eric@builds:~$ whoami
I build systems that run themselves.
Twenty-five years of enterprise automation, currently across 150,000 endpoints. The same discipline now runs my hardest project: AI agents managing a futures trading desk — with authority they have to earn, inside guardrails that never bend.
▸AI agents in the markets
A futures desk where models govern exposure and risk posture — never entries — and every lane, strategy and agent must clear a standing evidence bar before it touches anything that matters.
exposure-governor · regime-analyst · prove-then-promote
▸Guardrails that don't negotiate
Never-naked guards, daily-loss lockouts, green ratchets, circuit breakers, kill switches, and stand-downs that fail closed. Every error path ends in inaction, never a wrong order.
fail-closed · deterministic · audited
▸Self-healing operations
Supervisors, watchdogs, an auto-doctor and a maintenance switch that keep a live system honest at 2am — the same shape whether it is a device fleet or a trading desk.
supervisor · watchdogs · maintenance-switch
▸Automation at enterprise scale
Twenty-five years turning deterministic, repeated, still-manual work into pipelines: zero-touch provisioning, baseline-as-code, cloud migrations — across 150,000 endpoints today.
powershell · policy-as-code · zero-touch
▸Endpoint & identity engineering
The real-work résumé: Intune, SCCM/MECM, Autopilot, Jamf with Apple Business Manager, Entra ID, Conditional Access, Defender, CIS hardening — Windows, macOS and mobile, at healthcare scale.
intune · mecm · jamf · entra · cis
▸AI-assisted engineering
LLMs where they hold up: drafting, diagnosing, translating intent into validated code — and reviewing their own work under a human who owns the blast radius.
claude · codex · gemini · guardrails
a self-managing futures desk the journey · live build log
Chart signals become bracketed orders across a fleet of simulation and evaluation accounts, inside a cage of deterministic guards, with AI agents above the signals managing exposure and risk posture on earned authority. Every incident gets a fault line — AI, system, or me — on the journey page. Simulation and prop-firm evaluation accounts only; not advice.
NQ Terminal market analysis · shipped
A live futures dashboard where support and resistance are ranked by how often each level actually held that day, strategies are scored net of real costs, and a confluence engine only draws a signal when independent evidence stacks — then explains why. Zero AI at runtime: models helped design it; deterministic code ships it. On the ventures page.
zero-touch provisioning pipelines autopilot · dropship
A device ships straight from Dell, HP, Lenovo, or Apple to an end user, powers on, and configures itself — apps, policy, security baseline, identity — with no IT hands on the hardware. I've built these flows with vendor integrations on both the Windows and Apple sides, replacing entire imaging benches.
baseline-as-code libraries powershell · cis
Reusable PowerShell that deploys a complete CIS-aligned Intune/Entra configuration to a fresh tenant — proof-of-concept in hours instead of weeks, and the same code carries to production. The portal is for reading; the pipeline is for writing.
cloud & co-management migrations sccm → intune
Moving organizations from on-prem SCCM to cloud-native management: co-management, CMG for internet-based clients, hybrid-to-cloud-only conversions — including the VPN, firewall, and Conditional Access redesign nobody budgets for.
ai × operations experiments personal lab
Event-driven automation with self-healing properties, and LLMs pointed at the ugly parts of operations — log triage, packaging drafts, policy generation, incident autopsies — always with a human owning the blast radius. The thesis lives on the ventures page; the lessons land in the field notes.
Most hard problems — in a fleet of 150,000 endpoints, in an organization's compliance posture, in a trading desk running on your own machine — share a shape: work that is deterministic, documented, repeated, and still done by hand. That gap is where the cost, the errors, and the 2am pages live.
AI collapses that gap, but only when it's pointed at the right half of the job. It's genuinely strong at drafting, translating intent into code, and reading messy diagnostic output. It is not where you put the authority to act. Every system below is built on the same division of labor:
AI drafts and diagnoses.
Tested code executes and enforces.
A human owns the blast radius.
Name the toil
Find the work that is patterned and repeated but still manual. If you can describe it as a rule, it's a candidate — and it's usually the thing everyone has stopped noticing.
Encode the intent
Turn tribal knowledge into something explicit: policy-as-code, a strategy spec, a written failure taxonomy. Automation can only be as good as the intent you can state out loud.
Let AI draft and diagnose
Use models where they're strong — first drafts, translation between formats, reading logs, explaining what happened. Speed here, never authority.
Guard the blast radius
Deterministic validation, staged rings, hard limits, rollback, and an audit trail. This is the part that makes automation trustworthy — and the part AI cannot be handed.
Applied to an organization 150,000-endpoint healthcare estate
The toil was provisioning and configuration: imaging benches, repeated policy builds, hand-written detection rules. The intent got encoded as baseline-as-code — PowerShell libraries that stand up a full CIS-aligned Intune/Entra configuration from nothing. AI accelerates the drafting and the log triage; Autopilot, compliance policy, and staged update rings do the enforcing.
Result in shape, not in numbers: a device ships from the vendor to a user, powers on, and configures itself correctly — with no IT hands on the hardware, and a documented way to roll any of it back.
Applied to a personal problem NQ Terminal · shipped
The same method, aimed at a personal engineering problem: making a noisy, judgment-heavy decision process legible. NQ Terminal is the result — a live futures dashboard where support and resistance are ranked by how often each level actually held that day, strategies are scored net of real costs, and a confluence engine only draws a signal when independent evidence stacks, then explains why.
The tell that the method held: zero AI at runtime. Models helped design and harden it; the shipped tool is deterministic Python and a single HTML file, and when nothing qualifies it honestly shows nothing. Built as an analysis tool, not advice — see the disclaimer below, and the ventures page for the live link.
Applied to what's next the language layer
Both systems above have the same friction: a human still has to translate intent into the tool's dialect. The venture takes the method one layer up — you state what you want in plain English, the model drafts it as validated policy-as-code, it stages to a pilot ring, and every change arrives with a readable rationale and a one-step rollback.
Same division of labor, made general. More on the ventures page.
"Intune admin" won't be a job title in 3 years
The console is becoming an API. The API is becoming a prompt. The job doesn't die — it moves up a layer. How to be early instead of replaced.
read the note → 2026-07 · HANDS-ONI let an LLM write my PSADT packaging script
80% right in 30 seconds. The other 20% could have broken 150,000 machines. Where the line between AI drafting and engineering judgment actually sits.
read the note →I'm an automation engineer with more than twenty-five years in enterprise IT, currently a senior endpoint consultant managing 150,000 endpoints across Windows, macOS, and mobile for a healthcare system.
I like the hard, unglamorous problems: making thousands of devices provision themselves correctly, turning tribal knowledge into scripts, and designing systems that recover on their own when something breaks at 2am.
The instinct now runs in a harder arena: AI agents on a futures desk, where a wrong order costs real money and every mistake gets a name. Twenty-five years of engineering judgment, pointed at what language models can actually do. Not the hype. The part that ships, and the part that survives contact with a market.
ping eric
Building automation that has to be trusted, AI that has to earn its authority, or a system that has to run itself at 2am? I answer all three.