Merit AC™
Content Days 1–3 free · rest $79 one-time

Prompts

A daily prompt archive on governed agentic DevSecOps — the prompt itself, why it's built that way, and what to do with the answer. Adapted from our own Enterprise Agentic DevSecOps Handbook: ten recurring control disciplines, a tour of fourteen platform domains, then six days building the capstone project behind the challenge.

Every prompt is a full role, context, numbered-steps, constraints, and output-format brief — copy it as-is into ChatGPT, Claude, or any other assistant. Where a step needs your repo or pipeline config, the prompt tells you what to paste in first. Days 1–3 are free, no signup required; the rest unlock with a single one-time payment -- see below.

0 of 30 days checked off

Days 1–10 · The ten control disciplines

Day 4: Audit what credentials the agent actually inheritsDiscipline 4 of 10 — Identity boundary
Day 5: Replace one broad tool with a narrow oneDiscipline 5 of 10 — Tool design
Day 6: List your independent validation gatesDiscipline 6 of 10 — Validation
Day 7: Design the approval screen for a real changeDiscipline 7 of 10 — Approval
Day 8: Reconstruct one execution path end to endDiscipline 8 of 10 — Observability
Day 9: Design the rollback you don't have yetDiscipline 9 of 10 — Failure handling
Day 10: Score this workflow against the production checklistDiscipline 10 of 10 — Production criterion

Days 11–24 · The fourteen domains

Day 11: Draw your own three-concern splitDomain 1 of 14 — Platform operating model
Day 12: Frame the rollout as capability uplift, not replacementDomain 2 of 14 — Cloud transformation and enablement
Day 13: Make your repository legible to an agentDomain 3 of 14 — Agentic-ready repository engineering
Day 14: Separate model access from tool authorityDomain 4 of 14 — Governed model access
Day 15: Map your stack onto AgentCore's modular servicesDomain 5 of 14 — Amazon Bedrock AgentCore
Day 16: Check whether your MCP tools still need authorizationDomain 6 of 14 — MCP, Identity, Gateway and Policy
Day 17: Confirm CI/CD, not the agent, gates promotionDomain 7 of 14 — Agentic DevSecOps pipelines
Day 18: Scale autonomy to consequence, explicitlyDomain 8 of 14 — Security engineering and approval boundaries
Day 19: Connect a request to its full traceDomain 9 of 14 — Observability and evaluation
Day 20: Put a number on whether the agent is actually helpingDomain 10 of 14 — DORA and delivery performance
Day 21: Check your region's actual authorization boundaryDomain 11 of 14 — GovCloud and regulated workloads
Day 22: Write the runbook for your riskiest agent workflowDomain 12 of 14 — Implementation runbooks
Day 23: Set your own baseline before you expandDomain 13 of 14 — 30/60/90-day rollout
Day 24: Build your own service-to-control mapDomain 14 of 14 — Technical reference

Days 25–30 · Build the capstone project

Day 25: Build the foundation, before the agent gets write accessCapstone 1 of 6 — Foundation
Day 26: Let the agent look, before it can touch anythingCapstone 2 of 6 — Read-only agent
Day 27: Let the agent make one small, reviewable changeCapstone 3 of 6 — Controlled code change
Day 28: Make sure the agent can't pass its own buildCapstone 4 of 6 — DevSecOps gates
Day 29: Add the human decision, and the rollback that has to workCapstone 5 of 6 — Approval and deploy
Day 30: Reconstruct the whole run from one correlation IDCapstone 6 of 6 — Observability and evaluation

$79 one-time

Days 1–3 are free forever, no signup required. Unlocking the rest is a single one-time payment -- no subscription, full access to all 30 days from then on.

Payment link coming soon — visit any locked day for the notify-me form

Looking for something other than the daily archive? The composed & advanced prompt library has 235 more — prompts that combine multiple AI system design patterns for real, non-trivial work, each one naming exactly which patterns it's built from.