Weekly Research Update · Sept 7, 2026

Two of our oldest projects became commands — and the rubric may be scoring itself

Weekly Research Update · Monday, September 7, 2026 · a ~4-minute catch-up
Seven cards, about 30 seconds each. Two long-running projects closed by vendor features, one experiment whose success condition is a shorter file.
EDGEPOINTE · VANTAGE
The one-paragraph read

Two hand-rolled projects became vendor features in the same 48 hours. Tailwind

On September 3 Anthropic shipped ant apply — agents, environments, skills, memory stores and deployments declared in files and applied from a committed lockfile, with a plan you approve before it runs. On September 4 Claude Code shipped /skill-doctor, which reports unused loaded skills and what they cost in context.

Between them they answer the buildable half of the repo-level constraint that has been act-now for nine consecutive weeklies, and the whole of the skill-trim — across a roughly fifty-skill portfolio nobody has audited. Neither is a project any more. Both are commands.

The approve-the-plan step is exactly the AI proposes, a person posts discipline already adopted for Google Ads — now native.

Bottom line: declare two skills, not fifty. A lockfile that mis-maps a resource is worse than no lockfile.
Evals · the sixth amendment

A paper says the rubric leaks its own answer. This week's experiment deletes criteria. Method

A paper submitted August 31 finds that classifiers trained only on rubric text — with no access to any response — predict judge outputs at nontrivial accuracy. And judges often fail to change their verdict when the criterion is reversed.

Last month's worry was that judges agree for shallow reasons. This is sharper: if a score can be predicted from the wording of the criterion before anything is looked at, the criterion is not measuring the page — it is announcing an expectation. A criterion that scores the same when you invert it is not a criterion. It is decoration.

The test is small and runs against the rubric we already have: score every criterion against a blank page, then against its own inverted wording. Anything that does not move is an artifact.

Bottom line: a delete-list, not a build. First experiment on this board whose success is a shorter file.
Cloudflare · our stack

A hard new gate on crawling, six times the bundle headroom, and text rasterization at the edge. Act now

Crawl gate
August 31. The crawl endpoint now enforces the Content Signals use directive. If a target's robots file is more restrictive than what you declare, the request is rejected with a 400 — it does not degrade. That lands directly on the cloner. Grep the capture pipeline; if it is entirely Chrome-driven, exposure is nil and the row closes in five minutes.
Bundle size
September 4. The compressed ceiling is gone; it is now a flat 64 mebibytes uncompressed on every plan — roughly six times the headroom on Paid. Headroom, not permission. Record today's number as a baseline and stop treating size as a live constraint.
Images binding
September 2. Rasterize text over an image, and hand a client a signed direct-upload link with no API token in the browser. That is a per-tenant share image with no design step, and the right shape for owner photo upload.
Bottom line: prototype the share image first — self-contained, visible, demoable in a pitch.
The clock · and a framing device

The zone check is eight days out, third consecutive week at the top, still never run. Overdue

The scope is confirmed and unchanged: the new AI-bot defaults hit new customers, new sites, and all existing free-plan customers. Existing paid customers keep their settings, and mixed-use crawlers get blocked on pages that host ads.

Two facts decide our entire exposure and neither is recorded: plan tier per tenant zone, and ad presence. Vantage tenants are venue and small-business marketing sites that do not run ads, which very likely makes the answer no exposure. Likely is not recorded. It is a dashboard check.

New this week is the commercial half: Pay Per Crawl is now Pay Per Use, and the trigger moved — publishers get paid when content is used in an answer, not when a bot fetches the page. Almost certainly not economic at one venue's traffic. Its value is that "you get paid when an AI uses your content" makes AI visibility feel like an asset instead of an expense. Do not promise revenue.

Bottom line: five minutes, Ed's dashboard, third week at the top. Record the zero and close it.
Competitive · one correction, one concession

Webflow's platform is a gated preview. But "they can't build a portal" has stopped being true. Position

The correction, and it is favourable. Webflow Source is a limited research preview enrolling select partners — not a shipping product. Campaigns is in beta, purchasable next month. Last week's daily read it as imminent and reordered the stack; the substance stands, the calendar is softer. The "why doesn't Vantage run my ads" paragraph is still owed — the question a prospect asks does not wait for general availability.

The concession. Duda's Vibe shipped built-in user authentication on August 31, and forms plus AI-search optimization on September 4. Authentication is the line between a website and an application. A builder that generates a site with a login is generating something shaped like an owner portal.

Do not overstate it — a login screen is not a multi-tenant dashboard wired to a lead inbox, receptionist, reviews and analytics. The bundle is still ours. But the phrase should come out of the pitch before a prospect finds it.

Bottom line: the bake-off against a beta can be honestly timed — and joined to the Duda test as one sitting.
Channel + acquisition

AI is becoming native, not an add-on. And security became its own exit multiple. Tailwind

Pia's Q3 release ships a plain-language automation builder and 48-plus ready-to-deploy packs — a published list of what a funded vendor believes is worth automating. But the item that should change behaviour is Teams as the service desk: users trigger real fixes and view tickets without a call or a portal login. Our clients are Microsoft 365 clients; Teams is already open on every desktop. Read the catalog — it is free — and build Teams-native intake for the top three ticket types.

The channel says MSPs are past the AI add-on conversation. If AI is native to every platform, an "AI tier" reads as an upsell for something competitors include. Write the positioning as outcome pricing with AI included — calls answered, leads captured, tickets closed.

And the number that moved: the security premium over a comparable MSP widened from about 1.5× to 2.5× EBITDA since 2020. Recurring share still drives the multiple — security is now a second, independent lever, and it is widening.

Bottom line: carry two lines to Bob — recurring share, and security-attributable recurring revenue inside it.
Card 1 / 7 · ~20s