Skip to content
Berktug Berke Ates

Software Engineer

Contact

Blogs

Field notes on software architecture, AI products, cross-platform engineering, reliability, and technical leadership.

Permission Models for Multi-Tenant AI CopilotsA multi-tenant AI copilot that inherits chat permissions but ignores data ACLs will confidently quote the wrong tenant. Tool calls need the same authorization path as your APIs—scoped per tenant, role, and resource. · 7 min readCache Invalidation for Personalized AI UIsPersonalized AI surfaces cache embeddings, completions, and UI fragments for speed—then serve the wrong user the wrong answer. Invalidation must track identity, entitlements, and prompt versions, not just TTL. · 7 min readDesigning Human Escalation Queues for AgentsAgents that never escalate look autonomous until they silently fail users. Escalation queues need triage rules, context packs, SLAs, and feedback loops—not a generic 'talk to a human' button bolted onto a chat UI. · 7 min readCost Attribution for Shared LLM GatewaysA shared LLM gateway without cost attribution becomes a black hole: teams optimize prompts locally while finance sees one opaque bill. Tag every token to tenant, product, and caller—or you cannot charge, throttle, or debug spend. · 7 min readOffline-First Sync Conflicts in Mobile AppsOffline-first UX promises continuity; sync promises eventual consistency. Without explicit conflict models, users see duplicated actions, lost edits, and support tickets that reproduce only on airplanes. · 7 min readFeature Store vs Prompt Store TradeoffsFeature stores optimize deterministic signals for models; prompt stores optimize language, tools, and policy for LLMs. Conflating them creates duplicate truth, stale context, and the wrong on-call. · 7 min readContract Testing for AI Tool CallingWhen models invent arguments or skip required fields, unit tests on the prompt are not enough. Contract tests turn tool schemas into enforceable boundaries between the model and your systems. · 7 min readProgressive Delivery for Multi-Tenant SaaSShipping the same binary to every tenant at once is a blast-radius choice. Progressive delivery lets you prove change on the right cohorts before the whole fleet feels it. · 7 min readMeasuring Retrieval Quality Without Vanity MetricsEmbedding similarity and click-through on demos do not prove retrieval helps users. Measure task success, grounded answer rates, and hard negatives that should return nothing. · 7 min readOwnership Models for Shared Platform CodeShared libraries without clear owners become everyone's dependency and nobody's incident. Pick an ownership model that matches blast radius, change rate, and who gets paged. · 7 min read