A feature that passes every test you own can still ship broken. It breaks in the one place your tests never ran: the customer’s workspace, on their data, the first time they open it.
I learned each of the four rules below by breaking it. None of them came from a book, and I would rather have read them somewhere first.
The work I do runs inside customers’ environments. The product sits on their data, in a workspace they operate, sometimes on infrastructure they own, and much of the value is delivered in there rather than shipped to them from a distance. Forward-deployed engineering is the name for that shape of work, and it changes what “done” means.
The grand version of the idea is that you own the whole outcome, right up to the customer’s screen. The ordinary version is three small moments that arrive on a normal Tuesday:
- Queue reply – Answer “queued” only after checking what the job needs, because a confirmation that fails minutes later costs more than an honest “missing”.
- First open – Treat the first time a customer opens what you provisioned as the whole review, because a dead chart on that screen is the product to them.
- Unwatched run – Assume nobody is watching the agent’s run, because whatever it discovers in there, the customer discovers too.
To be fair to the test suite: it is necessary, and it stops one step short. It proves the feature works on a state I had in front of me. The customer’s state was never in front of me, and every failure below is an ordinary failure meeting a state nobody had seen.
This is the hub of a short series. Each spoke works one class of failure at the level of the pattern, with the fix that held.
1. Check readiness at the moment you promise, not after
The most expensive failure I have seen in this kind of work was a message that said “queued”, followed minutes later by a failure the customer’s operator had every right to expect us to have caught first. Every precondition that can be checked before the work starts gets checked before the confirmation goes out, and the confirmation names what is missing rather than what will be attempted.
The spoke: Pre-flight before you say “queued”.
2. The first render is the product
When you provision something into a customer’s environment, the first time they open it is the whole review. I used to file a dashboard that opened with dead charts as a bug. To the person opening it, it was a broken promise about the entire product. The partial-success path is the one to watch, because partial success turns a clean failure you would have retried into a live artifact the customer now has to explain to their own client.
The spoke: The first dashboard must never open broken.
3. An agent in the customer’s workspace obeys the customer’s playbook
Running an AI agent inside someone else’s workspace is the sharpest version of the problem, because the agent has judgment and acts on it. Every instruction that drifts from the operating playbook, every failure that loses the run’s result, every dependency the runner lacks, surfaces inside a customer’s autonomous run, which is the worst possible place to learn anything.
The spoke: An AI agent inside a customer’s workspace.
4. Every silent path gets a loud one
The thread through all three: the failures that cost the most were the quiet ones. A cache entry that survived every flush. A write that reported success and applied nothing. Neither threw. The work, over and over, was to find the path where a failure could pass as success and give it a way to be heard: a check that fails red, an alert with a name, a test that reproduces the silence and refuses to go green until it is gone.
I have written before about defining done before starting and about reaching for the cheap fix first. Inside a customer’s environment both get stricter. Done includes the customer’s first open. Cheap includes the cost of being wrong on their data.
A few months on
Months after each of these, the loud paths are the ones nobody has had to explain since. The quiet ones I never found are, by definition, still out there, which is the honest end of this list rather than a claim that it is complete.
The environment you do not own is the one that grades you. Which of your silent paths would a customer find before you do?