惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
T
Threatpost
T
Tor Project blog
S
Schneier on Security
Project Zero
Project Zero
Know Your Adversary
Know Your Adversary
P
Proofpoint News Feed
K
Kaspersky official blog
P
Privacy International News Feed
Latest news
Latest news
Cisco Talos Blog
Cisco Talos Blog
T
The Exploit Database - CXSecurity.com
The Hacker News
The Hacker News
D
Docker
aimingoo的专栏
aimingoo的专栏
S
Securelist
C
Cyber Attacks, Cyber Crime and Cyber Security
Spread Privacy
Spread Privacy
TaoSecurity Blog
TaoSecurity Blog
T
The Blog of Author Tim Ferriss
T
Threat Research - Cisco Blogs
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
Security Latest
Security Latest
V
Visual Studio Blog
WordPress大学
WordPress大学
J
Java Code Geeks
O
OpenAI News
T
Tailwind CSS Blog
S
Secure Thoughts
G
Google Developers Blog
博客园_首页
The Cloudflare Blog
The Register - Security
The Register - Security
A
Arctic Wolf
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
B
Blog RSS Feed
IT之家
IT之家
美团技术团队
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
G
GRAHAM CLULEY
S
Security Affairs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Application and Cybersecurity Blog
Application and Cybersecurity Blog
P
Palo Alto Networks Blog
C
CERT Recently Published Vulnerability Notes
W
WeLiveSecurity

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Two Doors, One Gate: Navigating Governance Beyond EDD
karl-heinz reichel · 2026-06-28 · via DEV Community

Two Doors, One Gate

Onboarding guardrails and power-user friction look like the same problem. They aren't.

June 2026 · 7 min · Karl-Heinz Reichel

Table of Contents

  • The Setup
  • The Category Error We Already Made Once
  • Two Layers, Not One Document
  • Letting the Data Set the Threshold
  • Accountability Instead of a Badge
  • Closing Thought

A few weeks ago we wrote about why we run AI coding sessions with two developers instead of one. Triplet programming works well as a transitional structure — a way to build shared fluency while the risk of agent-driven, codebase-wide changes is still high.

It does not survive contact with forty developers.

At team scale, you cannot put everyone in a triplet indefinitely, and you should not want to. Some developers arrived at agentic coding only recently. Others are already running skills and multi-agent setups solo and have been for months. The instinct, reasonably, is to write it all down: a CLAUDE.md, a copilot-instructions.md, a shared set of rules — plan before you change code, do not touch files outside the task scope, explain your reasoning before you act.

We tried exactly that. The result was a document that newer developers needed and barely noticed, and that experienced developers read once, in detail, and immediately wanted to relax.

That reaction was not impatience. It was the predictable result of asking one document to do two jobs that don't actually fit together.

The Category Error We Already Made Once

We have actually run into this shape of problem before — just at a different point in the pipeline.

In The Last Mile Problem and again in EDD Closes the Loop — But Only Half of It, we drew a distinction between two kinds of tools that get conflated constantly in AI-assisted development:

Awareness tools change what someone knows. A linting warning, an AI review comment, a suggestion to loop in another team — these work only if the person on the receiving end cares to act on them. We called this the receptionist: it notices, it says something, and whether anyone stops depends entirely on whether they were listening.

Governance tools change what someone can do. Branch protection, required reviewers, a merge gate that simply will not open. This is the turnstile. It does not negotiate.

The mistake worth reaching for here is a receptionist when the situation actually calls for a turnstile — an AI review that correctly flagged a risky interface change, and a developer who merged anyway, because a correct recommendation with no teeth is still just a recommendation.

Writing a single onboarding document for forty developers repeats the same pattern, mirrored. A planning requirement is, by nature, a receptionist: it asks a developer to pause and think before acting. That is exactly the right amount of friction for someone two weeks into agentic coding. For a developer who has been doing this — internalized, automatic, several skills deep — the same instruction is a receptionist stopping someone who already has full clearance, every single time, for no reason connected to actual risk.

Conversely, treating onboarding guardrails as if they were optional — something a confident developer can simply choose to skip — quietly turns governance into awareness for everyone, the moment the most senior person in the room decides the rule doesn't apply to them today.

One document was being asked to do two jobs it cannot do at the same time.

Two Layers, Not One Document

Once you see it this way, the fix follows the same shape we landed on for the merge gate: keep awareness and governance as genuinely separate layers, not as two paragraphs in the same file.

The governance layer stays small, repository-bound, and identical for everyone. No direct pushes to protected branches. No changes outside the declared task scope. Mandatory review before merge. This layer is not calibrated to skill — it is calibrated to blast radius, and an agent's blast radius does not shrink because the developer steering it is experienced. It lives in version control, travels with the repository regardless of whose machine it runs on, and is enforced structurally — branch protection, CI gates, CODEOWNERS — not just requested in a prompt. A senior developer cannot read past it any more than a new one can, and that is the point: it was never about trust in the first place.

The scaffolding layer is personal, and it is allowed to shrink. Explicit planning before a change. A second person in the loop. Verbose reasoning at every step. This is the receptionist, deliberately turned up high for someone still building judgment, and deliberately turned down for someone who has already demonstrated it. It belongs to the individual, not the repository — closer to a personal coding profile than a project rule.

The honest reframing for the team is this: the planning step was never really a rule about code. It was an externalized form of judgment a developer hadn't built yet — standing in for the second person in our triplet setup. Once that judgment exists, on its own, the scaffolding has done its job and can step back. That is not an exception being granted. It is the scaffolding successfully making itself unnecessary, which was the actual goal the whole time.

What makes this credible rather than arbitrary is that the path is visible and earnable, not asserted by title or tenure: a developer's track record across actual sessions — no scope violations, sound judgment under review, demonstrated fluency — is what shrinks their scaffolding, not how senior they happen to be on paper.

Letting the Data Set the Threshold

There is a version of this that goes one step further, and it connects back to something we have written about from the other direction.

Skill-level is one axis. It is not the only one that matters. A confident, fast-graduated developer touching a file that has never been part of anything risky is a low-stakes event regardless of who they are. The same developer touching a file that — according to the repository's own history — has repeatedly co-changed with code three other teams depend on is a different situation entirely, independent of their tier.

This is exactly the signal we described in the last-mile and EDD pieces: change coupling derived from actual commit history, not from someone's static opinion about which files are "important." A newcomer editing an isolated utility function does not need the full weight of scaffolding just because their tier says so. An experienced developer touching a highly coupled interface should not sail through frictionless just because their tier says so either.

In other words, the threshold for how much governance or scaffolding applies to a given change can be informed by two inputs at once — who is making the change, and what the change actually touches, according to the codebase's own coupling history — rather than skill-level alone. That keeps the gate honest in both directions: it does not punish a careful newcomer working in a quiet corner of the code, and it does not wave through a confident developer standing at a boundary the repository's history says has never been a purely local decision.

This integration is not built yet. It is the natural next step once you accept that "who is this developer" and "what does this change actually risk" are two different questions, and that only one of them is about the person.

Accountability Instead of a Badge

There is a way to sidestep the tiering problem almost entirely — and it starts from a different question. Instead of asking how skilled is this developer, ask who owns this change.

The answer doesn't change because an agent wrote the diff. "The AI did it" is not a defense for a bug any more than "the linter passed" ever was. The developer opening the pull request owns what's in it, and there is a simple test for whether that ownership is real: can they explain, in review, what the change does and why — without falling back on the agent's own explanation of itself? If they can't, the patch doesn't merge. Not as a verdict on the developer's general competence, but as confirmation that the editor role EDD describes has actually been exercised for this specific change, not merely rubber-stamped.

This works precisely because it requires no advance categorization of anyone. It is the same rule for the new hire and the ten-year veteran, applied after the fact to the change itself rather than in advance to the person. Combined with approval-required branch protection already in place via CI/CD, it is a turnstile in the proper sense — not a suggestion that explainability would be nice, but a condition the change cannot pass without.

What this rule doesn't do is tell a developer how to get to the point of being able to explain a change with confidence when they're not yet sure. That is where scaffolding still earns its place — just offered differently than a tier assigned at onboarding. Rather than the system deciding in advance who needs the planning ritual and who doesn't, the developer decides, per task, whether to invoke it: a "safer mode" — a skill or flag that constrains the agent to the explicitly declared scope and asks before touching anything adjacent — that anyone can reach for, for a single task, without it being a statement about their standing.

That reframing matters more than it looks. A tier assigned at onboarding is a status. A safer mode invoked for one afternoon because today's change touches unfamiliar territory is a tool. The first labels a person. The second describes a moment — and senior developers reach for it too, on the parts of the codebase they don't know well, which is exactly when they should.

The design work from the earlier sections doesn't disappear — someone still has to define what "safer mode" actually constrains, and what change-coupling risk should trigger heavier review regardless of who's making the change. What shifts is who decides when to use it, and the explainability gate at the end makes that choice consequential either way: skip the safer mode on an unfamiliar change, and the gap shows up in review, not three weeks later in production.

Closing Thought

The pattern underneath both of these stories — the merge gate and the onboarding document — is the same one: awareness and governance solve different problems, and a tool built for one quietly fails when asked to do the job of the other, often without announcing that it has failed. We caught it once at the point where code meets the repository. It was waiting at the point where a developer meets the agent for the first time, too.

The fix in both places turns out to be the same shape: keep the governance layer small, universal, and non-negotiable — ownership and explainability, enforced at merge, regardless of who you are — and let the awareness layer be something people choose for themselves, task by task, rather than something assigned to them once and carried as a label.


This post extends earlier pieces on the last mile problem in AI-assisted development and why EDD closes only half the loop, and follows on from why we structure development in threes.