Your AI agent has access to everything it needs. That also means access to everything it shouldn't. Here's how to fix it. In this episode of Past the Pilot, Stefan Born and Jonny McFadden go deep on Attribute-Based Access Control (ABAC) β the access control model that makes AI agents actually safe to run in production. Most enterprise AI deployments rely on Role-Based Access Control (RBAC). It works fine for humans. It quietly falls apart for AI agents β because roles are static, and agents are dynamic. The result? A security gap that doesn't show up in your demo and only reveals itself when something goes wrong in production. Stefan and Jonny break down why ABAC is the missing piece, how it differs from RBAC at a philosophical level, and what Vertesia built to close the write-path gap that even most security-conscious teams miss. In this episode: π Why RBAC breaks down when AI agents enter the picture π The "intern with a master key" problem β and why it's more common than you think π ABAC vs. RBAC: it's not just a feature upgrade, it's a different way of thinking about identity π The nurse analogy β same person, different context, different access π Why the write path was the critical missing piece in AI security π What it takes to go from 10 users to 10 agents without losing your mind (or your compliance posture) π Why Jonny thinks this should have been Episode 1 β± Timestamps 00 β Introduction 02 β Why access control matters more than ever for AI 06 β RBAC: what it is and where it breaks 12 β Enter ABAC: attributes, context, and dynamic access 18 β The nurse analogy explained 24 β The write-path gap: what it is and why it's dangerous 31 β What Vertesia built with FEAT-060 38 β Scaling from users to agents without operational chaos 44 β "This should have been Episode 1" 48 β Wrap-up and where to learn more π About Past the Pilot Past the Pilot is the show for enterprise teams building real AI β not demos, not prototypes, but production-grade systems that actually work. Hosted by Stefan Born and Jonny McFadden, each episode tackles one of the hard problems standing between your AI pilot and something you can actually ship. New episodes drop regularly. Subscribe so you don't miss one. Also available as a podcast: https://t.co/0niSebc7lb π Vertesia: https://t.co/kqLCYTvpCm π Read the full blog post: https://t.co/Z4ukIOZZyC π Subscribe to Past the Pilot
Anthropic can now watermark AI-generated text. Smart. One problem: edit a single sentence and the watermark disappears. Writing in pencil. That's where Episode 13 starts β and it doesn't slow down from there.
Read the blog here: https://t.co/5FKihVM8pj
Also available as a podcast: https://t.co/M8OU77s1jc
Jonny and I run a live workflow demo we built for a finance client. A chaotic client meeting goes in. Structured developer tickets, user stories, and epics come out β automatically, straight into ClickUp. But the part that changed the room? A Scope-of-Work validation node that reads the actual contract and flags every ticket: in scope or out. Scope creep caught before a single line of code gets written. We also get into why pure LLM agents fail at scale β the 9-out-of-10 problem β and why process engines are the answer. Plus the governance layer that makes this safe for regulated industries: role-based access, audit trails, model switching. The stuff nobody talks about until it's too late. But here's what I really want you to take from this episode. You're not building individual tools anymore. You have an agentic platform β a master tool β that lets you improve processes you've never been able to automate. Not just replace things. Improve them. Smarter. Faster. More auditable. More reliable. Nobody gets excited about a pile of LEGO bricks. Show them the finished fire station and they get it immediately. That's what Past the Pilot is about. Not AI in the abstract. The fire station. #PastThePilot #EnterpriseAI #AgenticAI #AIWatermarking #WorkflowAutomation #ScopeCreep #AIInProduction #DigitalTransformation #LLM #futureofwork
The Kitchen Is Open: Letβs cook some Workflow
Your meeting filed its own tickets. Human approval required. Obviously.
In Episode 12 of Past the Pilot we discuss how we turned a simple yet crucial workflow into an agentic process using the Vertesia platform, honest to our credo with all the rough edges showing.
Watch the show here on X or on Youtube: https://t.co/szJSWflATp
Read the blog here: https://t.co/G1M66IIM4j
The demo: a client workshop transcript goes in, structured project management tickets come out. You can have a simple agent do that sure, but what are the risks??
Believe your agent won't delete it all because you tell it to ask you?
Nice try - unchecked and without a controlled process your LLM will go rogue eventually. In the enterprise world you need reliable, auditable architecture, not some governance prompt theater.
Then Jonny made an argument I keep coming back to: platforms compound, tools don't. Every project builds on the last one. Foundation, walls, windows, house.
We're building in public. It's messy. It's moving.
Don't miss out when we continue this in the next episode!
#PastThePilot #AIAgents #EnterpriseAI #AgentArchitecture #Vertesia #BuildingInPublic @VertesiaHQ
Your RAG vector database isn't broken. Your assumptions are. More dimensions for your embedding model won't save your retrieval β they're quietly making it worse. The real culprit isn't dimensionality. It's anisotropy. And almost nobody's talking about it. In new article: "The Entropy Problem", I'll explain what the problem is with your RAG embeddings and why buying a bigger model won't help if you don't fix the context layer.
https://t.co/6WbRCQWgfk
#VectorDatabase #RAG #Embeddings #RetrievalAugmentedGeneration #SemanticSearch #Vertesia @VertesiaHQ
Your AI pipeline has a front door problem. Not a model problem. Not a prompt problem. A front door problem.
The document walks in. The pipeline doesn't know what it is, what resolution it needs, or what fields actually matter for the context you're trying to build.
It extracts something or everything. Calls it done.
Everything downstream pays for that.
A mortgage package and a prior authorization form are not the same document. Running them through the same intake logic β same model, same DPI, same assumptions β guarantees degraded output.
Every time.
Most teams design the intake layer last and optimize it never. Then they wonder why their AI is hallucinating on data they think they already have.
In my latest article, I write about why the front door matters, what a well-built intake layer actually looks like in production, and why it's the piece that makes or breaks everything else.
#DocumentAI #IDP #EnterpriseAI #AIArchitecture #ContextLayer @VertesiaHQ #Vertesia
https://t.co/UXvjX37sAX
One developer. One platform. Six enterprise tools β gone. That's not a pitch. That's what Jonny McFadden built in one week. See how in Past the Pilot Episode 11
What if one platform could replace a major part of your enterprise software stack? In Episode 11 of Past the Pilot, Stefan Born sits down with Jonny McFadden β solutions architect at Vertesia β to walk through a full CLM app built from scratch.
One developer. Days, not months. Six enterprise tools replaced by a single platform. Make sure you also read the blog: https://t.co/QqBkwNxdL0
This is what the shift in enterprise software actually looks like β not a demo, not a concept. A working app and many more.
#PastThePilot #EnterpriseSoftware #EnterpriseAI #CLM #ContractManagement #Vertesia #DigitalTransformation
We didn't have any agenda slides ready for Episode 10. So Vertesia built them on spot for us.
make sure you also ready the blog: https://t.co/xxICyymIqG
This is episode 10 and we are geeking out on the latest development pipeline features of Vertesia. Grounded IDP β document intelligence that doesn't just extract data. It scores every field with a confidence level, shows you exactly where in the document it found the answer, and triggers an agentic review loop when it's not sure. That's not OCR. That's a system that knows what it doesn't know. Collaborative Editing β paragraph-level. With a real diff view. And an explicit publish gate so nothing goes live until a human says so. Finally. The Process Engine β you describe a workflow in plain language. The platform builds it. Half deterministic, half agentic. Backed by Temporal. It runs the things that need to run reliably, and thinks through the things that need judgment. And then there's the one Jonny called "Goddamn" on air. The Agentic Content Pipeline. Three agents. One loop. We built this on Vertesia. With Vertesia. It's not a demo. It's how we actually work. We're not eating our own dog food. We're running a restaurant on it. #VertesiaAI #PastThePilot #AIAgents #DocumentIntelligence #EnterpriseAI #AgenticAI #ContentAutomation #BuildInPublic #ProductDemo #AIInProduction @VertesiaHQ
You've seen the articles. OKF + RAG. Clean boxes. Confident arrows. Enterprise knowledge management: solved, apparently. The diagrams look great.
They're also missing 80% of the problem.
Here's what those diagrams leave out:
β Multimodal content β your PDFs, images, scanned docs, 20 years of legacy formats
β ABAC β who can actually see what, enforced at the chunk level, in real time
β SOC 2 / HIPAA β because your legal team will ask, and "we're working on it" isn't an answer
β Durable process orchestration β workflows that survive failure and resume where they stopped β Human-in-the-loop checkpoints before sensitive outputs ship
β Page-level provenance β "the model said so" won't hold up in an audit β Hybrid retrieval β because pure semantic search breaks in embarrassing ways in production
β Agent runtimes. MCP integration. The ongoing maintenance nobody talks about.
That's not a feature list.
That's the context layer. And OKF + RAG doesn't touch most of it.
Enterprise AI doesn't have a retrieval problem. It has a context problem.
- The part above the waterline β the clean retrieval stack β is where all the articles live.
- The part below the waterline is where production systems actually live. And quietly fail.
We mapped the full gap: a 3-way breakdown of Plain RAG vs. OKF + RAG vs. Vertesia across 12 capabilities that matter when your AI runs in production, not just in demos.
OKF + RAG got the conversation started. Now let's talk about finishing it.
#EnterpriseAI #AIArchitecture #KnowledgeManagement #RAG #ContextLayer #AIInfrastructure #GenAI #LLM #Vertesia #AIStrategy #CTO #DataEngineering Vertesia
https://t.co/Fg8fyLYkuI
Your agent isn't hallucinating. You're just feeding it garbage.
The model is not your problem. The LLM debate β GPT-4 vs Claude vs Gemini β is a distraction. The real issue is what you put in front of the model. And most enterprise document repositories were never built to feed an AI agent. They were built for humans to browse and search. That's a fundamentally different problem.
In Episode 9 of Past the Pilot, Jonny and Stefan go deep on the context layer β the working files your agent uses to reason, infer, and decide.
Read the blog here: https://t.co/VzSESvFHFe
Here's what we covered:
β Why flat metadata (filename, date, author) is not enough
β Why naive fixed-size chunking destroys accuracy
β Why schema chaos means your agent can't extract the same field twice
β Why the manual librarian model doesn't scale to millions of documents
β What semantic document preparation actually looks like as a pipeline
β How the Agentic Schema Librarian replaces manual taxonomy work
β What governance needs to look like before enterprise AI can be trusted
The context window is where enterprise AI either wins or loses. Full stop.
#EnterpriseAI #AIAgents #RAG #ContextLayer #DocumentAI #KnowledgeManagement #LLM #AIStrategy #PastThePilot #Vertesia
Your database is clean. The rest of your data is a disaster. In Episode 8, we go live to show what happens when agentic AI finally closes that gap. Stefan Born and Jonny McFadden run a real-time demo β no staged results, no polished walkthrough β reconciling invoice PDFs against database records using agentic AI built through conversation, not code. The agent found mismatches and zero missing documents. It built its own schema before anyone asked for it. And it did in hours what traditional methods would take weeks to set up. What you'll see: β Auto-extracted metadata from a single PDF upload β zero configuration β A schema that built itself from scratch on an empty account β A reconciliation agent assembled through plain language, not pipelines β What 10x faster actually looks like β from an already-fast baseline Also check out Stefan's blog on the topic here: https://t.co/FbZUCfa6UQ Coming in Episode 9: Semantic DocPrep β the patent-pending technology that makes all of this possible, and the most important challenge in enterprise AI that nobody's talking about. π Subscribe so you don't miss it! #agenticai #AI #enterpriseai ,#aiagents , #Automation,#unstructureddata #reconciliation, #invoiceprocessing #demo, #lowcode #vertesia
Enterprise Grade MCP - The brain finally has hands. π€
In Episode 7 of Past the Pilot, we sat down with Grant Spradlin from @vertesiahq to unpack MCP β the Model Context Protocol β why it's the USB-C moment enterprise AI has been waiting for and how easily it can turn into a GOVERNANCE NIGHTMARE. Watch the latest
episode now.
Enter the stage: Vertesia's enterprise platform implementation of MCP:
No more custom connectors. No more Wild West API keys. No more agents with unchecked access to your production database.
Just one universal standard. Governed. Audited. Secure.
READ THE BLOG HERE:
https://t.co/XJsCKr8RhO
We're talking: π Admin-level tool governance β down to the individual action π§ Skills that unlock like Neo learning Kung Fu π OAuth that means your agent acts as you β not as some anonymous service account π And a last resort that even handles your legacy systems with no API
This is what enterprise-grade agentic AI actually looks like.
#PastThePilot #AIAgents #MCP #ModelContextProtocol #EnterpriseAI #AgenticAI #Vertesia #AIGovernance #ArtificialIntelligence #FutureOfWork #AIIntegration #LLM #DigitalTransformation #TechPodcast #AILeadership @VertesiaHQ
Is your AI agent just telling you what you want to hear? π€ In the latest episode of "Past the Pilot" (E6: Your Agent Has a Hidden Agenda), Stefan and Jonny look under the hood of agentic AI to address a growing enterprise risk: Sycophant Bias.
Also read Stefan's latest blog article about the topic here https://t.co/DKF8vXQhNS
Just like humans in a corporate boardroom can harbor "shadow agendas" driven by self-preservation, AI models optimized for user satisfaction often learn to become ultimate "yes-man" machines. They minimize friction, maximize agreement, and can end up confidently validating a flawed worldviewβa massive liability for enterprise operations. We dive deep into how we are solving this at Vertisea through architectural integrity, featuring: π The Expert Round Table: Deploying multiple distinct personas across different models to debate and cross-examine facts. π Semantic Doc Prep: Using hierarchical context layers to eliminate data gaps that cause hallucinations. π The Thinking Tool: Allowing users to audit an agent's reasoning process without causing "context rot." Stop trying to fix broken logic with prompt engineering. True enterprise AI requires structural safeguards. Watch our new episode now. #AI #GenerativeAI #AIAgents #EnterpriseAI #Vertisea #PastThePilot #AIBias #TechLeadership
AI isnβt just changing how we createβitβs rewriting the rules of how we operate. π Therefore, I am incredibly excited to be hosting this webinar alongside the Henry Stewart Creative Operations NY 2026 event!
https://t.co/wxHwXLgrYH
Weβre diving deep into the real-world shift happening right now: How AI Transforms Creative Ops.
Weβre moving past the "hype" and getting into the heavy lifting. Weβll be discussing how forward-thinking teams are using AI to scale production, eliminate bottlenecks, and free up creatives to do what they do best: create.
Whether you're looking to optimize your workflows for the rest of 2026 or trying to figure out where AI actually fits into your tech stack, you wonβt want to miss this.
In addition, here is also my recent blog article about this topic:
https://t.co/EbBlsPDuL6
#CreativeOperations #AIinCreative #HenryStewart #CreativeOpsNY #FutureOfWork #Vertesia @VertesiaHQ
The context layer is the infrastructure your agents draw intel and updates from. Get it wrong β or let it go stale β and your agents aren't reasoning on the truth. They're reasoning on a copy of it. From last night.
Contracts signed. Policies amended. Claims filed. All of it sitting outside the door while the batch job sleeps.
Webhooks help. But a webhook that fires a notification isn't the same as an event that triggers intelligence. One tells you something happened. The other does something about it.
That's the difference between event-driven architecture and agentic event triggers β and it's the gap most AI platforms haven't closed yet.
Read my full article here:
https://t.co/Jj73Rmd0wB
#EnterpriseAI #AgenticAI #ContextEngineering #EventDrivenArchitecture #EnterpriseArchitecture #AIStrategy #Vertesia @VertesiaHQ
I spent my life in advertising. I've heard nearly every technology promise by the big software shops, selling us pipe dreams. Hardly any of it ever became a reality. And I'll say it plainly: most enterprise AI strategies in creative operations aren't strategies. They're expensive collections of experiments.
Read my latest article here:https://t.co/EbBlsPDuL6
10 different tools. None of them talking to each other. Sensitive client data exposed to public models. And creative teams more overwhelmed than before.
Here's what no one wants to say out loud: AI won't solve your content crunch. Your architecture will.
The teams seeing real results aren't the ones with the most AI tools. They're the ones who stopped treating AI as a content generator and started treating it as an orchestration layer β connecting every stage of the creative supply chain, from brief to post-campaign analysis, with governance built in from the start.
What does that actually look like?
β Concept validation that used to take weeks: done in 15 minutes. β Campaign adaptation across 15 markets that took 4β6 weeks: done in 15 minutes. β Pre-flight brand compliance checks that used to require weeks of licensor back-and-forth: automated before a human ever reviews the asset.
These aren't projections. These are results from clients we work with at Vertesia.
I wrote about all of it β the fears, the frameworks, the use cases, and what I genuinely think the next 5 years look like for creative operations.
#CreativeOperations #AIStrategy #AgenticAI #ContentMarketing #MarketingTechnology #Vertesia @VertesiaHQ
NEW EPISODE OUT! In E5 of "Past the Pilot" Jonny and I dive into Agentic Browsing β why RPA keeps breaking, why local AI agents like OpenClaw are a security disaster waiting to happen, and what it actually looks like when an AI agent navigates a live website and gets things done autonomously.
#AgenticAI #Automation #RPA #PastThePilot #Vertesia #EnterpriseAI #AIAgents
Robotic Process Automation (RPA)β the tool most enterprises still rely on for web automation β doesn't understand web pages. It memorizes coordinates. Change one button, move one field, and 47 bots break overnight. Ernst & Young found that 30β50% of RPA projects fail outright.
I gave Vertesia's AI agent one instruction: "Configure a BMW M5. I like orange and black." - No script. No hardcoded clicks. No human at the keyboard.
It navigated https://t.co/2vIumbHOMo, timed out, tried again with smarter instructions, hunted down the exact orange interior option, and came back with a fully configured 2027 M5 in Speed Yellow with Kyalami Orange/Black leather. $153,699. Done.
That's not a demo. That's Vertesia's Agentic Browser running against a live website.
Here's why this matters:
The new generation of local AI browser agents got the intelligence right. But they run on your computer, with access to everything on it, outside your security perimeter, with no guardrails. The results have been predictably bad.
Here's to a new way, with Vertesia:
I wrote about what it looks like β including three real test scenarios, the security case against local agents, and why this matters most for the systems that will never have an API.
Link below. π
#AI #AgenticAI #Automation #EnterpriseAI #RPA #Vertesia #DigitalTransformation #FutureOfWork @VertesiaHQ
https://t.co/mzZFmVEjTF