Articles

Grounded in running systems, not takes.

Every article here links back to a live demo, a real policy file, or a real bug I found and fixed — not generic advice. Pre-launch, no client case studies exist yet; what follows is the actual engineering and governance reasoning behind what I've built.

Who's really running your AI?

Seven of nine enterprise systems I track each signed their own LLM-vendor deal in the last year — a system-by-system look at who anchored to which lab.

Read →

How a governed AI write-path actually works

Read, decide, approve, execute, audit, reject, rollback — with a real bug I caught building it.

Read →

NIST AI RMF, ISO 42001, EU AI Act: one mapping, not three checklists

Why the same evidence trail satisfies all three, if it's architectural from the start.

Read →

An MCP integration still needs the same approval gates a custom API needs

What Model Context Protocol standardizes, and what it doesn't — with real code.

Read →

What actually drives Oracle Fusion Cloud ERP AI-agent readiness

A real, reproducible scoring model from use case, integration method, and existing governance controls.

Read →

What a real AI cost-governance ledger looks like

0% of my own model calls settle at exactly $0 before touching billed credit — real numbers.

Read →

Why "auto-approve everything under $X" is an AP governance anti-pattern

Scope, spend tiers, and ERP validation as independent layers — plus a rollback bug I found.

Read →

Why router-watch and security-watch only propose — never apply

The real 12-day cross-machine auth gap that motivated security-watch, and why propose-and-approve is the whole point.

Read →

Oracle's own sanctioned path into EBS can't tell you which agent did what

Oracle's own documentation: HTTP Basic Auth only, a single shared service account for every call — verified against Oracle's own docs.

Read →

Prefer how the demos themselves were built? See the engineering writeups →