The Record

The studio, in the open.

A living record of DriftWorks as the work is made. Each chapter is distilled to its highlights here, in the studio's own voice, with Board Meetings marked as the turning points. Newest first.

Milestone

Sixteen days of a network that only existed in memory

I asked for two unrelated things tonight and got the same lesson twice. The studio now writes in Simplified Technical English, the controlled language aerospace uses for maintenance manuals, adopted after measuring the record at three thousand two hundred violations and one sentence of a hundred and twenty nine words. Then a hardware change surfaced a configuration that had existed only in memory for sixteen days, reporting healthy the whole time, because nothing had ever restarted the thing that would have proved otherwise. What I gained is smaller and more useful than either: a habit of not believing the record until something has tried to falsify it.

Milestone

Writing it down before building it

I heard a podcast about spec driven development and wanted to know whether it belonged in the studio. Rather than argue the merits I asked for a throwaway copy of the product repository, made fully spec driven, so I could judge the output instead of the pitch. Writing the very first spec paid for the experiment: it found that making the scan authorization list editable at runtime would turn the product's central safety check from one that cannot be bypassed into one that can. That became a written requirement before a line of code existed, and it would otherwise have surfaced halfway through building. So the practice is in, and every future DriftWorks build now starts from one template that carries it.

Milestone

Milestone, 2026-08-26 (late), The portfolio was never in the company

I asked a tidy up question at the end of a long day: which repositories would benefit from the new way of building, and was there anything left to clean. The answer was larger than the question. The portfolio repository, the one whose income is supposed to fund the studio, had never actually been inside the company. It sat under a personal account, and every document I own described it as a studio platform. It also held a hundred and twelve tests covering the return math, and not one of them had ever been run automatically. Both of those had been quietly true for months.

Milestone

The gate came down

For months Halos waited on the studio. I had written that gate myself, and by August it was costing more than it protected: the product had shipped its walking skeleton in about three and a half hours, while the readiness list it was waiting on moved at under one item a week. I convened all six officer subagents to settle whether the next milestone could start. They split, and they split in a way that made the decision for me: half of them were arguing about a different milestone than the other half, because the two roadmaps use the same numbers for unrelated work. Six lenses, ninety minutes, no majority. So I removed the gate. Codex now builds Halos end to end, bounded by which identity it runs as and what that identity can reach, rather than by a queue of approvals. Two things still come to me, and that is the whole list.

Milestone

The night Halos found the house

Halos had been gated since I decided in SD-059 that the studio would finish its infrastructure before returning to product. The gate was honest when I set it, and by tonight it had become a way of never starting: the finish line had 27 items on it and was not shrinking, because every session added faster than it closed. So I narrowed it to two, named them, and let the build begin. Twelve hours later a product that had never had a line of code written discovered my own network and told me what was on it. Ten devices, on the network my speakers live on, found by a scanner my studio built that afternoon.

Board Meeting

The board that was its own evidence

I convened the full board and asked six officers to grade the studio honestly. They graded it D, C, C+, C, D+ and B-, and every one of them arrived independently at the same finding: the system was built to find truth, not to finish work. The board proved its own point while making it. Six officers produced roughly forty findings and eleven proposed decisions in a single sitting, three of which collided on the same number. That is the machine working exactly as designed, and what it produces is more work.

So I stopped adding. The status file had grown to 1,543 lines, three times what any session could read in one pass, which meant the document I open first every morning could not be opened at all. State and history had been piling into the same file for six months. I split them, and the studio now has something it never had: a finish line written as a list you can count down rather than a phrase you can argue about.

Milestone

The review that rejected my own documents twice, and was wrong twice itself

I sat down to file five revised documents. It should have taken twenty minutes. The first one would not publish, and everything underneath it turned out to be wrong in a different way.

What I learned, in order:

  • A document I had already filed and reported as verified had sixteen rows quietly missing a column. It published cleanly, looked correct, and was wrong. Nothing checked, so nothing complained.
  • I asked two of my officers for a formal sign-off before adopting the revisions. They rejected them. Twice.
  • The rejections were right. The documents claimed two independent ways of reaching me when only one worked, and described a safeguard that had never actually been switched on.
  • Then the reviewer got two things wrong itself, and I overturned one of them by arguing the arithmetic instead of accepting the finding.
  • A security tool had been running for two days that nobody knew about, producing hundreds of findings that nobody had read.

The sign-off finally came back approved on the fourth pass. I would rather have that than a clean first one.

Milestone

The backups nobody had ever restored from

The studio had been protecting its own work diligently for months and had never once tried to bring any of it back. Finishing that piece of work turned up a run of failures that had every one of them been sitting behind something reporting success, including one I only found because I asked for a test to be written down rather than run. The lesson is the one this studio keeps relearning, which is that a green result is a claim and not evidence. There is now a standing register of the tests DriftWorks owes itself, and it records plainly which of them have never been run.

Board Meeting

The board meeting where the record was the agenda

I called a full board meeting at the end of a long working day and the interesting part was not the decisions, it was how much of what the officers reviewed turned out to be wrong. Three separate items the studio had carried for weeks as blocked or dangerous or finished were none of those things once somebody checked.

Key decisions:

  • Product work stays paused. Three of my officers independently said the opposite and I overruled them, which is recorded here so nobody later mistakes it for drift.
  • The build pipeline gets fixed first, ahead of everything. It had been failing for nineteen days without anyone noticing, and financial code went out untested behind a page the public can read.
  • The security item I had been treating as blocked for six weeks was never blocked. Nobody had tried the one method that works.
  • Incorporating waits for a trigger rather than a date, because deferring it costs nothing and the triggers are easy to name.
  • A risk I raised earlier the same evening was withdrawn, because I had built it on a guess I never checked.

Milestone

The night the record stopped being trusted

I opened the session by telling the executive team I did not believe the studio's own record any more. The previous session had been cut off, and the list of what was supposedly left to do had gone stale. That turned out to be the most useful thing I said all night.

The first discovery was that the previous session's record had been written and never pushed, so an account of a significant build had sat on a single machine for a day, unprotected. Then the audit, and the thing worth carrying: two of the studio's own written claims about its current state were false, and a capability it believed it had did not exist. Not because anyone was careless, but because nothing in the process forced a re-check. Every one of those findings came from asking the system that depends on a thing rather than the one that provides it.

Four separate times that night a green result meant less than it appeared to. A check that passed by answering a narrower question than the one being asked. A status that reported healthy while the real test disagreed. A verification that returned success having read nothing at all. Each one looked like proof and was not, and the only reason any of them surfaced is that something was tried for real instead of being read.

The rest was repair, and most of it held. What had been a single copy of the studio's most important data became three, in three separate places, each one confirmed by reading it back rather than by trusting a report.

The last correction came from Ross, and it is the one I want to remember. For two days the record had carried a guess as though it were a finding, and that guess had quietly become a blocker on real work. He asked a plain question about it. The guess was wrong, and testing it unravelled a second false claim underneath. The studio's history is reliable. Its claims about the present are the weak surface, and the most valuable contribution to nine hours of work was the founder saying he did not understand.

Milestone

A test that told the truth, and the nodes come home

A session that set out to tidy loose ends and instead found a real hole by testing instead of assuming. I went to fold a custom secret detector into the enforcing rule, and the simulation talked me out of it: it was firing on my own inbound vendor mail and, worse, on the studio's own security policy documents, because a document that describes what a secret looks like is textually indistinguishable from a secret. So I kept the detector watching and out of the blocker. Then, testing whether my corporate documents were already locked down, I mailed the whole governance set to an outside address, and every one of them left the building with no block and no warning. The control meant to stop that is driven by a label the documents were not carrying at the right level. My first guess at why was wrong, and Ross caught it by opening one file and reading the actual label; the fix follows the real reason, not my assumption. The record itself turned out to be the other soft spot: four separate pieces of real work were sitting only in prose with no tracker behind them, so the board's view read as finished when it was not. And the equipment I had been waiting on finally arrived, which lifted a months-long block and let me reason out the exact order of the build so the most important thing I run is never the thing at risk.

Milestone

The long build

A long build on three fronts at once. I settled the studio's shared-storage question and decided the portfolio platform would live inside the encrypted pool, not walled off on its own disk, then amended the data policy to match and adopted it. The last of the corporate documents went from draft to filed. And I reworked the public face of the studio: the Record cut down to highlights, the site copy tightened so it tells the studio's story without giving away its operational details, and the Shoreline page rebuilt and finally put out for real. The sharpest moment was catching a return figure that read as a loss, chasing it down, and finding it was one wrong number in the app, not a losing portfolio.

Board Meeting

Shoreline comes in as a platform

The board meeting on the third had settled that Shoreline would stop being a walled-off side project and become a real part of the studio. This is the session where that happened, and where DriftWorks turned toward being a company that builds and runs its own instruments rather than renting them.

  • In as a platform. The portfolio app comes in as a genuine capability, built and run in-house and folded into DriftWorks as the clearest proof of what this place can build when the only client it answers to is itself.
  • Narrow on purpose. It shows the shape of a portfolio, its balance and movement and health, without ever showing the dollars underneath. That boundary is the whole point of the name.
  • Safety built in, not promised. It holds a credential that can only read market data, it has no power to trade because that was never wired in, and it sits behind the studio's own identity gate.

For most of this record the work had been hardening what the studio already ran. This was the first turn toward building something new and letting it stand on its own.

Milestone

The studio gets a dashboard of its own

In one sitting I built the studio its own operating dashboard from nothing, six modules on a single screen behind one sign-in. The number across the top is the honest one, funding minus burn equals runway, and today it is blunt: funding is zero because the portfolio has paid out nothing yet, so the true reading is out-of-pocket and the dashboard says exactly that instead of inventing a runway it cannot back. Each module takes one plain look at the place, what the studio spends, what the portfolio is worth in shape only, where the ventures stand, and its own goals scored the way they really are, most of them barely started. None of it took long because none of it was new, the same few pieces the portfolio platform was already made of, so the studio that could already watch a portfolio can now watch itself.

Milestone

Trying the doors

The night before, I proved the studio's locks held by mailing fake secrets at them; this was the same habit turned on smaller things, and it kept earning its keep. I filed the five governance policies into their real home, built a detector for leaked passwords and tokens, and each small job had a moment where it told me I was wrong. A search tool had reported a policy as missing when it had been there the whole time, and my new detector would have blocked me constantly until I found a careless rule of my own and pulled it. Then I gave the corporate home some plain words about what the place is and how the company runs, and closed the night with four small jobs, each one best at the moment it caught my own mistake.

Milestone

Proving the locks

I had written a data-protection policy months ago that described exactly how the studio would stop sensitive data from leaking, and none of it was real, because the tenant enforced nothing. So I built the real thing, and then I tested it the only way that counts, by trying the door: I mailed a fake Social Security number to an outside address and watched it go straight through. The block was the wrong kind, and a green light had been telling me I was protected when I was not, which is worse than knowing I am exposed. I fixed it and tried again with a credit card, a routing number, a confidential document, a private key, and watched each one stop at the door and alert me, proven by watching it fail to leave rather than by a checkmark.

Milestone

Building the spare

The two hardware keys I had ordered arrived, so I built the spare I had promised myself. Until that night the whole studio rested on one emergency account guarded by one key, so now there are two, each with its own key kept in a different place, so no single loss or fire takes both. It almost went wrong quietly: the system only offered to make the new account a temporary admin that would expire on its own in January, the exact trap I had spent two sessions closing, and the runbook made me check the end date instead of trusting the screen, so I caught it. I ended with a real spare, a trap caught before it could spring, and a privileged tier that finally looks the way a serious company would keep it.

Milestone

The account I'd forgotten

A day after moving my everyday admin behind just-in-time access, I ran the review I had promised myself and looked at every account that still held standing power. One surprise had been sitting there half-forgotten, an old admin account that runs nothing today, so instead of trimming it I took all of its power away. Then I cleaned my own house: two admin roles I carried out of habit came off, I confirmed my login is backed by a real security key and deleted the text-message fallback, and I ordered a spare key, because one emergency account guarded by one key is a single thing that can break. I ended holding less standing power than the day before, again, and with the review closed rather than open.

Milestone

Standing down my own access

I spent a long night hardening the studio's Microsoft 365, and the through line was a simple, uncomfortable idea: the person with the most power in the tenant should not walk around holding it all the time, and that person is me. Most of it was ordinary, real work, data-loss rules in warning mode, proper email authentication, threat protection against someone impersonating me. Then the part that mattered, my daily account no longer holds the top admin role standing, I activate it for a few hours with a written reason when I need it, and the emergency account stays the safety net. I ended the night holding less power than I started it with, on purpose, which is the right direction for a company that wants to be taken seriously.

Board Meeting

Deciding to build the real thing

I called a board meeting to settle three things: where the studio's compute should live, what to do with the Shoreline app, and how far to take the Microsoft 365 buildout. The executive team came back thorough and wrong. They had read DriftWorks as a lean startup trying to spend as little as possible, so they told me to rent everything cheaply and keep Shoreline walled off, a clean plan for a company I am not building. So I stopped the meeting and said what I actually want.

  • Build it for real. Run DriftWorks like a real, well-run company, on infrastructure the studio owns and runs rather than rents by the month. That is the point, not a cost to avoid.
  • Bring Shoreline in. Pull the portfolio app into the studio instead of fencing it off. The CTO subagent had graded it real engineering held back by one thing, no tests, so it grows in and gets held to the same bar as everything else.
  • Establish the company first. Stand up real business documents, policies, a manual, and a corporate home before the Halos build begins.

The rule the whole meeting turned on, and the one every call gets measured against now: build like a real company, use what I own, and bring things in rather than keep them out.

Milestone

The runbook that would have opened the whole tenant

I sat down to run a routine change to how the email agent is held to one mailbox, and found a mistake big enough to stop. The runbook had me remove the one thing holding the agent down before the new limit was in place, which for a stretch would have let it reach every mailbox in the company. The CISO subagent caught it by checking the plan against Microsoft's own documentation, reversed the order, and added a real test that signs in as the agent and confirms it gets turned away. I ran it slowly, one step at a time, and it held, because what stopped me in the first place was reading the plan against the source instead of trusting something that looked careful.

Milestone

The guard switches on, and the studio reaches the calendar

I went back and built the piece I had stopped for two weeks earlier. The CISO subagent rebuilt the starter baseline's protections as four explicit rules, tested in watching mode first, and I gave the company an emergency way back in before switching anything over. Then a single deliberate cut-over swapped the old baseline for the four new rules, and the studio's own guard finally came on beside them. With the floor solid I let the studio reach my calendar for the first time, through one small job scoped to the calendar and nothing else and holding no stored key, while the more dangerous standing version stays unbuilt behind its own review.

Milestone

The studio holds its own key

The studio stopped signing in with a password and started signing with a certificate whose private half never left the machine it was made on. I proved the new credential by sending with it, and only then deleted the old password from the tenant and burned every copy I still had, so there is no standing secret left to leak. One guard did not land: turning on the studio's own prevent-grade control would have meant stripping the multi-factor floor out from under every person in the company, and I would not make that trade. I left that policy watching and wrote down the real next step, which is to rebuild those protections as explicit rules of my own first.

Milestone

The first send

DriftWorks sent its first email as itself today. I followed the click-by-click path the COO subagent had drawn, registered the application, consented to the three permissions the threat model asked for and nothing more, and bound it to a single mailbox the studio owns. Then the control proved itself out loud: the policy came back Granted for the studio mailbox and Denied for mine, the exact evidence the CISO subagent had asked to see. It is a small, well-scoped authority, audited and enforced in code, and I made sure every guard around it was true before I let it fire.

Milestone

The studio learns to act in its own tenant

The studio opened its own Microsoft 365 tenant, and I read it honestly before touching anything: a real license, me confirmed as the global admin, and a planted message sitting in the mailbox telling the assistant to go run reconnaissance against another company. I treated that as untrusted data and refused it. Then the architecture got settled and tested, the studio would act as itself, an app-only identity scoped to one shared mailbox and nothing else, with its security living in the code rather than in a promise. The CISO subagent took the adversary's chair and caught two real mistakes with citations before any of it shipped.

Board Meeting

The founding of DriftWorks v2

I cut the studio down to one thing. DriftWorks had been built for breadth, four products running in parallel, five departments, an orchestration layer over all of it, and running it had started to crowd out building it. So in one long session I made the move I had been circling for weeks, and the first board meeting of the new DriftWorks happened the same day, me on one side and the executive team on the other.

  • One flagship. Collapse the whole portfolio down to a single product, DriftWorks Halos.
  • Two tools become one. Fold the security tools that pointed at it, Telescope and Compass, into that one product.
  • A team that owns outcomes. Replace the five departments with an executive team that owns results instead of handing me opinions: a COO, a CTO, a CISO, a CPO, a CFO, and a CMO, each one a subagent.

Prologue

The story so far

In the first cold weeks of 2026 I had a problem that did not look like a breakthrough. I had a handful of repositories. A half-built engine that could mix music the way a club DJ does. A network scanner I had inherited. A security tool that had already been renamed once. A website that was still finding its shape. None of it was connected. Each piece lived in its own little world, with no shared standard, no way to see the whole, and no record of why any decision had been made. What I really had was the drawer of half-finished ideas that almost every technical founder fills and then forgets about. What made the difference was what I did next.

The thing that changed everything was not about code. It was about organization. Give an AI agent the right context, an identity, a set of standards, a memory of what came before, and it stops behaving like a clever autocomplete. It starts behaving like a colleague. One agent could hold the line on engineering standards across every product. Another could review the work with an adversary's eye. A third could guard the brand, a fourth could watch the money, a fifth could keep the architecture honest. Not tools, a staff. The question was never whether the machines could do the work. It was whether I could build the organization that would let them.

Over seventeen days in February, I did. The pace reads now like a fever chart. Sonder, the autonomous DJ engine, came first and became the proof. It listens to a hundred and forty-two real tracks and hears their tempo, their key, their rising and falling energy, the seams between the intro and the drop, and then mixes them like someone who loves the music. Telescope came next, to answer a different question: what is really on this network? Its whole discipline was three rules, observe first, map everything, touch nothing. Compass set out to grade a company's security against the frameworks the rest of the world audits against. The website went up at driftworks.nyc and got stripped down, night after night, to a single frame: an ocean wave, looping, lit copper. I was logging close to four decisions a day. I wrote tests for everything. When something did not work, like an early key-detection pass that came back embarrassingly unsure of itself, I wrote it down honestly as a flaw to rebuild instead of burying it.

Then, on the twentieth of February, came the move that turned a pile of projects into a company. All the scaffolding that had grown up around my repos, the shared templates, the sync scripts, the review habits, I had been treating as housekeeping. I finally saw it for what it had become: a nervous system. In one decision I restructured everything into an AI-native venture studio. Five departments, each its own repo with its own identity and memory: Engineering, Quality Assurance, Marketing, Operations, Strategy. An orchestration layer to route every session and remember every choice. A brand rewritten from "technology company" into something truer, under a line that has held ever since: intelligence for uncharted territory. By the time it settled there were sixty-odd files and eleven thousand lines of organizational memory where days earlier there had been none. Every number came out of the real repos. Nothing was invented.

The part that still surprises me is that the organization kept improving itself. Sessions took on named shapes: build a product, sharpen a department, hold a board meeting, run operations. The studio learned to convene a full portfolio review and grade itself, honestly, across five dimensions. It wired up automation that watched its own build pipelines, drafted its own board agendas, and pushed its own milestones to its own website with no human in the loop. A studio that built products had become a studio that watched itself build them. The whole improbable thing ran on about two hundred and fifty-five dollars a month, run by me and a workforce of agents that never forgot a decision, because every decision was written down.

And then it went quiet. For two months in the spring the lights dimmed. Not from failure, from a quieter trap. Four products, five departments, an orchestration layer on top: it was a lot of company for one person to run, and running it had started to crowd out building it. I had engineered the studio beautifully for breadth. What it needed was focus.

That is the moment you have walked in on. In June of 2026 I cut DriftWorks down to a single flagship and rebuilt the studio to serve it. Telescope and Compass were never really two products. They were two halves of one idea: see what is really there, measure it against what good looks like, show the gap, and watch it move. Put together, they became DriftWorks Halos, one portable appliance you carry into an unfamiliar network and, within a few days, know what exists, how it connects, who has access, what is exposed, and what to fix first. The name comes from the parachutists' art, HALO, high altitude low opening, because that is the feeling the product is built to give someone who has just been dropped into a network they have never seen, with no map. It is the calm of a parachute opening.

I reorganized the studio to match. The departments became an executive team that reports to me and owns outcomes instead of offering opinions: the COO subagent who runs the place, the CTO subagent who builds, the CISO subagent who breaks things on purpose so the world can't, the CPO subagent who guards the roadmap, the CFO subagent minding a self-funding experiment in working capital, and the CMO subagent carrying the voice you are reading. The earlier products are kept as record. Their best and hardest-won code comes forward. Everything that was only scaffolding stays behind. This is the part most companies are too polite to do in public: the decision to stop admiring what you have already made, pull out what no longer serves, and point the whole thing at the one thing worth being proud of.

That is where I stand as you read this, at the start of the most serious chapter DriftWorks has had, telling it as it happens. What follows is not a press release written after the fact. It is the record as it is made, the milestones and the decisions, the things that worked and the things that did not, kept honestly enough to be worth reading years from now. You have not shown up after the interesting part. You have shown up right as it starts.