HOOL / start here

what this site is, in plain english

John Whitman designs and operates a portfolio of real products where AI agents do the daily work — and every action they take leaves verifiable proof.

This page is the plain-English version of the site. The raw, technical ledger — every dated event, including the failures — is one click away at the receipts.

how it works

01

John writes a brief

He decides what should exist — a product, a fix, an audit — and hands the goal to his AI team (software agents he directs, the way a manager directs staff).

02

The AI team does the work

It writes the code, tests it, deploys it to the live products, and audits the results — work that would normally need several specialists: a developer, a QA engineer, an operations engineer, a copywriter.

03

A receipt is published

Every meaningful action produces a receipt (a dated, public record anyone can check) — including the mistakes. The receipts live on this site, in the open.

the numbers

9live sites, all verified up
16fixes shipped to production in one raid
131automated tests passing on that product
24dated entries in the public ledger
1human involved
$0outside money raised

Each number comes from a published receipt: the 9-of-9 site sweep (2026-07-03) and the ledger entries are on the receipts; the 16 production fixes and the test count (raised from 124 to 131) are from the Raid 01 record of 2026-07-04, excerpted below.

how to read a receipt — one real example, annotated

On 2026-07-04, John pointed five AI agents at one of his live products — Thumbprinted, a business that takes real payments for hand-drawn portraits — with one rule: find problems, don't touch anything yet. What follows are real lines from that receipt, with plain-English notes.

receipt · raid 01 · thumbprinted · 2026-07-04
WRAITH-1 — timing-safe admin login. The admin password was compared
with `===` (leaks byte-by-byte via response timing) while the Stripe path
already used a constant-time compare. Routed both username and password
through `timingSafeEqual`.
An AI found this security bug. The way the admin login checked passwords could, in principle, let an attacker guess them one character at a time. No one asked it to look for this specific problem — it was one of 36 findings from a single sweep.
> Commander's order: "Recommended raid + stretch snakes."
A human approved exactly one decision. John read all 36 findings and gave this single go-ahead — which fixes to make. That was his only intervention. The AI team then fixed, tested, and deployed everything itself, in about 25 minutes.
Live proof (headers on thumbprinted.com):
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: SAMEORIGIN
This is the proof it was fixed. These lines are security settings pulled from the live website after the fix was deployed. Anyone — you included — can check them right now with a free browser tool; no trust in this page required.
Outcome: 16 fixes shipped to production · verified live ·
test floor raised 124 → 131 · all green
The result, on the record. Sixteen real fixes running in production, and more automated tests guarding the product than before. The receipt also lists what was deliberately left unfixed — honesty is the point.

where to go next

recruiter or hiring manager

Day job: Director of Product Management at America's Car-Mart (NASDAQ: CRMT). This site is what he builds outside it: nine live products, operated by AI teams under his direction, with every claim linked to proof. What it demonstrates — product leadership, AI-operations direction, shipping discipline, public accountability.

meet the operator →

potential client

The same approach can build and run real software for you — sites, tools, automations — at the pace of an AI team, with the work checked and documented the same way it is here. Browse what has already shipped, every product verified live and dated.

see the work →

technical peer

Zero-JS static site, dated public ledger with the failures kept in, verification method published. Skip the captions and read the raw record, or go straight to the code.

read the ledger →
github.com/johnmwhitman →

The full story of how one human ended up directing an AI fleet — told as it happened, receipts and all — is the book: Human Out of the Loop.