Chief Platform Officer at OPAQUE · Creator of the Agent Governance Toolkit
Website · AgenTrust · LinkedIn · Sponsor
I build confidential AI infrastructure and verifiable agent systems. Before OPAQUE, I spent 18 years at Microsoft working on cloud, developer, and AI platforms.
My approach is Scale by Subtraction: remove unnecessary complexity, put policy checks on the action path, and make claims testable by someone outside the system that produced them.
At OPAQUE, my work connects three layers:
| Layer | What it provides |
|---|---|
| Behavioral policy | Explicit rules for tool calls and delegated authority, enforced outside the model's reasoning |
| Confidential computing | Workload isolation and attestation within a stated platform threat model |
| Runtime evidence | Signed records that bind claims to a signer, with independently verified evidence needed to establish those claims |
Hardware attestation does not establish policy correctness or eliminate side channels. A valid record signature establishes integrity and signer identity; it does not, by itself, prove the recorded action happened.
Documentation · Verification demo · Runnable demos
| Project | Purpose | Status and source |
|---|---|---|
| TRACE | Portable signed records of agent runs, with a specification and verification rules | Spec v0.2; hosted at the Linux Foundation. AAIF sandbox proposal remains open |
| cMCP | MCP gateway that evaluates Cedar policy on tool calls and emits TRACE evidence | Releases; gateway and attestation limits |
| Agent Manifest | Signed deployment manifests covering prompts, policy, tools, model identity, and other agent artifacts | Spec v0.2, Python and TypeScript SDKs; CoSAI WS4 RFC remains open |
| cA2A | Attenuated delegation, peer appraisal, and provenance as a profile on A2A | Releases; developer-preview limits |
| Weight Custody Manifest | A protocol for conditional model-weight release and custody evidence | Pre-1.0 public review; key-service, platform, and hardware-owner limits |
| TRACE test suite | Executable conformance checks for TRACE records | Public suite; results apply to the properties tested |
AGT is the open-source agent governance project I created, hosted by Microsoft under MIT. It brings together policy enforcement, agent identity and trust, runtime supervision, and reliability controls.
pip install "agent-governance-toolkit[full]"The repository includes Python, .NET, TypeScript, Go, and Rust SDKs, plus governance integrations for coding agents. See its documentation for current packages, installation paths, and supported integrations.
The published OWASP Agentic Top 10 mapping self-assesses seven categories as full and three as partial: supply chain, memory/context poisoning, and human-agent trust exploitation. This is a project mapping, not an independent audit or compliance certification. Deployment-specific controls still matter.
- Architecting at Scale, published by Packt. Follow ShopFlow from a monolith to a distributed system across 16 technical chapters. The companion repository contains the code, chapter notes, and 73 Architect's Prompts.
- Agentic Architecture: four patterns for routing, grounded context, constrained execution, and evidence, with executable checks and explicit limits.
- Proof, Not Promises, my LinkedIn newsletter on verifiable claims in AI systems.
- Notes on implementation findings, specification gaps, and fixes.
- awesome-ai-governance and awesome-auditable-ai: curated reading.
My standards work includes TRACE at the Linux Foundation, the AAIF sandbox proposal, CoSAI software supply chain and agentic-system design discussions, OWASP agentic security, and OpenSSF supply chain practices. An open proposal is not an adopted standard.
Selected merged contributions:
- LlamaIndex: AgentMesh trust-layer integration.
- GitHub Copilot: agent-governance skill.
- Agent Lightning: Agent OS integration for training governance.




