Make the workflow strong enough for the work.

A lot of what I actually do happens before anyone opens a timeline: how a project is structured, where the files live, who can reach them, and how the work survives three rounds of notes and a delivery spec that shifted on a Friday afternoon. Those choices are what keep a creative process from quietly coming apart once the schedule tightens.

For studios and production teams hitting the same failures over and over — broken handoffs, version confusion, brittle storage, unclear permissions, weak backups — I audit what is fragile and make it more reliable. And when an existing tool is too heavy, too vague, or too far from the way the work actually happens, I build the missing piece instead of waiting for it.

Hardware & Software

Small tools for real problems.

I design small tools around the workflow first: what the user needs to do, what the interface should make obvious, what needs to stay private, and where the process tends to fail. AI-assisted development helps with the implementation, but the useful part is defining the right problem clearly enough that the tool has a reason to exist.

Secure, Reliable, Redundant

A workflow that isn't secure isn't finished.

Every question a workflow audit asks is already a security question. Who can reach the masters. What happens when someone leaves mid-project. Whether the backup has ever been restored or merely scheduled. Where the client's unreleased footage actually sits tonight, and how many copies of it exist. These get treated as housekeeping until the week they become the entire problem.

I studied cybersecurity formally to put proper language and method behind what twenty-five years of post production had already taught me to notice. Production teaches you to feel where a process is fragile — the handoff nobody documented, the shared login, the drive that only one person knows the state of. The training turned that instinct into something I can audit against, document, and hand over, instead of a hunch I raise in a meeting and hope somebody acts on.

I hold the ISC2 Certified in Cybersecurity credential and the Certificate IV in Cyber Security from RMIT, and I use my own infrastructure as the place where the theory has to survive contact with reality.

There has also never been a moment where this mattered more. Post-production runs on shared cloud drives, remote review links, freelancers on their own machines, AI tools that quietly want your footage, and delivery chains that cross a dozen companies before a master lands. The attack surface of a modern production is enormous, and almost none of it was designed — it accumulated, one convenient shortcut at a time.

So I treat security as part of the workflow rather than a separate service bolted on afterwards: sane permissions, segmented networks, backups that get tested, redundancy where the schedule can't absorb a failure, and documentation that survives the person who wrote it. Not compliance theatre — just the version of the process that still works on the bad day.

My own lab is where I keep that honest: OPNsense with seven VLANs, Mullvad WireGuard with policy-based routing, Suricata IDS, Unbound DNS with DoT, and a Proxmox cluster hosting 13+ VMs monitored via Grafana and Prometheus. I have worked through real failures there, including a full floating rule collapse after a major OPNsense update, and recovered them systematically. The writing here and on Substack goes into more detail.

Something fragile you have not named yet?

Workflow audits, infrastructure reviews, custom tooling, or the security side of any of it. A short description of where the friction is now is enough to start.

Get in touch