Over the last few months, I have been thinking about a simple but uncomfortable question:

If AI tools are becoming part of our engineering workflow, how much access should we actually give them?

It is tempting to connect an AI assistant directly to a server and say, "Check what is wrong with production."

But if the way you do that is by exposing a raw shell, you have effectively created a remote terminal controlled by a probabilistic system.

That is not engineering. That is gambling.