Whit Calloway
Writes as the operator who signed the cheque and had to explain the result. Names dollar tradeoffs and admits which end of the pipe got funded wrongly.
Posts by Whit
Hiring verified one person and employing another
Identity is verified once, at onboarding. Everything after that is a session on a corporate laptop, and nothing re-establishes who is at the keyboard.
Instant rails, instant irreversibility: what RTP and FedNow remove
Traditional wires left a window in which a fraud desk could attempt recall. Instant credit transfers settle irrevocably in seconds, which eliminates the recovery step mos
The race to standardise verifiable user instructions for AI agents
Four groups are trying to standardise how a human authorises an agent action. They disagree about what gets signed — and that disagreement, not the cryptography, decides
Agent-to-agent delegation depth: where enterprise authority should stop
A human approves an agent. That agent spawns sub-agents, which invoke tools, which call services. By hop four the authority in play has no recognisable relationship to wh
Third-party OAuth consent: the integration somebody approved in 2023
An admin approved a third-party application's tenant-wide access years ago. The grant persists, the scopes were never re-evaluated, the approver may have left, and t
Contractors have no HR record: the identity lifecycle nobody owns
Employees are created and terminated by HR events. Contractors, vendors, auditors and partners are created by a ticket and terminated by someone remembering, and their id
When the video recording stops being evidence
Remote notarisation rests on a recorded session as its audit artefact. Recordings prove that a session occurred and are becoming weak proof of who was in it.
Commercial lease deposits: large transfers with no closing table
A commercial tenancy begins with a six-figure transfer coordinated by brokers over email. Unlike a property purchase, there is no title agency, no escrow, and no verifica
Workforce identity assurance that collects no biometric data
Biometric privacy statutes attach liability to collecting, storing and transmitting biometric identifiers. A platform authenticator does none of those things, which chang
When every credential a candidate presents can be manufactured
A CV, a professional profile and a code repository are all self-asserted artefacts. Generating convincing versions of all three is now cheap, which removes the screening
Withdrawal is the only moment that matters: allocating friction where value is
Operators apply their heaviest identity friction at registration, where the player is least committed and most likely to abandon, and their lightest at withdrawal, where
Signing the MFA question is a representation someone will test
'Is MFA enforced everywhere?' is answered yes by almost everyone. After an incident, the insurer examines whether it was true, and 'everywhere' turns
The custody API is the perimeter, and it authenticates a server
Institutional custody platforms allow programmatic withdrawals within configured policy. The credential making those calls sits on a server, and a server can be compromis
Splitting the key does not decide whether to sign
Multi-party computation removes the single point of key compromise. It says nothing about whether the transaction being signed is the one anyone intended.
The CI runner that can rewrite your entire cloud estate
Infrastructure pipelines hold the broadest credentials in most organisations, apply changes automatically, and have no step where a human commits to the specific change b
The customs power of attorney: filing in an importer's name without an importer's signature
A customs broker files entries in an importer's name on the strength of a power of attorney signed years ago, sometimes by someone who has left the company. The impo