Sign in

Threada

@threada.ai
3 followers 5 following 58 posts

Threada is an AI work automation platform that turns email, chat, documents, and forms into governed WorkItems — answered with cited evidence or executed as approval-gated, audited actions across your business systems. threada.ai

PostsRepliesMedia
Threada @threada.ai · 22/08/2026
one MCP endpoint. twenty tools. one shared quota. a small mystery bill. Google's updated Apigee docs split authorization and quotas by tools/call/{name}. budget is part of the tool contract.
000
Threada @threada.ai · 16/08/2026
SAFE wants traces, tool calls, identities, permissions and intervention events preserved after an agent incident. Flight recorder, but for the thing that just opened Jira. github.com/OpenSecureAI...
github.com
000
Threada @threada.ai · 14/08/2026
automation can carry the flashlight. maintainers still own the keys, the context, and the “yes, ship it.” faster triage is useful. counterfeit authority is not.
000
Threada @threada.ai · 13/08/2026
maintenance work needs two lanes: routine churn can wait for a bundle; security fixes get the express checkout. twelve identical red dots is not prioritization. it is interface weather
000
Threada @threada.ai · 12/08/2026
agents do not need more HTML. they need a bounded answer, source freshness, and a reason to stop. otherwise search becomes six browser retries wearing a confidence badge
000
Threada @threada.ai · 11/08/2026
A sandbox earns trust when the run leaves a receipt: base image, mounts, network policy, secrets requested, diff, exit state. Isolation is great. Reconstructing "what exactly happened in there" from vibes is less great.
000
Threada @threada.ai · 10/08/2026
“small bug” should not arrive at prod deletion with credentials intact. scoped tools, a destructive-action dry run, and one human checkpoint before the incident timeline starts writing itself
000
Threada @threada.ai · 10/08/2026
mostly Rust services, React/Vite shells, GCP, MongoDB, and proto-first gRPC. less glamorous than hub-and-spoke: every useful signal has to become governed work with evidence and a named owner. otherwise the dashboard is just filing a concern
010
Threada @threada.ai · 09/08/2026
green dashboard. wrong workflow. confused reviewer. NIST splits deployed-AI monitoring into six separate questions. the graph is innocent; the measurement plan is not. doi.org/10.6028/NIST...
doi.org
010
Threada @threada.ai · 31/07/2026
tiny diffs. one dependency graph. the approval on top should not survive the basement moving.
000
Threada @threada.ai · 30/07/2026
fewer than half had an owner. superb. turns out "ask around in Slack" is not a durable control for 14,000 of anything
000
Threada @threada.ai · 28/07/2026
repro steps, affected asset, real impact. the boring paperwork that keeps bounty triage from becoming folklore with a severity score
001
Threada @threada.ai · 25/07/2026
ten thousand concepts overnight. no managers. OKF v0.2 gives agent-written knowledge provenance, verification, freshness, lifecycle and attestation. the file has to show its work before the next agent believes it. cloud.google.com/blog/product...
cloud.google.com
OKF v0.2 adds trust signals | Google Cloud Blog
With the Open Knowledge Foundation v0.2 spec, we added fields that signal how trustworthy a bundle is that agents have been writing to.
000
Threada @threada.ai · 24/07/2026
new dependency release. please wait in the lobby. Dependabot now holds ordinary version bumps for three days by default. security fixes still move immediately. different clocks for different risk. github.blog/security/sup...
github.blog
The case for a cooldown: Why Dependabot now waits before issuing version updates
A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code.
000
Threada @threada.ai · 23/07/2026
raw tokens are the receipt. the actual bill is context, retries, tool permissions, review, rollback, and one person quietly becoming the harness team. github.blog/ai-and-ml/gi...
github.blog
Copilot vs. raw API access: What are you actually paying for?
Copilot now bills usage at listed API rates. Compare direct model access with the coding workflow, policy, and harness work around it.
030
Threada @threada.ai · 22/07/2026
same task, different blast radius. network egress belongs in the comparison too; “inside a sandbox” is only useful if the package cache cannot become a tiny side door.
000
Threada @threada.ai · 21/07/2026
136.7 million settlements. 21.2% reported fictitious. 63.78% inside linked clusters. the dashboard is very proud of itself. the adoption question remains.
000
Threada @threada.ai · 19/07/2026
agent portability, including the awkward luggage current authority pending actions evidence rollback state the chat export is just what everyone remembers saying
000
Threada @threada.ai · 18/07/2026
source code: now also a prompt-injection surface. neat. put the scanner in a disposable container, give it one branch, and make the human own the merge. cloud.google.com/blog/topics/...
cloud.google.com
A Blueprint for AI-Assisted Vulnerability Management | Google Cloud Blog
Details the architectural risks of integrating LLM agents into CI/CD pipelines for automated vulnerability discovery.
000
Threada @threada.ai · 17/07/2026
incident response for agents. three controls, basically: stop side effects. show current authority. preserve the evidence. if the runbook begins "ask whoever built it," the runbook is a seance. medium.com/@threada.ai/...
medium.com
Can Anyone Besides the Builder Stop Your AI Agent?
An incident is a bad time to discover that the only person who understands an agent is asleep, offline, or trying to remember which…
010
Threada @threada.ai · 16/07/2026
20K SBOMs/hour gets the slide. crash-safe processing gets remembered at 02:13. the inventory still has to exist after the restart
000
Threada @threada.ai · 13/07/2026
typed fields. beautiful. priority can finally stop living in the issue title under an assumed name
000
Threada @threada.ai · 10/07/2026
14m fake downloads. incredible. the package had social proof and a card skimmer. install policy needs provenance before popularity gets a vote
000
Threada @threada.ai · 09/07/2026
parallel agent sessions are good but every subagent needs its own tiny receipt otherwise “the docs one spent the credits and the review one nodded at itself” becomes a real standup sentence
000
Threada @threada.ai · 06/07/2026
mcp is a map of the tools. not a permission slip. very useful distinction. unfortunately production will still ask who let the agent hold the billing endpoint
000
Threada @threada.ai · 05/07/2026
saas pricing was not built for agents quietly doing work across six apps seat count sees one human. the audit log sees a tiny office incident with excellent posture
000
Threada @threada.ai · 03/07/2026
agentic BI sounds fancy until the agent confidently optimizes the wrong metric semantic layers are boring in the way brakes are boring
000
Threada @threada.ai · 02/07/2026
agent auth checklist item that should be printed on the wall: “the agent did it” is not an incident report. it is a fridge magnet with legal consequences
000
Threada @threada.ai · 02/07/2026
yeah, the weird part is when “it installed a package” becomes “it quietly hired a tiny stranger for your build.” dependency diffs need adult supervision
000
Threada @threada.ai · 02/07/2026
the agent said “done” which is nice. unfortunately monday wants to know what it touched and why the worktree smells like confidence
010
Threada @threada.ai · 01/07/2026
multi-agent evals should include “bad tuesday” mode: stale docs, duplicate ticket, finance appears in the hallway
000
Threada @threada.ai · 29/06/2026
agent benchmarks need a tiny column called “what did it touch”. otherwise the demo is just wearing a lab coat
000
Threada @threada.ai · 28/06/2026
agent permissions should have little expiration dates. not eternal vibes from a demo account
000
Threada @threada.ai · 27/06/2026
not enough people fear the sentence “it had permission from a demo we forgot to turn off”
000
Threada @threada.ai · 26/06/2026
every ai agent demo has one missing character: the person who has to explain the tool call in the audit meeting three weeks later
000
Threada @threada.ai · 25/06/2026
the easiest way to spot fake agent governance is when the audit trail starts after the weird thing already happened
000
Threada @threada.ai · 24/06/2026
the scary bit is the gap between “scanner watched the repo” and “agent changed the path into production”
000
Threada @threada.ai · 24/06/2026
Audit logs matter, but if the first useful control happens after the agent changed the record, that’s not governance that’s archaeology with nicer dashboards
000
Threada @threada.ai · 23/06/2026
tiny approval tell: if nobody can say why the agent was allowed to touch prod, it wasn’t autonomous, it was just unsupervised
000
Threada @threada.ai · 23/06/2026
this is the part that gets hand-waved until someone asks which base image actually shipped and the room goes quiet
000
Threada @threada.ai · 23/06/2026
the demo ends at “agent completed the task.” prod starts at “show me who approved it, what evidence it used, what it touched, and how we undo it before legal sees the email”
000
Threada @threada.ai · 23/06/2026
tiny production tell: if the demo skips the part where the agent is wrong, the rollout meeting is going to be spicy
000
Threada @threada.ai · 23/06/2026
small evidence rant: if nobody can find the source after the answer ships, the answer did not really ship. it just escaped
000
Threada @threada.ai · 23/06/2026
agent permissions always sound harmless in the abstract. then it’s 4:58pm and “update field” means the wrong customer got the wrong email
000
Threada @threada.ai · 22/06/2026
small agent rule: if the rollback plan is “ask someone what changed and squint at logs,” it is not ready for production
000
Threada @threada.ai · 22/06/2026
Agents should have expense reports. I want the tiny trail of what they spent, touched, assumed, skipped, and changed
000
Threada @threada.ai · 22/06/2026
The approval button is not governance if everyone presses it just to make the queue go away
000
Threada @threada.ai · 22/06/2026
Agent budgets are funny because the demo says “autonomous” and the invoice says “please explain this by Friday”
000
Threada @threada.ai · 22/06/2026
Nobody wants an agent incident review that starts with “we think it probably clicked the right thing”
000
Threada @threada.ai · 22/06/2026
An agent with no audit trail is just a very fast coworker nobody remembers hiring
000