Skip to content
View msaleme's full-sized avatar

Organizations

@CognitiveThoughtEngine

Block or report msaleme

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
msaleme/README.md

Michael K. Saleme

Enterprise architect. 30 years building production integration and architecture across Oil & Gas, Energy/Utilities, and CPG since 1996.

I am defining Enterprise Agent Architecture: the fifth domain enterprise architecture needs for a workforce of humans and AI agents. TOGAF, Zachman, SABSA, and NIST model what the enterprise builds and runs. None model a non-human actor that holds delegated authority, acts autonomously, and composes tools it was never explicitly granted. That gap is the work.

Read the series: Enterprise Agent Architecture — the fifth domain, one part at a time. Also on Substack.

Public DOI-backed research · public standards submissions · Agent Security Harness v4.15.0: 603 executable IDs across 43 test-bearing modules — dated record

Evidence record: PubPoint Facts & Evidence


The evidence

I do not just write about the agent workforce. I build the tools that prove how it fails and the research that measures it.

Research

I study the gap between who an agent is and how it behaves — what I call the WHO vs. HOW problem. Identity and permissions don't prevent an authorized agent from being manipulated into unsafe decisions. My work formalizes this gap and provides empirical evidence.

Record DOI Evidence boundary
Decision Load Index (DLI) 10.5281/zenodo.18217577 First-party public research record; citable, not clinical validation or product-efficacy evidence.
Constitutional Self-Governance (CSG) 10.5281/zenodo.19162104 First-party public research record; the record and stated methods define claim scope.
Normalization of Deviance (NoD) 10.5281/zenodo.19195516 First-party public research record; citable, not independent validation.
Beyond Identity Governance 10.5281/zenodo.19343034 First-party public research record; citable, not independent validation.
Community-Driven Security 10.5281/zenodo.19343108 First-party public research record; citable, not independent validation.

Standards engagement: public submissions are contributions, not adoption or acknowledgment by a receiving body. Dated evidence and boundaries: PubPoint Facts & Evidence.

Agent Security Harness

The research above is implemented as an open-source adversarial evaluation framework. Release v4.15.0 has 603 unique executable IDs across 43 test-bearing modules. The dated record distinguishes that release inventory from current main and explains the verdict-producing versus informational-check split.

red-team-blue-team-agent-fabric · dated inventory and evidence limits


Enterprise Architecture

30 years building production integration systems across Oil & Gas, Energy/Utilities, and CPG since 1996.


Connect

Pinned Loading

  1. start-here start-here Public

    Michael K. Saleme — Enterprise Agent Architecture & machine-verifiable governance for autonomous systems. Public Zenodo research, NIST submissions, a Linux Foundation x402 contribution, and an adve…

  2. red-team-blue-team-agent-fabric red-team-blue-team-agent-fabric Public

    AI agent security harness, adversarial testing: 623 executable tests in the v4.21.3 release, across MCP, A2A, x402/L402, decision governance, benchmark integrity, human-in-the-loop, skill supply ch…

    Python 30 7

  3. ace-experiment-framework ace-experiment-framework Public

    Contract and claim-boundary tooling for empirical AI-system experiments. Turns retained evidence into falsifiable, condition-specific decisions.

    Python 2

  4. aiuc1-readiness aiuc1-readiness Public

    AIUC-1 Readiness Assessment - Pre-certification adversarial testing for AI agents

    HTML

  5. awesome-mcp-security awesome-mcp-security Public

    Forked from Puliczek/awesome-mcp-security

    🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️

  6. awesome-eu-ai-act awesome-eu-ai-act Public

    Forked from GenAI-Gurus/awesome-eu-ai-act

    Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance.