Uploaded June 2026 | Updated September 2026, 1 day ago
David found Claude Code's workflows feature by accident. He asked Claude to QA its own output and Claude went and built him a full iterative test-fix-retest loop, two clean passes before exit, regression coverage included - because it had read his rules and knew he liked test-driven development. He didn't ask for any of that.
@thecote and David Zendzian use that as the way in. If a week of agentic vuln-finding turns up more than a big security firm finds in a year, what does that do to the buy-vs-build math? David reframes it: where do you want to spend your tokens? On your business app, on your own security tooling, or on someone else who's spending their tokens for you? "Why not both?" keeps coming up - and by the end it's a design principle, not a punchline.
Key topics:
- What Claude Code's workflows feature is actually doing when it feels like it read your mind
- "I love AI, I don't trust it" as an engineering posture, and how iterative QA loops operationalize it
- Where "where do you want to spend your tokens" is the more honest version of build-vs-buy
- What AI does to the security partner math when a week of vuln-hunting beats a decade of dedicated research
- Why "Why not both?" becomes a real design principle once UIs are cheap to generate
Interested in a platform that can help you with enterprise-y excellence? Check out: vmware.com/products/app-platform/tanzu
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote and David Zendzian
David found Claude Code's workflows feature by accident. He asked Claude to QA its own output and Claude went and built him a full iterative test-fix-retest loop, two clean passes before exit, regression coverage included - because it had read his rules and knew he liked test-driven development. He didn't ask for any of that.
@thecote and David Zendzian use that as the way in. If a week of agentic vuln-finding turns up more than a big security firm finds in a year, what does that do to the buy-vs-build math? David reframes it: where do you want to spend your tokens? On your business app, on your own security tooling, or on someone else who's spending their tokens for you? "Why not both?" keeps coming up - and by the end it's a design principle, not a punchline.
Key topics:
- What Claude Code's workflows feature is actually doing when it feels like it read your mind
- "I love AI, I don't trust it" as an engineering posture, and how iterative QA loops operationalize it
- Where "where do you want to spend your tokens" is the more honest version of build-vs-buy
- What AI does to the security partner math when a week of vuln-hunting beats a decade of dedicated research
- Why "Why not both?" becomes a real design principle once UIs are cheap to generate
Interested in a platform that can help you with enterprise-y excellence? Check out: vmware.com/products/app-platform/tanzu
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote and David Zendzian










