3 ms·
I used an LLM a year or more ago to generate a description of our SDLC for a compliance certification. Perfect application of LLMs IMO. Do you want to die on th
by antonvs 8d ago
I used an LLM a year or more ago to generate a description of our SDLC for a compliance certification. Perfect application of LLMs IMO. Do you want to die on that hill as well?
A lot of documentation generated in corporations has marginal real value.
> If your commands are bulleted instead of numbered and code blocked, it's wrong.
That’s easy to instruct an agent to do. Put it in a skill.
> If you didn't crawl through the playbook, it's immoral to hand that to me, you're wasting my time with untested slop.
Using an AI doesn’t absolve the user of their responsibilities. This is an easy problem to solve, just make sure teams know what’s expected of them and encourage everyone to push back (professionally) against offenders.
- SamInTheShell 8d agoIf someone sends me AI slop, they're getting chewed out and told I'm not doing it and I'll even tell my boss "no" and why. If I got fired over something like that, then it tells me everything I need to know about company and the leadership's priorities. I'll die on that hill. To be completely fair though, I'm against the behaviors in information transfer I've been seeing. I've pass along AI generated runbooks, but they look nothing like the default outputs of these models. It's because I took time to apply all the writing knowledge I like to see in my curation. If people are doing this, I can't even tell it's AI writing. My work is done in minutes instead of deciphering so BS pseudo language they developed in their AI workspace (people really need to turn off those memory features). --- Edit: Also if I'm the guy receiving a security report and it's AI generated and poorly formatted, I'm failing you short of producing something for a human to parse. Simple as that.
- alchemism 8d agoIf a security report is written for any particular human at all, I’d consider it to be a failure as an enterprise policy document. It should be written for The System, not for the boss; and LLMs are perfect for producing ritual boilerplate.
- SamInTheShell 8d agoWe're probably just going to disagree here. These LLMs are built to serve humans. They either need to make the system transparent for the operator or be limited in use to tasks that can be proven in whole (with code that can't be revised without human approval). Should you think it is wise to trust the machine that can't differentiate subject matters in a chat styled context, you have fun with that fluster cluck when it blows up. Like Fable is highly useful, but it's really bad at keeping it's responses straight. In fact, that "it's not X it is Y" pattern always crops up when it reasoned about the idea of X and I never fed it that. It's literally doing that because it can't predict that I'm a different entity despite it being able to say I am a different entity. Edit: Clarification by removal of incomplete sentence fragment. Edit2: Clarification on the "proven in whole" thing.
- antonvs 8d ago> Also if I'm the guy receiving a security report and it's AI generated and poorly formatted, I'm failing you short of producing something for a human to parse. Simple as that. It’s clear that you’ve never worked for a compliance company and probably have never been involved in a compliance project. As such, you don’t have the context needed to participate usefully in this discussion.
- SamInTheShell 8d agoPure conjecture on your part.
- SamInTheShell 7d ago[flagged]