Skip to content

Writing

Notes on operating AI on real infrastructure

Practical, vendor-neutral writing for the platform, DevOps and security teams who run the infrastructure AI agents touch — the access map, least-privilege drift, audit and self-hosted governance.

6 min read

v26.8.0: what shipped, what we refused to claim

The first public release: a self-hosted Go binary giving AI agents durable work, scoped access and signed evidence, with the gaps stated plainly.

  • release
  • self-hosted
  • ai-governance
  • go
  • open-core
Read article
11 min read

Audit evidence a verifier can check offline

How a hash-chained ledger with per-event Ed25519 signatures and OSCAL export produces audit evidence an external verifier can confirm independently.

  • audit
  • ledger
  • OSCAL
  • Ed25519
  • compliance
Read article
9 min read

Permitted vs observed: drift as a first-class finding

Drift between what an AI agent is permitted to do and what it is observed doing becomes a structured, classified finding with confidence levels.

  • least-privilege
  • drift
  • access-map
  • observability
Read article