MCP Grew Up by Giving Things Away

Across five revisions the Model Context Protocol has steadily reduced the set of responsibilities it claims for itself, transferring authentication to the identity provider, client identity to the domain name system, consent to the administrator, and session state and routing to the application and the gateway. What the reduction leaves behind is a single trust boundary for which no better owner exists, and the attacks that have succeeded in practice are concentrated there.

August 24, 2026 · 23 min · MdJawad

The Policy Engine Is the Ceiling: Authorization for Agents That Do Things

An agent can be trusted with exactly as much authority as your policy engine can scope, enforce, and afterwards prove. Which makes authorization not the tax you pay to ship agents, but the thing that decides how much power they can ever be given. A deep dive into PDP/PEP architecture, Cedar and Rego, partial evaluation, workload identity, and why the credential an agent presents should be minted for the action rather than held for the deployment.

July 20, 2026 · 39 min · MdJawad

The Platform Around the Agent: What Enterprise Architects Actually Build

Most enterprises have bought an AI coding agent and are stuck. The ones generating real productivity gains didn’t win by picking a better model. They built a platform around the agent. This post walks through the five control-plane responsibilities that separate the 11% of AI-native orgs from the 95% reporting zero ROI, grounded in public deployments from Block, Shopify, Atlassian, Airbnb, and others.

April 15, 2026 · 24 min · MdJawad