@orbientpro

I turn broken lead/support workflows into systems that stay up. n8n, agents, CRM. Ex-Check Point. Fixed-scope sprints from $600. No mandatory call. RU/EN

Da Nang, UTC+7
Joined May 2016
1/ I tried to force my AI agent to misclassify something. It refused. Nine times in a row. 2/ The build: inbound request triage in n8n. Strip PII, screen for prompt injection, then an agent sorts each request into one of 5 categories against a JSON schema with a hard enum. 12 real requests replay through the same pipeline as a regression test. 3/ To prove the tests catch regressions, I deleted "spam" from the enum. Expected: the agent files a scam email as something else, accuracy drops, clean before/after. GPT-5 mini said "spam" anyway. 4/ Schema rejects it. Auto-fix shows it the 4 remaining options and asks again. Says spam. Rejected. Asked again. Says spam. Nine rounds. Nine real API calls. Then the execution died in red. It never invented a workaround. 5/ Then I checked the eval dashboard. Accuracy: 100%. The averages only run over rows that finish. The two crashed rows weren't scored as failures. They were dropped from the math entirely. 6/ Perfect score, two dead executions, nothing on screen connecting them. If your only proof an agent works is an accuracy number, that number excludes its own worst cases. Failures don't show up as low scores. They show up as nothing.
24
1/ I automate the path. I don't automate the judgment call. 2/ Lead→CRM: webhook → normalize fields → route owner → send ack. That's a route. It repeats. It belongs in n8n. 3/ I don't automate fuzzy qualification, one-off pricing, "client is angry / I promised a discount," or merge/delete duplicates with no rule. If it needs a meeting to explain, it's not a node yet. 4/ A green "synced to CRM" with the wrong owner is worse than a loud fail. Same lesson from security work: silent success hides the blast. Fail loud. Human gate on judgment. 5/ Build the boring path first. Put a person on the edge cases.
29
⚙️ How I ship n8n automations without turning them into a security incident I come from a security background (Check Point). Now I build lead/support workflows in n8n for small teams. The pattern I keep seeing: people bolt an LLM onto a canvas, give it CRM + email + Slack, and call it "done." That is not automation. That is unsupervised privilege with a pretty diagram. What I actually care about in production: 1) Secrets stay out of node fields If an API key lives in a Set node, it will end up in an export, a screenshot, or a shared workflow. Vault / env only. 2) Tools are allowlisted An agent that can "call anything" will eventually call the wrong thing. Narrow tools. Prefer deterministic nodes for money, CRM writes, and outbound messages. 3) Writes need a human gate Draft is fine. Auto-send to a client or auto-update the CRM at 2am is where trust dies. Approval node before irreversible actions. 4) Failures need a budget Infinite retries hide broken auth and burn spend. Cap retries. Dead-letter the poison messages. Ping a human when the same error repeats. 5) Don't edit live If ops depends on the workflow, treat publish like a deploy. Review the diff. Then ship. The model is the easy part this week. The boring rails are what keep the system alive next month. Durable workflows beat clever agents. (checklist graphic below)
22
⚙️ GPT-6 Astra vs Claude Fable 5.1 Same price band. Different harness. Astra → computer use, browser tools, automation loops Fable → long agent runs, cheap cache, coding loops I pick by workload, not by brand. Short calls: either. Long looping agents: watch the cache. Desktop/browser automation: start with Astra. openrouter.ai/openai/gpt-6-a…
🤖 Made with AI
23
The viral part isn't "AGI escaped." It's unsupervised agents writing to the public internet because write wasn't actually blocked. I look at this like security work. Badly supervised agents are an ops failure, not a magic moment. Allowlist the tools. Block silent write out. If it can post without you, it will. collusion.wiki/
18