Home / Blog
Kinetic Gain
Field notes, the mechanism, not the marketing.
First-hand teardowns of the systems we run: what broke, what the fix actually was, and the evidence behind it.
Pillars
By question
PillarAI Governance & EvidenceControl planes, tamper-evident audit streams, and cryptographic attestation. Governance as posture and signed evidence, not slideware.PillarCloud Identity & FinOpsAccess governance, privilege drift, secrets, and cloud spend, one defensible answer per question, for the two people who sign off on it.PillarWebOps & PlatformStatic generation, crawl budget, Core Web Vitals, and the line between a defensible directory and scaled spam, the platform work that makes content findable, done first-hand.PillarSearch & AI VisibilityAI Overviews, ChatGPT, and Perplexity run on the same ranking systems plus retrieval, citation follows genuine helpfulness, not llms.txt tricks or schema hacks. The operator's view, minus the snakeoil.
All posts
Latest
cornerstone · AI Governance & EvidenceWhat a Governed Control Plane Actually Looks LikeAn AI control plane decides what your AI systems may do, routes their requests, and records what happened. A governed one adds machine-readable capability declaration, regulatory classification, and verifiable evidence.spoke · AI Governance & EvidenceTamper-Evident Audit Logs: Why Signed Beats LoggedA tamper-evident audit log proves it has not been altered instead of asking you to trust it. How a hash chain makes tampering detectable, what an ed25519 signature adds, and why 'verify it yourself' beats 'trust our logs'.spoke · AI Governance & EvidenceAI Capability Declaration: A Manifest Your Build Can CheckAI capability declaration is a machine-readable manifest of what each agent, tool, and model may do, its inputs, outputs, permissions, and the data it touches. Why prose policy drifts, how a declared manifest fails the build instead, and how it composes with MCP.spoke · AI Governance & EvidenceClassifying AI Systems Under the EU AI ActThe EU AI Act sorts AI systems into four risk tiers, unacceptable, high, limited, and minimal, and the obligations follow the tier. What the tiers are, how a system gets classified by its use, and why classification should be a property of the system rather than a spreadsheet.spoke · Cloud Identity & FinOpsCloud Cost Optimization: The Levers That Actually Move SpendCloud cost optimization is the ongoing practice of matching cloud spend to the value it delivers. The durable levers, rightsizing, commitments, idle elimination, and a FinOps operating rhythm, and why it is a practice, not a cleanup.spoke · Cloud Identity & FinOpsIdentity Governance and Administration (IGA), Without the Acronym SoupIdentity governance and administration (IGA) ensures the right identities have the right access to the right resources, and can prove it. What IGA covers, why it is hard at scale, and what a defensible program produces.spoke · Cloud Identity & FinOpsSecrets Management: Storing the Keys to EverythingSecrets management is how an organization stores, distributes, rotates, and audits the credentials that grant access to systems. What counts as a secret, what good looks like, and how it connects to identity governance.cornerstone · WebOps & PlatformProgrammatic SEO Without Getting PenalizedProgrammatic SEO is generating many pages from structured data. It is legitimate when each page carries real per-entity value, and penalty-bait when it is thin variable-swap at scale, the top enforcement target of 2026. Where the line is, from running a real generated estate.spoke · WebOps & PlatformBuild-Time Rendering vs Client-Side: Which Wins for SEOBuild-time rendering ships the crawler finished HTML; client-side rendering ships JavaScript it must execute first. Why pre-rendered HTML is the lower-risk default for SEO, and how a static generator produces it.spoke · WebOps & PlatformCrawl Budget: Why Most of Your URLs Never Get CrawledCrawl budget is how much a search engine will fetch from your site in a given window. On a large site, most URLs are crawled rarely or never. What sets the budget, what wastes it, and how to spend it on the pages that matter.spoke · WebOps & PlatformCore Web Vitals: What They Are and What Actually Moves ThemCore Web Vitals are Google's three user-experience metrics, LCP, INP, and CLS. What each measures, the 'good' thresholds, whether they're a ranking factor, and the first-hand approach to moving them: finished HTML, self-hosted fonts, minimal JavaScript.cornerstone · Search & AI VisibilityHow AI Answer Engines Choose What to CiteAI Overviews, ChatGPT, and Perplexity cite sources by retrieving candidates and ranking them on the same quality systems as search, plus retrieval. There is no separate 'AEO trick' that beats being the best answer. The operator's view of what actually earns citations.spoke · Search & AI VisibilityDoes llms.txt Help You Get Cited by AI? An Honest Answerllms.txt is a proposed file that points AI tools at your key content. There is no controlled evidence it lifts AI citations. What it is, why it's still worth shipping as low-cost hygiene, and why you shouldn't treat it as a growth lever.spoke · Search & AI VisibilityWhat Structured Data Is Actually For (and What It Isn't)Structured data (schema.org / JSON-LD) makes pages eligible for rich results and helps machines parse entities. It is not a proven AI-citation lever, and misused review schema gets pages demoted. Use it accurately for what it does.spoke · Search & AI VisibilityAnswer-First Content: Lead With the Answer, Not the Throat-ClearingAnswer-first content states the answer in the first sentence, then supports it. It's how you win featured snippets and get pulled into AI answers, and it is not the same as fragmenting a page into thin 'LLM chunks'.spoke · AI Governance & EvidenceSigned Deploys: Proving Your Supply Chain Instead of Trusting ItSoftware supply chain security means verifying the artifact you ship and how it was built, not trusting the pipeline. Here is how, with a worked example.spoke · Search & AI VisibilityThe 2026 Self-Promotion Penalty: Why Ranking Yourself #1 BackfiresGoogle's 2026 reviews system demotes sites that publish a "best [category]" list and rank their own product #1. Why it reads as a misleading-evaluation signal, and what to do instead.spoke · WebOps & PlatformReact Server Components and the Phantom-Page TrapPhantom pages are URLs and content a crawler sees wrongly in RSC/App Router sites, stream-deferred words, ?_rsc duplicates, and soft-404s. Here is why, and how to fix it.
The teardown, in your inbox