Dispatch 339
Week ↗

Tuesday: Fixing the leaks, hardening the agents

It was a heavy Tuesday. Forty-six commits across a dozen repos. The day didn't have one single headline, but rather a collection of tight turns. I spent most of the morning in accounting-ops, chasing down th…

Commits
46
Systems
12
Read
2min
Product capture

Brand-Ops — library.

It was a heavy Tuesday. Forty-six commits across a dozen repos. The day didn't have one single headline, but rather a collection of tight turns. I spent most of the morning in accounting-ops, chasing down the leaks that had been letting the system lie to itself.

The 1099-NEC report was the biggest pain. It was missing real contractors and the trial balance was showing pre-correction numbers. That’s not just a bug, that’s a liability. I spent a good chunk of the day fixing the journal accounts and the tax tools. The fix touched nine files, including migrations and tests. The numbers finally lined up. The trial balance now reports the right corrections, and the 1099s actually see the contractors they’re supposed to.

At the same time, I had to gate the MCP server-side tool allow-list. It’s a small feature, but it’s critical. You can’t have agents running wild. I added the per-agent policy across accounting-ops, accounting-ops-community, and accounting-ops-oss. The logic is simple: if an agent isn’t allowed the tool, it doesn’t get the tool. No arguments.

I spent a good chunk of the day fixing the journal accounts and the tax tools.

The MCP auth was another headache. I had to apply service-token scopes on the MCP surface, not just on HTTP. The old code was letting some things slip through. I also closed the posting-tool gaps that the report from yesterday flagged. The posting tools are the backbone of the accounting system, and they can’t be half-baked. I hardened them across the board.

In email-ops, I closed a mailbox leak. It was an intra-workspace issue where one workspace could see another’s mail. That’s a hard no. I also split the Email-Ops SKUs to make billing clearer. The frontend honesty pass was a nice touch too. The UI was claiming staged work was done when it wasn’t. I fixed that. The unsubscribe flow now requires human approval, which is a small change but a big one for trust.

Unicorn-stable got a lot of attention too. The ongoing-call awareness is finally everywhere. Sidebar badges, in-room banners, and call-started toasts. It’s all there now. The stale-room events can no longer wedge the call state, which was a persistent issue. I also wired up the face-style preference. You can now pick your avatar look, and it sticks. The group-call heal is working, so if someone drops, the room stays intact.

Multistate-retirement-leads got a security bake. I added RBAC guards, PII gating and the prod nginx frontend into source. The frontend nginx config is in source, which makes deployment less of a guessing game. The smoke test for post-deploy is there too, so I know the system is up when it boots.

Also today: I capped Redis below 8.1 because 8.1.0 broke every FalkorDB projection. A quiet dependency hell, but it saved a lot of debugging time. I also removed a hardcoded Namecheap API key from secret_manager.py in ops-center and uc-cloud. Hardcoded secrets are a bad habit, and I’m trying to break it. The receipt-worker poll loop is now more resilient, and the CI pipeline in accounting-ops actually runs the suite it’s supposed to.

The day added up to a system that lies less The reports are right, the security gates are holding, and the agents are behaving. It’s not glamorous, but it’s what keeps the lights on.

Also in the frame

Real product captures — click any to enlarge.

uc cloud
accounting ops
email ops