Intelligence Hub
Engineering publication
Research, architecture, engineering notes, governance patterns, and industry benchmarks — written for practitioners.
A Unified Vulnerability Management Program — Discover, Detect, Prioritize, Remediate
48K+ CVEs a year, 5–8 disconnected scanners, and under 25% of findings routed to an owner. One program that unifies discovery, scoring, and remediation across the whole stack — including OT and fielded devices.
Risk-Based Vulnerability Scoring and Remediation SLAs
Severity alone is misleading. A composite score from CVSS, EPSS, exploit signals, asset criticality, and compensating controls drives the tier, the notification path, and an SLA calibrated by exposure.
Patching Vulnerabilities on the Factory Floor and in Medical Devices
The standard patch lifecycle, and why it's hardest in medical-device manufacturing — validated OT you can't reboot, FDA-regulated devices where a patch requires re-validation, and how compensating controls make a missed 24h patch a defensible decision.
Beyond Vulnerability — a Unified Control Framework and AI Across the Lifecycle
One asset graph, one ownership map, one risk register, one set of dashboards — extending from vulnerabilities to InfoSec, BC/DR, access, change, and HIPAA/SOC 2/PCI audit evidence, accelerated by an AI engine with human-in-the-loop.
MCP & AI Agent Governance Marketplace for the Agentic Enterprise
MCPs and agents are multiplying faster than any governance process can see them. The answer is an internal app store + registry + governance workflow for the agentic layer — the AI-era sibling of the Data Marketplace.
Governing MCPs and Agents — Metadata, Lifecycle, and Risk-Tiered Approval
A common metadata model, one registration-to-retirement state machine, a risk score computed from sensitivity × autonomy × action × reach, and approval paths that scale review depth to risk.
The Business Journey Catalog — Organizing Agents Around How Work Actually Happens
Cataloging MCPs and agents by end-to-end business journey — so people find capabilities in the language of their work, gaps become a build/buy pipeline, and every stage is governed to its risk.
Building Data Products — Principles, Anatomy, and Best Practices
Data-as-a-product means discoverable, addressable, trustworthy, self-describing, interoperable, and secure by default. What a data product actually contains, and how to build one that lasts.
The Data Marketplace — Producer, Consumer, and the Path from Discovery to Access
A governed front door where producers publish once and consumers discover, request, and consume zero-copy. The operating model, the responsibilities on each side, and what good looks like.
Data Contracts — The Enforceable Interface Between Producer and Consumer
Schema, semantics, quality guarantees, and SLAs written as versioned, CI-enforced code — so a producer can evolve safely and a consumer can depend without fear. With a worked contract example.
Pricing Data Products — Costing, Chargeback, and FinOps for Data
How to cost a data product, meter its consumption, and choose a chargeback or value-based pricing model — so a data marketplace has real economics, not just a catalog.
What a Customer 360 Is — and Why It Changes the Economics of Banking
A single, holistic, readable view of one customer's entire journey — spanning the customer, operational, and regulatory layers — and the challenges it removes.
Building a Customer 360 — Strategy, MDM Foundation, and Data Model
Match & merge on an MDM foundation, event-driven real-time integration, a logical semantic data model across six subject areas, then AI on top — the sequence that delivers one view of the customer.
Customer 360 Analytics — From Dashboard to Journey and Attrition Risk
The single-pane customer dashboard, channel-activity drilldowns, and journey analytics that surface high-attrition-risk customers in time to act.
Customer 360 — Build vs Buy
Buying is faster to start but locks you into a vendor's model and a data migration; building on open frameworks and predefined 360 accelerators keeps control without the slow custom start.
Modern Master Data Management — Domain-Driven, Federated, and AI-Forward
MDM is the discipline of producing one trusted golden record for core entities. Why the modern approach is domain-driven and federated, not centralized and rigid.
An Incremental MDM Build — Foundational, Enhanced, Integrated
Big-bang MDM stalls. A concentric capability model and a Day 0 → Foundational → Enhanced → Integrated roadmap deliver a golden record in months and value along the way.
Gen AI for Master Data Management and Stewardship
Entity resolution, augmented classification, and data-quality repair turn stewardship from manual scratch work into review-and-approve — with a confidence gate and a human on the hook.
MDM in Banking — Customer 360, KYC/AML, and Regulatory Reporting
How financial institutions use master data for a unified customer view, consistent counterparty data for compliance, and a source of truth for regulatory reporting — plus an MDM maturity model to benchmark against.
Harness Engineering — Why the Runtime, Not the Model, Ships Your Agent
A capable model alone is a demo. The harness — agent loop, tool orchestration, memory, guardrails, and tracing — is what turns raw capability into a production-grade agent.
The Anatomy of an Enterprise Agent Harness
Five layers wrap the model between a user request and your systems of record — interface, orchestration, context, tools, and guardrails — with identity, secrets, and audit cutting across all of them.
Harness Guardrails for Regulated Agents
Least-privilege access, dual-approval on money movement, PHI minimization, and reproducible decisions — enforced in the runtime, not hoped for in the prompt.
The Five Dimensions of AI Data Readiness
Context, Clarity, Coverage, Credibility, Capacity — and why the lowest-scoring dimension is the binding constraint that caps every AI outcome.
Building an AI Data Readiness Scorecard
A repeatable five-step assessment that produces a composite readiness score, a banking KPI matrix with hard thresholds, and a remediation backlog.
A Federated Semantic Layer — Govern Data in Place, Without the Centralization Tax
Reference architecture for querying Oracle, SQL Server, Databricks, and real-time streams in place — bound by FIBO, Unity Catalog, and an MCP serving layer.
Semantic Layer, Ontology, Knowledge Graph — What They Are and When to Use Each
From metric translator to formal domain meaning to an operational knowledge graph: the maturity flow, the tooling, and realistic implementation timelines.
FIBO and In-Place Semantic Mapping for Banking
Why FIBO is the finance-native knowledge backbone, and how an agentic mapping pipeline aligns physical columns to ontology classes at scale.
Human-in-the-Loop Governance for Production AI
Automated decision → confidence gate → SME curation → feedback loop: turning expert review into an SLA with error budgets and named owners.
Compliance-in-Motion — Enforcing Consent, PII, and Do-Not-Train in the Pipeline
GDPR, GLBA, NY DFS, OCC, BCBS 239, and NIST AI RMF, enforced at the point of access rather than audited after the fact.