Named operating systems
Level 2 · repeated and concrete
Names Buzz, Block App Kit, Block Metrics Store, Block Data MCP, Query Expert MCP, CodeCrucible, and MeshLLM, and states each system's operating job; the naming recurs across the archive.
Names Buzz as the channel-driven workspace where people, agents, repos, and decisions work together in one signed room, with its protocol and storage design.
engineering.block.xyz/blog/buzz · observed 2026-08-23
Names Block App Kit as the sanctioned platform for internal apps, with its managed frontend, compute, and persistence layer and its agent-skill distribution route.
engineering.block.xyz/blog/from-localhost-to-launched-safely-shipping-apps-that-anyone-can-build · observed 2026-08-23
Names Block Metrics Store, Block Data MCP, and Query Expert MCP and states their distinct jobs: governed metric definitions, deterministic pre-approved SQL, and exploratory RAG retrieval.
engineering.block.xyz/blog/building-the-data-foundation-for-automated-analytics · observed 2026-08-23
Measured production results
Level 2 · repeated and concrete
Reports Block App Kit at over a thousand internal apps with weekly active users grown from the low hundreds into the thousands across more than fifty orgs, and the data platform at 1,100+ governed metrics with about a third of the company (2.1K monthly users) on Query Expert by March 2026; benchmark figures are published separately from these operating numbers.
Reports weekly active users climbing from the low hundreds into the thousands, a catalog of well over a thousand distinct apps across more than fifty orgs, and roughly four in five users outside engineering.
engineering.block.xyz/blog/from-localhost-to-launched-safely-shipping-apps-that-anyone-can-build · observed 2026-08-23
Reports 1,100+ governed metrics, 1,812 Block Data MCP and 1,899 Query Expert users in Q1 2026, 400M queries monthly, and a third of the company (2.1K monthly users) on Query Expert by March 2026.
engineering.block.xyz/blog/building-the-data-foundation-for-automated-analytics · observed 2026-08-23
Reports a 2,000+ app migration run with agent swarms, with Terminal-Bench benchmark figures labelled as benchmarks and kept separate from the migration account.
engineering.block.xyz/blog/effective-teams-buzz · observed 2026-08-23
Adverse evidence
Level 2 · repeated and concrete
Publishes a pilot dashboard that shipped incorrect data from a sampling-logic flaw, a first single-MCP design users rejected ('I can't trust this') that was discarded and rebuilt as two servers, and CodeCrucible's initial missed detection with stated recall and precision bounds.
Admits a pilot dashboard displayed excellent visuals over incorrect data from a subtle sampling-logic flaw, and states the fix: authoritative sources plus test scaffolding.
engineering.block.xyz/blog/from-localhost-to-launched-safely-shipping-apps-that-anyone-can-build · observed 2026-08-23
Admits the initial single-MCP design failed both audiences and records finance leadership's 'I can't trust this'; the design was discarded and rebuilt as two specialized servers.
engineering.block.xyz/blog/building-the-data-foundation-for-automated-analytics · observed 2026-08-23
States the Copy Fail vulnerability was initially missed without steering, that recall is bounded by the first pass and precision by the batch-local audit, and that repeated at-scale rescanning is unsolved.
engineering.block.xyz/blog/codecrucible-a-blueprint-for-llm-driven-sast · observed 2026-08-23
Reproducible mechanism
Level 2 · repeated and concrete
Publishes the identity-delegation token flow end to end, CodeCrucible's chunking, budget-gate, and deduplication blueprint, and Buzz's object-store guarantees specified in TLA+ with a backend conformance suite.
Publishes the four-component delegation design: edge identity issuer, token exchange, consent control plane, and authorization data plane, with effective capabilities computed as the intersection of user grants and delegated consent.
engineering.block.xyz/blog/whos-asking-identity-delegation-for-ai-agents-and-service-meshes · observed 2026-08-23
Publishes the SAST blueprint another engineer could challenge: semantic late chunking with intact file boundaries, budget gates, per-phase prompts, and CWE-keyed deduplication.
engineering.block.xyz/blog/codecrucible-a-blueprint-for-llm-driven-sast · observed 2026-08-23
Publishes Git-on-object-storage as content-addressed packfiles plus one mutable manifest pointer, with three object-store guarantees specified in TLA+ and a required backend conformance suite.
engineering.block.xyz/blog/buzz · observed 2026-08-23
Engineer authored cadence
Level 2 · repeated and concrete
Eight first-party practitioner articles between April and August 2026 cover distinct internal systems: agent collaboration, an internal app platform, data governance, security scanning, identity delegation, and distributed inference.
A practitioner account of configuring five production agents: instruction layers, memory tiers, harness and provider choices, and effort tuning.
engineering.block.xyz/blog/configuring-agents-in-buzz · observed 2026-08-23
A principal engineer's account of distributed inference over pooled idle compute, including its latency and best-effort limits.
engineering.block.xyz/blog/buzz-sharing-compute-powered-by-meshllm · observed 2026-08-23
A multi-role engineering account (tech lead, data engineers, AI engineer, platform engineering) of the data foundation build.
engineering.block.xyz/blog/building-the-data-foundation-for-automated-analytics · observed 2026-08-23
Human and societal consequences
Level 2 · repeated and concrete
A whole article keeps the human's identity and bounded consent attached to every agent action, with revocation and non-delegable capabilities; Buzz states that authorization does not erase authorship and argues against infrastructure lock-in of identities, history, and work; the MeshLLM post states plainly that prompts sent to another machine are visible to its owner.
Designs agent authority as 'this engineer, through this software actor acting on their behalf, with this bounded authority, for this request', with user revocation and capabilities that cannot be delegated at all.
engineering.block.xyz/blog/whos-asking-identity-delegation-for-ai-agents-and-service-meshes · observed 2026-08-23
States that authorization does not erase authorship, that owner revocation disconnects agents, and that running the infrastructure shouldn't mean owning the identities, history, or work.
engineering.block.xyz/blog/buzz · observed 2026-08-23
States plainly that prompts and any data sent to another machine are visible to its owner, and that compute should be shared only with people you trust.
engineering.block.xyz/blog/buzz-sharing-compute-powered-by-meshllm · observed 2026-08-23