01
Authorization & Data Governance
Who can do what, where, and why — answered well.
My home turf. I help teams design authorization that capture the whole story and hold up in regulated environments. Technical enforcemennt of personnel or device-attribute-based access control, resource-aware policies, business justification validation, tamper-proof audit, and human-and-agent approval flows. Drawn from a decade of running access systems at Google scale.
Typical outcomes
- —AuthZ architecture that minimizes friction and survives audits
- —Policy-as-code with strict SLOs and reliable continuous iteration of policy
- —Immutable audit trails that actually answer questions
- —A path for agents, not just humans, to use safely