Five layers that separate real governance from compliance theater
Read with a highlighter. There are a lot of pages. Most of them earn their place.
When the precedent hasn’t been set yet, we get to write it
Read with a highlighter. There are a lot of pages. Most of them earn their place.
This is what governance as infrastructure looks like in practice.
A control plane is active — it governs what can be used, by whom, under what conditions, and with what audit trail.
That gap is "harness engineering," and it's where the real work of building production-grade agents happens
Agent observability is a distributed systems problem, and OpenTelemetry is the backbone
That works for focused problems, not agents
Coffee without principle. A Lisbon lesson for AI.
Your existing security architecture assumes humans review and approve decisions. Agentic systems break this pattern.