Joey Barkley

I've spent 25 years building, breaking, and defending software systems. These days I think about what happens when autonomous AI agents need identity, access to secrets, and governance — and why the security frameworks we built for humans don't always transfer.

The Sentinel Ridge Files

A practitioner's framework for securing agentic AI, told through a small-town metaphor. Start with Article 1 and read in order.

Article 2

The Town Clerk's Office: How Agent Identity Gets Made

If agent identity is assigned, not inherent, then the authority that assigns it is your most critical trust anchor. In a small town, that's the clerk's office.

Article 3

The Bank Vault: Why Some Data Must Be Categorically Off-Limits

Access control and data sovereignty are fundamentally different security models. A locked office and a bank vault are not the same thing. Organizations need both.