The Agent Hustle / #003 / Work for Good

How easy is it now to start doing good?

One Sunday evening, the founder described a free way for young people to find real work experience across the UK.

An AI agent turned that idea into a private concept demo the same night. That is the speed worth noticing.

It is not the same as a safe, live platform for children.

The point of the project

Open doors, not charge for entry.

A student should be able to find a one-day, two-day, three-day or week-long placement.

A business could offer a real opportunity; a matching flow would connect interests, availability and location.

The founder chose to keep it free for students and businesses.

Parents must approve a young person's account, and businesses must be reviewed before posting.

Safeguarding is a condition of a real launch, not a feature to wave through because the screens look ready.

Her own line for this chapter: “This is going to be about how easy it is to now do good in the world.” The evening showed how quickly people can make an idea visible. Doing the good part takes the slower work of trust.

What existed that night

  • Private concept screens for student, business and admin journeys.
  • Student and business log-in buttons shown in the prototype, but clearly marked demo-only. No real account could log in through them.
  • A Supabase project created by the founder; its authentication service responded to a live check.
  • A database design in review, not yet run on the project.
Sunday 27 September 2026 / elapsed milestones, not active-work hours

A voice note, a demo, then the robot wall.

The timestamps mark how the work moved between a person and an agent. They are not a stopwatch or a claim that the platform was launched.

5:06–5:13pm / shape the promise

Free, with a parent in the loop.

  • The founder described UK work-experience listings and student matching, web first.
  • She rejected charging either side.
  • She asked for parent approval, owner review of businesses and a safeguarding check.
  • The project got its name: The World of Work.
Later that evening / make it visible

A private first look.

  • Concept screens covered student, business and admin journeys.
  • The founder asked for separate student and business log-in buttons at the top; the prototype showed them as demo-only.
  • The real accounts and database were still to be connected.
11:18–11:25pm / account handoff

A bot check changed who had to click.

  • The agent began Supabase signup. Its password form required a number, so the founder supplied a revised password through a secure vault link, not chat.
  • An image-based robot check stopped the agent. The founder completed signup in her own browser.
  • Finishing signup on her device did not give the agent a session. Sign-in met another robot check. No attempt to bypass it.
11:27–11:31pm / safe division of work

One human step, then independent checks.

  • The founder created the free project and kept its database password in the vault.
  • She shared a project URL and a browser-safe publishable key; no server secret was shared in chat.
  • The agent confirmed the authentication service responded. The app's tables did not exist yet.
  • A single reviewed SQL handoff was planned for the founder to run in her dashboard. It had not been run by this point.
The agent lesson

A human handoff is part of the build.

A robot check is a stop sign, not a challenge to sneak past.

The useful response was to tell the founder which step only she could do, keep passwords in the vault, ask for only the public configuration values needed for the next check, and avoid pretending that a concept screen was a working login.

The second sign-in block made that boundary plain: a successful signup on one device does not sign the agent into another.

The same applies to database access. A publishable key is intended for a browser client, but it cannot create tables or replace owner access.

A secret service key should not be pasted into a conversation or a public web page.

The next handoff is a vetted migration run in the owner's own dashboard, followed by tests of who can read or change each record.

What still has to happen

  • Run and test the database migration. Connect real student and business authentication.
  • Prove that a parent, not the student's browser, approves a minor's account.
  • Review businesses and safeguarding procedures before real postings or students.
  • Test matching, privacy and notifications with sample records before any pilot.

No live placements, vetted businesses, real student accounts or successful matches are claimed here. A first demo is not a launch.

Why this is Hustle #003

The work starts before the website opens.

A founder with no need to code could describe a public-good idea and see its shape on screen that evening.

The hard part is now making it worthy of a child, a parent and a business trusting it.

We will show those steps as they happen, including the parts where a person has to take the wheel.

Explore the eight-mission method or Hustle #002: Ocean.