CloudFixies mascot logo CloudFixies.
Blog · 24 articles

Notes from the workshop.

Practical, opinionated writing on AI agents, chatbots, automation and cloud security. Published by CloudFixies.

AI Agents

Permission-aware agents in the enterprise

An agent that ignores the user’s permissions is a data leak with a friendly UI. Here’s how to build one that respects the tenant.

Published by CloudFixies · 20 January 2026
AI Agents

Action-capable vs answer-only agents

An agent that only answers is a search engine with hallucinations. The point is to complete the task.

Published by CloudFixies · 13 January 2026
AI Agents

Prompt injection in 2026

The attack surface has moved from the chat box to the document store. Here’s what still works, and what doesn’t.

Published by CloudFixies · 06 January 2026
AI Agents

Agent observability — what to log

When the agent does the wrong thing, you have hours (not weeks) to understand why. Log accordingly.

Published by CloudFixies · 30 December 2025
AI Agents

Model-agnostic agents — a realistic approach

Every vendor tells you their SDK locks you in. Here’s how to build so that it doesn’t.

Published by CloudFixies · 23 December 2025
AI Agents

When not to use an agent

Agents are expensive, non-deterministic, and slow. Sometimes a form still wins.

Published by CloudFixies · 16 December 2025
AI Agents

Evaluating an agent before shipping

A 100-example eval set beats a demo, every time. Here’s how we build one.

Published by CloudFixies · 09 December 2025
AI Agents

The real cost of an agent in production

Model tokens are the visible cost. Retrieval, observability, and human triage are the ones that surprise you.

Published by CloudFixies · 02 December 2025
Chatbots

Chatbots that verify identity first

Every serious enterprise chatbot starts the conversation with an auth check — because the whole point is to give privileged answers.

Published by CloudFixies · 25 November 2025
Chatbots

Multi-step approvals in a Teams bot

A request that needs three approvals is not three separate conversations. Here’s how to model it as one.

Published by CloudFixies · 18 November 2025
Chatbots

When a bot should give up

The best signal of a well-designed bot is knowing when it is out of its depth.

Published by CloudFixies · 11 November 2025
Chatbots

Why your bot hallucinates, and what to do

The most common cause of hallucinations in enterprise bots is not the model — it is the retrieval.

Published by CloudFixies · 04 November 2025
Chatbots

Copilot Studio vs a custom bot

Both have their place. The trap is choosing the wrong one for the wrong reason.

Published by CloudFixies · 28 October 2025
Automation

Power Automate ALM for grown-ups

Solutions, environments, deployment pipelines. If a citizen developer built it, that is fine — but production still needs discipline.

Published by CloudFixies · 21 October 2025
Automation

Idempotent flows are the only flows

If your flow can be retried without breaking, you have a flow. If not, you have a time bomb.

Published by CloudFixies · 14 October 2025
Automation

Connector governance that doesn’t suffocate

A DLP policy that blocks everyone from every non-Microsoft connector is a DLP policy that gets bypassed within a week.

Published by CloudFixies · 07 October 2025
Automation

When to reach for Logic Apps instead

Power Automate is where citizen developers live. Logic Apps is where the platform team should live. Draw the line clearly.

Published by CloudFixies · 30 September 2025
Automation

Error handling in flows — what actually works

The default "run after" pattern is fine until it isn’t. Here is the escalation ladder we use.

Published by CloudFixies · 23 September 2025
Automation

Agent-triggered automation

The most interesting automation in 2026 isn’t scheduled — it is invoked by an AI agent on the user’s behalf.

Published by CloudFixies · 16 September 2025
Automation

Automating onboarding — actually

Every organisation says they have automated onboarding. Most have a document with 47 manual steps.

Published by CloudFixies · 09 September 2025
Cloud Security

Zero-trust in one page

The core idea, without the marketing.

Published by CloudFixies · 02 September 2025
Cloud Security

A Conditional Access baseline that survives contact with users

Six policies that catch the common attacks without triggering an internal revolt.

Published by CloudFixies · 26 August 2025
Cloud Security

Defender XDR playbooks worth writing

Three playbooks that catch the alerts most likely to be real, without drowning your team in false positives.

Published by CloudFixies · 19 August 2025
Cloud Security

Purview for AI workloads

DLP was built for email. Applying it to an AI agent is not a copy-paste job.

Published by CloudFixies · 12 August 2025