Monolith-to-microservices migration with kill thresholds, immutable audit logs and an Agent Accountability Envelope — every architectural choice carries an ADR.
The model is the easy part. The plumbing is what kills you.
70% of AI pilots die before production — at the governance layer, not the model layer. I build the layer that ships: identity, auditability and kill switches for agents operating under real regulators.
Most governance consultants have zero real deployments. The receipts are the moat — four regulated systems, in production.
Four regulated systems, shipped.
Each one anchors a pillar of the method. Figures are as delivered — attribution is fixed, never reassigned.
End-to-end immersive AV and AR/VR estate synchronised from a central control engine, on sovereign data residency with 24/7 kill-switch monitoring and a 5-year O&M term.
An EU AI Act classification and roadmap with GDPR guardrails and human authorization gates on high-stakes actions — velocity preserved, exposure contained.
A multi-agent pipeline governed by telemetry that auto-suspends on runaway loops, cost spikes and error spikes — autonomy with a hard backstop.
The 6 Pipes — governance topology.
We isolate model processes inside strict containment layers — shielding your core databases from hallucination and runaway execution cost. Four non-negotiables, built on six pipes.
Intelligence is rented. Piping is owned.
No agent inherits broad admin privileges. Every system runs least-privilege service accounts with strict database limits and zero default write permissions.
Every decision, database query and citation is logged on a read-only ledger. Any AI action is traceable — and reversible — in under 30 seconds.
Continuous monitoring evaluates speed and error volume. If the agent begins looping or spends too much, it suspends automatically — before damage.
High-stakes actions pause immediately and wait for manual approval. The agent cannot execute financial or legal tasks on its own.
Old core mainframes sit behind strict gateway layers. The agent works with insulated, hashed data feeds — never the direct core databases.
Every workflow error and human override is documented. Each one updates the system's core rules via ADR — an evolving defense moat, not patching.
THE 6 PIPES — GOVERNANCE TOPOLOGY
├── NON-NEGOTIABLES (Pipes 1–4)
│ ├── 1. Constrained Identities -> least-privilege service accounts
│ ├── 2. Attributable Actions -> logged, reversible, traceable <30s
│ ├── 3. Kill Threshold Monitoring -> telemetry + auto-suspend on breach
│ └── 4. Human-in-the-Loop Gates -> high-stakes actions pause for a human
└── ENTERPRISE-FIT (Pipes 5–6)
├── 5. Legacy Insulation -> API gateway wraps legacy systems
└── 6. Learning Loop -> ADR-driven evolution, not patching
The 10-20-70 model.
Why agentic AI requires more than algorithms. The visible model is the tip; the value — and the risk — sits below the waterline, in the data, the operating model and the governance. The 6 Pipes live in the 90% you can't see.
- Agentic reasoning and decision logic
- Model selection & prompt design
- Agentic-AI-ready data foundations
- Business-context services
- Orchestration, monitoring & lifecycle tooling
- North Star & strategy for agent execution
- Agentic-AI-first process reimagination
- Roles, responsibilities & ecosystem partnerships
- Talent enablement, culture & change management
- Responsible use of data and AI agents
Active Infrastructure Board.
Test the physical safety valves. Simulate a runaway cost loop, or trigger a divergence error to see how the system halts before delivering bad outputs.
Three tiers. One conversation.
Read-only audit, full implementation, or end-to-end orchestration. Scoped to the size of the system, not the hours.
Read-only audit, EU AI Act classification and a risk register. The artifact a board can act on.
The four pillars built into production systems — constrained identities, attributable actions, gates and kill thresholds, live.
Multi-system, multi-client governance across the full lifecycle — the operating layer for an enterprise agent estate.
The method in long form — and in your runtime.
The four pillars written long-form, each chapter anchored to one verified deployment. The 70% pilot-death problem, and the four non-negotiables that decide whether AI ships.
Read the framework →The open-source layer that enforces the four pillars in your agent runtime. aiplumber.dev is the consultancy and the method; Kleiber is the installable proof.
Install the layer →Regulatory currency: EU AI Act high-risk (Annex III) obligations apply from 2 August 2026 (operative date; subject to pending Digital Omnibus revisions — verify current status before relying on it).