The book

Operating a Fleet of Coding Agents

Building verifiable trust around workloads that write your code.

An agent that can edit files, run shell commands, and call APIs is not an assistant. It is an untrusted workload with production access, and "be careful" is not a control. You move trust out of the model and into the environment: instruction files, guards, evals, a knowledge substrate. But the environment is built from artifacts that go stale, drift, and lie exactly the way the agent does.

So the operator's real artifact is one turn deeper: the verification loop that keeps the environment honest, the discipline of turning the same suspicion you aimed at the agent back onto every control you built to contain it. Fourteen chapters, system by system, bypass by reproduced bypass, with the work shown so you can argue with it.

Fourteen chapters, read in order. New here? The essay series is the shorter way in.

Contents

  1. Preface 3 min
  2. Part I · The Reframe and the Loop
  3. The Untrusted Workload 10 min
  4. The Map and the Territory 11 min
  5. The Guard That Enumerates Loses 15 min
  6. The Dossier Was Already Wrong 10 min
  7. The Measurement That Lied 12 min
  8. The Flywheel 14 min
  9. Part II · The Fleet
  10. The Control Plane 10 min
  11. Two Harnesses, One Floor 8 min
  12. Peers, Not Owners 10 min
  13. The Knowledge Substrate 7 min
  14. Context Is the Budget 8 min
  15. Part III · In Public
  16. The Auditor Audits Itself 11 min
  17. Proof You Can Hand a Stranger 10 min
  18. The Operator's Artifact 10 min
  19. Afterword 3 min
  20. Colophon 2 min

The series essays map to the book: Ulysses Pacts in Software deepens Chapter 2, Sermons vs. Instruments deepens Chapter 3, The Coordination Platform You Don't Need deepens Chapter 9, The Subtraction Dividend deepens Chapter 10, and We Rigged Our Own Benchmark deepens Chapter 12.

Want the next one? New work (the book, the essays, the field notes) lands in the feed. Point your reader there to follow along.