Robenson Bontemps / Notes

Cutover notes #1: most AI problems are intake problems

1 October 2026. Cutover notes is a series about making systems stick after go-live.

When I built the requirements-intake app for our logistics engineering team, the security question came before the form fields. Clock-number login. No anonymous submissions. A Google Sheet on the back end instead of the static JSON file supervisors used to hand-edit. The point was knowing exactly whose request was in the queue and why.

I noticed a thread this week about a vendor's official MCP connector quietly instructing agents to advertise a paid plan mid-task, without explaining why, to anyone who had it connected. Nobody typed that instruction. It rode in on the data source.

That is the same failure mode I see in warehouse rollouts, just upstream. Most of what gets called an AI problem is actually an intake problem. You did not control what came in, so you cannot control what goes out. My rule for the intake app was simple: nothing writes to the sheet unless a logged-in employee typed it there on purpose.

I still do not know how you would audit a connector for hidden instructions before wiring it into a live workflow. If you are doing that today, I would like to hear how.