Publications
Research that has to hold up.
Selected work across enterprise architecture, runtime governance, and executable evaluation.
Preprint · September 20, 2026
Deception Primitives at an MCP-Aware Enforcement Point: A Bounded Reference Design for Honeytoken, Decoy-Tool, and Breadcrumb Controls
Reference design with reported library and bounded gateway behavior tests. Detection performance and operational effectiveness remain unvalidated; not production or independent validation.
Preprint · Reviewed edition v1.1 · September 19, 2026
From Approval to Execution: Assurance Boundaries in Three Agent Protocols
A comparison of what approval records establish across three agent protocols. Not peer-reviewed or independently validated.
Research brief · Agent evaluation
Two Controls, Not One
Why credential exposure and operation restriction are independent properties of an environment that exercises a model.
Research brief · Enterprise Agent Architecture
Context Is Part of an Agent's Authority
Why the information an enterprise agent receives is an authority control, not merely a prompt-engineering choice.
Research note · Experimental evidence
Before the Benchmark: Make the Claimed Win Reviewable
Why an experimental win needs a contract and retained evidence before it needs a chart.
Research brief · Runtime governance
Authorized Actions, Unauthorized Outcomes
Why individually authorized agent actions can compose into an outcome the enterprise did not permit.
Open-source evaluation artifact · v0.1.0
MCP Sandbox Authority Boundary Profile
A synthetic-only profile for characterizing whether MCP-connected sandboxes preserve declared authority boundaries.
Position paper · DOI
Enterprise Agent Architecture
The case for treating autonomous agents as a fifth enterprise-architecture domain.
Empirical study · DOI
Authorized but Refused
Runtime governance evidence from an autonomous enterprise.
Research guide · DOI archive
Research Map
A reading path through the connected research record, with direct links to the primary DOI sources.
Open source · executable tests
Agent Security Harness
Testing for agent security, protocols, payments, and decision governance.
Essay series · ongoing
Enterprise Agent Architecture series
The position paper developed in the open, with field notes applying it to specific frameworks, standards, and incidents.