Skip to main content
Advisory

Advisory engagements, from the person who built it

AI Identity is a working platform, not a slide deck — and the thinking behind it is available as advisory work. Here's the direct version: anyone can emit an audit record. What's hard is evidence that holds up under scrutiny — tamper-evident chaining, signed attestations, forensic replay, retention that survives a regulator's questions. I wrote the standard your auditors will measure you against, and I help you build systems that pass it. I help you build it right; an independent auditor verifies it.

Where I Can Help

01 / IDENTITY

Agent identity & governance architecture

You have agents acting on shared credentials, service accounts, or someone's OAuth token. I help you design the identity layer they actually need: per-agent identity, scoped delegation, policy enforcement at the point of action, and key management that survives an audit question.

02 / EVIDENCE

Audit evidence that stands up afterward

Logs answer “what happened” only until someone asks “can you prove it?” I design tamper-evident evidence: cryptographically signed audit records, hash-chained histories, and verification that works independently of the system that produced the records — even offline.

03 / STANDARDS

OCSF adoption & standards alignment

I contribute to OCSF directly — my agent-attestation work shipped in the OCSF 1.9.0 release. If you're mapping AI or agent telemetry to OCSF, deciding what belongs upstream versus in an extension, or want your logging to interoperate with the broader security ecosystem, I can shorten that road considerably.

How I Work

Short and focused. A typical engagement starts with an assessment — your agents, credentials, logs, and obligations as they exist today — and ends with an architecture you can build, a prioritized roadmap, and working reference examples where they help. Hands-on implementation support is available where it makes sense. No long retainers pitched by default; the goal is that you stop needing me.

  • Make the problem legible. Map the agents, credentials, decisions, logs, and obligations so the team can see what is actually happening.

  • Build the proof. Working examples, reference architectures, and verifiable evidence instead of hand-wavy recommendations.

  • Separate verified from assumed. Claims arrive with receipts, and uncertainty stays visible.

  • Convert insight into structure. Good ideas become decisions, checkpoints, policies, and reusable tools.

What to expect: receipts over hype, steady follow-through, and directness about what's working, what isn't, and what I'd do next.

Why Me — the Receipts

The credibility here was built in public — in standards bodies, open-source documentation, and a production platform — not in a pitch deck.

OCSF 1.9.0. Contributions shipped in the OCSF 1.9.0 release — agent attestation is now part of the open cybersecurity standard, with follow-on proposals queued for the next release.

IBM & CoSAI. Working with engineers at IBM on OCSF-based audit logging for open-source AI gateway tooling; active contributor in CoSAI (OASIS) on agentic identity and trust.

LangChain. Listed in LangChain's official documentation as an integration for agent identity and audit.

12+ years in production. Operating systems where failure is expensive — cloud banking infrastructure supporting $50B+ in client assets, executive escalations at Sprint and Google.

AI Identity itself. A production platform for agent identity, policy, and tamper-evident evidence — built, operated, and dogfooded by me.

Who you'd be working with: founder profile (PDF) · about AI Identity

Start a conversation

Tell us about your situation — what your agents do, and the question you can't currently answer — and we'll reply with an honest read on whether we can help, and what we'd look at first. All advisory engagements are paid services.

Request services

Existing client? jeff@ai-identity.co