Grounded in running systems, not takes.
Every article here links back to a live demo, a real policy file, or a real bug I found and fixed — not generic advice. Pre-launch, no client case studies exist yet; what follows is the actual engineering and governance reasoning behind what I've built.
Who's really running your AI?
Seven of nine enterprise systems I track each signed their own LLM-vendor deal in the last year — a system-by-system look at who anchored to which lab.
How a governed AI write-path actually works
Read, decide, approve, execute, audit, reject, rollback — with a real bug I caught building it.
NIST AI RMF, ISO 42001, EU AI Act: one mapping, not three checklists
Why the same evidence trail satisfies all three, if it's architectural from the start.
An MCP integration still needs the same approval gates a custom API needs
What Model Context Protocol standardizes, and what it doesn't — with real code.
What actually drives Oracle Fusion Cloud ERP AI-agent readiness
A real, reproducible scoring model from use case, integration method, and existing governance controls.
What a real AI cost-governance ledger looks like
0% of my own model calls settle at exactly $0 before touching billed credit — real numbers.
Why "auto-approve everything under $X" is an AP governance anti-pattern
Scope, spend tiers, and ERP validation as independent layers — plus a rollback bug I found.
Why router-watch and security-watch only propose — never apply
The real 12-day cross-machine auth gap that motivated security-watch, and why propose-and-approve is the whole point.
Oracle's own sanctioned path into EBS can't tell you which agent did what
Oracle's own documentation: HTTP Basic Auth only, a single shared service account for every call — verified against Oracle's own docs.
Prefer how the demos themselves were built? See the engineering writeups →