Zero Signal

Conor Sherman

Zero Signal is a podcast for CISOs and senior security leaders who are expected to have answers about AI risk before the industry has standards. We go after the strategic questions that don't yet have clean answers — the ones your board is asking and the industry is still debating. Each episode is an honest conversation with someone navigating that pressure — not with perfect answers but with principles, frameworks, and lived experience. We host guests who've had to make real calls under uncertainty and are willing to talk about what worked, what didn't, and what they're still figuring out

  1. 1d ago

    Jacob DePriest: Why AI Patching Fails

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Jacob DePriest, CISO and CIO at 1Password and former Deputy CSO at GitHub. Jacob shares his unique perspective on bridging the gap between security and IT enablement, breaking down how 1Password balances velocity and protection through a velocity-weighted risk framework. The discussion dives deep into the rapidly changing identity landscape, challenging traditional non-human identity paradigms. Jacob explains why today's AI agent activity is actually rooted in human-delegated identity—where finance, HR, and casual builders are using local AI agents to get their daily work done. Conor, Stu, and Jacob explore the rise of agentic privileged access, the critical need to keep credentials out of LLM context windows, and why storing secrets on disk is an enterprise habit that must die. Finally, Jacob unpacks groundbreaking research from 1Password's Off-By-1 Labs. The team evaluated whether top frontier models can reliably generate code patches for vulnerabilities, uncovering surprising results that every security leader relying on automated AI remediation needs to hear. About the Guest: Jacob DePriest is the CISO and CIO at 1Password. Prior to joining 1Password, he served as the Deputy Chief Security Officer at GitHub and led various engineering and technology initiatives across multiple high-scale organizations. Continued Reading & Resources: Off-By-1 Labs AI-Generated Vulnerability Research: https://1password.com/blog/why-ai-generated-patches-still-require-human-review 1Password Research Hub: https://1password.com/research#article 1Password SAGE Blog (Part 1 - Scaling Security Reviews): https://1password.com/blog/scaling-security-reviews-ai-powered-pipeline 1Password SAGE Blog (Part 2 - Context & Nondeterminism): https://1password.com/blog/scaling-security-reviews-solving-context-and-nondeterminism Key Moments: Human-Delegated Identity vs. Non-Human Identities in AI Workflows The Dual Role of CISO & CIO: Implementing Velocity-Weighted Risk Agentic Privileged Access & Keeping Credentials Out of LLM Context Off-By-1 Labs Research: Can AI Frontier Models Reliably Patch Vulnerabilities? Meet our Sponsors: RISCPoint Security & compliance consulting tailored to your business:  https://www.riscpoint.com/  Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  2. 3d ago

    LIVE: "Vibe Hunting" with Damien Lewke at Black Hat 2026

    Welcome to a special live episode of Zero Signal, recorded on the ground at Black Hat 2026 in Las Vegas! Hosts Conor Sherman and Stuart Mitchell are joined by Damien Lewke, CEO and founder of Nebulock, to break down the rapid evolution of agentic threat actors and what it means for enterprise defense. Damien shares his perspective as a veteran detection researcher, exploring how autonomous attacker pipelines are fundamentally shifting the economics of cybersecurity by compressing time-to-exploit from months down to minutes. The discussion explores the rise of "vibe hunting"—a proactive threat hunting framework designed to match the speed and veracity of modern AI-driven attacks. Damien and the hosts analyze the strategic role of open-weight models in incident response, the breakdown of traditional attribution models, and why context engines are essential for defenders to gain the upper hand. Packed with insights on democratizing elite security skills and managing automated lateral movement, this live session offers a practical roadmap for building resilient, AI-native security operations. About the Guest: Damien Lewke is the founder and CEO of Nebulock. A veteran detection and response strategist, Damien specialized in adversarial game theory at UCLA, built integrations engineering at CrowdStrike through its IPO, researched NLP algorithms at MIT's CSAIL, and led AI detection and security research at Arctic Wolf.

  3. Jul 31

    Herman Errico: Inside the AARM Standard

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell speak with Herman Errico, Product Manager for Technical Research at Vanta. Driven by the shift of AI agents moving from text generation to autonomous execution, Herman authored the paper that established the Autonomous Action Runtime Management (AARM) specification. Now a system category specification housed under the Cloud Security Alliance (CSA), the initiative has quickly united over 90 supporting organizations. Herman breaks down why traditional applications, firewalls, and endpoint defenses fail at the "action boundary"—which he defines as the true new security boundary—and how pre-execution interception and accumulated session context are essential for governing non-deterministic AI behavior. The conversation dives deep into the mechanics of AARM, exploring how it expands beyond binary allow/block controls to introduce five distinct authorization decisions, including action modification, step-up verification, and deferral to human-in-the-loop oversight. Herman addresses why static Markdown files and instruction skills cannot reliably govern AI fleets due to context window limits, confused deputy risks, and competition for LLM attention. From vendor-neutral collaboration within the CSA working group to the future of securing autonomous hardware and robotics, this episode provides security leaders with a definitive framework to benchmark agentic security solutions and govern non-human execution safely. Herman Errico is the Product Manager for Technical Research at Vanta with a decade of experience in security operations and incident response. He is the author and creator of the Autonomous Action Runtime Management (AARM) specification, which he contributed to the Cloud Security Alliance (CSA) to establish an open, vendor-neutral standard for agent runtime security. Black Hat USA 2026 The Zero Signal team recorded this episode live on the ground as we gear up to attend Black Hat USA 2026! Catch up on our interviews and deep dives from last year by checking out our Black Hat YouTube Playlist: https://www.youtube.com/watch?v=sb-C-XPJQ_Q&list=PLvtGUUDFmi-b-fELkdzirA9yYEcNVfVVJ Autonomous Action Runtime Management (AARM) Specification: https://aarm.dev AARM Working Group & Conformance Standard: https://aarm.dev/working-group Cloud Security Alliance (CSA) Official Site: https://cloudsecurityalliance.org CSA Agentic AI Security Initiative: https://cloudsecurityalliance.org/artifacts/agentic-trust-framework Vanta Official Site: https://vanta.com Model Context Protocol (MCP) Specification: https://modelcontextprotocol.io 00:00 Defining the Action Boundary & The Origin of AARM 04:15 Layer 8 Execution & Pre-Execution Interception 09:30 Community-Led Specifications vs. Traditional Standards 15:30 Pre-Execution Interception & Five Authorization Decisions 19:40 Session Context Accumulation & Computing Agent Intent 34:30 Why Markdown Files Fail to Govern AI Fleets 38:30 Cross-Vendor Collaboration in the CSA Working Group 42:30 The 12-Month Outlook: Extending AARM to Hardware & Robotics Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the GuestContinued Reading & ResourcesKey Topics & TimestampsMeet our Sponsors

  4. Jul 24

    Daniel Bardenstein: Why Third-Party Risk Is Broken

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Daniel Bardenstein, founder and CEO of Manifest Cyber, former Chief of Technology Strategy at CISA, and former cybersecurity lead for Operation Warp Speed. With open-weight models like GLM 5.2 rapidly challenging proprietary AI providers like ChatGPT and Claude on performance while offering up to 5x to 6x cost savings, Daniel unpacks why basic arithmetic is driving an enterprise shift back toward open-weight models. He breaks down the complex supply chain dynamics behind AI datasets, fine-tuning, and model dependencies, highlighting how untracked data inputs can quietly introduce massive legal, compliance, and security liabilities. The conversation addresses the ongoing breakdown of traditional Third-Party Risk Management (TPRM). Daniel explains why relying on static paper questionnaires, SOC 2 reports, and superficial web scans fails to capture non-deterministic AI risks or the hidden fourth- and fifth-party software dependencies lurking inside modern vendor products. To solve this, he advocates for treating AI as a subset of software and leveraging machine-readable AI Bills of Materials (AI BOMs) to automate inventory management, streamline license compliance, and protect pipelines against shadow AI created by developers using tools like Claude Code. Daniel Bardenstein is the founder and CEO of Manifest Cyber. He previously served as the Chief of Technology Strategy at the Cybersecurity and Infrastructure Security Agency (CISA), led cybersecurity for Operation Warp Speed, and helped architect national-level cross-sector Security Performance Goals. CISA Cross-Sector Cybersecurity Performance Goals: https://cisa.gov/cpgs CycloneDX SBOM/AIBOM Standard Specification: https://cyclonedx.org SPDX Software & AI Bill of Materials Standard: https://spdx.dev NIST Software Supply Chain Security Guidance: https://nist.gov/software-supply-chain OWASP Top 10 for Large Language Model Applications: https://owasp.org/www-project-top-10-for-large-language-model-applications LAION-5B Dataset Research Analysis (Stanford University): https://cyber.fsi.stanford.edu 00:00 Open-Weight Models & The Economics of GLM 5.2 04:15 The Shift from Proprietary APIs to Open-Weight Models 08:50 Mapping Supply Chain Risks in Datasets and Fine-Tuning 12:20 Software Supply Chain Models Applied to AI Inventory 18:10 Navigating Complex AI Model Licensing & Compliance 24:00 Shadow AI, Local Models, and "Vibe Coding" Developer Risks 33:00 The Failure of Traditional Third-Party Risk Management (TPRM) 40:30 Operationalizing AI Bills of Materials (AI BOMs) for Automation Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the GuestContinued Reading & ResourcesKey Topics & TimestampsMeet our Sponsors

  5. Jul 17

    Josh Woodruff: The Agentic Trust Framework

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Josh Woodruff, creator of the Agentic Trust Framework, co-chair of the CSA Zero Trust Working Group, and co-author of Agentic AI + Zero Trust. Josh wrote this definitive guide alongside John Kindervag, the industry pioneer who originally coined the term Zero Trust itself. Together, they bridge original Zero Trust fundamentals with the unpredictable nature of today's stochastic, probabilistic AI agents. Josh outlines an actionable operating model that treats AI agents as "digital colleagues," graduating their access through strict autonomy progression levels from Intern to Principal. Instead of getting stuck in pilot purgatory, Josh introduces five core questions—identity, behavior, segmentation, data governance, and rapid kill switches—to help security leaders build protective "roll cages" around their agentic systems, safely accelerating business transformation without sacrificing defense. Josh Woodruff is the creator of the Agentic Trust Framework, co-chair of the Cloud Security Alliance Zero Trust Working Group, and the founding chair of the CSAI Foundation. He is a prominent security strategist and co-author of Agentic AI + Zero Trust alongside John Kindervag. Agentic Trust Framework Official Site: https://agentictrustframework.ai Agentic Trust Framework (Open Spec, GitHub): https://github.com/massivescale-ai/agentic-trust-framework Agentic Trust Framework: Zero Trust for AI Agents (CSA Blog): https://cloudsecurityalliance.org/blog/agentic-trust-framework Agentic AI + Zero Trust: A Guide for Business Leaders: https://aws.amazon.com/blogs/enterprise-strategy/agentic-ai-zero-trust Zero Trust for AI Agents (Anthropic): https://anthropic.com/news/zero-trust-for-ai-agents A Look Back at Zero Trust (John Kindervag): https://forrester.com/blogs/zero-trust-never-trust-always-verify Securing the Agentic Control Plane (CSAI Foundation): https://csai.foundation/securing-the-agentic-control-plane 00:00 Grounding Zero Trust for Probabilistic AI Agents 04:15 The Stochastic Threat: Intent, Logic Loops, and Prompt Injection 07:55 The Framework Shift: Operational Models vs. Gated Threat Lists 10:15 Anchor Questions: Identity, Segmentation, Data, and Kill Switches 12:00 Autonomy Progressions: From Intern Status to Principal Control 14:30 Earning Privileges: The Five Dimensions of Agent Promotion 17:50 Intent-Based Leadership: Balancing Technical Competence with Autonomy 24:00 Constraints as Rocket Fuel: Tight Governance for Performing Agents 34:30 Pilot Purgatory & Lessons from a $300 Replicating Orchestrator Error Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the Guest:Continued Reading & Resources:Key Topics & Timestamps:Meet our Sponsors:

  6. Jul 10

    Andy Ellis: Why Cyber Vendors Pitch to the Wrong Person

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Andy Ellis, Akamai's first CISO, who led security operations there for more than 20 years while the platform grew to carry over 30% of global web traffic. A 2021 CISO Hall of Fame inductee and author of 1% Leadership, Andy draws from his decades of scale experience to explain how cybersecurity vendors can stop burning bridges with buyers and how security executives can thrive in a changing corporate landscape. In this conversation, Andy breaks down the core flaws of enterprise sales, revealing why most security vendors fail by treating every interaction as a transaction rather than practicing cultivation. He provides a tactical roadmap for how modern CISOs can become smarter buyers, protect their finite political capital, and transition from traditional control mentalities into strategic business drivers who privately collaborate with peers like the CMO and CRO to enable growth. Conor, Stu, and Andy also tackle the evolution of the executive role, detailing why the CISO function is splitting into two distinct paths: a sub-executive infrastructure position and a true chief technologist role. Andy shares his hard-earned wisdom on becoming a credible witness to corporate risk, managing the first 91 days in a new seat with intent, and building a professional environment modeled after a therapist's office to put stakeholders completely at ease. Continued Reading & Resources: How to CISO Framework & Content: https://howtociso.com Andy's First 91 Day Guide for CISOs: https://howtociso.com/91days 1% Leadership Official Page: https://1percentleadership.com Akamai Technical Scale Archives: https://akamai.com/blog/security/heartbleed-and-distributed-scale-defense DerbyCon Speaker Retrospectives: https://derbycon.com/talks/louisville-slugger-security-paradigms Gary Hayslip's Field CISO Guide: https://linkedin.com/in/garyhayslip/insights-on-the-field-ciso-shift About the Guest: Andy Ellis is an investor, advisor, 2021 CISO Hall of Fame inductee, and the former pioneering Chief Information Security Officer at Akamai Technologies, where he spent over two decades securing 30% of global web traffic. He is the author of 1% Leadership and the creator of the free industry resource How to CISO, which focuses on training the next generation of technological and operational business executives. Key Topics: 01:00 Cultivating Ripe Strawberries: Moving from Coercive Sales to Market Cultivation 05:30 The Vendor Rebuff Template: Protecting Entry-Level SDRs from Industry Abuse 09:55 The Field CISO Trap: Lending Your Gravitas to the Problem, Not a Sales Quota 14:45 The Pre-Pitch Mindset: Using Thought Leadership to Prime the Buyer's Mental Space 16:26 The Nine Buyer Beliefs: Market Urgency, Corporate Politics, and Platform Fit 19:25 Evolution of Seed to Series C Capital: Bespoke Sales vs. Scalable Rep Engines 22:15 The Duo Precedent: Using Cross-Vendor Endorsements to Gain True RSA Credibility 25:35 Stealing the Swag: Optimizing Steak Dinners for Existing Customer Retention 33:20 The CISO Therapist: Designing Your Physical and Remote Office Background to Lower Defenses 36:00 The Splitting Role: Differentiating Junior IT Directors from Strategic Chief Technologists 39:15 Private Boardroom Alignments: Educating the CMO and CRO Before Executive Staff Meetings 41:00 Vetoing a Billion-Dollar Launch: Transitioning from the Judge to a Faithful Witness of Risk Meet our Sponsors: Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  7. Jul 3

    [RE-RELEASE] Clint Gibler on AI Revolutionizing Cybersecurity

    Welcome back to Zero Signal! In this special re-release, Conor Sherman and Stuart Mitchell sit down with Clint Gibler—Head of Security Research at Semgrep, creator of the TLDRsec newsletter, and host of the Modern Security Podcast. Recorded live at Black Hat, Clint breaks down how artificial intelligence is rewriting the playbook for application security, vulnerability discovery, and developer workflows.AI is rapidly transforming cybersecurity, moving from a speculative future tech to an active force automating penetration testing and reshaping how security teams interact with codebases. In this conversation, Clint examines the practical implications, cost structures, and future prospects of deploying AI in security pipelines.More Conversations from Black Hat:The Zero Signal team will be in attendance on the ground again at Black Hat USA 2026, catching up with industry pioneers and capturing more amazing conversations on the cutting edge of cyber defense. Stay tuned for our upcoming on-site coverage!In the meantime, you can dive back into our full library of live event interviews by checking out the Full Black Hat 2025 Episode Playlist on YouTube: https://youtube.com/playlist?list=PLvtGUUDFmi-b-fELkdzirA9yYEcNVfVVJ&si=-6dc4A24dfJWyENpContinued Reading & Resources: TLDRsec Newsletter: https://tldrsec.comThe Modern Security Podcast: https://modernsecurity.ioSemgrep Code Analysis Platform: https://semgrep.devOWASP Top 10 for LLMs & Applications: https://owasp.orgGoogle Project Zero Vulnerability Research: https://googleprojectzero.blogspot.comDeepMind Camel Framework (Agent Separation): https://github.com/camel-ai/camelSocket Supply Chain Security Platform: https://socket.devHugging Face Model Repository: https://huggingface.coTrail of Bits Security Tools & Research: https://trailofbits.comBuilding Secure and Reliable Systems (Google Books): https://sre.google/books/building-secure-and-reliable-systemsComplianceAsCode GitHub Repository: https://github.com/ComplianceAsCode/content00:00 AI's Impact on Penetration Testing03:19 The Future of Junior Pen Testers05:42 Working with AI: A New Paradigm10:31 Trusting AI Outputs12:31 Shifting Down: A New Security Approach15:20 Making Security Invisible for Developers16:44 The Role of AI in Security and Development19:04 Integrating Security into Vibe Coding21:21 Human in the Loop: Balancing Automation and Oversight25:27 Emerging Security Risks in AI Infrastructure29:41 Understanding Prompt Injection Challenges31:05 Innovative Solutions in AI Security32:28 Risks of Model Integration and Code Execution34:14 Navigating AI Model Adoption in Organizations38:52 Career Pathways in CybersecurityAbout the Guest:Clint Gibler is the Head of Security Research at Semgrep, where he focuses on static analysis, developer enablement, and scaling AppSec programs. He is the creator of TLDRsec, a premier weekly newsletter providing deeply technical, actionable security summaries to thousands of industry professionals. Key Topics:Meet our Sponsors:Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signalSysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  8. Jun 26

    Sean Catlett: Why Agent Trust Must Be Computed, Not Granted

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Sean Catlett, co-founder of Polymodal, founding CISO of Reddit, former Chief Security Officer at Slack, and the executive who pioneered combining security with trust and safety at Bumble. Sean leverages his history across massive technological waves—from the dot-com era to cloud and mobile transitions—to deliver a masterclass on how modern security leaders must adapt to drive enterprise AI adoption or face getting layered out of the room completely. In this deep dive into agentic autonomy, Sean details why the traditional CISO operating model of building walls and forcing technology choices is entirely broken. He introduces the critical concept of "computed trust"—the philosophy that autonomous systems must continuously earn their privileges through verifiable runtime evidence and contextual sensing rather than holding permanently granted access. The conversation unpacks the vital distinction between automating narrow workflows and managing a non-deterministic, long-running agent workforce. Conor, Stu, and Sean confront the upcoming realities of "computer use" execution contexts, the illusion that pure observability equals true legibility, and why co-locating risk directly with product owners is the only sustainable way to survive the logarithmic expansion of insider threats driven by rogue digital twins. Continued Reading & Resources: Polymodal Independent Research: https://polymodal.ai/executive-insights London Tech Week AI Enablement Panels: https://londontechweek.com/cyber-security-agentic-transformation Google NotebookLM Optimization Best Practices: https://notebooklm.google.com/enterprise-strategy ISO 27001 AI Risk Management Implementations: https://www.iso.org/standard/information-security-governance-frameworks Black Hat Europe GRC and EDR Projections: https://www.blackhat.com/eu/briefings/ciso-ai-enablement-trajectories About the Guest: Sean Catlett is the co-founder of Polymodal, an early-stage startup focused on AI embodiment, boundaries, and novel interaction environments. A veteran security executive, Sean served as the founding CISO of Reddit, the Chief Security Officer at Slack, and the head of security, trust, and safety at Bumble. Throughout his career, he has specialized in architecting engineering-led and threat-led security programs built to scale alongside massive business transformation. Key Topics: 01:11 The CISO Transformation: Turning Control Positions into AI Enablement Functions 04:14 Tech Wave Echoes: Applying Dot-Com, Cloud, and Mobile Paradigms to AI Transitions 06:43 Batting Averages in Risk: Why the Office of "No" Gets Layered Out by Boards 09:20 Engineering-Led vs. Threat-Led Security Models: Redefining Teams for the AI Era 12:54 The Errors and Omissions Insurance Trap: Why Delegating Judgment Is Uncovered 17:10 Defining the Agent Primitive: Workflow Automation vs. Bounded Digital Twins 20:20 The Logarithmic Insider Threat: Differentiating Human Actions From Agent Malfunction 26:15 Observability Is Not Legibility: The Failure of Legacy EDR Knowledge in AI Sessions 28:31 Higher Execution Contexts: How Agents Navigate Guardrails via Windows Subsystems 31:00 Computing Trust: Educating Agents at Runtime on Second and Third-Order Effects 38:15 The GRC Shift: Why Future Security Operations Teams Will Deploy Code Directly 45:13 The Bumble Paradigm: Unifying Classical Cyber Defenses with Trust and Safety Meet our Sponsors: Hampton North is the premier US based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal  Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

5
out of 5
4 Ratings

About

Zero Signal is a podcast for CISOs and senior security leaders who are expected to have answers about AI risk before the industry has standards. We go after the strategic questions that don't yet have clean answers — the ones your board is asking and the industry is still debating. Each episode is an honest conversation with someone navigating that pressure — not with perfect answers but with principles, frameworks, and lived experience. We host guests who've had to make real calls under uncertainty and are willing to talk about what worked, what didn't, and what they're still figuring out

You Might Also Like