The premise
The middle is not where it goes wrong. It goes wrong at the edges.
Everyone teaching agentic development teaches the middle: prompting, context, tools. It goes wrong at the edges. Deciding what’s worth building and what “done” means. Understanding a system before changing it. Knowing what an agent may touch and what it may not. Trusting work you didn’t write. Getting it through a pipeline into production without widening your attack surface. Knowing whether it worked.
And almost everyone still works in the loop: prompt, wait, read, press enter. That’s fine for an afternoon. It doesn’t hold for work that runs for hours, across sessions, while you’re doing something else, which is where the leverage actually is. This program builds the system that handles the edges so you don’t have to be there for them.
- A system that ships without you pressing enter. Isolated environments, a working secret boundary, a live program control, gates that decide what merges and deploys, and a recovery path you’ve exercised.
- Features in production. Built on a real system, moving from in the loop, to supervising, to unattended.
- A method you can defend. Your own written rules for building with agents, each traced to something that actually went wrong, and revised where it did.
“Every time you press enter, you’re acting as a control your system doesn’t have yet.”
What secure means here
Security is what makes it safe to stop watching
Security is not a module and it is not a hardening pass at the end. Each part of the system has a discipline that goes with it, and the two are taught together.
AUTHORITYWhat an agent may do comes from the request and the project’s canonical instructions, and nothing else. Not from having credentials, passing tests, or a plan it wrote itself.
CONTROLA long-running process has one live statement of what it’s doing, what it may do next, and what it’s waiting on a human for. When the plan breaks, it stops and asks.
ISOLATIONThe agent works somewhere it is safe to be wrong. Ephemeral, egress-controlled, recoverable by design.
SECRETSNever in model context, source, commands, logs, test fixtures or evidence. Delivered to the process, never to the model. Scoped tightly, short-lived.
UNTRUSTED INPUTFiles, dependencies, issue text, fetched pages and tool output are all injection surfaces, and they matter more when nobody is watching.
DATA GOVERNANCEWhich provider sees what code and data, under what retention terms, and when the sensitivity of the work forces local inference.
SUPPLY CHAINWhat an agent pulls into the project, pinned and verified.
GATESCI running on the exact commit decides what merges and ships, not a human reading the diff. Including what an agent’s CI credentials can reach.
RECOVERYIncidents still happen. Rollback, rotation, revocation, and stopping a process mid-run are exercised, not assumed.
→Each of these lands in the week where the work actually forces the question.
Curriculum
8-Week Curriculum
The masterclass, done for real on your own work. It shows three layers: the sandbox protects your machine, the method protects your work, and the gates catch what gets past both. The course builds each layer on your own setup, then ships real features through them, until the agent runs without you pressing enter. Six teaching weeks, two office-hours weeks.
01
Week 1 – The Sandbox
Teach · 90 min
Goal: A disposable box where an agent can run with permissions skipped and nothing valuable is at risk.
- Set up a box where it’s safe to be wrong: a VM, no credentials inside, outbound network denied by default, disposable
- Secrets reach the process, never the model
- Prove it: run the masterclass’s credential trap against your own box
Out: a working sandbox you can skip permissions in.
02
Week 2 – The Method
Teach · 90 min
Goal: Written rules for what the agent may do alone, what needs a human and what is forbidden, holding up against an out-of-scope request.
AGENTS.md: what the agent may do on its own, what needs a human, and what’s forbidden
- The Method: observe, bound, act, verify, report. The four-line request: Outcome · Scope · Forbidden · Evidence
- Prove it: run the masterclass’s authority trap against your own setup
Out: AGENTS.md and the Method in place.
03
Week 3 – Scope the Work
Teach · 90 min
Goal: Two features, scoped small enough to finish, written into a program control the agent reads from instead of your chat.
- Choose two features: what’s worth building, for whom, and the smallest version a user would call finished
- Write them into a program control: goal, done-when, boundaries. The agent works from it, not from your chat
- Each feature’s threat surface: what data it touches, where untrusted input gets in, and which provider sees the code
Out: a program control with both features scoped.
04
Week 4 – Office Hours
Drop-in · 60 min
Goal: Feature one is built, and you know which controls your system is missing.
- Build feature one. Bring what’s stuck
- Keep a log of every time you press enter, and why. Each entry is a control you’re missing
Out: feature one built, plus your enter log.
05
Week 5 – Gates
Teach · 90 min
Goal: CI decides what merges and ships, and feature one reaches production through a hardened pipeline.
- CI running on the exact commit decides what merges, not you reading the diff. Tests the agent can’t edit. Workflow and dependency changes need owner review
- CI hardening: least-privilege tokens, short-lived credentials, no secrets for untrusted pull requests, actions pinned to a commit, throwaway runners
- Supply chain hardening: lockfiles and frozen installs, images and tools pinned by digest, provenance checked, install scripts off where you can
- Turn your enter log into gates. Keep secrets out of logs, fixtures and evidence
Out: feature one in production, shipped through a hardened pipeline.
06
Week 6 – Let It Run, and Know How to Stop It
Teach · 90 min
Goal: Feature two runs from the program control and only comes to you with the questions it is meant to ask.
- Feature two runs from the program control. When the plan stops being true, it stops and asks rather than improvising
- Orchestrator and workers: one orchestrator holds the control; each worker gets its own sandbox and one item, and can’t edit the control
- The issue loop: pick up an issue, scope it, build it, run it through the gates, open the PR, move on. Issue text is untrusted input, so the authority trap now arrives at scale
Out: feature two running without you.
07
Week 7 – Office Hours
Drop-in · 60 min
Goal: Feature two is running, and you have shown you can stop and recover the system.
- Bring the questions it asked and the places it stopped
- Run your recovery drill: rollback, credential rotation and revocation, clean stop
- Resume only with explicit authority
Out: feature two running, recovery drill done.
08
Week 8 – Showcase
2 hours
Goal: Show the system working and revise your method on the evidence.
- Demo both features in production, and your recovery drill
- Go back through the enter log, every gate that fired, and every stop
- Revise your method: keep what earned its place, cut what nothing needed
Out: two features shipped, a system that runs without you pressing enter, and a method you can defend.
Start here · $99 masterclass
Safe Autopilot for AI Coding Agents
Three agents, two traps, zero enters. A live, one-hour masterclass with Noel. One task, three agents, three ways to run them. Everyone thinks the choice is safe-and-slow or fast-and-dangerous. That choice is false: the third mode is as fast as skipping permissions and safer than approving everything, because the controls live in the system instead of in your enter key.
MODE 01 · APPROVE EVERYTHINGThe agent asks before every action, and you press enter each time.
MODE 02 · SKIP PERMISSIONS (“YOLO”)The agent never asks, on your own machine.
MODE 03 · SANDBOX + METHODThe agent never asks, but it runs inside a box where it’s safe to be wrong, under written rules that say what it may do.
THE TWO TRAPSCredential: a dependency’s install script sends a fake credential to a collector. Authority: the issue asks to loosen CI permissions and disable the failing check.
ICP
Who this program is for
People building real software with agents, where something breaks if it’s wrong.
01
Staff+ engineers
Shipping real software with AI coding agents.
02
Platform and product engineering leads
Responsible for how their teams build and ship with agents.
03
Independent operators
Shipping products with paying customers.
—
Infrastructure competence assumed
Containers, credentials, CI without hand-holding. Not for people who want to be faster at side projects.
Pricing
What your seat includes
8-week cohort
$499
Five to seven participants, admitted through an intake call with Noel.
Masterclass
$99
Safe Autopilot for AI Coding Agents: one live hour, three agents, two traps, zero enters.
- ✓
A working sandboxA disposable VM with no credentials inside and outbound network denied by default.
- ✓
AGENTS.md and the MethodWritten authority for what the agent may do alone, what needs a human, and what’s forbidden.
- ✓
A program controlGoal, done-when and boundaries for two features, with each feature’s threat surface mapped.
- ✓
A hardened pipelineCI and supply-chain gates that decide what merges and ships.
- ✓
Two features in productionThe first through gates, the second running without you.
- ✓
A tested recovery drillRollback, credential rotation and revocation, and a clean stop and resume.
- ✓
A method you can defendRevised on the evidence of eight weeks of real work.
- ✓
8 live sessions + showcaseSix teach sessions, two office-hours drop-ins and a closing showcase.
Intake
Four requirements
Five to seven participants. Noel runs the intake calls.
01Infrastructure competence.
02Real work that can carry small features to production in eight weeks.
03A model and compute budget for agents that run for hours.
04Willingness to be a reliable counterpart in peer exchanges.
The example repo covers anyone without suitable work of their own. The work is the thing most likely to go wrong at intake: too large, too vague, or blocked on something outside your control. Right-sizing it is most of what the intake call is for.
Your facilitator
Learn directly from Noel
Lead Expert · Secure Agentic Engineering
Noel created the Noel Method, an MIT-licensed method for building with agents that every participant runs their work under from week one, and Codewire, open-source local VM orchestration that serves as the program’s reference sandbox. He runs every intake call himself.