Security architect and engineer working on AI and agent security, cloud security, runtime isolation, and policy-governed automation.
I write about bounded autonomy: how a system can detect risk, reason about impact, and take action without becoming a new source of risk. That takes more than good automation — it takes trustworthy identity and delegation, enforceable policy, a constrained blast radius, verification and rollback, and complete auditability.
Bounded Autonomy — secure systems design, agent identity, and policy-governed autonomous defense.
- Autonomous Defense Without Autonomous Risk — a blueprint for policy-governed security agents
- IAM Design for Multi-Tenant AI Platforms — identity and delegation when your tenants are agents
- Policy as Code: Enforcing Security Guardrails with OPA and Rego — beyond Kubernetes admission control
| Repository | What it is |
|---|---|
| agentic-identity-graph | Graph-based identity resolution and runtime authorization for enterprise AI agents. Models users, agents, tools, connectors, scopes and policies to make explainable allow/deny decisions on agent tool calls. |
| autonomous-defense-policy-agent | Policy-governed autonomous remediation. Detects risk, scores impact, plans fixes, auto-executes low-risk actions, escalates the rest — with a full audit trail. |
| agent-guard | A safety and audit layer for autonomous agents. |
| coupon | An intentionally vulnerable agentic AI app — the DVWA/WebGoat of the OWASP LLM Top 10, hardened one category at a time. Teaching code, not production. |
Views expressed in my writing are my own and do not represent those of any employer.