Max Nardit

Max Nardit

Data & AI Systems Engineer working on visibility, measurement, and agentic systems.

AI now sits between people and what they’re looking for, and between work and the software that runs it. It answers, routes, remembers, forgets, and now acts on its own. Usually before anyone can check whether it got things right. I study that layer with original data and build the tools to work inside it. My background is the supply side of digital marketing: the crawl, the analytics, the automation and reporting, the plumbing under what looked like marketing. The marketing was never really the problem. Visibility, measurement, and control were. AI didn’t make that problem smaller. It moved it somewhere you can’t see.

Beetroot featured in 窓の杜 (Japan) · original-data research · shipped open-source tools

the systems that decide

what gets found, trusted,

and acted on

Thesis

Operating thesis

AI is changing two things at once: how people find information, and how work moves through software.

That shift isn’t only a search problem. It touches tracking, attribution, context, memory, handoff, and trust: the systems that decide what a person sees before they make a choice.

I work on that layer. Some of it is research: measuring what changes and publishing what holds up. Some of it is engineering: building tools and workflows that keep context, expose failures, and make AI-assisted work inspectable.

Focus

Current areas

Visibility & discovery
How people, businesses, and tools stay findable when AI systems answer, summarize, route, and act.
Measurement & tracking
How to know what’s working when clicks, cookies, referrals, and dashboards stop telling the whole story.
Agentic systems
Memory, handoff, orchestration, tool boundaries, and recovery for agents that touch real workflows.
Operational evidence
Original-data research, field notes, and shipped tools. Findings over forecasts.

Writing

Recent writing

All articles →

A model is a dependency that won't hold still

A pinned software library is an artifact you can inspect and rerun: if the output changed and you didn't, something you can read changed, and you can find out what. A model breaks that. It shifts behind an unchanged name, loses capacity without notice, and drifts in disposition, so a regression arrives with no cause you can point to and you waste a week blaming your own prompt. Treat it as a dependency you measure, not a foundation you trust: pin the version so you own the moment it changes, and fix a small panel of cheap metrics in advance so you can tell the vendor's drift from your own.

Your approval gate is a guess now

A security boundary is judged on the one action built to cross it, and a model judging by resemblance is weakest exactly there. The unattended allow belongs on the reach the harness itself grants, the write scope, the network, the credential, refusing what it cannot account for. Trust the model as the boundary and you rebuild the seam that prompt-injection detection could never close.

Your watchdog kills the busy agent and trusts the stuck one

A health check that watches whether a long-running agent still exists gets both hard cases wrong: it kills a healthy agent the moment it goes quiet enough to look absent, and it waves through a frozen one whose process is still up. The repair is not a sharper probe but a different signal, the durable trail an agent leaves only by doing the work, which a wedged one stops extending because extending it is the work.

Contact

Get in touch

Email or Telegram both reach me. Telegram is faster.