Field reports

Notes from the engagement floor.

Lean, technical, and written by the engineers who ran the work. Published when we find something worth saying — not on a content calendar.

· 8 min read

What 'Stop, Drop, and Roll Out' Looks Like in a Real Engagement

The Lean-First framework, walked through a single 90-day client engagement. No hand-waving.

MethodologyLean ITCase Walk-Through
· 7 min read

When to Build a Web App Instead of Buying SaaS

The build-vs-buy decision is rarely about money. Three questions that actually matter, and the math that follows.

Custom BuildWeb ApplicationsBuild vs Buy
· 8 min read

The Hidden Cost of Vendor Sprawl: A Lean IT Audit Worksheet

Most mid-market firms are paying for between 18 and 40 SaaS vendors that their team uses in name only. Here's how we count it.

Lean ITVendor AuditMethodology
· 6 min read

When to Hire a Fractional CISO (and When You Shouldn't)

A fractional CISO is the right answer about 60% of the time. Here's the frame for figuring out which side you're on.

Security LeadershipComplianceHiring
· 6 min read

How We Found 78 Forgotten Permissions in a Single Salesforce Org

A 1,200-user firm asked us to pentest their Salesforce org. The blind spot was hiding in plain sight.

SalesforcePentestPermission audit
· 7 min read

When On-Prem Wins: A Decision Frame for Hybrid Cloud

Cloud-only is a default, not a strategy. Three questions we ask before we recommend keeping anything inside your own building.

NetworkHybrid CloudArchitecture
· 7 min read

MCP Is the New Perimeter: Securing the Tools an Agent Can Reach

Model Context Protocol is the most important security boundary you have not yet inventoried.

MCPAgentsAgentic AI
· 6 min read

When to Write Apex, When to Build Flow: An Engineering Frame for Salesforce Customization

Three questions we ask before we recommend Apex over a declarative tool — and what each one costs when answered wrong.

SalesforceCustom DevelopmentApex
· 7 min read

Three Snowflake RBAC Anti-Patterns We See Every Engagement

Functional roles bleeding into account roles. Default warehouses with too much grant. The pattern that lets a BI tool read your billing tables. A practical walk-through.

SnowflakeDataRBAC
· 8 min read

The Agentic Attack Surface: Why Your Permission Model Wasn't Built for This

An LLM agent calling tools is not a user. Treating it like one is how data leaves the building.

PentestAgentic AIMCP
Take the next step

Innovate without technical debt.

A one-hour discovery call. We map your stack, surface the bleed, and tell you exactly what Stop-Drop-Roll-Out would touch first. No deck. No sales engineer.