Decision rights, then the graph.

I'd own the seams and the org that has to live with them. Architecture without written decision rights dies in the second quarter.

I own — Control-plane seams

Where orchestration stops, where the gateway starts, how RAG fails closed, which evals can fail a release. I write the invariant. Teams implement inside it.

I own — Irreversible writes

If a tool can publish, pay, push, or mutate a system of record, it goes through the gateway. HITL stays on until a named owner takes the risk in writing.

Teams own — Product wedges inside the invariant

Once the deny-path and eval gate exist, squads ship without me in the review. If every graph still routes through me at day 90, I failed the seat.

Teams own — Model choice on a metered path

Buy vs RAG vs PEFT vs self-host is a receipt, not a brand. I set the decision framework. The team that owns the path picks — and shows the meter.

What I will not let the org automate.

Governance bolted into the agent graph

The graph gets a back door the first time someone is late. Orchestration and policy stay separate layers.

Rank-then-filter RAG

Demos that skip access-before-ranking look smart and leak. Filter by who the caller is, then score.

Autonomous side effects

Publish, pay, push, deploy — gateway or HITL. Fail-closed in prod. I will not automate the write that embarrasses us on the front page.

Demo-day without an eval owner

If a fixture cannot fail the build, it is a launch, not a platform. Soft multi-tenancy is the same refusal.

Listen, then three written outcomes.

Days 1–14 I map decision rights, where retrieval sits relative to authorization, and the irreversible action the org already fears. IAM owner, noisiest agent path, one skeptic, one business partner.

Outcomes

  • One deny-path a stranger can replay (tenant or authZ-before-retrieve) with a negative test in CI
  • Gateway / HITL on one irreversible tool that used to be autonomous
  • One eval gate that can fail a build — and at least one other team reusing the pattern

Non-goals

  • No org-wide multi-agent rewrite in Q1
  • No provider swap in the first 60 days unless risk demands it
  • No new public product brand from this seat

A skeptic can verify a standard another team reused — not a prettier chatbot, and not me as the permanent approval bottleneck.

If I leave, the platform still denies the bad write, the eval still fails the build, and a named owner can resume HITL. A Principal who cannot be replaced was a bottleneck, not an architect.

Employer programs. Not public-repo receipts. Full ledger on /proof.

I publish the decisions I would defend in a panel — not launch spam. Shared vocabulary before a program scales.