Building high-assurance infrastructure around foundation models: deterministic policy boundaries, Model Context Protocol (MCP) gateways, mathematical multi-tenant data isolation, and verified execution.
Architecture Focus · Proof-Backed Systems · Production Invariants · Architecture Matrix · Technical Writing · Platform Topology · Sovereign AI Lab · Engineering Stack · About & Track Record
ENTERPRISE AI ARCHITECTURE · MODEL CONTEXT PROTOCOL (MCP) · POSTGRESQL RLS · AGENT EVALS · AMD EPYC & NPU · FINOPS · FORMAL VERIFICATION
AI demos are easy. Production enterprise systems must survive retries, partial failures, hostile inputs, prompt injections, runaway inference spend, model drift, and regulatory scrutiny under strict enterprise boundaries.
I design and build the infrastructure outside and around the model: observable workflows, explicit policy boundaries, capability-gated tool execution, replayable evidence, and mathematically isolated multi-tenant data fabrics.
Intelligence can be probabilistic. Infrastructure cannot.
| Observe | Control | Prove |
|---|---|---|
| Capture model, tool, cost, and transaction events with sub-millisecond telemetry. | Route workloads, enforce capability policies, isolate risk, and recover safely. | Replay decisions, verify state invariants, reconcile transactions, and export audit evidence. |
[Untrusted Input / Event]
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ Ingress & FinOps Guardrails (TokenGoblin) │
│ • Daily tenant budget quota check ($50 hard cap) │
│ • Sub-millisecond token telemetry & latency tracking │
└──────────────────────────────┬──────────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────────┐
│ Unprivileged Model Planner (gpt-4o / o3-mini / vLLM) │
│ • Zero execution privileges inside the context window │
│ • Emits typed, candidate tool intent via Model Context Protocol │
└──────────────────────────────┬──────────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────────┐
│ MCP Policy Firewall & Authorization Gateway │
│ ├── READ Operation: Auto-approved under tenant scope │
│ ├── WRITE Operation: Scoped execution + immutable audit log │
│ └── DESTRUCTIVE Operation: HALTED for Cryptographic HITL Token │
└──────────────────────────────┬──────────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────────┐
│ Relational Kernel & Settlement (Settler & PostgreSQL RLS) │
│ • Mathematical cross-tenant isolation (zero leakage) │
│ • Merkle evidence packet generated for replayable audit log │
└─────────────────────────────────────────────────────────────────┘
- Enterprise Applied AI Architecture: Guiding institutional and enterprise stakeholders through secure agent topologies, governance boundaries, legacy data integrations, and scalable production deployment.
- Distributed Agent Infrastructure & MCP: Engineering resilient agent control planes, sandboxed Model Context Protocol (MCP) gateways, policy proxies, and deterministic model failover cascades.
- Data Boundary & Multi-Tenant Security: Enforcing mathematical cross-tenant isolation directly in database kernels (PostgreSQL RLS) with automated negative penetration test batteries.
- Inference FinOps & Execution Observability: Architecting high-throughput Go ingestion pipelines, real-time token spend quotas, latency/cost routing trade-offs, and continuous evaluation suites.
| Dimension | Architectural Standard | Verifiable System Proof |
|---|---|---|
| Tenant Isolation | Kernel-enforced PostgreSQL Row-Level Security (RLS) | Settler automated cross-tenant penetration test suites |
| Spend Governance | Sub-millisecond Go ingestion with hard token quotas | TokenGoblin ingestion benchmarks & budget cutoff tests |
| Execution Trust | Formally verified state machines and DAG ordering | veridag Quint temporal logic models & conformance specs |
| Tool Authorization | LLM as unprivileged planner; cryptographic approval tokens | ReadyLayer CI security gates & policy contracts |
| Audit Provenance | Tamper-evident transaction settlement & replayable proofs | truthcore & Settler audit chains |
| Hardware-Informed | Dedicated 5-tier on-premise EPYC, NPU & GPU compute cluster | model-tools & Sovereign AI Lab routing testbeds |
| If you are… | Start here | What you get |
|---|---|---|
| Reviewing engineering architecture & code | Inspect the public evidence | 4 canonical open-source systems with benchmarks, test suites, and conservative maturity labels. |
| Exploring production AI capabilities | Inspect the Architecture Matrix | Cross-system mapping of MCP gateways, Postgres RLS multi-tenancy, formal Quint verification, and CI quality gates. |
| An enterprise or engineering leader | Book a free 30-minute diagnostic | A constraint map, failure-mode assessment, and concrete next steps for brittle AI workflows. |
| Evaluating private or local AI | Run the free AI lab audit | A fast readiness signal before spending on infrastructure or local hardware. |
Field-tested engineering implementations across core production AI competencies, mapped to public repositories, verified test suites, and technical guides:
| Competency Domain | Production Implementation Pattern | Evidence & Repositories |
|---|---|---|
| Agent Control Planes & MCP Gateways | Treating the LLM as an unprivileged planner; implementing policy-gated Model Context Protocol (MCP) reverse proxies with dynamic tool discovery, input sanitization, and cryptographic single-use approval tokens for destructive side effects. | ReadyLayer agent-infra Tool Authorization Guide |
| Multi-Tenant Security & Relational Isolation | Enforcing mathematical tenant isolation directly in PostgreSQL Row-Level Security (RLS) policies rather than fragile application-level WHERE filters; verified with automated negative penetration test suites. | Settler Tenant Isolation Guide Settler Benchmarks |
| Inference FinOps & Spend Governance | High-throughput Go ingestion pipelines measuring cost, usage, latency, and tenant token quotas; automated circuit breakers halting runaway agent loops; budget-governed model cascades (gpt-4o → gpt-4o-mini → local fallback). |
TokenGoblin Ingestion Benchmarks TokenGoblin Spec |
| Formal Verification & Protocol Design | Specifying distributed execution semantics and capability security using Quint temporal logic formal models, state invariant checks, and cross-language conformance test vectors. | veridag Quint Formal Models Protocol Architecture |
| Local-First & Hybrid Model Routing | Tiered inference pipelines utilizing owned AMD EPYC host compute and Ryzen AI 9 NPU/GPU workers for low-latency classification, tool selection, and embeddings at zero marginal API cost, cascading to frontier cloud LLMs only when needed. | model-tools autopilot Sovereign AI Lab |
| Continuous Evals & CI/CD Delivery | Automated evaluation batteries scoring tool selection accuracy, argument schemas, prompt injection refusals, and structured outputs; gating PR merges on deterministic quality thresholds. | ReadyLayer Production Agent Guide Quality Gates CI |
| Cryptographic Provenance & Audit Chains | Immutable Merkle evidence chains and offline-verifiable proofpacks recording all agent tool executions, financial transactions, and state changes for regulatory compliance and audit replay. | Settler truthcore veridag |
| Full-Stack SaaS & Enterprise Integrations | Modern SaaS delivery with Next.js 16 App Router, Supabase RLS, Prisma, Stripe billing, Kafka messaging, Keycloak OIDC, and enterprise LMS/SIS protocol connectors (LTI, OneRoster). | ReadyLayer Settler Enterprise Architecture Record |
These are the four clearest public examples of the approach. The table is generated from a versioned manifest, checked against GitHub every week, and deliberately separates released, beta, and research work.
Public project metadata last verified 2026-10-01 · source manifest · verification policy
| Project | Problem | Public evidence |
|---|---|---|
| TokenGoblin · Go Measure · beta |
LLM workloads need cost, usage, and routing data before teams can control inference spend. | Public ingestion benchmarks, cost and routing tests, and a repository-level CI workflow. Architecture · Evidence |
| ReadyLayer · TypeScript Govern · beta |
AI-assisted delivery needs policy, review, and evidence before generated changes reach production. | Public policy contracts, evidence export documentation, test suites, and CI quality gates. Architecture · Evidence |
| veridag · Rust Prove · research |
Distributed execution needs explicit ordering, capability security, and cross-language conformance. | A public protocol specification, Quint formal models, test vectors, and dedicated conformance workflows. Architecture · Evidence |
| Settler · TypeScript Reconcile · beta |
Payment, banking, and operational records diverge unless matching and evidence rules are explicit. | Public reconciliation benchmark source and checked-in snapshots, with CI and security-invariant workflows. Architecture · Evidence |
Field-tested engineering guides grounded in verified production code and open-source infrastructure:
- Building Safe Multi-Tenant AI Agents with Postgres RLS
POSTGRESQL RLS·NEGATIVE PENETRATION TESTING·KERNEL-ENFORCED MULTI-TENANCY
Why application-level filtering fails in autonomous agent workflows, and how to enforce mathematical tenant boundaries via PostgreSQL Row-Level Security with automated negative penetration tests. - Enterprise Tool Calling: Why Authorization Belongs Outside the Model
MODEL CONTEXT PROTOCOL (MCP)·CRYPTOGRAPHIC HITL TOKENS·UNPRIVILEGED PLANNERS
Treating the LLM as an unprivileged planner; implementing policy-gated MCP reverse proxies with single-use cryptographic approval tokens for privileged side effects. - From Prototype to Production: Architecture for Enterprise AI Agents
THE SIX PRODUCTION PILLARS·CONTINUOUS CI EVALS·OPENTELEMETRY TRACING
The six production pillars: model abstraction, tool execution boundaries, continuous CI/CD evaluations, OpenTelemetry observability, and token spend governance. - Hardonia Architecture Playbook
SYSTEM TOPOLOGY·OPERATING LOOPS·CAPABILITY BOUNDARIES
Public architecture notes on bounded context separation, data ownership, cutover controls, and provider-correlated evidence verification.
| Engagement | Best when | Outcome |
|---|---|---|
| AI clarity audit | The opportunity is real, but the workflow and risk boundaries are not yet clear. | A decision-ready map of constraints, ownership, ROI assumptions, and the smallest safe pilot. |
| Stabilization sprint | An AI workflow is live but flaky, opaque, or expensive. | Explicit contracts, retries, telemetry, fallbacks, acceptance tests, and an operator runbook. |
| Governance architecture | Agents or models can take consequential actions. | Approval boundaries, policy gates, audit trails, incident paths, and evidence you can inspect. |
| Local AI systems | Data control, predictable cost, or offline capability matters. | Model and hardware fit, routing, deployment, observability, and a practical operating plan. |
Every engagement starts with the workflow—not a predetermined model or platform. See the service details, case studies, or book a diagnostic.
Detailed capability mappings and operational boundaries are documented in the Architecture Playbook.
Seven monorepos keep related systems coherent while preserving clear boundaries:
| Boundary | Public monorepos | Responsibility |
|---|---|---|
| Observe + control | agent-edge · agent-infra | Agent traffic, policy, governance, mission state, and MCP boundaries. |
| Model + execute | model-tools · autopilot | Inference routing, GPU fit, and runnerless ops, support, growth, and FinOps workflows. |
| Integrate + operate | api-tools · ops-tools | APIs, webhooks, continuity, drift inspection, and golden paths. |
| Consumer outcomes | consumer-tools | Warranty, review intelligence, and inbox automation. |
Open the component map
signal policy execution
agent-edge ──────────────► agent-infra ──────────────► autopilot
packet capture control plane ops / finops
mesh edge agent mesh growth / support
MCP firewall
│ │ │
└──────────────────── model-tools ◄───────────────────┘
inference / routing
│
local GPU testbed
│
evidence / reconciliation
Each public monorepo includes an ARCHITECTURE.md describing its boundary and migration history.
Hardonia includes an owned, local testbed for model routing, image and video workflows, and failure-mode testing. It is where local-first claims are exercised before they become architecture advice.
| Lane | Hardware | Primary use |
|---|---|---|
| Enterprise Server Host & Virtualization | AMD EPYC · High PCIe lane density · DDR4/DDR5 ECC RAM | Multi-GPU virtualization, heavy Ollama/vLLM endpoints, vector database indexing, container cluster networking. |
| Edge Orchestration & NPU | AMD Ryzen AI 9 HX370 · 50 NPU TOPS · 32 GB | Local agent orchestration, low-latency reasoning, and local eval suites. |
| Heavy Inference | NVIDIA V100 · 16 GB HBM2 | Larger model and video-generation workloads. |
| Memory-Oriented | NVIDIA P40 · 24 GB | ComfyUI pipelines, quantized models, and training experiments. |
| Interactive & Vision | NVIDIA RTX 3060 · 12 GB | Vision, embeddings, and latency-sensitive workflows. |
The lab uses Ollama-compatible routing, ComfyUI, containerized services, and Prometheus/Grafana-style observability. Public implementation lives primarily in model-tools and api-tools.
Decision-layer experiment: where Jev fits
TypeSafe Jev is being evaluated for low-cost typed classification where a general-purpose LLM is unnecessary—for example intent classification, routing, and tool-selection gates. It complements deterministic policy; it does not replace it. TypeSafe currently lists input pricing at $42 per billion tokens.
Trust, execution, and agent systems
- Requiem — unified AI control plane and execution contracts.
- Nautilus — local AI execution, orchestration, and policy enforcement.
- Keys — auditable mission control for constrained agents.
- truthcore — verification kernel and offline evidence reports.
- Zeo — governance, policy enforcement, and deterministic audit trails.
- agent-governance — enforceable agent laws and a governance gateway.
Applied systems and simulation
- SawyerCore — deterministic edge-AI runtime and agent simulation.
- WorldForge — deterministic, moddable simulation runtime.
- World26 — open planetary-systems simulator.
- FlexibleAccessible — accessibility auditing and remediation workflows.
- MortgageMatchPro — mortgage scenario and matching platform.
Productized audits, kits, and workflows
| Starting point | Intended outcome |
|---|---|
| SaaS repo rescue | Find auth, billing, webhook, RLS, and reliability gaps before they leak revenue. |
| TokenGoblin cost optimizer | Measure and control model-inference spend. |
| Local AI lab audit | Review hardware fit, routing, security, and operating posture. |
| AI command center | Replace operational blind spots with health and priority signals. |
| ComfyUI workflow packs | Run repeatable private image-production workflows on owned compute. |
| Principle | Working rule |
|---|---|
| Evidence over confidence | If a run cannot be inspected or replayed, it is not production-ready. |
| Local-first where it earns its keep | Own the compute, data boundary, fallback path, and cost model when the trade-off is justified. |
| Determinism at the edges | Keep probabilistic intelligence inside explicit policy, schema, and execution constraints. |
| Boring reliability wins | Idempotency, row-level security, state machines, and observable queues beat hidden cleverness. |
| Revenue is a reconciled event | A dashboard row is not money; provider-correlated settlement evidence is money. |
| Fix the smallest root cause | Isolate the failure, repair it surgically, prove the result, then ship. |
Verify this profile locally
git clone https://github.com/Hardonian/Hardonian.git
cd Hardonian
uv run python -m unittest discover tests -v
uv run python scripts/profile-metadata.py --check --verify-remote
uv run python scripts/profile-link-audit.pyThe checks reject stale project metadata, missing public evidence, broken local assets, and dead links.
I am a Solutions Architect at McGraw Hill and build Hardonia independently from Toronto. Alongside that work, I contribute part-time expertise to confidential frontier-AI evaluation and systems initiatives; client, model, dataset, and internal research details remain private.
- Dual-Discipline Mastery: Combining high-level enterprise architecture (C-suite technical alignment, procurement, institutional security, FERPA/SOC-2 compliance) with low-level systems implementation (Go distributed control planes, Rust formal models, TypeScript/Next.js production apps, and PostgreSQL kernel-level isolation).
- Enterprise Integrations at Scale: Deep experience architecting mission-critical data exchanges across large-scale distributed systems, identity providers (Keycloak, SAML, OIDC), message buses, and legacy institutional platforms (LMS, SIS, ERP).
- Commercial & Delivery Track Record: Winner of the President's Award for Sales Excellence; proven ability to bridge frontier AI research into reliable, revenue-generating enterprise customer outcomes.
- Open Standards & Protocol Leadership: Deep domain fluency in open standards across education and enterprise systems (LTI 1.3 Advantage, OneRoster 1.2, OAuth 2.0 / Keycloak OIDC, SCIM, Model Context Protocol, and OpenTelemetry trace propagation).
- Sovereign Infrastructure: Hands-on hardware systems engineering operating an owned multi-tier AMD EPYC server, AMD Ryzen AI 9 NPU, and NVIDIA GPU cluster for local model evaluations, quantized inference, and private agent pipelines.
If you have an AI workflow that is expensive, unreliable, hard to govern, or stuck between prototype and production—or want to connect on high-assurance AI systems architecture and enterprise engineering—reach out directly:



