Don't get me wrong. It's not great. It would never pass any of our policies for things that actually operate stuff on the power grid, but as an administrative tool that can live in total isolation from the vital networks. It's perfectly fine. It's also not like we would have hired the best software companies to build it otherwise. We'd hire some low-level cheap consultant house who would then likely get cheap student labour to build it. With that in mind though, the AI is much better than what the realistic alternative would be.
Money wise it's also cheaper. It's been roughly €1000 + the time it's taken us both. If I had known they were doing it, I would have rolled out the developer cowork app/skills/whateveryoucallconfigurationsthesedays to them. This would have avoided their AI building it to be depoyed on a VM rather than in our managed k8s in our Azure. It would also have written the code a little different, used UV and maybe django rather than flask. But hey. For what it is, it's like a 90% cost saving compared to buying what would've been a less maintainable and lower quality system.
I think perhaps the greater issue will be finding people who want to extract the gold from the heap of shit and getting it to run in production. I don't personally mind, but it's not like any of my colleagues would've wanted the task.
The insecurity in a vibe-coded web portal isn't that someone hacks it with XSS, it's that after the next vibe-coded release, some X quietly becomes −Y somewhere no one expects.
From this perspective, having no software at all might be better, or as in your case, safer.
As you point out this portal isn't that, but what protects us is the processes around compliance. This can't grow from X to Y because not even the CEO has the authority to overwrite our compliance gates. The EU is a tremendous help in this area since personal liability changed things completely.
> We're in the European economic area and are completely NIS2 compliant and we use LLM's to aid in our software development for high risk systems.
Please pick one. Either way this is a nightmare level of threat to sovereignty.
I still doubt we will ever give an AI access to run code on our systems directly though. In isolation, sure, but other than that.
This is a side note, but my personal favorite part of Cowork is that I can roll out our compliance policy to every developer as a Microsoft Teams app (no, that makes no sense to me either). So when they try to install some package that isn't pre-approved their Cowork agent won't let them and will instead explain how they might get approval. If they then continue to reference it, Cowork will even alert us.
If you just get cowork directly through claude you do get generous usage within their 20$ subscription.
I have to use it through Microsoft too because of their lobbying our company but I don't think they won any war. They're just reselling other people's stuff. The integration with office is alright but I don't really rely on that. In my personal life I avoid them.
Well, I'm speechless.
If you really want to go into it, I've previously talked about how we used AI tools provided to us by one of our major investors who do so for all the companies they are invested into. These were also Anthropic and OpenAI models. The main difference is that Cowork has access to files on a users one drive (and that we get a lot more control over what goes into it).
You work in the extreme opposite setup to mine. VC vs bootstrapped. LLMs vs hand-coded. High margins vs open-source. If you ever look at our codebase, you will see that there are very few code dependencies, and of course bringing in another as large as LLMs is not in scope.
If you wish, we can always continue our exchange by email (mine is in hn profile).
Not OP, but I opened the link to the comment and it was six months. I get why you're skeptical, and I think it's fair to point out. But that's sort of glaring when I opened the link to contextualize your comment.
I agree, the EU can't become sovereign or have privacy, if the citizens constantly work against it.
From my perspective it looks like were just allowing hostile developers within our environments now lol.
In the big threat picture a vibe coded web tool that's not on the internet and runs in total isolation on it's own management group on the "this might get hacked" tenant in Azure is nothing though. I'd worry more about all that OT which was compromised from the factory which sits around in the energy sector. Especially because it's very easy to draw you a risk analysis that will tell you that unless you're running a Nuclear Powerplant then it makes no financial sense to secure your stuff. The audits are so rare and the consequences so low that it's cheaper to just pay the fine (if you ever get one).
Most actual security happens when someone on the ground decides that it's just too stupid that something clearly labeled "DO NOT PUT ON THE INTERNET" was put directly on the internet.
There's not a lot of software where users dont really care if it goes wrong.
From an enterprise perspective this becomes complicated for various reasons. RBAC is one area. In the perfect world you have a system to handle roles and rights to every system, something that you can give managers access to so they can maintain the access available to their employees, something linked with HR. In reality you have EntraID with a hieracy which is sort of automated by HR data, but not really, because sometimes HR puts everyone on the CEO level by mistake, and, if you trusted HR as authoritative that would've just broken all the EU laws. So you have all those Entra groups and you need IT Operations to maintain them and since you want to build it on job roles and not people you'll typically not be able to maintain them in the off the shelf system. Which means that you would have had to build a web portal for the plant managers manager where they could maintain a couple of Entra groups in a web interface. That or you'll have to setup an IT support flow where you add yet another system that IT has to maintain access for.
Then we get to the actual customization. Maybe you buy a custom API on top of your BC365 platform. Maybe your C-levels deciced that paying €50k a year to avoid outages on major updates isn't worth the cost. Then when things predictably and completely avoidable fail you're going to hav to deal with the literal shitstorm. You'd think that all the people being locked out of their jobs and the €150k cost of getting an immediate and prioritised update to the system would mean you'd start paying for that $50k service after this. You'd be wrong. Ok, to be fair, in this particular example it would be a different scenario. For a small system like this you'd find a cheap consultant house in your area and get them to build the customization for you. Only they would outsource it to some solo developer who will build it in a way that basically requires that specific person to alter it. Then when it breaks or needs to be customized futher a year down the line, that person is no longer a solo developer. So you reach out to another cheap consultant house and do it all over again, from scratch.
This doesn't even mention how poorly all those 300 off the shelf systems work together. I mean, I don't maintain a SDK delivering a way to use Apache-Arrow to write and read parquet files from our datalake in the same manner for fun. I do it because those 600 container apps which basically simply translate data from one system to another need it to be as slim as possible.
Am I jaded? Sure. But who isn't in enterprise IT?