althor
Writing

Essays on agent infrastructure

Working notes from shipping agent systems into regulated environments. Each piece is a pattern I've watched succeed or fail in production.

2026-04-21 · Pattern

Making agent deployments pass security review

A five-layer architecture distilled from shipping three agent systems in regulated environments — identity, credential broker, scoped tools, policy gating, audit. Skip a layer and the review fails.

2026-04-21 · Pattern

Drawing the right boundaries for an MCP server

An MCP server is a security boundary, not a convenience layer. Six rules that keep tool surfaces narrow enough to defend without making them too narrow to use.