Issue #752

Essential Reading For Engineering Leaders

Friday 18th September issue is presented by WorkOS

AI agents need access to GitHub, Slack, and Google Drive, but handing them user tokens creates credentials that can leak into prompts, logs, and tool calls.

WorkOS Relay keeps each token at WorkOS, attaches it only when an agent makes an approved request, and sends it only to allowlisted hosts.

Your agent completes the task without ever holding the credential.

— James Stanier

tl;dr: “The pitch of this article is that engineering management today in the AI age isn’t about upskilling, it’s actually about rediscovery, and the ramp back to your technical best has never been easier with the tools that are now available. Change can be embraced and it can be fun.”

Management AI CareerGrowth

— Steve Huynh

tl;dr: “Everything important and urgent was, at some earlier point, important and not urgent. The expired certificate was once a mere maintenance task. But because it was deferred, it turned into a 2am page that woke up four teams.”

Management TechDebt

— Maria Paktiti

tl;dr: AI agents need access to GitHub, Slack, and Google Drive, but handing them user tokens creates credentials that can leak into prompts, logs, and tool calls. WorkOS Relay keeps each token at WorkOS, attaches it only when an agent makes an approved request, and sends it only to allowlisted hosts. Your agent completes the task without ever holding the credential.

Promoted by WorkOS

Auth Security Agents

— Bharat Sharma

tl;dr: “AI has made activity proxies like lines of code, commits and PR counts actively misleading. Here is what to measure instead, and a 90-day plan to get there.”

Management AI Metrics

“One of the best ways to influence people is to make them feel important.”

― Roy T. Bennett

— Sean Goedecke

tl;dr: “Models are now smart enough to have meaningful input on your broader goals. If you’re just prompting them with a concrete technical spec, you are committing the same mistake as in the XY problem: asking expert advice without giving the expert the context it needs.”

Communication AI Agents

tl;dr: LegalOn's 200+ engineers ship across multi-region GKE, and their platform team rebuilt the golden path so coding agents count as users of it, not just authors of code. Agents validate changes against real dependencies before a PR merges, and more than half of the infrastructure repo's 300 daily PRs need no human review. Their realization behind the platform: writing code was never the bottleneck.

Promoted by Signadot

Agents DevEx PlatformEngineering

— Will Keleher

tl;dr: “My favorite tool to flush out intermittently failing tests is running the test suite on an hourly cron. The crux is using a commit that has already passed CI on master/main so that you can be sure that every failure represents a true problem of some sort. Once you have a way of discovering and tracking intermittent failures, it’s relatively straightforward to start driving the failure rate down.”

DevEx CodeQuality Testing

— Olaf Alders

tl;dr: “All of the sharp edges we discussed are the result of .git in a linked worktree not being what you first might expect. So if you remember one thing from today, let it be “.git can be a directory or it can be a pointer and which one you get depends on where you are.”

DeepDive Git

— Louise Deason

tl;dr: “Here are nine questions that have served me well. Some of them are diagnostic. Some of them are trapdoors. All of them have, at one point or another, told me something the company did not realise they were telling me.”

InterviewAdvice

Kickoff

Hand-drawn by Manu. View the Null Pointer series.

Security Audit: Skill for multi-phase security audits.

Superpowers: Agentic skills framework & dev methodology.

OpenCodeReview: AI-powered code review CLI tool.

OpenResearch: Local-first workspace for research agents.

WeKnora: OS LLM knowledge platform.

How did you like this issue of Pointer?

1 = Didn't enjoy it all // 5 = Really enjoyed it
1  |  2  |  3  |  4  |  5

Login or Subscribe to participate in polls.