The AppGenie Blog

Controlled AI-assisted delivery, DevSecOps and compliance engineering, written from inside environments where somebody eventually has to answer for the outcome. 90 posts and counting.

You Did Not Write Most of Your Software. Can You List It?

Google publishes two billion lines of its own code, but the number that should worry you is how little of your product you wrote. Vulnerability submissions rose 263 per cent, NIST has stopped enriching all of them, and mean time to exploit is now negative. What an SBOM is, what one actually looks like, and why a filed one is worthless.

DevSecOps, Supply Chain, Compliance · Q3 2026

Time-to-Market Is Not the Same Thing as Quality-to-Market

Microsoft shipped fixes for the better part of a thousand vulnerabilities in a single Patch Tuesday, including two already being exploited. That is not a story about Microsoft. It is what an industrial-scale problem discovery mechanism looks like, and it exposes the fact that we have spent thirty years measuring how fast we ship and never once measuring the quality of what arrived.

DevSecOps, Compliance, AI · Q3 2026

We Stopped Making the Browser Wait for the Backend

Five years of running FTP2SF in production showed us that the Lambda layer did not need to carry every byte. Where the provider supports it the browser now streams directly against a signed, narrowly scoped transfer, while Lambda keeps control of authentication, authorisation and orchestration. Plus what we did with the move from Aura to LWC.

FTP2SF, AWS, Architecture · Q3 2026

Has the Gloss Finally Come Off Salesforce?

Microsoft has shipped an AI tool that reads your Salesforce estate and tells you what to move, change and redesign. That is aimed squarely at the one thing that has always kept customers in place: nobody knows what they have built. A look at the numbers behind the incumbent, the footnotes in the earnings release, and why this fight is different.

Salesforce, Microsoft, Market Commentary · Q3 2026

Who Watches the Watcher? The DevSecOps Dirty Little Secret

Plenty of firms will audit your pipelines and tell you your release process is a liability, while running build pipelines of their own that would not survive the same review. So here are ours with the actual numbers: 21 deployments averaging 82 lines, 29 shared templates, 14 gates that fail the build, and the one that sat written but unwired for weeks.

DevSecOps, Azure DevOps, Engineering Governance · Q3 2026

Stop Merging Permission Sets. Start With a Golden Set.

Merging Salesforce security metadata does not resolve the disagreement between two branches. It just makes the disagreement happen automatically, on the way to production, with nobody watching. Keep an approved Golden Set in its own branch, overwrite the promotion branch before Salesforce sees it, and there is nothing left to merge.

Salesforce, Copado, Release Management · Q3 2026

All Knowledge Is Not the Same

A good AWS reference architecture will find you the passage that mentions Acme. It will not tell you whether three of those documents are about the same Acme, which one is out of date, or that two of them disagree. Finding something is not the same as knowing something, and the gap between them is where the next few years get interesting.

AI Technology, Knowledge Architecture, Evidence · Q3 2026

The 18-Month AI Cliff

Salesforce did not raise margin guidance this year because it is covering token spend. That is the first visible instance of a large, sophisticated customer looking at the invoice and asking whether the frontier model was worth it. Behind it sits a 3 to 5 trillion dollar financing requirement and a lot of buildings about to switch on.

AI Technology, Economics, Infrastructure · Q3 2026

The Knowledge Migration Nobody Is Talking About

Your organisation holds a huge amount of knowledge. That is not the same as your AI being able to consume it. Information survives text extraction while meaning does not, and most retrieval failures are created upstream, at the moment a document became a pile of characters. Why the real transition is documents to knowledge, not documents to AI.

AI Technology, Knowledge Architecture, RAG · Q3 2026

MCP and A2A Are Not Integration

Everyone is wrapping an existing API catalogue in MCP and calling it an agent platform. Anthropic's own figures put a large tool surface at 77K tokens before the model does any work, and tool-selection accuracy drops with it. Integration and agent capability are different design problems, and they should not have the same owner.

AI Technology, Agent Architecture, Integration · Q3 2026
Follow along. New posts are published to RSS, Atom and JSON Feed, so you can read them in whatever you already use rather than remembering to come back here.