Thursday, 8 October 2026

Mendix VSIX for IDEs to do AI regression E2E testing

MendixWright is a free VS Code plug-in; please ask, and I'll email you a copy.

  • Documentation that matches the app, generated from the model rather than written by hand afterwards.
  • Regression coverage from day one, without hand-scripting each test.
  • Traceability from requirements to acceptance criteria to tests.
  • Built for Mendix developers, working in VS Code beside Studio Pro.

https://youtu.be/Z4r3jKSCyRY

Thursday, 1 October 2026

OWASP API Risks Updated - BOLA

As AI use and sophistication grow, BOLA attacks have risen rapidly.  Broken Object Level Authorisation (BOLA) is when an authenticated user can switch parameters like the URL in an API request and access other users' data. For example, GET https://api.example.com?client=32 returns the authenticated user's information, such as your age or other PII.

The authenticated user changes the client to "33"; I now get someone else's records, as the API only checks that I am an authenticated user, not that I am authorised to check another client.

ActionURLResult
GEThttps://api.example.com?client=32The user sends valid authentication for their own client.  The result returns their data.  Correct.
GEThttps://api.example.com?client=33The user sends valid authentication for their own client data but requests another client's info.  The result returns the other client's private data.  Incorrect behaviour.  Major security issue.

Tools like Wiz and StackHawk will pick up BOLA API weaknesses.

Sunday, 20 September 2026

Using StackHawk for DAST and API Security Testing on Azure

I recently started using StackHawk, and I am impressed with the tooling.  Its DAST and API security testing are outstanding, and it integrates beautifully with VS Code.

Application security requires more than simple source code scanning. While SAST, SCA, and secrets scanning are great in CI pipelines, key vulnerabilities remain hidden until an application is running. This is where Dynamic Application Security Testing (DAST) becomes essential.

In my development environment, Claude and GitHub Copilot are building my code and do so much of the Static Application Security Testing (SAST) 7I don't feel compelled to use them in the IDE.  Claude does a great job; it can do SAST and implement security best practices extremely well.

Software Composition Analysis (SCA) focuses on the third-party and open-source components our code relies on.  Claude once again does a great job of identifying vulnerabilities and upgrading to the latest versions.

Security secrets: Claude once again does a great job, especially with remote repo integrations such as GitHub, ADO, and GitLab.

Conclusion:

For enterprises building Azure-hosted web applications and APIs, StackHawk offers a developer-focused DAST approach that integrates directly into modern DevSecOps workflows. Unlike traditional DAST tools, which security teams often operate, StackHawk is designed to work with developers, providing rapid feedback during testing and deployment.  This "shift left" saves time and money. There are various DAST options, but StackHawk has become my favourite.  With the rise of AI coding, developer-level DAST is more important than ever.

BURP has been the standard for pen testing for many years.   Three DAST tools focus on different things: Burp Scanner, OWASP ZAP, and StackHawk.
Wiz API is a great test tool for API Security: runtime security, covering much of the same area as StackHawk for API security, but its key differentiator is runtime threat detection.

Saturday, 19 September 2026

Native Mobile App Development Notes

Overview: Many approaches exist for building and deploying native apps to the App Store (Apple) and Play Store (Android).  This post shows an approach that works well for converting a React web app into a Play Store app using the Expo toolchain.  The choice remaining is whether to use a wrapper or port the code to native UI. 

EXPO, as a company, has two independent products that work together nicely for mobile apps.

At one of my businesses, we are using the approach below successfully to deploy the core SaaS app onto the stores:
Using Expo products to build and deploy native Apps onto the two main public stores using a wrapper or native approach) 

Monday, 14 September 2026

An Introduction to Microsoft Azure SRE Agent

Managing cloud environments often involves jumping between alerts, logs, dashboards, and code repositories when something breaks.  Azure SRE Agent aims to simplify operational troubleshooting.  The tool:

  1. Investigate incidents
  2. Automates routine workflows
  3. Helps resolve issues faster

What is the Azure SRE Agent?

The SRE Agent combines 1) Brain - Large Language Models (LLMs, either OpenAI or Anthropic models) with 2) Azure-specific product knowledge - tools and knowledge, and 3) Instructions - custom configuration.  Allowing it to reason over operation support data.

The agent is deployed directly inside an Azure Resource Group, which sits within an Azure Subscription.  I have only used the Reader Scope for my assigned identity permissions; it can operate in Reader Scope (for inspection and telemetry analysis) or Privileged Scope (to execute changes and automated mitigations).

The Azure SRE Agent operates across three main operational patterns

Automate Incidents: When an alert fires, the agent queries monitoring platforms, correlates signals across systems, determines probable root causes, and suggests or executes fixes

Automate Scheduled Workflows: It can perform scheduled background tasks, such as routine health checks and compliance sweeps

Investigate and Advise (Virtual Team Member): Engineers can ask natural-language questions (e.g., "what changed in the last hour?") in chat interfaces like Microsoft Teams to get grounded operational insights.

Running Incident Response Issues

Instead of forcing engineers to manually correlate disparate data, the agent follows a streamlined incident workflow: when an alert fires (in Azure Monitor, in my case), the SRE agent picks it up.  It queries logs using correlation IDs to connect the data so that the agent can do the Root Cause Analysis & Ticketing: The agent identifies the probable cause (such as a bad commit or memory trend) and can prefill an incident ticket in ServiceNow or PagerDuty with diagnostic findings

The support engineer, in this case me, reviews and approves the remediation.

Connects natively with Azure Monitor, Application Insights, Log Analytics, PagerDuty, ServiceNow, GitHub, and Azure DevOps

Tip: External tools can also connect via the Model Context Protocol (MCP), basically making any API accessible.

Customisation: Capabilities can be extended using Skills (Azure CLI scripts and marketplace runbooks), Python tools, Custom sub-agents, and Agent hooks

Billing: Operational reasoning is metered using Agentic Units (AUs) rather than standard raw tokens, with standard monthly allocations; I still have no idea what this will cost or how it is calculated.

Summary

The Microsoft Azure SRE Agent provides a structured, governed way to use AI for incident management. By pulling together context from observability tools and code repositories into a single thread, it reduces tool switching and speeds resolution.

Friday, 11 September 2026

Create a single View of all your tenants subscriptions - easily identify Azure Credit availability

One Azure Dashboard for all Subscriptions in Your Azure Tenant

A production subscription. A development environment. A Microsoft for Startups sponsorship. Perhaps a Visual Studio subscription, a trial subscription, or a subscription dedicated to experimentation.

The information you need is scattered across Azure:

💰 Cost Management for spend
📦 Resource Graph for inventory
💳 Billing for credits and subscriptions
🔍 Individual subscription pages for everything else

I wanted a single place to answer three simple questions:

✅ What is running?
✅ What is it costing?
✅ How much Azure credit is left?

This solution creates an Azure Portal dashboard covering every subscription in a tenant.  Barclays Eagle Labs is amazing for startups, and they have helped me immensely, including getting Microsoft Startup Credits, and I think this will help a lot of people with their Startups.

What the dashboard shows

• Monthly cost per subscription
• Resource counts by subscription
• Resources grouped by type
• Complete resource inventory across all subscriptions
• Subscription offer type (Pay-As-You-Go, Sponsorship, Visual Studio, etc.)
• Billing account details
• Remaining Azure credit and expiry dates where available
• Direct links into Subscription Overview and Cost Analysis

Deployment in Four steps

1. Download the file:

  • New-SubscriptionsDashboard.ps1

2. Open Azure Cloud Shell and select PowerShell

3. Upload the New-SubscriptionsDashboard.ps1 file into your Cloud Shell home directory

4. Get your tenant ID, set the dashboard location and run the creation PowerShell script:

PS> $tenant = (az account show --query tenantId -o tsv)
PS> $region = "uksouth"   // Set your region for the new dashboard
PS> ./New-SubscriptionsDashboard.ps1 -Tenant $tenant -Location $region

5. Open the dashboard URL returned by the deployment.

Why I like this approach

The dashboard continuously updates resource inventory, resource counts and subscription costs using Azure Resource Graph and Cost Management, while also providing a snapshot of credit balances and billing information.

For organisations using multiple subscriptions, especially Azure Sponsorship or Microsoft for Startups credits, this gives a genuine single pane of glass across the entire tenant. No more jumping between Cost Management, Billing, Resource Graph and Subscription Overview pages. One dashboard. One view.



Wednesday, 9 September 2026

Introduction to EULYNX

Current position: Signalling has traditionally been set at the national level, which is hard to integrate when trains cross borders. It is expensive and harder to make interoperable. 

  • EULYNX is the digitalisation of the railway signalling industry.  
  • The aim is to create open, standardised interfaces between signalling system components.
  • Modular approach to signalling, offering standard interfaces for interaction. 
  • Reduces vendor lock-in and allows for modular replacement.
  • EULYNX publish documents on the architecture and interface specifications.
  • Covers architecture, components and interfaces.

EULYNX specifications cover the following subsystems:

  1. Signals & Object Controllers (SCI LS) 
  2. Points and point machines (SCI-P), Points and Switches
  3. Axle counters and train detection (SCI TDS), train block vacancy
  4. Level crossings (SCI LC/LX)
  5. IP-based communications (including RaSTA) (SCI IO) Interfaces
  6. Cybersecurity and networking interfaces (Core)
  7. Maintenance and Data Mgmt (MDM) (Core)
  8. Electronic Interlocking (Core)
Adjacent EULYNX systems communicate with:
  1. Radio Block Centre (SCI RBC),
  2. Traffic Management (SCI CC),
  3. Adjacent Interlocking (SCI ILS).

15 key partners are: DB InfraGO (Germany), Network Rail/GBR (UK), SNCF (France), RFI (Rete Ferroviaria Italiana), ÖBB (Austria), ProRail (Netherlands), Infrabel(Belgium), Croatia, Czech Republic, Finland, Luxembourg, Norway, Slovenia, Sweden, and Switzerland.

Understanding Railways Series:

UK Railway Industry for Dummies, focusing on Rail Infrastructure

Railway Infrastructure - Signalling

EULYNX Signalling (this post)

Sunday, 9 August 2026

Introduction to the Investment Landscape in the UK for SaaS Startups

Elevator Pitch - 30 seconds

  1. Hook: Start with the problem
  2. Who you are
  3. What problem you solve
  4. Why your solution is special
  5. What is the goal of each elevator pitch? Did I get it?

    AI generate template: "[Target customer] struggles with [problem], which costs them [$ / hours / risk]. I'm [name], founder of [company], and I [credibility]. We [solution], so they [key benefit]. Unlike [current alternative], we [differentiator]. We already have [traction]. I'd love to [specific ask]."

Product/Market Fit

You're in a good market with a product that meets its needs. Customers pull the product from you instead of you pushing it on them.  Have data that proves the business will work. Aim to be the best-in-class solution; attracting paying customers without advertising is ideal.  

Investors Looking for:

  1. Size of the business; how quickly can the product/business get there.
  2. Is AI a threat to the business,
  3. People's needs/wants - do they need this going forward, will they?  Move up the Maslow hierarchy of needs chain.
  4. Cloud native, API-centric, data-centric, AI, ML, security, 
  5. Show the roadmap, it must be clear: how will finance be used?
  6. They don't want capital-intensive businesses

Investment Stages

  1. Idea,
  2. Secure Founders,
  3. MVP,
  4. Seed (Angels, & Early VCs),
  5. Scale (Series A)
  6. Exit - Sell or IPO, average 7 years.

Capitalisation Table (who owns what in the business)

e.g. 50% ordinary shares to both founders
e.g. 35% each to both founders, Angel 20%, VC 10% at year 2.

Angels invest their own money; attractive to Angels get favourable tax breaks (SEIS/EIS)
Angel syndicates: groups of angels who invest; tools such as Odin/Funderbeam/FundMyPitch.
Venture Capitalist (VS) - Use "Risk and Reward" to decide on investing.  Seed VCs, focus on sectors or tax efficiency (EIS funds)

Ways to raise Funding:

  1. Bootstrapping (self-funding and/or customer financing thru revenue) 
  2. Equity (Pre-seed valuation typically £0.5-£1.5m, Seed with Revenue typically £1.5-£3m with Monthly Recurring Revenue MRR)
  3. Crowd Funding (can be a good fit but generally tougher than most think)
  4. Grants
  5. Debt funding

Tip: Don't let it drag on - get it done fast, 3- 6 months max.
Tip: Raise investment as late as possible.  
Tip: Build my investment strategy before looking for investors.
Tip: The investor must fit with the startup
Tip: UKPostbox.com apparently offer good services for registered offices.

"Delaware flip" is how a startup can switch to being incorporated in Delaware. Delaware company owns the original company.

IP: Business & IP Centre

General Business Readiness (Business plan including project financials and GTM): 

  1. Roadmap/Map your Journey
  2. Where is the startup on the journey
  3. Prove/show what has been done on the roadmap - Proof Points
  4. Client validation
  5. Differentiator
  6. Scale Potential
  7. Team

Recommended to me:

Zero to One by Blake Masters & Peter Thiel book


Friday, 17 July 2026

Testing for Coded Apps (automated E2E testing to get high quality)

Overview: Automation testing using AI generally ends with "test rot".  Kaizen Fix gets around test rot by switching the test source from the analysed system requirements to the code source as the logic to test.

Why: Gathering requirements in Agile software is continuously changing, so building tests based on the ask coupled with AI updating code realistically means the behaviour will change, DOM/Shaow DOM updating per build, and the full code base needs to be retested to ensure operational behaviour.

Hypothesis: Break the E2E testing into two distinct parts:
1) Does what the user asked for match what is delivered?  Ask AI to document the requirement from the code and compare it to the requirement the stakeholder signed off on. 
2) When code is updated, does this break any existing logic?  Regression tests to check existing logic work; if not, this requires a man in the loop to validate the change.

Proposed Solution: 
The four-step loop: 1. Code with AI → 2. Generate the code specification → 3. Tests generated by AI and MCP → 4. Test Baselines (run the dynamic Playwright test suites).  As the release occurs, the developer can automatically run the old tests and identify what is no longer working and why.  This can also be run during development.  I've been working on this different approach: an AI-assisted testing framework that treats the source code as the single source of truth — and turns it into a living, executable specification.

Key Point: reruns against the original/previous baseline catch genuine behaviour changes, not test rot. I deliberately left it unbranded so you can drop in KaizenFix (or keep it vendor-neutral) depending on where you're posting it.

How it works, in four steps:

1. Read the AI-generated code

AI (Claude or GitHub Copilot, working inside the IDE) analyses the application's source — components, routes, validation, business logic — and generates a full behavioural specification: what the system does today, fully documented, straight from the code.

2. Turn behaviour into programmed behaviour requirements

That specification becomes a structured requirements document. Not aspirational requirements — actual behaviour. If the app rounds a value, enforces a limit, or hides a button under a condition, it's captured.

3. Generate the regression suite

From the actual requirements into Playwright tests. AI generates detailed Playwright end-to-end tests — using platform-specific best practices for selectors and patterns, and environment configuration so the same suite runs against dev, UAT, or production. Each web app lives as its own isolated project with its own context and rules.

4. Lock in the baseline

At this point, the tests and the app agree by construction — the suite documents and validates the working behaviour. The tests part of the documentation.

The payoff comes when things change:

When the app or its logic evolves, rerun the original suite. Anything that breaks is a genuine, intentional-or-not change in behaviour — surfaced immediately, with the old expected values as evidence. Regenerate the spec, diff it against the last one, and you can see exactly what changed and whether you meant it. 

Amended +- June 2026 with Picture below: Source unknown


Thursday, 9 July 2026

Simple Explanation of LLM's, Coding Agents

      GitHub Copilot, Claude Code, and Cursor are not AI models!  They are Coding Agents/Assistants.

They are the developer experience layer that sits in your IDE and seamlessly accesses various Large Language Models (LLMs) such as Claud Opus/Fable/Sonnet/Haiku or GPT5.

The actual intelligence comes from the underlying Large Language Model (LLM) such as GPT-5, Claude Opus/Sonnet, Gemini, 

Naming breakdown:

  VS Code / Visual Studio /Claude Code (IDE)    

      ─────▼────

GitHub Copilot / Cursor Extension / Claude Code Extension        (Coding Agent)      

      ─────▼────

 GPT-5 / Claude Opus / Gemini (LLMs)

Local vs Premium LLMS: 

Cursor can reference online LLMs like Claude Opus and use Ollama to run Qwen3-Coder (my pref. for now), DeepSeek-Coder, Llama 3.x, Mistral.  Ollama lets me point to a local LLM and use it for free (saving on tokens; there are other advantages as well).

My Setup for local LLM usage:

VS Code                                   +
Cursor Extension                     +
Ollama                                     +
Local LLM (Qwen3-Coder)    = 🚀 AI-Powered Software Development

Azure Container Jobs with Docker containing E2E Playwright testing

Overview: I recently did a great project with Playwright to continuously test Canvas Apps.  This post outlines how I did it.

Reporting: Every test suite run and the tests inside are documented in SharePoint lists. p Below you can see for a project called feedback the tests that verify DTAP Canvas apps (Dev, Test, and Prod).

The Feedback app, in production, is showing the availability tests run recently
 

CI: I decided to use Azure Container Jobs to run the Playwright tests on a Docker image.


Jobs: The Docker image get params and starts the type of tests, the trigger uses cron timing.



Azure Container Job: Each time a job is called, a new instance is created. This means multiple jobs can run simultaneously, and on each job instance I get multiple COUs, so I spawn out 2-4 Playwright processes so the tests run faster.



Monday, 6 July 2026

Client-Side vs Server-Side Rendering Websites

Web applications generally fall into the CSR or SSR.

Feature Client-Side Rendering (CSR) Server-Side Rendering (SSR)
Rendering location Browser Server
Initial page load Slower Faster
SEO Worse Better
Server workload Lower Higher
Browser workload Higher Lower
Typical use Internal apps, dashboards Public websites, e-commerce
System Classification
  • Power Apps Canvas App
  • OutSystems (Low Code)
  • Mendix (Low Code)
  • React SPA
  • Flutter
  • Blazor WebAssembly
  • Angular
  • Vue
  • Power Pages
  • Next.js Website
  • ASP.NET MVC
  • PHP
  • E-commerce Product Page
  • Blazor Server
  • Ruby on Rails
  • Razor Pages

The table is worth understanding as it affects architectural decisions as the project progresses.



Sunday, 5 July 2026

Code Apps (Power Platform)

Code Apps (Power Platform) look to be gaining momentum. I think they will work for corporate app development as they offer governance and ALM as part of the Power Platform.   I saw this summary and thought it was a great overview.




Tuesday, 19 May 2026

AI infiltrates Development Segments so quickly

A decade ago, the companies that used Agile processes along these lines built the best software using CI/CD, and Automated Testing were the big winners. 


5 Years ago, low-code and platforms provided governance and faster ways to build apps.

We are seeing AI coming into all 6 steps, and low code is optional; it still offers good governance for businesses.


Test
Was: Unit Tests, Postman, Spec Flow, Selenium 
Becoming: Postman, MCP, Unit test generation

Deploy
Was: Scripts, PowerShell, TeamCity, Ansible, ARM, Portal UIs, TFS, Git, Terraform, Pulumi
Becoming: BICEP, MCP, VS Code/IDEs, GitHub, Claude CLI, GitHub Copilot

Code
Was: Java, C#, NodeJS, SDKs, RUST, GO APIs, Low-code/No-code
Becoming: Python, TypeScript, Power Platform, Agents

Saturday, 9 May 2026

Key Anthropic terminology for Ai (and Claude)

Overview: I have found that many people don't understand what Anthropic and Claude do, how they relate to each other, or how they fit into the AI industry.


The key takeaway is that Claude has two main parts: Tooling (e.g., Claude AI chat, Claude code, and Claude Cowork), and models for AI. The main product lines for these LLMs are Opus, Sonnet, and Haiku.

Saturday, 25 April 2026

VSCode with Claude Code or GitHup Copilot

Overview: I have seen people really struggling with understanding that Claude is not GitHub Copilot (GHCP).  And GitHub Copilot is not an LLM. 

Terminology: 

Claude by Anthropic is made up of various parts, and it helps to be more specific.  Calusde is amazing at providing great Large Language Models (LLMs).  There are Claude Opus (for programming the lastest us 4.7), Claud Sonnet, and Claude Haiku.  GPT-5.4 is OpenAI's current flagship LLM.  Gemini 3.1 Pro is known for UI-focused coding. I found Gemini 3.0 good, but I don't use it that often.   

Claude also offers other services beyond supplying LLMs like Claude Code and Claude CLI.  These are the key ones for me:

  • Claude in Chrome — a browsing agent
  • Cowork — a desktop tool for non-developers to automate file and task management, rival to Microsoft 365 Copilot.
  • GitHub Copilot for VS Code is the equivalent of Claude Code for VS Code

    Developing in VS Code:

    In the screen below, I am using both Claude Code and GitHub Copilot in the VS Code IDE.

    Here I have some C# code that creates and deploys an Azure Function. I can use either option until I run out of credits with my monthly (GHCP) or hourly (Claude) subscription allowance.  When I go over my GHCP allowance, I have it set up to use my Azure Credits.

    Wednesday, 22 April 2026

    Copilot Studio Custom Agent SharePoint Channel unexpected behaviour

    Overview: I have been using Copilot Studio for production solutions for a few weeks now, and I am impressed.  I pushed my fist Copilot Studio custom agent from using ALM into QA and Production, where I finished the iteration a week ago.  My boss was looking at the Agent in SharePoint and identified a bug with uploading files and using them.

    Anyway, I tested the scenario in other channels and in the Test area without issue.  In SharePoint, a Custom Copilot Agent can't upload a file to work with OOTB.






    Sunday, 15 March 2026

    Chess, I mean IT for beginners

    Medium- and large-sized IT projects often run into trouble at various points.  This analogy has helped me keep projects online and delivered, so I thought I'd share.

    Firstly, for those who don't know in depth about chess strategy, it generally goes something like this: 

    Opening, Middle and Endgame is how to break down a chess game.

    Chess Cheat Sheet for Beginners

    Opening Principles

    • Control the center: Aim for squares e4, d4, e5, d5.
    • Develop pieces early: Knights and bishops out before moving the same piece twice.
    • Don’t bring your queen out too soon: Avoid early queen moves.
    • Castle early: Protect your king and connect rooks.

    Middle Game Tips

    • Coordinate pieces: Make them work together.
    • Avoid unnecessary pawn moves: Pawns can’t move back.
    • Look for tactics: Pins, forks, skewers, discovered attacks.

    Endgame Basics

    • Activate your king: It becomes powerful in endgames.
    • Push passed pawns: They’re your winning ticket.
    • Rooks behind passed pawns: Classic endgame rule.

    General Rules

    • Every move should have a purpose.
    • Don’t sacrifice without clear compensation.
    • The threat can be more serious than the execution.
    As an Analogy, I find this extremely useful for getting all stakeholders working together and understanding how to do so.

    MVP cost balloons when “nice‑to‑haves” silently become “required”.  Not relatable to chess, except it is key, what are we doing in the Min viable Prod and why?  Think of it more like recon for the battle, learn, don't try to win it.

    Sunday, 15 February 2026

    Azure Networking Basics

     Here is an Overview of Azure Networking:


    Only some services offer private endpoints - I think private endpoints are basically NICs.  The DNS directs traffic to the private endpoint, which connects to the service (e.g., Key Vault).


    Entra ID App Registrations

    Overview: MS Graph and OAuth permissions must be assigned via Entra ID (IdP) App Registrations.

    App registration - is the definition of an app (API permissions it exposes, scopes, app roles, redirect URIs, etc.).

    Enterprise Application (Service principal) - the instance of that app in the Entra tenant, created after consent is granted.

    Consent is granted to an Enterprise Application instance/service principal, not by an app registration.

    Steps to Set up MS Graph Access for SharePoint Online (Site Collection Level Access)

    1. Register a new App Reg in Entra ID


    2. Add the MS Graph API Permission: Sites.Selected Delegated

    3. Using PowerShell 7, install the Pnp.PowerShell module and connect to PnPOnline

    PS> Install-Module PnP.PowerShell -Scope CurrentUser

    PS> Connect-PnPOnline -Url https://radimaging.sharepoint.com/sites/Contracts  -ClientID <xxx-xxx> -Interactive

     
    4. Assign the new App Registration to your SharePoint site, and you will need Site Collection Admin.

    PS> Grant-PnPAzureADAppSitePermission  -AppId "8f468b7c-9APP-YOU-WANT-TO-GRANT"   -DisplayName "My App"  -Site "https://<tenant>.sharepoint.com/sites/<site>" -Permissions Write

    Tip: You may want "Read" instead of "Write" permissions or another higher level.

    5. When you access the Site for the first time, you will be asked to provide consent (the administrator can also consent on behalf of business users).

    6. Verify that within Portal.azure.com > Enta ID > Manage > Enterprise Applications (find the app reg that has been consented to)

    7. Connect to the site using Postman or any client to verify you have the access you need.







    Thursday, 22 January 2026

    GitHub Copilot (GHCP) for VS Code - Notes

    I’m a big fan of using GitHub Copilot with VS Code. Right now, my preferred LLM is Claude Opus 4.5 — it’s so good.

    Anyway, these are my notes and findings for using GHCP:

    Custom Agents are built for a specific role or working style. You select an agent when you want Copilot to follow a particular set of instructions and use dedicated tools tailored to that job.

    Agent Skills, on the other hand, are reusable capabilities. They bundle instructions, scripts, and resources that Copilot can automatically draw on whenever they’re relevant—no need for you to choose or switch anything manually.

    Tuesday, 20 January 2026

    App Insights for Power Platform - Part 12 - A fix story

    Overview: My system notified me that my production errors were going crazy.  Quickly I knew all the tenants at my largest customer were down.  

    Problem: Apps would load and stay in a loading state.  I could see the Canvas apps but that is where is would continue try to load.  

    Initial Hypothesis: Originally, I thought is was 1 environment and I know it was loading a SharePoint list so i thought it may be permissions, but it was on all my environments and my continuous test was picking them all up.

    I checked the Microsoft Services and all the services are working: https://azure.status.microsoft/en-gb/status

    I went to QA and Dev and they were also failing with the same issue.  I ran the Canvas app in debug mode and could see the error was relating to Connectors to the European APIM for Dataverse.

    Next I went to other environments on my client in other regions, they too were also failing.  I was a bit surprised as I wasn't getting any feedback from other clients, or feeds, so i logged onto my own company Power Platform tenant and in environments, they were working.  So this was only to this specific client. And now I knew the extent, and i could not run flows only on the client environments.

    Here are the CI test report and results for a subset of the apps on the business units production environment.

    Ran a test to check a single Production department Environment with 24 Canvas apps:

    Simple test: runs on 3 worker processes on a single browser engine chromium.

    Reports logs show all 8 of these sites are not working

    All 8 tests were not finding the Title of the page.  I log from Playwright and from Canvas apps using App Insight traces, the error was supper easy to pickup even without the Power Platform trace in the Dev environment.

    Resolution: Raise a ticket, tell MS that we had the issue and provide the info (not raised by me, but by a support engineer).  30 minutes later, the company has been advised to close the browsers and try again.  Did this manually and issue resolved.

    I still had the old token for SPO in Playwright for Chromium, so I ran the test on for all 3 browser engines.  Chromium fails with the old token, Firefox and webkit pass as they grabbed new login tokens.
    Success: Same test using webkit browser engine - working as they have a new SPO Bearer token.


    If I find out what cause the issue, I'll post what MS did and found out.  


    Useful Dashboards I used:


















    Portal.azure.com OOTB App Insights Url to retrieve an OperationIDs' history
    https://portal.azure.com/#blade/HubsExtension/BladeRedirect/bladeName/Microsoft_Azure_LogicAppsRunBlade/
    runId/<OPERATION_ID>/ logicAppName/<LOGIC_APP_NAME>/ resourceGroupId/%2Fsubscriptions%2F<SUBSCRIPTION_ID>
    %2FresourceGroups%2F<RESOURCE_GROUP_NAME>%2Fproviders%2FMicrosoft.Logic%2Fworkflows%2F<LOGIC_APP_NAME>



    Series

    App Insights for Power Platform - Part 1 - Series Overview 

    App Insights for Power Platform - Part 2 - App Insights and Azure Log Analytics 

    App Insights for Power Platform - Part 3 - Canvas App Logging (Instrumentation key)

    App Insights for Power Platform - Part 4 - Model App Logging

    App Insights for Power Platform - Part 5 - Logging for APIM 

    App Insights for Power Platform - Part 6 - Power Automate Logging

    App Insights for Power Platform - Part 7 - Monitoring Azure Dashboards 

    App Insights for Power Platform - Part 8 - Verify logging is going to the correct Log analytics

    App Insights for Power Platform - Part 9 - Power Automate Licencing

    App Insights for Power Platform - Part 10 - Custom Connector enable logging

    App Insights for Power Platform - Part 11 - Custom Connector Behaviour from Canvas Apps Concern 

    App Insights for Power Platform - Part 12 - A fix story (this post)


    Thursday, 15 January 2026

    MS Fabric - Storage underpinning

     Microsoft Fabric get all its data from OneLake.  I believe all storage, except Real Time Intelligence (RTI), uses OneLake to ensure there is only one copy of the data.


    Left side of the diagram/Data sources:

    Any data source - copy data from any source into a Lakehouse, and the Parquet and Delta is stored in OneLake and exposed via the Catalog Layer

    Mirroring: Some data sources are mirrored into OneLake Parquet, including Snowflake, PostgreSQL, and Azure SQL 2025. 

    MS Fabric SQL is part of Fabric, and the SQL database is mirrored into OneLake.

    Shortcuts - 3rd party software holds the parquet* data and allows MS Fabric to query the data.   

    Sunday, 11 January 2026

    Working with Snowflake and MS Fabric

    Overview: Snowflake covers a small area of what Fabric does.  But Snowflake cover it's area unbelievably well.  For large enterprises use these together even though there is some overlap, Snowflake is great at what it does! 

    Five ways to use Snowflake data in Fabric: 

    1. ETL - use Data Factory or an ETL tool to copy data from Snowflake to Fabrics OneLake (point in time copy).  This should be your last option. 

    2. Direct query (no copy) - Fabric compute (Power BI, Notebooks, Dataflows, Pipelines) runs queries directly against Snowflake’s SQL endpoint. Best when you want zero‑copy and Snowflake stays the system of record.

    3. Mirroring (copy + sync) - Fabric mirrors a Snowflake database using CDC into OneLake so Fabric can work locally with governed, accelerated data while staying synced with Snowflake.  Good for small and commonly accessed data. 

    4. Shortcut to Snowflake‑hosted Iceberg (no data copy) - Fabric creates a Shortcut (virtual pointer) to Iceberg tables stored with Snowflake, so Fabric tools read them without moving data.

    5. Snowflake writes Iceberg to OneLake - Like option 3 but Snowflake handle the outbound - Snowflake materializes Iceberg tables into a OneLake location; Fabric then reads them natively (open‑format interop).

    Reference:
    Greg Beaumont's Architecture blog - Fantastic stuff! 

    Saturday, 10 January 2026

    SharePoint AI new features

     SharePoint has added some great AI components when coupled with M365 Copilot.  We have had this for a few weeks in GA:

    The Summarize feature is fantastic:

    • It works well in Word and Excel and is okay in PPTX files.
    • It processes images using OCR and AI to interpret them and generate a summary.
    • It works with PDFs/Adobe documents, including text with embedded images and image-based PDFs.  Pdf-A also.

    There is no MS Graph API yet for this functionality, so I used Playwright to scrape the summaries and add them to a summary metadata field.  I came across Knowledge Agent, which is in public preview, and it is fantastic.  

    Knowledge Agent (for SharePoint online if you have a M365 Copilot licence): 

    Knowledge Agent in the SPO UI

    If you need it enabled, as a SharePoint Admistrator you need to enable it using PowerShell.

    Generate metadata using your existing files and metadata as the example shows below: