A Long Night, an AI Partner, and Ten Seconds to Spare
I had a server build, multiple handoffs, and a final pickup window. AI helped me keep the evidence, decisions, and next steps connected as I worked.
By Kaleb Hill
The final pickup was already pulling away when I arrived. I caught it with roughly ten seconds to spare.
Getting there took a fifteen-hour push that began on Friday afternoon. I had a server build to prepare, a teammate waiting to take the next stage early the next morning, and a delivery deadline after the build returned to me. There was little room in the schedule for a surprise, and the build gave me several.
Familiar steps behaved differently in the environment in front of me. One recovery raised another question. A promising observation still had to be checked. I needed to keep moving, but I also needed to know what the last result actually showed before I built the next decision on it.
That night, AI became part of how I kept the work connected. I was still accountable for access, consequential decisions, and the hands-on work. The AI contexts helped preserve the investigation while the build moved through its deadlines.
Two contexts, two kinds of access
The OTM Cyber staff model gave the work a useful structure. My AI coordinator was the investigation and coordination context. It could work through logs, prior records, support material, and the questions already on the table. The console-side AI agent was the console-facing context. It could report what it saw at the system itself.
Each had only part of what I needed. My AI coordinator could follow the history, but it could not see the console. The console-side AI agent could supply that observation, but it did not carry the full trail of earlier evidence. I directed both, handled the access that required me, and decided which result justified the next action.
At first, I relayed the results myself. A console observation would arrive, I would carry it into the investigation, and then I would take the next question back. That worked for a while, but the hand-carried loop became part of the delay. Every new result had to wait for me to move it before the investigation could continue.
The problem was not simply speed. I had to make sure the context on the other side was current. A partial observation could look more certain than it was after it had been repeated once or twice. Under a deadline, I did not want the next person to inherit a server and a story that no longer lined up.
I stopped carrying every message myself
We set up a shared, time-stamped evidence exchange. The console-facing context posted observations and results. My AI coordinator watched the shared record, added the next bounded question, and kept important replies in the wider project history. I could see the same current record that both AI contexts were using.
The change gave my AI coordinator enough continuity to work without waiting for me to relay every message. It monitored the new evidence, compared it with the state already recorded, and brought forward a focused next check. The shared record did not remove my role. It freed me to work the part that required me while the investigation kept its place.
The proposed checks stayed narrow. My AI coordinator diagnosed the next thing worth testing, directed a limited recovery check through the connected context, and checked the returned evidence. It recorded what the check could show and what it could not settle. That kept a useful result from becoming a larger claim than the evidence could support.
When an observation suggested that a limited recovery step had improved the condition, my AI coordinator treated it as a lead. It preserved the relevant state, left the broader build alone, and asked for a fresh confirmation through another available path. The next evidence showed restored access. My AI coordinator then continued with smaller checks instead of treating that one recovery as the end of the investigation.
I asked my AI coordinator to keep monitoring the shared record without waiting for another manual prompt from me. It watched for the next observation, reasoned from the evidence already available, and selected the next bounded question within the authority I had already given it. That was autonomy with a clear job: maintain the investigation, identify the next useful check, and return the evidence for me to assess.
The work became easier to direct because the record did not reset with every handoff. I could look at what was confirmed, what was still open, and why the next check had been chosen. The AI could do the same. When I needed to intervene, I was joining an investigation that had remained current rather than trying to recreate it from memory.
The record carried the first handoff
As the first deadline approached, the shared record became the handoff. Before my teammate took the next stage, the console observation and a fresh remote verification agreed that access had returned. My AI coordinator followed that recovery with smaller, targeted checks. It did not turn one successful response into proof that every part of the build was complete.
I could prepare the current condition, the open questions, the last verified result, and the reason for the next step. That gave my teammate a build with a usable history. It also gave the next person a clear way to distinguish a known result from a new symptom.
I made that first handoff on time. The work changed hands, but the evidence did not scatter. The shared history kept the observations beside the questions they answered, so the next person did not have to guess which earlier recovery still mattered.
A separate review agent later completed an independent review of the documented host handoff. Another member of our agentic staff checked what we had recorded and whether the reported results held up. I had help carrying the investigation forward and a separate review of the work we handed over.
After five hours of sleep, I returned when the server came back to me for the remaining work. The deadline had shifted, but the investigation had kept its shape. I did not have to start by asking what had happened while I was gone. The shared record showed the last confirmed condition and the questions that were still waiting.
More unexpected behavior appeared in the final stretch. My AI coordinator could separate those new questions from the recovery work already verified. The console-side AI agent remained available when an interactive observation was needed. My AI coordinator handled the already-authorized, read-only verification that did not require the console. I could keep the hands-on work moving while the evidence stayed organized around the decisions it supported.
The record also helped protect the recovered state. It identified the recent condition that had restored access and the wider actions that had not been justified by the evidence. We continued from a known condition instead of reopening a large recovery process on assumptions that no longer fit.
The evidence never established one complete cause for every problem that appeared during the build. It established enough at each point to choose the next careful step. That was the standard I needed as the final deadline got closer.
A team that could keep its place
By the final stretch, I was working with an OTM Cyber team whose AI members had different jobs. My AI coordinator kept the investigation moving. The console-side AI agent brought back observations. A separate review agent reviewed the host handoff. I could concentrate on the work in front of me while those responsibilities stayed connected.
I still had to finish the build and get it out the door. But I no longer had to carry every exchange myself or reconstruct the previous hour before deciding what to do next. The AI could watch for a result, work out which question came next, and keep that work available while I handled the next physical step.
At the end of the push, I completed the remaining checks, packed the server, and headed for the pickup. The clock had never given me more room. Working with a coordinated AI staff had given me a better way to use the time I had. After the long night, the handoff, and the return to finish the work, I reached that departing truck with ten seconds left. They were enough.
Get practical cyber readiness updates
Receive OTM Cyber insights, relevant event invitations, and guidance for leaders who have to keep operations moving.
Continue the conversation.
Explore related services or talk with OTM Cyber about the cybersecurity pressures facing your environment.