Automo Notes
AI-assisted engineering, not vibe coding.
Most AI builders ship something that looks right and breaks on contact. Here's what the alternative looks like, and why it matters for the people who put their name on the work.
Last week I woke up to a 100-plus message thread. Never a good sign.
Kate, Automo's co-founder, was working from somewhere in Europe. She'd been using Automo to fix a small issue with emojis in our chat surface. Instead of fixing the emojis, Automo built a whole new chat surface from scratch, sitting next to the one we already had. Hours of pain in the thread as she watched it drift, corrected, drifted again, corrected again.
I caught up over coffee. Ran a post-mortem with our own diagnose agents.
The prompt was loose. “The emoji doesn't work.” Three words. The kind of brief I would never have given a human engineer ten years ago without expecting a hundred follow-up questions. Today, we send it to Automo and expect signal.
That's not a complaint. It's the most interesting finding in the post-mortem: our own team trusts the AI more than they'd trust a person.
The agent took the bait. Misread the intent. Shipped the wrong thing into review.
The deeper finding sat one layer down. That Automo project wasn't using Guardrails yet, the surface in Automo that constrains where the agent can act and forces it to clarify intent before touching sensitive code.
The bug was a Automo bug. The fix wasn't “prompt better.” The fix was turning on the Guardrails.
The two ways to use AI to write software
There are two ways to use AI to write software for paying clients.
The first is to take what the model produces, render it, and ship it. Let's call this vibe coding, because the demo videos work on vibes. Visual polish. Fast turnaround. “Look how short the prompt was.” Vibe coding ships things that look right.
The second is to use the same models, with the same speed, but constrained by the practice senior engineering teams have been using for two decades. Let's call this AI-assisted engineering. It ships things that work.
Most of what's shipping under the banner of “AI builders” today is vibe coding. The people deploying it are about to find out.
What vibe coding actually is
Vibe coding is pattern-matching on plausible-looking code. The model generates what's most likely to come next based on what looks like the right shape of an answer. It's optimized for “feels right.” Not for “is right.”
The closest human comparison is a junior developer who's read a lot of Stack Overflow but never deployed to production. The output looks correct. The instincts haven't been built yet. The failures show up only when real users start typing things into real forms.
The dangerous failure mode is not broken code. Broken code gets noticed. Broken code crashes the build. Broken code throws errors a human can read.
The dangerous failure mode is code that looks fine and is silently wrong.
- The login screen that asks for email and password, with no rate limiting and no lockout, and proudly tells you “User not found” when you guess wrong.
- The dashboard query that filters by user input, dropped straight into a
whereclause, with no parameterisation in sight. - The Stripe key in the client bundle because the model has seen “stripe key” appear in client code somewhere in its training set, and it doesn't know which side of the network boundary that's allowed to live on.
- The auth check on the frontend that disappears the moment someone opens DevTools.
- The transaction that “looks like a transaction” and silently doesn't roll back.
The demos are impressive because demos run on the happy path. So does the AI's training. Real users do not.
This isn't a moral failing of the people building these tools. It's a misunderstanding of where the line is between generation and shipping. The model can generate. The line you cross when you put your name on something for a paying client is a different line.
What AI-assisted engineering means in practice
Same models. Same speed. Different posture.
Six things turn AI output from “demo” into “production-ready.”
1.Production stack by default.
Not a toy stack with five hidden assumptions. React, TypeScript, Tailwind, shadcn/ui, Supabase or equivalent. The same choices a senior team would make on day one. The reason matters less than the discipline: the stack chooses what kinds of bugs you can have. Toy stacks have wider failure surfaces.
2.Types, not vibes.
A type system catches a whole class of “looks right, isn't right” errors before they reach a user. The model can guess at intent. The compiler can't. Most vibe-coded output runs in dynamic environments where the compiler's job has been delegated to runtime, which is to say to your client.
3.Guardrails.
Some parts of the codebase are sensitive in ways that don't show up in a diff. Billing logic. Auth boundaries. Secrets. Schema migrations. The AI should be allowed to work freely outside these zones, and required to ask before touching them. Guardrails are the practice of telling the model “here's where you stop and check with a human.” (This is what we got wrong on Automo last week. The lesson stuck.)
4.Approval flows.
AI-generated code goes through a real review surface. Not “merge if green,” but “merge if a human nods.” The bar for production should be at least as high as for human-written code, not lower because “it was just an AI.” If anything, it should be higher, because the AI has more confidence per unit of competence than most junior engineers.
5.Audit trail.
Every AI change, every prompt, every diff, every approval, every rollback, signed and timestamped. If something breaks in production, you can answer “what changed and when” in thirty seconds. Without an audit trail, the answer is “we have no idea, the AI did it.” That answer ends agency relationships.
6.One-click rollback.
Production state needs to be reversible. If the AI ships something that breaks, the fix is not “ask the AI to fix it.” The fix is “undo.” Then investigate. Then fix forward. Vibe-coded systems treat rollback as a feature you build later. AI-assisted-engineered systems treat it as a precondition.
These are not features in a marketing comparison table. They are a posture. The platforms that bake the posture in produce different output than the platforms that don't, even when the underlying model is identical.
Why this matters for agencies
Your client doesn't care if AI wrote the code. They care if it works the first time they click through the demo.
Trust is the agency's asset. Reputation. Repeat business. Referrals. AI-generated code that fails to a paying client kills trust faster than missing a deadline, faster than a billing dispute, faster than almost anything.
There is a bifurcation about to happen in the agency market. In the next eighteen months, agencies will split into two camps.
The first camp ships vibe-coded prototypes early. Wins a few demos. Looks fast. Loses a few clients. Loses trust faster than it accumulates revenue. Exits the market quietly.
The second camp adopts AI-assisted engineering early. Demos as fast as vibe coding does, because the underlying model is the same. Ships faster than vibe coding ever will, because nothing breaks on first contact. Compounds trust. Becomes the full-service software partner that the brand-shop generation used to outsource to.
Which camp the agency lands in is not a tooling decision. It's a posture decision. The agencies that join camp two pick tools that enforce the posture. The agencies that join camp one pick tools that hide it.
The window to pick is closing. Whoever picks first owns the next five years of work the no-code generation can't do.
We bet our own company on this. Automo is the platform we built because we wanted to take that bet ourselves and put our own production app, Automo, on it. (The Kate story above is what happens when we get a configuration wrong on our own dogfood. We notice. We learn. We turn the right thing on. That's the posture too.)
The pick
Three things to leave you with.
AI-assisted engineering is not a feature. It's a posture. You can see the posture from the outside, in the tools an agency uses, the way it reviews code, the way it talks about what its AI can and cannot do.
The agencies that adopt it early will look like senior engineering teams that don't need senior engineers. That sentence sounds like a contradiction. It isn't. The seniority moves into the practice, not the headcount.
The agencies that don't will look like the agencies the no-code generation already replaced. Slower. Less serious. Suddenly competing for a smaller pie.
Pick early.
You don't have to pick alone. Automo is built around AI-assisted engineering, and the team that built it sits with you while you set it up. We've made the configuration mistakes you'd be about to make (Kate is still teasing me about last week). We know which Guardrails matter and when. Think of us as a partner in the practice, not just the tool.