← Trespassing — A Brief

The Champion Who Never Wrote a Line

I did not write a single line of code or prose. Did I still author anything?

2026-07-09 — origin: an unattended research run on ATProto infrastructure, briefed and reviewed but not written by hand

The Question

This morning an agent read a brief I wrote, queried three sources I named, and produced about a thousand words that changed a real infrastructure decision. I didn’t write any of those thousand words. I didn’t make any of the lookups. I wasn’t in the room while it ran — that was the point.

So: did I still author anything? The honest answer took the whole day to arrive at, and it isn’t the reassuring one you’d reach for by reflex.

What a Champion Is, and Isn’t

The word for this in my own practice is champion — a carefully briefed agent that executes a decision already made, unattended. The framing came out of noticing that marathon coding sessions happen when project-organized work (task-driven, plannable, can run without me once scoped) and person-organized work (presence-driven, requires me by definition) collapse into the same unbroken block. Traditional work/life balance tries to separate them by time of day. That axis is wrong. The real axis is who needs to be present.

A champion isn’t a shortcut around judgment. It’s a container built specifically to hold judgment steady while the execution happens somewhere I’m not. I plan, I review, I re-brief. I don’t sit at the keyboard while it runs. The bottleneck was always me as decision-maker, never me as typist — so the framework tries to spend my attention on the former and delegate the latter, on purpose, in writing, before the loop starts.

The Stack That Keeps You the Author

This isn’t the first time this site has had to reckon with what the agentic loop does to authorship. A few weeks earlier, after a sleep-deprived sprint that ended in something close to a dissociative state, the same question showed up in a smaller, more personal shape: in an agentic coding session, the loop produces things that feel like your decisions because you initiated them. The longer you’re in it, the harder it gets to tell your judgement from the agent’s output.

The counter-measure that came out of that was a three-layer stack. Vibe-cards — pen-and-paper notes written before narrating anything to an AI, physical and slow, a record that exists outside the context window. Beans — externalized task memory, so scope creep is reviewable across sessions instead of invisible inside one long one. Burndown and burn-up metrics — making the loop legible from the outside, a discovery ratio as an early warning that the work is expanding faster than it’s closing. Each layer makes it a little harder for the loop to replace your judgement without you noticing. Author-preservation, it turns out, is a form of agency.

A champion brief is that same insight, pushed one step further. If the loop is going to run with genuinely nobody watching, the judgment can’t live in the moment-to-moment narration anymore — there is no moment-to-moment. It has to be written down in advance: which sources to trust, what standard the output has to meet, what it’s explicitly not allowed to decide. The brief is the vibe-card, just addressed to something that won’t improvise past it.

Today, Concretely

Here is what actually happened, not the abstraction of it. I’d spent the day chasing a fork of an ATProto sync tool, which led to a wider ecosystem — a backlink-index-and-firehose-tooling project called microcosm.blue, and a decentralized container registry called ATCR — and I wanted a real answer to a real question: is any of this worth self-hosting for a fleet of personal domains that’s mostly just me?

Instead of answering it myself, I wrote a brief. It named three signal sources explicitly, and asked whoever executed it to tag every finding by which source produced it: my own journal, for the values and constraints that don’t change day to day; a live query against Semble, a curated social-bookmarking network built on the same protocol; and the actual public posts of the practitioners involved, standing in for a codebase read on a topic that had no code of mine to read.

The agent that ran it found something I’d missed all day: the person behind microcosm.blue, going by “fig,” had written her own job description into her Bluesky bio — “making/running constellation.microcosm.blue, slingshot, UFOs, spacedust, lightrail, relays, plc mirrors, hubble, service SLA & atproto consulting available.” One person, eight services, a stated business model I’d had no idea existed. That single sentence resolved an open question my own web searches hadn’t: this wasn’t four independent projects sharing a brand, it was one practitioner’s whole practice.

It also found the case against copying that practice. A second self-hoster’s writeup of a mature, official, single-service install — fighting an opinionated installer, a silently-wrong environment variable, a workaround they themselves called “insane” — became the counterweight to the temptation of self-hosting a whole stack with guides that are still “coming soon.” The recommendation that came back wasn’t a survey of options. It was a call: don’t self-host, not at this fleet’s size, and here’s the specific evidence, tagged by source, that a future me can accept, argue with, or overturn once the fleet actually grows into the tradeoff.

Worth saying plainly, because it’s a real result and not a marketing line: the Semble query step earned its place. It surfaced a maintainer’s bio, two hosted alternatives, and a traction signal that a plain web search across the same afternoon never turned up. Ronen, who built the thing at Cosmik, will be glad to hear that — and he should be; it’s a better compliment than most, because nobody asked for it and nothing was riding on saying it.

The Trap Sitting Right Next to the Win

The same afternoon produced the failure mode this whole exercise is meant to guard against, and it happened to me, not to the agent. Reading about the practitioner behind the tool — Bailey Townsend, who self-hosts his own version of that stack, publishes his own container images to two registries, and offered his docker-compose files to strangers on Bluesky unprompted — I caught myself about to just copy his setup. Not reason through it. Copy it, because it visibly worked for him.

That has a name: cargo-culting. Copying the outward form of a working ritual without the causal understanding underneath it, on the assumption that repeating the motions reproduces the result — the term comes from islanders who, having watched Allied logistics summon supply planes with airstrips and control towers, built their own mock airstrips and bamboo radio masts, expecting the planes to land. The imitation was faithful. The mechanism it was missing was the entire point.

So the actual infrastructure decision got split into two beans instead of one: a research task, gated in front of a build task, specifically so understanding has to happen before imitation is even possible. And then — worth naming, because it’s the funnier and more honest part — in the same breath as naming cargo-culting as the failure mode to avoid, I turned around and asked for the observation to be filed as a bean. Externalizing task memory isn’t exempt from its own critique. A bean only preserves agency if it still carries the reasoning, not just someone else’s config restated as a checklist.

Answering the Question

So: did I author anything, having written none of the sentences that answered my own question?

Yes — just not the sentences. I authored which three sources were allowed to speak, and in what order of trust. I authored the standard the brief had to meet before I’d accept its output — ground the recommendation in a real practitioner’s reasoning, not an idealized composite, the exact test I’d just failed and caught myself failing an hour earlier. I authored the choice of which of two candidate research threads to run as the actual demonstration, and the decision to gate one infrastructure bean behind another rather than let convenience win. I authored the frame you’re reading right now, including the decision to put the failure in it rather than only the win.

The champion wrote the paragraph. I wrote the reason the paragraph was worth writing, and the constraints that kept it honest once it existed. That is a thinner slice of authorship than drafting the sentence by hand — and it is not nothing. It might be the only part of the work that was ever actually mine to begin with; the sentence-level draft was always going to be, in some sense, disposable — what mattered was never stored there alone.

The Closing Thought

Nothing here resolves cleanly, and it shouldn’t. The fleet-infrastructure decision this whole episode was ostensibly about is still open — still gated behind a research bean, still waiting on a judgment call nobody’s agent can supply on its own, because the judgment isn’t “what does the evidence say,” it’s “what does my fleet actually need,” and only one of us has a fleet.

Author-preservation is a form of agency — and the test of it isn’t whether you wrote the sentence. It’s whether you can still say, afterward, exactly which part was never the agent’s to decide.

That’s the actual shape of the answer: not in the paragraph the champion produced, but in what I refused to let the paragraph decide for me.

Companion pieces: Trespassing — A Brief, Sprunginnovationspotential, and Seeking Out the Hans Zimmer of AI. Sources: journal entries 2026-06-11 (“Champion-Driven Work Pattern”), 2026-06-16 (“Vibe-cards and cognitive security”, “Author-preservation as agency”), and 2026-07-09 (“Cargo-culting, Bailey, and catching myself mid-loop”); the champion run itself, brief and output on record in the tracker planning repo; Bailey Townsend (pds.dad) and “fig” (bad-example.com) of microcosm.blue, whose public practice this piece draws on directly; Semble/Cosmik, whose API made the second signal source possible.