Research focus · Governed autonomous AI

How much authority can an autonomous agent hold while remaining auditable, verifiable, and revocable?

I research the architecture, security, and governance of autonomous and distributed AI systems — with a focus on Agentic AI, multi-agent systems, Edge AI, Zero Trust, Continuous GRC, and Evidence-as-Code.

Independent Researcher · Brazil ORCID 0009-0008-2411-6995 Software & systems career since 1977
01Research

Governed autonomous intelligence

My work examines the control problem that emerges when AI systems move from recommendation to action: they acquire identities, tools, credentials, delegation paths, and the ability to affect external systems. The objective is useful autonomy under explicit, enforceable, auditable, and revocable limits.

01.1

Agentic AI & Multi-Agent Systems

Architectures for agents that plan, delegate, collaborate, and act across distributed environments while preserving traceable chains of authority.

01.2

AI Security & Zero Trust

Identity, authenticated delegation, runtime policy enforcement, bounded authority, revocation, and explicit trust boundaries between autonomous components.

01.3

Governed Autonomous Edge Intelligence

Autonomous intelligence operating across hybrid edge–cloud infrastructures where latency, intermittent connectivity, and local action complicate centralized control.

01.4

Continuous GRC & Evidence-as-Code

Governance, risk, compliance, and assurance evaluated continuously as properties of the system rather than treated as periodic administrative activities.

02SGAEIA

Secure Governed Autonomous Edge Intelligence Architecture

SGAEIA is an open reference architecture and research program for autonomous and distributed AI systems. It investigates how bounded and revocable authority, authenticated delegation, Zero Trust, Continuous GRC, and Evidence-as-Code can make autonomous operation auditable and governable by design.

Bounded AuthorityUseful autonomy requires explicit limits on authority.
Authenticated DelegationDelegated authority remains attributable, constrained, and traceable.
Zero TrustConsequential interactions are explicitly verified rather than implicitly trusted.
Revocation by DesignAuthority can be withdrawn as deliberately as it is granted.
Continuous GRCGovernance, risk, and compliance remain active at runtime.
Evidence-as-CodeGoverned operation produces machine-verifiable evidence.
03Publications

Selected research publications & artifacts

A selection of archival research records and artifacts. Zenodo records provide persistent identifiers for citation and long-term access.

Explore the SGAEIA Zenodo Community
04Writing

Research notes & essays

Selected research essays and technical notes on autonomous AI, AI security, governance, multi-agent systems, and the SGAEIA research program.

2026

Continuous GRC for Agentic AI

Governance, risk, and compliance as continuous runtime processes for autonomous agents.

Medium
SGAEIA Research Series
See all writing on Medium
05About

A long view of software systems — informing research on autonomous AI

My career in software and information systems began in 1977. It has spanned embedded software, mainframe environments, distributed computing, enterprise systems, web and e-commerce platforms, IT infrastructure, and modern software architecture.

Across that trajectory, I have worked in software development, systems architecture, technology management, project management, and strategic transformation, including large-scale ERP/MRP, e-government, industrial IT, LAN/WAN infrastructure, and enterprise modernization.

I am the author or co-author of four books in Portuguese: Bug do Milênio — Antes, Durante e Depois; Dominando a Tecnologia de Objetos; Desvendando o Pregão Eletrônico; and Sistemas de Informação na Administração Pública.

That long view — from centralized systems to distributed and increasingly autonomous architectures — directly informs my current research on Agentic AI, multi-agent systems, AI security, Zero Trust, Continuous GRC, and SGAEIA. This site documents that work, its archival publications, and related technical writing.