Advisory engagements, from the person who built it
AI Identity is a working platform, not a slide deck — and the thinking behind it is available as advisory work. If your team is putting AI agents into production and the questions are starting to sound like who did what, under whose authority, and can we prove it — that's the work I do every day.
Where I Can Help
Agent identity & governance architecture
You have agents acting on shared credentials, service accounts, or someone's OAuth token. I help you design the identity layer they actually need: per-agent identity, scoped delegation, policy enforcement at the point of action, and key management that survives an audit question.
Audit evidence that stands up afterward
Logs answer “what happened” only until someone asks “can you prove it?” I design tamper-evident evidence: cryptographically signed audit records, hash-chained histories, and verification that works independently of the system that produced the records — even offline.
OCSF adoption & standards alignment
I contribute to OCSF directly — my agent-attestation work shipped in the OCSF 1.9.0 release. If you're mapping AI or agent telemetry to OCSF, deciding what belongs upstream versus in an extension, or want your logging to interoperate with the broader security ecosystem, I can shorten that road considerably.
How Engagements Work
Short and focused. A typical engagement starts with an assessment — your agents, credentials, logs, and obligations as they exist today — and ends with an architecture you can build, a prioritized roadmap, and working reference examples where they help. Hands-on implementation support is available where it makes sense. No long retainers pitched by default; the goal is that you stop needing me.
Why Me — the Receipts
The credibility here was built in public — in standards bodies, open-source documentation, and a production platform — not in a pitch deck.
OCSF 1.9.0. Contributions shipped in the OCSF 1.9.0 release — agent attestation is now part of the open cybersecurity standard, with follow-on proposals queued for the next release.
IBM & CoSAI. Working with engineers at IBM on OCSF-based audit logging for open-source AI gateway tooling; active contributor in CoSAI (OASIS) on agentic identity and trust.
LangChain. Listed in LangChain's official documentation as an integration for agent identity and audit.
12+ years in production. Operating systems where failure is expensive — cloud banking infrastructure supporting $50B+ in client assets, executive escalations at Sprint and Google.
AI Identity itself. A production platform for agent identity, policy, and tamper-evident evidence — built, operated, and dogfooded by me.
Who you'd be working with: founder profile (PDF) · about AI Identity
Start a conversation
Email jeff@ai-identity.co with two or three sentences about your situation — what your agents do, and the question you can't currently answer. I'll reply with an honest read on whether I can help, and what I'd look at first.
Email Jeff