Institute the inspectable-function rule for AI data access as company-wide hygiene - and refuse to make it either a shared library or retroactive
Situation
At the Friday AI Committee, Peter re-delivered the rule he had set once before and watched not land. He used Mini-Me as the worked example: AI helped create the capability, but AI is not part of the runtime function of accessing the repositories. Claude cannot get to Slack except through that function. It does not have the keys. He asked for exactly one thing - if you are pulling data in or out of a CIQ system, do it through a function that you write and could inspect - and explicitly declined two obvious extensions. He would not make it a shared implementation, because there is no value in building a library of these things and because forcing an MCP server would block people from experimenting with technology being stood up today. He would not apply it retroactively, because a year from now we are going to have 100 times as many tools running around the company, so he is way more worried about the giant tsunami of stuff that is coming. He named three reasons rather than one: inspectability, 100 percent repeatability, and teaching the company the right pattern, since Claude is going to make everybody at the company a developer and that is incredibly terrifying if we do not teach people to be better developers. He extended the bar to local models when asked, and licensed Michelle to publish the message with his name attached.
Reasoning
The rule is a bet about scale rather than about any current incident. Peter is not defending against a leak that happened; he is pricing what happens when a hundred non-engineers each wire an off-the-shelf connector into a system of record. The mechanism he constrains is the one that cannot be reviewed - a model deciding at runtime what to pull - and he leaves everything else free, because the exploration is the thing he actually wants and a centralised guardrail would kill it. He also had to spend some of his own accumulated permission here: he knows people invoke his name to bypass Michelle, said so out loud, and offered to go talk to the company directly to make clear that this is not a roadblock. Choosing to demonstrate from his own tool rather than assert a policy is deliberate - it makes the bar concrete and provably achievable rather than aspirational.
Additional Context
This was the explicit tomorrow-focus item from the 2026-07-30 reflection: the first delivery of this rule had failed silently and the test was whether anyone could repeat it back. It landed. Ryan Smith volunteered to be the guinea pig on company tooling in the same meeting, and by Aug 5 had filed CUSP-3473 turning it into a Customer Engineering department standard with Mission Control and butler-go as reference implementations - which is repetition back, in the strongest available form. Michelle also surfaced the second-order problem Peter created for her: people cite his laissez-faire stance to avoid review.
Observed Evidence
Direct transcript quotes across a 14-minute stretch of the AI Committee, plus his own follow-up in #announcements the same evening and again on Aug 3. Confirmed downstream by Ryan Smith filing CUSP-3473 on Aug 5 which cites the policy date and reproduces the three pillars back verbatim - inspectability, repeatability, safety.
Matching Patterns
Confidence Breakdown
Reasoning Depth Analysis
People Involved
Source
reflection
AI Confidence
97%
Related Context
fathom
my ask is that if you are pulling data in or out of a CIQ system, just do it through a function that you write. The AI is super capable of doing that. ... Claude cannot get to Slack, except through that function. It does not have the keys.
slack
The key is repeatabilty. If your agent is calling a function that you can inspect, you KNOW what is going in/out of that data source. If the AI has direct access to a connector - it can do what it wants in the moment.
slack
constrain the data returned by different queries to only the columns you need. And remove write abilities you do not need. ... instead of having a generic function that does it have specific, hard coded functions that take a hard coded list of inputs. Then the llm cannot decide to do more than you intend.
Outcome
Held under pressure - extended unchanged to two new AI systems on 2026-08-15 with no policy fork and no per-system approval
Rating: 4/5
Decision ID: 7afc2f64-09c4-41d1-a7b9-323c551164d0