Weekly chapter74
2026-W33 · ending August 16, 2026· August 2026 chapter ↗

Accounting for truth, broadcast for clarity

This week was about tightening the belt. I spent most of my time chasing down places where the system was lying to itself, whether that meant financial reports missing contractors or UI states pretending wor…

181commits19systems6min read
Product capture

Accounting-Ops — transactions.

This week was about tightening the belt. I spent most of my time chasing down places where the system was lying to itself, whether that meant financial reports missing contractors or UI states pretending work was done when it wasn’t. The headline for the week is trust. I built a broadcast feed for streaming, but I also spent equal energy making sure the accounting pipeline didn’t hallucinate confirmations and that email routing didn’t leak secrets. It was a week of foundational work, and that is exactly what I needed.

Monday started with security and stability. I spent the day fixing the accounting-ops repo, specifically how posting confirmations were handled. The old logic relied on an agent’s user_confirmed argument. That was a design flaw. If an agent got confused or the UI state drifted, we could end up with postings that weren’t actually confirmed by a human. I rewrote the logic to derive the confirmation server-side. The backend now makes the final call based on hard facts. I touched five files, adding 285 lines and removing 10. The bulk of that was in app/journal/posting.py and the new test suite. I also pushed a hotfix to the dogfood environment to keep the rackboy1 setup stable during the transition.

Over in uc-meeting-ops, I cut our losses on language-aware speech-to-text. We had been experimenting with Whisper and custom routing, but it was adding complexity without delivering value. I reverted that entire feature. I removed the language-aware STT and the Whisper integration, keeping only a small fix for the reprocess banner. It was a relief to clean up that mess. The tests for language routing are gone, and the provider registry is simpler. Sometimes the best engineering decision is to remove a feature that was never quite right.

I spent the day fixing the accounting-ops repo, specifically how posting confirmations were handled.

Tuesday was a heavy day. Forty-six commits across a dozen repos. The biggest pain was the 1099-NEC report. It was missing real contractors and the trial balance was showing pre-correction numbers. I spent a good chunk of the day fixing the journal accounts and tax tools. The fix touched nine files, including migrations and tests. The numbers finally lined up. The trial balance now reports the right corrections, and the 1099s actually see the contractors they’re supposed to.

I also gated the MCP server-side tool allow-list. You can’t have agents running wild. I added the per-agent policy across accounting-ops, accounting-ops-community, and accounting-ops-oss. If an agent isn’t allowed the tool, it doesn’t get the tool. In email-ops, I closed a mailbox leak where one workspace could see another’s mail. That’s a hard no. I also fixed the unsubscribe flow to require human approval. Unicorn-stable got a lot of attention too. The ongoing-call awareness is finally everywhere. Sidebar badges, in-room banners, and call-started toasts are all there now. The stale-room events can no longer wedge the call state. I also wired up the face-style preference. You can now pick your avatar look, and it sticks. The group-call heal is working, so if someone drops, the room stays intact.

Wednesday was about getting the single-participant broadcast feed ready for OBS. It was a full-stack job that touched the server, the web client, and the database. I needed a clean way to pull a single video stream into streaming software without the overhead of a full conference room. On the server side, I added a new model for broadcast tokens and wrote the tests. The API endpoints in broadcast.py and webhooks.py got the logic to handle these streams. I also wrote a threat model document. The server changes added nearly nine hundred lines of code across seven files.

The web side was heavier. I rebuilt the broadcast page, the participant strip, and the voice video bar. That was over fifteen hundred lines of changes in the frontend. It was a lot of CSS and React components to wire together, but it finally gives me a dedicated feed. I also fixed a bug where URL path components in the broadcast API were not being encoded correctly. While I was pushing code, I cleaned up the CI pipeline in the accounting repo. I pinned the ruff version to stop the guessing game and changed the Docker container from python:3.12-slim to something that actually supports the checkout process. I also deleted the one-shot CI trigger file because it was just clutter.

Thursday was a thin day in panel-ops, but the work was specific. I spent my time tightening up the shell logic and building out the visual presence card for the agent. The shell had a bug where muting didn’t actually stop the ring from spinning. I fixed that by forcing the ring to idle whenever mute is engaged. You mute it, it stops. No more phantom listening states.

The heavier lift was the agent presence card. I built a canvas-based component that renders the Brigade avatar. It uses a cached data URI with an emoji fallback, so it loads fast and doesn't break if the image asset is missing. It uses a cached data URI with an emoji fallback, so it loads fast. The card has state animations for listening, thinking, and speaking. This gives immediate visual feedback on the agent's current mode. This gives immediate visual feedback on the agent’s current mode. I wired this into the panel canvas, which clears cleanly when the panel closes. It is not just a static icon. It is a dynamic indicator. I also made sure the STT_MODEL environment variable drives the model selection. This keeps the configuration out of the code and into the environment, which is cleaner and easier to manage across different deployments. The selftest covers the basic rendering path, while the fake satellite simulates the voice hub behavior. This gives me confidence that the presence card works even when the actual voice service is not running.

Friday was about wrapping up loose ends and fixing foundations. The uuda agent had been churning through restart loops, so I split the lifetime restart logic from the actual restart loop. That fixed the churn. I also added a fleet liveness watchdog and a nightly PostgreSQL backup script. The macOS codesigning and .deb packaging scripts are added to the repo. I ran cargo fmt across the tree and made it a real CI gate, because if the code isn't formatted, it doesn't exist. In the meeting ops repo, I tackled the session identity problem. The goal was simple: one call is one session, readable by the people who were in it. I moved participant visibility resolution from Python into JSON SQL, which cleaned up the logic significantly.

The avatar work was a cleanup spree. I committed the 42 roster portraits that had only been living in the container. They are now part of the source tree. This also touched the brand-ops repo, where I fixed the agent bio prompt so the image model actually receives the data, and corrected the cost governance so the spend meter runs on the HTTP MCP transport. They are now part of the source tree. I also fixed the agent bio prompt so the image model actually receives the data. On the ops-center side, I fixed the service worker to stop swallowing /auth/* requests. The catalog now reflects reality.

Sunday was quiet but productive. I spent the day tightening up the email-ops repo. I needed to route Gmail broker connections through a dedicated link-only IdP alias. This required touching the Keycloak broker service and the connected accounts service. I also fixed a classification bug where Keycloak was returning a 400 "not-linked" error. Our system was treating it as a failure, but it was an expected miss. I added an honest create receipt for mailbox creation so the UI reflects the state accurately.

The week ended with a system that lies less. The reports are right, the security gates are holding, and the agents are behaving. It’s not glamorous, but it’s what keeps the lights on.

Also in the frame

Real product captures — click any to enlarge.

accounting ops
brand ops
email ops
07 / Activity

The week, in commits.

Daily velocity and the systems that carried the work.

23Mon10
47Tue11
58Wed12
8Thu13
41Fri14
·Sat15
4Sun16
Week beginning August 10, 2026.
Index

19 systems,
one week of work.

accounting-opsaccounting-ops-communityaccounting-ops-cpa-exportaccounting-ops-ossaccounting-ops-receipt-workerbrand-opscustomer-opsemail-opsglitter-manemagic-unicorn-outreachmultistate-retirement-leadsops-centerpanel-opsuc-clouduc-meeting-opsunicorn-brigadeunicorn-stableuudawealth-ops