Max Nardit

Max Nardit

Data & AI Systems Engineer working on visibility, measurement, and agentic systems.

AI now sits between people and what they’re looking for, and between work and the software that runs it. It answers, routes, remembers, forgets, and now acts on its own. Usually before anyone can check whether it got things right. I study that layer with original data and build the tools to work inside it. My background is the supply side of digital marketing: the crawl, the analytics, the automation and reporting, the plumbing under what looked like marketing. The marketing was never really the problem. Visibility, measurement, and control were. AI didn’t make that problem smaller. It moved it somewhere you can’t see.

Beetroot featured in 窓の杜 (Japan) · original-data research · shipped open-source tools

the systems that decide

what gets found, trusted,

and acted on

Thesis

Operating thesis

AI is changing two things at once: how people find information, and how work moves through software.

That shift isn’t only a search problem. It touches tracking, attribution, context, memory, handoff, and trust: the systems that decide what a person sees before they make a choice.

I work on that layer. Some of it is research: measuring what changes and publishing what holds up. Some of it is engineering: building tools and workflows that keep context, expose failures, and make AI-assisted work inspectable.

Focus

Current areas

Visibility & discovery
How people, businesses, and tools stay findable when AI systems answer, summarize, route, and act.
Measurement & tracking
How to know what’s working when clicks, cookies, referrals, and dashboards stop telling the whole story.
Agentic systems
Memory, handoff, orchestration, tool boundaries, and recovery for agents that touch real workflows.
Operational evidence
Original-data research, field notes, and shipped tools. Findings over forecasts.

Writing

Recent writing

All articles →

The tool you install has your reach

An installed tool holds whatever authority you already have, and handing it over is the one security decision that gets no second look: taken once, in the least deliberate act of the whole install, and never revisited. You can contain what it can reach or read what its code actually touches; trusting the name does neither.

The compaction is an untrusted input

Input from outside gets a discipline and the agent's own output does not, so the summary it writes to survive a reset and the memory it recalls come back in as instructions with a standing nothing revoked. The author the harness records for them is the model itself, which is the exact reason the check lets them through.

A prompt is not an invariant

A rule you write into an agent prompt or a CLAUDE.md is advisory: the model reads it on every path but only weighs it, and weighing is not refusing, so it holds most of the time, and most of the time is not what a load-bearing rule is for. To make one actually hold it has to move to where compliance is not optional, a check the harness runs and enforces on its own, regardless of what the model decided. With a limit: a gate binds only over the paths it covers, and some rules cannot be settled at any gate at all, because their violation shows up in the world and not in the action it would inspect.

Contact

Get in touch

Email or Telegram both reach me. Telegram is faster.