Author
Jonathan Haas
Founder · 20 posts
Founded ThreatKey (acquired). Worked at Carta and Snap. Background in security, infrastructure, and developer tooling.
- NIST AI RMF and ISO/IEC 42001 for the agent runtimeAudit & compliance · 5 min
- Keeping a software factory aliveEngineering · 5 min
- Controls that hold when the agent stops agreeingApprovals & policy · 4 min
- Agent spend, before the invoiceCost · 3 min
- Discovery lag: how long before you find out what your agents did?Operations · 5 min
- We rewrote the kernel in Rust — with agents writing most of the PRsEngineering · 3 min
- What Rust gives this control plane that Go did notEngineering · 4 min
- An operating model the runtime can enforceOperations · 3 min
- What an agent audit row should carryAudit & compliance · 9 min
- Why service-account permissions don't fit agentsIdentity & access · 8 min
- Five things that keep breaking when AI agents move into productionOperations · 8 min
- Policy at action time: what the gate evaluatesApprovals & policy · 10 min
- Sub-agent identity: inherit and narrowIdentity & access · 8 min
- The lethal trifecta: where it actually livesIdentity & access · 7 min
- Stopping a running agentOperations · 8 min
- Introducing DeixicCompany · 1 min
- What the EU AI Act means for the agent runtime: an Article-by-article readAudit & compliance · 9 min
- Designing approvals operators actually readApprovals & policy · 9 min
- Finding the agents nobody deployedOperations · 8 min
- Replay: reconstructing an agent action from the audit logAudit & compliance · 9 min