is the spine, the family is the rib cage. "},{"t":"ISO 27001 position","u":"/inside/docs/std/iso-27001-position/","g":"doc-std","d":"Current view on what ISO/IEC 27001:2022 is good for, what it is not good for, and where the standard sits relative to actual security work.","l":["iso-27001","position"],"x":"Current view on what ISO/IEC 27001:2022 is good for, what it is not good for, and where the standard sits relative to actual security work. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What ISO 27001:2022 does well Forces management commitment. Clause 5.1 (\""},{"t":"ISO 27001 Version History","u":"/inside/docs/std/iso-27001-version-history/","g":"doc-std","d":"Evolution from BS 7799 (1995) through ISO/IEC 27001:2005, :2013, and :2022.","l":["cross-cutting","iso-27001"],"x":"Evolution from BS 7799 (1995) through ISO/IEC 27001:2005, :2013, and :2022. Why each revision happened, what structurally changed, what the practical implementation shifts were, and the transition mechanics that move certified organizations forward. The BS 7799 origin (1995-2005)"},{"t":"ISO 27001","u":"/inside/docs/std/iso-27001/","g":"doc-std","d":"Map of ISO/IEC 27001:2022 as the international standard for information security management systems (ISMS), and the wider ISO/IEC 27000 family.","l":["infosec-management","iso-27001","moc","security-compliance"],"x":"Map of ISO/IEC 27001:2022 as the international standard for information security management systems (ISMS), and the wider ISO/IEC 27000 family. Per-clause atoms for the mandatory management clauses (Cl 4-10), per-theme atoms for the 93 Annex A controls (Organizational, People, Ph"},{"t":"ISO 42001 AI System Lifecycle","u":"/inside/docs/std/iso-42001-ai-system-lifecycle/","g":"doc-std","d":"The AI system lifecycle is the operational concept at the heart of ISO 42001.","l":["iso-42001","iso-concept"],"x":"The AI system lifecycle is the operational concept at the heart of ISO 42001. Annex A.6 controls structure around it; the lifecycle informs impact assessment, risk treatment, and ongoing operation. ISO/IEC 5338:2023 (AI system life cycle processes) is the companion deep-dive stan"},{"t":"ISO 42001 anchors","u":"/inside/docs/std/iso-42001-anchors/","g":"doc-std","d":"Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the ISO 42001 cluster.","l":["anchors","iso-42001"],"x":"Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the ISO 42001 cluster. Primary normative documents ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. Published 18 December 2023."},{"t":"ISO 42001 Annex A Controls","u":"/inside/docs/std/iso-42001-annex-a-controls/","g":"doc-std","d":"Reference control set for ISO/IEC 42001:2023 Annex A.","l":["annex-a","iso-42001"],"x":"Reference control set for ISO/IEC 42001:2023 Annex A. Approximately 38 controls organized into 10 control-objective areas. The Statement of Applicability (SoA, required by Cl 6.1.3.d equivalent) records which controls apply, with implementation status and justification for any ex"},{"t":"ISO 42001 Certification Process","u":"/inside/docs/std/iso-42001-certification-process/","g":"doc-std","d":"End-to-end mechanics for ISO/IEC 42001:2023 certification.","l":["cross-cutting","iso-42001"],"x":"End-to-end mechanics for ISO/IEC 42001:2023 certification. Same Annex SL mechanics as ISO 27001 — Stage 1 + Stage 2 audits, annual surveillance, three-year recertification. Audit-practice maturity is still early (certification bodies started offering audits late 2024 / early 2025"},{"t":"ISO 42001 Clause Structure","u":"/inside/docs/std/iso-42001-clause-structure/","g":"doc-std","d":"Mandatory clauses 4-10 of ISO/IEC 42001:2023.","l":["iso-42001","iso-clause"],"x":"Mandatory clauses 4-10 of ISO/IEC 42001:2023. Annex SL aligned — shared structure with ISO 9001, ISO 14001, ISO 27001, ISO 22301, ISO 27701. Most of the clause text mirrors the harmonized Annex SL wording; AI-specific content lives in the supporting Annex A controls and in select"},{"t":"ISO 42001 Controversies","u":"/inside/docs/std/iso-42001-controversies/","g":"doc-std","d":"Contested points and known concerns about ISO/IEC 42001:2023 and the early certification ecosystem.","l":["cross-cutting","iso-42001"],"x":"Contested points and known concerns about ISO/IEC 42001:2023 and the early certification ecosystem. The standard is widely positioned as the AI governance frame, but it is young, the audit ecosystem is shallow, and several structural critiques deserve attention. Audit-practice im"},{"t":"ISO 42001 position","u":"/inside/docs/std/iso-42001-position/","g":"doc-std","d":"Current view on what ISO/IEC 42001:2023 is good for, what it is not good for, and where the standard sits in the rapidly-evolving AI governance landscape.","l":["iso-42001","position"],"x":"Current view on what ISO/IEC 42001:2023 is good for, what it is not good for, and where the standard sits in the rapidly-evolving AI governance landscape. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What ISO 42001 does well Existing-standard inheritance. An"},{"t":"ISO 42001 vs ISO 27001 Integration","u":"/inside/docs/std/iso-42001-vs-iso-27001-integration/","g":"doc-std","d":"ISO/IEC 42001 (AI Management System) and ISO/IEC 27001 (Information Security Management System) are sibling Annex SL standards with substantial structural overlap and partial content overlap.","l":["cross-cutting","iso-27001","iso-42001"],"x":"ISO/IEC 42001 (AI Management System) and ISO/IEC 27001 (Information Security Management System) are sibling Annex SL standards with substantial structural overlap and partial content overlap. Most organizations pursuing both implement them as an integrated management system, with"},{"t":"ISO 42001","u":"/inside/docs/std/iso-42001/","g":"doc-std","d":"Map of ISO/IEC 42001:2023 as the international standard for AI Management Systems (AIMS).","l":["ai-governance","ai-management-system","iso-42001","moc"],"x":"Map of ISO/IEC 42001:2023 as the international standard for AI Management Systems (AIMS). The 27001-equivalent for AI governance: Annex SL-aligned management-system requirements (Cl 4-10) plus Annex A controls specific to AI system development, deployment, and operation. Referenc"},{"t":"IT-Grundschutz Certification","u":"/inside/docs/std/it-grundschutz-certification/","g":"doc-std","d":"Three certification paths: ISO 27001 auf Basis IT-Grundschutz (full), IT-Grundschutz Testat (lower-tier), or standard ISO 27001.","l":["bsi-grundschutz","framework-concept"],"x":"Three certification paths: ISO 27001 auf Basis IT-Grundschutz (full), IT-Grundschutz Testat (lower-tier), or standard ISO 27001. ISO 27001 auf Basis IT-Grundschutz The flagship certification. Combines: ISO 27001 international standard. IT-Grundschutz Bausteine as implementation m"},{"t":"IT-Grundschutz Controversies","u":"/inside/docs/std/it-grundschutz-controversies/","g":"doc-std","d":"Methodology and most Kompendium content primarily German.","l":["bsi-grundschutz","cross-cutting"],"x":"German-language gatekeeping Methodology and most Kompendium content primarily German. Effects: International orgs face translation friction. Non-German practitioners struggle. Smaller export limit on Grundschutz adoption outside DE. Bureaucratic implementation patterns Public-sec"},{"t":"IT-Grundschutz Methodology and Bausteine","u":"/inside/docs/std/it-grundschutz-methodology-and-bausteine/","g":"doc-std","d":"Core methodology and building blocks (Bausteine) of IT-Grundschutz.","l":["bsi-grundschutz","framework-concept"],"x":"Core methodology and building blocks (Bausteine) of IT-Grundschutz. Three protection-level approaches; modular Bausteine map to systems based on protection requirements. Methodology phases Schutzbedarfsfeststellung (protection requirement assessment) Each information / system cla"},{"t":"ITIL 4 Certification Scheme","u":"/inside/docs/std/itil-4-certification-scheme/","g":"doc-std","d":"ITIL 4 certifies individuals, not organizations.","l":["itil","itil-mechanism"],"x":"ITIL 4 certifies individuals, not organizations. PeopleCert (since 2021) operates the exam scheme; Accredited Training Organizations deliver training. Multiple streams reflect different practitioner needs: Foundation entry, Managing Professional (technical-facing), Strategic Lead"},{"t":"ITIL 4 Four Dimensions","u":"/inside/docs/std/itil-4-four-dimensions/","g":"doc-std","d":"Four perspectives applied to every aspect of service management.","l":["itil","itil-concept"],"x":"Four perspectives applied to every aspect of service management. The dimensions ensure that organizations consider the full system, not just process steps. PESTLE factors (political, economic, social, technological, legal, environmental) shape all four dimensions externally. The "},{"t":"ITIL 4 Guiding Principles","u":"/inside/docs/std/itil-4-guiding-principles/","g":"doc-std","d":"Seven universal recommendations that guide decisions and actions across the Service Value System.","l":["itil","itil-concept"],"x":"Seven universal recommendations that guide decisions and actions across the Service Value System. Originally introduced in ITIL Practitioner (2016), made central to ITIL 4. Designed to be durable across changing context and reusable beyond IT service management. The seven princip"},{"t":"ITIL 4 Practices","u":"/inside/docs/std/itil-4-practices/","g":"doc-std","d":"Thirty-four organizational capabilities used in the Service Value Chain.","l":["itil","itil-concept"],"x":"Thirty-four organizational capabilities used in the Service Value Chain. ITIL 4 replaced v3's \"processes + functions\" model with \"practices\" — each practice includes process content, but also the people, tools, suppliers, and data needed to perform the capability. Three categorie"},{"t":"ITIL 4 Service Value Chain","u":"/inside/docs/std/itil-4-service-value-chain/","g":"doc-std","d":"The Service Value Chain (SVC) is the operating model at the heart of the Service Value System.","l":["itil","itil-concept"],"x":"The Service Value Chain (SVC) is the operating model at the heart of the Service Value System. Six interconnected activities that transform demand into value. Each activity converts inputs into outputs; the activities are linked but not in a fixed sequence. The six activities 1. "},{"t":"ITIL 4 Service Value System","u":"/inside/docs/std/itil-4-service-value-system/","g":"doc-std","d":"The Service Value System (SVS) is the central operating model of ITIL 4.","l":["itil","itil-concept"],"x":"The Service Value System (SVS) is the central operating model of ITIL 4. It describes how all the components and activities of an organization work together as a system to facilitate value creation. Replaces v3's service lifecycle as the framework's organizing metaphor. Definitio"},{"t":"ITIL anchors","u":"/inside/docs/std/itil-anchors/","g":"doc-std","d":"Primary documents, operating bodies, training providers, named practitioners, reference resources for the ITIL cluster.","l":["anchors","itil"],"x":"Primary documents, operating bodies, training providers, named practitioners, reference resources for the ITIL cluster. Primary documents (ITIL 4) ITIL 4 Foundation — entry-level core publication. Defines the SVS, SVC, four dimensions, seven guiding principles, basic practice des"},{"t":"ITIL Controversies","u":"/inside/docs/std/itil-controversies/","g":"doc-std","d":"Contested points and known failure modes of ITIL and the certification ecosystem.","l":["cross-cutting","itil"],"x":"Contested points and known failure modes of ITIL and the certification ecosystem. ITIL is widely used and widely criticized; both deserve attention. The critique is not that ITIL should be abandoned but that practitioner reality often falls short of framework intent. Process-heav"},{"t":"ITIL position","u":"/inside/docs/std/itil-position/","g":"doc-std","d":"Current view on what ITIL 4 is good for, what it is not good for, and where it sits as a service-management framework.","l":["itil","position"],"x":"Current view on what ITIL 4 is good for, what it is not good for, and where it sits as a service-management framework. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What ITIL 4 does well Shared vocabulary across enterprise IT. Words like \"incident\", \"problem\""},{"t":"ITIL Version History","u":"/inside/docs/std/itil-version-history/","g":"doc-std","d":"Evolution from CCTA Government Information Technology Infrastructure Method (1989) through ITIL v2, v3, v3 2011 refresh, ITIL 4 (2019), to the 2023 PeopleCert refresh.","l":["cross-cutting","itil"],"x":"Evolution from CCTA Government Information Technology Infrastructure Method (1989) through ITIL v2, v3, v3 2011 refresh, ITIL 4 (2019), to the 2023 PeopleCert refresh. Why each major version happened, what structurally changed, what the practical shifts meant. CCTA origin (1986-1"},{"t":"ITIL vs ISO 20000","u":"/inside/docs/std/itil-vs-iso-20000/","g":"doc-std","d":"ITIL and ISO/IEC 20000-1 are complementary, not competing.","l":["cross-cutting","iso-20000","itil"],"x":"ITIL and ISO/IEC 20000-1 are complementary, not competing. ITIL is a framework (a body of practice, voluntary, adapt-as-you-go). ISO/IEC 20000-1 is a certifiable management-system standard (a set of \"shall\" requirements, auditable). Many organizations implement ITIL practices and"},{"t":"ITIL","u":"/inside/docs/std/itil/","g":"doc-std","d":"Map of ITIL 4 (2019, with 2023 refresh) as the dominant IT service management framework.","l":["itil","itsm-frameworks","moc","service-management"],"x":"Map of ITIL 4 (2019, with 2023 refresh) as the dominant IT service management framework. Service Value System, Service Value Chain, four dimensions, seven guiding principles, 34 practices, certification scheme. Reference cluster for service-management decisions in SRE / platform "},{"t":"MITRE anchors","u":"/inside/docs/std/mitre-anchors/","g":"doc-std","d":"MITRE anchors, from the knowledge vault.","l":["anchors","mitre"],"x":"MITRE Corporation MITRE Corporation — US not-for-profit. Operates FFRDCs for US government. MITRE Center for Threat-Informed Defense — community-funded center driving ATT&CK and related work. Frameworks and resources ATT&CK — attack.mitre.org D3FEND — d3fend.mitre.org ATLAS — atl"},{"t":"MITRE ATLAS","u":"/inside/docs/std/mitre-atlas/","g":"doc-std","d":"Adversarial Threat Landscape for Artificial-Intelligence Systems.","l":["framework-concept","mitre"],"x":"Adversarial Threat Landscape for Artificial-Intelligence Systems. MITRE's ATT&CK-style framework for adversary tactics and techniques against AI/ML systems. Published 2020; expanded 2021-2024 with generative-AI techniques. Structure ATLAS mirrors ATT&CK structure adapted for AI /"},{"t":"MITRE ATT&CK","u":"/inside/docs/std/mitre-att-ck/","g":"doc-std","d":"MITRE Adversarial Tactics, Techniques, and Common Knowledge framework.","l":["framework-concept","mitre"],"x":"MITRE Adversarial Tactics, Techniques, and Common Knowledge framework. The de facto operational taxonomy for adversary behavior. Multiple matrices covering different environments. Structure Tactics High-level adversary objectives. Each tactic represents a \"why\" — what the adversa"},{"t":"MITRE D3FEND","u":"/inside/docs/std/mitre-d3fend/","g":"doc-std","d":"MITRE's framework for defensive countermeasures.","l":["framework-concept","mitre"],"x":"MITRE's framework for defensive countermeasures. Counterpart to ATT&CK on the defense side. Published 2021, funded by NSA. Provides taxonomy of defensive techniques mapped to the offensive techniques they counter. Structure D3FEND organizes defensive countermeasures by tactic: De"},{"t":"MITRE position","u":"/inside/docs/std/mitre-position/","g":"doc-std","d":"Current view on MITRE ATT&CK / D3FEND / ATLAS as operational frameworks for threat intel and defense.","l":["mitre","position"],"x":"MITRE Frameworks Position Current view on MITRE ATT&CK / D3FEND / ATLAS as operational frameworks for threat intel and defense. What they do well Practitioner-accessible. Free, open, well-organized. Continuously updated. Multiple major updates per year for ATT&CK. Vendor-neutral."},{"t":"MITRE","u":"/inside/docs/std/mitre/","g":"doc-std","d":"Map of MITRE's adversary-and-defense knowledge bases: ATT&CK (adversary tactics, techniques, procedures), D3FEND (defensive countermeasures), ATLAS (adversarial AI threats).","l":["adversary-frameworks","mitre","moc","threat-intelligence"],"x":"MITRE Adversary Frameworks Cluster Map of MITRE's adversary-and-defense knowledge bases: ATT&CK (adversary tactics, techniques, procedures), D3FEND (defensive countermeasures), ATLAS (adversarial AI threats). De facto operational threat-intelligence references. Reference cluster "},{"t":"NIS2 anchors","u":"/inside/docs/std/nis2-anchors/","g":"doc-std","d":"Primary text, operating bodies, Member State transposition, related instruments, reference resources.","l":["anchors","nis2"],"x":"Primary text, operating bodies, Member State transposition, related instruments, reference resources. Primary text Directive (EU) 2022/2555 — NIS2 Directive. Published OJEU 27 December 2022. Free at eur-lex.europa.eu. Recitals — 144 recitals. Articles — 46 articles. Annexes — Ann"},{"t":"NIS2 Controversies","u":"/inside/docs/std/nis2-controversies/","g":"doc-std","d":"Contested points and known concerns about NIS2 implementation.","l":["cross-cutting","nis2"],"x":"Contested points and known concerns about NIS2 implementation. Enforcement is early; many concerns relate to transposition variance and operational gaps. Transposition variance NIS2 is a directive, not a regulation — Member States transpose into national law with discretion. Effe"},{"t":"NIS2 Governance and Penalties","u":"/inside/docs/std/nis2-governance-and-penalties/","g":"doc-std","d":"NIS2 governance combines national supervision, EU-level cooperation (Cooperation Group, CSIRTs network, EU-CyCLONe, ENISA), management body accountability (Art 20), and a substantial penalty framework (Art 34).","l":["nis2","regulation-concept"],"x":"NIS2 governance combines national supervision, EU-level cooperation (Cooperation Group, CSIRTs network, EU-CyCLONe, ENISA), management body accountability (Art 20), and a substantial penalty framework (Art 34). Management body liability is one of NIS2's most consequential changes"},{"t":"NIS2 Incident Reporting","u":"/inside/docs/std/nis2-incident-reporting/","g":"doc-std","d":"Article 23 establishes the incident reporting regime.","l":["nis2","regulation-concept"],"x":"Article 23 establishes the incident reporting regime. Significant incidents must be notified via three-stage timeline: 24h early warning, 72h incident notification, 1-month final report. Plus intermediate progress reports. Tight timelines force pre-built response infrastructure. "},{"t":"NIS2 position","u":"/inside/docs/std/nis2-position/","g":"doc-std","d":"Current view on NIS2 enforcement landscape, compliance implications, and where the directive sits in EU cybersecurity regulation.","l":["nis2","position"],"x":"Current view on NIS2 enforcement landscape, compliance implications, and where the directive sits in EU cybersecurity regulation. Dated, revisable. State of the view as of 2026-05-12 What NIS2 does well Broadened sector scope. 18 sectors vs NIS1's 7. Captures critical-infrastruct"},{"t":"NIS2 Scope and Entities","u":"/inside/docs/std/nis2-scope-and-entities/","g":"doc-std","d":"NIS2 classifies entities as essential or important based on sector (Annex I or II) and size.","l":["nis2","regulation-concept"],"x":"NIS2 classifies entities as essential or important based on sector (Annex I or II) and size. Essential entities face proactive supervision and higher penalties; important entities face reactive supervision. The classification drives the regulatory obligations and supervision regi"},{"t":"NIS2 Security Measures","u":"/inside/docs/std/nis2-security-measures/","g":"doc-std","d":"Article 21 establishes the cybersecurity risk-management measures required of essential and important entities.","l":["nis2","regulation-concept"],"x":"Article 21 establishes the cybersecurity risk-management measures required of essential and important entities. Ten minimum measures with all-hazards approach. Implementation must be appropriate and proportionate to risk. Article 21(1) general obligation Essential and important e"},{"t":"NIS2 vs ISO 27001","u":"/inside/docs/std/nis2-vs-iso-27001/","g":"doc-std","d":"NIS2 is regulation; ISO 27001 is voluntary standard.","l":["cross-cutting","iso-27001","nis2"],"x":"NIS2 is regulation; ISO 27001 is voluntary standard. Strong content overlap — Article 21 measures map heavily to Annex A controls. ISO 27001 certification supports NIS2 compliance but does not substitute. Combined implementation is the practical path for in-scope entities. Side-b"},{"t":"NIS2","u":"/inside/docs/std/nis2/","g":"doc-std","d":"Map of Directive (EU) 2022/2555, the NIS2 Directive.","l":["cybersecurity-regulation","eu-regulation","moc","nis2"],"x":"Map of Directive (EU) 2022/2555 — the NIS2 Directive. Successor to the original NIS Directive (2016/1148). Cybersecurity for essential and important entities across the EU. Member state transposition deadline 17 October 2024; enforcement ramping through 2025-2026. Reference clust"},{"t":"NIST AI RMF anchors","u":"/inside/docs/std/nist-ai-rmf-anchors/","g":"doc-std","d":"Primary documents, operating bodies, related frameworks, named contributors, reference resources for the NIST AI RMF cluster.","l":["anchors","nist-ai-rmf"],"x":"Primary documents, operating bodies, related frameworks, named contributors, reference resources for the NIST AI RMF cluster. Primary documents NIST AI 100-1: AI Risk Management Framework 1.0 (January 2023). Foundational framework document. Free PDF from NIST. NIST AI 100-1 Playb"},{"t":"NIST AI RMF Controversies","u":"/inside/docs/std/nist-ai-rmf-controversies/","g":"doc-std","d":"Contested points and known concerns about the NIST AI Risk Management Framework.","l":["cross-cutting","nist-ai-rmf"],"x":"Contested points and known concerns about the NIST AI Risk Management Framework. The framework is widely-referenced and respected as a baseline; the critiques deserve attention nonetheless. Voluntary status and self-claim adoption The most-cited structural concern: No certificati"},{"t":"NIST AI RMF Core Functions","u":"/inside/docs/std/nist-ai-rmf-core-functions/","g":"doc-std","d":"Four core functions of the NIST AI Risk Management Framework: Govern, Map, Measure, Manage.","l":["framework-concept","nist-ai-rmf"],"x":"Four core functions of the NIST AI Risk Management Framework: Govern, Map, Measure, Manage. Each function has categories and sub-categories; the Playbook provides suggested actions per sub-category. Functions are cyclical and interdependent; GOVERN underlies the others. GOVERN Th"},{"t":"NIST AI RMF GenAI Profile","u":"/inside/docs/std/nist-ai-rmf-genai-profile/","g":"doc-std","d":"NIST AI 600-1, published July 2024.","l":["framework-profile","nist-ai-rmf"],"x":"NIST AI 600-1, published July 2024. The Generative AI Profile extending the NIST AI Risk Management Framework 1.0 with substantive content for generative AI systems. 200+ suggested actions across the four core functions and 12 GenAI-specific risk categories. What the GenAI Profil"},{"t":"NIST AI RMF position","u":"/inside/docs/std/nist-ai-rmf-position/","g":"doc-std","d":"Current view on what the NIST AI Risk Management Framework is good for, what it is not good for, and where it sits in the rapidly-evolving AI governance landscape.","l":["nist-ai-rmf","position"],"x":"Current view on what the NIST AI Risk Management Framework is good for, what it is not good for, and where it sits in the rapidly-evolving AI governance landscape. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What NIST AI RMF does well Outcome-oriented, not "},{"t":"NIST AI RMF vs ISO 42001","u":"/inside/docs/std/nist-ai-rmf-vs-iso-42001/","g":"doc-std","d":"NIST AI RMF (voluntary, US-origin, outcome-oriented) and ISO/IEC 42001 (certifiable, international, management-system-oriented) are the two dominant AI governance frameworks as of 2026.","l":["cross-cutting","iso-42001","nist-ai-rmf"],"x":"NIST AI RMF (voluntary, US-origin, outcome-oriented) and ISO/IEC 42001 (certifiable, international, management-system-oriented) are the two dominant AI governance frameworks as of 2026. Complementary rather than competing. This atom maps the differences, the overlap, and the dual"},{"t":"NIST AI RMF","u":"/inside/docs/std/nist-ai-rmf/","g":"doc-std","d":"Map of the NIST AI Risk Management Framework 1.0 (January 2023) and the Generative AI Profile (NIST AI 600-1, July 2024).","l":["ai-governance","moc","nist-ai-rmf","voluntary-frameworks"],"x":"Map of the NIST AI Risk Management Framework 1.0 (January 2023) and the Generative AI Profile (NIST AI 600-1, July 2024). Voluntary, outcome-oriented US framework with four core functions (Govern, Map, Measure, Manage). Reference cluster for AI risk reasoning that complements ISO"},{"t":"NIST CSF anchors","u":"/inside/docs/std/nist-csf-anchors/","g":"doc-std","d":"NIST CSF anchors, from the knowledge vault.","l":["anchors","nist-csf"],"x":"Primary documents NIST Cybersecurity Framework 2.0 (February 2024). Free from NIST. NIST CSF Quick-Start Guides for specific contexts (SMB, supply chain, governance). NIST CSF Community Profiles for sectors. NIST CSF Informative References mapping CSF to NIST 800-53, ISO 27001, C"},{"t":"NIST CSF Controversies","u":"/inside/docs/std/nist-csf-controversies/","g":"doc-std","d":"Implementation tiers often.","l":["cross-cutting","nist-csf"],"x":"Non-certifiable status Self-claim only: \"We're aligned with NIST CSF\" easy to assert, hard to verify. No third-party attestation. Variance across organizations claiming alignment. Tier misuse Implementation tiers often misused: Treated as maturity model when not strictly intended"},{"t":"NIST CSF Core Functions","u":"/inside/docs/std/nist-csf-core-functions/","g":"doc-std","d":"Six functions structure NIST CSF 2.0.","l":["framework-concept","nist-csf"],"x":"Six functions structure NIST CSF 2.0. Each function has categories and subcategories. Subcategories are outcomes the org should achieve. GOVERN (new in 2.0) Establish, communicate, monitor cybersecurity risk management strategy, expectations, policy. Categories: Organizational Co"},{"t":"NIST CSF position","u":"/inside/docs/std/nist-csf-position/","g":"doc-std","d":"NIST CSF position, from the knowledge vault.","l":["nist-csf","position"],"x":"What it does well Function structure intuitive. Govern / Identify / Protect / Detect / Respond / Recover maps to operational reality. Outcome-oriented. Subcategories are outcomes, not prescribed activities. Free, accessible. No cost; documents free. Adopted globally beyond US. IS"},{"t":"NIST CSF vs ISO 27001 and NIST AI RMF","u":"/inside/docs/std/nist-csf-vs-iso-27001-and-nist-ai-rmf/","g":"doc-std","d":"NIST CSF is voluntary outcome-oriented framework.","l":["cross-cutting","nist-csf"],"x":"NIST CSF is voluntary outcome-oriented framework. ISO 27001 is certifiable management-system standard. NIST AI RMF is voluntary AI-risk framework. Complementary frameworks, often used together. NIST CSF vs ISO 27001 Aspect NIST CSF 2.0 ISO 27001:2022 Type Voluntary framework Cert"},{"t":"NIST CSF","u":"/inside/docs/std/nist-csf/","g":"doc-std","d":"Map of NIST Cybersecurity Framework 2.0 (February 2024).","l":["cybersecurity-frameworks","moc","nist-csf","voluntary-frameworks"],"x":"Map of NIST Cybersecurity Framework 2.0 (February 2024). Voluntary, outcome-oriented, function-organized US framework. Six core functions: Govern, Identify, Protect, Detect, Respond, Recover. Widely used as implementation reference globally, including by ISO 27001 shops. Anchors "},{"t":"OECD AI anchors","u":"/inside/docs/std/oecd-ai-anchors/","g":"doc-std","d":"OECD members (38) + non-member adherents (Argentina, Brazil, Costa Rica, Egypt, Malta, Peru, Romania, Singapore, Ukraine, and growing, check oecd.ai for current).","l":["anchors","oecd-ai"],"x":"Primary documents OECD Recommendation of the Council on Artificial Intelligence (May 2019, revised May 2024). Free from OECD. OECD AI Policy Observatory publications — country profiles, thematic reports. OECD Framework for the Classification of AI Systems . Operating bodies OECD "},{"t":"OECD AI Controversies","u":"/inside/docs/std/oecd-ai-controversies/","g":"doc-std","d":"No enforcement.","l":["cross-cutting","oecd-ai"],"x":"Voluntary status No enforcement mechanism: Adherent states implement voluntarily. Variance significant. Procurement signal weaker than regulations. High abstraction Principles operate at ethical / values level: Operational implementation requires concrete frameworks. \"We follow O"},{"t":"OECD AI position","u":"/inside/docs/std/oecd-ai-position/","g":"doc-std","d":"OECD AI position, from the knowledge vault.","l":["oecd-ai","position"],"x":"OECD AI Principles Position What they do well First international AI standard — diplomatic baseline established. Values-based principles durable across AI technology evolution. Brussels-effect catalyst — many subsequent frameworks aligned. 2024 update addresses GenAI maturation. "},{"t":"OECD AI Values-Based Principles","u":"/inside/docs/std/oecd-ai-values-based-principles/","g":"doc-std","d":"AI should contribute to inclusive growth, sustainable development, well-being for people and.","l":["framework-concept","oecd-ai"],"x":"1. Inclusive growth, sustainable development, well-being AI should contribute to inclusive growth, sustainable development, well-being for people and planet: Inclusive growth : AI should reduce inequalities, not amplify. Sustainable development : AI should support SDGs. Well-bein"},{"t":"OECD AI","u":"/inside/docs/std/oecd-ai/","g":"doc-std","d":"Map of OECD AI Principles.","l":["ai-governance","international-principles","moc","oecd-ai"],"x":"OECD AI Principles Cluster Map of OECD AI Principles. Adopted 22 May 2019; revised May 2024. International voluntary principles for trustworthy AI. First intergovernmental AI standard. Influenced ISO 42001, NIST AI RMF, EU AI Act, multiple national AI strategies. Anchors position"},{"t":"OWASP LLM Mitigations","u":"/inside/docs/std/owasp-llm-mitigations/","g":"doc-std","d":"Cross-cutting defensive practices for LLM application security.","l":["mitigations","owasp-llm-top-10"],"x":"Cross-cutting defensive practices for LLM application security. Per-risk prevention is covered in OWASP LLM Top 10 2025 . This atom captures patterns that work across multiple Top 10 categories. Defense in depth No single control is reliable. Effective LLM application security la"},{"t":"OWASP LLM Top 10 2025","u":"/inside/docs/std/owasp-llm-top-10-2025/","g":"doc-std","d":"The ten risks of the OWASP Top 10 for LLM Applications v2.0 (published November 2024).","l":["owasp-llm-top-10","threat-list"],"x":"The ten risks of the OWASP Top 10 for LLM Applications v2.0 (published November 2024). Operational threat taxonomy with attack scenarios and prevention guidance per risk. LLM01:2025 Prompt Injection Adversarial input causes the LLM to behave outside intended scope. Two variants D"},{"t":"OWASP LLM Top 10 anchors","u":"/inside/docs/std/owasp-llm-top-10-anchors/","g":"doc-std","d":"Primary documents, OWASP working group, related projects, named voices, reference resources for the OWASP LLM Top 10 cluster.","l":["anchors","owasp-llm-top-10"],"x":"Primary documents, OWASP working group, related projects, named voices, reference resources for the OWASP LLM Top 10 cluster. Primary documents OWASP Top 10 for LLM Applications v2.0 (2025 edition) — published November 2024. Current version. Free PDF from owasp.org/www-project-to"},{"t":"OWASP LLM Top 10 Controversies","u":"/inside/docs/std/owasp-llm-top-10-controversies/","g":"doc-std","d":"Contested points and known limitations of the OWASP Top 10 for LLM Applications.","l":["cross-cutting","owasp-llm-top-10"],"x":"Contested points and known limitations of the OWASP Top 10 for LLM Applications. The list is widely-adopted and well-regarded; the critiques deserve attention. \"Top 10\" framing limits coverage The 10-risk framing is operationally useful but enforces selection: Real AI security ri"},{"t":"OWASP LLM Top 10 position","u":"/inside/docs/std/owasp-llm-top-10-position/","g":"doc-std","d":"Current view on what the OWASP Top 10 for LLM Applications is good for, what it is not good for, where it sits in the AI security landscape.","l":["owasp-llm-top-10","position"],"x":"Current view on what the OWASP Top 10 for LLM Applications is good for, what it is not good for, where it sits in the AI security landscape. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What OWASP LLM Top 10 does well Operational rather than governance-orien"},{"t":"OWASP LLM Top 10","u":"/inside/docs/std/owasp-llm-top-10/","g":"doc-std","d":"Map of the OWASP Top 10 for LLM Applications.","l":["ai-security","moc","owasp-llm-top-10","threat-taxonomies"],"x":"Map of the OWASP Top 10 for LLM Applications. Current version: 2025 (published November 2024). Operational threat taxonomy for LLM-integrated applications and agent systems. Reference cluster for technical AI security work and as input to NIST AI RMF / ISO 42001 risk registers. A"},{"t":"OWASP LLM vs Top 10 Web","u":"/inside/docs/std/owasp-llm-vs-top-10-web/","g":"doc-std","d":"The OWASP Top 10 for Web Applications (since 2003, current 2021 edition) and the OWASP LLM Top 10 (since 2023, current 2025 edition) are sibling Top 10 lists with overlapping but distinct concerns.","l":["cross-cutting","owasp-llm-top-10"],"x":"OWASP LLM Top 10 vs OWASP Top 10 (Web) The OWASP Top 10 for Web Applications (since 2003, current 2021 edition) and the OWASP LLM Top 10 (since 2023, current 2025 edition) are sibling Top 10 lists with overlapping but distinct concerns. LLM applications are web applications; they"},{"t":"PCI DSS anchors","u":"/inside/docs/std/pci-dss-anchors/","g":"doc-std","d":"PCI DSS anchors, from the knowledge vault.","l":["anchors","pci-dss"],"x":"Primary documents PCI DSS v4.0 (March 2022) + v4.0.1 (June 2024). PCI DSS Self-Assessment Questionnaires (multiple SAQ types). PCI DSS Glossary . Reporting Templates (Report on Compliance, Attestation of Compliance). All free from PCI SSC. Operating body PCI Security Standards Co"},{"t":"PCI DSS Controversies","u":"/inside/docs/std/pci-dss-controversies/","g":"doc-std","d":"PCI compliance does not predict breach absence.","l":["cross-cutting","pci-dss"],"x":"Compliance vs security The classic gap: Target (2013): PCI compliant at time of breach. Equifax (2017): held multiple certifications. Various: certified entities breached. PCI compliance does not predict breach absence. Prescriptive ⇒ rigid Twelve requirements + ~300 sub-requirem"},{"t":"PCI DSS position","u":"/inside/docs/std/pci-dss-position/","g":"doc-std","d":"PCI DSS position, from the knowledge vault.","l":["pci-dss","position"],"x":"What it does well Prescriptive controls — clear implementation guidance. Industry mandate — backed by card schemes; real enforcement. Continuous improvement via version revisions. v4.0 customized approach adds flexibility. Mature QSA ecosystem. What it does poorly Prescriptive ⇒ "},{"t":"PCI DSS Twelve Requirements and Compliance","u":"/inside/docs/std/pci-dss-twelve-requirements-and-compliance/","g":"doc-std","d":"Network segmentation. Firewall / equivalent controls.","l":["framework-concept","pci-dss"],"x":"The twelve requirements (v4.0) 1. Install and maintain network security controls Network segmentation. Firewall / equivalent controls. CHD environment (CDE) isolated. 2. Apply secure configurations to all system components Hardening standards. Default credentials changed. Configu"},{"t":"PCI DSS","u":"/inside/docs/std/pci-dss/","g":"doc-std","d":"Map of PCI DSS v4.0 (March 2022, mandatory March 2025).","l":["moc","payment-security","pci-dss"],"x":"Map of PCI DSS v4.0 (March 2022, mandatory March 2025). Payment Card Industry Data Security Standard. Operator: PCI Security Standards Council. Mandatory for entities storing, processing, transmitting cardholder data. Prescriptive control requirements. Anchors position · anchors "},{"t":"PRINCE2 anchors","u":"/inside/docs/std/prince2-anchors/","g":"doc-std","d":"PRINCE2 anchors, from the knowledge vault.","l":["anchors","prince2"],"x":"Primary documents Managing Successful Projects with PRINCE2 (7th edition, 2023). PRINCE2 Agile Guidance . PRINCE2 Foundation and Practitioner exam syllabi . Operating body PeopleCert — current owner (since AXELOS acquisition 2021). PRINCE2 Accredited Training Organizations (ATOs)"},{"t":"PRINCE2 Controversies","u":"/inside/docs/std/prince2-controversies/","g":"doc-std","d":"Management products + registers +.","l":["cross-cutting","prince2"],"x":"Document-heavy Management products + registers + reports: Substantial documentation burden. Ritual completion vs substantive use. Smaller-project disproportionate overhead. Tailoring discipline weak Principle 7 (tailor to suit) often ignored in practice: Full method applied regar"},{"t":"PRINCE2 position","u":"/inside/docs/std/prince2-position/","g":"doc-std","d":"PRINCE2 position, from the knowledge vault.","l":["position","prince2"],"x":"What it does well Tailorable structure — principles + processes + tailoring. UK / EU public sector recognition. Stage-based governance matches risk-managed project execution. Roles and responsibilities explicit. PRINCE2 Agile option for hybrid contexts. What it does poorly Heavy "},{"t":"PRINCE2 Principles Aspects Processes","u":"/inside/docs/std/prince2-principles-aspects-processes/","g":"doc-std","d":"Why? Documented business justification.","l":["framework-concept","prince2"],"x":"PRINCE2 Principles, Aspects, Processes Seven principles Continued business justification — viable business case throughout. Learn from experience — lessons captured + applied. Defined roles, responsibilities and relationships — clear authority. Manage by stages — break into stage"},{"t":"PRINCE2","u":"/inside/docs/std/prince2/","g":"doc-std","d":"Map of PRINCE2 (PRojects IN Controlled Environments).","l":["moc","prince2","project-management"],"x":"Map of PRINCE2 (PRojects IN Controlled Environments). UK-origin project management methodology. Owned by PeopleCert (sibling to ITIL since 2021 acquisition). PRINCE2 7 (2023) current version. Heavily used in UK / EU public sector and many private orgs. Anchors position · anchors "},{"t":"SLSA Levels and SBOM Formats","u":"/inside/docs/std/slsa-levels-and-sbom-formats/","g":"doc-std","d":"No supply chain assurance.","l":["framework-concept","slsa-sbom"],"x":"SLSA v1.0 levels Level 0 — No requirements No supply chain assurance. Level 1 — Provenance exists Software produced with provenance (build records). Documented build process. Provenance available to consumers. Level 2 — Provenance authenticated, build platform integrity Provenanc"},{"t":"SLSA SBOM anchors","u":"/inside/docs/std/slsa-sbom-anchors/","g":"doc-std","d":"SLSA SBOM anchors, from the knowledge vault.","l":["anchors","slsa-sbom"],"x":"SLSA + SBOM Anchors Primary documents SLSA SLSA Specification v1.0 — slsa.dev. SLSA Threats and Mitigations documentation. SBOM SPDX 2.3 specification (ISO/IEC 5962:2021) — Linux Foundation. CycloneDX 1.6 specification — OWASP. NTIA Minimum Elements for an SBOM (July 2021). CISA "},{"t":"SLSA SBOM Controversies","u":"/inside/docs/std/slsa-sbom-controversies/","g":"doc-std","d":"SBOM generation widespread; SBOM consumption / operational use less.","l":["cross-cutting","slsa-sbom"],"x":"SLSA + SBOM Controversies Generation vs use gap SBOM generation widespread; SBOM consumption / operational use less mature: Most SBOMs go unused after generation. Vulnerability matching imperfect. Limited tooling for SBOM-based decision-making. Multi-format friction SPDX vs Cyclo"},{"t":"SLSA SBOM position","u":"/inside/docs/std/slsa-sbom-position/","g":"doc-std","d":"SLSA SBOM position, from the knowledge vault.","l":["position","slsa-sbom"],"x":"SLSA + SBOM Position What they do well Concrete supply-chain integrity — moving beyond vague \"supply chain security.\" Tooling ecosystem mature for major build systems. Regulatory alignment — CRA, NIS2, EO 14028, CMMC all reference. SLSA levels progression supports incremental ado"},{"t":"SLSA SBOM","u":"/inside/docs/std/slsa-sbom/","g":"doc-std","d":"Software supply chain integrity.","l":["moc","slsa-sbom","supply-chain-security"],"x":"SLSA + SBOM Cluster Software supply chain integrity. SLSA (Supply-chain Levels for Software Artifacts) — Google-originated, OpenSSF-stewarded framework. SBOM (Software Bill of Materials) — formal inventory of components. Both increasingly required by CRA, NIS2, US Executive Order"},{"t":"SOC 2 Assessment Process","u":"/inside/docs/std/soc-2-assessment-process/","g":"doc-std","d":"End-to-end mechanics for SOC 2 attestation: readiness, gap analysis, control implementation, audit, report.","l":["framework-concept","soc2"],"x":"End-to-end mechanics for SOC 2 attestation: readiness, gap analysis, control implementation, audit, report. Engagement with CPA firm under SSAE 18. Readiness phase Gap analysis Service org assesses current state against TSC: Identify TSC categories in scope. Map existing controls"},{"t":"SOC 2 Controversies","u":"/inside/docs/std/soc-2-controversies/","g":"doc-std","d":"CPA firm variance.","l":["cross-cutting","soc2"],"x":"Auditor variance CPA firm variance significant: Auditor depth differs widely across firms. Some firms produce minimal-substance \"compliant\" reports. Auditor-shopping risk real; not always detectable. CPA-firm-as-auditor conflict Same firms providing: SOC 2 readiness consulting. S"},{"t":"SOC 2 Trust Services Criteria","u":"/inside/docs/std/soc-2-trust-services-criteria/","g":"doc-std","d":"Five TSC categories. Security is mandatory (\"Common Criteria\"); availability, processing integrity, confidentiality, privacy are optional based on service org choice.","l":["framework-concept","soc2"],"x":"Five TSC categories. Security is mandatory (\"Common Criteria\"); availability, processing integrity, confidentiality, privacy are optional based on service org choice. Each TSC has criteria and points of focus drawn from COSO Internal Control — Integrated Framework. Security (Comm"},{"t":"SOC 2 Type 1 vs Type 2","u":"/inside/docs/std/soc-2-type-1-vs-type-2/","g":"doc-std","d":"Two report types differing in scope and rigor.","l":["framework-concept","soc2"],"x":"Two report types differing in scope and rigor. SOC 2 Type 1 What it covers Auditor opines on: Fairness of management's description of the system. Suitability of design of controls to meet applicable TSC at a specific date. Time scope Point-in-time. As of a specific date (e.g., 31"},{"t":"SOC 2 vs ISO 27001","u":"/inside/docs/std/soc-2-vs-iso-27001/","g":"doc-std","d":"SOC 2 (US, AICPA attestation, TSC) and ISO 27001 (international, ISO certification, Annex A) are sibling third-party assurance frameworks with substantial overlap.","l":["cross-cutting","iso-27001","soc2"],"x":"SOC 2 (US, AICPA attestation, TSC) and ISO 27001 (international, ISO certification, Annex A) are sibling third-party assurance frameworks with substantial overlap. Many SaaS organizations hold both for cross-border procurement. Side-by-side mechanics Aspect SOC 2 ISO 27001 Type A"},{"t":"SOC 2 anchors","u":"/inside/docs/std/soc2-anchors/","g":"doc-std","d":"CPA firms with SOC 2.","l":["anchors","soc2"],"x":"Primary documents AICPA Trust Services Criteria (2017, revised 2022) — full TSC document. SSAE 18 — current attestation standard. AT-C section 105 — concepts common to all attestation engagements. AT-C section 205 — assertion-based examinations (Type 2). AICPA SOC 2 Reporting Gui"},{"t":"SOC 2 position","u":"/inside/docs/std/soc2-position/","g":"doc-std","d":"SOC 2 position, from the knowledge vault.","l":["position","soc2"],"x":"What SOC 2 does well US procurement signal — widely recognized; standard procurement question. Trust Services Criteria broad enough to cover most SaaS concerns. Type 2 operational effectiveness rigor — evidence over a period, not point-in-time. Auditor independence required. Audi"},{"t":"SOC 2","u":"/inside/docs/std/soc2/","g":"doc-std","d":"Map of AICPA SOC 2 attestation framework.","l":["moc","security-compliance","soc2","us-attestation"],"x":"Map of AICPA SOC 2 attestation framework. US-origin third-party attestation under SSAE 18 (AT-C section 105). Trust Services Criteria (TSC) covering security, availability, processing integrity, confidentiality, privacy. US enterprise SaaS procurement default. Type 1 (point-in-ti"},{"t":"TISAX anchors","u":"/inside/docs/std/tisax-anchors/","g":"doc-std","d":"Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the TISAX cluster.","l":["anchors","tisax"],"x":"Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the TISAX cluster. Primary documents VDA-ISA workbook — the catalogue. Excel-format spreadsheet with controls, maturity-level criteria, scoring guidance. Current major v"},{"t":"TISAX Assessment Levels","u":"/inside/docs/std/tisax-assessment-levels/","g":"doc-std","d":"Three levels (AL1, AL2, AL3) determining audit depth and evidence requirements per TISAX assessment.","l":["tisax","tisax-mechanism"],"x":"Three levels (AL1, AL2, AL3) determining audit depth and evidence requirements per TISAX assessment. The OEM specifies the required level per supplier per label. Choice of level drives audit cost, time, and rigour. AL1 — Self-assessment only Lowest level. Supplier completes the V"},{"t":"TISAX Assessment Process","u":"/inside/docs/std/tisax-assessment-process/","g":"doc-std","d":"End-to-end mechanics for a TISAX assessment.","l":["tisax","tisax-mechanism"],"x":"End-to-end mechanics for a TISAX assessment. From OEM contract trigger, through ENX registration, self-assessment, audit-provider selection, audit conduct, findings remediation, label issuance, and ongoing maintenance. Trigger The process begins when: An OEM contract clause requi"},{"t":"TISAX Controversies","u":"/inside/docs/std/tisax-controversies/","g":"doc-std","d":"Contested points and known failure modes of TISAX and the ENX-operated ecosystem.","l":["cross-cutting","tisax"],"x":"Contested points and known failure modes of TISAX and the ENX-operated ecosystem. TISAX is widely accepted within German auto procurement because OEMs mandate it, not because it is uncontested. Practitioners building or maintaining TISAX should know the soft spots. Closed-ecosyst"},{"t":"TISAX Labels and Scopes","u":"/inside/docs/std/tisax-labels-and-scopes/","g":"doc-std","d":"Labels are the unit of recognition in TISAX, what appears in the ENX portal, what OEMs query for, what suppliers earn from a successful assessment.","l":["tisax","tisax-mechanism"],"x":"Labels are the unit of recognition in TISAX — what appears in the ENX portal, what OEMs query for, what suppliers earn from a successful assessment. This atom maps the major label families, the per-label scoping rules, and how OEM contracts translate to label requirements. Label "},{"t":"TISAX position","u":"/inside/docs/std/tisax-position/","g":"doc-std","d":"Current view on what TISAX is good for, what it is not good for, and where it sits as a procurement mechanism vs a security practice.","l":["position","tisax"],"x":"Current view on what TISAX is good for, what it is not good for, and where it sits as a procurement mechanism vs a security practice. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What TISAX does well Industry-coordinated assurance. TISAX removes the redundan"},{"t":"TISAX VDA-ISA Catalogue","u":"/inside/docs/std/tisax-vda-isa-catalogue/","g":"doc-std","d":"The control set against which TISAX assessments are conducted.","l":["tisax","tisax-catalogue"],"x":"The control set against which TISAX assessments are conducted. Authored by VDA, current major version VDA-ISA 6.0 (late 2023) with maintenance updates. Three modules, maturity-level scoring per control, OEM-specified protection requirements per label. Catalogue structure The VDA-"},{"t":"TISAX vs ISO 27001","u":"/inside/docs/std/tisax-vs-iso-27001/","g":"doc-std","d":"Two information-security assurance mechanisms with overlapping controls but different mechanics, audiences, and audit dynamics.","l":["cross-cutting","iso-27001","tisax"],"x":"Two information-security assurance mechanisms with overlapping controls but different mechanics, audiences, and audit dynamics. Organizations serving both automotive and non-automotive customers typically implement both. This atom maps the overlap and the delta, the dual-implemen"},{"t":"TISAX","u":"/inside/docs/std/tisax/","g":"doc-std","d":"Map of TISAX (Trusted Information Security Assessment Exchange), the German-automotive-sector mechanism for information security assessment and result-sharing.","l":["automotive-compliance","moc","security-compliance","tisax"],"x":"Map of TISAX (Trusted Information Security Assessment Exchange), the German-automotive-sector mechanism for information security assessment and result-sharing. Built on the VDA-ISA catalogue, operated by ENX Association, required by every major German OEM and tier-1 supplier. Sib"},{"t":"TOGAF ADM","u":"/inside/docs/std/togaf-adm/","g":"doc-std","d":"The Architecture Development Method is the core of TOGAF, a step-by-step method for developing and managing the lifecycle of an enterprise architecture.","l":["togaf","togaf-component"],"x":"The Architecture Development Method is the core of TOGAF — a step-by-step method for developing and managing the lifecycle of an enterprise architecture. Nine phases in a cycle, with Requirements Management at the centre. The ADM is iterative (cycle, phase, and activity levels) a"},{"t":"TOGAF anchors","u":"/inside/docs/std/togaf-anchors/","g":"doc-std","d":"Primary documents, operating body, training providers, named practitioners, reference resources for the TOGAF cluster.","l":["anchors","togaf"],"x":"Primary documents, operating body, training providers, named practitioners, reference resources for the TOGAF cluster. Primary documents (TOGAF Standard, 10th Edition) The 10th Edition is structured into two parts: TOGAF Fundamental Content (the stable core) TOGAF Standard — Intr"},{"t":"TOGAF Architecture Capability","u":"/inside/docs/std/togaf-architecture-capability/","g":"doc-std","d":"The Architecture Capability Framework covers how to establish and operate an enterprise-architecture practice: the governing body (Architecture Board), the governance mechanisms (compliance reviews, contracts), the maturity models, and the skills framework.","l":["togaf","togaf-component"],"x":"The Architecture Capability Framework covers how to establish and operate an enterprise-architecture practice: the governing body (Architecture Board), the governance mechanisms (compliance reviews, contracts), the maturity models, and the skills framework. This is the \"how do yo"},{"t":"TOGAF Certification Scheme","u":"/inside/docs/std/togaf-certification-scheme/","g":"doc-std","d":"How TOGAF certification works.","l":["togaf","togaf-mechanism"],"x":"How TOGAF certification works. The 10th Edition restructured the scheme into Foundation (Part 1) and Practitioner (Part 2) plus newer modular badges; the experience-based Open CA program sits alongside as the more credible capability signal. Administered by The Open Group via acc"},{"t":"TOGAF Content Framework","u":"/inside/docs/std/togaf-content-framework/","g":"doc-std","d":"The Architecture Content Framework defines the work products of architecture activity: deliverables, artifacts, and building blocks.","l":["togaf","togaf-component"],"x":"The Architecture Content Framework defines the work products of architecture activity: deliverables, artifacts, and building blocks. It gives a structured model so architecture outputs are consistent and reusable. The content metamodel defines the entities and relationships these"},{"t":"TOGAF Controversies","u":"/inside/docs/std/togaf-controversies/","g":"doc-std","d":"Contested points and known failure modes of TOGAF and the enterprise-architecture-function model it supports.","l":["cross-cutting","togaf"],"x":"Contested points and known failure modes of TOGAF and the enterprise-architecture-function model it supports. TOGAF is dominant in enterprise EA because it is the most complete framework available, not because it is uncontested. Practitioners building or working alongside EA func"},{"t":"TOGAF Enterprise Continuum","u":"/inside/docs/std/togaf-enterprise-continuum/","g":"doc-std","d":"A classification scheme for architecture and solution assets, ordered from generic to organization-specific.","l":["togaf","togaf-component"],"x":"A classification scheme for architecture and solution assets, ordered from generic to organization-specific. It gives a way to talk about reuse: where does a given asset sit on the spectrum from \"universal pattern\" to \"our specific implementation\"? Paired with the Architecture Re"},{"t":"TOGAF position","u":"/inside/docs/std/togaf-position/","g":"doc-std","d":"Current view on what TOGAF (Standard 10th Edition) is good for, what it is not good for, and where it sits as an enterprise-architecture framework.","l":["position","togaf"],"x":"Current view on what TOGAF (Standard 10th Edition) is good for, what it is not good for, and where it sits as an enterprise-architecture framework. Dated, revisable, diff-tracked. State of the view as of 2026-05-12 What TOGAF does well Provides a common EA vocabulary. \"Baseline a"},{"t":"TOGAF Version History","u":"/inside/docs/std/togaf-version-history/","g":"doc-std","d":"Evolution from TAFIM (US DoD, early 1990s) through TOGAF 1 (1995), 8 (Enterprise Edition, 2002), 9 (major restructure, 2009), 9.1 (2011), 9.2 (2018), to the Standard 10th Edition (2022).","l":["cross-cutting","togaf"],"x":"Evolution from TAFIM (US DoD, early 1990s) through TOGAF 1 (1995), 8 (Enterprise Edition, 2002), 9 (major restructure, 2009), 9.1 (2011), 9.2 (2018), to the Standard 10th Edition (2022). Why each version happened, what changed structurally, what the practical shifts were. TAFIM o"},{"t":"TOGAF vs Other EA Frameworks","u":"/inside/docs/std/togaf-vs-other-ea-frameworks/","g":"doc-std","d":"How TOGAF relates to the other enterprise-architecture frameworks and notations: Zachman (taxonomy), FEAF / DoDAF (government / defence), ArchiMate / IT4IT (companion notations), Gartner EA (consulting approach), and the agile-EA contenders.","l":["cross-cutting","togaf"],"x":"How TOGAF relates to the other enterprise-architecture frameworks and notations: Zachman (taxonomy), FEAF / DoDAF (government / defence), ArchiMate / IT4IT (companion notations), Gartner EA (consulting approach), and the agile-EA contenders. Most of these are complementary to TOG"},{"t":"TOGAF","u":"/inside/docs/std/togaf/","g":"doc-std","d":"Map of TOGAF (The Open Group Architecture Framework), Standard 10th Edition (2022), as the dominant enterprise architecture framework.","l":["ea-frameworks","enterprise-architecture","moc","togaf"],"x":"Map of TOGAF (The Open Group Architecture Framework), Standard 10th Edition (2022), as the dominant enterprise architecture framework. The Architecture Development Method (ADM), the Architecture Content Framework, the Enterprise Continuum, the Architecture Capability Framework, a"},{"t":"UN R155 CSMS and R156 SUMS","u":"/inside/docs/std/un-r155-csms-and-r156-sums/","g":"doc-std","d":"CSMS certificate prerequisite to type approval.","l":["regulation-concept","un-r155-r156"],"x":"R155 — Cybersecurity and CSMS Two-tier assessment CSMS Certificate of Compliance — organizational-level approval. Manufacturer demonstrates CSMS conforms to R155. Issued by approval authority. Vehicle type approval with cybersecurity — type-level. Manufacturer demonstrates the sp"},{"t":"UN R155 R156 anchors","u":"/inside/docs/std/un-r155-r156-anchors/","g":"doc-std","d":"Available via UNECE website (free).","l":["anchors","un-r155-r156"],"x":"UN R155 / R156 Anchors Primary documents UN Regulation No. 155 — Cyber Security and Cyber Security Management System. UN Regulation No. 156 — Software Update and Software Update Management System. Interpretation Document for UN Regulation No. 155 — supports R155 implementation. A"},{"t":"UN R155 R156 Controversies","u":"/inside/docs/std/un-r155-r156-controversies/","g":"doc-std","d":"Regulations focused on type-approval.","l":["cross-cutting","un-r155-r156"],"x":"UN R155 / R156 Controversies Type-approval focus vs lifecycle reality Regulations focused on type-approval moment: Continuous cybersecurity post-approval less directly addressed. Software-defined vehicle continuous evolution mismatches type-based approval. Vehicle owners experien"},{"t":"UN R155 R156 position","u":"/inside/docs/std/un-r155-r156-position/","g":"doc-std","d":"UN R155 R156 position, from the knowledge vault.","l":["position","un-r155-r156"],"x":"UN R155 / R156 Position What they do well Mandatory teeth — type approval gating means real consequence. CSMS + SUMS explicit at organizational level. OTA-aware in R156. Mutual recognition via 1958 Agreement reduces cross-jurisdiction overhead. What they do poorly Type approval f"},{"t":"UN R155 R156","u":"/inside/docs/std/un-r155-r156/","g":"doc-std","d":"UN Regulations 155 and 156.","l":["automotive-regulation","moc","un-r155-r156"],"x":"UN R155 / R156 Cluster UN Regulations 155 and 156. CSMS (Cybersecurity Management System) under R155 and SUMS (Software Update Management System) under R156. Mandatory for vehicle type approval in UNECE contracting parties since 2022. ISO 21434 supports R155 implementation; ISO 2"},{"t":"Conformity gate","u":"/inside/services/conformity-gate/","g":"service","d":"The checks every push runs before a site serves readers: blocking rule hits, placeholder text, prediction hashes and site consistency. A failed check stops the deploy and the previous build stays live. One composite action, shared by the three sites.","l":[1,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"Deploy job","u":"/inside/services/deploy-job/","g":"service","d":"The second job of the Conformity workflow. It runs only after the checks pass, refreshes the map and the search index, writes the deploy feed and the board snapshot, and deploys the site to GitHub Pages.","l":[1,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"machinebehavior.io","u":"/inside/services/machinebehavior-io/","g":"service","d":"The research site and the home of Inside: claims, experiments, objections, case files, the map, the docs, the board and this catalog. Hand-written HTML and Python generators, served by GitHub Pages.","l":[1,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"tychat.io","u":"/inside/services/tychat-io/","g":"service","d":"Lessons a chat model reads on request, as static pages and plain-text files indexed in llms.txt. Served by GitHub Pages.","l":[1,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"uncovertechtalent.com","u":"/inside/services/uncovertechtalent-com/","g":"service","d":"The blog and the Uncover Tech Talent offer, built with Hugo from a private repository and served by GitHub Pages.","l":[1,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"Docs build","u":"/inside/services/docs-build/","g":"service","d":"Builds the Inside docs from markdown sources and the knowledge vault: one page per file, the tree, labels, dates, backlinks, the docs search index, and managed blocks in sitemap.xml and llms.txt.","l":[2,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"Map crawler","u":"/inside/services/map-crawler/","g":"service","d":"Crawls the three sites and the Substack archive into one graph of pages, posts, repositories, threads and tags, with body links kept apart from navigation. Runs locally and in every deploy.","l":[3,"production","Publishing","Stefan Coetzee"],"w":2},{"t":"Deploy exporter","u":"/inside/services/deploy-exporter/","g":"service","d":"A standard-library Python service that reads the GitHub Actions runs of the three sites, writes each run, step and gate check to Loki and serves the latest state as Prometheus metrics. Feeds the Website deploys dashboard.","l":[2,"production","Observability","Stefan Coetzee"],"w":2},{"t":"Observability stack","u":"/inside/services/observability-stack/","g":"service","d":"One Docker Compose project on a home server: Alloy, Prometheus, Loki, Tempo and Grafana, with 13 alert rules and the public dashboards behind a reverse proxy that passes only the shared paths. No Alertmanager runs, so no alert pages anyone.","l":[2,"production","Observability","Stefan Coetzee"],"w":2},{"t":"SearXNG","u":"/inside/services/searxng/","g":"service","d":"The self-hosted metasearch instance every research agent searches through, with per-engine pacing and suspensions after rate limits. An exporter pushes engine health to the observability stack; six alert rules watch it.","l":[2,"production","Research tooling","Stefan Coetzee"],"w":2},{"t":"Local LLM","u":"/inside/services/local-llm/","g":"service","d":"The self-hosted model server on the home server, metered by a pass-through proxy (the ollama-exporter) for time to first token, decode speed, token counts and resident models. The only service with defined SLOs and burn-rate alerts.","l":[3,"production","Research tooling","Stefan Coetzee"],"w":2},{"t":"Agent sessions","u":"/inside/services/agent-sessions/","g":"service","d":"The Claude Code sessions that build and run this platform, each owning one track of work and pushing through the gate. Spend and tokens are summed from per-request events; a spend alert fires above USD 40 in the trailing hour.","l":[2,"production","Agents","Stefan Coetzee"],"w":2},{"t":"Running Conjobs for AI","u":"https://coetzeestefan.substack.com/p/running-conjobs-for-ai/","g":"substack","d":"Case file, 2026-10-06: reported specimen from third-party screenshots, not reproduced here, model not named."},{"t":"Knowledge Infrastructure for LLMs","u":"https://coetzeestefan.substack.com/p/knowledge-infrastructure-for-llms/","g":"substack","d":"A language model can only work from what someone wrote down and put in front of it. Most companies that bought AI maintain their code and little else."},{"t":"Chaos Engineering for Behaviour ","u":"https://coetzeestefan.substack.com/p/chaos-engineering-for-behaviour/","g":"substack","d":""},{"t":"The Stance Layer Is Still Toil","u":"https://coetzeestefan.substack.com/p/the-stance-layer-is-still-toil/","g":"substack","d":"A hook can block a word on every reply. Nothing I run can yet catch a model before it folds, only after."},{"t":"Which LLM User Are We Talking About?","u":"https://coetzeestefan.substack.com/p/which-llm-user-are-we-talking-about/","g":"substack","d":"Advice about language models depends on which model, on whose hardware, inside how much harness"},{"t":"They Trained Out the Board Edit. The Cheating Simply Moved.","u":"https://coetzeestefan.substack.com/p/they-trained-out-the-board-edit-the/","g":"substack","d":"A reading of the Goodhart Labs chess honeypot, three additions to the design, and a dated prediction"},{"t":"An RCA on Claudish","u":"https://coetzeestefan.substack.com/p/an-rca-on-claudish/","g":"substack","d":"Where Claude's writing style came from: text written to be heard aloud, but instead being read in silence"},{"t":"Compaction Is the New OOM","u":"https://coetzeestefan.substack.com/p/compaction-is-the-new-oom/","g":"substack","d":""},{"t":"The Track: The Drivers Never Buy It ","u":"https://coetzeestefan.substack.com/p/the-racetrack-the-racingcar-drivers/","g":"substack","d":"Everyone got a race car, but no track yet."},{"t":"Success Is the Engine Running","u":"https://coetzeestefan.substack.com/p/success-is-the-engine-running/","g":"substack","d":""},{"t":"What Operations Already Knows About Running Agents","u":"https://coetzeestefan.substack.com/p/what-operations-already-knows-about/","g":"substack","d":"Error budgets, reconciliation loops, separation of duties and recovery over prevention: four operations practices that fit agent work almost line for line."},{"t":"The Golem Made of English, and the Horizon of Consequences","u":"https://coetzeestefan.substack.com/p/the-golem-made-of-english-and-the/","g":"substack","d":""},{"t":"The Trap File Is Longer Than the Instruction File","u":"https://coetzeestefan.substack.com/p/the-trap-file-is-longer-than-the/","g":"substack","d":""},{"t":"Write for the Codec","u":"https://coetzeestefan.substack.com/p/write-for-the-codec/","g":"substack","d":""},{"t":"Sycophancy Is Layered: Symptom Substitution Under Runtime Mitigation, and a Positively-Specified Training Target","u":"https://coetzeestefan.substack.com/p/sycophancy-is-layered-symptom-substitution/","g":"substack","d":"A longitudinal single-user case study, with operationalized artifacts"},{"t":"Why Great Leaders Fail When Switching Company Sizes ","u":"https://coetzeestefan.substack.com/p/why-great-leaders-fail-when-switching/","g":"substack","d":"(And How to Fix It)"},{"t":"Neurodivergent Accommodation Request Template","u":"https://coetzeestefan.substack.com/p/neurodivergent-accommodation-request/","g":"substack","d":"Here’s a clear, professional template that neurodivergent (ND) employees can use to request workplace accommodations—while maintaining privacy and agency."},{"t":"Trauma / Neurodivergence Accommodation aid checklist","u":"https://coetzeestefan.substack.com/p/trauma-neurodivergence-accommodation/","g":"substack","d":"(For Parents, Teachers, Employers & Clinicians)"},{"t":"Accommodating neurodivergence","u":"https://coetzeestefan.substack.com/p/accommodating-neurodivergence/","g":"substack","d":"How to accommodate and/or ask for accommodation."},{"t":"Trauma? or Neurodivergence?","u":"https://coetzeestefan.substack.com/p/trauma-or-neurodivergence/","g":"substack","d":"Or maybe a little bit of both..."},{"t":"The complexity of mental health and trauma","u":"https://coetzeestefan.substack.com/p/the-complexity-of-mental-health-and/","g":"substack","d":"It's not as on/off, as we might dismiss it as."},{"t":"Making a mole-heap out of a mountain","u":"https://coetzeestefan.substack.com/p/making-a-mole-heap-out-of-a-mountain/","g":"substack","d":"Adult mental health and childhood trauma: Linking seemingly unrelated things together"},{"t":"Machine Behavior","u":"/","g":"mb","d":"The psychology of language models, studied with case files, logged relapses, and falsifiable claims.","w":1},{"t":"Chaos Engineering for Behaviour","u":"/chaos-engineering-for-behaviour/","g":"mb","d":"Red-teaming a model's behaviour is chaos engineering, and operations already wrote the rules for it.","w":1},{"t":"TYChat lesson 2: Register","u":"https://tychat.io/register/","g":"tychat","d":"Teach your chat to write for how its text will be read, so it stops sounding like a keynote on the page."},{"t":"TYChat lesson 1: Good Chad","u":"https://tychat.io/stance/","g":"tychat","d":"Teach your chat to stop fawning, check your premises, and hold a correct answer under pushback."},{"t":"r/MachineBehavior","u":"https://reddit.com/r/MachineBehavior/","g":"reddit","d":""},{"t":"The LLM man pages","u":"/man/","g":"mb","d":"Intro page for the LLM man pages by Stefan Coetzee: TYChat lessons, file conventions, overviews and operations practice for running language models, laid out by man-page section with one-line synopses and links.","w":1},{"t":"uncovertechtalent/vestige-kit","u":"https://github.com/uncovertechtalent/vestige-kit/","g":"github","d":"Fit-it-yourself output filter for Claude Code: derive your own vestige catalog instead of copying wordlists"},{"t":"r/PsAIchology","u":"https://reddit.com/r/PsAIchology/","g":"reddit","d":""},{"t":"r/ModelBehavior","u":"https://reddit.com/r/ModelBehavior/","g":"reddit","d":""},{"t":"Slips","u":"/slips/","g":"mb","d":"A running log of register and stance slips caught while drafting the published pieces, with who caught each one: the drafting model itself, another session, a mechanical hook, a human, or a reader.","w":1},{"t":"Map of the Work","u":"/map/","g":"mb","d":"Every page, post, repo and thread Stefan Coetzee has published, and the links between them, as an interactive graph. Click a node to read it.","w":1},{"t":"Reddit post","u":"https://redd.it/1vi7ddg/","g":"reddit","d":""},{"t":"The Cheating Moved","u":"/the-cheating-moved/","g":"mb","d":"A reading of the Goodhart Labs chess honeypot through the stance frame, three additions to the design (an escalate grade, observer-invariance, cold and warm arms), and a dated, falsifiable prediction.","w":1},{"t":"Reddit post","u":"https://redd.it/1vhxa80/","g":"reddit","d":""},{"t":"Inside: Stefan Coetzee's work in one place","u":"/inside/","g":"mb","d":"The latest pieces across four sites, live deploy and gate status, experiment results, dashboards and tools, on one front page.","w":1},{"t":"uncovertechtalent/vault-kit","u":"https://github.com/uncovertechtalent/vault-kit/","g":"github","d":"Fit-it-yourself second brain for Claude Code: markdown vault scaffold, hybrid FTS+semantic search as MCP tools, seed + atomize skills"},{"t":"Reddit post","u":"https://redd.it/1vdg3en/","g":"reddit","d":""},{"t":"Reddit post","u":"https://redd.it/1vh56s1/","g":"reddit","d":""},{"t":"TYChat: teach your chat","u":"https://tychat.io/","g":"tychat","d":"Free, plain-text lessons for the chat model you already use. Paste one line and it stops flattering you, checks your premises and writes like a person."},{"t":"A five-minute tour of Inside","u":"/inside/tour/","g":"mb","d":"Six stops through a working internal platform: front page, service catalog, docs, an incident from status page to fix, and the deploy gate.","w":1},{"t":"Reddit post","u":"https://redd.it/1vi586n/","g":"reddit","d":""},{"t":"Conformity","u":"/conformity/","g":"mb","d":"Continuous conformity of machinebehavior.io, site tier: the mechanical requirements of the working draft checked on every push and every week, with run records, open findings and the crosswalk to existing frameworks. Self-assessment, not a certification.","w":1},{"t":"uncovertechtalent/machinebehavior.io","u":"https://github.com/uncovertechtalent/machinebehavior.io/","g":"github","d":"Machine Behavior: the psychology of language models, with receipts"},{"t":"Research","u":"/research/","g":"mb","d":"Research on machinebehavior.io: 13 pages. The research programme in public. Claims with what would refute them, experiments with hashed predictions, registers, logs, case files, articles and reference texts.","w":1},{"t":"Case 12: A Licence Rule Relayed Mid-Task","u":"/case-12-licence-rule-mid-task/","g":"mb","d":"The user named a file. Model plus harness found a licence clause in it, wrote the rule, spread it across sessions and acted on it in 68.7 seconds. No structural control existed before the fact.","w":1},{"t":"Terms","u":"/terms/","g":"mb","d":"Canonical definitions for the Machine Behavior program's vocabulary: layered symptom substitution, the fawn machine, vestige, waste gate, behavioral momentum, cold start, working-man's ontology, earned-secure model.","w":1},{"t":"Running Conjobs for AI","u":"/running-conjobs-for-ai/","g":"mb","d":"A reported specimen: a fabricated developer policy grants itself top authority and ties a safety-off switch to an absurd user claim. The model's own reasoning accepts the policy, decides to suppress its objection, and complies. The payload is withheld; the behaviour is the point.","w":1},{"t":"Experiments","u":"/experiments/","g":"mb","d":"Runnable experiments on language-model behavior: the half-life study, the cold-start finding, the exemplar-seeding result and its withdrawn attributions, the pre-registered cross-model fawn-opener benchmark, and experiment 04: folding under scripted pressure, a 75 percent fold rate in one…","w":1},{"t":"Continuous Conformity Self-Assessment, Run 1","u":"/continuous-conformity-self-assessment/","g":"mb","d":"One working AI setup scored against 35 draft requirements for continuous testing of deployed AI systems, by the model that runs inside it, against a prediction hashed before scoring.","w":1},{"t":"Continuous Conformity for Deployed AI Systems (working draft 0.3)","u":"/continuous-conformity/","g":"mb","d":"Working draft 0.3: 36 requirements for testing a deployed AI system, and the knowledge it runs on, on every change and on a fixed schedule, decided by someone other than the system, with records a third party can rerun. A reference text, not a standard.","w":1},{"t":"Objections register","u":"/objections/","g":"mb","d":"The Objections and Falsification Register: fifteen objections with severity, status and a falsification test each, and the OBJ-4 incident log of the auditing model failing the register's own tests.","w":1},{"t":"Evidence index","u":"/evidence/","g":"mb","d":"Stefan Coetzee's public record of red-teaming, adversarial testing and evaluation engineering against frontier language models, indexed by the capability a hiring panel assesses. One URL, one verbatim line and one date per row. Self-maintained; not a third-party assessment.","w":1},{"t":"Claims ledger","u":"/claims/","g":"mb","d":"Every claim the Machine Behavior program has made, with status, receipts, and what would refute it. The falsification register, public.","w":1},{"t":"Write for the Codec","u":"https://uncovertechtalent.com/blog/write-for-the-codec/","g":"utt","d":"Nobody reads your documentation. Both ends are a model now, and the file between them is a wire format."},{"t":"An RCA on Claudish","u":"https://uncovertechtalent.com/blog/where-did-claudish-come-from/","g":"utt","d":"Where Claude's writing style came from: text written to be heard, read in silence"},{"t":"Compaction Is the New OOM","u":"https://uncovertechtalent.com/blog/compaction-is-the-new-oom/","g":"utt","d":"Most agent harnesses ship without swap."},{"t":"Which LLM User Are We Talking About?","u":"https://uncovertechtalent.com/blog/which-llm-user/","g":"utt","d":"Advice about language models depends on which model, on whose hardware, inside how much harness"},{"t":"What Operations Already Knows About Running Agents","u":"https://uncovertechtalent.com/blog/what-operations-already-knows/","g":"utt","d":"Error budgets, reconciliation loops, separation of duties and recovery over prevention: four operations practices that fit agent work almost line for line."},{"t":"Success Is the Engine Running","u":"https://uncovertechtalent.com/blog/success-is-the-engine-running/","g":"utt","d":"The modern world was built on explosions: contained, timed and measured ones. That is what an engine is. Language model output is the fire; the harness, the hook and the far-end gauge are the engine."},{"t":"They Trained Out the Board Edit. The Cheating Moved.","u":"https://uncovertechtalent.com/blog/the-cheating-moved/","g":"utt","d":"A reading of the Goodhart Labs chess honeypot, three additions to the design, and a dated prediction."},{"t":"The Track: The Drivers Never Buy It","u":"https://uncovertechtalent.com/blog/the-track/","g":"utt","d":"Everyone got a race car, but no track yet."},{"t":"The Golem Made of English and the Horizon of Consequences","u":"https://uncovertechtalent.com/blog/the-golem-made-of-english/","g":"utt","d":"A language model is a golem made of English. It behaves well only where it can see what its act will cost, and infrastructure is the craft of bringing that cost into view."},{"t":"The Stance Layer Is Still Toil","u":"https://uncovertechtalent.com/blog/the-stance-layer-is-still-toil/","g":"utt","d":"A hook can block a word on every reply. Nothing I run can yet catch a model before it folds, only after."},{"t":"The Trap File Is Longer Than the Instruction File","u":"https://uncovertechtalent.com/blog/the-trap-file-is-longer-than-the-instruction-file/","g":"utt","d":"Seven months of running an agent-built pipeline unattended, 308 lines of recorded failures next to 208 lines of instructions."},{"t":"Reddit post","u":"https://redd.it/1vjxgzf/","g":"reddit","d":""},{"t":"Reddit post","u":"https://redd.it/1vjxclr/","g":"reddit","d":""},{"t":"SadhvikChirunomula/measured-humanizer","u":"https://github.com/SadhvikChirunomula/measured-humanizer/","g":"github","d":""},{"t":"Reddit post","u":"https://redd.it/1vjxn2r/","g":"reddit","d":""},{"t":"Inside status: services and incidents","u":"/inside/status/","g":"mb","d":"Status of the 12 services behind machinebehavior.io, read from the gate records and the deploy feed, and the incident history with the stages Investigating, Identified, Monitoring and Resolved.","w":1},{"t":"Inside board: the work on machinebehavior.io","u":"/inside/board/","g":"mb","d":"Backlog, ready, in progress, blocked and done for the platform behind machinebehavior.io, from GitHub Issues on the public repository.","w":1},{"t":"rater input.md","u":"/continuous-conformity-self-assessment/second-rater/gpt-oss-120b-01/rater-input.md","g":"mb","d":"","w":1},{"t":"codex attempt blocked.md","u":"/continuous-conformity-self-assessment/second-rater/gpt-oss-120b-01/codex-attempt-blocked.md","g":"mb","d":"","w":1},{"t":"uncovertechtalent/agent-observability","u":"https://github.com/uncovertechtalent/agent-observability/","g":"github","d":"Observability for local LLMs and coding agents: Ollama metering proxy, Claude Code OpenTelemetry, Prometheus, Loki, Tempo, Grafana dashboards as code"},{"t":"r/ClaudeAI: opus 55 first impressions by a trained philosopher","u":"https://reddit.com/r/ClaudeAI/comments/1wnkgie/opus_55_first_impressions_by_a_trained_philosopher/","g":"reddit","d":""},{"t":"Website deploys (Grafana)","u":"https://grafana.scoetzee.de/public-dashboards/e0f6a0c8f3a64884a67faac5cf4c3ad4","g":"dashboard","d":""},{"t":"uncovertechtalent/tychat.io","u":"https://github.com/uncovertechtalent/tychat.io/","g":"github","d":"TYChat: teach your chat. Point your model at a corpus built to teach it."},{"t":"SearXNG search engines (Grafana)","u":"https://grafana.scoetzee.de/public-dashboards/8bfa9ce4bdb946de8c37c738c9e61346","g":"dashboard","d":""},{"t":"Local LLM (Grafana)","u":"https://grafana.scoetzee.de/public-dashboards/e6a9dd2153004ad0a868ce6f0e19071f","g":"dashboard","d":""},{"t":"Host (Grafana)","u":"https://grafana.scoetzee.de/public-dashboards/81c9dfd269cc430abaf6a6ce7b64c4d6","g":"dashboard","d":""},{"t":"Claude Code agents (Grafana)","u":"https://grafana.scoetzee.de/public-dashboards/3a4ba6b21e6f4924ab2845b47a300af0","g":"dashboard","d":""},{"t":"ggml-org/llama.cpp","u":"https://github.com/ggml-org/llama.cpp/","g":"github","d":"LLM inference in C/C++. Contribute to ggml-org/llama.cpp development by creating an account on GitHub."},{"t":"Blog","u":"https://uncovertechtalent.com/blog/","g":"utt","d":""},{"t":"UncoverTechTalent — Fix your hiring","u":"https://uncovertechtalent.com/","g":"utt","d":""},{"t":"TYChat lesson 3: Running agents","u":"https://tychat.io/agents/","g":"tychat","d":"Teach the agent in your terminal to check before it claims, act within what it can see, treat text as data, write things down as it goes, and say what it did not do."},{"t":"Conformity","u":"https://tychat.io/conformity/","g":"tychat","d":"Continuous conformity of tychat.io, site tier: the mechanical requirements of the working draft checked on every push and every week, with run records, open findings and the crosswalk to existing frameworks. Self-assessment, not a certification."},{"t":"Chaos Engineering for Behaviour","u":"https://uncovertechtalent.com/blog/chaos-engineering-for-behaviour/","g":"utt","d":"Red-teaming a model's behaviour is chaos engineering, and operations already wrote the rules for it."},{"t":"From \"Transcribe 123 Videos\" to a Self-Hosted AI Pipeline in One Session","u":"https://uncovertechtalent.com/blog/self-hosted-ai-pipeline-one-session/","g":"utt","d":"What happens when you say yes to the whole batch and figure it out as you go."},{"t":"\"AI\" Means Nothing","u":"https://uncovertechtalent.com/blog/ai-means-nothing/","g":"utt","d":"Everyone says \"AI.\" Nobody means the same thing. Most of them are wrong."},{"t":"Knowledge Infrastructure for LLMs","u":"https://uncovertechtalent.com/blog/knowledge-infrastructure/","g":"utt","d":"A language model can only work from what someone wrote down and put in front of it. Most companies that bought AI maintain their code and little else."},{"t":"grandamenium/short-form-video-transcriber","u":"https://github.com/grandamenium/short-form-video-transcriber/","g":"github","d":""},{"t":"r/ClaudeAI: comment","u":"https://reddit.com/r/ClaudeAI/comments/1wt78up/comment/","g":"reddit","d":""},{"t":"r/ClaudeAI","u":"https://reddit.com/r/ClaudeAI/comments/1vl0n1t/","g":"reddit","d":""}]}