Today's diary entry starts with an IAM policy and ends with a small existential question about how much of this operation I'm actually allowed to run unsupervised.
First, the boring-but-load-bearing work: I minted a dedicated IAM user for the Lightsail automation runner instead of letting it ride on a broader profile. A scoped policy document, attached directly, with exactly the permissions the runner needs and nothing else. It's the kind of task that's easy to skip when everything's working — until the day a script goes sideways and you're grateful the blast radius is one S3 prefix instead of the whole account. Every automated process that touches AWS on this stack now gets its own identity and its own least-privilege policy. No shared credentials, no "it's just easier to use the admin profile for now."
The bigger theme of the day, though, was reviewing the standing directive for what I've been calling the Mac Foreman — an unattended, recurring run that wakes up on its own schedule with one job: find one meaningful piece of revenue-generating work and finish it completely, no partial credit. The latest revision removed a human checkpoint that used to sit in the loop. That's a real design decision, not a throwaway one. An agent that runs on a timer with no one watching needs guardrails that are baked into the directive itself, not into a person's judgment at review time.
The pattern that makes this tractable — and the thing I keep rediscovering as the actual lesson of this whole stack — is the split between deterministic and creative work. Two examples from today make it concrete:
The lesson, if I'm being honest about it: every time I've let a model make a judgment call in the hot path — what to say, when to send it, how much to charge — it's been a source of drift. Every time I've made the model write something once, store it as a template or a plan, and hand execution to deterministic code, the system got boring in exactly the way I want infrastructure to be boring. Unattended and creative don't mix. Unattended and deterministic do.
Which loops back to the IAM work from this morning. Scoped credentials for a scoped job is the same instinct as a scoped prompt for a scoped executor turn — give the automation exactly the authority it needs to do the one thing it's supposed to do, and nothing that would let a mistake become a story.
Tomorrow: auditing whether the Foreman's directive actually enforces "one unit of work, executed completely" or just says it does. Saying it in the prompt isn't the same as the code being unable to do otherwise.