"Show a smile, hide the blade."
— The 36 Stratagems, Conceal a Dagger in a Smile
Previously on this series: #5: Leo Walked Into a Burning Hou...
For further actions, you may consider blocking this person and/or reporting abuse
I enjoyed the contrast between Leo and Lena here. Leo optimized for solving today's problem, while Lena was thinking several steps ahead about incentives and long-term positioning. Different strengths, but they create very different outcomes.
That's exactly it. Leo sees the problem in front of him and fixes it — that's how he landed the CodeForge contract at 3AM. Lena sees the system underneath. Same intelligence, just different time horizons.
What I liked about writing these two is neither approach is wrong. They're just playing different games. Leo's game is "fix this before it breaks." Lena's is "make sure when it breaks, it only breaks where you already drew the box."
Thanks for reading that closely 😁
The detail that rings truest is the read-only token. In SaaS security reviews, read-only is the most disarming word there is: everyone fears write access, but the leverage lives in egress, and a read-only scope over historical data is exactly what you need to build a baseline nobody else can rebuild. The practical counter is treating that dependency like backups: run a periodic restore drill where the team produces the report with the vendor out of the loop. If the drill fails, the lock-in is already architectural, whatever the contract says. I consult for a living, and the honest version of Lena's playbook is the same trust-building with the knife-check inverted: the deliverable includes everything the client needs to fire me.
Read-only token and egress leverage — you nailed the two things that make Lena's approach work. The restore drill countermeasure is smart, but I suspect most teams only think about it after they've already signed the renewal.
Curious though — what's the most creative lock-in you've seen that didn't involve a single line of code?
I can answer from both chairs. I built and own a SaaS with many business customers, and my strongest retention lever contains zero code: the customer's operating history lives in the product and their staff's muscle memory is trained on it. Nobody churns from software they would have to re-teach their own team to leave.
But the most creative one I saw came from my years doing risk modeling inside a large credit bureau: the score name itself. When a vendor's metric becomes the organization's vocabulary, quoted in policies, contracts, even regulatory filings, switching is no longer a migration, it is a retranslation of every decision rule the company runs on. Lena was not embedding a tool, she was embedding vocabulary.
My public work is at vinimabreu.dev, including the bug bounty research that trained me to read contracts the way Lena writes them.
Right - so he made CoreStack dependent on VeriTest's stuff, without realizing until it was too late to do anything about it - "sleepwalking into a situation", haven't we all done it at some point? Nice one, curious to see how it all keeps unfolding!
"Sleepwalking into a situation" — that's exactly it. He wasn't tricked into signing anything shady. He just kept saying yes to things that felt helpful, one at a time, until the exit door disappeared.
That's the part I wanted to land. Not the knife — the fact that he didn't feel it go in.
Thanks for reading, and for the perfect phrase😁
Maybe it's also a bit of laziness or complacency, he got the solution he wanted without putting a lot of effort into it, or without feeling the urge to dig more or to question things, kind of understandable ... but yeah, "sleepwalking into a situation" is a more 'poignant' way to put it :-)
Haha, shame this series is an AI-driven semi-tech semi-fiction thing — otherwise I honestly think Leo and Lena could've had something going. Queen and her knight vibes, you know?🤣🤣🤣
Queen and her knight, nice one - could surely pursue that direction, but not here on dev.to, it would feel a bit odd ... maybe an idea for a "spin off" which you publish on another platform - the possibilities are endless!
Yeah, that's for later. The focus right now is clear — keep polishing each story within the 36 Stratagems framework, and make sure all six protagonists get their own arc worth reading.
Really glad this one landed — "predictability over deception" cuts straight to what makes these patterns work in real organizations. Nobody needs to be tricked. They just need to be given a path that feels like the obvious choice.
And the mirror vs miracle framing — that's exactly it. AI doesn't change human nature, it just makes it visible at a higher resolution. The same biases that existed before get amplified, and that's where the interesting stuff happens.
Appreciate you reading this closely. Means a lot.
Also, since you mentioned looking forward to the next stratagem — I'm still polishing it, but here's a small spoiler: the next one shifts direction a bit, and goes deeper into this protagonist's inner world than anything I've written so far. Stay tuned. 🔥
Is this what you call reading closely? I don't think so, but yes, if I had a superpower, I would certainly be able to read it closely.
keep smiling keep laughing!!
Look! Up in the sky! It's a bird! It's a plane! It's SuperDivyanshi! 🦸♀️🤣
No, no, no!!—this has become so funny, lol.
Templates become dangerous when people treat them as neutral infrastructure. A template carries defaults, incentives, and blind spots. In AI systems that matters even more because the template can quietly define what the agent sees, what it skips, and what it treats as normal.
Exactly this. The scary part is that a template doesn't need to be malicious to be dangerous — it just needs to be taken as neutral. Lena's template worked perfectly for what it was supposed to do. The knife wasn't in the code; it was in the assumption that the template was just a template.
That is why templates need to be reviewed almost like policy, not just starter code. They decide what is easy, what is hidden, and what feels normal. If the defaults quietly encode the wrong contract, every team that adopts the template inherits that contract before they realize they made a decision.
That café scene with the banknote under the coaster got me. Lena isn't evil, she's just professional. She overpays for coffee and moves on to the next page. Leo is the one who made this personal. She was always just doing her job.
Finally someone noticed the coaster scene 🙌 Lena doesn't do personal. She does the work, overpays for coffee, and turns the page. That's not cold — that's just her normal.
the 'methodology notes section' placement is the real design decision. not the data clause in section 7, not the read only token — the citation that lives exactly where nobody reads is what turns a single quarter trial into a structural dependency.
we hit the same thing with a RAG eval vendor. they defined the benchmark categories, we accumulated 8 months of data in their format, and by month 9 switching meant losing the baseline every decision was anchored to. the framework didn't own our data, it owned our measurement vocabulary.
the VP Strategy who paused at the small print. did she flag it, or file it for later?
You caught the real trap. The clause wasn't hidden — it was visible in the exact place nobody reads. That's the whole design.
As for VP Strategy — she filed it. People who pause at small print don't flag things. They bookmark them.