Notes from the workshop.
Practical, opinionated writing on AI agents, chatbots, automation and cloud security. Published by CloudFixies.
Permission-aware agents in the enterprise
An agent that ignores the user’s permissions is a data leak with a friendly UI. Here’s how to build one that respects the tenant.
Action-capable vs answer-only agents
An agent that only answers is a search engine with hallucinations. The point is to complete the task.
Prompt injection in 2026
The attack surface has moved from the chat box to the document store. Here’s what still works, and what doesn’t.
Agent observability — what to log
When the agent does the wrong thing, you have hours (not weeks) to understand why. Log accordingly.
Model-agnostic agents — a realistic approach
Every vendor tells you their SDK locks you in. Here’s how to build so that it doesn’t.
When not to use an agent
Agents are expensive, non-deterministic, and slow. Sometimes a form still wins.
Evaluating an agent before shipping
A 100-example eval set beats a demo, every time. Here’s how we build one.
The real cost of an agent in production
Model tokens are the visible cost. Retrieval, observability, and human triage are the ones that surprise you.
Chatbots that verify identity first
Every serious enterprise chatbot starts the conversation with an auth check — because the whole point is to give privileged answers.
Multi-step approvals in a Teams bot
A request that needs three approvals is not three separate conversations. Here’s how to model it as one.
When a bot should give up
The best signal of a well-designed bot is knowing when it is out of its depth.
Why your bot hallucinates, and what to do
The most common cause of hallucinations in enterprise bots is not the model — it is the retrieval.
Copilot Studio vs a custom bot
Both have their place. The trap is choosing the wrong one for the wrong reason.
Power Automate ALM for grown-ups
Solutions, environments, deployment pipelines. If a citizen developer built it, that is fine — but production still needs discipline.
Idempotent flows are the only flows
If your flow can be retried without breaking, you have a flow. If not, you have a time bomb.
Connector governance that doesn’t suffocate
A DLP policy that blocks everyone from every non-Microsoft connector is a DLP policy that gets bypassed within a week.
When to reach for Logic Apps instead
Power Automate is where citizen developers live. Logic Apps is where the platform team should live. Draw the line clearly.
Error handling in flows — what actually works
The default "run after" pattern is fine until it isn’t. Here is the escalation ladder we use.
Agent-triggered automation
The most interesting automation in 2026 isn’t scheduled — it is invoked by an AI agent on the user’s behalf.
Automating onboarding — actually
Every organisation says they have automated onboarding. Most have a document with 47 manual steps.
Zero-trust in one page
The core idea, without the marketing.
A Conditional Access baseline that survives contact with users
Six policies that catch the common attacks without triggering an internal revolt.
Defender XDR playbooks worth writing
Three playbooks that catch the alerts most likely to be real, without drowning your team in false positives.
Purview for AI workloads
DLP was built for email. Applying it to an AI agent is not a copy-paste job.
No articles match — try a different keyword.