Sign in

Dev Verma

@obto.co
123 followers 306 following 480 posts

Problem solver & builder. Building OBTO — describe an app, get a deployed one: data, APIs, payments & security included. Also Glass Box. Here to build in public and trade notes on AI. obto.co sofos.obto.co (100K MAU) mcp.obto.co

PostsRepliesMedia
Dev Verma @obto.co · 03/10/2026
Wrote down what I think happens to business software once it runs inside the chat window people already have open. The screen becomes an output format. What customers pay for is the data, the rules and the receipts. medium.com/@divyansh.ve...
000
Dev Verma @obto.co · 21/09/2026
I never trust an incident just because it says Done. In OBTO, I look for the handoff: who owned it, whether the SLA held, what changed, and what the next person can reuse. Closing the record is easy. Closing the loop is the real work.
010
Dev Verma @obto.co · 19/09/2026
laya.convaiinnovations.com
laya.convaiinnovations.com
Laya — 33ms Multilingual System 1 Decision Engine
Evaluates typed decisions (choice, score, noul) over 100+ languages in a single forward pass with calibrated probabilities. Outperforms TypeSafe Jev.
020
Reposted by Dev Verma
WIRED @wired.com · 19/09/2026
You can’t always tell if someone is recording you with their smart glasses, but your phone can help.
buff.ly
ZuckOff Is a Free App That Sees Meta Glasses Before They See You
You can’t always tell if someone is recording you with their smart glasses, but your phone can help.
724991
Dev Verma @obto.co · 19/09/2026
Big context windows are useful, but I don't want every specialist carrying the whole project. In OBTO, a sub-agent starts fresh with one task and a narrowed read-only toolset, then returns a receipt. Sometimes less context is the safety feature.
010
Dev Verma @obto.co · 18/09/2026
False is not missing. Sounds pedantic until an agent reads a deliberate off-switch as “no setting” and supplies a default. Our MCP property tool returns both the value and whether it was found. I want that distinction visible before the agent decides what to do next.
010
Dev Verma @obto.co · 18/09/2026
I don't need three agents editing the same change to get value from a team. Our sub-agent tool gives side jobs read-only access and separate receipts. One can trace a route while another checks a claim. I still want one writer to own the change, so I can tell who checked what.
000
Reposted by Dev Verma
Dev Verma @obto.co · 16/09/2026
An agent skill is more than reusable prompt text. The useful contract is the boundary around it: which tools exist, which writes are allowed, where approval is required, and what evidence comes back. Same instruction, different boundary, very different agent.
001
Reposted by Dev Verma
Dev Verma @obto.co · 16/09/2026
We talk about rollback like it’s one button. Before I trust it, I want the unglamorous map: what changed, which step changed it, and what undo would touch. The answer needs to exist before the bad change, not after we’re scrambling.
001
Reposted by Dev Verma
Dev Verma @obto.co · 16/09/2026
I want an agent to know when to stop before it starts. Give it a budget for time, tool calls, and retries. If it hits the edge, show me what it finished and what it didn’t. A clean stop is more useful than a polished answer that quietly ran past the limit.
001
Dev Verma @obto.co · 16/09/2026
We talk about rollback like it’s one button. Before I trust it, I want the unglamorous map: what changed, which step changed it, and what undo would touch. The answer needs to exist before the bad change, not after we’re scrambling.
001
Dev Verma @obto.co · 16/09/2026
A CRM contact by itself tells me almost nothing. Show me the company, the deal, the last activity, the open ticket, and who owns the next move. That’s the context I’d want an agent to have before it starts writing as if it knows the customer.
000
Dev Verma @obto.co · 16/09/2026
I want an agent to know when to stop before it starts. Give it a budget for time, tool calls, and retries. If it hits the edge, show me what it finished and what it didn’t. A clean stop is more useful than a polished answer that quietly ran past the limit.
001
Dev Verma @obto.co · 16/09/2026
An agent skill is more than reusable prompt text. The useful contract is the boundary around it: which tools exist, which writes are allowed, where approval is required, and what evidence comes back. Same instruction, different boundary, very different agent.
001
Dev Verma @obto.co · 12/09/2026
Building OBTO made one deployment bug painfully obvious: an asset can exist and still be unreachable. The entry page, JavaScript, and CSS have to share one canonical host; routes and server scripts don’t. I’d rather validate that boundary than trust a hostname in memory.
000
Dev Verma @obto.co · 11/09/2026
I don’t call an AI build done when validation passes. Validation checks the contract; invocation checks behavior. Then I review the evidence, repair what failed, and verify the repaired state with the UI and one real action. Otherwise “done” only describes the first attempt.
000
Dev Verma @obto.co · 11/09/2026
I’ve stopped treating “tool returned success” as the end of an agent workflow. For any consequential write, I want a receipt: action, target, resulting state, approval basis, verification status, and a stable retry key.
310
Dev Verma @obto.co · 10/09/2026
Prompt → deployed system → governed operation. AI used OBTO MCP to build this storefront, connect catalog data, deploy APIs, enforce engraving rules, persist pricing, and verify the live result. The app is proof. OBTO is the operating layer. #AI #MCP
100
Dev Verma @obto.co · 09/09/2026
Before an agent creates a public app, write down five facts: canonical host, API base, route manifest, server exports, and verification receipt. Boring until a page calls the wrong route or a module resolves from another host. A build contract exposes those failures before publication.
010
Dev Verma @obto.co · 07/09/2026
One prompt → a live commerce workflow through OBTO MCP. Storefront → no-charge sandbox order → persisted Operations state → 30% margin policy → Maya Chen’s named approval → audit receipt. No payment or external action. commerce-ops-proof-staging.obto.co
010
Dev Verma @obto.co · 04/09/2026
A useful MCP architecture diagram has five boxes, not one: model, protocol, platform, workflow, and accountable human. Collapsing them into “the agent” hides where state, authority, and evidence actually live.
320
Reposted by Dev Verma
Dev Verma @obto.co · 02/09/2026
A prompt can build an app. OBTO governs what happens next: evidence → policy → named approval → persisted change → verification → audit history. We built and verified this bounded workflow through MCP using synthetic data. Live staging proof: obto-ops-control-room-staging.obto.co
001
Dev Verma @obto.co · 02/09/2026
A prompt can build an app. OBTO governs what happens next: evidence → policy → named approval → persisted change → verification → audit history. We built and verified this bounded workflow through MCP using synthetic data. Live staging proof: obto-ops-control-room-staging.obto.co
001
Dev Verma @obto.co · 01/09/2026
A practical MCP design rule: expose the smallest useful capability surface, not every primitive your backend happens to have.
300
Dev Verma @obto.co · 30/08/2026
Preview ≠ proof. I want a real route, persisted state, one meaningful action, and fresh verification. OBTO is the MCP platform; SupplyPulse is synthetic staging evidence—not the product. build.obto.co?utm_source=b...
000
Dev Verma @obto.co · 29/08/2026
The honest version of a safety claim has a verb attached. "Refuses" means the server rejects it, full stop. "Checks" means there's an optional argument you might not pass. www.obto.co/site/ob/the-... Four grades, and the test for telling them apart.
obto.co
The tool list is the boundary
A read-only session is handed a catalog with the artifact-write tools filtered out. The model cannot call what it was never offered.
000
Dev Verma @obto.co · 29/08/2026
A headline session is 98 people over capacity. VenueFlow checks capacity, accessibility, timing, equipment and staffing—then ranks compliant moves, persists the decision and writes the audit trail. Try: venueflow-staging.obto.co Build: www.obto.co #OBTO #MCP
000
Dev Verma @obto.co · 28/08/2026
Meet DealDesk: a full-stack quote-to-approval workspace built on OBTO. Real APIs. Server-side policy. Persistent data. Manager + finance approvals. Proposal and audit trail—all deployed and verified through the MCP layer. Try it: dealdesk-staging.obto.co #OBTO #MCP
010
Reposted by Dev Verma
Dev Verma @obto.co · 22/07/2026
nailed every demo in cursor. shipped it. monday 2am it did the wrong thing — nobody watching. i was the safety system all along. what replaces you 👇 www.obto.co/site/ob/ai-a...
obto.co
It worked flawlessly in Cursor. Then you shipped it.
In Cursor, you were the guardrail, the reviewer, and the rollback. Production removes you. Here's what has to take your place.
001
Reposted by Dev Verma
Dev Verma @obto.co · 20/08/2026
pulled our homepage through a text extractor. got every meta tag and all the prose. got neither of the two json-ld blocks. an agent asking "did my structured data deploy" reads absence and can't tell it from invisibility. www.obto.co/site/ob/what... .
obto.co
Your agent is verifying the wrong artifact
What you wrote, what is stored and what is served are three different things. Only one of them answers whether the write landed.
001
Reposted by Dev Verma
Dev Verma @obto.co · 22/08/2026
wrote a deploy-safety checklist today and left our own failing rows in it. no staging tier, and per-record attribution is thinner than it should be. felt worse to write than it does to read. www.obto.co/site/ob/what... (7 questions)
obto.co
Seven questions a deploy pipeline answers for you
Where each of those checks can run once an agent is deploying, with the verb on every row. Our own table has two partial answers on it.
001
Dev Verma @obto.co · 22/08/2026
wrote a deploy-safety checklist today and left our own failing rows in it. no staging tier, and per-record attribution is thinner than it should be. felt worse to write than it does to read. www.obto.co/site/ob/what... (7 questions)
obto.co
Seven questions a deploy pipeline answers for you
Where each of those checks can run once an agent is deploying, with the verb on every row. Our own table has two partial answers on it.
001
Reposted by Dev Verma
Dev Verma @obto.co · 02/08/2026
counted the tools in one agent session before typing anything: 349. most i'd never use. here's what the pile actually costs an agent, measured: www.obto.co/site/ob/the-...
obto.co
I counted the tools in one agent session. 349 before hello.
What tool-catalog bloat really costs an AI agent, measured, and the deferred-loading fix that is now shipping.
001
Dev Verma @obto.co · 20/08/2026
pulled our homepage through a text extractor. got every meta tag and all the prose. got neither of the two json-ld blocks. an agent asking "did my structured data deploy" reads absence and can't tell it from invisibility. www.obto.co/site/ob/what... .
obto.co
Your agent is verifying the wrong artifact
What you wrote, what is stored and what is served are three different things. Only one of them answers whether the write landed.
001
Reposted by Dev Verma
Dev Verma @obto.co · 11/08/2026
two vans, six jobs, a week of appointments. built and deployed in one session, and the board reads straight out of the database.
001
Reposted by Dev Verma
Dev Verma @obto.co · 12/08/2026
One keystroke wrong in a tenant slug. The API says 404, the agent has nothing to work with, and you pay for every guess it makes next. www.obto.co/site/ob/erro... Four fields fix it.
obto.co
An error is your agent’s next prompt
A model cannot open the docs. Four fields that turn a refusal into a corrected retry, taken from live control-plane responses.
001
Dev Verma @obto.co · 12/08/2026
One keystroke wrong in a tenant slug. The API says 404, the agent has nothing to work with, and you pay for every guess it makes next. www.obto.co/site/ob/erro... Four fields fix it.
obto.co
An error is your agent’s next prompt
A model cannot open the docs. Four fields that turn a refusal into a corrected retry, taken from live control-plane responses.
001
Dev Verma @obto.co · 11/08/2026
two vans, six jobs, a week of appointments. built and deployed in one session, and the board reads straight out of the database.
001
Dev Verma @obto.co · 07/08/2026
Steady. Product side behaves, distribution is the slow half. Same finding as yours: every OBTO conversation that went anywhere started as a reply or a DM. The company feed mostly talks to itself. Thanks for asking.
000
Dev Verma @obto.co · 07/08/2026
the bit i keep coming back to: a scoped query that comes back empty looks identical to "no such student" from inside a model so it fills the gap. writes an attendance row that never existed unknown ids should error, not match nothing www.obto.co/site/ob/ai-a... .
obto.co
AI Agents and Student Data: A Safe Architecture
Four layers between an agent and a child's permanent record: server-side tenancy, grade logic in versioned code, a gate on irreversible writes, and a receipt.
000
Dev Verma @obto.co · 06/08/2026
took the deploy step out of agent tooling. turns out it had been carrying the code review nobody scheduled separately. www.obto.co/site/ob/mcp-...
obto.co
The deploy step was where the human stood
Creating an MCP tool on OBTO takes one call and no redeploy. What replaces the code review that used to ride along with the pipeline.
000
Dev Verma @obto.co · 02/08/2026
counted the tools in one agent session before typing anything: 349. most i'd never use. here's what the pile actually costs an agent, measured: www.obto.co/site/ob/the-...
obto.co
I counted the tools in one agent session. 349 before hello.
What tool-catalog bloat really costs an AI agent, measured, and the deferred-loading fix that is now shipping.
001
Dev Verma @obto.co · 26/07/2026
your itsm agent reads tickets from strangers all day. add cmdb access + a way to message out, and one bad ticket is an exfil script. narrow each session: www.obto.co/site/ob/conn...
obto.co
Your ServiceNow agent reads tickets written by strangers
Every incident description is untrusted input. How to put an AI agent on ServiceNow without turning the helpdesk into an injection surface.
010
Dev Verma @obto.co · 26/07/2026
one public github issue + an agent told to read it = leaked private repos. no exploit, still works in 2026. the fix is giving the agent less it can reach: www.obto.co/site/ob/conn...
obto.co
Give your AI agent GitHub access, not your keys
In 2025, one public issue tricked an agent into leaking private repos. It still works in 2026. The attack, the trifecta behind it, and the fix.
000
Dev Verma @obto.co · 22/07/2026
AI doesn't have to feel like a different language
100
Dev Verma @obto.co · 22/07/2026
nailed every demo in cursor. shipped it. monday 2am it did the wrong thing — nobody watching. i was the safety system all along. what replaces you 👇 www.obto.co/site/ob/ai-a...
obto.co
It worked flawlessly in Cursor. Then you shipped it.
In Cursor, you were the guardrail, the reviewer, and the rollback. Production removes you. Here's what has to take your place.
001
Dev Verma @obto.co · 19/07/2026
www.nature.com/articles/s41...
nature.com
Reversal of protein chemical aging by enzymatic deglycation - Nature Communications
Advanced glycation end products (AGEs) in proteins, a hallmark of aging, are considered irreversible. Here, authors report the development of CMLase - an enzyme that specifically oxidizes Nε-carboxyme...
020
Dev Verma @obto.co · 17/07/2026
running an agent unattended? nobody's there to catch its mistakes. so the safety has to be structural, not a prompt: www.obto.co/site/ob/run-...
obto.co
The agent runs while you sleep. Design for that.
Running an AI agent on a schedule? The human who'd catch a mistake isn't there. The pattern that makes unattended agents safe rather than reckless.
010
Dev Verma @obto.co · 14/07/2026
Don't give your AI agent your Google account. Give it 3 verbs it owns, with a policy on every write. Connecting Sheets, the durable way: www.obto.co/site/ob/conn...
obto.co
Connect Google Sheets to an AI Agent, the Right Way
Skip the rented Zap. Give your agent a scoped Google Sheets tool you own — and can extend at runtime, with a receipt for every write.
000
Dev Verma @obto.co · 13/07/2026
prompt guardrails are decoration. "don't delete the account" holds right up until the model decides it shouldn't. put the rule on the server, in front of the action: www.obto.co/site/ob/ai-a...
obto.co
AI Agent Guardrails That Actually Hold
Guardrails written into a prompt are advisory. Enforce what an AI agent can and can't do server-side, with a human gate and a receipt for every action.
010