{
  "name": "Swfte how-to guides",
  "description": "Step-by-step guides for building, deploying, validating, governing, securing and operating AI on infrastructure you control. Each typed guide has a markdown twin at the \"markdown\" URL.",
  "hub": "https://www.swfte.com/how-to",
  "generatedFrom": "src/data/howto (scripts/generate-howto-index.mjs)",
  "latestVerification": "2026-10-07",
  "count": 26,
  "journeys": [
    {
      "id": "build",
      "label": "Build"
    },
    {
      "id": "deploy",
      "label": "Deploy"
    },
    {
      "id": "validate",
      "label": "Validate"
    },
    {
      "id": "govern",
      "label": "Govern"
    },
    {
      "id": "secure",
      "label": "Secure"
    },
    {
      "id": "comply",
      "label": "Comply"
    },
    {
      "id": "operate",
      "label": "Operate"
    }
  ],
  "guides": [
    {
      "slug": "how-to-audit-ai-systems",
      "title": "How to Audit AI Systems: Scope, Evidence, Findings",
      "h1": "How to audit AI systems",
      "url": "https://www.swfte.com/how-to-audit-ai-systems",
      "markdown": "https://www.swfte.com/how-to/how-to-audit-ai-systems.md",
      "summary": "How to audit an AI system, internally or for a client: scope it, choose criteria, request and sample evidence, test logs, change control and human oversight, and write findings that can be fixed.",
      "journey": "validate",
      "difficulty": "Intermediate",
      "time": "Two to four weeks for one system, depending on how quickly evidence arrives",
      "totalMinutes": 4800,
      "stepsCount": 10,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "audit",
        "evidence",
        "ISO 42001",
        "NIST AI RMF",
        "EU AI Act",
        "logging"
      ],
      "primaryQuery": "how to audit an AI system"
    },
    {
      "slug": "how-to-build-a-company-brain-for-ai",
      "title": "How to Build a Company Brain for AI: A Practical Guide",
      "h1": "How to build a company brain for AI",
      "url": "https://www.swfte.com/how-to-build-a-company-brain-for-ai",
      "markdown": "https://www.swfte.com/how-to/how-to-build-a-company-brain-for-ai.md",
      "summary": "Build a permission-aware knowledge layer for AI: resolve identities, copy access lists from each source, keep provenance, retrieve under access control, and test freshness and leaks.",
      "journey": "build",
      "difficulty": "Intermediate",
      "time": "Two to three days for one source and one team, then about a week per extra source",
      "totalMinutes": 1200,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "company brain",
        "knowledge",
        "permissions",
        "retrieval",
        "knowledge graph"
      ],
      "primaryQuery": "how to build a company brain for ai"
    },
    {
      "slug": "how-to-build-a-rag-system",
      "title": "How to Build a RAG System: Step-by-Step, Runs Locally",
      "h1": "How to build a RAG system",
      "url": "https://www.swfte.com/how-to-build-a-rag-system",
      "markdown": "https://www.swfte.com/how-to/how-to-build-a-rag-system.md",
      "summary": "Build a retrieval-augmented generation system end to end on one machine, with hybrid search, per-group permissions, citations and a retrieval test set.",
      "journey": "build",
      "difficulty": "Intermediate",
      "time": "About 90 minutes to a working system, plus time to collect your own documents",
      "totalMinutes": 90,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "rag",
        "retrieval",
        "pgvector",
        "ollama",
        "evaluation"
      ],
      "primaryQuery": "how to build a rag system"
    },
    {
      "slug": "how-to-build-an-ai-agent",
      "title": "How to Build an AI Agent in 2026 (Code & No-Code)",
      "h1": "How to Build an AI Agent in 2026 (Code & No-Code)",
      "url": "https://www.swfte.com/how-to-build-an-ai-agent",
      "markdown": null,
      "summary": "Build an agent as a loop with tools, a turn budget and an eval set: define a narrow job, pick a build path, connect tools, choose models per step, test, deploy and observe.",
      "journey": "build",
      "difficulty": "Intermediate",
      "time": "About an afternoon for the loop; longer for the eval set",
      "totalMinutes": 240,
      "stepsCount": 6,
      "lastVerified": "2026-07-27",
      "datePublished": "2026-07-27",
      "topics": [
        "agents",
        "tool use",
        "evals",
        "no-code"
      ],
      "primaryQuery": "How to Build an AI Agent in 2026 (Code & No-Code)"
    },
    {
      "slug": "how-to-build-an-air-gapped-ai-environment",
      "title": "How to Build an Air-Gapped AI Environment (2026)",
      "h1": "How to build an air-gapped AI environment",
      "url": "https://www.swfte.com/how-to-build-an-air-gapped-ai-environment",
      "markdown": "https://www.swfte.com/how-to/how-to-build-an-air-gapped-ai-environment.md",
      "summary": "Stage model weights, container images and Python packages on a connected machine, verify and carry them across, run the model with every online lookup switched off, and prove nothing leaves.",
      "journey": "deploy",
      "difficulty": "Advanced",
      "time": "Allow one to two days for the first environment, mostly waiting on downloads, transfers and approvals. Later updates take a few hours.",
      "totalMinutes": 720,
      "stepsCount": 8,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "air-gapped",
        "offline",
        "model supply chain",
        "vLLM",
        "Ollama",
        "egress testing"
      ],
      "primaryQuery": "how to build an air-gapped ai environment"
    },
    {
      "slug": "how-to-choose-an-llm-for-your-company",
      "title": "How to Choose an LLM for Your Company: A Scorecard",
      "h1": "How to choose an LLM for your company",
      "url": "https://www.swfte.com/how-to-choose-an-llm-for-your-company",
      "markdown": "https://www.swfte.com/how-to/how-to-choose-an-llm-for-your-company.md",
      "summary": "A selection process, not a leaderboard: requirements, a hosted and open-weight shortlist, a test on your own tasks, a weighted scorecard, licence and data-terms checks, and an exit plan.",
      "journey": "build",
      "difficulty": "Beginner",
      "time": "About 2 to 5 working days, mostly collecting the test cases and reading terms. The test runs themselves take hours.",
      "totalMinutes": 1800,
      "stepsCount": 7,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "model selection",
        "scorecard",
        "licensing",
        "data terms",
        "vendor exit"
      ],
      "primaryQuery": "how to choose an llm for your company"
    },
    {
      "slug": "how-to-create-your-own-local-model",
      "title": "How to Create Your Own Local Model: LoRA to GGUF",
      "h1": "How to create your own local model",
      "url": "https://www.swfte.com/how-to-create-your-own-local-model",
      "markdown": "https://www.swfte.com/how-to/how-to-create-your-own-local-model.md",
      "summary": "Adapt a small open-weight model to your own examples on one machine, convert it to GGUF, run it locally and check it beats the base model on cases it has not seen.",
      "journey": "build",
      "difficulty": "Advanced",
      "time": "About 1 day for a first working model: a few hours for data, then training time that depends on your hardware and example count.",
      "totalMinutes": 480,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "lora",
        "qlora",
        "gguf",
        "ollama",
        "llama.cpp",
        "mlx"
      ],
      "primaryQuery": "how to create your own local model"
    },
    {
      "slug": "how-to-deploy-an-llm-in-the-eu",
      "title": "How to Deploy an LLM in the EU: Data Residency Steps",
      "h1": "How to deploy an LLM in the EU",
      "url": "https://www.swfte.com/how-to-deploy-an-llm-in-the-eu",
      "markdown": "https://www.swfte.com/how-to/how-to-deploy-an-llm-in-the-eu.md",
      "summary": "Choose between EU-region hosted APIs, a self-hosted open-weight model on EU infrastructure, or on-premises, then check storage, processing, logs, support access and sub-processors, and test where requests actually run.",
      "journey": "deploy",
      "difficulty": "Intermediate",
      "time": "About half a day to choose and configure a hosted EU option; one to two days to add a verification test and write the record. Self-hosting adds the time in the self-hosting guide.",
      "totalMinutes": 480,
      "stepsCount": 7,
      "lastVerified": "2026-10-07",
      "datePublished": "2026-10-06",
      "topics": [
        "EU",
        "data residency",
        "hosted APIs",
        "self-hosting",
        "transfers",
        "sub-processors"
      ],
      "primaryQuery": "how to deploy an llm in the eu"
    },
    {
      "slug": "how-to-detect-shadow-ai",
      "title": "How to Detect Shadow AI in Your Organisation",
      "h1": "How to detect shadow AI",
      "url": "https://www.swfte.com/how-to-detect-shadow-ai",
      "markdown": "https://www.swfte.com/how-to/how-to-detect-shadow-ai.md",
      "summary": "Define what counts as unsanctioned AI, then find it through identity grants, network logs, expense data and a short staff survey, rank what you find by the data it touches, replace the risky tools with approved ones, and keep monitoring in a proportionate way.",
      "journey": "govern",
      "difficulty": "Intermediate",
      "time": "About one to two weeks for a first sweep; then a monthly review",
      "totalMinutes": 3000,
      "stepsCount": 8,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "shadow AI",
        "discovery",
        "OAuth",
        "governance",
        "data protection"
      ],
      "primaryQuery": "how to detect shadow ai"
    },
    {
      "slug": "how-to-do-a-dpia-for-ai",
      "title": "How to Do a DPIA for AI: GDPR Article 35 Steps",
      "h1": "How to do a DPIA for AI",
      "url": "https://www.swfte.com/how-to-do-a-dpia-for-ai",
      "markdown": "https://www.swfte.com/how-to/how-to-do-a-dpia-for-ai.md",
      "summary": "Decide whether an AI system needs a DPIA, then describe the processing, assess necessity, identify risks to people, choose measures, record the sign-off and review it, with AI-specific risks and a worked example.",
      "journey": "comply",
      "difficulty": "Intermediate",
      "time": "Allow two to five working days for a first DPIA on a moderately complex system, spread over a few weeks for the consultations and sign-off.",
      "totalMinutes": 1800,
      "stepsCount": 7,
      "lastVerified": "2026-10-07",
      "datePublished": "2026-10-06",
      "topics": [
        "DPIA",
        "GDPR",
        "Article 35",
        "risk assessment",
        "FRIA",
        "personal data"
      ],
      "primaryQuery": "how to do a dpia for ai"
    },
    {
      "slug": "how-to-evaluate-an-open-source-llm",
      "title": "How to Evaluate an Open-Source LLM: Hands-On Steps",
      "h1": "How to evaluate an open-source LLM",
      "url": "https://www.swfte.com/how-to-evaluate-an-open-source-llm",
      "markdown": "https://www.swfte.com/how-to/how-to-evaluate-an-open-source-llm.md",
      "summary": "Check the licence first, write a small task set of your own, run it against the full-precision and quantised model, add a public benchmark as a sanity check, measure speed and memory, and write down the decision.",
      "journey": "validate",
      "difficulty": "Intermediate",
      "time": "About 4 hours for one candidate, plus the time to write your task set",
      "totalMinutes": 240,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "evaluation",
        "open-weight models",
        "licences",
        "quantisation",
        "lm-evaluation-harness"
      ],
      "primaryQuery": "how to evaluate an open source llm"
    },
    {
      "slug": "how-to-fine-tune-an-llm-on-your-own-data",
      "title": "How to Fine-Tune an LLM on Your Own Data (2026)",
      "h1": "How to fine-tune an LLM on your own data",
      "url": "https://www.swfte.com/how-to-fine-tune-an-llm-on-your-own-data",
      "markdown": "https://www.swfte.com/how-to/how-to-fine-tune-an-llm-on-your-own-data.md",
      "summary": "The decision and the method: when fine-tuning beats prompting and retrieval, how to build and split the dataset, two training routes, how to evaluate, and what it really costs.",
      "journey": "build",
      "difficulty": "Advanced",
      "time": "About 1 to 2 weeks end to end, most of it on data and evaluation. The training run itself is usually the shortest part.",
      "totalMinutes": 4800,
      "stepsCount": 7,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "fine-tuning",
        "sft",
        "dataset",
        "evaluation",
        "openai fine-tuning",
        "trl"
      ],
      "primaryQuery": "how to fine tune an llm on your own data"
    },
    {
      "slug": "how-to-govern-ai-agents",
      "title": "How to Govern AI Agents: Identity, Policy, Approvals",
      "h1": "How to govern AI agents",
      "url": "https://www.swfte.com/how-to-govern-ai-agents",
      "markdown": "https://www.swfte.com/how-to/how-to-govern-ai-agents.md",
      "summary": "Govern agents at runtime: list every agent, give each an identity and an owner, write down what it may and may not do in a Trust Profile, enforce allow, deny and approve rules, choose an autonomy level, record every action and review on a schedule.",
      "journey": "govern",
      "difficulty": "Intermediate",
      "time": "About one week for the first inventory, profiles and policy on your main agents; then a standing monthly review",
      "totalMinutes": 2400,
      "stepsCount": 8,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "agent governance",
        "identity",
        "policy",
        "autonomy levels",
        "Trust Profile"
      ],
      "primaryQuery": "how to govern ai agents"
    },
    {
      "slug": "how-to-migrate-from-openrouter-or-litellm",
      "title": "How to Migrate from OpenRouter or LiteLLM (Safely)",
      "h1": "How to migrate from OpenRouter or LiteLLM",
      "url": "https://www.swfte.com/how-to-migrate-from-openrouter-or-litellm",
      "markdown": "https://www.swfte.com/how-to/how-to-migrate-from-openrouter-or-litellm.md",
      "summary": "Inventory what you use, map model names, replay real requests against old and new routes, switch the base URL, then canary the traffic with a rollback ready.",
      "journey": "operate",
      "difficulty": "Intermediate",
      "time": "About 1 to 2 days of work for one application, plus a canary period of a few days",
      "totalMinutes": 480,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "migration",
        "OpenRouter",
        "LiteLLM",
        "LLM gateway",
        "parity testing"
      ],
      "primaryQuery": "how to migrate from openrouter"
    },
    {
      "slug": "how-to-monitor-ai-agents-in-production",
      "title": "How to Monitor AI Agents in Production (2026 Guide)",
      "h1": "How to monitor AI agents in production",
      "url": "https://www.swfte.com/how-to-monitor-ai-agents-in-production",
      "markdown": "https://www.swfte.com/how-to/how-to-monitor-ai-agents-in-production.md",
      "summary": "Give every agent run an id, record each model and tool step as a span, redact before you store, alert on loops, tool failures and cost per run, and read a weekly sample by hand.",
      "journey": "operate",
      "difficulty": "Advanced",
      "time": "About 4 hours for tracing, redaction and the first alerts; the weekly review is ongoing",
      "totalMinutes": 240,
      "stepsCount": 8,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "observability",
        "tracing",
        "OpenTelemetry",
        "Langfuse",
        "alerts"
      ],
      "primaryQuery": "how to monitor ai agents in production"
    },
    {
      "slug": "how-to-prepare-for-the-eu-ai-act",
      "title": "How to Prepare for the EU AI Act: 2026 Readiness Steps",
      "h1": "How to prepare for the EU AI Act",
      "url": "https://www.swfte.com/how-to-prepare-for-the-eu-ai-act",
      "markdown": "https://www.swfte.com/how-to/how-to-prepare-for-the-eu-ai-act.md",
      "summary": "A readiness workflow for the EU AI Act: inventory AI systems, rule out prohibited uses, set provider or deployer role, classify risk, plan obligations and evidence, and track the dates after the Digital Omnibus.",
      "journey": "comply",
      "difficulty": "Intermediate",
      "time": "About one to two weeks for a first inventory and classification of a mid-sized organisation, longer if tools are bought across many teams. Evidence work continues after.",
      "totalMinutes": 4800,
      "stepsCount": 8,
      "lastVerified": "2026-10-07",
      "datePublished": "2026-10-06",
      "topics": [
        "EU AI Act",
        "readiness",
        "risk classification",
        "Digital Omnibus",
        "AI literacy",
        "evidence"
      ],
      "primaryQuery": "how to prepare for the eu ai act"
    },
    {
      "slug": "how-to-red-team-an-llm",
      "title": "How to Red Team an LLM App: Tools, Scoring, Retest",
      "h1": "How to red team an LLM",
      "url": "https://www.swfte.com/how-to-red-team-an-llm",
      "markdown": "https://www.swfte.com/how-to/how-to-red-team-an-llm.md",
      "summary": "A step-by-step LLM red-team exercise: authorisation and scope, a threat model mapped to the OWASP LLM Top 10, automated testing with promptfoo, garak and PyRIT, manual attack sessions, scoring, fixes and retest.",
      "journey": "secure",
      "difficulty": "Advanced",
      "time": "Two to five working days for a first exercise on one application",
      "totalMinutes": 1800,
      "stepsCount": 10,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "red teaming",
        "security",
        "OWASP LLM Top 10",
        "promptfoo",
        "garak",
        "PyRIT"
      ],
      "primaryQuery": "how to red team an LLM"
    },
    {
      "slug": "how-to-reduce-llm-costs",
      "title": "How to Reduce LLM Costs: Step-by-Step Guide (2026)",
      "h1": "How to reduce LLM costs",
      "url": "https://www.swfte.com/how-to-reduce-llm-costs",
      "markdown": "https://www.swfte.com/how-to/how-to-reduce-llm-costs.md",
      "summary": "Measure token spend per feature first, then apply the levers in order of payoff: output caps, prompt caching, batch APIs, model routing, response caching, and a self-hosting break-even check.",
      "journey": "operate",
      "difficulty": "Intermediate",
      "time": "About 3 hours to add measurement and the first three levers; routing and batch work take longer",
      "totalMinutes": 180,
      "stepsCount": 8,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "cost",
        "prompt caching",
        "batch API",
        "model routing",
        "FinOps"
      ],
      "primaryQuery": "how to reduce llm costs"
    },
    {
      "slug": "how-to-run-llms-locally",
      "title": "How to Run LLMs Locally: Ollama, LM Studio, llama.cpp",
      "h1": "How to run LLMs locally",
      "url": "https://www.swfte.com/how-to-run-llms-locally",
      "markdown": "https://www.swfte.com/how-to/how-to-run-llms-locally.md",
      "summary": "Install Ollama, LM Studio or llama.cpp, download a model that fits your memory, chat with it and call it from code through a local OpenAI-compatible endpoint.",
      "journey": "deploy",
      "difficulty": "Beginner",
      "time": "About 20 to 30 minutes, most of it downloading the model.",
      "totalMinutes": 25,
      "stepsCount": 7,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "ollama",
        "lm studio",
        "llama.cpp",
        "quantisation",
        "local api"
      ],
      "primaryQuery": "how to run llms locally"
    },
    {
      "slug": "how-to-secure-mcp-servers",
      "title": "How to Secure MCP Servers: OAuth, Scopes, Allow-Lists",
      "h1": "How to secure MCP servers",
      "url": "https://www.swfte.com/how-to-secure-mcp-servers",
      "markdown": "https://www.swfte.com/how-to/how-to-secure-mcp-servers.md",
      "summary": "Harden an MCP deployment against the attacks the specification names: validate token audience, never pass tokens through, ask for minimal scopes, sandbox local servers, allow-list servers, gate sensitive tools with a human, and log every call.",
      "journey": "secure",
      "difficulty": "Advanced",
      "time": "About half a day to inventory and apply client-side controls; one to three days to harden a server you build",
      "totalMinutes": 480,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "MCP",
        "OAuth",
        "tool security",
        "agents",
        "allow-list"
      ],
      "primaryQuery": "how to secure mcp servers"
    },
    {
      "slug": "how-to-self-host-an-llm",
      "title": "How to Self-Host an LLM with vLLM (2026 Guide)",
      "h1": "How to self-host an LLM",
      "url": "https://www.swfte.com/how-to-self-host-an-llm",
      "markdown": "https://www.swfte.com/how-to/how-to-self-host-an-llm.md",
      "summary": "Serve an open-weight model as a private, OpenAI-compatible endpoint on your own GPU server, with memory sizing, authentication, TLS, metrics and an upgrade routine.",
      "journey": "deploy",
      "difficulty": "Advanced",
      "time": "About 2 to 3 hours for a first working endpoint; add a day for hardening, monitoring and a load test.",
      "totalMinutes": 180,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "vllm",
        "self-hosting",
        "gpu sizing",
        "openai-compatible api",
        "inference"
      ],
      "primaryQuery": "how to self host an llm"
    },
    {
      "slug": "how-to-self-host-chatgpt-alternative",
      "title": "How to Self-Host a ChatGPT Alternative (Open WebUI)",
      "h1": "How to self-host a ChatGPT alternative",
      "url": "https://www.swfte.com/how-to-self-host-chatgpt-alternative",
      "markdown": "https://www.swfte.com/how-to/how-to-self-host-chatgpt-alternative.md",
      "summary": "A hands-on setup of Open WebUI in front of a model you host, with admin accounts, roles, HTTPS, backups and a clear view of where prompts go.",
      "journey": "deploy",
      "difficulty": "Intermediate",
      "time": "About 1 to 2 hours for a working pilot, plus time for single sign-on and a short policy for users.",
      "totalMinutes": 90,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "open webui",
        "ollama",
        "chat interface",
        "self-hosting",
        "team workspace"
      ],
      "primaryQuery": "how to self host a chatgpt alternative"
    },
    {
      "slug": "how-to-set-up-an-llm-gateway",
      "title": "How to Set Up an LLM Gateway with LiteLLM (2026)",
      "h1": "How to set up an LLM gateway",
      "url": "https://www.swfte.com/how-to-set-up-an-llm-gateway",
      "markdown": "https://www.swfte.com/how-to/how-to-set-up-an-llm-gateway.md",
      "summary": "Run the open-source LiteLLM proxy in Docker with a config file, add a model, issue virtual keys with budgets, set fallbacks, wire health checks, and harden it for production.",
      "journey": "operate",
      "difficulty": "Intermediate",
      "time": "About 2 hours to a working, budgeted gateway; a day to production-harden it",
      "totalMinutes": 120,
      "stepsCount": 9,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "LLM gateway",
        "LiteLLM",
        "virtual keys",
        "fallbacks",
        "budgets"
      ],
      "primaryQuery": "how to set up an llm gateway"
    },
    {
      "slug": "how-to-set-up-human-approval-for-ai-agents",
      "title": "How to Set Up Human Approval for AI Agents (With Code)",
      "h1": "How to set up human approval for AI agents",
      "url": "https://www.swfte.com/how-to-set-up-human-approval-for-ai-agents",
      "markdown": "https://www.swfte.com/how-to/how-to-set-up-human-approval-for-ai-agents.md",
      "summary": "Decide which agent actions need a person, set thresholds, pause the agent with LangGraph interrupts, route requests to a queue with a timeout that denies by default, show reviewers the evidence, and record every decision.",
      "journey": "govern",
      "difficulty": "Intermediate",
      "time": "About half a day for the design, one to two days to wire in and test",
      "totalMinutes": 720,
      "stepsCount": 7,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "human in the loop",
        "approvals",
        "agents",
        "LangGraph",
        "oversight"
      ],
      "primaryQuery": "how to set up human approval for ai agents"
    },
    {
      "slug": "how-to-stop-prompt-injection",
      "title": "How to Stop Prompt Injection: Layered Defences That Work",
      "h1": "How to stop prompt injection",
      "url": "https://www.swfte.com/how-to-stop-prompt-injection",
      "markdown": "https://www.swfte.com/how-to/how-to-stop-prompt-injection.md",
      "summary": "A layered defence for prompt injection: assume it will happen, keep untrusted content apart from instructions, give agents the fewest tools and shortest-lived privileges, require human approval for risky actions, block data leaving, and test with canary documents.",
      "journey": "secure",
      "difficulty": "Intermediate",
      "time": "About one to two days to map and apply the controls to one application",
      "totalMinutes": 720,
      "stepsCount": 8,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "prompt injection",
        "security",
        "agents",
        "OWASP LLM01",
        "defence in depth"
      ],
      "primaryQuery": "how to stop prompt injection"
    },
    {
      "slug": "how-to-validate-your-ai",
      "title": "How to Validate Your AI: Eval Sets, Gates, Evidence",
      "h1": "How to validate your AI",
      "url": "https://www.swfte.com/how-to-validate-your-ai",
      "markdown": "https://www.swfte.com/how-to/how-to-validate-your-ai.md",
      "summary": "A system-level method to validate an AI product: define the task and risk, build a held-out eval set, score it, gate releases, sample for human review, monitor and keep an evidence pack.",
      "journey": "validate",
      "difficulty": "Intermediate",
      "time": "One to two working days for the first suite; minutes per release after that",
      "totalMinutes": 720,
      "stepsCount": 10,
      "lastVerified": "2026-10-06",
      "datePublished": "2026-10-06",
      "topics": [
        "evaluation",
        "validation",
        "eval sets",
        "LLM-as-judge",
        "regression gates",
        "evidence"
      ],
      "primaryQuery": "how to validate an AI system"
    }
  ]
}
