Writing
Most of what I write these days goes out on the Cerbos blog, the OpenID Foundation blog or LinkedIn. The older posts further down are from this site, back when I had more time for smart home wiring.
Published elsewhere
- Why your audit trail breaks at the sub-agent boundary
- Multi-hop delegation for AI agents, and how the consent chain gets lost
- Delegated authorization: why acting on behalf of someone else is not a role
- MCP authorization standards: OAuth scopes, AuthZEN, and what's still missing
- Getting cozy with COAZ: securing APIs and AI agents with standardized authorization
Co-written with Atul Tulshibagwale. Introduces the COAZ framework and its MCP binding, which turn any protocol's request into an AuthZEN evaluation so every AI agent tool call can be authorized before it runs.
- The kill switch that never got pressed
What the OpenAI and Hugging Face incident says about agent authorization.
- AuthZEN at Identiverse 2026: authorization in the agent era
Authentication is largely solved. Authorization isn't, and no single spec fixes it. Shared Signals, AuthZEN and Transaction Tokens have to work together.
- Identiverse 2026: agents made authorization the story
- EIC 2026: stop counting agents, protect what they can touch
- IIW42 recap: where agent authorization got real
- Your AI coding agents need guardrails. Not the kind you think
- OpenID AuthZEN is official, and Cerbos is ready
The Authorization API 1.0 became a Final Specification in January 2026.
- Key takeaways from Workload Identity Day 0 at KubeCon
- Integrate Qubit with your continuous integration process
- Three top tips for effective customer segmentation
- How Qubit and Google Cloud helped Ubisoft create personalized customer experiences
On this site
The never-ending product requirements of user authorization
Having built access controls into 4 SaaS products, it always takes too long and doesn't scale.
ReadFinding the ideal light switch for a UK smart home
OHHH THE ZIGBEE! My quest to find the perfect wall switch for the UK Smart Home owner
ReadDatabase to client type safety with Typescript, TypeORM, type-graphql and Apollo
The nirvana of having type safety all the way from your database model through to the actual queries/mutation in the client application is now possible!
ReadThe shifting role of a Technical Product Managers
Going from an engineering track to a product one, specifically focuses on the technical aspects is commonplace, but can leave you feeling dissatisfied.
ReadStatic site hosting on GCP with HTTPS for (nearly) free with Cloudflare
Stop wasting money on Google Cloud Load Balancing for simple static website hosting by using GCS + Cloudflare for HTTPS
ReadDeploy your side-projects at scale for basically nothing - Google Cloud Run
Google Cloud Run is the perfect deployment system for all your side projects. It is dirt cheap, fully managed serverless and scalable.
ReadWhat the fog? Rise of the ‘intelligent edge’
‘Fog Computing’ is a new term for the up-coming form of computing which is meant to be the next evolution of cloud.
Read