Area of expertise
Agent Security
Identity, authorization, execution boundaries, human-in-the-loop controls, and evidence for agentic systems.
Agent identityAuthorizationHarness safetyMCPPiNon-human identity
Research
Rethinking Identity for Agentic Systems
The mental model I use to reason about identity controls across the originating principal, the agent, and the infrastructure running it.
Authorization Beyond Tool Calling
Why enterprise authorization is about capabilities, identity, and resource boundaries, not just tool permissions.
Your Prompt Isn't the Security Boundary
A practical way to think about harness safety when agents can actually execute.
Tools