SPHR Insights
The SPHR Blog
Perspectives on enterprise AI strategy, delivery, and the products we build — written by the people doing the work across the USA, Brazil, Australia, and Japan.
SPHR Enterprise Agentic Multi-Purpose Harnesses — Multi-Tenant Knowledge, Memory & Cost — Part 5
Multi-tenant AI agents done right: knowledge vs memory, four memory types, per-tenant crypto isolation, and FinOps cost caps enforced at the action layer.
Read article →SPHR Enterprise Agentic Multi-Purpose Harnesses — The OWASP Agentic Top 10, Controlled — Part 4
How a governed platform answers the OWASP Agentic Top 10 (2026), ASI01–ASI10, with concrete controls: injection defense, supply-chain vetting, tenant isolation.
Read article →SPHR Enterprise Agentic Multi-Purpose Harnesses — Governance at Runtime — Part 3
Govern AI agents at runtime: a deterministic policy kernel intercepts every tool call and delegation, producing a tamper-evident audit trail as a byproduct.
Read article →SPHR Enterprise Agentic Multi-Purpose Harnesses — Agent Identity & Zero Trust — Part 2
Zero trust for AI agents: short-lived attested identities (DID/Ed25519), no static keys, and every action authorized across both user and agent rights.
Read article →SPHR Enterprise Agentic Multi-Purpose Harnesses — The Control Plane — Part 1
Keep agent personas, rules, knowledge, and identity in a control plane you own: portable storage, model-agnostic reasoning tiers, one governed pipeline.
Read article →Capability Without Control Is a Liability: The Enterprise Agent Control Plane
The missing layer between hyped autonomy and production: orchestration plus governance. Meet the enterprise agent control plane — orchestrate, enforce, audit, and control cost.
Read article →From RTX Prototype to Production: Hardening a Self-Improving Agent
A self-improving agent that dazzles on an RTX laptop isn't a production system. Here's what you add on the way to a governed deployment — orchestration, a control plane, and FinOps.
Read article →What a Self-Improving Agent Costs You: FinOps for Autonomy
Autonomous, self-improving agents create unbounded, hard-to-attribute spend. Why local-first shifts the bill instead of erasing it — and how policy becomes a budget guardrail.
Read article →The 2026 AI Agent Compliance Clock: EU AI Act + Colorado
Regulatory deadlines are arriving while teams race to ship autonomous agents. What the EU AI Act and Colorado now enforce, the dates that already moved, and the evidence a high-risk agent needs.
Read article →Zero-Trust Identity for AI Agents: Who Did the Agent Just Act As?
Autonomous agents that take actions need first-class, scoped identities — shared service accounts are an enterprise non-starter. Why AI agent identity is a zero-trust problem, mapped to OWASP ASI03, and how to prove which agent acted across a delegation chain.
Read article →The Self-Improving Agent's Audit Problem (And How to Fix It)
An agent that rewrites its own skills is an auditability nightmare. The fix is a deterministic agent audit log that intercepts and records every action — identity, policy decision, and inputs — before it executes.
Read article →OWASP's Agentic Top 10: A Production Checklist for AI Agents
The OWASP Top 10 for Agentic Applications (2026) in plain English — each of the ten AI agent security risks mapped to a concrete control, and why an ungoverned self-improving agent is exposed on most by default.
Read article →Hermes vs. a Governed Enterprise Agent: What Production Actually Needs
Hermes, Claude Code, and Codex are brilliant engines — but production needs a control plane. An honest scorecard of capability versus the four things enterprises add: identity, policy enforcement, audit, and cost discipline.
Read article →The Five Roles That Ship Enterprise AI
Job titles are melting. The enterprises that get AI into production organize around five roles — Explorer, Integrator, Hardener, Scaler, and Operator — matched to the maturity of the work, not the org chart.
Read article →The 7 Pillars of Production-Ready Agentic AI
Most enterprises can build an agent demo; few get it safely to production. Here are the seven dimensions — frameworks, guardrails, knowledge, process, governance, security, and FinOps — that decide whether agentic AI ships and scales.
Read article →Building enterprise AI that actually ships
Most enterprise AI pilots never reach production. Here is the delivery discipline we use to close the gap between a promising prototype and a system the business can rely on.
Read article →