INV—24/7 · FIELD NOTES · EST. 2014 WRITING · VOL. 04 · 2026
Invental/Writing

Field notes from a software studio.

Essays, playbooks, and the occasional post-mortem. Engineering, design, SEO, and what it takes to ship real software in 2026 — written by the people doing the work.

42 essays · Updated weekly RSS → /feed.xml
Filter by topic —
KYC-Gating an ERC-20 in One Function: The OpenZeppelin _update Hook PatternEngineering

One function, one compliance chokepoint.

How a single OpenZeppelin v5 _update override enforces "only verified addresses can ever hold this token" on an ERC-20 — the pattern, the mint/burn exemptions, and when to graduate to ERC-3643.

Read essay
Derived State, Whole Shares: Designing a Safe Crowdfunding EscrowEngineering

Derived State, Whole Shares.

A goal-based raise only ends three ways. How deriving that state instead of storing it, splitting settlement into three narrow functions, and rounding whole-unit shares on purpose became the real engineering in a crowdfunding escrow.

Read essay
Building a Desktop App Where Nothing Leaves the MachineEngineering

Building a Desktop App Where Nothing Leaves the Machine.

How we shipped a native-feeling Mac analytics app with no backend server: a universal Electron binary bundling a compiled native module, local SQLite in WAL mode as the entire data layer, defensive import of a user's own data export, and provider-agnostic LLM calls made straight from the desktop client.

Read essay
Monitoring Whether AI Answer Engines Actually Cite YouEngineering

Does ChatGPT Even Mention You?

Inside an AEO monitor from a product we built: it asks ChatGPT, Claude, and Perplexity the questions your buyers actually type, logs whether they name you, and pairs that with Search Console rank deltas — plus the honest limits of a method with no official citation-rank API.

Read essay
Eight Feeds, One Table: The Provider-Adapter Pattern in AngerEngineering

Eight Feeds, One Table.

Six feeds had real APIs, two didn't, and none of the eight agreed on team IDs or match state. How a provider-adapter layer and a canonical identity table turned that into one clean table per match.

Read essay
The Live Feed That Never Goes Dark: Fallback, Freshness, and Stale-Live CleanupEngineering

The Live Feed That Never Goes Dark.

A rich push feed preferred when fresh, a fallback poller that never stops running, and the lease-based cleanup that stops a system from calling frozen matches "live."

Read essay
Detect the Render Mode Before You Write the ScraperEngineering

Detect the Render Mode Before You Write the Scraper.

How to tell a client-rendered page from a server-rendered one in under a minute, and why routing each to the cheapest reliable extraction path — fetch-and-parse or headless browser — is the single biggest cost lever in a scraping pipeline.

Read essay
Cross-Source Product Matching: A Tiered Cascade That Doesn't Lie to YouEngineering

Cross-Source Product Matching: A Cascade, Not a Model.

A practical playbook for matching product records across catalogs: exact-key matching first, pg_trgm fuzzy similarity for the messy middle, a confidence-banded human review queue, and normalizing units and package sizes so comparisons are actually valid.

Read essay
Two-Stage Retrieval: Cheap Recall, Exact Precision, One IndexEngineering

Two-Stage Retrieval: Cheap Recall, Exact Precision, One Index.

A technical walkthrough of matryoshka retrieval: how Matryoshka-trained embeddings let a single vector serve as both a cheap ANN prefix and an exact rerank target, why the full-dimension vector should live on disk with no HNSW graph, and how RRF layers a sparse signal on top without a second collection.

Read essay
Multi-Tenant RAG Has a Bug That Never Throws an ErrorEngineering

Multi-Tenant RAG Has a Bug That Never Throws an Error.

Sparse retrieval computes term-frequency statistics across the whole corpus. Share one Qdrant collection between RAG tenants and their IDF weights silently blend — a retrieval-correctness leak with no stack trace. The trap, and the four-part isolation checklist that avoids it.

Read essay
We Cleaned 8,000 Messy Product Records for Under $30Engineering

We Cleaned 8,000 Records for Under Thirty Dollars.

How we normalized ingredients, mapped tags, and extracted structured data across 8,000 product records with a small vision+text model — total AI spend under $30, failure modes reported honestly.

Read essay
When 436,000 Messages Broke Our WebSocket RelayEngineering

When 436,000 Messages Broke Our WebSocket Relay.

A bulk dump-on-connect flooded a WebSocket relay with 436,000 messages, triggered a 1006 disconnect storm, and buried live data under a 3.4M-message backlog — here's the diff-based fix.

Read essay
Don't Marry Your Product to One LLM VendorEngineering

Don't Marry Your Product to One LLM Vendor.

Inside the provider-agnostic LLM layer from an applied-AI product we built: one interface, three adapters, two cost tiers, typed outputs — and the benchmark that showed a free model beating a frontier one on quality.

Read essay
Building a Shopify Widget That Survives Any ThemeShopify

A widget that survives any theme.

Shipping UI onto a Shopify store you don't control means giving up nearly every assumption a normal frontend gets to make — one IIFE bundle, prefixed CSS, an app embed block, and the store's own cart API.

Read essay
Building a custom Shopify app: theme extension to App StoreShopify

Building a custom Shopify app: theme extension to App Store.

The anatomy of a full Shopify app — a merchant-configurable theme extension, an embedded Polaris admin, an App Proxy backend, and the compliance webhooks reviewers actually check.

Read essay
Application security analysis tools: SAST, DAST, SCA and ASPM, explainedSecurity

Application security analysis tools: SAST, DAST, SCA and ASPM, explained.

Every scanner finds a different class of flaw; none, on its own, tells you what to fix first. How the tools actually work in 2026 — and why buying more rarely makes an app more secure.

Read analysis
Whitespots vs DefectDojo: managed ASPM vs open-source triageSecurity

Whitespots vs DefectDojo: managed ASPM vs open-source triage.

A fair comparison of managed ASPM and open-source vulnerability triage — native scanning, dedup, false positives, the real cost of "free", and who should pick which.

Read analysis
Open-source application security tools: the best free scanners in 2026Security

Open-source application security tools: the best free scanners in 2026.

The free SAST, DAST, SCA, secrets and IaC scanners worth running — and the honest point where a DIY open-source stack starts costing more than it saves.

Read analysis
The Middle East's real fintech buyer isn't a unicorn — it's the mid-market on a regulator's clockMarket

The Middle East's real fintech buyer isn't a unicorn — it's the mid-market on a regulator's clock.

In the Gulf, modernization is set by the regulator's calendar, not the CFO's budget. The 201–1,000 mid-market is legally in scope, and too lean to build in-house.

Read analysis
The 201–1000 squeeze: why mid-sized European fintechs are the receptive onesMarket

The 201–1000 squeeze: why mid-sized European fintechs are the receptive ones.

Investors killed growth-at-all-costs while DORA and PSD3 imposed bank-grade compliance regardless of size. The mid-band is caught in a buying window.

Read analysis
The squeezed middle of US finance — the real buyers aren't who you thinkMarket

The squeezed middle of US finance — the real buyers aren't who you think.

Not the megabanks (they build in-house), not the seed neobanks (no budget). The 201–1,000-employee tier can't hire or fundraise its way to modernization — it has to buy.

Read analysis
The LatAm fintech sweet spot isn't the unicorns — it's the tier underneathMarket

The LatAm fintech sweet spot isn't the unicorns — it's the tier underneath.

Everyone studies Nubank's 123M customers. If you sell into LatAm fintech, that's the wrong company to study. The reachable buyers are the 200–1,000-person tier below it.

Read analysis
Typed from day one: why we don't ship untyped JavaScript anymoreEngineering

Typed from day one: why we don't ship untyped JavaScript anymore.

Types aren't about purity — they're about shipping faster with fewer nights on call. What we use, what we skip, and the two rules we enforce on every project.

Read essay
How we scope a project in a single week (and what we refuse to estimate)Process

How we scope a project in a single week (and what we refuse to estimate).

Five days, four artefacts, one honest number. The shape of our discovery engagement and why we never send a multi-page proposal.

Read essay
SEO for product teams: the ten things that actually move the needleSEO

SEO for product teams: the ten things that actually move the needle.

Engineering-grade SEO for 2026 — Core Web Vitals, structured data, content architecture. No content farming, no link swaps.

Read essay
Notes on designing Shopify checkout extensionsShopify

Notes on designing Shopify checkout extensions.

What the new extensibility surface gets right, what it still gets wrong, and the patterns we've arrived at after shipping twelve of them.

Read essay
What a studio-grade design system looks like in 2026Design

What a studio-grade design system looks like in 2026.

Tokens, primitives, composition — how we structure design systems so they survive a handoff, a team change, and three years of product drift.

Read essay
Postgres is still the correct answerEngineering

Postgres is still the correct answer.

We audited fourteen greenfield stacks we've shipped since 2023. In every one of them, Postgres plus a decent ORM was the right default. Here's why.

Read essay
The two-week sprint contract — our engagement model, written outProcess

The two-week sprint contract — our engagement model, written out.

No hour-by-hour invoicing, no scope creep, no mystery. The cadence we've used on forty-plus engagements and why clients renew on it.

Read essay
Editorial typography for product interfacesDesign

Editorial typography for product interfaces.

What magazines do better than product designers, and how to borrow from them without your dashboard turning into a zine.

Read essay
Observability for teams of five or lessEngineering

Observability for teams of five or less.

You don't need a platform team to know what your app is doing. A minimal observability stack that costs less than one senior engineer's monthly coffee.

Read essay

Get field notes first.

One essay every other Tuesday. Engineering, design, and the craft of shipping software. No tracking pixels, unsubscribe in one click.