notes from the field
Making cloud run itself,
one agent at a time.
Hands-on writing on agentic infrastructure, MCP, and reliability — from someone shipping it in production at a Fortune-500 aviation platform, not theorizing about it. By Ajin Baby.
Right now:
Field notes, by email
Confirm via the email Listmonk sends. Unsubscribe in one click.
Latest field notes
-
Observability for Agents: What You Instrument When the System Decides for Itself
A request either worked or didn't. An agent run can succeed on every span and still be wrong, slow and expensive. What the GenAI conventions ask you to record.
-
Prompt Injection: Why Your Agent Believes the Wrong Text
An LLM sees one stream of tokens, not instructions and data. That is why prompt injection has no parser fix — and why provenance, not filtering, is the control.
-
Token Exchange: Delegation Is Not Impersonation (RFC 8693)
When a service calls another service for a user, the token it carries decides whether your audit log says who acted. RFC 8693 makes that a design choice.
Tools I build in the open
Who's writing this
Ajin Baby — 15 years making cloud platforms reliable, 2x founder before that. Azure AI Engineer, Neo4j Certified, IEEE member. More about me →