Back Office · office.temerarii.xyz
One asset, all the way in — composition, the wireframe + storyboard, the output format stack, and the template, all read from the SAME content-index record. The expected output matches what /media surfaces for this post.
post longform-W35-Wedkind longformweek W35date 2026-09-02campaign longform-youtubepillar multimediabeat asset videoduration 145.4sground whitescenes 7

Checklist the per-video bar — engine/sim

98.2/100
plain languagevo coverageno dead airuniquenesscaption fitcompletenesscleanliness
quantitative quality · weights learn from your reviews (engine.sim.memory review longform-W35-Wed good|bad)
⚠ 1 flag(s) — not yet ship-ready: copy_generic · see docs/strategy/VIDEO-CHECKLIST.md

Composition comp · template family · expected output

composition LongFormChaptersfamily / template LongFormChapters
9:16 Reelpending1:1 Squarepending16:9 Widepending9:16 4Kpending1:1 4Kpending16:9 4KpendingGIF (SMS)pending
render pending — silent master not yet on disk
expected output: 0/7 rendered — same matrix the /media preview surfaces for this asset.

Composition layer × scene 7 scenes · 145.4s · comp_id + rendered still + tier + the script

#Layer (comp_id · still · tier)BeatTimecodeMotionLogoAudioVO / on-screen / caption
1s1
matches intent
shared field
signature-3d
open0–22.0sspatial-parallaxicon·color♪ bed_in
This week is about choosing an automation platform with no copy-paste. Today, the part people skip until it bites them: cyber security. When one agent can touch your email, your money, and your data, a small hole is a big hole. We will teach plain moves to lock down an automated system before you hand it real keys, not after.
on-screen: Lock it down before you trust it
expected on screen: white ground · octa hero in the shared Signal Field · Lumen leads · node-graph · spatial-parallax · icon·color logo · caption bottom-left
spec (the prompt): comp_id shared Signal Fieldvisual node-graphshape octaground whitetreatment colormotion spatial-parallaxpower summoninstrument summon→Lock it down before you trust it
2s2
matches intent
NumberedList
template
teach22.0–45.8skinetic-buildicon·color♪ node_lock
First rule: least privilege. Each key, each tool, gets only the access it truly needs and nothing more. The thing that sends email should not be able to delete the database. Make a separate key per job. When one leaks, the damage is one job wide, not company wide. A platform that wants one master key for everything is asking you to bet the farm.
on-screen: Give each tool the least it needs
expected on screen: white ground · a NumberedList panel over a dimmed Signal Field · Lumen leads · node-graph · kinetic-build · icon·color logo · caption bottom-left
spec (the prompt): comp_id NumberedListvisual node-graphshape octaground whitetreatment colormotion kinetic-buildpower morphinstrument morph+laser→Give each tool the least it needscurate items, nodes
3s3
matches intent
ChecklistCard
template
teach45.8–69.19999999999999skinetic-buildicon·color♪ node_lock
Second, keep secrets out of the workflow body. Store them in a secrets manager or an environment variable, and reference them by name. The step says use the email key, it never shows the key. Now you can screen-share the workflow, log it, even publish it, and nothing spills. If a tool prints your key in its own logs, that tool is the leak.
on-screen: Never paste secrets into the steps
expected on screen: white ground · a ChecklistCard panel over a dimmed Signal Field · Lumen leads · node-graph · kinetic-build · icon·color logo · caption bottom-left
spec (the prompt): comp_id ChecklistCardvisual node-graphshape octaground whitetreatment colormotion kinetic-buildpower morphinstrument morph+laser→Never paste secrets into the stepscurate items, nodes
4s4
matches intent
StepFlow
template
teach69.2–94.0skinetic-buildicon·color♪ node_lock
Third, treat every outside input as hostile until checked. A webhook, a form, a scraped page, all of it can carry a trick. Check the shape, the size, and where it came from before you act on it. Especially when a model reads outside text and then takes action, make a human approve anything that spends money or deletes data. The model is helpful, not your security guard.
on-screen: Trust no input from outside
expected on screen: white ground · a StepFlow panel over a dimmed Signal Field · Lumen leads · node-graph · kinetic-build · icon·color logo · caption bottom-left
spec (the prompt): comp_id StepFlowvisual node-graphshape octaground whitetreatment colormotion kinetic-buildpower morphinstrument morph+laser→Trust no input from outsidecurate nodes, steps
5s5
matches intent
NodeGraphCard
template
teach94.0–118.8skinetic-buildicon·color♪ node_lock
Our proof is forced on us by our own choice. We run the studio in public at office dot temerarii dot xyz, which means the locks have to be real, because the building has windows. We will not quote a breach count. The honest self-proof is that the keys live outside the code, each tool is fenced, and we built it that way before we opened the doors.
on-screen: We publish, so we lock down
expected on screen: white ground · a NodeGraphCard panel over a dimmed Signal Field · Lumen leads · node-graph · kinetic-build · icon·color logo · caption bottom-left
spec (the prompt): comp_id NodeGraphCardvisual node-graphshape octaground whitetreatment colormotion kinetic-buildpower morphinstrument morph+laser→We publish, so we lock downcurate hub, nodes
6s6
matches intent
RankList
template
proof118.8–140.4sreceipts-counticon·color♪ node_lock
So the takeaway: split your keys, hide them by reference, and distrust every input from the outside world. Put a human gate on anything costly. Then go see a system built to be looked at safely, at office dot temerarii dot xyz. Your next step is small: list every key you have, and ask what each one can break.
on-screen: Audit your keys at office.temerarii.xyz
expected on screen: white ground · a RankList panel over a dimmed Signal Field · Lumen leads · receipts · receipts-count · icon·color logo · caption bottom-left
spec (the prompt): comp_id RankListvisual receiptsshape octaground whitetreatment colormotion receipts-countpower receiptsinstrument spotlight→Audit your keys at office.temerarii.xyzcurate rows, statsLabels
7s7
matches intent
shared field
signature-3d
resolve140.4–145.4scoalescenceicon·color♪ bed_out
Multimedia proof: the generative + 3D pipeline, shown
on-screen: Chapter 6
expected on screen: white ground · octa hero in the shared Signal Field · Lumen leads · coalescence · coalescence · icon·color logo · caption bottom-left
spec (the prompt): comp_id shared Signal Fieldvisual coalescenceshape octaground whitetreatment colormotion coalescencepower coalescenceinstrument coalescence→Chapter 6

Format stack 1 aspects · same scenes[], re-cropped

16:9
1920×1080
X/Twitter · YouTube · LinkedIn video

Channels 2 destinations

YouTubeBlog

Social captions supplemental published copy · per channel (comp_id level)

youtubeHow to lock down an AI automation system before you hand it real keys When one agent can touch your email, your money, and your data, a small hole becomes a big one. This is the security part most people skip until it bites them. We walk through plain moves to lock down an automated system before it gets real access, not after. What you learn: - Least privilege: give each key and each tool only the access it truly needs. The thing that sends email should not be able to delete the database. One key per job, so a leak is one job wide, not company wide. - Keep secrets out of the workflow. Store them in a secrets manager or an environment variable and reference them by name. Then you can screen-share, log, even publish the workflow and nothing spills. - Trust no outside input. A webhook, a form, a scraped page can all carry a trick. Check the shape, the size, and where it came from before you act. When a model reads outside text and then takes action, put a human in front of anything that spends money or deletes data. We run the studio in public at office.temerarii.xyz, so the locks have to be real, because the building has windows. We will not quote a breach count. The honest self-proof is that the keys live outside the code and each tool is fenced, built that way before we opened the doors. Your next step is small: list every key you have, and ask what each one can break. Keywords: AI agent security, least privilege, secrets management, MCP automation safety.

Cross-links every lens is a view on this one record