Dispatch 278
Week ↗

Brand-Ops launches, Meeting-Ops ships the moat

I spent Monday building the thing we've been sketching out for weeks: Brand-Ops, the brand identity and AI image-asset generation system. I dropped 22,449 lines across 136 files as the initial commit, coveri…

Commits
77
Systems
9
Read
2min
Product capture

Brand-Ops — library.

I spent Monday building the thing we've been sketching out for weeks: Brand-Ops, the brand identity and AI image-asset generation system. I dropped 22,449 lines across 136 files as the initial commit, covering the whole stack from the Dockerfile through the alembic migrations, the brand-kits template, and the MCP integration. It's a new product surface now.

But the day's real arc was Meeting-Ops, where I shipped v3.29.0 through v3.30.0 in a single production-ready push. This was the audit remediation wave, all of it. I tightened Brigade tenancy to fail-closed, added WebSocket handshake auth with org-scoped live meeting sockets (that closed the audit's last security item), and did a sweep across settings panels to make every surface honest for new users. I tore out speaker avatars that didn't belong, replaced Whisper references with the actual Parakeet stack, and made the session record surface its own speaker roster as a collapsible card instead of hiding it in a tab. The Sessions speed got an uplift, page-size control landed, and I closed out summary idempotency and reprocess dedup so the finalize path doesn't re-invent work. I also wired per-org toggles to auto-send action items to Project-Ops triage and got the finalize worker submitting proposals properly.

Contact-Ops got a knowledge graph that populates and shows itself by default, powered by a force-directed 2D layout from react-force-graph-2d. The overview clusters by employer instead of a single ring, the ego graph always includes the center person, and zoom-to-fit frames it on engine stop. I added CSV upload with existing-person dedup so re-imports are safe, and the dashboard counts are now real instead of frozen. The import path supports vCard alongside CSV.

The Sessions speed got an uplift, page-size control landed, and I closed out summary idempotency and reprocess dedup so the finalize path doesn't re-invent work.

Ops-Center got a security overhaul I'm actually glad to have behind me. I implemented a default-deny auth middleware, which meant going back through every endpoint and asking who actually needed access. I gated the LLM providers handler that was being shadowed, repaired the inert fake-admin auth in billing events, and locked down 11 residual admin endpoints. The session-token prefix logging that was leaking at INFO level got silenced, and I stopped writing user PII to the request log. I also rebuilt the validate-key flow to resolve workspace_id from the uc-registry instead of a local stub, and added the pricing rates API with cost-plus margin controls and server-side never-lose-money clamping.

Project-Ops shipped the Triage Inbox review UI with approve/reject and create-project-from-unassigned, part of the 1.7.0 release. The iOS app got its design system module with tokens and Liquid Glass, the Record hero with live waveform and morphing button, a Session Detail screen, and a workspace/org switcher for multi-org scoping. I made on-device no-account mode real and cleared three App Review blockers.

Also today: Listing-Ops got a Claude-powered in-app assistant and consignor self-service, tax-planning-ops got its PRD and coding-agent prompt, and ops-center's uc-registry added the user-to-workspaces reverse lookup.

Seven commits on Meeting-Ops, seventeen on iOS, sixteen on ops-center, fifteen on contact-ops, and a new repo in the world. The moat got deeper and the audit came back clean.

Also in the frame

Real product captures — click any to enlarge.

ops center
ops center
ops center