Enterprise architect. 30 years building production integration and architecture across Oil & Gas, Energy/Utilities, and CPG since 1996.
I am defining Enterprise Agent Architecture: the fifth domain enterprise architecture needs for a workforce of humans and AI agents. TOGAF, Zachman, SABSA, and NIST model what the enterprise builds and runs. None model a non-human actor that holds delegated authority, acts autonomously, and composes tools it was never explicitly granted. That gap is the work.
Read the series: Enterprise Agent Architecture — the fifth domain, one part at a time. Also on Substack.
Public DOI-backed research · public standards submissions · Agent Security Harness v4.21.3: 623 executable IDs across 45 test-bearing modules — dated record
Evidence record: PubPoint Facts & Evidence
I do not just write about the agent workforce. I build the tools that prove how it fails and the research that measures it.
I study the gap between who an agent is and how it behaves — what I call the WHO vs. HOW problem. Identity and permissions don't prevent an authorized agent from being manipulated into unsafe decisions. My work formalizes this gap and provides empirical evidence.
Publication links use concept DOIs for the evolving record; named editions retain version DOIs.
| Record | Concept DOI | Evidence boundary |
|---|---|---|
| Deception Primitives at an MCP-Aware Enforcement Point: A Bounded Reference Design for Honeytoken, Decoy-Tool, and Breadcrumb Controls | 10.5281/zenodo.22859851 | Preprint; pinned v1.1, September 20, 2026. Reference design with reported library and bounded gateway behavior tests. Detection performance and operational effectiveness remain unvalidated; not production or independent validation. |
| From Approval to Execution: Assurance Boundaries in Three Agent Protocols | 10.5281/zenodo.22847474 | Preprint; pinned v1.1, September 19, 2026. Not peer-reviewed; no claim of independent validation, certification, adoption, or production effectiveness. |
| Decision Load Index (DLI) | 10.5281/zenodo.18207847 | First-party public research record; citable, not clinical validation or product-efficacy evidence. |
| Constitutional Self-Governance (CSG) | 10.5281/zenodo.19162103 | First-party public research record; the record and stated methods define claim scope. |
| Normalization of Deviance (NoD) | 10.5281/zenodo.19195515 | First-party public research record; citable, not independent validation. |
| Beyond Identity Governance | 10.5281/zenodo.19343033 | First-party public research record; citable, not independent validation. |
| Community-Driven Security | 10.5281/zenodo.19343107 | First-party public research record; citable, not independent validation. |
Standards engagement: public submissions are contributions, not adoption or acknowledgment by a receiving body. Dated evidence and boundaries: PubPoint Facts & Evidence.
The research above is implemented as an open-source adversarial evaluation framework. Release v4.21.3 has 623 unique executable IDs across 45 test-bearing modules. The dated record distinguishes that release inventory from current main and explains the verdict-producing versus informational-check split.
red-team-blue-team-agent-fabric · dated inventory and evidence limits
30 years building production integration systems across Oil & Gas, Energy/Utilities, and CPG since 1996.
- ORCID: 0009-0003-6736-1900
- X: @mikesaleme
- LinkedIn: mikesaleme
- PyPI: agent-security-harness




