§ Releases
What shipped, and why it mattered.
A reverse chronological changelog across the projects. Each entry is framed by the value it delivered and the risk it carried, not the diff behind it.
Also here: Incidents · How I work
IncidentsBugs, and what they taught
Blameless postmortems across the products: impact, root cause, fix, and the follow through.
How I workHow I build, start to finish
The operating system behind the products: the cadence behind the work, and the artifacts you can lift and use.
Discover
Get close to the real problem. Talk to the user, scan the alternatives, and name what the thing is not.
→ Research notesDecide
Weigh options in the open and write the tradeoff down, so the reasoning survives the decision.
→ Windchime ADRs → Lichtspiel ADRsShip
Small, validated releases against a checklist. Done means running in the room, not merged.
→ ReleasesLearn
Soak it, let it break, write the blameless postmortem, and fold the fix back into the system.
→ Postmortems◇ From signal to shipped
The same pipeline runs under all three projects, from a raw observation to a shipped, soaked release. Every stage leaves an artifact, and each card names a real one.
Each stage, with a real example
Signal
A problem observed in the room or in the data, not invented at a desk.
Poetic prompts retrieved loosely; visitors read the drift as play.
Frame
A one page PRD lite: problem, goal, what is out of scope, and a success metric stated up front.
Install mode framed as "survives a full day with no operator."
Decide
Options weighed in the open and captured as a decision record.
Retrieval over generation on the audio path, written as an ADR.
Prototype
The smallest real version that can prove the idea wrong.
Voice to stem retrieval running end to end before any polish.
Gate
Nothing ships on trust: typed schemas, validation chains, redaction checks, soak runs.
A 6 hour, 879 visitor synthetic soak before the gallery gets it.
Ship & learn
Releases framed by customer value; failures become blameless postmortems that feed the roadmap.
The audio runaway postmortem became a three layer safety fix.
◆ Shipping cadence
Ingested from 13 repos, most of them private: day level counts plus redacted, truncated subject lines (most research repos give counts only), all through the redaction gate. See the note on the source code.
Hover a day for its commit detail.
◈ Public templates
The same lightweight templates I use at each stage. Click one to open it, take any of them.
PRD lite One page before building anything nontrivial.
# <feature>: PRD lite **Problem**: what's broken, for whom, and why now. **Users / context**: who hits this, how often, in what situation. **Goal**: the one outcome that means success. **Out of scope**: what we are deliberately NOT doing. **Approach**: the shape of the solution (a level up from implementation). **Success metric**: how we'll know, stated before we build. **Risks / unknowns**: what could make this wrong. **Rollout**: how it ships, and how it rolls back.
Decision record (ADR) Capture a judgment call so the reasoning outlives it.
# <decision>: ADR **Status**: proposed | accepted | superseded **Context**: the forces in play; what makes this a real choice. **Options considered**: each with its honest tradeoffs. **Decision**: what we chose. **Rationale**: why this beat the alternatives. **Consequences**: what this makes easy, and what it costs.
Experiment note Keep discovery honest. Hypothesis first.
# <experiment>: note **Hypothesis**: we believe X will cause Y, because Z. **Method**: what we ran, on whom/what, how controlled. **Measured**: the metric(s), defined up front. **Result**: what actually happened (including "nothing"). **Decision**: ship / iterate / drop, and why.
Release checklist Preflight before anything ships.
# Release: <label> - [ ] Tests + typecheck green - [ ] `redact:check` clean (no secrets/hosts leaked) - [ ] Customer value written (not just the diff) - [ ] Known risks noted - [ ] Rollback path exists and is understood - [ ] Changelog / release note updated - [ ] Verified in the real environment, not just locally
Bug report Enough to reproduce and prioritize.
# <bug> **Summary**: one sentence. **Repro**: the shortest reliable steps. **Expected vs actual**: what should happen; what does. **Impact / severity**: who's affected, how badly. **Environment**: where it shows up.
Postmortem Turn an incident into institutional learning, blamelessly.
# <incident>: postmortem **Impact**: what users/experience felt. **Detection**: how we found out. **Response**: what we did, in order. **Root cause**: the real mechanism, not the symptom. **Fix**: what changed, and how we verified it. **Followup actions**: owner + status for each. **Blameless note**: the systemic lesson, not the culprit.
⌘ Building with agents
Every project here, and this site, is built with agentic coding tools in the loop. The practices below are what make that fast without making it careless.
The agent practices
Context before code
Every repo carries a context document an agent must read first: architecture, invariants, privacy hard stops, known hazards.
Persistent memory, curated
Durable notes carry decisions and gotchas across sessions, pruned when stale, because a wrong memory is worse than none.
One mission per session
Each session owns one scoped mission and ends with a handoff note, because context windows are a budget.
Subagents for fanout
Research is delegated to parallel agents with narrow briefs and the privacy rules restated in every prompt.
Gates decide "done", not the agent
Typecheck, build, and a redaction scan define finished; the agent claiming success does not.
Human gated commits
Nothing lands without the owner directing it, because the history itself is a product artifact.
Verification over trust
Visual work gets a browser pass and reliability claims get a soak harness, never a vibe check.
Review loops on agent code
Agent written diffs get adversarial review before landing, the same as any teammate would.
↳ Product & engineering practices
The practices
- A PRD lite with a success metric exists before anything nontrivial gets built.
- Judgment calls are captured as decision records at the moment they are made.
- Typed content and validated schemas everywhere. A broken crosslink fails the build.
- A redaction gate (redact:check) runs before anything privately derived ships.
- Releases are written as customer value, not diffs, against a preflight checklist.
- Incidents get blameless postmortems with tracked followup actions.
- CI installs, typechecks, and builds every change; deploys are automated.
- Issue/PR templates and CODEOWNERS keep the repo itself honest.