Blog

Notes from the team.

Thoughts on AI, how we build it, and what we are learning as we build MITRA.

Posts

Five posts, published together as our first set. Each one covers something we have actually debated and decided while building MITRA, written up rather than just claimed. None of them is backdated.

What a defensible AI agent audit trail looks like

· Governance

Logging is not evidence. The six properties that separate the two, why tamper-evident is the honest word rather than tamper-proof, and the recordkeeping rules that already reach agent-generated records.

What model portability actually requires

· Architecture

An abstraction layer is the easy coupling to remove. The five that actually decide whether you can change providers, why silent fallback is a design error sold as a feature, and the difference between provider resolution and a policy engine.

Hosted, private endpoint, or self-hosted

· Architecture

Open weights are a licensing property, not a privacy one. Six deployment cells, three claims to stop making, and why country-based routing is not a data-residency guarantee.

Why AI pilots stall at the security review

· Delivery

Pilots rarely die from bad model output. They die at review, on four shortcuts that are reasonable in a pilot and inadmissible in production. The eight questions that decide it.

Measuring a site with no analytics

· Practice

This site loads no third-party scripts at all, so there is no analytics tag to read. What Search Console and CDN access logs still tell you, what they genuinely cannot, and the discipline the constraint forces.

Where this comes from: the AI practice · financial services · how an engagement runs