Suzanne Chartier

Suzanne Chartier

Co-Founder | Re-imagining Agile with AI

About

Hey 👋 I'm Suzanne, founder of Agiloop. Tired of rigid agile tools that don't keep up with AI-speed dev? I'm building the future: AI that auto-generates workflows from plain specs. Colorado-based maker sharing the journey. Follow for updates & feedback! 🚀 agiloop.ai

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking
Gone streaking 5
Gone streaking 5

Maker History

Forums

•

13d ago

What's your "is it safe to ship?" checklist for AI-built apps?

AI can get me to a working app in a day, but "it works on my machine" and "it's safe for real users" are very different things.

The part that worries me is the boring stuff that's easy to miss when the code looks clean and everything runs: API keys sitting in the frontend, auth checks that exist on the page but not on the endpoint, database rules left wide open from the prototype stage, no rate limits on anything. The AI rarely warns you about these unless you ask, and by the time you think to ask, you've already moved on to the next feature.

Right now my pre-launch process is mostly manual and a bit random: I skim through the auth flow, search the repo for hardcoded secrets, and try to break things as a logged-out user. It catches some things, but I never feel fully confident.

I'd love to hear how others handle it:

•

17d ago

Shipping a feature got cheap. Deciding to delete one didn't.

We've got 111 one click apps in Arteza across six studios. Building them was the easy part. With an agent you can take a prompt template to a shipped, working app in an afternoon, so adding one feels free and you stop asking whether it earns its place.

The bill arrives later. A menu nobody can scan. Support load for things almost nobody opens. And every model swap underneath means retesting all of it, because 111 apps sitting on 30+ models is a test matrix, not a feature list.

The mistake wasn't building them. It was not writing the kill rule first. If I'd set a number up front, opened by this many distinct people in 30 days or it goes, removal would be a rule instead of an argument. Now every deletion is a conversation with someone who liked that one.

Vibe coding collapsed the build cost and did nothing to the maintenance cost, so the ratio is worse than it has ever been. Most of the feature bloat I see right now isn't ambition, it's just that saying no got expensive relative to saying yes.

Would you let AI take control of your whole app?

Vibe coding a personal project that works on your laptop is one thing.
Building a tool your team opens every morning to manage projects, serve customers, and run the business is another.
Suddenly there s shared data.
Different people need different levels of access.
Your teammates need to understand how the app works so they can change it too.
And the app needs to keep evolving without turning into a black box nobody wants to touch.
At that point, would you be comfortable letting AI change anything it wants?
We ve been thinking about this a lot while building WeWeb MCP (launching on PH tomorrow!)
Agents like Claude, ChatGPT, Cursor, and Gemini can now build apps directly inside WeWeb.
Across the frontend & backend from: UI, data, workflows, integrations, permissions, and more.
But the important part for us was making sure the builder stays in control of both the app and the AI building it.
That s why we built guardrails into the way AI works inside WeWeb:

  • Before AI builds: choose what AI can and can t touch: pages, components, workflows, tables, APIs, and more.

  • After AI builds: see exactly what changed in the visual editor. Tweak it yourself, keep iterating with AI, and publish when you re ready.

So AI gets room to move fast, without getting free rein over the whole app.
I m curious how you think about this: Would you give an AI agent access to everything?
Or are there parts of your app you d always want to lock down?

View more