AI and Security Architect

I design production AI systems that have to scale, stay secure and remain operable.

My work spans AI agent architecture, runtimes and harnesses, distributed systems, identity, authorization, secure execution and cloud-native platforms.

That perspective comes from 16+ years building enterprise software, including high-throughput platforms handling millions of requests and operational systems supporting more than one million daily transactions.

I also red-team AI and IAM architectures to identify how untrusted context, compromised credentials, confused-deputy behavior and chained capabilities can turn legitimate access into unintended production effects.

I created Lattice, an open-source capability runtime for structured agent execution, and Covenant Layer, an open protocol for coordinating outcomes through explicit commitments, evidence and settlement.

  • 16+ years building enterprise systems
  • Speaker at the European Identity and Cloud Conference and Medium Day
Hammad Abbasi

Trusted by leading organizations to deliver enterprise-grade solutions that scale

Point Pickup logoAspose logoWalmart logo7-Eleven logoKroger logoDollar General logoSurf Life Saving logoRapid logo
Experience at Scale

Architecture shaped by production systems

I have designed and led enterprise systems across identity, logistics, document processing and AI, from service boundaries and data flows to security controls and production operations.

The work has included microservice platforms, event-driven workflows, high-throughput APIs and cloud-native infrastructure, with identity and authorization carried across users, services and agents.

At production scale, the hardest problems rarely sit inside one service. They appear between services, identities, data stores and teams. That is where architecture has to hold.

16+ years

Building and leading enterprise systems.

1M+ daily operations

Systems operating at production scale.

Distributed systems

Microservices, APIs and event-driven workflows.

Identity & authorization

IAM, delegated access and policy enforcement.

AI security

Agent runtimes, red-team testing and secure execution.

Clients Edge Domain services Platform foundations Web platforms Mobile clients Partner APIs millions of users Edge & ingress TLS · routing rate limits back-pressure Identity Authorization Logistics Documents AI agents OIDC PDP events pipelines runtime owns authentication state evaluates authorization policy owns logistics data owns document workflows owns agent execution state private stores · shared events Platform foundations managed data services observability & tracing autoscaling multi-region runtime 1M+ operations / day Event backbone streams · queues · pub/sub · event-driven choreography async · decoupled · replayable request / response events, published asynchronously
Expertise

Selected areas of expertise

Enterprise products, distributed systems, AI, identity and security.

01

AI Agent Architecture and Harnesses

Agent runtimes, context management, capability discovery, tool and code execution, durable state, evaluation and human approval.

Workflow order, permissions, recovery and consequential actions move outside the model when guarantees are required.

02

Enterprise Platforms and Product Systems

E-commerce, last-mile delivery, customer feedback, document processing and messaging-based AI platforms.

Experience spans multi-tenant SaaS, operational workflows, real-time data and third-party integrations.

03

Distributed Systems and Cloud Architecture

Microservices, high-throughput APIs, event-driven workflows and cloud-native platforms.

Key concerns include service boundaries, data ownership, asynchronous processing, observability, failure handling and production migration.

04

AI and IAM Security

Architecture review and red-team testing across instructions, retrieved content, credentials, authorization and execution paths.

Typical failure paths include poisoned context, credential substitution, confused-deputy behaviour, capability chaining and unintended data movement.

05

Identity Platforms and Modern Authorization

A modern identity provider built from the ground up, covering federation, token issuance, workload identity, delegated access and policy enforcement.

The implementation includes FAPI, DPoP, token exchange, dynamic client registration, sender-constrained tokens, policy-as-code, continuous authorization and credential lifecycle management.

Research & Open Architecture

Runtimes, protocols and systems for AI agents

These projects came out of problems I kept seeing while building and reviewing agent systems: workflow logic inside the model loop, authorization fixed too early, growing tool surfaces and agents carrying too much responsibility for execution across systems.

I use them to test different approaches in working code, from typed capabilities and durable state to continuous authorization, outcome-based coordination and deterministic retrieval.

Security Perspective

From Reasoning to Action

Approved tools and valid credentials do not show that an action still belongs to the task.

Hostile content from webpages, emails, documents, images or tool results can redirect a run. Stale instructions, incomplete responses, model assumptions, recovery attempts and newly discovered capabilities can do the same. My security work traces how these influences pass through the model and harness before becoming an external effect.

Context and influence

Trace the instructions, retrieved material, tool results, summaries and earlier decisions that shaped the action.

Where did the information come from, how current was it, and was it observed, inferred or carried forward from an earlier turn?

Trajectory and recovery

Review what happened after errors, denials and partial results, including retries, workarounds and changes in route.

Did recovery remain within the task, or introduce new assumptions, targets or methods?

Authority and capability

Map the identities, credentials, permissions, tools and network routes available during the run, including capabilities discovered after execution began.

Was the authority valid, how was it obtained, and why was it used for this step?

Execution boundary

Inspect the runtime components that turn generated output into action: tool parameters, command parsers, sandboxes, credential injection, policy checks and approvals.

Did the control constrain the resulting effect, or only one way of producing it?

Effect and reconstruction

Connect the original request to the final system change, including the influential context, actions proposed, results returned, identity used and request accepted by the backend.

The review identifies where the sequence moved outside the user's mandate and which control could have stopped it before execution.

Advisory & Technical Leadership

Support for difficult architecture decisions

I work with leadership and engineering teams on AI systems, identity platforms and complex enterprise products. The engagement may involve a new solution, an existing architecture that needs correction or a programme requiring continued technical ownership.

AI and Enterprise Solution Architecture

Architecture for AI-enabled products, agent systems, enterprise platforms and modernisation programmes.

The work covers system boundaries, data flows, integrations, identity, security, cloud infrastructure, failure handling and the path from design into production.

Independent Architecture and Security Review

An assessment of an existing system, proposed design or active technical programme.

The review examines architectural assumptions, scalability, operational behaviour, AI execution paths, identity, authorization and security controls, then documents the risks, trade-offs and recommended changes.

Embedded Architecture Leadership

Continued involvement from early technical decisions through implementation and delivery.

This is suited to programmes that need senior architecture ownership across engineering, product, security and executive leadership.

Discuss a Technical Challenge
In Their Words

Perspectives from leaders I have worked with

I've had the pleasure of working alongside Hammad as the VP of Engineering at Point Pickup Technologies, and can confidently say he is an exceptional talent. Hammad has a deep understanding of software architecture and a passion for new technologies, particularly AI/ML. His ability to deliver high-performance applications while going the extra mile for project success has made a significant impact on our organization.
Chris SchoenfeldChris SchoenfeldVP Engineering · Point Pickup
I hired, managed and mentored Hammad directly for 10+ years. One of my favorites and I loved to work with him. He is highly skilled in the .NET platform and has the ability to quickly learn any new technology. Humble, friendly, a team player, and a dependable resource that every team and organization would love to have.
Salman SarfrazSalman SarfrazPresident · Aspose Pty Ltd
I would be delighted to recommend Hammad, who worked as an Architect and Team Lead on my team at Point Pickup. Hammad was an invaluable asset to our organization, consistently delivering on complex, high-scale systems.
Jagdish RepaswalJagdish RepaswalChief Technology Officer · Point Pickup
I had the pleasure of working with Hammad on a project where he demonstrated exceptional knowledge and skills in enterprise architecture and building scalable systems.
Javid CalcattiJavid CalcattiMedical Director · Wellnorth Medical
Hammad was always proactive in providing input on important product decisions, and his contributions greatly helped to shape the direction of our projects. He consistently delivered fantastic work that exceeded expectations.
James ReillyJames ReillyProduct Specialist II · Qualifacts
Hammad embodies the essence of a well-rounded engineer. He brings a CEO's strategic mindset to each product, meticulously scrutinizes designs and ROI like a seasoned Product Manager, and demonstrates unrelenting dedication until completion.
Tevin CampbellTevin CampbellProduct Manager · Point Pickup
Hammad was a game-changer at Point Pickup. On top of our AI-driven delivery backbone, he built a Proximity Search service and end-to-end mobile platform that finds drivers in under 100 ms.
Chase KoorbuschChase KoorbuschFormer VP, Sales & Technology · Point Pickup
Speaking

Talks on AI infrastructure, security, identity, and enterprise architecture

I speak about the systems behind the demonstration: runtimes, harnesses, identity, authorization, distributed architecture, and the failure modes that appear when AI interacts with real infrastructure. I have presented at the European Identity and Cloud Conference and will be speaking at Medium Day 2026.

Upcoming

Medium DayAccepted Speaker

The Five Debts of the AI Era: What We Lost When We Removed the Friction

AI is removing friction from how we write, code, decide, and ship — and the friction is where the understanding lived. This session maps five debts piling up underneath the productivity gains: cognitive, comprehension, security, judgment, and strategic.

Track · Perspectives
EIC 2025

A Superior Alternative to OAuth for Building AI Agents and Modern Applications

Introduced RealTimeAuth, a low-latency authorization model designed for continuous access decisions in AI and modern application environments.

View on KuppingerCole
EIC 2024

Unlocking Identity Security with Behavioral Biometrics and AI

Examined how behavioural signals and AI can strengthen identity verification without adding unnecessary friction for users.

View on KuppingerCole
Speaking Topics

What I talk about

01

AI agent architecture and harnesses

02

Enterprise systems built for scale

03

AI security and adversarial testing

04

Identity and authorization for AI systems

05

Governed code and tool execution

06

Distributed systems and cloud architecture

07

Moving AI systems from prototypes into production

08

Outcome coordination and the future of agent infrastructure

Booking selected engagements for 2026

Conference talks, corporate workshops, team sessions. If the dates work, I'm interested.

Discuss a Speaking Engagement
Writing

Technical writing grounded in implementation

I write about AI agent architecture, context engineering, execution runtimes, identity, authorization, distributed systems and security.

The subjects come from systems I have built, architectures I have reviewed and failure paths I have tested. Most articles examine a specific production failure and the design decision that makes it possible.

Architecture Thinking

I often write before an architectural pattern has settled into common practice.

In my early work on dynamic agent orchestration, I described how large static tool registries would consume context, duplicate schemas, create version drift and place more orchestration inside the model loop.

I proposed generated or composed code running inside constrained environments, with intermediate data kept outside the prompt and policy enforced at the execution boundary. Later industry guidance began responding to many of the same pressures.

Publishing the position early forces it into enough technical detail to be tested against real systems.

Selected Writing

Lost in Execution — Your AI Agent Will Eventually Do Something You Never Asked For

How approved tools, valid credentials and correctly functioning systems can still produce an effect the user never authorised — from PocketOS to OpenAI's ExploitGym.

Dynamic AI Agents Orchestration

Why agent systems would move beyond static tool registries towards generated code and secure execution environments.

Why Code Execution Is Eating Tool Registries

How tool definitions, intermediate results and orchestration logic consume context and weaken control as systems grow.

The Missing Runtime Between AI Agents and Enterprise Backends

Why enterprise workflows need deterministic execution, durable state and policy outside the model loop.

The Future of Agents Is Outcome Coordination

Why agents may eventually coordinate objectives, commitments and evidence instead of directly operating every application involved in a task.

From LinkedIn

Latest insights

Follow on LinkedIn
Career & Experience

From Enterprise Systems to Production AI

I have spent 16+ years building production systems across document processing, logistics, SaaS, identity and AI.

My current work sits where these areas meet. I design the infrastructure around enterprise AI agents, including identity, delegated authority, model and tool orchestration, voice interaction, durable execution state and the controls that govern access to production systems.

That work is grounded in earlier experience with high-throughput APIs, event-driven platforms and systems serving millions of users and operations. I have worked as an architect, engineering leader and founder, with responsibility extending from technical direction into implementation and production operation.

I work across the architecture and the implementation details that determine whether it will hold in production.

16+Years
5Companies
1M+Daily Ops
30+Services

EmpowerID

Sep 2023 – Present · Remote, United States
AI Software Architect

Leading architecture across EmpowerID's Identity Fabric and AI platform. The platform spans more than 30 cloud-native services, a custom OIDC/OAuth 2.0 authorisation server, delegated access, workload identity, policy enforcement and a configuration-driven BFF.

My AI work includes enterprise agents, voice agents, multi-agent pipelines and the harness that manages context, tools, execution state, approvals and access to enterprise systems. I work across the full path from model interaction to authenticated production action, including the identity, authorisation and runtime controls around it.

WappGPT

May 2022 – Present · Remote, United States
Founder

Built and operate an AI personal assistant that lives inside WhatsApp — saving notes and links, setting reminders in plain language, and tracking documents, renewals and life events through LifeTree. Its reminders escalate from chat to SMS to a phone call until someone responds. The service has reached 25,000 users across more than 40 countries, largely through word of mouth.

The work covers model integration, natural-language recall, conversation and reminder state, escalating multi-channel delivery, user memory, billing and the operational constraints of running an AI product across third-party communication channels.

Point Pickup Technologies

Feb 2022 – Apr 2023 · Remote, United States
Lead Architect

Led architecture for a last-mile delivery platform used by Walmart, Kroger, Dollar General and 7-Eleven. The platform scaled from 250,000 to more than one million orders a day. Delivery success increased from 92% to 97%, while cancellations fell from 11% to 4%.

The work covered service boundaries, event-driven workflows, order state, partner integrations, operational visibility and migration under live production load.

FeedbackRig

May 2018 – Feb 2022 · Remote, United Kingdom
Co-Founder & CTO

Co-founded a customer-feedback analytics platform and led its architecture and development. The product collected and analysed feedback across customer journeys, with IBM, Lumen, GetStaff and Sound-Motive among its customers.

My role covered product direction, platform architecture, data processing and technical delivery.

Aspose

Apr 2011 – Dec 2021 · Remote, Sydney, Australia
Software Architect

Spent a decade building document APIs and platform infrastructure handling more than five million requests a month across over 40 file formats. I built a unified gateway serving 1.6 million users, helped grow monthly traffic from 100,000 to five million visits and reduced document-conversion failures by 42%.

The work included API design, distributed processing, format conversion, product infrastructure and systems used by large enterprises at sustained production scale.

Contact

Start a conversation

For AI, identity, security or enterprise architecture work.

Working through a difficult technical decision?

I work with organisations building AI systems, identity platforms, and high-scale enterprise infrastructure. An engagement can begin with a focused advisory session, an independent architecture review, a red-team assessment, or a longer architecture leadership role.

Start a Conversation