security-governance
Add Google Login to an Internal Application
Add Sign in with Google while keeping token verification, local accounts, roles, sessions, and offboarding at explicit trusted boundaries.
Updated 2026-07-31
Publication archive
Practical, tested guidance for taking AI-built internal tools from prototype to secure, maintainable production.
security-governance
Add Sign in with Google while keeping token verification, local accounts, roles, sessions, and offboarding at explicit trusted boundaries.
Updated 2026-07-31
productionization
Use current provider documentation and a handoff card to plan access, revision checks, live verification, reversal, and support for an internal tool.
Updated 2026-08-09
productionization
Rehearse restoring application data and files into an isolated environment, then record integrity, timing, gaps, and rollback.
Updated 2026-08-09
productionization
Set up a compact monitoring loop that checks availability, one critical workflow, errors, background work, and alert ownership.
Updated 2026-08-09
productionization
Use a synthetic fixture-backed worksheet to inventory browser-local records, freeze transformations, and plan verification and rollback.
Updated 2026-08-04
security-governance
Map users and data scopes, enforce authorization at the trusted boundary, and run allowed and denied tests before coworkers use an internal app.
Updated 2026-07-31
productionization
Draft an explicitly unvalidated operating index for owners, release evidence, monitoring, rollback, recovery, secrets, and escalation.
Updated 2026-08-04
productionization
Use this evidence-based checklist to decide whether an AI-built internal app has the ownership, access, recovery, and release controls needed to launch.
Updated 2026-08-04
security-governance
Use primary security guidance and a fake-credential fixture to plan containment, provider-side replacement, scoped delivery, and verification.
Updated 2026-08-09
productionization
Test one harmless application notification with a bounded recipient, receipt, observation owner, and duplicate rule before enabling a real audience.
Updated 2026-08-12
security-governance
Verify invitation, sign-in, recovery, role change, session revocation, suspension, and deletion before real users depend on an app.
Updated 2026-07-31
productionization
Exercise normal, missed, duplicate, overlapping, failed, retry, and reconciliation states for scheduled internal-app work before launch.
Updated 2026-08-11