01 Essay
Essay pieces
Positions on governance and evidence, argued in full.
Essay
What an AI agent receipt proves—and what it does not
A receipt is evidence of what happened, not a guarantee of what will happen next.
Read Essay
The missing chain of command
Why "an agent did it" is not an answer, and what a chain of command actually requires.
Read Essay
Audit is the product
Why the receipt, not the badge, is the thing worth inspecting.
Read 02 Architecture
Architecture pieces
How the access model behaves when something changes.
Architecture
How connector drift changes an agent’s permission surface
An upstream tool list is not static, and a governed grant has to treat that as a security fact, not a convenience.
Read Architecture
Why an approval must bind one exact call
An approval that authorizes a category of future calls is not an approval — it is a standing exception.
Read Architecture
One MCP connection is not one permission model
Why a shared connector credential is not, by itself, a caller-specific permission model.
Read 03 Checklist
Checklists
What to actually check before you trust agents with real access.
Next step
Where to go next
Two readers, two different next steps.