
About
I work on the problem of letting AI agents act inside real companies without handing them the keys to everything.
That means identity, delegation, and audit: how an agent proves which human it's acting for, how that authority narrows at each hop, and what a defensible record of the action looks like afterwards. In practice it pulls in OAuth and OIDC, token exchange and attenuation, policy enforcement at the point of action, MCP's authorization model, and, increasingly, what regulators expect an audit trail to contain.
I write about it here in depth, and I build it at my company, an access control layer for enterprise AI, built in Germany and hosted in the EU.
On the obvious conflict: I run a company in the space I write about. So the writing stays vendor-neutral, specs, tradeoffs, and architectures you can implement yourself, with no product pitches in the technical content. Where something is genuinely a product decision rather than an architectural one, I say so. If I ever fail that standard, tell me.
Before this I spent 15+ years as a Principal Software Engineer and Tech Lead, building and scaling web, mobile, and backend systems and leading engineering teams. Distributed systems, observability, and production debugging, which turns out to be most of what agent authorization actually is, once the novelty wears off.
I take a limited number of advisory conversations with teams putting agents into production. Book 25 minutes →
Get the series as it ships
New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.