Dallas, Texas Security architecture

Organizations are adopting AI faster than they are governing it. I write about what it takes to close that gap: who can reach a model, what data goes into it, and how anyone knows afterward what it did.

I've worked in enterprise security for about twenty years, mostly on Zero Trust and identity, across operations that run on both sides of the US–Mexico border. This is where I think out loud about how that work changes when the thing asking for access isn't a person. More about me.

Recent writing

Zero Trust for AI agents: who is the agent acting as?

AI agents now call APIs, read files, and take actions. The identity question underneath that is one we already know how to answer.