How AI Reduces the Cost of Choosing Drupal (and Improves the Citizen Experience)
● Acquia Room (Charles Carroll)
📍 Acquia Room (Charles Carroll)
AI is lowering the barrier to adopting Drupal, from AI-assisted “vibe coding” that speeds up building CMS sites, templates, and recipes, to AI-driven migrations off legacy platforms.AI is lowering the barrier to adopting Drupal, from AI-assisted “vibe coding” that speeds up building CMS sites, templates, and recipes, to AI-driven migrations off legacy platforms. This session covers both: practical AI-assisted development for Drupal, plus how agencies are using AI-powered search and content tools to help citizens find services faster, with less friction and lower call-center costs. We will also address the elephant in the room: government hesitancy around AI adoption, and how to train AI on an agency's own voice instead of generic AI output.read more
Rob Ellis
Martin Anderson-Clutz
☆
Wed Aug 12 · 9:00 AM - 9:45 AM
From Firefighting to Playbooks: Keeping Large Drupal Codebases Maintainable
● Benjamin Banneker
📍 Benjamin Banneker
Drupal sites rarely fail all at once. They drift. The codebase grows, one-off fixes stack up, and the team reacts instead of builds. Every request feels custom, so nothing gets faster.Drupal sites rarely fail all at once. They drift. The codebase grows, one-off fixes stack up, and the team reacts instead of builds. Every request feels custom, so nothing gets faster.
This session shows how to turn reactive work into playbooks: written, repeatable processes for the senior tasks that usually live in one engineer's head. We'll walk one playbook end to end. We'll do some refactoring and architecting an expanding codebase so a growing team can work in it without stepping on each other. You'll see the decision points, the guardrails, and the checks that hold quality steady when the person doing the work changes.
That example is one of 25+ playbooks we run across migrations, performance, testing, and admin tooling. Walk out with a method for writing your own, plus a model you can hand a new developer on day one.
Takeaways:
- How to turn tribal knowledge into playbooks the whole team can run
- A worked example: architecting a growing Drupal codebase for long-term maintenance
- A way to keep code quality steady as the people doing the work changeread more
Fredric Mitchell
☆
Wed Aug 12 · 9:00 AM - 9:45 AM
In Defense of Paragraphs: Why Structured Content Beats Drag-and-Drop at Scale
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
The Drupal community is obsessed with the promise of visual, drag-and-drop page builders. But when managing thousands of pages across rigid government design systems, handing editors a "blank canvas" is often a liability.The Drupal community is obsessed with the promise of visual, drag-and-drop page builders. But when managing thousands of pages across rigid government design systems, handing editors a "blank canvas" is often a liability. This session argues that the constraints of the Paragraphs module remain the superior choice for large-scale federal site building.
We will explore the philosophy of constrained authoring. By replacing unconstrained layouts with strictly modeled content, you can prevent broken responsive grids, improve Section 508 accessibility compliance, enforce design system standards, and generate clean JSON payloads that map naturally to decoupled Next.js frontends.
As organizations increasingly explore AI-powered search, chatbots, summarization, and content automation, structured content becomes even more valuable. Large language models do not eliminate the need for content architecture—they amplify it. Well-modeled Paragraphs provide the structured data that AI systems can retrieve, summarize, and reason about efficiently, while reducing token costs and avoiding the need to parse complex page-builder output.
Most importantly, attendees will leave with a practical blueprint for building the "Goldilocks zone" of content editing. You will learn how to architect and configure Drupal and Paragraphs to give editors the customization they want—such as predefined background palettes, image alignments, and component styles—while maintaining the governance, consistency, accessibility, and machine-readable structure required by modern government websites.read more
Kerry Greer
☆
Wed Aug 12 · 9:00 AM - 9:45 AM
36 Hours to Rescue a Site: Lessons Learned from an Emergency Migration
● Margaret Brent Room
📍 Margaret Brent Room
When a federal agency's cloud hosting contract wasn't renewed with days to spare and no backup plan, Ad Hoc's Drupal team had one business weekend to migrate a live, publicly accessible, FedRAMP-conformant site to a new host.When a federal agency's cloud hosting contract wasn't renewed with days to spare and no backup plan, Ad Hoc's Drupal team had one business weekend to migrate a live, publicly accessible, FedRAMP-conformant site to a new host. No access to the original servers. A 1.6GB database dump. Broken image styles, a relocated config folder, SSO module conflicts, and a security dependency chain that couldn't be uninstalled from a cold database.
This session is a real-world case study on what separates a local dev migration from a production-grade federal one. Attendees will walk away with a practical framework for the three legs of any Drupal migration (codebase, database, and files) and hard-won lessons about FedRAMP compliance, DNS timing, and why a static HTML fallback is sometimes the right call.read more
Michael LeVan
Michael Weeks
☆
Wed Aug 12 · 9:00 AM - 9:45 AM
Proof, Not Vibes: AI-Assisted Accessibility for the Drupal Sites You Run
● Pyon Su Room
📍 Pyon Su Room
AI can find and fix accessibility problems on the Drupal sites you run — if you can check its work.AI can find and fix accessibility problems on the Drupal sites you run — if you can check its work. I'll show the open-source workflow I use to plan, test, and re-test accessibility in a real browser, with evidence behind every finding.
You'll leave knowing how to:
- Run an proof-first accessibility workflow on Drupal: plan, test in a real browser, critique, fix, re-test.
- Route accessibility work across local and hosted models, and tell when a local model is enough.
- Gather repeatable keyboard and browser evidence with Playwright, agent-browser, and axe-core.
- Spot where automated testing ends and a human screen-reader user has to take over.
- Use accessible markup that also makes your site readable to AI answer engines.read more
Consolidating to Drupal - Live Migration Deep Dive
● Acquia Room (Charles Carroll)
📍 Acquia Room (Charles Carroll)
Many government agencies are running a patchwork of legacy CMS platforms and one-off sites.Many government agencies are running a patchwork of legacy CMS platforms and one-off sites. This session gets technical on how to consolidate them into a single Drupal codebase using open source tools and Acquia Source, walking through a real migration approach rather than staying at the strategy level, which was feedback on last year's more business-focused version. We will offer a live migration demo.read more
Dave Devaney
John Faber
☆
Wed Aug 12 · 10:00 AM - 10:45 AM
Site Analysis and AI's Strengths and Limits
● Benjamin Banneker
📍 Benjamin Banneker
From content inventories to multi-site analysis, AI allows new types of analysis that were before impossible at scale (for instance things that used to require manual review).From content inventories to multi-site analysis, AI allows new types of analysis that were before impossible at scale (for instance things that used to require manual review). Whenever you are looking to transform sites (including merging sites or otherwise making them more coherent) so need to understand and make decisions or are simply looking for day-to-day improvements, you need to be able to analyze your existing content. We'll look at how AI can dramatically improve content analysis but also be clear-eyed about what AI cannot do (including where old-school deterministic algorithms are more appropriate).read more
David Hobbs
☆
Wed Aug 12 · 10:00 AM - 10:45 AM
An Easier, More Cost-Effective Way to Build with Drupal - without limits
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
Drupal has a reputation: powerful, flexible, enterprise-ready—and complicated. This session explores how to approach Drupal builds differently.Drupal has a reputation: powerful, flexible, enterprise-ready—and complicated.
This session explores how to approach Drupal builds differently. By strategically managing tasks including Site Building, Module development, Theming, and even migration tasks, as well as removing avoidable friction points with clever tool selection, you can dramatically change your experience building with Drupal for the better.
Join us for a conversation about how to make your Drupal builds more cost effective and enjoyable for both developers and customers.read more
Ashraf Abed
☆
Wed Aug 12 · 10:00 AM - 10:45 AM
Your AI Decisions Are Creating Risk: What Agency and Business Leaders Need to Own Now
● Margaret Brent Room
📍 Margaret Brent Room
AI is already part of how work gets delivered. It’s in the tools your teams are using, the platforms you’re recommending, and the solutions you’re putting in front of clients. It’s being introduced quietly often without much scrutiny.AI is already part of how work gets delivered.
It’s in the tools your teams are using, the platforms you’re recommending, and the solutions you’re putting in front of clients. It’s being introduced quietly often without much scrutiny.
That raises real concerns around data privacy, sovereignty, and who actually controls the systems your work depends on. A lot of AI-enabled workflows depend on sending data to systems you don’t control, running on models you can’t inspect, in environments you didn’t choose.
That creates a gap between what organisations believe they are responsible for, and what is actually happening.
We can close that gap.
We’ll look at how AI is really showing up in client work today in delivery pipelines, vendor decisions, and everyday tooling. Let's sort out where risk is introduced, how sovereignty is affected by common integration patterns, and what it takes to stay in control.
We'll review:
• Where AI is entering projects without clear oversight
• How data moves through typical AI-enabled workflows
• The implications of relying on closed vs open ecosystems
• How vendor choices shape long-term control and flexibility
• What transparency looks like when you actually need to explain a system
• Approaches to governance that can be applied in active projects
We don't need to slow teams down, but let's make sure the decisions being made are intentional, understood, and aligned with the responsibilities you carry.read more
MatthewS - he/him/his
☆
Wed Aug 12 · 10:00 AM - 10:45 AM
AI made my Drupal a little Rusty!
● Pyon Su Room
📍 Pyon Su Room
CPU-intensive processes can often lead to service interruptions, with PDF generation and site search being two common examples. Using AI-assisted development, I built two Drupal modules that harness the power of Rust binaries to solve these challenges with exceptional performance.CPU-intensive processes can often lead to service interruptions, with PDF generation and site search being two common examples.
Using AI-assisted development, I built two Drupal modules that harness the power of Rust binaries to solve these challenges with exceptional performance.
In this session, you'll discover how Rust—the systems programming language now used by Linus Torvalds and the Linux kernel community—transformed a 200-page PDF generation process that previously took 1.5–2 minutes for a $4 billion enterprise into one that completes in just a few seconds.
You'll also see how another Rust-powered binary enables lightning-fast site search without relying on Solr or database queries. Instead, the entire search experience runs on the client side, delivering fast, responsive results with a dramatically simpler architecture.read more
Mayank Gupta
Built for you by(617)-PATRICK, Champion AI speaker
Say What You Mean: Spec-Driven Development and the End of AI Guesswork
● Benjamin Banneker
📍 Benjamin Banneker
You've been here: you describe what you want, the agent hands back a clean block of code that compiles, and then you realize it solved the wrong problem. The fix isn't a cleverer prompt.You've been here: you describe what you want, the agent hands back a clean block of code that compiles, and then you realize it solved the wrong problem. The fix isn't a cleverer prompt. Coding agents are literal-minded pair programmers that need unambiguous instructions, not search engines.
This session is about spec-driven development: making a specification, not your chat history and not the code, the thing your AI agent builds against. We'll work through OpenSpec, a lightweight take on the idea. It keeps your current specs as the source of truth and gives each proposed change its own folder with a proposal, specs, design, and tasks. A change starts with one command, the agent drafts the artifacts, and you review them before any code is written, then apply and archive when it's done. You'll see how every change becomes deterministic and reviewable instead of a wall of code to rubber-stamp, plus the honest tradeoffs: more upfront thinking, more tokens, and the discipline to keep the spec alive instead of letting it rot.
You'll leave knowing how to write a spec an agent can build from, how to keep your specs and code in sync as the system changes, and how to fold this into the way your team already works. Bring a project you're stuck reverse-engineering from your own AI's output, and you'll see how to flip it around.read more
William Hurley
Matthew Clewley
☆
Wed Aug 12 · 1:00 PM - 1:45 PM
Pre-Flight Checklist: Local Code Quality for Drupal Developers
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
You've pushed your code. GitLab CI rejects it. You fix it. You push again. Sound familiar? This session is about ending that cycle.You've pushed your code. GitLab CI rejects it. You fix it. You push again. Sound familiar?
This session is about ending that cycle. I'll show you how to run the exact same code quality checks that Drupal.org's GitLab CI pipeline uses, directly inside your DDEV environment, before you ever push a commit.
Along the way, I'll demo a DDEV add-on I built specifically for this: ddev-drupal-code-quality. One command installs it, and it brings in Drupal-appropriate configurations for PHPCS, PHPStan, ESLint, Stylelint, and CSpell — matching what GitLab CI actually runs. You'll see a real workflow: run the checks, interpret the output, use autofix tools like PHP Code Beautifier where they help, use PHPStan baselines to manage pre-existing issues without being overwhelmed, and work through errors one checker at a time.
I'll also cover how to get IDE integration so problems surface while you're writing code, not after you push — and when to use ddev-drupal-contrib instead if you're working on a standalone contrib module or theme.
You don't need deep expertise in any of these tools. The add-on handles configuration, and I'll show you exactly what to do when things don't work.
At the end of this session, attendees will be able to:
Install and configure ddev-drupal-code-quality to run PHPCS, PHPStan, ESLint, Stylelint, and CSpell locally with Drupal-standard configuration.
Work through code quality errors systematically — using autofixers and PHPStan baselines to handle issues incrementally without blocking progress.
Integrate checks into their IDE and daily workflow to catch problems early, reduce failed CI builds, and ship cleaner code.read more
UltraBob
☆
Wed Aug 12 · 1:00 PM - 1:45 PM
Conquering Messy Spreadsheet Data: Building a Low-Code Faculty Activity Tracker
● Margaret Brent Room
📍 Margaret Brent Room
Administrative teams and clinical faculty are frequently trapped in spreadsheet chaos when tracking activities and incentives. Currently in development for an upcoming pilot, this session shares a behind-the-scenes look at building a low-code tracking application using Drupal 10.Administrative teams and clinical faculty are frequently trapped in spreadsheet chaos when tracking activities and incentives. Currently in development for an upcoming pilot, this session shares a behind-the-scenes look at building a low-code tracking application using Drupal 10. Learn how we paired core content modeling with a lean contrib stack—Field Group, Conditional Fields, and Inline Entity Form—to declutter the form experience. Finally, we will demonstrate how to transform the traditional Drupal look into a clean, application-like UI that simplifies data entry and wins over non-technical staff.
Key Takeaways:
- Map complex spreadsheet workflows into clean Drupal content types.
- Use site-building modules to craft a streamlined user interface.
- Gain practical insights from preparing an internal clinical tool for its first pilot.read more
Neil Liwanag
☆
Wed Aug 12 · 1:00 PM - 1:45 PM
Anatomy of an Agentic Harness: Building the Same Agent in Drupal AI, LangChain, and CrewAI
● Pyon Su Room
📍 Pyon Su Room
Every AI agent demo looks the same: type a prompt, watch it work, applause. Almost none show you the part that actually determines whether that agent survives contact with production: the harness. That's the infrastructure layer wrapping the model.Every AI agent demo looks the same: type a prompt, watch it work, applause. Almost none show you the part that actually determines whether that agent survives contact with production: the harness. That's the infrastructure layer wrapping the model. What context it's allowed to see, which tools it can call, how it remembers state across steps, how you catch it when it's wrong, where a human has to sign off, and what happens when it crashes halfway through a job.
This session builds one real task, finding Drupal pages with missing image alt-text and drafting remediation recommendations for editor review, three separate times: natively in Drupal AI, in LangChain, and in CrewAI. Then we dissect each build organ by organ, using a six-component harness framework to compare how each one actually handles context, tools, memory, verification, human review, and failure recovery.
Each framework wins somewhere. Drupal AI on role-based approvals, revisions-as-audit-trail, and editor-facing review. LangChain on tool breadth and prototyping speed. CrewAI on multi-agent roles. Each also has honest gaps, including Drupal AI's still-evolving verification and safety tooling and prompt-injection questions raised at DrupalCon Vienna. To keep this honest and reproducible, the task is deliberately tiny, about twenty pages, and every demo moment is pre-recorded as a fallback, so you're seeing the same small build compared three ways, not three frameworks surveyed. You'll leave with a reusable comparison framework you can apply to any agent stack.read more
Building Secure, Adaptable AI Modules in Drupal: Best Practices for Government Digital Platforms
● Benjamin Banneker
📍 Benjamin Banneker
Session Focus:
This session will provide a practical roadmap for designing, developing, and sustaining AI-enabled Drupal modules that are secure, configurable, reusable, and adaptable to government mission needs.Session Focus:
This session will provide a practical roadmap for designing, developing, and sustaining AI-enabled Drupal modules that are secure, configurable, reusable, and adaptable to government mission needs.
Session Description:
Federal agencies are rapidly exploring generative AI, but turning AI interest into secure, maintainable, mission-aligned digital services remains a major challenge. Many teams struggle to move beyond pilots because AI integration can introduce uncertainty around cost, security, governance, user experience, content quality, and long-term maintainability.
This session will provide a practical roadmap for developing AI-native Drupal modules that can be adapted to real government use cases. Rather than focusing on AI as a standalone tool or building custom solutions from scratch, we will examine how Drupal can serve as a secure, extensible platform for integrating AI into existing federal digital ecosystems. A key focus will be how developers can leverage and extend the existing Drupal AI ecosystem, building on the foundation created by the Drupal community to accelerate delivery, reduce duplication, and create solutions that are easier to maintain over time.
Attendees will learn best practices for designing Drupal AI solutions that are modular, configurable, reusable, and aligned with government requirements for security, accessibility, transparency, and operational control. The session will draw on Rob’s hands-on experience creating, extending, and adapting AI-enabled Drupal tools over the past three years, including lessons learned from building solutions that connect Drupal workflows, content, search, and chatbot capabilities with emerging AI services. This experience provides a practical foundation for helping developers and government technology leaders understand what works, what creates risk, and how to avoid common pitfalls that lead to overly complex or unsustainable implementations.
Attendees will leave with a clear understanding of how to approach AI-native Drupal module development, including how to define the right use case, integrate with the Drupal AI ecosystem, structure modules for adaptability, protect data and user interactions, design for configuration rather than hard-coded assumptions, and create solutions that can evolve as AI models, agency policies, and mission needs change. The session will be especially valuable for Drupal developers, technical leads, digital service teams, and government stakeholders seeking to responsibly introduce AI into existing web platforms without creating unnecessary cost, complexity, or vendor lock-in.
Themes Covered:
Leveraging Drupal’s AI module for effective AI flexibility
LLM selection and adaptability
Built in security
Testing, Validation, and continued training
Tech Stack Referenced:
Generative AI (AWS Bedrock, Large Language Models)
Drupal (CMS Integration, Open-Source Development)
Cloud-Native Solutions (AWS OpenSearch Serverless, Amazon S3 Vectors, API-Driven Workflows)
Speaker Biography: Rob Morris has been an advocate and participant for the Drupal GovCon community for the last 12 years, attending his first Drupal GovCon in 2014 and was an early implementer of Drupal for Federal Organizations. Through the emergence of AI, Rob has worked to empower the Drupal community by encouraging integration with AI to enhance the user experience within Drupal. This will be Rob’s second speakership at Drupal GovCon. Rob carries Acquia Certified Developer certifications for Drupal 7, 8, 9, 10 and was one of the first community members to achieve the Drupal 11 Certified Developer certification. Additionally, he is an AWS Certified DevOps Engineer Professional and will provide the audience with subject matter expertise that has been gathered over a decade plus of experience working with federal clients and Drupal.read more
RobbyMo
☆
Wed Aug 12 · 2:00 PM - 2:45 PM
Ctrl+Alt+Delegate: Making The Shift from Developer to Manager
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
I began my career as a developer, where building websites for clients and learning development best practices were my primary responsibilities.I began my career as a developer, where building websites for clients and learning development best practices were my primary responsibilities. As I became a team leader and manager, I quickly learned that my job now had a very different set of objectives, priorities, and keys to success.
This session will cover how I shifted from a development role into management, and the lessons I've learned that may help other developers thinking of making a similar move. I'll detail how delegation was my biggest struggle and greatest help, the importance of clear communication, and how to support my team while building their skills, not just my own.read more
Kurt Trowbridge
☆
Wed Aug 12 · 2:00 PM - 2:45 PM
What FY27's Federal Budget Means for Digital Services Contractors
● Margaret Brent Room
📍 Margaret Brent Room
Defense hits $1.45T in the FY2027 budget request, but the number that actually matters for this room is smaller and easier to miss: the civilian agency digital modernization and public-facing services funding buried inside dozens of agency budget justifications most...Defense hits $1.45T in the FY2027 budget request, but the number that actually matters for this room is smaller and easier to miss: the civilian agency digital modernization and public-facing services funding buried inside dozens of agency budget justifications most contractors never open.
This session breaks down what the FY2027 budget and the appropriations process moving through Congress actually mean for teams building and managing government websites, content platforms, and digital experiences. We'll walk through which civilian agencies are expanding digital modernization and accessibility-related investment, where new public-facing platforms and CMS consolidations are likely to originate, and how to spot an agency standing up a new digital initiative, before its first RFI even drops, versus one quietly winding one down.
Attendees leave with a repeatable framework for reading federal budget documents and acquisition forecasts, a clear picture of where FY2027 digital services money is concentrated, and a specific list of civilian agency signals worth tracking heading into the new fiscal year.
This session is for any Drupal practitioner or government technology contractor who wants to work smarter on the business side, independent developers, small shops, and BD leads at larger firms alike.read more
Brittany Winkler, Sr. GTM Manager @ GovDash
Built for you by(617)-PATRICK, Champion AI speaker
Event-Driven Integration for Real-Time Digital Services
● Benjamin Banneker
📍 Benjamin Banneker
Modern organizations depend on a growing ecosystem of applications, data sources, and business processes that must work together seamlessly. As integration landscapes become more complex, enterprises need approaches that reduce fragmentation while supporting agility, scalability, and long-term maintainability.Modern organizations depend on a growing ecosystem of applications, data sources, and business processes that must work together seamlessly. As integration landscapes become more complex, enterprises need approaches that reduce fragmentation while supporting agility, scalability, and long-term maintainability.
This session examines how SAP Business Technology Platform (BTP) Integration Suite helps organizations connect applications, data, processes, and external partners across hybrid environments. Attendees will gain an overview of key integration capabilities, including Cloud Integration, API Management, Open Connectors, and Event Mesh, and how these services work together to support a unified integration strategy.
Through a practical enterprise integration scenario involving SAP S/4HANA and e-commerce systems, the presentation will explore common integration challenges, architectural design considerations, and lessons learned from implementing connected business processes. The discussion will highlight approaches for reducing point-to-point complexity, improving data consistency, and enabling more reliable information flow across systems.
Designed for architects, developers, and technology leaders, this session provides a practical look at building integration solutions with SAP BTP and offers guidance for organizations seeking to modernize their enterprise architecture while maintaining flexibility for future growth.read more
Praveen Kumar Chakilam
☆
Wed Aug 12 · 3:00 PM - 3:45 PM
Evolving FWS.gov: A Headless Migration Tale of AI, React, and Drupal 10
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
This session examines the strategic transformation of the U.S. Fish & Wildlife Service (FWS.gov) website from a traditional coupled architecture to a modern, decoupled digital experience.This session examines the strategic transformation of the U.S. Fish & Wildlife Service (FWS.gov) website from a traditional coupled architecture to a modern, decoupled digital experience. We will share the technical journey of re-platforming to Drupal 10 on Acquia with a Next.js frontend, focusing on the practical challenges of implementation rather than a platform sales pitch. Our discussion centers on the reality of empowering content editors, detailing how we mapped Drupal Paragraphs to React components to provide intuitive, component-based layout control.
Beyond architecture, we will address the complexities of large-scale content consolidation. Attendees will learn about our phased, agile migration approach, which prioritized high-traffic landing pages while maintaining legacy stability. We will demonstrate how we standardized complex legacy data into modern, unified schemas, effectively transitioning disparate content into streamlined content types.
Finally, we will discuss the human-centric integration of AI in our migration strategy. We will detail how we utilized AI to assist in the intelligent classification and migration of over 14,000 location detail pages, emphasizing the necessity of human-in-the-loop review cycles to ensure data integrity. Attendees will walk away with repeatable strategies for delivering structured government data, managing complex phased rollouts, and balancing programmatic migration engines with essential editorial oversight to meet rigid government compliance requirements.
Note: Government speakers pending agency approval.read more
Kerry Greer
Keith Setliff
Bryson Jones
☆
Wed Aug 12 · 3:00 PM - 3:45 PM
Drupal Canvas: Strengths and Weaknesses against WP Gutenberg
● Margaret Brent Room
📍 Margaret Brent Room
Drupal Canvas promises a lot, and although it has a good set of features, it misses the mark on some elements that could lead small and medium sites to grow on it.Drupal Canvas promises a lot, and although it has a good set of features, it misses the mark on some elements that could lead small and medium sites to grow on it.
One of their biggest issues currently is code components. A great concept, but on its current iteration, it delivers a poor experience compared to the WP HTML block.
Come see why! Let's get it fixed and allow the Drupal ecosystem to grow.read more
Bernardo Martinez
☆
Wed Aug 12 · 3:00 PM - 3:45 PM
Scope creep isn't a contract problem, it's a conversation you didn't have
● Pyon Su Room
📍 Pyon Su Room
Scope creep gets blamed on clients who ask for too much, project managers who don't enforce boundaries, or SOWs that weren't tight enough.Scope creep gets blamed on clients who ask for too much, project managers who don't enforce boundaries, or SOWs that weren't tight enough. When scope drifts, there's almost always a moment earlier where something was left unsaid, assumed, or softened to keep the relationship comfortable. This session names that moment and gives account managers and/or project managers acting as account managers the language to handle it differently.read more
Getting Simple When It’s Complex: A Workshop Kit for Messy Projects
● Benjamin Banneker
📍 Benjamin Banneker
Complex projects don't stall from lack of information... they stall from lack of alignment. When stakeholders can't agree, teams spin in circles and meetings produce more meetings. The answer usually isn't another document; it's markers, sticky notes, and guided conversation.Complex projects don't stall from lack of information... they stall from lack of alignment. When stakeholders can't agree, teams spin in circles and meetings produce more meetings. The answer usually isn't another document; it's markers, sticky notes, and guided conversation.
This talk walks through half a dozen workshop exercises that cut through chaos and create alignment fast, each matched to a specific failure mode teams face again and again. Attendees leave with a framework for choosing the right exercise, real examples from large-scale civic projects, and printable templates to start facilitating their own sessions.
This kit works across all levels and even multiple roles: all who are curious are welcome!read more
Marissa (Mars) Epstein
☆
Thu Aug 13 · 9:00 AM - 9:45 AM
It's Ready When You Are: Shifting Feedback Left at SAMHSA.gov
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
Government teams know the long road to "yes." A feature gets built, then waits — for review, for sign-off, for someone with the authority to make time.Government teams know the long road to "yes." A feature gets built, then waits — for review, for sign-off, for someone with the authority to make time. And while it waits, it costs you: a staging server tied up, a demo VM someone might wipe, a prototype going stale. When a test environment is scarce, you guard it, and the iffy idea that might've been great never gets built at all.
The team behind SAMHSA.gov changed that by making one thing cheap: the environment. A full preview now builds on every merge request, wired into their pipeline — so QA, stakeholders, and the client see the running site before it merges, not after. The work moved off the developer's laptop and onto the branch, where anyone who can click a link can weigh in.
Ramakrishnan “Rama” Parameswaran, Drupal Lead at Alpha Omega, and Amber Matz, Developer Advocate at Tugboat, will follow that single shift as it pays off at three escalating levels, each drawn from real work at SAMHSA.gov:
- Shifting feedback on a change left — a preview on every merge request, so the team catches problems before a merge tangles them up.
- Shifting feedback on a feature left — a long-running feature branch parked on a preview for months, no staging server held hostage.
- Shifting feedback on a bet left — a high-risk AI proof-of-concept built and locked for the client to evaluate, with every hour going into the feature instead of the infrastructure.
The throughline: in government you can't make approvals faster — but you can make waiting for them nearly free. When an environment costs almost nothing and rebuilds itself on every push, you stop rationing experiments, reviewers can honestly send work back without it being expensive, and a finished feature can simply sit ready until the people with authority have the time. It's ready when they are.
Attendees will leave with:
- A bigger way to think about "shift left" — not just testing earlier, but moving review of changes, features, and risky bets onto the branch where the whole team can reach it.
- A working pattern for per-merge-request previews wired into CI, so clients and reviewers join QA instead of waiting for the merge.
- How disposable previews let a feature or a POC sit ready for months without tying up a server or a VM.
- A first step you can take on your own Drupal project this week.read more
Amber Matz
Ramakrishnan Parameswaran
☆
Thu Aug 13 · 9:00 AM - 9:45 AM
Implementing Content Security Policy in Drupal
● Margaret Brent Room
📍 Margaret Brent Room
Your security scan came back with an F. Two of the biggest culprits are almost always the same: missing HSTS and missing Content Security Policy (CSP) headers.Your security scan came back with an F. Two of the biggest culprits are almost always the same: missing HSTS and missing Content Security Policy (CSP) headers. CSP is one of the most effective defenses against cross-site scripting and supply-chain attacks, but it's also one of the easiest things to get subtly, dangerously wrong.
This session is a practical, hands-on guide to implementing CSP on a Drupal site. We'll start with what CSP actually is and the problem it solves, then dig into the directives, the specific-to-general cascade, and why default-src and report-only mode are your best friends. From there we get into the real-world friction: unsafe-inline, hashes vs. nonces (and why most advice about both is wrong), inconsistent browser support, and the analytics and Google Tag Manager scripts that quietly break the moment you turn CSP on.
We'll focus on doing this in Drupal: the CSP contrib module, why you should avoid Security Kit for this, the CKEditor gotcha, and handling inline JavaScript when you truly can't avoid it. A live demo will show the same page under no CSP, report-only, enforced, and the different allow-listing strategies side by side.
Takeaways: You'll leave knowing how to roll out a Content Security Policy on a Drupal site incrementally, without taking down your editors or your analytics, and how to right-size your security posture to what your site actually needs.read more
bburg
☆
Thu Aug 13 · 9:00 AM - 9:45 AM
Selling Drupal Canvas: Winning in a Visual Builder World
● Pyon Su Room
📍 Pyon Su Room
The CMS market has shifted. Clients increasingly expect visual builders, real time editing, and marketing autonomy. Competing platforms have made this their primary selling point, and agencies often find themselves defending Drupal instead of confidently positioning it.The CMS market has shifted. Clients increasingly expect visual builders, real time editing, and marketing autonomy. Competing platforms have made this their primary selling point, and agencies often find themselves defending Drupal instead of confidently positioning it.
Drupal Canvas brings modern visual building capabilities into the Drupal ecosystem. The opportunity is not just technical. It is strategic.
This session explores how to position Drupal Canvas when clients are considering other CMS platforms known for their visual builders. We will look at how Canvas compares to popular alternatives, how to frame the conversation around flexibility and governance, and how to shift from defensive selling to confident differentiation.
This is not a feature walkthrough. It is a practical guide to positioning Drupal confidently in a market that increasingly prioritizes visual editing experiences.read more
Jeff McWherter
Built for you by(617)-PATRICK, Champion AI speaker
The Expert in the Room: Building Visibility and Career Authority in Government and Tech
● Benjamin Banneker
📍 Benjamin Banneker
In a workforce where layoffs, reorgs, and AI are reshaping who gets noticed and who gets passed over, being good at your job is no longer enough.In a workforce where layoffs, reorgs, and AI are reshaping who gets noticed and who gets passed over, being good at your job is no longer enough. This session covers how to build professional visibility intentionally, tell your career story in a way that transfers across sectors, and position yourself as a go-to expert rather than a generalist. Attendees will leave with practical tools they can apply immediately to strengthen their professional presence and build the kind of recognition that opens doors.read more
Kanika Watson
☆
Thu Aug 13 · 10:00 AM - 10:45 AM
Simple Complexity: Building a Custom Drupal Diff Module
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
Regulatory changes in government documents are often small edits buried in large files. Identifying them manually is time-consuming and error-prone.Regulatory changes in government documents are often small edits buried in large files. Identifying them manually is time-consuming and error-prone. This session walks through the end-to-end process of building a custom Drupal module that highlights differences between content revisions, making those changes visible and navigable for both editors and anonymous users.
We'll cover the full module development cycle: defining requirements from a Figma spec, researching the Drupal hook and render pipeline, decisions for performance enhancement, and iterating when real data broke assumptions. Spoiler: 172 text changes on a single page is not something a reasonable designer expects.
This session offers a practical, honest look at how Drupal modules actually get built, and the UX influence on those decisions, including the parts that send developers back to step one.read more
Michael Weeks
☆
Thu Aug 13 · 10:00 AM - 10:45 AM
Beyond the Prompt: Operationalizing Digital Teammates in your CMS
● Pyon Su Room
📍 Pyon Su Room
Most organizations are stuck in a loop of AI experimentation that never reaches production. The problem isn’t the models; it’s that we’re trying to build houses on sand.Most organizations are stuck in a loop of AI experimentation that never reaches production. The problem isn’t the models; it’s that we’re trying to build houses on sand. Without structure, governance, and reliable data flows, AI is just a parlor trick.
In this session, I’ll show you how we’re moving past prompts to build AI agents that are governed, measurable, and embedded directly into real-world editorial and marketing workflows.
We’ll look at a two-part framework for operationalizing AI in your CMS:
Stop experimenting, start systemizing: How to define a digital teammate charter so AI has clear inputs, outputs, and SLAs.
Moving Beyond the Sandbox: How to take the logic from your team’s best individual experiments and bake them directly into your CMS. We’ll talk about how to turn isolated wins into shared, governed, human-in-the-loop workflows that actually move the needle for the entire organization.read more
The House That AI Built: Lessons in Systems Thinking from Two Nursery Rhymes
● Acquia Room (Charles Carroll)
📍 Acquia Room (Charles Carroll)
What do The House That Jack Built and There Was an Old Lady Who Swallowed a Fly have to do with artificial intelligence? More than you might think.What do The House That Jack Built and There Was an Old Lady Who Swallowed a Fly have to do with artificial intelligence?
More than you might think.
As organizations race to adopt AI, most conversations focus on prompts, tools, and outputs. Far less attention is paid to what happens next. A single AI-generated output becomes part of a workflow. A workflow becomes a dependency. New processes emerge to manage quality, governance, and risk. Before long, the organization is navigating a system that evolved one decision at a time.
In this thought-provoking session, we'll use two familiar nursery rhymes as unexpected frameworks for understanding how complexity develops, how systems evolve, and why some AI initiatives create more value while others create more work. Through real-world examples and practical lessons learned, attendees will leave with a new lens for thinking about AI adoption, organizational change, and the unintended consequences of well-intentioned solutions.read more
Caroline Jones
William
☆
Thu Aug 13 · 1:00 PM - 1:45 PM
Navigating the Digital Realm: A Journey Through the Eyes of a Screen Reader User
● Benjamin Banneker
📍 Benjamin Banneker
In today's interconnected world, digital accessibility is paramount to ensure inclusivity and usability for all users, including those with disabilities.In today's interconnected world, digital accessibility is paramount to ensure inclusivity and usability for all users, including those with disabilities. This interactive conference session aims to provide participants with a profound insight into the challenges and experiences of blind individuals using screen readers to navigate websites. By demoing the user experience with a person who identifies as blind and is native to screen reader technologies, attendees will gain a firsthand understanding of the usability and accessibility divide.read more
Matthew Elefant
☆
Thu Aug 13 · 1:00 PM - 1:45 PM
Chasing Ghosts: How fighting bots turned one facet hack into a threat-scoring engine
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
AI crawlers and aggressive scrapers now generate the majority of traffic to many public-sector Drupal sites — and the old defenses don't hold.AI crawlers and aggressive scrapers now generate the majority of traffic to many public-sector Drupal sites — and the old defenses don't hold. User-Agent blocklists are trivially spoofed, and per-IP rate limiting is useless against distributed operations that rotate real-looking browser identities across hundreds of thousands of residential IPs. On one high-traffic federal `.gov` site, automated traffic accounted for nearly 59% of scored requests, over 12 million blocked requests in a matter of months.
Bot Blocker is a lightweight, dependency-free Drupal module that takes a different approach: instead of trying to enumerate every bad bot by name, it scores each anonymous request on how faithfully it reproduces a real browser's request fingerprint. A composite threat score is assembled from many independent header and behavioral signals, and a three-tier User-Agent "scope gate" automatically exempts honest, self-identifying crawlers (Googlebot, Bingbot, search.gov, and friends) while reserving full scrutiny for clients impersonating a browser.
This session is the story of how the module evolved into 2.0. The headline change is architectural: detection was rebuilt as a ThreatDetector plugin system, where every signal is a small, weighted, independently testable plugin. Detection logic became composable and extensible without ever touching the core scorer. We'll trace how analyzing a single real 24-hour scraping event — millions of requests from ~878,000 unique IPs, a suspiciously flat pool of rotated Chrome/Safari User-Agents exhaustively paging through listing views, directly produced new behavioral detectors that catch what header inspection alone misses. We'll also cover making the block response pluggable (a configurable 403/410 page or a fully themeable Twig template) and adding an operations dashboard that surfaces live block metrics and the signals driving them.
Just as valuable are the hard-won deployment lessons: how Bot Blocker behaves behind a CDN and Varnish, how it interacts with Drupal's internal page cache, why a stateless, per-request design is the right layer for this problem (and why per-IP rate limiting is futile against fan-out botnets), how to keep the whole thing dependency-free for easy adoption, and how we used kernel tests and config-schema validation to ship changes with confidence.
If you run a Drupal site that's drowning in bot traffic, or you just want a practical case study in designing an extensible, plugin-based subsystem in Drupal, this talk is for you.
## What attendees will learn
- Why browser-fingerprint scoring beats name-based blocklists and IP rate limits against modern AI scrapers
- How to design a weighted, plugin-based detection system in Drupal that's composable and testable
- How to turn real access-log analysis into targeted detection signals
- Practical patterns for pluggable responses, operational dashboards, and config validation
- Real numbers and deployment gotchas from running this on a federal `.gov` behind Acquia/Varnishread more
bburg
☆
Thu Aug 13 · 1:00 PM - 1:45 PM
Surviving the Swarm: Bot and Crawler Protection for Drupal Sites
● Margaret Brent Room
📍 Margaret Brent Room
Uncontrolled bots, from aggressive scrapers to the latest AI crawlers, can grind your Drupal site to a halt, overwhelming your infrastructure and tanking user experience. As AI-driven and other bot traffic explodes, yesterday’s strategies and defenses are no longer enough.Uncontrolled bots, from aggressive scrapers to the latest AI crawlers, can grind your Drupal site to a halt, overwhelming your infrastructure and tanking user experience. As AI-driven and other bot traffic explodes, yesterday’s strategies and defenses are no longer enough. What is your plan when a swarm of traffic consumes 100% of your resources and brings down your site?
Luckily, Drupal provides a variety of great modules that can prevent your infrastructure from collapsing under the pressure. The contributed module ecosystem has a number of options to limit or completely block traffic, and there are also other tools and services, such as Web Application Firewalls (WAFs), that can further mitigate the risk, allowing you to be proactive instead of reactive.
In this session, we’ll review the current state of some of these modules and examine additional strategies that you can use, such as implementing a WAF, to protect your site. As we examine these options, we’ll highlight real-world examples of implementations and what worked (and what didn’t).
By the end of this session, you’ll have an actionable playbook to defend your Drupal site against the next bot swarm.read more
Rich Lawson
☆
Thu Aug 13 · 1:00 PM - 1:45 PM
The Senior IC's Guide to Saying No (Without Burning Bridges)
● Pyon Su Room
📍 Pyon Su Room
The request is small. The deadline hasn't moved. And the yes is out before the sentence is even finished. That reflex is probably part of what earns a promotion to senior.The request is small. The deadline hasn't moved. And the yes is out before the sentence is even finished. That reflex is probably part of what earns a promotion to senior. It's also the thing that quietly wrecks focus, delivery, and a lot of evenings.
This session is about the skill nobody gets trained on: saying no in a way that protects the work and the relationship at the same time. It's aimed at senior individual contributors, the people who can't escalate every hard conversation upward and have to hold the line themselves, often with a client on the other side of the table.
The focus is on the moves that actually work. Saying no to the request while saying yes to the goal. Making tradeoffs visible instead of silently absorbing them, so "yes, and here's what slips" replaces the heroic all-nighter. Pushing back on a shaky technical decision without it reading as ego. Managing up without sounding insubordinate. Declining a client ask without torching the account. And the part most advice skips: picking the battles worth the friction and letting the rest go.
The tradeoffs get an honest look too. No is uncomfortable, it sometimes lands wrong, and some bad "yeses" are inevitable. The goal isn't to become the person who blocks everything. It's to spend hard-won credibility on the things that actually matter, instead of being the bottleneck that says yes to everyone.read more
William Hurley
Kimberly Cabbagestalk
Built for you by(617)-PATRICK, Champion AI speaker
Your agency has or is switching to Wordpress. Get ahead with WP 7.
● Acquia Room (Charles Carroll)
📍 Acquia Room (Charles Carroll)
If you used paragraphs and never got your agency to the layout builder, they are likely asking you to migrate them into a WordPress site. Editors want the block editor experience.If you used paragraphs and never got your agency to the layout builder, they are likely asking you to migrate them into a WordPress site. Editors want the block editor experience.
If so, you are in luck; this session covers how you could translate your theme, content types, and other functionality. We will do a 10,000-foot dive, starting with the theme and working our way back to post types and custom Gutenberg blocks.
For this, we will assume the site will be migrated into WordPress 7, and you are leveraging some AI agent.read more
Bernardo Martinez
☆
Thu Aug 13 · 2:00 PM - 2:45 PM
I’m Picking up Good Migrations: High-Fidelity Site Consolidation with Drupal AI
● Benjamin Banneker
📍 Benjamin Banneker
Across government agencies, teams are facing a modern imperative: consolidate scattered legacy web properties into unified, efficient open-source platforms to cope with tightening budgets and reduced staff. However, large-scale consolidation frequently falls into the "extract-and-dump" trap.Across government agencies, teams are facing a modern imperative: consolidate scattered legacy web properties into unified, efficient open-source platforms to cope with tightening budgets and reduced staff. However, large-scale consolidation frequently falls into the "extract-and-dump" trap. Because manual field mapping for thousands of legacy pages is financially and logistically prohibitive, unstructured HTML is often shoved into a single, massive Drupal "Body" field.
This shortcut creates technical debt that sabotages content flexibility, and site extensibility; it dooms search, SEO, and future redesigns. The manual effort required to funnel unstructured legacy content into sophisticated target schemas remains a resource-intensive and high-friction endeavor.
While semantic migration for humans is hard, it’s easy for AI. So, let’s leverage it to create clean, structured data—and not just raw piles of HTML.
This session explores how the Drupal AI Migration module bridges architectural vision and automated execution. Instead of letting AI guess your data model, we show how Drupal can generate a schema from well-designed content types, providing the AI with a strict "contract" for the target data.
We will discuss how this approach allows an LLM to parse raw legacy HTML and precisely populate structured fields according to your specific schema. You’ll see how combining Drupal’s core strengths with AI-driven semantic parsing creates a high-integrity, consolidated data layer that will serve your sites for years to come.read more
Jonathan Bourland
ChristianB
☆
Thu Aug 13 · 2:00 PM - 2:45 PM
The Approval Seat: Weighing AI Trade-offs Under a Move-Fast Mandate
● Juan Ramon Jimenez
📍 Juan Ramon Jimenez
Agencies are adding AI fast — that's the mandate, and for plenty of use cases it's the right call.Agencies are adding AI fast — that's the mandate, and for plenty of use cases it's the right call. The pitch is that AI will handle the hard parts: drafting content, tagging metadata, generating alt text, holding brand consistency, even filling the skill gaps a team is missing. Much of that is real. It also leaves a specific person in an exposed seat — the program manager, digital lead, or subject-matter expert who has to approve, fund, and stand behind these systems without being the one who builds them.
As AI absorbs more of the work, the judgment moves up, not away. Someone still decides whether the output is trustworthy, whether a use case is worth it, and what "good" means for the mission. "Human-in-the-loop" is the promise across public-sector AI right now; the person holding that loop is the one this session equips.
This session builds practical literacy for weighing AI trade-offs that someone else executes: the line between what AI reliably takes off the plate and the judgment that stays human, the questions that expose a shaky use case before it ships, and a way to reason about a technical choice well enough to own the decision. Attendees leave able to sit in the approval seat and earn it — moving fast without moving blind.
Key takeaways
A clear line between what AI reliably takes off your plate and the judgment that stays yours as tools improve.
Questions a non-technical decision-maker can use to weigh an AI trade-off and own the call.
Why faster automation puts more decision weight on decision-makers, not less — and how to carry it.read more
Aparna Darisipudi
☆
Thu Aug 13 · 2:00 PM - 2:45 PM
Humanizing AEO/GEO: How Accessibility Influences the Agent Experience
● Margaret Brent Room
📍 Margaret Brent Room
Almost every organization is scrambling to change their SEO habits to understand the evolving AEO/GEO landscape. How has search changed discoverability, and what are the new metrics, terms, and tools to know?Almost every organization is scrambling to change their SEO habits to understand the evolving AEO/GEO landscape. How has search changed discoverability, and what are the new metrics, terms, and tools to know? Further, how can some of the best practices teams already leverage — content strategy, content hygiene, and accessibility — become superpowers within this agent-driven landscape?
While the ground has shifted beneath our feet, we already have many of the tools and concepts that we need to encourage discoverability within AI-driven search experiences. And the answer may surprise you — its not about being more robotic, its about being more human.
— A similar session delivered at NED Camp (November 2025) is attached. This talk will be updated to include the latest developments in the AEO/GEO space.read more
J. Hogue
Julie Elman
☆
Thu Aug 13 · 2:00 PM - 2:45 PM
Your Organisation Has a Design Problem: How Cognitive Friction Is Killing Performance
● Pyon Su Room
📍 Pyon Su Room
Most organisations are not underperforming because of people but because of how they are designed. Hidden inside everyday workflows is a constant layer of cognitive friction. Unclear expectations, unpredictable processes, and social guesswork all lead to inefficencies.Most organisations are not underperforming because of people but because of how they are designed.
Hidden inside everyday workflows is a constant layer of cognitive friction. Unclear expectations, unpredictable processes, and social guesswork all lead to inefficencies. These systems reward conformity of style over clarity of contribution.
Neurodivergent people are the canary in the coalmine.
They carry the cost through masking, translation, and constant interpretation. Over time, that same friction spreads. It slows execution, weakens decision-making, and quietly drives burnout and attrition across the organisation.
This session reframes neuroinclusion as an organisational design problem.
Drawn from lived experience and real-world leadership practice, we will examine how flawed systems create unnecessary friction across hiring, team operations, and leadership behaviour.
We will then focus on three structural shifts that high-performing organisations solve:
• Clarity: explicit expectations so people can execute without guesswork
• Predictability: visible processes so people can plan and contribute with confidence
• Psychological Safety: permission to challenge, question, and think differently without penalty
My thesis? These are not inclusion initiatives, they are performance systems.
Attendees will leave with a practical lens to diagnose where their organisation is creating friction, and concrete strategies so different kinds of minds can contribute fully.read more
MatthewS - he/him/his
🤖 Let AI help you determine which sessions to attend
Download the full session list and paste it into Claude (claude.ai).
Then paste a prompt like the example below — it gives the AI a role, context about the data, and a clear task.
Tip: This is a large session list. Claude (claude.ai) handles the full file reliably. Other tools like ChatGPT and Gemini may silently cut off the data — the verification step in the prompt will catch that.
Example prompt:
ROLE: Expert conference advisor for Drupal GovCon 2026 attendees CONTEXT: I'm pasting 38 sessions for the Drupal GovCon 2026.
I build and manage Drupal sites for a government agency. I want practical sessions on AI, accessibility, migration and security, and the chance to meet other public-sector Drupal teams. GOAL: Pick the top 10 sessions for me. OUTPUT FORMAT: List in chronological order. Do NOT number them sequentially.
Instead, start each entry with its relevance rank in bold, like: Rank #3 of 38 — Session Title.
Follow with the day and time, then 2-3 sentences on why it fits my goals. VERIFICATION: Before answering, confirm how many sessions you received.
You should have at least 38. If you received significantly fewer,
tell me immediately — my paste was probably truncated.
😎 How cool am I? 😎
Which sessions are right for you?
Describe yourself and what you want from Drupal GovCon 2026. The more specific you are, the better this works.
You can also say how many you want or when you're free — “just my top 3”, “give me 20”, “only Friday afternoon”. You get 10 unless you ask for more.
There's a daily limit on this instant version, so it stays free for everyone at the event. Want to run it as many times as you like? Scroll down, tap Copy prompt, and paste it into Claude or ChatGPT at home — the same session list, with no daily limit.
Powered by Claude. Your text is sent to Anthropic to generate the ranking, and is logged on this site so the feature can be improved. Please don't type anything confidential.
⭐
Schedule Builder v67 Schedule data captured August 13, 2026