The Receipts
The Receipts is a public capability record. Every skill sits on one of four tiers, and every claim carries the artifact behind it. If a claim cannot survive a follow-up question, it is listed as a gap instead of a skill.
I ship production software by directing AI tooling. That makes me an AI-native operator rather than an engineer, and the page says so plainly where it matters.
The tier scale exists because a normal skills list flattens everything into bullets. Having used a tool and having run it with money at stake are different claims. Only one of them belongs on a CV without a qualifier.
Every row below can be opened, watched, or checked.
- PractitionerDone repeatedly in production, with money or reputation at stake. I can own it and lead others through it.
- WorkingDone end to end for real at least once. I can do it again unaided, sometimes with the docs open.
- FamiliarUsed it and understand the model. I would need ramp time before owning it.
- Won't claimNo real evidence behind it. Listed anyway, because the gaps are what make the rest checkable.
Product work with my own money at risk, including the part that did not work.
Full physical product lifecycle, on my own capital
PractitionerResearch, sourcing, design, freight and launch on a private-label product I funded myself. It failed, and the loss was mine rather than an employer's. See it
Market and competitor research
PractitionerCategory demand analysis, margin modelling and product selection against written criteria.
Listing and conversion design
PractitionerTitle and bullet architecture, enhanced content and imagery built to convert rather than decorate.
Launch and demand generation
PractitionerPaid launch, brand registry and account health on a platform where one takedown ends the launch window.
Authoring a validation methodology
PractitionerA content-first testing method with staged capital risk and defined kill criteria. Its unanswered benchmark questions are written into it rather than papered over.
Shipping digital products solo
PractitionerTwelve or more live products where I was the only product, design and build resource. See it
Supplier sourcing and negotiation
WorkingDirect sourcing, supplier identification, terms and sampling on a first production run.
Freight, landed cost and inventory
WorkingFreight planning and landed-cost modelling across a 300-unit order. This part ran smoothly.
Pricing and packaging decisions
WorkingBundled a SaaS free as a retention tool before pricing it standalone. Adoption sequenced ahead of monetisation, deliberately.
Quality control and supplier inspection
WorkingI sampled the product and commissioned third-party inspection, and a 10% electrical failure rate still reached customers across 300 units. Both checks read a subset and pass the rest. On an electrical product the fault shows up in use, which is not what a pre-shipment check looks at.
The part I am actually hired for. All of it runs daily rather than sitting in a demo.
LLM APIs in production
PractitionerContent engine across six brands, plus 30+ daily automations. See it
Prompt engineering and system design
Practitioner300+ custom Claude Code skills, with hook-based self-correction turning failures into standing rules.
Workflow automation (n8n)
PractitionerProduction workflows, webhook routing, and a written record of every gotcha that cost me a day.
AI agent frameworks (LangGraph)
WorkingAgent stack on my own VPS, exposed as run endpoints.
RAG and vector search (Qdrant)
WorkingA live memory collection with semantic recall across the knowledge vault. See it
Voice AI (ElevenLabs)
WorkingEight production voice agents covering scheduling, intake and overflow.
Human-in-the-loop design
WorkingContent pipeline with a deliberate approval gate before anything publishes. Not full auto, on purpose.
Data pipelines from wearables
WorkingA webhook receiver processing 900+ transcript segments a day through AI summarisation.
Observability (Langfuse)
FamiliarDeployed and running. Light use so far.
Model fine-tuning and training
Won't claimNever done it.
What I can build and operate without an engineer, and the exact line where that stops.
AI-assisted delivery as the primary build method
PractitionerEvery product listed on this site was built this way, including the site itself. See it
Docker and self-hosted VPS operations
Practitioner16 containerised services and 22 scheduled jobs on one production box, self-healing and self-managed.
REST APIs, webhooks and third-party integrations
PractitionerLive integrations across CRM, CMS, automation, messaging and Search Console.
Next.js, React and Vercel
WorkingSix production sites, including this one at roughly 150 routes. See it
Supabase and PostgreSQL
WorkingMulti-tenant SaaS with row-level security enabled at table creation.
Infrastructure monitoring and alerting
WorkingUptime and performance monitors feeding an auto-generated dashboard every 30 minutes, failures alerting to Slack.
Git and GitHub, branch to PR to main
WorkingStandard workflow across every repo I own.
DNS, Cloudflare and deployment
WorkingMultiple domains across three hosts, with the failure modes documented.
Browser automation (Playwright)
WorkingSite checks and render pipelines that run unattended.
Python and TypeScript
FamiliarI direct and debug both. I cannot read code unaided, and I will not pretend otherwise.
One full cycle on a client's multi-site estate: assessment, then live incident response on the site that was actually compromised, then cleanup and a hardening plan. Authorised work on their own systems, run the same way everything else here is run.
External attack-surface assessment
WorkingFingerprinted the stack, headers and exposed endpoints across roughly twelve sites without credentials. Nothing was exploited, which is why I do not call it a penetration test.
Vulnerability assessment
WorkingNulled plugins, live XML-RPC, user enumeration and missing security headers, found and ranked by what an attacker reaches first.
Infrastructure mapping
WorkingGrouped the estate by DNS and IP to work out which sites share a hosting account. A blast radius map rather than a list.
Incident response on a live host
WorkingSSH investigation of the compromised site: file modification times, database analysis and log hunting, on production while it was still serving.
Malware analysis, source level
WorkingTook apart a nulled plugin activator that phoned home, hid itself and faked a licence, plus a spam kit. PHP source rather than compiled binaries.
Eradication and verification
WorkingRemoved the activator, purged around 360 injected database rows, then went back and confirmed nothing regenerated. The second half is the part most cleanups skip.
SEO forensics on an injection
WorkingTraced a pharma and escort spam injection back to the shell page mechanism serving it, which is where my SEO work and this overlap.
Application security review
WorkingWrote the review protocol I now use on my own Next.js work: object level access, secrets handling, content security policy, supply chain. See it
Threat modelling a migration
WorkingCompared the risk of staying on WordPress against moving to a headless stack, including the concentrated data problem that consolidation creates.
Email authentication posture
WorkingSPF, DKIM and DMARC audited across the whole estate rather than the one domain that prompted it.
Revocable access handover
WorkingKey based SSH set up so my access can be withdrawn without resetting a password or touching anything else.
Writing the findings up for a non technical owner
WorkingForensics tracker, action plan, remediation runbook and hosting inventory, then the licensing and migration decisions in terms the owner could actually decide on.
Cryptography review
FamiliarReviewed a password vault design: AES-256-GCM, Argon2id, envelope key wrapping, nonce handling. I reviewed it. I did not design it and I have not implemented one.
Security certifications
Won't claimI hold none. No OSCP, no CISSP, no CEH.
Offensive work on systems that are not the client's
Won't claimEverything above was authorised work on a client's own estate. I have never run a scoped engagement against a third party.
Reverse engineering and exploit development
Won't claimNot done. Source level analysis is where I stop.
Security as a role
Won't claimOne engagement is range on a technical operator, not a security career, and I would rather say that than have someone find it out.
Ten years of this would be the normal claim here. What I have instead is a small number of channels run properly, with the failures kept in.
Marketplace advertising and retail media
Practitioner400 to 500 active campaigns, roughly half a million dollars in lifetime managed spend, peak 15× return.
P&L and unit economics ownership
PractitionerOwned the KPI set on a seven-figure brand and doubled its profitability in six months.
SEO, technical SEO and structured data
PractitionerThis site: ~150 routes, page-level structured data on all but four, 3,000 impressions in month one on a new domain. See it
Local SEO and Google Business Profile
PractitionerThe core agency motion. Profile work plus suburb and service page architecture.
CRM and lifecycle automation
PractitionerFull delivery stack: pipelines, email and SMS nurture, lead scoring, missed-call text-back.
Cold calling, setting and closing
Practitioner1,000+ calls placed personally. A conversation every 10 to 15 dials, measured rather than estimated.
Content systems and publishing
Practitioner45+ articles across three owned properties through one AI pipeline. See it
Client delivery management
PractitionerA repeatable five-phase pipeline, tracked in Linear, handed over with an operations handbook.
Conversion optimisation
WorkingFunnel and product-page work, landing builds, A/B tests, session replay. See it
Cold email and SMS systems
WorkingSystems built to roughly 4,000 emails a month. The 5,000-email test returned close to zero replies, and killing it is the credential. See it
Paid search
WorkingClient campaigns, run and reported.
Creative production
WorkingAd copy systems, video editing and graphic design. Enough to ship, not a design hire.
The most under-sold group on my CV. Most marketers stop at the tag manager.
GA4 and Google Tag Manager
PractitionerStandard on every property I run.
Session replay and heatmaps
PractitionerUsed daily rather than installed and forgotten.
Dashboard design and instrumentation
PractitionerOperations, sales and client-facing dashboards, generated live. See it
Server-side tag management
WorkingReal implementation, not a tutorial. Rare in marketing hires.
Conversions API
WorkingServer-side conversion forwarding in production.
Call tracking
WorkingNecessary for local services, where the conversion is a phone call rather than a click.
Offline conversion imports
WorkingClosing the loop from CRM outcome back to the ad platform.
Looker Studio reporting
WorkingClient-facing reporting, refreshed automatically.
Mixpanel and Amplitude
Won't claimNever used either. Same event-model thinking from GA4, but I would be learning the tool in week one.
Product work done as the only product, design and build resource. That is a strength on scope and a gap on team process.
Customer discovery at volume
Practitioner1,000+ direct conversations with the actual buyer, instrumented rather than remembered.
KPI definition and instrumentation
PractitionerEvery launch measured before it ships, not after it disappoints.
Killing your own work on evidence
PractitionerA public kill log with the reasoning, the post-mortem and the rule carried forward. See it
Stakeholder and client communication
PractitionerSales through delivery through retention, as the only point of contact.
Async remote across timezones
PractitionerBased in Thailand, working with Australian, UK and US clients. See it
Requirements, specs and acceptance criteria
WorkingWritten for my own builds. Not yet inside a team PRD process.
Roadmap and backlog prioritisation
WorkingPhased delivery tracked in Linear. See it
Experiment design
WorkingField tests with the numbers published, including the ones that failed. See it
Agile delivery
WorkingPhased and tracked. Not formal Scrum ceremonies, and I would not claim to have run them.
Line-managing engineers
Won't claimI direct AI tooling. I have not managed an engineering team.
Jira and ClickUp
Won't claimNot used. Linear and Notion daily.
Figma
Won't claimI design through built components rather than in a design tool.
Scrum certification
Won't claimNo certification and no ceremony ownership.
The hardest thing to evidence is having shut your own project down.
I have killed a private-label product, a faceless YouTube channel, an agency positioning and a SaaS idea. Each one has a written post-mortem and a rule I carried into the next build. One of them cost about seven thousand dollars of my own money and taught me not to buy inventory before proving demand.
None of that is retold here, because it already has its own page. The reasoning is public, dated, and open to being checked.
Read the kill log →- Founder and growth operatorClearScale01/2025 – present
- E-commerce brand managerAmazon aggregator, multi-brand portfolio11/2023 – 01/2025
- Freelance e-commerce consultantMarketplace brand04/2024 – 06/2024
- FounderOwn private-label brand03/2023 – 04/2024
- Customer service consultantTelstra2020
- EarlierLogistics, hotel guest services, hospitalitypre-2020
Diploma of Business, TAFE Queensland, 2020. Everything technical after that was self-taught and is listed above with its evidence.
Want the long version?
The portfolio walks through the whole stack, including a 13-minute video. The systems themselves are on the apps page, the client work is on services, and the reasoning behind what I stopped doing is in the vault.