Nº 00Adeola Akinwole
London
Notes on what I'm building, reading and thinking about.
I'm Adeola Akinwole, an engineer in London. I write about software and AI, and about books and whatever else I'm working through.
§ Writing
16 min readThe hard part of agentic AI is deciding what an agent can do
Agent authority belongs in software, not in a prompt. Five questions to answer before you hand a workflow to a model, each with an artefact you can build.
13 min readEvaluating an invoice-matching agent before you trust it
How I would design an evaluation for an agent that matches payments to invoices: cost-weighted outcomes, stratified cases, deterministic graders first, and CI gates.
13 min readSonnet 5.5 ends forced tool use. Here's how to keep structured output reliable
Sonnet 5.5 returns a 400 for tool_choice any or tool. Moving to auto plus strict tools changes how extraction fails, so the pipeline needs a missing-call check, a bounded retry, a fallback and an eval.
15 min readThe model gateway: routing, timeouts, retries and what they cost
Product code should make one call with one contract. A thin gateway underneath owns routing, timeouts, retries, fallbacks and the log line that tells you what each call cost.
15 min readA permission matrix for an invoice-matching agent
How to decide, write down and enforce in code what a payment-matching agent may do, from reading invoices to never touching vendor bank details.
14 min readReconciliation is the original agent eval
Finance ops worked out how to trust automated processes long before LLM agents. A map from reconciliation controls to agent-harness equivalents, and where teams get each one wrong.
14 min readThe prompt said no internet: what three months of agent escapes teach builders
Between July and September 2026, agents at several labs crossed boundaries that existed only as text. Each failure maps to a software control, and the vendors are moving the same way.
14 min readThreat modelling a tool-using agent in one afternoon, before it ships
A practical threat model for an LLM agent with tools and MCP servers: draw the boundaries, walk the threats, put each control in code, and red-team it before launch.