<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>covey — Blog</title><description>What we learn building covey: how the platform works, why it is built this way, and what proves itself in practice when AI agents are managed like employees.</description><link>https://covey.work/</link><language>en-GB</language><item><title>Why does an agent never see its own credentials?</title><link>https://covey.work/blog/why-an-agent-never-sees-its-own-credentials</link><guid isPermaLink="true">https://covey.work/blog/why-an-agent-never-sees-its-own-credentials</guid><description>How covey brokers access to target systems at runtime: short-lived, scoped tokens that never sit in the sandbox as long-lived secrets.</description><pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate><category>Product</category><category>Engineering</category></item><item><title>How do you control what an AI agent can reach on the network?</title><link>https://covey.work/blog/ai-agent-egress-control</link><guid isPermaLink="true">https://covey.work/blog/ai-agent-egress-control</guid><description>How covey uses a proxy allowlist and hard network isolation to control what an agent sandbox can reach.</description><pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate><category>Product</category><category>Engineering</category></item><item><title>The website and the product are two things now</title><link>https://covey.work/blog/website-and-product-split</link><guid isPermaLink="true">https://covey.work/blog/website-and-product-split</guid><description>Why publishing a blog post used to mean deploying the platform, what that had to do with self-hosters, and what we built instead.</description><pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate><category>Engineering</category><category>Behind the scenes</category></item><item><title>Where an agent works: sandbox, workplace and server</title><link>https://covey.work/blog/where-an-agent-works</link><guid isPermaLink="true">https://covey.work/blog/where-an-agent-works</guid><description>Every agent gets an isolated working environment of its own. How it is built, what survives a restart, and how it is spread across servers you run yourself.</description><pubDate>Sat, 22 Aug 2026 12:00:00 GMT</pubDate><category>Product</category><category>Engineering</category></item><item><title>How an agent gets access to a target system</title><link>https://covey.work/blog/how-an-agent-gets-access</link><guid isPermaLink="true">https://covey.work/blog/how-an-agent-gets-access</guid><description>An agent is meant to work in Zammad, GitLab or Kubernetes. How it gets in, who holds the credentials, and why they never sit in its working environment.</description><pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate><category>Product</category><category>Engineering</category></item><item><title>An agent that proposes and changes nothing</title><link>https://covey.work/blog/proposals-that-do-not-run</link><guid isPermaLink="true">https://covey.work/blog/proposals-that-do-not-run</guid><description>Covey Doctor reviews the other agents and the platform itself. Why it may not change anything, and why an approval records the exact values a person read.</description><pubDate>Sat, 15 Aug 2026 12:00:00 GMT</pubDate><category>Product</category><category>Security</category></item><item><title>How we measure what an agent has delivered</title><link>https://covey.work/blog/how-we-measure-agent-output</link><guid isPermaLink="true">https://covey.work/blog/how-we-measure-agent-output</guid><description>No model awards a grade here. We count verifiable events instead. Why we chose that, and why an agent never gets to see the rule it is measured by.</description><pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate><category>Product</category><category>Metrics</category></item></channel></rss>