AI, LLMs, and applied ML.
Senior-engineer field notes on AI, LLMs, agents, and applied machine learning by Ercan Ermis.
All posts
M365 Security 101: AI Pilot and Business Impact Reports
Where AI earns its place in security: remediation behind a per-change approval gate, and reports leadership can act on. A 101 with Aether365 as the example.
Agents on Call, Part 6. Guardrails: The Part Everyone Skips
Threat model, then guardrails: Bedrock Guardrails in Terraform, why IAM still does the heavy lifting, and the failure modes nobody demos on stage.
Trust the Model, Audit the Binary
A coding agent's client is the most privileged binary on your machine. Claude Code's hidden prompt fingerprint shows why you audit it, not trust it.
AWS Monthly (June '26): Agents Get a Feedback Loop
June 2026 on AWS: the Summit in New York turned production traces into agent improvement, shipped Continuum for security, and took the AgentCore harness to GA.
Agents on Call, Part 5. The Team: Supervisor and Three Specialists
A supervisor delegates to triage, runbook, and cost agents over the network, AgentCore Memory ties their findings together, and when one agent still wins.
AWS Built a Sandbox for AI-Generated Code: Lambda MicroVMs
AWS Lambda MicroVMs give AI agents a place to run model-generated code, isolated at the VM level. The missing piece for production agents was the runtime.
Your Multi-Agent System's Real Limit Is Tokens Per Minute
Amazon Bedrock now exposes per-model tokens-per-minute quotas in Service Quotas. For agents, TPM is the real scaling ceiling. Plan for it before the 429s start.
Estonia Is Giving AI Agents an ID. That Is the Easy Part
Estonia plans to issue AI ID codes to AI agents, a world first. The identity is the easy part: authority, delegation, and accountability are the real work.
Le Chaton Fat: The Fattest AI Model That Never Existed
There is no AI model called Le Chaton Fat. No weights, no API, no benchmark. Here is how a Mistral cat joke became the AI community's favourite running gag.
Agents on Call, Part 4. Tools and the Gateway: MCP, Allowlists, Read-Only Default
Tools move behind AgentCore Gateway: scoped Lambdas, cross-account read-only roles, and the one gated path that is allowed to change anything.
More from Ercan
Two more sites, same author, different ground.
Cloud, AWS, EKS, Terraform, platform engineering.
Field notes from production systems. EKS, IAM, Terraform at organization scale, observability, cost optimization.
Visit ercan.cloud →The hub. About, consulting, contact.
Personal hub for both writing tracks. Who I am, how the consulting works, how to reach me.
Visit ercanermis.com →