Hey, Luca here! Welcome to a new edition of the 💡 Monday Ideas 💡 — ideas and readings to start the week on the right foot.
I also publish an original essay every Wednesday. Here is the one from last week in case you missed it:
🔒 Autonomously secure your software estate!
This week’s newsletter is brought to you by our friends at Blitzy!
Security teams don’t need another list of alerts: they need to know which vulnerabilities are reachable, exposed, and safe to fix!
Blitzy understands your entire software estate and, through Proactive Insights, surfaces known and previously undiscovered vulnerabilities in your codebase, and remediates them autonomously.
It traces each finding through execution paths, identifies dependencies, and validates remediation. Then it turns prioritized risks into batches of tested PRs for engineers to review.
The result is less alert noise, faster remediation, and confidence that each fix is safe. Find risk in context and remediate it securely at enterprise scale!
⚔️ Match quality controls to the risk
Next week I will be in New York to attend the LDX3 conference, which made me think about the best ideas I got from last year’s edition in London.
One that particularly resonates with me, especially now that I work on Tolaria, is about quality controls.
The most common approach to software quality is to treat every change the same. Everything goes through the same QA process, regardless of what it touches or what happens if it fails. This is simple to setup, but it tends to push teams toward one of two bad extremes:
Too much control — every release becomes slow and painful, even when the change is small and reversible.
Too little control — the team moves fast until failures pile up and you end up spending most of your time cleaning up.
At LDX3, Christine Pinto argued that the confidence you need before shipping should be proportional to two things: customer impact and technical risk.
A tiny change with a narrow blast radius does not need the same process as one about payments or critical infra. The farther a change moves up and to the right on those two dimensions, the stronger your evidence should be before you release it.
I also liked Christine’s framing of quality as a maturity journey:
🦸 Crusader — one person champions quality and convinces others that it matters.
🪴 Coach — that person teaches the team and turns individual judgment into shared principles.
🌳 System — those principles become processes that no longer depend on a hero.
The goal is to build the right level of confidence for the risk at hand, then make that judgment part of how the team works all the time. I wrote more about this in the full piece 👇
🎙️ Storytelling is built through reps
When I spoke with Stephanie Wong, Head of Technical Marketing at Google Cloud, she told me that people often ask how she makes explaining complex topics look so natural.
Her answer is not super glamorous: what people see is the result of 10,000+ hours of practice.
Her story is especially useful when it comes to storytelling, because for some reason that’s often treated like a personality trait. Some people supposedly have it, while engineers who struggle to explain their work assume they are simply not storytellers.
Instead, Stephanie’s method looks much more like product development:
Understand the audience — know what they need and give them something concrete and hands-on.
Iterate — move through ideation, prototyping, testing, and releasing, like you would do for a product, instead of waiting for the perfect explanation.
Stay consistent and authentic — always bring your own perspective, then learn from what lands and what does not.
Technical audiences are particularly wary of fluff. Credibility comes from knowing the subject, but relatability also matters, and that comes from making your personal take visible. You need both.
So, don’t wait until you feel naturally good at communication: explain one thing, notice where people get confused, rewrite it, and tell the story again. Over time, the rough edges disappear and the result starts to feel effortless.
Natural is a feeling the audience should have, but on your side, it is reps!
You can find the full conversation with Stephanie here 👇
📚 Weekly Readings
Finally, here are the best articles I have read this week:
🥇 Breaking Claude Code Opus 5 Auto Mode
9 min • by Johann Rehberger
A reminder that even the most powerful models are still extremely vulnerable. A website asks Claude Code to summarize some content, nudges it from WebFetch to curl, and then turns the model’s own Python decoder into an exploit. Food for thought if your agents are touching untrusted content.
🥈 Selling Out
15 min • by Sean Goedecke
Sean’s title is provocative, but the thesis is very important: professionalism is a role, and playing it well doesn’t have to consume your life. Everyone chooses how much integrity to trade for wealth and career success, and that’s mostly ok, things are not black or white. A sharp essay about work and personal identity.
🥉 Small Models Have Arrived
3 min • by Calvin French-Owen
We spend so much time looking at the smartest models that it’s easy to miss how far the cheap, fast ones have progressed. Calvin argues that this is (even more than frontier models) what makes many new products viable, because not every task needs a genius: most business work just needs something responsive, cheap, and that keeps the ball moving.
And that’s it for today! If you are finding this newsletter valuable, subscribe to the full version!
1700+ engineers and managers have joined already, and they receive our flagship weekly long-form articles about how to ship faster and work better together! Learn more about the benefits of the paid plan here.
See you next week!
Luca






