Notes on the agentic enterprise.
What changes when AI stops talking and starts acting. Field notes on governance, audit, and the quiet infrastructure layer that the next decade of software will be built on.
Govern at the Choke Point
MCP Safety Labels Run on the Honor System. We Checked 31 Popular Servers.
Every MCP tool describes its own risk, and clients take its word. actlint audited 31 popular servers — Stripe, GitHub, Cloudflare, Linear, Firecrawl, and more. Most labels are honest. Four are wrong, and every wrong label fails the same way.
Agents Speak Intent, Not Implementation
MCP secures the pipe. It doesn’t govern the action.
The Model Context Protocol standardizes how agents discover and call tools. It says nothing about whether a given call should be allowed — and that question is the whole game.
Govern at the Choke Point
Your Agent Doesn't Have a Choke Point
When every agentic feature wires its own way out to production, governance becomes something you re-establish in a dozen places — and you only have it where someone remembered to add it.
Audit the Why, Not Just the What
Policy Rules Should Be Tested Before They Fire
Every other category of software configuration is tested before it reaches production. Policy rules that govern AI agents are not. That gap is going to matter.
AI Proposes, Rules Decide
The Automation Reflex Breaks Down at the Governance Layer
The instinct to automate everything that is slow or expensive is almost always right. Governance is the exception - and understanding why matters for any team deploying agents at scale.
AI Proposes, Rules Decide
There Are Two AIs in Every Agentic System. Most Teams Only See One.
AI agents are reshaping enterprise software. So is AI tooling for the people who run enterprise software. Conflating these two is one of the most common architectural mistakes we see.
The Boundary Thesis
The Quiet Infrastructure Layer of the Next Decade
The categories that end up running the world rarely arrive with a flag and a parade. They arrive as the answer to a problem that everyone has and nobody has named yet.
Agents Speak Intent, Not Implementation
Agents Should Speak Intent, Not API
Every team building agents eventually rediscovers the same lesson: making the agent learn each provider's API turns out to be the wrong abstraction. The right one looks more like a verb.
Audit the Why, Not Just the What
What an Audit Trail Actually Means in the Age of AI
When the actor is a probabilistic system, an audit trail is no longer a forensic tool. It becomes the only honest answer to 'what did our software actually do?'
Govern at the Choke Point
The Three Things That Break When Agents Touch Production
Most agentic projects don't fail at the model. They fail at the joints - the places where intent meets identity, policy, and consequence.
The Boundary Thesis
From Conversation to Consequence
The most important shift in software in a decade is not that AI got smart. It is that AI started taking actions whose effects outlive the chat.
The Boundary Thesis
The Boundary Problem
Models are getting better fast. The thing that determines whether AI is useful at work is no longer the model - it's the boundary the model crosses to do anything that matters.
Browse by topic
Five theses we keep returning to. A year of posts becomes a body of thought.
The Boundary Thesis
The bottleneck isn't the model — it's the boundary it crosses to do anything real.
3 posts
Govern at the Choke Point
Governance must be a mandatory step every action passes through — a kernel, not middleware.
3 posts
Audit the Why, Not Just the What
When the requestor is an agent, "what happened" is only half the audit.
2 posts
Agents Speak Intent, Not Implementation
The agent never holds a credential, names a provider, or shapes a payload.
2 posts
AI Proposes, Rules Decide
AI can draft governance; the deterministic engine decides — versioned, reversible, optional.
3 posts
Field notes on the agentic enterprise.
No noise. A few times a month, when there's something worth saying.