Mon–Fri · 6 AM ET
← All Episodes
EP  • 00:11:46

Deno Desktop | Build or Be Replaced

Today: Deno Desktop | Did my old job only exist because of fraud? | Apertus – Open Foundation Model for Sovereign AI Episode date: 2026-06-22.

Download MP3 →

Transcript

JOSH: It's Monday, June 22. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson.
ERIK: Desktop apps are coming back, open models are getting good enough, and identity checks are about to become part of the AI stack.
JOSH: Stick around — Erik's got an AI pro tip at the end about using model routing without turning your app into a science project.
[pause]
JOSH: First headline. Deno Desktop showed up in Deno 2.9 canary. Is this actually interesting, or just another Electron alternative?
[beat]
ERIK: Interesting. One binary, Deno runtime, web rendering, fewer moving parts. If it lands clean, it gives builders a way to ship desktop tools without dragging half a browser-shaped apartment building with them.
JOSH: Second. Apertus Mini dropped a set of open foundation models for sovereign AI.
ERIK: That's the direction. Smaller models, distillation, quantization, local deployment. Not every task needs a frontier model with a credit card attached.
JOSH: Third. Identity verification on Claude is getting attention.
ERIK: Makes sense. Once agents can take real actions, accounts need stronger gates. It's boring until your agent emails a client, opens a ticket, or merges code. Then boring is beautiful.
[pause]
JOSH: ScanBrief scored 54 items across 54 sources today. Deno Desktop came in at the top. Why did that one jump out?
[beat]
ERIK: Because desktop software never died. It just got annoying to ship.
ERIK: Web apps won because deployment was easy. Open a browser, done. But builders still need local tools. Network engineers need packet viewers, config editors, lab dashboards, serial console helpers, local AI tools. Stuff that talks to files, sockets, USB, CLIs, and weird vendor nonsense.
ERIK: Electron solved that by saying, cool, we'll ship a browser with every app. It works. I'm not going to pretend it doesn't. VS Code exists. Slack exists. Tons of tools use it.
ERIK: But the cost is real. Big binaries. Heavy memory use. Slow startup. And then every small utility feels like it needs a loading dock.
JOSH: Deno Desktop changes that how?
ERIK: The pitch is simple. Take a Deno project, bundle it into a self-contained desktop app, include the runtime and rendering engine, and ship one redistributable binary.
ERIK: That matters because Deno already has a strong permissions model, TypeScript first, web APIs, good tooling, and a sane runtime story. If desktop packaging becomes boring, that's a win.
JOSH: Why do you care as an automation guy?
ERIK: Internal tools. That's where this gets useful fast.
ERIK: In my lab, PrimeDash watches what's alive across the LAN. Right now I've got 128 services running on the production server. I don't need a giant product ceremony to view that. I need a fast local app that shows status, logs, events, maybe a button to restart a dev service.
ERIK: Same with PrimeBus. It processed 865 automation events across 18 projects today. A desktop view into that event stream would be useful. Not a SaaS dashboard. A local operator console.
ERIK: Deno Desktop could be a nice fit for that kind of thing. Small app. Local permissions. Talks to NATS. Reads logs. Opens a browser only when it has to.
JOSH: Is this a threat to Electron?
[beat]
ERIK: Not immediately. Electron has years of scars and fixes. That's valuable. Packaging is ugly. Auto-update is ugly. Native menus are ugly. Code signing is ugly. Every OS has its own little personality disorder.
ERIK: But builders don't always need the mature truck. Sometimes they need a motorcycle that starts.
ERIK: If Deno Desktop makes the first 80 percent easy, people will use it for internal tools, prototypes, agent consoles, local dashboards, and weird little utilities. That's where adoption starts.
JOSH: What would you build first with it?
ERIK: PrimeBus event inspector. Live tail of events, filters by project, click into the payload, show which agent touched it, show whether Gandalf blocked or approved it.
ERIK: The auto-merger has run 1276 attempts since 2026-06-05: 846 merged, 430 blocked by Gandalf, 0 escalated to Erik. That's not a web page problem. That's an operator console problem.
ERIK: I want to see the guardrails working in real time. I want to see why something got blocked. I want a button that says rerun with more context, not a Jira ticket that says someone is sad.
JOSH: That's very specific.
ERIK: Specific is where software gets good.
[pause]
JOSH: The second big theme today is open models. Apertus Mini, GLM 5.2 versus Opus, and even a post saying there's minimal downside to switching to open models.
JOSH: Are we at that point?
[beat]
ERIK: For a lot of work, yes.
ERIK: Not all work. Don't be silly. Frontier models still matter. Claude is still my daily driver for serious coding and reasoning. I use it because it solves real problems in my systems.
ERIK: But if your task is classification, routing, extraction, summarization, formatting, log labeling, dedupe, or first-pass review, open models are good enough more often than people admit.
ERIK: That's the shift. You don't need one giant brain for every task. You need a bench.
JOSH: What's the practical difference for builders?
ERIK: Cost, latency, privacy, and control.
ERIK: If ScanBrief is scoring stories, summarizing feeds, deduping titles, and ranking relevance, I don't need Opus for every step. Some steps can run on a smaller model. Some can run local. Some can run cheap. Save the heavy model for the judgment calls.
ERIK: That's how I think about agents too. Put the expensive model where mistakes are expensive. Put smaller models where mistakes are cheap and easy to catch.
JOSH: Is sovereign AI mostly government language, or does it matter for normal teams?
ERIK: It matters if you care where your data goes.
ERIK: A bank cares. A hospital cares. A defense contractor cares. A small business with client emails should care too, even if they don't say sovereign AI at lunch.
ERIK: Open models give you options. Run local. Run in your VPC. Fine-tune for a narrow task. Quantize it. Put it behind your own auth. Log the outputs. Control the retention.
ERIK: That's not ideology. That's engineering.
JOSH: But people hear open model and think worse model.
ERIK: Sometimes it is worse. Sometimes it doesn't matter.
ERIK: If a model extracts the requested website change from an email and produces a JSON object, I don't need it to write a novel. My email-reactor needs sender, site, requested change, confidence, and whether a human should review. That's it.
ERIK: If confidence is low, route it to a human or a stronger model. If confidence is high, make a branch, change the file, run tests, open the review path.
ERIK: That's a great open-model job.
JOSH: So it's not open versus closed. It's routing.
ERIK: Exactly. Model routing is the real skill.
ERIK: Claude for hard reasoning. Smaller open model for cheap repetitive work. Maybe GPT for another kind of writing or comparison. Maybe a local model for private logs.
ERIK: Builders who wire that correctly will spend less and move faster. Builders who send everything to the biggest model are basically using a forklift to move a coffee cup.
JOSH: Wait, really? You'd trust a smaller model inside an automation pipeline?
[beat]
ERIK: With guardrails, yes.
ERIK: Never trust any model naked in prod. I don't care whose logo is on it.
ERIK: Put schemas around it. Put tests around it. Put policy checks around it. Put a second reviewer on risky changes. That's what Gandalf does in my pipeline.
ERIK: Ten code changes were automatically reviewed by Gandalf and merged to production overnight. That's not because I told an AI, good luck buddy. It's because the system has stages. Generate. Test. Review. Block if weird. Merge only if it passes.
ERIK: Models are workers. The system is the boss.
[pause]
JOSH: That connects to the Claude identity verification story.
JOSH: Why is identity suddenly part of the AI conversation?
[beat]
ERIK: Because agents crossed the line from chatting to acting.
ERIK: The moment an AI can send email, call an API, buy ads, merge code, touch infrastructure, or access customer data, identity matters. Who is running it? What account owns it? What permissions does it have? What did it do? Can you prove it?
ERIK: Old chatbots didn't need much identity because they were mostly producing text. Agent systems need identity because they create consequences.
JOSH: Some people are going to hate that.
ERIK: Of course. Nobody loves verification until fraud shows up.
ERIK: There was also a story today from someone asking whether their old startup job only existed because of fraud. That's the uncomfortable side of tech. Sometimes the demo is real, the payroll is real, the career step is real, and the money behind it is rotten.
ERIK: AI agents make that risk worse if you don't know who is operating what.
JOSH: How does that show up technically?
ERIK: Service accounts everywhere. API keys copied into random places. Personal tokens doing company work. Agents with broad permissions. No audit trail. No approval boundary.
ERIK: That's how you get trouble.
ERIK: In network automation, this is old news. With Cisco NSO or Terraform, you don't give every script full access to the kingdom. You use roles. You separate plan from apply. You log changes. You require review for dangerous moves.
ERIK: AI doesn't get a pass because it sounds confident.
JOSH: What's the right pattern?
ERIK: Start with least privilege. Give the agent only the tool access it needs. Use short-lived credentials where you can. Tie every action to an actor, even if the actor is an agent. Store the prompt, the model, the tool call, the diff, and the result.
ERIK: Then separate authority. The model can propose. The system decides. For low-risk work, let it run. For high-risk work, require a reviewer or a policy gate.
ERIK: PrimeBus does this naturally because everything is an event. The agent doesn't secretly do magic in a corner. It emits an event. Another service picks it up. Gandalf reviews it. The merge path records what happened.
JOSH: That's the opposite of just giving an agent your laptop.
[beat]
ERIK: Yeah, please don't give an agent your laptop and a root shell because a demo looked cool.
ERIK: Start small. Lab first. One repo. One task. One permission. Then expand.
ERIK: I built this stuff because I want systems that run while I'm asleep. But asleep doesn't mean careless. It means the guardrails are awake.
JOSH: There's also a headline about preferring duplication over the wrong abstraction.
JOSH: Does that apply here?
ERIK: Completely.
ERIK: People love building one grand agent framework that does everything. That's usually how you make a haunted spreadsheet with API keys.
ERIK: Duplicate a little. Have one small workflow for email changes. One for code review. One for ScanBrief scoring. One for infrastructure checks. Let them prove themselves. Then pull out the common pieces when the pattern is obvious.
ERIK: Wrong abstractions are expensive because they hide risk. In automation, hidden risk becomes a 2 AM phone call.
JOSH: Dry but accurate.
ERIK: That's my brand.
[pause]
ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com
[pause]
JOSH: Alright, what's the AI pro tip today?
[beat]
ERIK: Build a model router before you build another prompt.
ERIK: Pick three lanes. Cheap, normal, and serious.
ERIK: Cheap is for extraction, classification, tagging, cleanup, and simple summaries. Use a small model. Open model if it fits. Local if the data is sensitive.
ERIK: Normal is for everyday writing, code edits, and analysis where you want quality but the blast radius is low.
ERIK: Serious is for architecture, production changes, security-sensitive work, and anything that can cost money or trust.
ERIK: Then add rules. If confidence is below a threshold, move up a lane. If the action touches prod, require review. If the output doesn't match a schema, fail closed. If the model asks for a permission it doesn't have, deny it and log the event.
ERIK: Don't make the model decide how important the task is. Your system decides that.
ERIK: That's your tip. Use it.
[pause]
ERIK: That tip is straight out of The Autonomous Engineer — my book on building systems that run themselves. Grab it on Amazon.
[pause]
JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev.
ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff.
[pause]
ERIK: Build or be replaced.
JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.