A reference architecture for governed agentic systems — synthesizing NIST, OWASP, CSA, ISO, EU AI Act, OpenTelemetry, MITRE ATLAS, and academic research into a composable governance framework.
- NIST AI RMF
- OWASP
- CSA
- +2
30 years building security programs. The last year, building the agents that need governing.
Enterprise security leader with three decades across cybersecurity architecture, GRC, and advisory — from leading global security practices and coaching field teams to sitting across the table from CISOs during a breach. Over the past year I've been heads-down in a different way: writing agentic workflows, building governance primitives in Claude Code and Codex, and learning how autonomous systems actually behave at runtime. That practitioner experience, both enterprise security and hands-on agentic AI development, is where the Agentic Governance Framework (AGF) came from. Not theory. From shipping code and watching what breaks.
A reference architecture for governed agentic systems — synthesizing NIST, OWASP, CSA, ISO, EU AI Act, OpenTelemetry, MITRE ATLAS, and academic research into a composable governance framework.
A multi-tenant SaaS platform for AI governance and compliance — helping organizations profile AI systems, surface relevant risks from the MIT AIRISK database, and map to established frameworks like NIST AI RMF.
Occasional writing on security architecture, AI governance, and what I'm learning along the way.