Publications

Research that has to hold up.

Selected work across enterprise architecture, runtime governance, and executable evaluation.

Preprint · September 20, 2026

Deception Primitives at an MCP-Aware Enforcement Point: A Bounded Reference Design for Honeytoken, Decoy-Tool, and Breadcrumb Controls

Reference design with reported library and bounded gateway behavior tests. Detection performance and operational effectiveness remain unvalidated; not production or independent validation.

Preprint · Reviewed edition v1.1 · September 19, 2026

From Approval to Execution: Assurance Boundaries in Three Agent Protocols

A comparison of what approval records establish across three agent protocols. Not peer-reviewed or independently validated.

Research brief · Agent evaluation

Two Controls, Not One

Why credential exposure and operation restriction are independent properties of an environment that exercises a model.

Research brief · Enterprise Agent Architecture

Context Is Part of an Agent's Authority

Why the information an enterprise agent receives is an authority control, not merely a prompt-engineering choice.

Research note · Experimental evidence

Before the Benchmark: Make the Claimed Win Reviewable

Why an experimental win needs a contract and retained evidence before it needs a chart.

Research brief · Runtime governance

Authorized Actions, Unauthorized Outcomes

Why individually authorized agent actions can compose into an outcome the enterprise did not permit.

Open-source evaluation artifact · v0.1.0

MCP Sandbox Authority Boundary Profile

A synthetic-only profile for characterizing whether MCP-connected sandboxes preserve declared authority boundaries.

Position paper · DOI

Enterprise Agent Architecture

The case for treating autonomous agents as a fifth enterprise-architecture domain.

Empirical study · DOI

Authorized but Refused

Runtime governance evidence from an autonomous enterprise.

Research guide · DOI archive

Research Map

A reading path through the connected research record, with direct links to the primary DOI sources.

Open source · executable tests

Agent Security Harness

Testing for agent security, protocols, payments, and decision governance.

Essay series · ongoing

Enterprise Agent Architecture series

The position paper developed in the open, with field notes applying it to specific frameworks, standards, and incidents.