About me
Product person, recovering engineer, and the co-founder who ended up owning authorization. Based in London.
Now
I’m co-founder and Chief Product Officer at Cerbos, which I started in 2021 with Emre Baran and Charith Ellawala. We were three people who kept rebuilding authorization at every company we worked at, so we decided to build it once, properly. I ran product as Product Lead from the first open-source release and became CPO in January 2024.
Cerbos is an authorization platform. The core is an open-source policy decision point (Apache 2.0) that answers “can this principal do this action on this resource?” wherever your code runs. Cerbos Hub manages policy across a whole fleet of those, and Synapse pulls in the identity and resource data each decision needs.
I’m also one of the co-chairs of the OpenID AuthZEN Working Group, which is standardizing how applications ask that question. I’m a contributor to the Authorization API 1.0, which became a final specification in January 2026. With Atul Tulshibagwale I co-author COAZ and its MCP binding, which map any protocol (AI agent tool calls included) onto an AuthZEN request. The reference implementation is mine too.
A lot of my time goes on AI agents at the moment. An agent can’t be pre-provisioned like an employee, so every tool call it makes needs its own authorization decision. I build the demos, write the specs and then go and talk about it.
How I got here
I started out as an engineer, at Microsoft as a development engineer and then as a JavaScript engineer at Qubit. At Qubit I moved into pre-sales engineering and then product management, and got to speak at Google Cloud NEXT a few times along the way. My favourite is still Fun with a Petabyte.
After that I did product at Zencargo, using data to fix global supply chains, and helped launch Manatee as interim CTO (and stuck around as an advisor).
Across eCommerce, marketing, supply chain, fitness and finance, every product I worked on hit the same wall. Roles were fine until sales needed a custom package for one big deal, GDPR meant access depended on where people sat, an enterprise customer wanted permissions that followed their org chart, and an auditor in a basement meeting room wanted proof of all of it. Each time it took months out of the roadmap. I wrote that up in 2021 as The never-ending product requirements of user authorization, and Cerbos is what came out the other end.
Before tech
- I grew up between the UK and the US, and hold dual British and Dutch nationality.
- From the age of 12 I ran The Remembrall, which became one of the world’s largest Harry Potter fan sites.
- I started podcasting in 2005 and live video streaming in 2010.
- I had a brief media career running It’s Kinda Cool, which meant interviewing people like David Attenborough, Gary Oldman and Emma Watson.
Outside work
I’m a proper avgeek (which may explain the departure board on the talks page). I’m building my own flight tracker to log every trip, airport and aircraft, and a conference held at the TWA Hotel at JFK is my idea of a good week.
At home there’s a Home Assistant setup, far too many Zigbee buttons and a growing pile of ESP32 boards. One of them is an e-paper sign that tells the rest of the house when I’m in a meeting.
Elsewhere
- LinkedIn is where I post most
- GitHub has the specs, demos and side projects
- X, occasionally
- Sessionize, for conference organisers