How we bound AI in a regulated system
Long-form engineering writing for the architects and security reviewers who evaluate platforms like this one. We publish the decisions behind Samba — including the ones that cost us something — because the architecture is the argument.
Two Grammars: Why Constrained Decoding Doesn't Replace a Domain Contract
Cirrus Tempo Engineering • March 16, 2026The word "grammar" is doing two unrelated jobs in AI engineering. Constrained decoding (XGrammar, Guidance) guarantees well-formedness. Domain contracts guarantee legality. They're complementary — and one cannot do the other's job, no matter how far you push it.
Grammar Is Discovered, Not Designed
Cirrus Tempo Engineering • April 15, 2026The instinct when you need a grammar is to sit down and write it. That instinct is wrong. A grammar written before the domain has taught you what it needs formalizes ignorance. This essay traces how a production grammar earned its shape — four files of drift, two wrong architectural positions, a catalog gap diagnosed by three consecutive wrong answers, and a plumbing bug masquerading as a grammar gap.
Why AI Needs a Typed Contract to Talk to Your System
Cirrus Tempo Engineering • May 12, 2026The hardest problem in AI integration is the AI talking to the system, not the human. A typed contract — an explicit, externally inspectable grammar — bridges the AI's output and the system's acceptance criteria as a single source of truth across both task-execution and problem-solving modes.
Domain Grammars as a Single Source of Truth for AI-Authored Integrations
Cirrus Tempo Engineering • June 8, 2026Scattering rules across prompt blocks, UI forms, and code creates architectural drift that silently corrupts AI behavior. A single declarative YAML grammar consumed simultaneously by AI prompts, runtime validators, and CI/CD parity tests eliminates that drift between grammar and code — and stops precisely where two grammar layers get composed into one prompt.