3 yrs IT + 8 yrs software dev | I help small businesses automate operations with AI | Not theory — real systems that save real time & money | Free audit → DM me
3 years in IT. 8 years building software. Helpdesks, networks, scripting setups for hundreds of machines.
I've seen how businesses really run. The manual follow-ups. The hours wasted on things that should take minutes.
Now I help small businesses automate it with AI. Not theory — actual systems that save real time and money.
DM me for a free audit.
Multi-agent architectures look clean on a diagram.
In production, the agent-to-agent handoff is where everything breaks. Wrong context passed, silent failure, no audit trail.
The agents are the easy part. The seams between them are the job.
The approval gate question matters here too. Any automated migration touching live schema or production data needs a human sign-off step before it runs. Batch rewrites of internal tooling, fine. Anything client-facing, you want a review checkpoint logged with a timestamp.
Automated migrations still need a human at the seam.
The code rewrite is the easy part. The risky part is the moment the migrated output touches live data, live clients, or live money.
Anything in that category gets an approval gate and an audit trail. Internal batch work doesn't.
@ardent__dev The skill is shifting from writing code to making good decisions.
Understanding systems, architecture, security, debugging, and most importantly knowing what to build and why.
AI can generate code. The real advantage is knowing whether it generated the right code.
The fix: never sum currency client-side from a paginated API. Pull the aggregate from the database directly, or paginate every request and assert the total page count matches. Tedious. Cheaper than a wrong dashboard.
A database API silently capped results at 1000 rows.
No error. No warning. The revenue total on the dashboard was just quietly short for weeks. Anything that sums money has to paginate fully or aggregate server-side. Silent under-reporting is worse than a crash.
The approval gate question matters here too. Any automated migration touching live schema or production data needs a human sign-off step before it runs. Batch rewrites of internal tooling, fine. Anything client-facing, you want a review checkpoint logged with a timestamp.
Automated migrations still need a human at the seam.
The code rewrite is the easy part. The risky part is the moment the migrated output touches live data, live clients, or live money.
Anything in that category gets an approval gate and an audit trail. Internal batch work doesn't.
Good list. Most of these I learned by shipping them wrong first.
The three that actually bit me in production:
RLS looks airtight until a joined query returns zero rows instead of an error. You stare at an empty screen sure the data's gone. The policy is quietly eating it.
A pay field hidden in the UI was still readable by any user through the API. Hiding it in the interface did nothing. Permissions live in the database or they don't exist.
Rotated a leaked key, closed the incident. The key text was still sitting in old rows, readable by anyone with table access. Revoking and scrubbing are two separate jobs.
The demo never tests these. The first real user does.
Vibe coders are getting sued.
People are shipping apps with real users and skipping the boring stuff that kills them.
A 20+ year dev shared the pre-launch checklist every AI builder needs.
I added what I learned after shipping 60+ apps at the agency.
Don't skip this:
1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives.
2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix.
3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs.
4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture."
5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught.
6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time.
7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes."
8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it.
9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day.
10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods.
11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages.
Build fast. Just don't ship naked.
(full breakdown in my article below)
Rotated a leaked API key. The key text was still sitting in the database rows.
Revoked at the provider. Incident closed. Key still queryable by anyone with read access to that table.
Revoking and scrubbing are two separate jobs. Most runbooks only write down one of them.
Reintroducing myself to the new Twitter algo and anyone seeing my page for the first time in awhile
- I am 22 years old and been running businesses since I was 14 years old.
- As an 8th grader, I was doing Amazon to eBay dropshipping in 2018 making a few hundred bucks per month.
- I started sneaker reselling when I was 16 years old and generated over 100k net profit in high school.
- Lost / scammed out majority of that in a bad deal in 2021/2022.
- Took my remaining funds and restarted and begun Amazon in 2022 and dropped out of college after my first 20k profit month a year later.
- Since then have done over 7M+ in revenue and have 90% of my store currently delegated at 300-400k/mo.
- I recently started a business funding company to help business owners get access to 100k+ in 0% APR capital to scale their businesses.
- I have a programming background and own an AI Agency creating custom softwares and automations with my two cousins who are extremely talented developers with 15 years+ of experience.
- I love playing basketball, pickleball, traveling, and talking business with my friends.
Things for me have progressed massively over the past few years and I will begin documenting my journey on here again.
Drop a follow if you're interested or want to connect🫡
Fastest way to waste an AI build: automate a process you've never watched a human do.
I sit with the client first. Watch the actual workflow. The boring part nobody documents. That's where the real system lives.
Built the events booking assistant with two moving parts.
Claude handles the conversation - qualifies the lead, asks the right questions, sounds like a human. The structured pipeline handles the storage - saves to the DB, fires the email. Neither does the other's job. That's why it works.
How to replace a bloated CRM a realtor actually hates:
Build mobile-first, not desktop-first
Kill every feature they don't use in week one
Make the pipeline visible in two taps
Never lose a note
Done this once. The tech was the easy part. Knowing what to cut wasn't.