I’m a security researcher, architect and engineer focused on AI and agent security, cloud security, runtime isolation and policy-governed automation. I write about the design problems that emerge when software systems begin acting on their own behalf.

This site is named after the problem I keep returning to: bounded autonomy—enabling systems to detect risk, reason about impact, and take action without becoming a new source of risk. That requires more than intelligent automation. It requires trustworthy identity and delegation, enforceable policy, constrained blast radius, verification and rollback, and complete auditability.

What you’ll find here

  • Identity and authorization patterns for multi-tenant AI platforms
  • Security architectures for agents, tools, and delegated actions
  • Policy as code with OPA and Rego, extending beyond Kubernetes admission control
  • Runtime isolation, containment, and intent-aware enforcement
  • Autonomous remediation designs that preserve meaningful human oversight

The work presented here is based on public technologies, original experiments, and first-principles analysis. I make the assumptions, limitations, and architectural tradeoffs explicit rather than hiding them behind a diagram.

Contact

Reach me at qwoxff@gmail.com.

The views expressed on this site are my own and do not represent those of any employer. Posts are based on public security concepts and published for educational purposes. Nothing here describes any employer’s internal systems, customers, roadmaps, incidents, or confidential information, and no post is written about, or in response to, any specific real-world event I have been involved in professionally.