security-governance
Add Google Login to an Internal Application
Add Sign in with Google while keeping token verification, local accounts, roles, sessions, and offboarding at explicit trusted boundaries.
Updated 2026-07-31
Publication archive
Practical, tested guidance for taking AI-built internal tools from prototype to secure, maintainable production.
security-governance
Add Sign in with Google while keeping token verification, local accounts, roles, sessions, and offboarding at explicit trusted boundaries.
Updated 2026-07-31
productionization
Use current provider documentation and a handoff card to plan access, revision checks, live verification, reversal, and support for an internal tool.
Updated 2026-08-09
productionization
Rehearse restoring application data and files into an isolated environment, then record integrity, timing, gaps, and rollback.
Updated 2026-08-09
productionization
Set up a compact monitoring loop that checks availability, one critical workflow, errors, background work, and alert ownership.
Updated 2026-08-09
productionization
Use a synthetic fixture-backed worksheet to inventory browser-local records, freeze transformations, and plan verification and rollback.
Updated 2026-08-17
security-governance
Map users and data scopes, enforce authorization at the trusted boundary, and run allowed and denied tests before coworkers use an internal app.
Updated 2026-07-31
productionization
Draft an explicitly unvalidated operating index for owners, release evidence, monitoring, rollback, recovery, secrets, and escalation.
Updated 2026-08-04
productionization
Use this evidence-based checklist to decide whether an AI-built internal app has the ownership, access, recovery, and release controls needed to launch.
Updated 2026-08-04
security-governance
Use primary security guidance and a fake-credential fixture to plan containment, provider-side replacement, scoped delivery, and verification.
Updated 2026-08-09
productionization
Test one harmless application notification with a bounded recipient, receipt, observation owner, and duplicate rule before enabling a real audience.
Updated 2026-08-12
productionization
Record the appointment identity, local time and zone, calendar counterpart, observed update, and reconciliation owner in one bounded reschedule exercise.
Updated 2026-08-26
productionization
Exercise a booking-to-calendar boundary with named records, a sync checkpoint, change and delete observations, and a reconciliation owner.
Updated 2026-08-25
security-governance
Verify invitation, sign-in, recovery, role change, session revocation, suspension, and deletion before real users depend on an app.
Updated 2026-07-31
productionization
Exercise a CSV import with a safe fixture, declared schema, row results, owner, and reconciliation path before it changes operational records.
Updated 2026-08-21
productionization
Exercise one signed synthetic webhook with an event ID, replay boundary, owner, and reconciliation path before it starts operational work.
Updated 2026-08-17
productionization
Retain a bounded recovery receipt that names the attendance record, policy, capacity decision, customer-contact owner, and escalation route.
Updated 2026-08-28
security-governance
Exercise a password-reset flow in an approved non-production environment, retain a narrow receipt, and stop when recovery boundaries are unknown.
Updated 2026-08-24
productionization
Retain a bounded receipt that separates payment, appointment, expected confirmation, observation, and recovery ownership.
Updated 2026-08-27
productionization
Use a bounded receipt to keep accepted work, a new request, authority, impact review, and escalation separate before staff act.
Updated 2026-08-30
productionization
Use a bounded receipt to keep one intended request, an uncertain result, any retry, reconciliation, and escalation visible before staff act.
Updated 2026-08-31
productionization
Exercise normal, missed, duplicate, overlapping, failed, retry, and reconciliation states for scheduled internal-app work before launch.
Updated 2026-08-11
productionization
Use a bounded receipt to show an expected and observed status, the evidence time and source, reconciliation owner, decision, and escalation before staff act.
Updated 2026-09-01