The Policy Engine Is the Ceiling: Authorization for Agents That Do Things

An agent can be trusted with exactly as much authority as your policy engine can scope, enforce, and afterwards prove. Which makes authorization not the tax you pay to ship agents, but the thing that decides how much power they can ever be given. A deep dive into PDP/PEP architecture, Cedar and Rego, partial evaluation, workload identity, and why the credential an agent presents should be minted for the action rather than held for the deployment.

July 20, 2026 · 39 min · MdJawad
Teaching Hermes to Tutor Tamil — architecture poster showing the dedicated AWS account, the hint ladder over Telegram, and the curriculum-as-code pipeline

Guide, Never Solve: Teaching Hermes to Tutor Tamil

My son was using chatbots to finish his homework instead of learning from it. So I built him a tutor on a network-caged agent platform: one that guides instead of answers, reads his Tamil worksheets, runs scheduled drills, and is safe by architecture rather than by prompt.

June 10, 2026 · 24 min · MdJawad