//
Search articles, pages, and resources across BaristaLabs.
Start typing to search...

Hands-on guides for approval policies, shadow weeks, agent receipts, and other AI workflow controls.
Resource path
Use this shelf when the AI idea has become specific enough to sketch. These tutorials turn approval policies, security reviews, shadow weeks, rollback paths, and queue designs into artifacts a teammate can inspect before the system acts.
Start here
Build the approval queue before the agentIt shows the core BaristaLabs sequence: proposed action, reviewer evidence, approval decision, receipt, and safe execution boundary.
Turn one workflow into reviewable proposal, evidence, decision, receipt, and rollback fields.
Sketch one approval queueStart with the point where an AI draft becomes a real action: update the CRM, send the email, refund the order, change the customer status. That boundary decides what the queue must show.
Turn the candidate workflow into a written approval policy, a receipt template, and a rollback owner before the agent earns write access.
If the artifact is still theoretical, run a shadow week: let AI produce work beside the current process, compare misses, and decide whether the next permission is earned.
Observed captureA practical way to verify a versioned website change across code, browser behavior, accessibility, metadata, links, and performance before approval.
Run a Node.js fixture that drops the first acknowledgement after a destination write, replays the same request ID, rejects changed parameters, and checks the business-state count.
Constructed diagramPortSwigger generated 30,000 candidate HTTP attack vectors. The useful result came from the evaluator, deterministic proof, authorization boundary, and expert-guided cascade.
Constructed diagramCloudflare Kitesurf uses less CPU and memory but takes longer in vendor tests. Trial one-shot browser jobs and keep stateful work on Chromium.
Constructed diagramA provider failure could look like a completed Microsoft Agent Framework workflow with an empty message. Version 1.17.0 restores the failure state.
Constructed diagramArmature combines observed MCP execution with context supplied by the calling agent and judgments made later. Product and release decisions should keep those sources separate.
Constructed diagramOneCLI's grants migration converts expressible credential access, removes rules it cannot map, and resets one project default. A staged before-and-after access diff shows whether v1.45 is ready to promote.
Constructed diagramNightcrawler makes autonomous mobile penetration testing concrete. Its auto-derived network scope also shows why a device's current subnet cannot define where an AI agent is authorized to act.
Constructed diagramSprocket v0.3.0 documents a path from a bill of materials, pin map, schematic, and assembly notes toward checkout. Design acceptance must come before purchase authorization.

Anthropic's early Cyber Jailbreak Severity proposal gives security teams a useful first question: what attacker capability did the AI output add beyond public tools and information?

Microsoft Flint gives AI agents a compact chart language. Use a chart-intent diff and one-question/three-intents test to inspect fields, denominators, cohorts, and viewer inference before approval.

A mobile Lighthouse score can look mostly healthy while Total Blocking Time says the browser is still too busy to answer a tap. Use a blocking-work receipt before changing the site.

Implementation notes for building AI tools around real business data, handoffs, review queues, and safeguards.

Product notes, service updates, and BaristaLabs news that affect how small teams use AI at work.

AI market news translated into workflow decisions, risk boundaries, and practical next steps for small businesses.

Model concepts explained through thresholds, queues, and error costs that small teams can actually manage.

Plain-language guidance for owners and operators choosing one useful, reviewable AI workflow at a time.