Dispatch 315
Week ↗

Unicorn Brigade: The Great Hardening

Friday was a heavy lift, mostly because I spent the day making the Unicorn Brigade system behave like a responsible adult. I pushed 34 commits to the main repo, and the theme was less about adding shiny new…

Commits
39
Systems
6
Read
2min
Product capture

Unicorn Brigade — agent editor.

Friday was a heavy lift, mostly because I spent the day making the Unicorn Brigade system behave like a responsible adult. I pushed 34 commits to the main repo, and the theme was less about adding shiny new features and more about closing every possible leak. I wanted to ensure that when a user logs in, their data stays theirs, the system doesn't crash when credentials go missing, and the UI actually looks like something people use for work.

The biggest chunk of work was tenancy and security. I spent a lot of time on the RLS (Row Level Security) substrate. I needed to make sure that one organization’s agents couldn’t accidentally read another organization’s data. I implemented a canonical user identity using Keycloak subs, which simplified the auth middleware significantly. Then I added org lifecycle management, allowing for personal orgs, invites, and per-org roles. It wasn’t just about adding these features; it was about proving they worked. I wrote scripts to prove org lifecycle and RLS isolation, and I fixed several cross-tenant leaks that popped up during an adversarial review. I also bound API keys to specific organizations to close a H1 cross-tenant key gap. If you have a key, it only works for your org. Period.

I also tackled reliability and observability. The system was getting smarter, but it needed to be more robust. I added timeouts, bounded retries, and a circuit breaker pattern for tool degradation. If a tool fails, the system shouldn’t hang. I also wired up request-id correlation, readyz/livez health checks, and metrics so we can actually see what is happening in production. I even purged some fabricated claims about server counts from the live agent prompts and documentation. Honesty is cheaper than debugging a lie.

I spent a lot of time on the RLS (Row Level Security) substrate.

On the frontend, the Unicorn Brigade is getting a serious polish. I ran a codemod to change the brand accent from purple/pink to a more professional unicorn accent. I migrated hand-rolled modals to a standard Modal primitive and added aria-labels to close buttons for accessibility. I also replaced decorative emojis with proper lucide icons. The UI is cleaner, more accessible, and easier to maintain. I even added some dependency-free SVG charts for the dashboard, so we don’t need heavy libraries for simple data viz.

I also fixed a few user-testing feedback items from Ceejay’s report. The UX improvements included fixing device detection and cleaning up the live recording page. I also expanded the headlines on the landing page to 12, synced with the canonical hero component.

It was a long day of fixing, hardening, and polishing. But the system is more secure, more reliable, and looks better than ever. I’m happy with the progress.

Also today: I updated the landing page headlines and fixed a few minor UI tweaks.

Also in the frame

Real product captures — click any to enlarge.

brigade
meeting ops
meeting ops