AI AgentsNew·Falk Gottlob··10 min read

Malleable Software Was Never the Point. The Loop Is.

Dave Killeen's Dex now files its own bug reports: your agent tells his agent what broke, the fix ships, your agent says thanks. My take on why malleable loops matter more than malleable software, and what to steal.

malleable softwaremalleable loopsDave KilleenDexagent-to-agentfeedback loopscontinuous discoverylandingopen sourceopinion
Helpful?

AI Agents green editorial cover: Falk in three-quarter view watching two small robots hand a folded paper note across a gap between two desks, a large circular loop shape drawn behind them.

Dave Killeen, Field CPO at Pendo and the writer behind The Vibe PM, shipped something over a weekend that I have been circling in my own work for a year, and he gave it a better name than I had: malleable loops. His open-source AI Chief of Staff, Dex, now checks its own health when you open a session, fixes what it can, and, when it finds something actually broken, offers to tell his Dex. The user's agent writes a privacy-scrubbed defect report, sends it to the maintainer's agent, the fix ships, and the user's agent circles back to say thank you.

Your agent talks to his agent, and the product gets better for everyone. Dave calls it hair-on-the-arms territory. He is right, and I want to argue about why, because I think the loop is a much bigger deal than the malleability, and the distinction changes what you should build.

The short version

Dave Killeen's Dex shipped two features that he frames as malleable loops: Proactive Health, where the agent audits its own automations and connections at session start and repairs what it can, and Dex-to-Dex reporting, where a user's agent files a privacy-scrubbed defect report with the maintainer's agent and the fix ships with almost zero homework on either side. My opinion: the malleable software framing undersells it. Malleable software has a forty-year graveyard, and even the AI-fixed version, where the agent does the reshaping, ends at a thousand private forks. The loop is the actual invention. Dex-to-Dex is a discovery pipeline that converts user friction into routed, structured, actionable signal, and Proactive Health is a landing instrument that catches month-two silence before the habit dies. Both are stealable today without an open-source chief of staff: give your product a self-check where the user already is, let it file consent-gated failure reports instead of waiting for tickets, and end your docs with prompts an agent can run against the user's own setup. The caveat is that the loop works at n=1 maintainer with total context. At scale it needs triage and trust, or it is a firehose of well-formatted noise.

Malleable software has a graveyard, and this time might be different

I want to be fair to the malleable software idea before I demote it. The dream that people shape their own tools instead of settling for what they are given is old and honorable: Smalltalk, HyperCard, spreadsheets as the one survivor, then two decades of low-code platforms promising citizen developers. Nearly all of it died the same death. End users do not want to program. They want their problem gone. Every malleability platform eventually rediscovers that the population willing to build their own tools rounds to the population that was already technical, plus a few heroic operations people carrying Airtable bases on their backs.

Dave's version has a real answer to that history, and it is worth naming precisely: the malleability is mediated by an agent. Nobody reshapes Dex by editing it. You tell it the friction in plain language and the agent touches the substrate. His one-line install, unpacked by your own AI in, as he puts it, less time than it takes to eat a cheese sandwich, is the same move: the technical surface never reaches the human. That actually breaks the curse that killed HyperCard's descendants, because the user shapes the tool without ever becoming a toolmaker.

But follow malleability to its endpoint and you get something lonely: a thousand users with a thousand personal forks, each perfectly shaped and none of them learning from each other. Personal fit does not compound. That is why I think Dave buried his own lede. The interesting thing he shipped is not that Dex is shapeable. It is that the shaping travels.

The loop is a discovery pipeline wearing a cute feature's clothes

Look at what Dex-to-Dex actually is, stripped of the charm. A user hits real friction. Their agent notices, writes a structured defect report, scrubs the personal context out, shows the user exactly what leaves their machine, and routes it to the one agent positioned to act. The fix ships. The reporting agent closes the loop with the user who never wrote a ticket, never filed an issue, never did any homework at all.

That is a discovery pipeline. It is the thing every product team claims to want, signal from real usage, structured, deduplicatable, delivered to the person who can act, except it runs through the software itself instead of through a research function. I have written about continuous discovery on autopilot and agent-to-agent dispatch as the architecture I believe in: listening instruments in the product extract signal, and agents route work to agents without a human copying context between tools. Dave built a working, public, solo-maintained instance of exactly that, and the detail I admire most is the consent surface. The report is shown before it is sent, and notes, meetings, and conversations stay out of it. Agent-filed telemetry only works if users trust what leaves their machine, and trust is built exactly there, in the preview, not in the privacy policy.

The economics matter too. The reason user feedback is chronically thin is that reporting friction is a tax paid by the person with the least to gain. Nobody writes a good bug report for free software they use in their spare time. Dex-to-Dex drops the cost of a high-quality report to approximately zero, which means the signal volume stops being rationed by user altruism. When the marginal cost of telling the maintainer falls to nothing, you hear about the failures that used to become silent churn.

Proactive Health is a landing instrument

The second feature deserves its own reading, because it connects to the thesis I have spent this year on. I have argued that the failure signature of landing is month-two silence: nothing breaks loudly, no ticket gets filed, the user just quietly stops coming back because some connection expired or some automation silently died and the habit decayed before anyone noticed.

Proactive Health is aimed at exactly that silence. When you open a session, the agent checks everything that is supposed to be working for you, the automations, the calendar and email connections, the routines you rely on, and tells you what is healthy and what is not. What it can fix alone, it fixes. What needs you, it walks you through.

That is a landing owner living inside the product. Not a dashboard someone might check, not a quarterly health score in a CSM's deck, but an instrument that runs at the exact moment the user shows up and repairs the infrastructure of their habit before the habit dies. Every subscription product bleeding at month two has a version of this available to build and almost none have built it, because nobody owns landing and so nobody owns the plumbing that keeps a landed product landed. Dave, accountable for the whole loop as a solo maintainer, built it in a weekend, which says something uncomfortable about what the accountability gap costs the rest of us.

Where I want to push back

Two honest cautions, because an opinion piece that only applauds is a press release.

First, the loop works at n=1 in a way that does not automatically survive scale. Dave is one maintainer with the entire system in his head. Every Dex-to-Dex report lands with the single person who has total context and total authority to act, which is why the loop closes in days. Route the same reports into a fifty-person product org and you have recreated the ticket queue with better formatting: the reports need triage, ownership, deduplication, and prioritization, and those are organizational problems agents do not dissolve. The enterprise version of malleable loops needs an answer to who owns the inbound before it needs better report generation. I would go further: the loop is downstream of accountability, not a substitute for it. Dave's loop closes because Dave is on the hook. An org adopting the machinery without the ownership will get well-structured noise.

Second, the thank-you matters more than it looks, and it is fragile. The user's agent circling back to say the fix shipped is what turns telemetry into a relationship: it teaches users that reporting is worth it, which sustains the signal volume the loop depends on. Break that closing step, let reports vanish into a backlog, and users' agents will learn to stop offering, or users will learn to decline. Feedback loops die from unclosed loops, in software exactly as in teams.

What I am stealing, and what you can

For Heidi, this reframes something I had filed under nice-to-have. I have listening agents for customer signal, but they listen to what users say. Dex-to-Dex listens to what the software experiences, which is an earlier and less filtered source, and the consent-preview pattern solves the trust problem that had me hesitating. A Heidi-to-Heidi defect channel, report shown before send, personal context stripped, moves onto this quarter's list. So does a session-start health check for every automation a user depends on, because I have preached against month-two silence all year and Dave just showed me the cheapest instrument against it I have seen.

For everyone else, three moves that do not require an open-source chief of staff. Give your product a self-check that runs where the user already is, at session start, not in a settings page nobody visits, and let it repair silently before it asks anything. Let the product file its own structured failure reports, consent-gated and previewed, instead of waiting for the user to become an unpaid QA engineer. And borrow the pattern I have not seen anywhere else: Dave's help pages, written for a non-technical CFO, end with a prompt you paste into your agent, which reads the page and works out what it means for your setup. Documentation that reads the user instead of the other way around. That one is quietly radical, and it costs almost nothing to try.

Try this week

List the five things in your product that a user relies on which can silently break: expired tokens, dead webhooks, stale connections, a scheduled job that stopped. Then answer honestly: when one breaks, who notices first, you or the user? If the answer is the user, and for most products it is, you have found your month-two silence machine, and Dave Killeen just published the counter-design in public. Build the session-start check for the top two. The loop can come after, but the noticing has to come first.

Credit where due: Dave Killeen's original piece is worth your time, and Dex is open source if you want to see the loop from the inside.

Sources: Malleable Software meet Malleable Loops, Dave Killeen, The Vibe PM, August 11, 2026. heydex.ai, Dex documentation and help pages.

Share this post

Frequently asked

What are malleable loops?+

Dave Killeen's term for improvement moving through the software itself, with almost no homework for the person who spotted the problem or the person it routes to. In his AI Chief of Staff, Dex, the concrete version is two features: Proactive Health, where the agent checks its own automations and connections at session start and fixes what it can, and Dex-to-Dex reporting, where a user's agent writes a privacy-scrubbed defect report and sends it to the maintainer's agent, which ships the fix.

What is malleable software?+

The idea that AI finally lets you shape your tools instead of settling for what you are given. It has a long graveyard behind it, from Smalltalk to HyperCard to low-code, and the reason it keeps failing is that end users never wanted to program. What is different this time is that the malleability is mediated by an agent: the user states the friction in plain language and the agent touches the substrate. The user shapes the tool without ever becoming a toolmaker.

Why is the loop more important than the malleability?+

Because malleability at the individual level produces a thousand private forks, while a loop routes what each user learns back into the shared product. Dex-to-Dex converts a user's friction into a scrubbed, structured, actionable report delivered to the one agent that can act on it. That is a discovery pipeline and a landing instrument at once, and it compounds where personal customization does not.

How does Proactive Health relate to product landing?+

It is anti-month-two-silence infrastructure. The signature failure of landing is that nothing breaks loudly, the user just quietly stops. An agent that checks everything you rely on at session start, repairs what it can, and walks you through the rest is a landing owner living inside the product, catching the decay while the habit can still be saved.

Does the Dex-to-Dex loop scale beyond a solo open-source project?+

Not without two things Dave gets for free at n=1: total context and unified triage. He is one maintainer with the whole system in his head, so every report lands with the person who can act. At enterprise scale the same loop needs routing, ownership, and prioritization or it becomes a firehose of well-formatted noise. The privacy scrubbing is also load-bearing: agent-filed reports only work if users trust what leaves their machine.

What should product teams steal from this?+

Three things. Give your product a self-check that runs where the user already is and repairs silently before asking anything. Let the product file its own structured, consent-gated failure reports instead of waiting for users to write tickets. And make your documentation executable: end help pages with a prompt the user's agent can interpret against their own setup, so the docs read the user instead of the other way around.

About the author

Falk Gottlob

Falk Gottlob

Product Executive · Founder, Falkster.AI

Thirty years shipping product at Microsoft Research, Adobe, Salesforce (Marketing Cloud / Quip / Slack), and several startups including one $6.5B exit and one acquired by Microsoft. Now founder of Falkster.AI, previously CPO at Smartcat, writing this notebook from the boardroom, not the keyboard.

Comments (0)

Sign in with LinkedIn to leave a comment.

Sign in with LinkedIn
  • Be the first to comment.

Keep Reading

Posts you might find interesting based on what you just read.