Apple •Spotify• Pocket Casts •Youtube •Overcast •RSS

What’s up everyone, today we have the pleasure of sitting down with Stéphane Hamel, Founder and Product Architect at MANTIS.
Summary: Stéphane Hamel built the first web analytics QA tool back in 2006, watched an ad blocker quietly borrow his logic, and spent the next 20 years learning that tracking got harder to see every year while the industry got better at documenting it. Now he’s building MANTIS, a privacy observability platform that watches what a website actually does instead of what its policy claims. Along the way he audited his own credit bureau account after a breach, found trackers from companies that no longer exist sitting on the page displaying his credit file, and spent 2 years fighting to get them removed. He also coined the term vegetative AI, sold his house and furniture after one good vacation in the Rockies, and will tell you your consent banner is a receipt for a transaction nobody actually agreed to. Wait until you hear what a third party script collects before it fires a single tag.
In this Episode…
- How To Audit Which Trackers Are Firing On Your Website
- Why Nobody On Your Team Owns The Tags Firing On Your Site
- Why Your Consent Banner Does Not Match What Your Site Actually Does
- Does Server Side Tagging Actually Improve Privacy Governance
- Why Loading A Third Party Script Is Already A Privacy Risk
- What Happens When You File A Privacy Complaint
- Why AI Output Is Useless Without Domain Expertise
- Is AI Removing The Training Path For Junior Marketers
- When Vibe Coding Works And When It Falls Apart
- Why Marketing And IT Still Fight Over Who Maintains The Stack
Recommended Martech Tools and Agencies 🛠️
We only partner with products and agencies that are chosen and vetted by us. If you’re interested in partnering, reach out here.
🎨 Knak: Go from idea to on-brand email and landing pages in minutes, using AI where it actually matters.
📧 MoEngage: Customer engagement platform that executes cross-channel campaigns and automates personalized experiences based on behavior.
🔌 GrowthBench: Twilio’s top-tier consulting partner, turning your Twilio investment into a customer engagement engine
🔄 GrowthLoop: The agentic, composable CDP that drives compound growth by uniting your cloud data + AI into one marketing engine.
About Stéphane

Stéphane Hamel is the founder and product architect of MANTIS, a privacy observability platform built to show what a website actually does at runtime rather than what its policy claims. He’s spent 35 years across the full arc of digital analytics, building WASP in 2006 as the first web analytics quality assurance tool, publishing the Digital Analytics Maturity Model in 2009, and creating Da Vinci Tools, which was later acquired by Supermetrics.
He teaches MBA and EMBA students at Université Laval and advises privacy tech startups including Supermetrics, Caden, and Masthead Data. He’s currently writing his first book on digital analytics concepts, and having been a victim of 2 of Canada’s largest data breaches, he treats privacy as a trust problem rather than a legal one.
How To Audit Which Trackers Are Firing On Your Website

Open the network tab on your own company’s homepage and count the outbound requests. Most marketers who try this land somewhere between 40 and 100 calls going to domains nobody on the current team approved. In 2006 that number was small enough to check by hand, and the only question worth asking was whether your analytics tag fired on the right page at the right moment.
That’s the question Stéphane built WASP to answer. He was on the technical side back then, implementing trackers on client websites, and nobody in the room was talking about privacy or where any of this data ended up. The tool checked whether tags fired when they were supposed to and whether they collected the right information. It was quality assurance work, and it was the first tool of its kind.
“20 years later, after a long track record of teaching, consulting, being a victim of data leaks multiple times, fraud and stuff like that, I’ve gradually shifted toward, yes, marketing is still important of course, but more a focus on ethics and privacy.”
That shift wasn’t academic. Stéphane got hit by data leaks more than once, watched fraud follow, and spent 35 years consulting and teaching through every generation of the tracking stack. MANTIS is what came out the other side, and it asks a very different question than WASP did.
The new question has 3 parts:
- What is actually loading on this website in terms of trackers
- Whether any of those trackers fire without consent
- What kind of data each one collects once it does
The hard part is the chain. Websites include third party scripts that load other scripts, a pattern Stéphane calls piggybacking, and every hop moves further from anything a marketer ever approved. Fingerprinting rides along in the same traffic. By the time a script 4 hops deep does something it shouldn’t, nobody on the marketing team can name what triggered it or say where the data went.
So MANTIS is built for people who don’t read network waterfalls for a living. Marketers, decision makers, privacy specialists, and the technical folks stuck doing QA on tags all need to see the same picture, and right now they each see a different slice of it. The industry spent 20 years getting very good at deploying tags and almost no time getting good at watching them. That gap is why most privacy programs audit documents instead of traffic, and why the documents keep passing while the traffic keeps failing.
Key takeaway: Run your own homepage through a network inspector before you click anything on the consent banner, and write down every third party domain that already received a request. Compare that list against the vendor list your consent management platform declares. Any domain in the first list that’s missing from the second is a gap you own right now.
Back to the top ⬆️
Why Nobody On Your Team Owns The Tags Firing On Your Site

Anyone can inspect a page now. Right click, open the debug console, watch the calls go out live. That was exotic in 2006 and it’s table stakes today, which raises a reasonable objection to the whole category of tag surfacing tools. If the browser already shows you everything, what’s left to build?
Stéphane’s answer is that the console shows you the calls and tells you nothing about who authorized them. Working with technical people for 35 years, he’s watched the gap widen. The traffic is visible. The accountability is gone.
“I was just a guy in my basement. I was doing it because I wanted to solve my own issue that doing quality assurance was too time-consuming and too error-prone.”
There’s a story from the WASP years he still turns over. Someone messaged him saying the tool should block the tags it found. He said no, that’s not the purpose, the purpose is quality assurance. Shortly after, ad blockers took off, and he found some of his own logic sitting inside one of the very first ones. He had no way to prove it and no means to enforce anything. He was one guy solving his own problem, and the industry took the idea somewhere he hadn’t intended.
20 years on, the reason tags go unowned has less to do with technology than with how many people handle a single pixel on its way to production. Stéphane walks through the cast:
- The marketer, who asks for something and moves on
- The software engineer, or the data engineer, depending on which fancy name the org uses this year
- Legal, who reviews the words and doesn’t get the technical constraints
- The consent management platform vendor, whose position is that they provide a tool and don’t provide legal advice
That’s 4 groups, and not one of them can describe the whole system. That’s before you count the agency your marketing lead handed tag manager access to, the one that said trust us, we know what we’re doing, we’re just going to put a tag on your website. Then somebody runs an audit 2 years later and finds tags firing that nobody recognizes.
Here’s the part that should bother you more than it probably does. Every single tag is a privacy risk and a security risk at the same time. The moment you put third party JavaScript on your site, you’ve given someone else write access to your users’ browsers, and that script can change tomorrow without telling you. It might start recording keystrokes. It might start fingerprinting. Stéphane notes that vendors coming out of the US tend to be particularly greedy about collection, and none of that requires a new contract or a new conversation.
What MANTIS does about it is draw a timeline. You got consent at this point. Here’s what fired before it. Here’s what fired after. Around that sits a map of the stack, your tag manager, your consent platform, and the pile of tags hanging off both. Seeing it laid out in order is usually the moment the room goes quiet, because the sequence is the evidence and nobody had ever looked at the sequence. Marketing has spent a decade treating tag governance as a documentation exercise, and documentation has never once caught a script that changed its behavior overnight.
Key takeaway: Pull the list of every user and agency with publish rights to your tag manager, then remove anyone who hasn’t shipped a change in 6 months. For the accounts that remain, require that every new tag gets logged with an owner, a business purpose, and the vendor’s data collection scope before it goes live.
Back to the top ⬆️

Speaking of web audits and who added what script on your site and what tools you’re using… are you still operating like it’s 2013 and you haven’t updated your chatbot? We recently started collaborating with the Docket team and what they are building with their Inbound Demand Agent is super cool. Check it out.
Why Your Consent Banner Does Not Match What Your Site Actually Does

Plenty of companies spend real money on a consent management platform and treat the purchase as the end of the project. Legal signed off on the text. Marketing configured the categories. IT confirmed the tags respect the setting. Everyone goes back to their quarter. It’s the classic martech pattern, where buying the tool feels identical to solving the problem.
Start with the wording on the banner itself. Most of them ask whether you agree to cookies, and Stéphane’s objection is that cookies were never the point. You can build a unique ID with fingerprinting. You can build one from half a dozen signals that have nothing to do with a cookie jar. So the question at the top of the page is already asking about the wrong thing, and the answer a visitor gives is being applied to a mechanism instead of to a behavior.
“When I do audits, I look at what the CMP is doing, what the privacy policy says, and what is actually going on, and it never match. Never.”
Never is a strong word and he means it, including on government websites that exist to enforce privacy law. That’s 3 documents telling 3 different stories, every single time.
The mechanism question matters because consent attaches to what a tool does, not to how it stores an identifier. A vendor still needs consent the moment it starts profiling or collecting anything personal, whether or not a cookie is involved. That’s exactly the gap the big platforms have learned to talk their way through. Google and Facebook will tell you they have a private, cookieless way of collecting data and that it’s going to be fine. So a visitor clicks reject, and Google Analytics might still fire. The Meta pixel might still fire.
Now ask what the visitor thought they were doing. Stéphane’s test is to imagine explaining the actual plumbing to someone on the street and then asking what they meant when they clicked no. Almost nobody means “no cookies.” They mean “don’t track me.” The banner collected an answer to a technical question and the company booked it as permission for a commercial one.
And the thing is right there in your face on arrival. A visitor lands on your site and gets a big ugly window before they’ve seen a single thing you make. For most brands, that window is the first touchpoint in the entire relationship, and it opens with cookies and legal boilerplate. Bad for user experience, bad for the brand, and bad legally too, because the words in it don’t describe what the site is about to do.
Treating Consent As Risk Mitigation Instead Of Trust
Ask a company why it hasn’t fixed any of this and you’ll get an honest answer wrapped in a risk calculation. What are the odds we get caught? What’s the fine? In most jurisdictions the honest math says the odds are low, so the work slides to next quarter, then the quarter after that.
Stéphane’s position is that the calculation itself is the failure. Nobody gets to 100% perfect and he doesn’t expect it. What he expects is that a company claiming to be customer focused should behave that way when the customer isn’t watching. His question skips the compliance framing entirely: if a person tells you no, and later finds out you collected data on them anyway, what do they think of you now? Where does the trust go? That’s why he talks about building on ethics rather than on exposure, and it’s a harder standard than any regulator currently enforces. Privacy budgets get approved on fear of enforcement, which is why they stay small in the places where enforcement is weak and why the same companies will be genuinely surprised when trust turns out to have been the asset all along.
Key takeaway: Run the 3 way comparison Stéphane runs in his audits. Put your consent platform’s configured behavior, your published privacy policy, and a live recording of what actually fires side by side for one high traffic page. Document every place the 3 disagree, and fix the ones where a visitor who clicked reject is still being profiled.
Back to the top ⬆️
Does Server Side Tagging Actually Improve Privacy Governance

Server side tagging keeps getting sold as the privacy friendly upgrade, often by the same agencies that sold you the client side setup. Move the tags off the browser, the pitch goes, and you stop worrying. Stéphane’s answer is more interesting than a yes or a no, because he thinks the technical case is genuinely good and the governance case is where it falls apart.
Take the upside seriously first. Moving tags server side cuts the number of dependencies your page loads. Instead of firing a dozen different trackers in the visitor’s browser, you send one signal to your own server saying here’s something worth collecting. He calls it the Lord of the Rings approach, one to rule them all. Your site gets faster and your client side attack surface shrinks, which is a real security win. On the server you can enrich the data, clean it, or route it wherever it belongs. The browser goes back to doing what a browser should do, which is show a person a page, and the heavy machinery moves out of their hands.
Then comes the cost, and it’s paid by everyone outside your building. A consumer can no longer audit your site. Neither can an independent third party, a journalist, or a regulator, because none of them can see past the first hop anymore.
Notice that “it’s privacy friendly” isn’t a false claim. It’s an unfalsifiable one. Whether a server side setup protects anybody depends entirely on what you do once the data lands, and you’re the only party who knows. That’s the whole reason Stéphane talks about causal request flow instead of talking about tags. A request means nothing on its own. What matters is what triggered it, whether the event was important enough to track in the first place, and what actually got sent.
How Cloaked Server Names Hide Tracking From Ad Blockers
“Some websites are cloaking or changing the name of the server. So if instead of sending data to Google Analytics, I’m sending data to data.mycompany.com, it doesn’t look as harmful, and ad blockers are typically not able to discover that.”
This is the part where the privacy story stops being a story. A first party subdomain looks harmless in a network log and it defeats the blocklists, because blocklists match on known vendor domains and yours isn’t one. The data still reaches the same destination. Stéphane found a way to identify those cloaked hostnames and match them back to the vendor sitting behind them, which is most of what MANTIS is doing when it flags a server side setup.
Even then, detection is where a typical visitor’s visibility ends. They learn that a site uses server side tracking and nothing else. Paying MANTIS clients can monitor their own server side behavior, because they own the box. For everyone on the outside it stays a black box, which is precisely the property that made the architecture attractive to some of the people buying it.
Nobody says the quiet part out loud, and Stéphane doesn’t pretend the motive is always cynical. He points out that agencies and vendors push the privacy framing hard, so plenty of teams adopt it in good faith and inherit the opacity by accident. His test for telling the 2 apart doesn’t require reading anyone’s mind. When your customer finds out how you’re handling their data, will they be fine with it? If the idea of someone monitoring your site and publishing what they find makes you uncomfortable, you’ve already answered the question, and no amount of architecture diagrams will change the answer. The industry keeps treating observability as a compliance feature when it’s closer to a market condition, and the companies that can survive being watched are going to end up with a structural advantage over the ones that can’t.
Key takeaway: List every first party subdomain your site sends data to and trace each one to the vendor actually receiving it. If a hostname like data.yourcompany.com resolves to a third party endpoint, disclose that vendor by name in your privacy policy and wire it into your consent categories. Treat any endpoint you can’t trace as an open finding until someone can name its owner.
Back to the top ⬆️
Why Loading A Third Party Script Is Already A Privacy Risk

Show a marketing team hard evidence that their stack misbehaves and the first question back is always the same. Okay, but is it illegal? Stéphane won’t answer that, and he’s been refusing to answer it long enough that the refusal has become part of his method. MANTIS surfaces evidence. It doesn’t certify compliance, and he’s adamant about the difference.
His reasoning is procedural. The only body that can call something illegal is a court, and even a lawyer will hedge down to a specific scenario under a specific circumstance and say it looks close to the line. Nothing gets certified until cases go through and produce examples the rest of us can reason from. In Europe that process has been grinding forward for years. In Quebec, where Law 25 was supposed to bring things to a GDPR level, Stéphane says there’s simply nothing going on. Regulators sit in an education posture, telling people privacy is really important, and as far as he knows nobody has been fined for doing digital marketing badly on their own website.
So he stays inside what he can observe. He can say a tag fired before consent. That much is a fact on the timeline, and most teams assume that’s the whole finding. It isn’t, and the part they miss is the part that should worry them.
“The mere fact of loading a third-party script, even if that script is not actually doing anything, loading any resource from any third party is potentially an issue.”
Sit with that for a second, because it breaks the mental model most consent setups are built on. Teams think in terms of firing. Did the pixel send an event or didn’t it? Stéphane thinks in terms of loading, and loading happens earlier. The moment your page requests a file from someone else’s server, that server receives a request, and a request carries a payload whether or not anyone intended it to.
What arrives on the other end is your visitor’s IP address, their browser, their operating system version, and a handful of other technical attributes. Combine those and you have a fingerprint. Keep receiving requests as the person moves from page to page and you have their browsing behavior across the session. None of that required the tag to fire. It required the script tag to exist.
He’s careful about how far he pushes it, and the caution is worth copying. He describes the risk as real enough to flag and stops there, leaving the question of how often it bites to someone with more evidence. That’s the honest position for a tool that watches traffic and stops short of practicing law. It also leaves the liability question wide open, which is the uncomfortable place most marketers actually live: the person who added the pixel usually can’t unwind a server side config or overrule legal, so the finding gets logged and nobody owns the fix. Quiet enforcement and low exposure are 2 different things, and the gap between them is where every organization is currently placing an unexamined bet.
Key takeaway: Separate your tag inventory into 2 columns, scripts that load on page render and scripts that fire on an event, then check which ones load before a visitor has answered the banner. Move every third party script you can behind consent gated loading rather than consent gated firing. For the ones that genuinely have to load early, name the vendor and the data they receive in your privacy policy.
Back to the top ⬆️
What Happens When You File A Privacy Complaint

Anyone who’s been the ops person on an in-house marketing team knows how this fight goes. You want to fix the consent setup. The founders want to know why you’re spending a sprint on a banner when the pipeline is behind. Somebody says it’s good enough, we updated it last year, and asks what the realistic odds are that a single annoyed visitor files a complaint and follows it all the way through.
In most of Canada the honest answer is that the odds are low, which is exactly why the work keeps losing. California is a different market. Defense lawyers working the wave of privacy litigation there report that 41 of 197 recent lawsuits under the state’s wiretapping statute alleged the same thing, that a visitor who opted out kept getting tracked anyway, with statutory damages running to $10,000 per class member. Multiply that by everyone who saw a misconfigured banner over 2 or 3 months and the arithmetic stops being theoretical. Kaiser Permanente reportedly paid 46 million over a single tracking pixel, and Duke Health 3.7 million. The settlements are the visible part. Underneath them sit thousands of quiet demand letters at 15K and up that never reach a courtroom.
Stéphane’s reaction to all of this starts with the sentence at the top of nearly every privacy policy ever written.
“When you read a privacy policy and it starts with, ‘Your privacy is important to us,’ I’m always calling bullshit on that.”
He files it next to the hold message telling you your call is important while they experience unusually high volume. Nobody ever specifies higher than what. It’s always higher than expected. What bugs him about the privacy version is the clause companies leave off the end: your privacy is important to us, but it depends where you live. A company that genuinely means the sentence would pick the strictest standard it faces anywhere and apply it to every customer, because a customer in a weakly regulated market is still a customer. Anything less is wishful thinking dressed up as policy.
The Equifax Complaint That Took 2 Years To Resolve
Here’s where it stops being abstract for him. After the Desjardins breach, victims across Quebec were offered free credit monitoring through Equifax. Stéphane took it, logged in, and did what he does. He audited the page.
The authenticated section of the site, the screen listing his address, his phone numbers, and every account he held, was carrying a pile of third party trackers. Facebook. Google. Assorted data brokers. Some of them belonged to companies that no longer existed. Any script sitting on that page could read anything rendered on it, which makes it a security problem before it’s ever a privacy problem.
He tried Equifax directly and got nowhere. So he filed with the Privacy Commissioner of Canada and heard nothing for one full year. When someone finally picked it up, the process turned into a game of ping pong. What are you talking about? Well, it’s technical, there’s this tracker, and this scenario, and this other thing. We’ll contact Equifax. Equifax says it’s fine. It isn’t fine. Back around again. Roughly a year after that, it was resolved. That’s 2 years, end to end, for something that should have taken an afternoon. Go look at your own Equifax or TransUnion account today and you’ll still find trackers firing in the most sensitive part of the site.
The Desjardins leak itself gives you a sense of scale that US listeners sometimes miss. Take a province or a state and assume essentially everyone in it was affected. Years later Stéphane woke up one morning to find a 25,000 car loan in his name from a bank he’d never done business with. Was it the leak? He can’t prove it, and that’s the actual damage. A breach isn’t a bad afternoon where your email address goes for a walk. It’s a thing that sits behind your head for years, and you never find out when it’s going to strike. Marketing has gotten very comfortable describing customer data as an asset on its own balance sheet while the liability side of that ledger accrues quietly on someone else’s.
Key takeaway: Audit your logged-in pages the way Stéphane audits them, starting with any screen that renders account numbers, balances, health information, or personal identifiers. Strip every third party script from those templates unless someone can defend it by name, and check the vendor list for companies that have since shut down or been acquired. Treat authenticated pages as a separate tagging environment with its own allowlist.
Back to the top ⬆️
Why An Hour Long Privacy Interview Airs As 2 Minutes
Stéphane once sat down with a Quebec television network for an hour to talk about stolen data and GDPR. Only 2 minutes aired. If you’ve ever watched an expert get compressed into a soundbite, you know the reflex is to assume something got buried on purpose.
He’s done enough radio and TV to have lost that reflex. Sometimes a producer tells him up front that there are 3 minutes for the whole segment. The audience isn’t a room full of analytics people, it’s the general public, and the explanation has to arrive fast enough to survive a channel flip.
“It’s not unusual that they will take a long interview and look for the few punches that will really resonate with the audience.”
He admits it’s frustrating and then talks himself out of the frustration in the same breath, because the point was to educate people and 2 minutes reaching a mass audience does that. Anyone who works on a genuinely technical problem eventually faces the same trade, where the version of your argument that travels is never the version you’d defend in a room of peers.
Key takeaway: Write the 2 minute version of your privacy findings before you write the full report. Pick the 3 sentences a non-technical executive would repeat to someone else, and lead with those. Keep the detailed evidence as an appendix for the people who ask for it.
Back to the top ⬆️
Why AI Output Is Useless Without Domain Expertise

The argument against paying for an MBA has never been easier to make. Everything’s online, the model will explain any concept you name, and it’ll do it at 2am for the price of a subscription. Stéphane teaches MBA students at Université Laval, so he hears this weekly, and he has a specific answer rather than a defensive one.
Watch a student who doesn’t have the fundamentals try to use one of these tools. They can’t ask the right question, because framing the question is the part that requires knowing the shape of the problem. Then they can’t check the answer. The output arrives sounding intelligent and credible, formatted beautifully, and they have no way to tell whether it’s correct. That second failure is worse than the first, because it feels like success.
He coined a term for the state you end up in, an obvious pun he clearly enjoys. Vegetative AI, as opposed to generative AI. You hand over your judgment, the tool hands back something plausible, and nobody in the loop is thinking.
“In a way, AI, I feel like it will give you the average best answer. What I want is the best answer.”
He brings up a study he’d read where researchers monitored brain activity while people wrote essays and found less of it when AI was involved. His reaction isn’t to dismiss the finding, which he thinks makes sense on its face. His complaint is about what the researchers didn’t measure. Nobody checked which other kinds of thinking became available once the rote part was handled. Point the tool at pushing an idea further, getting more creative, arguing with yourself, and you get higher quality out of the same hours. Point it at asking lazy questions and swallowing whatever comes back, and yes, your brain goes to sleep and your output gets worse.
The classroom is where he applies the standard. His students all have access to these tools, so his expectations went up. He now rejects work at the level a model produces on a first try, because that level is free to everyone and therefore worth nothing. Raising the bar, in practice, means refusing to be impressed by competence.
What AI Unlocked That 20 Years Of Effort Could Not
The personal version of this is the most convincing part of his case. Stéphane had a vision 20 years ago for what WASP should have become, and he could never build it. Some of that was technical, the platform simply couldn’t do what he wanted. Most of it was resources: people, budget, and time he didn’t have. The idea sat there.
He’s building it now, and he says what exists is light years past the thing he originally imagined. He’s blunt that it wouldn’t exist without AI, and that money alone wouldn’t have closed the gap either, because even a funded team would still be years out. The same unlock got his book moving after 20 years on the bucket list. What changed there was structural. He stopped treating it as a writing project and started running it like software development, which is a discipline he already knows, and suddenly the thing had a shape he could work in.
The uncomfortable implication for everyone else is that the tools reward whatever you brought with you. A person with 35 years of pattern recognition gets a force multiplier. A person without it gets confident-sounding output they can’t evaluate, and the industry is about to find out how many of its practitioners are in which group.
Key takeaway: Pick one thing you shipped with AI help this month and try to defend every decision in it without opening the tool. Wherever you can’t explain why a choice is right, you’ve found a concept gap to close rather than a task to keep delegating. Make that check a habit before the output ships, not after someone questions it.
Back to the top ⬆️
Is AI Removing The Training Path For Junior Marketers

Someone with 35 years of accumulated pattern recognition gets an enormous amount out of these tools. That’s the happy version of the story, and it raises an obvious question about everyone standing at the bottom of the ladder wondering whether the rungs are still there.
Stéphane takes the worry seriously, and he can name the mechanism. The tasks that get delegated to AI first are almost exactly the tasks that used to go to junior people. That wasn’t a coincidence of difficulty. Those tasks were the apprenticeship. You did the tedious work, you got it wrong, somebody senior corrected you, and 3 years of that turned into judgment. Remove the tedious work and you’ve removed the training loop that came free with it.
School doesn’t fill the gap either, and he’d know, since he teaches. Classroom work is fine as far as it goes. Then you hit the market and the market is a different reality. His conclusion is uncomfortable and short: if junior people don’t get the chance to learn in the field, we’re going to be at risk in a few years.
“We heard about companies firing their whole team and replacing with AI. It makes for a good LinkedIn post. But the reality is, oftentimes what they realize is that maybe we went a little too far and we need to rehire some people because the human in the loop is still important.”
He’s read something recently that made him a little more hopeful, though he can’t remember where, and he flags that honestly rather than dressing it up as research. The suggestion was that this particular phase might already be running out. The easy tasks have been handed over. What’s left is a new category of work that juniors can absolutely do, which means the demand comes back in a different shape.
You can already watch the correction happening in public. A company announces it replaced a whole function with AI, collects the engagement, and then quietly hires several of those roles back once the output starts costing more to fix than it saved. Apprenticeship in this industry was never a program anybody funded. It was a byproduct of work being inefficient enough to need extra hands, and now that the inefficiency is gone, somebody has to pay for the training on purpose or stop complaining about the talent pipeline in 5 years.
Key takeaway: Pick 2 recurring tasks on your team that you’ve already automated and hand one of them back to a junior person as a supervised exercise, with the AI output used as the thing they critique rather than the thing they submit. Put it on the calendar as a standing block so it survives a busy quarter. Judgment only develops on work where being wrong has a visible cost.
Back to the top ⬆️
When Vibe Coding Works And When It Falls Apart

Vibe coding has picked up a sneer somewhere along the way, and Stéphane thinks the sneer is mostly deserved by a specific version of it. Picture the path: you’ve got no software engineering background, you wake up one morning with a brilliant idea, and you assume the tool will carry you the rest of the way. Sometimes that works. Often you end up with an app riddled with errors you can’t see, which is the same failure as before, just faster and with better syntax highlighting.
He describes what’s happening on the App Store as a gold rush. People are generating apps in bulk and pushing them out in the hope that one of them prints money. The volume is the tell. Nobody producing at that rate is evaluating anything.
His own example lands harder than the statistic would. Someone got in touch about a product for managing privacy workflow, and the conversation went well right up until Stéphane started asking specific questions. Underneath the interface there was a database, and between the 2 of them there was nothing. No logic. The founder hadn’t understood the concepts of privacy and consent well enough to know what the software was supposed to actually do, and the tool had happily built the shell of a product around a hollow middle.
“I’m an architect. I’m telling the AI, ‘This is what I want you to do, and this is how you will do it. This is the result I expect.'”
Notice how much is packed into that. He specifies the goal, he specifies the method, and he states the result he’s expecting before anything runs. That’s 3 constraints, all of which require knowing the domain. Then comes the part he treats as non-negotiable: the code comes back and he can read it. He says the quality is genuinely impressive, and in the same breath he says understanding what it does is the thing that matters. Being impressed by output you can’t audit is how you get the hollow product.
He reaches for medicine to make the general case. You go to your doctor and at some point they swivel around and run a quick search. That’s never bothered anybody, because a doctor isn’t valuable for having memorized everything. They’re valuable for knowing what to look up and being able to tell whether the answer is any good. These days they’re probably asking a model instead of a search engine, and the job is unchanged. The background and the critical judgment are doing the work; the lookup is just a lookup.
Every field is heading toward the same arrangement, and marketing is further along than it admits. The uncomfortable part is that the arrangement only holds for people who already earned the judgment somewhere, which means the tools that make expertise more valuable are also the tools quietly making it harder to acquire.
Key takeaway: Write down the result you expect before you prompt, in enough detail that you could tell a contractor whether they delivered it. Then read what comes back and find one thing you’d change and explain why. If you can’t produce that critique, you’re not directing the build, you’re accepting it.
Back to the top ⬆️
Why Marketing And IT Still Fight Over Who Maintains The Stack

You’ve seen the post. Why would anyone pay for Salesforce or HubSpot now, I can build my own CRM. And sure, a few prompts will get you from 0 to something that demos well. Then comes month 4, when a field needs to change, an integration breaks, and the person who built it has moved on to a different shiny thing. Marketing ops teams have spent their entire careers as the ones who inherit that, quietly maintaining whatever the top of the funnel decided to launch.
Stéphane doesn’t argue the maintenance point. He goes underneath it.
“What is your core business as an organization? Is it to develop software? Or is it to actually deliver value for the whatever thing you’re doing?”
That question has been sitting under the marketing and IT conflict since long before anybody generated a line of code from a prompt. Stéphane has worked both sides of it and describes the fight as one that started years and years ago and simply never ends.
Look at what each side is rewarded for and the conflict stops looking like a personality problem. Marketing’s job is the next thing. The next campaign, the next quarter’s number, the next launch. Decades of media buying trained the whole function to love a particular feeling: put $100,000 into Google Ads and you know exactly what you spent and roughly what you got. It’s legible and it’s reassuring. Stéphane says vibe coding delivers the same feeling. You’re building something, you can see it taking shape, and it feels like control.
IT is graded on the opposite outcome. Security, stability, and the guarantee that when you put A in, B comes out, this week and next quarter and after the vendor pushes an update. Getting there takes longer on purpose. So one group is sprinting after the next big thing while the other is deliberately slowing down to keep the last 10 things standing, and both are doing exactly what their scoreboard asks.
Where he’s optimistic is translation. The gap between the 2 sides has always been partly linguistic, marketers unable to specify what they want in terms an engineer can build against, engineers unable to move at a speed marketing recognizes as responsive. AI narrows both.
A marketing ops person can now build a rough prototype and send that to the data team instead of a paragraph of description. It’s unmaintained and unpolished and full of problems, and it still communicates more in 5 minutes than a requirements doc does in a week. Stéphane’s response to that idea is 3 words long: and that’s innovation. The teams that win the next few years will be the ones that treat a throwaway prototype as a specification format rather than as a threat to whoever owns the roadmap.
Key takeaway: Next time you file a request with your data or engineering team, build a rough working version first and attach it to the ticket with a note saying this is throwaway, here’s the behavior I’m after. Label it clearly so nobody mistakes it for something to ship. You’ll cut a round of clarification calls and find out fast whether what you asked for is what you actually wanted.
Back to the top ⬆️
How To Decide Which Projects Deserve Your Energy

Stéphane is a teacher, a builder, a marketer, a privacy specialist, and an author with a first book on the way. He’s also a grandfather, a dog owner, and an outdoor adventurer who has done a stretch as a digital nomad. That’s a lot of competing claims on a calendar, so the obvious question is how any of it gets prioritized.
His answer doesn’t start with a system. It starts with adventure, and with the idea that feeling young is worth protecting deliberately. The mechanism he trusts for that is having projects going at all times.
“They say projects keeps us young. Well, I’m just 20 years old.”
The proof he offers isn’t a career move. He and his wife took a vacation in the Rockies, made the obligatory stop in Canmore, and had the thought every visitor has on a good day, that they could live here. Most people get back on the plane and let it fade. They went home, sold the house, sold the furniture, sold essentially everything they owned, and drove back out with a travel trailer, the dog, and whatever fit. They lived there for a couple of years before coming back to Québec, and he’s not finished with it. There are hiking trails he hasn’t done yet, and the current project is 2 rental cottages in Charlevoix.
What he keeps coming back to is guts. The willingness to challenge yourself, and to challenge other people while you’re at it, which tracks with a career spent telling organizations things they didn’t want to hear about their own websites. The same instinct that made him file a complaint and chase it for 2 years is the one that emptied the house. Energy goes wherever the challenge is.
Key takeaway: Audit your current commitments against a single question: which of these still requires you to be brave. Cut or delegate the ones that only require you to be competent, since those are the ones quietly consuming the hours. Keep at least one project running at all times that you aren’t yet sure you can pull off.
Back to the top ⬆️
Episode Recap

Stéphane Hamel makes one central argument across this whole conversation, and it reframes privacy work for anyone running a martech stack. Privacy is an observability problem before it’s a legal or configuration problem. There’s a declared system, made of your consent banner, your privacy policy, and the vendor promises behind both, and there’s an observable system, which is whatever your visitor’s browser actually does. Only the second one is real, and in 35 years of audits he says the 2 have never once matched.
The tactical thread running underneath is a steady narrowing of visibility. In 2006 you could count the tags on a page by hand, which is the problem WASP solved. Then scripts started loading other scripts, and the chain moved past what any single team approved. Then consent platforms arrived and gave everyone a document to point at. Then server side tagging moved the traffic somewhere no outsider can audit at all, sometimes behind a first party subdomain chosen specifically because blocklists won’t match it. At every step the industry gained a capability and lost a way to check itself, and the sharpest technical point in the episode is that a third party script collects your visitor’s IP, browser, operating system, and page to page behavior purely by being loaded. It doesn’t have to fire anything. Most consent setups are gating the wrong event.
The second half turns to what all of this does to expertise, and the through line holds. AI collapses the cost of building things, which is why Stéphane can finally build the product he sketched 20 years ago and finish a book that sat on his list just as long. The same collapse removes the tedious work that used to train junior people, and he’s genuinely worried about the gap that leaves in 5 years. His term for the failure mode is vegetative AI, meaning you’ve outsourced judgment to something that produces a credible answer you have no way to evaluate. The person who can direct the work and audit the output gets a force multiplier. Everyone else gets confident output and no way to check it, which is the same asymmetry the privacy story describes, applied to careers instead of websites.
What makes him credible is how much he refuses to claim. He won’t say any of the behavior he finds is illegal, because only a court can, and he’s watched regulators in Quebec stay in an education posture while nobody gets fined. He can’t prove an early ad blocker borrowed his logic even though he recognized it. He can’t prove the 25,000 car loan that appeared in his name came from the Desjardins breach. He couldn’t remember where he read the more hopeful take on junior hiring and said so rather than dressing it up. That restraint is the point of the tool he’s building, which surfaces evidence and stops short of issuing verdicts. The uncomfortable residue is a liability vacuum: the marketer who added the pixel usually can’t unwind a server side config or overrule legal, so findings get logged and the fix belongs to nobody. Silence from regulators is a measure of their capacity rather than of your risk.
Find Stéphane on LinkedIn, and find MANTIS at getmantis.net.
Full episode ⬇️ or Back to the top ⬆️

✌️
—
Intro music by Wowa via Unminus
Cover art created with Midjourney (check out how)
Apple •Spotify• Pocket Casts •Youtube •Overcast •RSS
Related tags
<< Previous episode
Next episode >>
All categories
- AI (110)
- career (66)
- customer data (68)
- email (64)
- guest episode (187)
- operations (127)
- people skills (35)
- productivity (10)
- seo (6)
See all episodes
Future-proofing the humans behind the tech
Apple •Pocket Casts•Google •Overcast •Spotify •Breaker •Castro •RSS
