EdgePointe · Weekly Executive Briefing

What moved in tech this week — and what it means for EdgePointe

Week of September 21, 2026 · a 5–7 minute catch-up
Nine cards, ~30 seconds each. You get the so-what; Paul carries the detail. Hit Play narrated to listen.
EDGEPOINTE · VANTAGE
The big picture · our bet

A thing we verified last week was reversed eight days later — and that is the business Bet intact

Our bet has never been on which AI company wins. It is that somebody has to stand between a small business and software that changes underneath it every few days. This week made that case better than any pitch deck we could write.

In five days, the tool at the centre of our own build shipped eight releases. Five of them fixed security holes in how permissions are enforced. Two of them fixed leaks that were printing passwords into log files. And one of them reversed a fix we reported to you last Monday as closed.

None of that is a scandal — it is a fast-moving product behaving like one. The point is what it costs a business owner who has nobody watching. A verification is good for about a week. That sentence is either a nuisance or a service line, depending on who you are.

Bottom line: we are not selling AI. We are selling the fact that someone read the changelog on Tuesday. That job does not go away when the models get better — it gets bigger.
Where we stand

Finished work is still parked — eleven days now — and one date lands Friday Clock running

The phone AI
Code complete, tested, answering a real phone number. Eleventh straight day at the top of the board, unshipped.
Friday, Sept 25
The only item on the board with a calendar date — a decision about packaging a new small-business AI offering. Four days out.
Our pricing page
The rewrite triggered by competitors entering this space is ten days owed. This week added a fifth piece of evidence for it.
The data loop
The thing that would make our quality claims defensible is unbuilt for the fifteenth week.

Nothing on that list is hard. Everything on it is old.

Bottom line: four of these are decisions, not projects. A quiet research week is the cheapest possible week to clear them — and this was a quiet research week.
Claude · our core tool this week

A five-day repair wave — and one part of it we cannot just upgrade our way out of Act now

Between Sept 15 and Sept 18 our core tool fixed five separate flaws in how it decides what the AI is allowed to do, plus two credential leaks. Most of that we collect for free by updating.

  • The serious one: a destructive delete command could be hidden inside a wrapper and slip past the safety check. That is exactly the shape a malicious instruction would take.
  • The one that needs a hand: two separate bugs were printing passwords and tokens into error messages and log files until Sept 17. Updating stops future leakage — it does not un-write what is already in the logs. Anything that sat in those places gets rotated.
  • Free protection we did not ask for: two changes landed on Sept 18 that harden exactly the risk in our website-cloning work — untrusted text pulled off a stranger's website can no longer masquerade as an instruction from us.
Bottom line: upgrade, re-check our settings, rotate the credentials. One sitting, and the rotation half is the part that cannot be deferred to next week.
Platform · Cloudflare

Vantage is fine — and Cloudflare just handed us a twenty-minute security upgrade All calm

Nothing on our platform broke, is breaking, or is scheduled to break. Three notes, in descending order of usefulness.

The good one
Cloudflare shipped a way to give a deploy key access to one specific piece of our platform instead of all of it — and their own documentation describes our exact setup. Roughly twenty minutes, and it is the same key we are rotating on card 4.
Security filters
Three new attack detections switched from watching to blocking on Sept 15, on schedule and without incident. Four more start watching tomorrow — watching only, nothing changes for clients.
2027 housekeeping
An old connector tool drops support for 32-bit Windows and Intel Macs next year. A five-minute inventory question for client fleets, not a Vantage question.
Bottom line: rotate the key and narrow it in the same sitting. Right now one key opens the whole house; after twenty minutes it opens one door.
Biggest growth move · Managed IT

A paid assessment we can sell without building anything first Act now

Cloudflare made a feature generally available this week that hands us a service we have been describing for a month: showing a client what AI tools their staff are already using without permission.

The detail that makes it sellable: it produces findings without anyone having to configure a policy first. That is the exact shape of a paid assessment — we turn it on, we read the report, we walk the owner through what we found, and the remediation that follows is the recurring work.

Why now, and not next quarter: most of our clients have not deployed an AI agent yet, so governing agents is not the near-term product — visibility into the AI already in the building is. Every one of them has staff pasting company information into a chatbot today. Nobody has told them.

A second, smaller Cloudflare change makes client-owned accounts easy to create — which is a better answer to "who actually owns this website" than anything we have said to date.

Bottom line: this is a conversation, a switch, and a report — not a build. It is the cheapest new line item on the board and the one clients will understand fastest.
Client-facing · venues & Vantage

Our phone AI's worst failure just got fixed — by the same vendor now selling one of its own Fix + watch

The single worst thing our receptionist could do is fail to pick up when a venue gets busy — a bridal show weekend, an ad burst, a post that takes off. Until this week, hitting that ceiling meant a lead simply never got through. That is the outcome that ends a contract.

  • The vendor shipped queueing with branded hold audio and a bounded wait. Callers hear the venue's own recording instead of nothing.
  • Hold time is not billed.
  • It is switched off by default — so we do not have it today. Turning it on and uploading each venue's own clip is small work that reads as bespoke to an owner.

The uncomfortable half: the same vendor's own AI receptionist product now sits as a top-level section in their documentation, beside their core platform. They are not experimenting. Our defensible line was never the voice — it is the venue-specific booking logic, where the lead goes next, and a human being answering when the AI cannot.

Bottom line: turn queueing on this week and put each venue's voice on the hold clip. It costs an afternoon and removes the one failure that would lose us the account.
The wider AI race · so what

A 541,000-judgment study says the test we designed last week would have lied to us Redirect

We have been building a way to score whether a website we rebuild is actually better than the one it replaced. Last week's briefing told you how to run the control. A study found this week says that control does not work.

Scale first, because it matters: 21 different AI judges, nine vendors, about 541,000 individual judgments. Three findings that cost us something:

  • An AI judge can be perfectly consistent and still be reading the wrong thing. Our plan was to check it against itself. Self-agreement does not detect the error — the control has to be a question where we already know the right answer.
  • Percentage agreement overstates these scores by roughly a third of the scale. Every quality number we have quoted internally is inflated.
  • Verbosity is not the problem we assumed — which cancels a build. That is the only free thing on this card.

Separately, a second study on voice agents says judge the phone AI partly by machine and partly by human — and the two things it says a machine cannot yet score reliably are did the agent recover when it got confused and did it miss something it should have caught. Those are the two a venue owner cares about most.

Bottom line: better to find this in a paper for free than in a client QBR for money. Fix the measuring instrument first, then measure — that order is now settled.
The bottom line

Two decisions need Bob and Niven this week — and one has Friday attached Decisions

1 · Set a ship date
The phone AI is finished and has been parked eleven days. This week removed its worst failure mode and told us which quality claims will hold. It does not need more build — it needs a date on a calendar.
2 · Settle the pricing position
Four AI receptionist products launched in twenty days, and our own vendor now sells one self-serve at a consumer price. We either state what we include that they do not, or the market states our price for us. Ten days owed.
Also Friday, Sept 25
The small-business AI packaging decision — Paul carries it, but flag it if either of you wants a say before it is made.

Two things Paul does without you this week: rotate the credentials and narrow the deploy key (one sitting), and turn on hold queueing for the venues.

Bottom line: the research was quiet this week. That is exactly the week to clear finished work off the shelf — nothing new is competing for the attention.
Card 1 / 9 · ~20s