Engineering · Platform Architecture · B2B SaaS Technologist Boston, MA · ~30 years across IBM, CyberArk, Alteryx, Digital.ai, Gryphon.ai
I build the systems that sit between traffic, revenue, and the teams that operate them. Platform engineering, GTM systems, traffic integrity, digital intelligence, AI governance. I also author open specifications for the answer-engine era — and a fifteen-repo implementation stack that consumes them (Suite × Implementations). Polyglot by choice: the language fits the problem, not the resume.
Publication note: many of the repos below were published in a concentrated May 2026 portfolio sprint. The dates reflect public packaging, CI, screenshots, and repo hardening, not the first moment the ideas or workstreams existed.
The current public wave now spans revenue systems, traffic integrity, web-platform reliability, regulated workflow operations, a polyglot language atlas, and multi-cloud identity & platform governance:
GTM Systems & Growth— demand-gen automation, CRM routing, lifecycle control, offer motionTraffic Integrity— bot mitigation, click-fraud reduction, clean analytics inputsDigital Intelligence— attribution, telemetry, SEO governance, pipeline clarityPlatform Engineering— headless CMS, DevOps, core web vitals, resilient deliveryRegulated Workflow Systems— approval routing, obligation graphs, consent evidence, audit postureOperational Command Surfaces— bookings, creator launches, menu sync, store incidents, permits, crop complianceLanguage Atlas— real operator surfaces in Flutter, Julia, Python, Rust, Go, PHP, Kotlin, and more where the language fits the system shapeCloud Identity, Platform, FinOps & Threat Detection— operator surfaces for Microsoft (Entra access reviews, Intune device compliance, M365 Purview retention), AWS (IAM Access Analyzer + GuardDuty triage), GCP (IAM policy drift + billing-anomaly routing), and Azure (landing-zone drift). Each is a synthetic-data operator console at production hardness — AGPL-3.0-or-later, dual-Node CI, dependabot, 95%+ coverage, deployed on its own kineticgain.com subdomain.
Early anchors in that lane:
revops-lead-router— control plane for lead enrichment, CRM routing, speed-to-lead posture, and queue integrityfraud-click-filter·cf-bot-shield-tf·honeypot-form-validator·anomaly-log-hunter— traffic-integrity layer for blocking fraudulent sessions before they burn ad spend or poison analyticsdbt-multi-touch-attr·gtm-datalayer-standards·seo-vital-monitor·pipeline-velocity-dash— digital-intelligence layer for attribution, signal clarity, and route-level performance postureoffer-ladder-engine— offer-path and conversion-state control for pricing and package motionedge-redirect-manager·headless-wp-vue-starter— web-platform layer for headless CMS delivery, route migration, preview-safe rendering, and SEO-conscious frontend architectureregulatory-comment-intelligence-hub·contract-clause-obligation-graph·prior-authorization-evidence-router·patient-consent-audit-stream— regulated workflow layer for approvals, obligation mapping, evidence routing, and synthetic audit posturecreator-partnership-deal-desk·booking-disruption-command-center·menu-availability-sync-engine·store-ops-incident-board— launch and operations layer for creator programs, hospitality disruption handling, menu sync, and store incident responseflutter-operator-console·capacity-optimizer-jl·regulatory-reporting-mart— language-atlas proof that the portfolio ships real operator systems in Flutter/Dart, Julia, and Python, not just one web stack- Multi-cloud identity, platform, FinOps & threat-detection lane — eight operator consoles all at v1.0-prod, all running on their own kineticgain.com subdomain:
entra-access-review-control-plane→ entra.kineticgain.com — Microsoft Entra access reviews & privileged role driftintune-device-compliance-ops→ intune.kineticgain.com — Intune device compliance & jailbreak / OS-drift posturem365-retention-case-orchestrator→ retention.kineticgain.com — Microsoft 365 Purview retention & eDiscoveryaws-iam-access-analyzer-console→ aws.kineticgain.com — AWS IAM Access Analyzer & cross-account trustaws-guardduty-triage-board→ guardduty.kineticgain.com — AWS GuardDuty detector posture, threat-finding triage & incident responsegcp-iam-policy-diff-lab→ gcp.kineticgain.com — GCP IAM policy drift & org-policy posturegcp-billing-anomaly-router→ billing.kineticgain.com — GCP billing-anomaly routing, budget breaches & FinOps escalationazure-landing-zone-drift-radar→ zone.kineticgain.com — Azure landing-zone baseline drift & guardrail risk
- Polyglot Operator Reporting lane — three new operator surfaces in three different runtimes, each picked because the language fits the problem (mobile briefings → Flutter, scientific optimization → Julia, warehouse-style mart → Python). All v1.0-prod, all subdomain-deployed:
flutter-operator-console→ flutter.kineticgain.com — Flutter web operator console: signal triage, briefings, dispatch posturecapacity-optimizer-jl→ capacity.kineticgain.com — Julia + JuMP capacity planning, constraint optimization, scenario diffsregulatory-reporting-mart→ reporting.kineticgain.com — Python warehouse-style mart: docket readiness, evidence packets, deadline pressure, late-risk
Current public GitHub count: 372 repos. Operator-surface hardening backlog (squad doctrine v1.1): 49 .kineticgain.com subdomains now at v1.0-prod, every Codex-shipped v0.1 caught up — zero gaps remaining at the cutoff. The full grouped index is at kineticgain.com/constellation.
Three sibling repos enforce a buyer's AI Procurement Decision Card → PolicyBundle at request time, one per upstream surface — the v2 strategy's IBM-credibility flagship lane. Same primitive (deny-trumps-allow eval, x-kg-correlation-id propagation, audit-stream emission), three platforms:
ibm-watsonx-governance-bridge→ watsonx.kineticgain.com — IBM watsonx.ai (Python · IBM Cloud IAM · Code Engine deploy manifest · v1.0-prod)azure-openai-governance-bridge— Azure OpenAI (Python · Azure Functions v2 · Bicep IaC)mcp-permission-broker— Model Context Protocol transport (the MCP-side sibling)
Same buyer-published AI Procurement Decision Card v0.2, a different enforcement axis: instead of gating requests, this family gates field-level PII at the seam. The Decision Card declares data_vault_targets[] — which fields may be tokenized through a Skyyflow-shaped vault, and which roles may detokenize. Four sibling surfaces consume one contract:
ai-procurement-decision-spec— the JSON Schema (v0.2 addsdata_vault_targets)kg-skyyflow-klaviyo-bridge— Node lib + CLI ·audit·tokenize·detokenize·transform(webhook → Klaviyo) · per-field protection levels (none/masked/tokenized) · v0.2.0 · AGPL-3.0skyyflow-klaviyo-bridge-console— React + Vite operator console for the bridge engine: dashboard · live webhook simulator with a 3-stage animated pipeline · field mapper · sync log streamrag-sentinel— tokenize-before-index for RAG pipelines (server-side enforcement of the same contract)deal-desk-workspace— RBAC-aware reveal for the deal-desk surface (client-side enforcement of the same contract)
One Decision Card, four enforcement points. Same SkyyflowVault interface across server-side (rag-sentinel), client-side (deal-desk-workspace, console), pipeline-side (bridge lib), and CLI.
Fourteen new public repos now sit underneath the portfolio as a reusable developer toolkit layer:
MCP governance—mcp-registry-risk-scanner·mcp-tool-card-generator·mcp-tools-diffGenAI observability—agent-trace-normalizer·llm-cost-span-exporter·rag-evidence-trace-linkerK8s control planes—governance-disclosure-operator·llm-cost-budget-operator·scheduled-audit-operatorAgent-runtime adapters—agent-tool-adapters·agent-card-runtime-adaptersKnowledge graph + evidence—rag-evidence-graph·wellknown-index-aggregator
These are not customer-facing protocol specs. They are the implementation toolkit underneath the protocol layer: manifest scanning, disclosure generation, tool drift detection, runtime adapters, evidence integrity, cost spans, and Kubernetes-native governance publishing.
The next ~10 operator-surface repos are organized as three sub-verticals × four-tier monetization ladder, with SEO and security posture as first-class concerns on every repo. Each lane lands on a real enterprise platform; each repo carries the credible "from someone who lived in this stack" hook — IBM enterprise integration · CyberArk identity · Alteryx analytics.
Three sub-verticals:
| Sub-vertical | Platforms | Buyer | Placement |
|---|---|---|---|
| Workflow / CX | IBM watsonx Governance · Genesys Cloud · Camunda 8/Zeebe | CISO / CTO / Platform Eng / VP CX | Kinetic Gain Suite |
| Workforce / Internal Comm | UKG Pro · employee-AUP cross-cut · FirstUp (second-tier priority) | CISO / Head of HR Tech / Compliance | Kinetic Gain Suite |
| Growth Ops | Klaviyo EP · VWO REST · MarTech-stack cross-cut | CMO / RevOps / Growth Eng | Lane under Kinetic Gain (growth.kineticgain.com) — brand split deferred until demand proves it |
Four-tier monetization ladder per repo (honest tier wording):
| Tier | What ships | Pricing | README phrasing |
|---|---|---|---|
| 1 · Free operator surface | Public README + static dashboard + CLI + synthetic fixtures at <repo>.kineticgain.com |
$0 | "Free now" — only once deployed and CI-green |
| 2 · Template / policy pack | Governance YAMLs · dashboard configs · audit checklist templates · CSV starter datasets | $49–$199 | "Template pack available" OR "Template pack planned" — never imply available if not |
| 3 · Hosted SaaS | OAuth into tenant · multi-tenant scheduling · signed evidence packets | $99–$499 / mo | "Hosted preview" — only when a real OAuth + tenant path exists; otherwise omit |
| 4 · KGE module | Embedded in-app dashboard inside the customer's own product, per kineticgain.com/embedded | $1.5K–$7.5K / mo | "Embedded available by engagement" — direct-contract phrasing, no signup form |
Default for a tier-1-only repo: list tiers 1 + 2-planned only. No SaaS-looking promises without an OAuth + billing + tenant + support motion behind them.
Cross-cutting (every repo, no exceptions):
- SEO — dark slate/blue theme · descriptive dofollow anchors ·
/.well-known/Suite docs · hub-and-spoke interlinking · GH topics + homepage set · sitemap entry - Security — read-only by default · minimal OAuth scopes · no tenant credentials in repo · synthetic fixtures only · evidence packets signed (ed25519 once
pulse-signing.jsonships) - Compliance language (broad) — across HIPAA · FERPA · SOC 2 · GDPR · ISO 27001 · accessibility (WCAG/ADA) · AI governance (NIST AI RMF, EU AI Act, ISO 42001): always frame as
readiness · evidence · posture · controls · scaffolding. Never "certified" / "compliant" unless truly audited and currently attested. No "BAA" / "DPA" / "PHI" / "PII" / "audit ready" promises without legal review. - Anti-overlap discipline — before opening any new repo, document core primitive · target buyer · target platform · monetization tier path · nearest existing repo · why distinct. Blocks the "same surface, different wrapper" drift.
- Pulse universe entry — every deploy adds its CNAME to the AI Procurement Pulse universe, additively · async if possible · non-fatal on failure. Pulse-entry never blocks a publish.
Phase 0 anchors (founder-credibility-ordered):
ibm-watsonx-governance-bridge— founder-credibility flagship. IBM is the most credible "lived in this stack" hook in the portfolio; watsonx Governance is the cleanest disclosure-shaped target.genesys-cx-disclosure-board— enterprise workflow/CX flagship. Warmest CISO/VP-CX buyer + highest tier-4 KGE fit.klaviyo-flow-consent-audit— Growth Ops flagship. Cleanest CMO/RevOps narrative; consent-state lineage is a timely angle.
Three anchors prove the four-tier ladder in three distinct buyer contexts before the remaining 7 fill out at tier-1 + tier-2-planned. FirstUp deferred to second-tier priority — good fit, weaker instant recognition than IBM/Genesys/Camunda/UKG/Klaviyo/VWO.
The portfolio runs on two parallel layers that compose:
- A growing network of productized open-source properties live at
kineticgain.comsubdomains — front doors, per-spec landings, operator dashboards, vertical command surfaces, vendor directory, and prompt-injection bench. All push-to-deploy via GitHub Actions FTP CI/CD. Front door: suite.kineticgain.com · Quickstart hub: docs.kineticgain.com · Live portfolio constellation across every public repo: portfolio.kineticgain.com. - Fifteen-repo Suite Implementation Stack — the software that consumes the Kinetic Gain Protocol Suite specs. Decision Intelligence engines · Platform Reliability primitives · MCP servers · data-contract enforcement · ed25519 attestation · drift detection · streaming validators. All CI-green, all semver-tagged at v0.1.0, all MIT-licensed. Four cross-ecosystem hooks chain them into one composable system. The catalog: Suite × Implementations. The compliance mapping: NIST AI RMF crosswalk (v0.2 includes the implementation-tooling alignment).
flowchart TB
classDef spec fill:#10b981,stroke:#065f46,color:#fff,stroke-width:2px
classDef hook fill:#3b82f6,stroke:#1e40af,color:#fff,stroke-width:2px
classDef sup fill:#f3f4f6,stroke:#6b7280,color:#1f2937
classDef stream fill:#f59e0b,stroke:#92400e,color:#fff
classDef mcp fill:#a855f7,stroke:#581c87,color:#fff,stroke-width:2px
SPECS["📐 11 Kinetic Gain Protocol Suite specs<br/>AEO · Agent · Tool · Tutor · AUP · Disclosure<br/>Evidence · Provenance · Clinical · Incident · Decision"]:::spec
SPECS -->|"#1 ingest Suite docs"| PDA["procurement-decision-api<br/>drafts Decision Cards"]:::hook
PDA -->|"#2 conditions → runtime gates"| PAC["policy-as-code-engine<br/>PolicyBundle enforcement"]:::hook
PDA -->|"#3 extract owners"| DCR["data-contract-registry<br/>schema + SLAs"]:::hook
DCR -->|"#4 streaming CSV check"| CDQ["csv-data-quality-rs<br/>row-by-row validation"]:::hook
SPECS -.->|sign + verify| HA["hash-attestation-rs<br/>ed25519 over canonical hash"]:::sup
SPECS -.->|drift detection| AVS["aeo-validator-service<br/>always-on validation"]:::sup
AVS -.->|JSONL feed| AGE["aeo-graph-explorer-rs<br/>graph-query layer #5"]:::sup
SPECS -.->|incident → plan| ICR["incident-correlation-rs<br/>Suite-graph BFS"]:::sup
ICR -.->|drives| PAC
PDA --> AS
PAC --> AS
DCR --> AS
AVS --> AS
ICR --> AS
HA --> AS
AS["📋 audit-stream-py<br/>hash-chained tamper-evident spine"]:::stream
SPECS ==>|spec tools| MCP
PDA ==>|preview tools| MCP
AS ==>|event tools| MCP
HA ==>|verify tools| MCP
MCP["🤖 mcp-kinetic-gain v0.7.1<br/>63 tools · one Claude Desktop config entry"]:::mcp
Green = spec layer (the foundation). Blue = the four cross-ecosystem hooks that make it a stack rather than a pile. Grey = supporting implementation tools that feed into either side. Amber = the tamper-evident audit spine every governance moment writes to. Purple = the unified MCP surface that exposes the whole thing to Claude through one config entry.
Zoom in on the amber spine: every governance moment in the stack writes to one hash-chained, tamper-evident log via audit-stream-py. Same opt-in env-var contract (AUDIT_STREAM_URL) across all seven producers; same best-effort semantics (a failed POST is logged, never raised). 17 event kinds, seven producers, four FastAPI services + three Rust crates, all feeding one verifiable narrative an auditor can replay end-to-end.
flowchart LR
classDef pyprod fill:#3b82f6,stroke:#1e40af,color:#fff,stroke-width:2px
classDef rsprod fill:#dea584,stroke:#92400e,color:#1f2937,stroke-width:2px
classDef spine fill:#f59e0b,stroke:#92400e,color:#fff,stroke-width:3px
classDef sink fill:#f3f4f6,stroke:#6b7280,color:#1f2937
PDA["procurement-decision-api<br/>Python · FastAPI"]:::pyprod
AVS["aeo-validator-service<br/>Python · FastAPI"]:::pyprod
PCE["policy-as-code-engine<br/>Python · FastAPI"]:::pyprod
DCR["data-contract-registry<br/>Python · FastAPI"]:::pyprod
HA["hash-attestation<br/>Rust · crypto library"]:::rsprod
ICR["incident-correlation<br/>Rust · graph library"]:::rsprod
AGE["aeo-graph-explorer<br/>Rust · axum service"]:::rsprod
PDA -->|"decision_card_drafted"| AS
AVS -->|"watch_created<br/>watch_drifted<br/>watch_validity_flipped"| AS
PCE -->|"policy_bundle_registered<br/>request_allowed<br/>request_denied"| AS
DCR -->|"contract_promoted<br/>contract_deprecated<br/>contract_compatibility_failed"| AS
HA -->|"attestation_signed<br/>attestation_verified<br/>attestation_failed"| AS
ICR -->|"incident_correlated<br/>incident_correlation_failed"| AS
AGE -->|"graph_ingested<br/>graph_ingest_failed"| AS
AS{{"📋 audit-stream-py<br/>hash-chained · tamper-evident<br/>SSE live tail · REST query · GET /verify"}}:::spine
AS -->|GET /events/stream| LT["governance dashboards<br/>(live tail)"]:::sink
AS -->|GET /events| Q["compliance evidence<br/>(REST query)"]:::sink
AS -->|GET /verify| V["auditor replay<br/>(walk the chain)"]:::sink
Blue = Python FastAPI producers. Tan = Rust producers (two libraries gated behind --features audit-stream so library consumers can strip out the HTTP dep, one axum service with the feature on by default). Amber = the spine itself. Grey = the three downstream surfaces auditors and operators consume.
| Property | What it does | Buyer |
|---|---|---|
| suite.kineticgain.com | Kinetic Gain Protocol Suite — canonical front door for all 11 open AI governance specs + NIST AI RMF crosswalk | Recruiters / investors / generalist |
| docs.kineticgain.com | Quickstart hub — per-role guides (CISO / district / healthcare vendor / answer engine) + canonical /.well-known/ path map |
New visitors / implementers |
| directory.kineticgain.com | Vendor directory — curated list of domains publishing Kinetic Gain documents | Procurement reviewers |
| examples.kineticgain.com | Examples gallery — pick a spec, see its canonical example with JSON highlight | Developers / spec authors |
| walker.kineticgain.com | well-known-walker — paste any domain, see every Kinetic Gain disclosure it publishes | Procurement / Risk reviewers |
| bench.kineticgain.com | prompt-injection-bench — visual harness, paste a JSONL transcript, see pass rates | CISO / Red-team / Trust & Safety |
| pulse.kineticgain.com | AI Procurement Pulse — quarterly research index of vendor AI governance disclosure across the open internet | Journalists / Analysts / Buyers |
| Property | Spec | Buyer |
|---|---|---|
| aeo.kineticgain.com | AEO Protocol — interactive visualizer | Platform Eng / AEO |
| prompts.kineticgain.com | Prompt Provenance | LLM Platform / SRE |
| agents.kineticgain.com | Agent Cards | Platform Eng / Procurement |
| evidence.kineticgain.com | AI Evidence Format | RAG / Search / Answer engines |
| toolcards.kineticgain.com | MCP Tool Cards | MCP authors / Platform Sec |
| tutor.kineticgain.com | AI Tutor Cards | EdTech / District Procurement |
| student.kineticgain.com | Student AI Disclosure | Academic integrity / LMS |
| aup.kineticgain.com | Classroom AI AUP | District / school / instructor |
| clinical.kineticgain.com | Clinical AI Disclosure (HIPAA / FDA / SaMD) | Hospital CMIO / Compliance |
| incidents.kineticgain.com | AI Incident Card — "CVE for AI agents" | CISO / Trust & Safety |
| decisions.kineticgain.com | AI Procurement Decision Card — the buyer-side artifact (spec #11) | Procurement / District / Agency |
| Property | What it does | Buyer |
|---|---|---|
| gv.kineticgain.com | GitVisualizer — visual portfolio intelligence for any GitHub user | Engineering / Hiring |
| mcp.kineticgain.com | MCP Sentinel — governance dashboard for Model Context Protocol servers | CISO / Platform Security |
| rag.kineticgain.com | RAG Sentinel — hallucination, drift, and citation quality monitoring | ML / AI Ops |
| observe.kineticgain.com | AgentObserve — operator console for AI agent fleets | SRE / Platform |
Across the live property network: mix of AGPL-3.0 and Apache-2.0, CI green, push-to-deploy via FTP Action. The current mix includes React + TypeScript operator apps, hand-written static HTML landings, and newer vertical command surfaces.
Fifteen standalone vertical operator surfaces, each a TypeScript control plane for a regulated/operations workflow — intake → risk & obligation mapping → posture → safe escalation. Codex ships at v0.1-shipped; I (Platform/SRE) harden each to v1.0-prod: CI on Node 20 + 22, ≥60% service-test coverage, AGPL-3.0, Dependabot, npm audit, SECURITY.md, static prerender → GitHub Pages. All live, all CI-green.
| Live surface | Vertical | What it does |
|---|---|---|
| dockets → live | GovTech / RegTech | Regulatory comment intake, obligation mapping, approval posture, evidence-packaged submission (dockets.kineticgain.com provisioning) |
| clauses.kineticgain.com | LegalTech | Clause extraction, obligation graphs, review blockers, renewal-safe execution |
| priorauth.kineticgain.com | Digital Health | Prior-auth evidence routing, payer rules, approval-safe escalation |
| consent.kineticgain.com | Digital Health | Consent state, audit streams, revocation-safe escalation |
| shipments.kineticgain.com | Supply Chain | Shipment exceptions, carrier rules, SLA-safe recovery |
| downtime.kineticgain.com | Manufacturing | Downtime incidents, root-cause blockers, restart-safe escalation |
| dispatch.kineticgain.com | Mobility | Dispatch readiness, route adherence, SLA-safe intervention |
| catalog.kineticgain.com | Commerce | Catalog schema governance, dependency blockers, release-safe field changes |
| campaigns.kineticgain.com | Growth / MarTech | Campaign taxonomy, audience blockers, launch-safe conventions |
| creators.kineticgain.com | Creator economy | Partnership deal desk, obligation blockers, launch-safe collaboration |
| bookings.kineticgain.com | Travel / Hospitality | Booking disruptions, recovery blockers, guest-communication posture |
| permits.kineticgain.com | Construction / GovTech | Permit-package readiness, inspection posture, construction-safe submission |
| crops.kineticgain.com | AgriTech | Crop-compliance observations, field-review triage, buyer-safe packet posture |
| menus.kineticgain.com | Food / Restaurant Tech | Menu availability sync, channel posture, launch-safe conventions |
| stores.kineticgain.com | Retail / Store Ops | Store incident triage, SLA blockers, reopen-safe recovery posture |
HealthTech surfaces (
priorauth,consent) are HIPAA-readiness scaffolding only — synthetic data, no PHI; see each repo'sSECURITY.md.
Seventeen Action wrappers that turn every Kinetic Gain protocol library into a per-PR governance gate. Composite Node 20 actions with dist/index.js committed for SHA/tag pinning, hermetic tests with injected gitShow, AGPL-3.0-or-later, Dependabot-managed.
Each one retrieves the previous version of a single governance doc via git show <base.sha>:<path>, diffs against HEAD, posts the structured diff as a PR comment, and fails the build on breaking changes.
| Protocol | Action | Headline breaking-change reasons |
|---|---|---|
| A2A AgentCard | agent-card-diff-action |
autonomy-level-elevated, tool-side-effects-elevated, incident-response-uri-removed, refusal-category-removed |
| MCP Tool Card | mcp-tool-card-diff-action |
side-effect-class-escalated, pii-exposure-escalated, human-approval-removed, external-system-added, input-schema-changed |
| Prompt Provenance | prompt-provenance-diff-action |
prompt-hash-changed, approval-state-regressed, lineage-parent-changed, intent-out-of-scope-changed |
| Evidence Bundle | evidence-bundle-diff-action |
item-hash-changed, item-removed, signature-removed, signature-signer-changed, bundle-expires-shortened |
| OTel GenAI rollup | otel-genai-diff-action |
cost-increased, input-tokens-jumped, output-tokens-jumped, model-added, currency-changed (configurable threshold) |
Each one summarizes a single doc against the rest of a fleet (a directory of peer docs of the same protocol), surfacing the outliers and posting a structured PR summary.
agent-card-fleet-summary-action · mcp-tool-card-fleet-summary-action · prompt-provenance-fleet-summary-action · evidence-bundle-fleet-summary-action · otel-genai-fleet-summary-action
The wiring that ties the per-protocol quintets together across mixed-content repos:
| Action | What it does |
|---|---|
kg-protocol-detect-action |
Scans a directory of JSON docs and identifies which Suite protocol each belongs to. Routes mixed-content repos to the right per-protocol diff lane. |
kg-suite-canonicalize-action |
Canonicalizes every Suite doc in a directory (stable key ordering, hash-ready output). PR-gates drift between canonical and authored forms. |
kg-suite-conformance-runner-action |
Runs spec-conformance checks across every Suite doc in a directory; reports per-spec compliance + per-finding evidence. |
kg-suite-fleet-overview-action |
Protocol-aware fleet overview across all 5 governance protocols in one repo — buckets, doc counts, unrouted-document gate. |
kg-suite-spec-version-tracker-action |
Tracks the *_version discriminator across every Suite doc in a repo, fails the PR on unsanctioned spec-version upgrades. |
| Action | What it does |
|---|---|
llm-cost-rollup-action |
Runs otel-genai-rollup across an OTLP trace export and gates the PR on cost budget breaches. |
k8s-pre-merge-action |
Composite gate across the K8s scanner family — deprecated APIs, RBAC over-scope, pod security, Helm values coverage — one Action, one PR comment. |
procurement-pulse-action |
Probes your own /.well-known/ for all 11 Suite documents and reports a 0-100 self-score + tier. Three output modes (PR comment / pulse-receipt JSON / self-score SVG badge), two gate modes (min-score threshold / min-tier ladder). Same probe core as the Pulse Issue crawler and the browser-extension Vendor Inspector. |
Composition story: kg-protocol-detect-action identifies what protocols live in the repo → the matching per-protocol *-diff-action gates breaking changes → the matching *-fleet-summary-action surfaces outliers across the fleet → kg-suite-conformance-runner-action checks spec conformance → kg-suite-canonicalize-action enforces stable serialization → procurement-pulse-action self-scores the deployed /.well-known/ surface. End-to-end PR governance with zero hand-rolled glue.
Dogfooded on kineticgain.com itself. Weekly
procurement-pulse-action run probes the apex and refreshes the badge + the public receipt at kineticgain.com/.well-known/pulse-receipt.json.
A different discipline from the governance suite: a studio-grade, offline-first notepad at sveska.studio. No account, no telemetry, no cloud dependency — every note lives in the browser's IndexedDB and the app works with the network unplugged.
| Editor | CodeMirror 6 rich editor — inline screenshot paste, Markdown highlighting, slash commands, snippets, find/replace, typewriter; classic textarea opt-out |
| Depth | Multi-note tabs · version history + diff · fuzzy search · per-note Excalidraw canvas · streaming AI via a secure edge proxy (zero keys in the client) · .txt / .md / .html / .pdf export |
| Engineering | React 18 + TS strict · Zustand · Dexie · vite-plugin-pwa · 281 tests · <180 KB initial JS · accessibility-audited · Cloudflare Pages + edge function |
Repo: mizcausevic-dev/sveska · v0.8.0 · MIT
A family of eleven open JSON specifications for the answer-engine and agent era — five core (AEO, Prompt Provenance, Agent Cards, AI Evidence Format, MCP Tool Cards), a three-spec EdTech trio (vendor / district / student), a HealthTech vertical extension (Clinical AI Disclosure — HIPAA / FDA / SaMD posture), a cross-cutting AI Incident Card that ties everything together post-hoc, and an AI Procurement Decision Card that signs off on a vendor's posture across the rest of the Suite. Two regulated verticals covered. NIST AI RMF crosswalk shipped alongside. All AGPL-3.0, all v0.1 draft, all kinetic-gain-protocol-suite tagged. Single landing: kinetic-gain-protocol-suite.
| Spec | What it declares | Detect via |
|---|---|---|
aeo-protocol-spec |
AEO Protocol — entity declaration at /.well-known/aeo.json |
aeo_version |
prompt-provenance-spec |
Prompt Provenance — versioned, lineaged, reviewable LLM prompt records | provenance_version |
agent-cards-spec |
Agent Cards — declarative agent capability + refusal disclosure | agent_card_version |
ai-evidence-format-spec |
AI Evidence Format — structured citations for LLM-generated claims | evidence_version |
mcp-tool-card-spec |
MCP Tool Cards — per-tool disclosure for Model Context Protocol servers | tool_card_version |
ai-tutor-card-spec |
AI Tutor Cards — EdTech vendor-side: pedagogy, FERPA/COPPA/GDPR posture | tutor_card_version |
student-ai-disclosure-spec |
Student AI Disclosure — student-side: roles, prompt evidence (full/hashed/omitted), artifact-hash binding | disclosure_version |
classroom-ai-aup-spec |
Classroom AI AUP — district / school / course-side policy (closes the EdTech trio) | aup_version |
clinical-ai-disclosure-spec |
Clinical AI Disclosure — HealthTech vendor-side: HIPAA / FDA / SaMD posture, bias audits, EHR (FHIR / CDS Hooks) | clinical_ai_card_version |
ai-incident-card-spec |
AI Incident Card — "CVE for AI agents," cross-references every other affected document in the Suite | incident_card_version |
ai-procurement-decision-spec |
AI Procurement Decision Card — buyer-side approval/rejection record that signs off on a vendor's posture across the rest of the Suite | decision_card_version |
The canonical depth example — every layer needed to consume the spec, across five languages:
| Layer | Repos |
|---|---|
| SDKs | aeo-sdk-python (live on PyPI) · aeo-sdk-typescript · aeo-sdk-rust · aeo-sdk-go · aeo-sdk-swift |
| CLI | aeo-cli — aeo validate / fetch / inspect / claim, colored output, end-to-end against the live well-known URL |
| Crawler | aeo-crawler — BFS over AEO graphs, JSON Lines output, configurable depth + concurrency |
| Validator service | aeo-validator-service — always-on HTTP validator for AEO + all 11 Suite docs. Auto-detects the spec via *_version sniffing, hashes canonically, tracks drift across re-checks (POST /watches/{id}/recheck returns a structured DriftReport). |
| Graph explorer | aeo-graph-explorer-rs — Rust + axum + petgraph graph-query service over aeo-crawler JSONL output. Ingests atomically; exposes /nodes · /neighbors · /shortest-path · /find-by-claim. The fifth layer of the AEO Reference Stack — 3→5 layers gap closed. |
hash-attestation-rs — sign + verify Suite docs with ed25519 over the same canonical-hash convention every other Suite repo uses. The missing "this AEO actually came from the vendor" layer. Vendors sign, publish a well-known public key URL, consumers verify. Composes with aeo-validator-service (tamper events surface as structured issues) and procurement-decision-api (Decision Cards can carry a signature).
The spec is only one layer. The newer control-plane layer covers citation readiness, publication safety, visibility monitoring, and release posture:
| Repo | What it does |
|---|---|
aeo-citation-gap-finder |
Detects weakly sourced, stale, or unsupported claims before they leak into answer-engine surfaces |
llms-txt-governance-hub |
Governs llms.txt manifests, exclusions, freshness windows, and release approvals |
geo-competitive-visibility-tracker |
Tracks answer-surface share, citation pressure, and competitor query ownership |
aeo-registry |
Governed inventory of manifests, claim readiness, freshness pressure, and publisher posture |
aeo-linter |
Rust CLI for manifest hygiene, source freshness, claim coverage, and answer-surface readiness |
| Repo | What it does |
|---|---|
mcp-aeo-server |
AEO-only MCP server — 4 tools, one Claude Desktop config entry |
mcp-kinetic-gain |
Unified MCP server — 63 tools across 11 specs (v0.7.1, git-tagged), one Claude Desktop config entry, 126 tests passing. Headline tools: aup_check_compliance joins an AUP + Student AI Disclosure into a single allow/deny call; decision_card_validate enforces the full procurement Decision Card conditional ruleset. |
mcp-reliability-toolkit |
Reliability MCP server — 4 tools (compute_slo_burn, design_rate_limiter, design_circuit_breaker, compose_reliability_pattern). Same math as slo-budget-tracker; emits drop-in Python + Rust configs from a Claude conversation. |
mcp-decision-intelligence |
Decision Intelligence MCP server — 4 tools (validate_decision_card, preview_policy_bundle, plan_incident_remediation, check_contract_compatibility). Read-only preview of what procurement-decision-api + policy-as-code-engine + incident-correlation-rs + data-contract-registry would do — deterministic, no LLM-in-the-loop reasoning. |
mcp-permission-broker |
Runtime permission gate — the enforcement point between an AI Procurement Decision Card and an MCP tool call. Composes Decision Card conditions into PolicyBundles, applies deny-trumps-allow at request time, emits tool_invocation_* events to the audit-stream spine. The piece that turns "buyer signed off" into "this tool call is denied." |
azure-openai-governance-bridge |
The Azure-native sibling of the broker. An Azure Function in front of Azure OpenAI that enforces the same deny-trumps-allow PolicyBundle contract on every chat-completion call (deployment + each declared tool), forwards allowed calls, 403/409s denied ones, emits tool_invocation_* to audit-stream-py. Bicep IaC included. Puts the Suite's governance on the data path enterprises actually run AI on. |
| Live | Repo | What it does |
|---|---|---|
aeo.kineticgain.com |
aeo-visualizer |
Dedicated AEO Protocol web visualizer |
kinetic-gain-visualizer |
kinetic-gain-visualizer |
Unified visualizer — auto-detects the spec from the top-level *_version field and renders the appropriate view. Eleven specs auto-detected; five views: Visualize / Editor / Architecture / Tools / About |
examples.kineticgain.com |
kinetic-gain-examples-gallery |
Examples gallery — sidebar of 11 specs, click any to see its canonical example rendered with JSON syntax highlighting |
walker.kineticgain.com |
well-known-walker-web |
well-known-walker — paste any domain, see every Kinetic Gain disclosure document it publishes |
bench.kineticgain.com |
prompt-injection-bench-web |
prompt-injection-bench visual harness |
The unified visualizer + unified MCP server give the Suite a complete read-side (human) and tool-side (agent) entry point. Eleven specs, two front doors, and a growing operator subdomain network.
| Repo | What it does |
|---|---|
well-known-probe-js |
Zero-dependency vanilla JavaScript probe for all eleven Suite documents at any domain's /.well-known/ paths. Runs in browser + Node 18+ + Deno + Bun. Returns a 0-100 disclosure score + tier + per-spec found/missing. Discriminator-aware (a 200 of the wrong JSON shape doesn't count). The shared core of the Vendor AI Disclosure Inspector. |
kineticgain-vendor-inspector |
Browser extension (MV3) + Greasemonkey userscript that score what AI governance documents any vendor publishes at /.well-known/, right from the toolbar (extension) or as an on-page corner badge (userscript). One shared probe core, two distribution surfaces, a build step that keeps both in sync. The client half of the distribution lane — Procurement Pulse runs the same probe server-side. |
| Repo | What it does |
|---|---|
prompt-injection-bench |
30-attack prompt-injection corpus + Python harness. Every record back-references the Agent Card refusal_taxonomy[].category it tests, so a vendor can mechanically verify declared refusals hold under attack. Failed runs feed AI Incident Cards. Not a 10th spec — the testing-counterpart to the disclosure layer. |
Reliability primitives. Each independent. All designed to compose:
| Repo | Lang | Surface | Buyer |
|---|---|---|---|
rate-limit-shield |
Python | Token bucket + circuit breaker + jittered retry, HTTP 429 / Retry-After awareness | SRE |
identity-mesh |
Python | SPIFFE-style JWT-SVID broker — short-lived tokens, audience binding, zero long-lived keys | CISO |
agent-canary |
Python | Progressive rollout, shadow mode, sticky-percent routing, auto-rollback | Platform / SRE |
model-registry-pro |
Python | Model lifecycle catalog: lineage, stage promotion, approval gates | Platform / MLOps |
slo-budget-tracker |
Python | SLO + error-budget library, FastAPI middleware, Prometheus exporter, multi-window burn-rate alerts | SRE |
reliability-toolkit-rs |
Rust | Async Tokio primitives: token-bucket rate limiter · 3-state circuit breaker · exponential-backoff retry with jitter · bulkhead | SRE / Platform |
feature-flag-rs |
Rust | Server-side feature flag eval — targeting rules, sticky percentage rollouts (SHA-256 bucketing, no RNG), hot reload | Platform / SRE |
request-shadow-rs |
Rust | Async request mirroring with sampling + divergence detection — fires both legs concurrently, returns the primary while collecting a structured diff. The SRE primitive for safe migrations | SRE / Platform |
audit-stream-py |
Python | Append-only governance event stream for the whole portfolio. Hash-chained for tamper-evidence, SSE for live tailing, REST for queries. Every other portfolio repo is a producer. Platform Reliability Stack #10 — the 10+ target is hit. | SRE / Compliance |
Identity at the edge → rate limits at the model → canary at deploy → registry as source of truth → SLO budget at the API surface → Rust primitives for hot paths → feature flags for rollout control → shadow traffic for migrations → tamper-evident audit log. Defense-in-depth for the agent era.
Production-shaped backend services in the right language for the problem. 15+ languages across one coherent platform.
| Language | Repo | What it does |
|---|---|---|
| Go | edge-policy-enforcer |
Edge request governance, bot handling, redirect control |
| Go | latency-budget-enforcer |
Latency budget enforcement, dependency drag review |
| Rust | crawl-anomaly-detector |
Crawl log anomaly scoring, indexing risk review |
| Rust | support-escalation-router |
Support queue escalation, SLA pressure scoring |
| Java | compliance-event-ledger |
Spring Boot immutable compliance event history |
| C# | tenant-isolation-guard |
ASP.NET Core tenant-boundary policy evaluation |
| C# | approval-workflow-orchestrator |
ASP.NET Core approval routing, SLA-aware escalation |
| Kotlin | release-readiness-gatekeeper |
Release gate evaluation, dependency readiness scoring |
| Kotlin | reliability-policy-coordinator |
Dependency drag review, error-budget policy |
| Scala | policy-decision-simulator |
Policy simulation for governance scenarios, launch gates |
| Elixir | incident-handoff-broker |
Incident routing, SLA-aware handoff scoring |
| Ruby | message-retention-guardian |
Retention policy enforcement, legal hold protection |
| PHP | entitlement-request-portal-api |
Entitlement requests, approval routing, access review |
| Dart | mobile-briefing-companion |
Flutter mobile app for executive briefings, signal summaries |
| Terraform | platform-foundation-blueprint |
Multi-environment networking, IAM blueprint |
| Go | grpc-mesh-shadow |
gRPC shadow traffic mirroring, divergence detection, sampling |
| Go | miz-otel-pack |
OpenTelemetry SpanProcessor — GenAI spans → business cost/latency spans |
| Rust | wasm-policy-gateway |
WASI policy engine — geo + rate-limit + A/B routing, ~128 KB module |
| Rust | bls-attestation-broker |
BLS12-381 aggregate signatures for multi-signer attestation |
| Zig | zig-agent-graph-db |
In-memory directed graph for agent context, stdlib only |
| Haskell | haskell-policy-engine |
Type-safe policy DSL with Hspec + QuickCheck properties |
| Python | embedding-drift-graph |
Track cosine drift of entity embeddings across encoder versions, GraphQL API |
| Python | audit-graph-explorer |
Neo4j + Cypher relationship-driven audit analysis |
| Python | secret-rotation-scheduler |
Secret rotation windows, owner prompts, stale-secret detection |
| Python | warehouse-reconciliation-engine |
Source-to-warehouse drift detection, finance-grade reconciliation |
| Python | data-quality-guardrail |
Schema drift, freshness lag, null spike detection |
| dbt + DuckDB | dbt-search-observatory |
Search console, crawl, index coverage, freshness modeling |
| SQL Warehouse | search-observability-warehouse |
Crawl analytics, indexation, technical SEO observability |
Production-shaped governance and observability for AI / LLM workloads:
mcp-sentinel— MCP server observability + security auditrag-sentinel— RAG quality / drift / hallucination signalsagentobserve— Datadog-shaped operator surface for agent fleetsagent-codex— governance-as-code: SOC 2 / EU AI Act / ISO 27001 / NIST mappingsagent-eval-arena— eval harness with regression detection + CI gatesagent-router— LLM router with provider-aware routing and breakersllm-redaction-gateway— PII + secret redaction for LLM API callsshadow-ai-detector— unauthorized LLM usage detectionai-finops-radar— token-level cost attribution + anomaly detectionkinetic-flightdeck— unified AI Platform Engineering ops console
| Repo | Lang | What it does |
|---|---|---|
procurement-decision-api |
Python | First cross-ecosystem bridge in the portfolio. Drafts AI Procurement Decision Cards from a buyer rubric and vendor Suite documents (AEO + agent-card + tool-card + ai-evidence + …). Connects Kinetic Gain Protocol Suite (spec #11) with Decision Intelligence. Pydantic v2, FastAPI, httpx async, NIST AI RMF crosswalk linked from the OpenAPI spec. |
policy-as-code-engine |
Python | Companion to procurement-decision-api. Declarative policy evaluator — JSON/YAML rules, first-match-wins, deny-trumps-allow. Headline: POST /bundles/from-decision-card turns a Decision Card's conditions into a runtime-enforceable PolicyBundle. Closes the loop from "buyer signed off" to "request gated." |
incident-correlation-rs |
Rust | Walks the Suite graph from an AI Incident Card and emits a structured remediation plan. BFS over typed SuiteEdges; DecisionCard → RecheckPolicy, Vendor → RequestReview, AEO/agent/tool → Revalidate. petgraph under the hood. The piece that turns "we had an incident" into "here's exactly what to touch next." |
briefing-intelligence-engine |
Python | Executive briefing scoring, narrative generation, risk ranking |
signal-orchestration-lab |
Python | Dependency-aware signal routing, escalation sequencing |
decision-memory-engine |
Python | Decision history, rationale recovery, stale assumption tracking, and revisit posture |
evidence-ranking-engine |
Python | Evidence packet ranking by trust score, freshness, contradiction pressure, and citation density |
Executive dashboards, control planes, decision studios — organized by domain:
Executive & Portfolio
executive-briefing-studio · portfolio-command-center · executive_operations_dashboard · scenario-planning-atlas
Revenue & Growth
customer-intelligence-graph · growth-systems-control-room · revenue-forecasting-workbench · attribution-intelligence-studio · pricing-experiment-studio · conversion-funnel-intelligence-hub · deal-desk-workspace
AI Governance & Risk
ai-governance-review-studio · model-risk-oversight-hub · vendor-risk-operations-center · compliance-workflow-hub · ai-operations-console
Identity & Security
identity-command-center · identity-lifecycle-workbench · security-posture-control-room
Workflow & Operations
workflow-orchestration-studio · feature-flag-rollout-studio · ab-testing-command-center · customer-journey-control-plane
Spec-first OpenAPI services:
Identity-Access-Audit-API · observability-incident-command-api · customer-health-churn-api · partner-lead-distribution-engine · content-workflow-intelligence-platform · experimentation_insights_kpi · seo-governance-platform · webhook-ingestion-pipeline · kinetic-api-gateway · revenue-ops-ai-assistant
The newer CMS lane is not brochure work. It is governance, preview trust, query discipline, cache freshness, schema safety, and contract protection for headless WordPress estates:
wordpress-block-seo-governance-auditor · wordpress-graphql-governance-gateway · headless-seo-fallback-engine · headless-preview-recovery-kit · wpgraphql-query-cost-inspector · frontend-contract-testing-for-wordpress · headless-editorial-command-center · headless-wp-vue-starter · wpgraphql-schema-diff-gate · wordpress-cache-invalidation-map · wordpress-preview-trust-monitor · wp-kinetic-gain-audit
This cluster now covers answer-surface safety, preview recovery, metadata fallback, query cost, frontend payload contracts, editorial release readiness, schema-drift approval gates, cache invalidation mapping, preview trust monitoring, and — via wp-kinetic-gain-audit — a tamper-evident MySQL hash-chained governance audit log that plugs WordPress straight into the Suite's audit-stream-py spine.
Commercially legible systems work across access review, evidence plumbing, connector testing, workflow infrastructure, and HR-to-identity provisioning:
cyberark-access-review-sync · cyberark-connector-observability-exporter · servicenow-cyberark-evidence-pipeline · ibm-custom-connector-starter · ukg-to-scim-provisioner · camunda-connector-test-harness
| Repo | What it does |
|---|---|
data-contract-registry |
Schema registry for data contracts. Semver versioning, compatibility checks (backward / forward / full), declared owners, freshness SLAs. Bridges to procurement-decision-api via POST /contracts/owners/from-decision-card — buyer + decision_maker from a Decision Card become the contract's paging targets. Cross-ecosystem hook #3. |
csv-data-quality-rs |
Rust streaming CSV validator against a data-contract-registry contract. Async, row-by-row, structured violation report (required / bad_type / enum_mismatch / column_count_mismatch / invalid_json). Memory cost is proportional to max_samples, not file size. Cross-ecosystem hook #4. |
sql-contract-enforcer |
Cross-dialect DDL from a data contract — CHECK / NOT NULL / UNIQUE / PK / FK for Postgres, MySQL, Snowflake, BigQuery (dialect-aware: BigQuery demotes CHECK/UNIQUE to comments + PK/FK to NOT ENFORCED; Snowflake informational; MySQL VARCHAR lengths). Plus a contract-vs-schema violation checker for CI. Cross-ecosystem hook #5 — enforces at the table boundary what the registry declares and csv-data-quality-rs validates row-wise. |
revops-database-lab |
PostgreSQL revenue modeling lab. |
revenue-intelligence-db |
Attribution + forecast + renewal-risk reporting. |
cloud-cost-intelligence-dashboard |
Cloud cost intelligence dashboards. |
semantic-metrics-catalog |
Governed metric definitions, ownership lanes, semantic contracts, and freshness posture. |
attribution-warehouse-lab |
Warehouse-first attribution modeling, path analysis, and governed revenue-credit logic. |
pg-audit-stream-extension |
Postgres extension (PL/pgSQL) that emits audit-stream-py-compatible governance events on watched table CRUD via pg_notify, plus a Python LISTEN bridge daemon. Database-tier governance — the spine's 8th producer, catching DML the application path would miss. PG14-17, CI green. |
procurement-pulse-engine |
The crawl + aggregate engine behind pulse.kineticgain.com. Probes a universe of vendor domains for all 11 Suite documents (vendored well-known-probe core), aggregates publication rate by vertical + per-spec + leaderboard. Issue #1 ran the first real baseline: 0.0% across 37 domains — the honest starting line. |
| Layer | Tools |
|---|---|
| Languages | Python · TypeScript · Go · Rust · Java · C# · Kotlin · Scala · Elixir · Ruby · PHP · Dart · Swift · Zig · Haskell · SQL · HCL · dbt |
| Backend | FastAPI · Express · Spring Boot · ASP.NET Core · Javalin · Cowboy/Plug · WEBrick |
| Frontend | React 19 · Vue 3 · Flutter · TypeScript · Vite · Tailwind · Recharts · Motion |
| Data | PostgreSQL · DuckDB · dbt · Neo4j · Pandas · Pydantic |
| AI / Platform | SPIFFE zero-trust identity · governance-as-code · LLM routing · token-cost attribution · OpenAPI specs · MCP servers · OpenTelemetry GenAI · BLS aggregate signatures · WASI · spec authorship |
| CI/CD | GitHub Actions · FTP auto-deploy · Hostinger · AGPL-3.0 licensing |
Open to Director / Principal-level Platform Engineering, Web Engineering, or AI Platform roles at enterprise B2B SaaS companies. East Coast time zone. Remote-friendly.
"Long-lived credentials are tomorrow's incident reports. Build short-lived. Audit always. Document once."
All active repositories · Career one-pager
Connect: LinkedIn · Kinetic Gain · Medium · Skills

