Portfolio & resume

Andrew Goodson

Agent engineering, cloud security, and data intelligence

I build agent systems, cloud security tooling and public-record data products. The common thread is evidence: every answer should show where it came from, and every tool an agent holds should be limited to what its job needs. Below are seven projects, three with public source.

Agents you can inspect, data you can cite.

Evidence graphSources such as documents, datasets and records flow through scoped tools (read-only access, an approval gate and an audit trail) into agents and cited answers, which connect to the seven projects below. SOURCESSCOPED TOOLSAGENTS & ANSWERSTHE SEVEN PROJECTSDocumentsDatasetsRecordsRead-only accessApproval gateAudit trailAgentCited answer AEFRed Team OrchestrationCustodiaAgentic Data MiningEconomicIQPeptideIQDIBIQ
Evidence graphDocuments, datasets and records pass through read-only access, an approval gate and an audit trail into an agent and cited answers, which lead to the seven projects below.SOURCESSCOPED TOOLSAGENTS & ANSWERSDocumentsDatasetsRecordsRead-onlyApprovalAudit trailAgentCited answer

The seven projects

  • 7projects
  • 3public repositories
  • 4live product pages
  • 3focus areas

02

Selected work

Seven projects. The first three have public source. The other four are products whose source is private, so I describe scope here and link to the public pages only.

  • Agent engineering

    AEF — Agent Engineering Foundation

    A Python foundation for building agents you can inspect and control: graph-based execution, memory, checkpoints, tool-permission policy, audit, and evaluation behind a gated review loop.

    • Python 3.11+
    • Graph kernel
    • Checkpoint / replay
    • OpenTelemetry tracing

    First published

    Details for AEF — Agent Engineering Foundation

    Problem

    Agents that retrieve, act and learn are hard to audit: tool access is implicit, runs are not repeatable, and “learned” advice is rarely tested before it is trusted.

    Implementation

    Workflow nodes share one typed state and return explicit state changes and routes. Runs can be checkpointed and resumed, and deterministic nodes can be replayed against recorded inputs. Tool access is deny-by-default with human approval gates and an audit trail. Self-improvement means proposing and evaluating bounded changes to instructions and knowledge, with a human review step. It does not retrain models.

    Current scope

    Developer preview. Built today: the graph kernel, checkpoint and replay, policy controls, rule-based reflection, bounded prompt proposals and a gated loop harness. LLM reflection is off by default, automatic merging is disabled, and the project states that learning quality is unproven. A scaffold is not a working agent until real tools and evaluations are wired in.

  • Cloud security

    Red Team Orchestration

    Azure security assessment orchestration: specialist agents work an explicit graph to turn configuration into evidence, attack paths and reports, under read-only guardrails with coverage tracking.

    • Node.js
    • Azure
    • Multi-agent graph
    • Fail-closed guard

    First published · Updated

    Details for Red Team Orchestration

    Problem

    Cloud assessments are broad and repetitive, and an AI agent with cloud credentials is only acceptable if it provably cannot change anything.

    Implementation

    An explicit state graph validates scope first, then fans out to specialist agents (identity, network, compute, data, governance and others) in parallel. A deterministic guard shared by every runtime allows recognized read operations and stops unknown or mutating commands. A memory firewall lets the system learn only inert methodology notes, never code, prompts, tools or guardrails. Findings are checked, correlated into attack paths and written up.

    Current scope

    Described as an independent demonstration and not affiliated with Microsoft. Active testing stays off until scope and human authorization unlock it, and AI findings need independent human validation. Intended for authorized assessments only.

  • Public-records workflow

    Custodia

    A Copilot Studio agent for Microsoft Purview eDiscovery and public-records requests. It turns a request into a named case, a bounded search and an item-count estimate, using delegated Microsoft Graph access.

    • Copilot Studio
    • Microsoft Purview
    • Microsoft Graph
    • PowerShell

    First published · Updated

    Details for Custodia

    Problem

    Setting up an eDiscovery case for a records request is tedious and error-prone: consistent naming, a bounded query and a size estimate all come before any review can begin.

    Implementation

    A conversational agent restates the case name, query, date range and scope and waits for confirmation before each create, and one confirmation covers one action. Calls run as the signed-in reviewer through delegated access, with no application permissions. Delete, purge and legal-hold operations are not defined in the connector, so the agent has no tool to perform them.

    Current scope

    A connector and agent template, not a standing service. Responsiveness, exemptions and privilege stay with people. The sample conversation on the site is illustrative, and the project advises testing against synthetic data in your own tenant first. Not affiliated with Microsoft.

  • Data intelligence

    Agentic Data Mining

    Public-record datasets served to AI agents through one MCP server as structured JSON, with a catalog, documentation and a flat subscription model.

    • MCP server
    • Python ingestion
    • Parquet
    • Static site

    Source code is private.

    Details for Agentic Data Mining

    Problem

    Public records are scattered across agencies and formats, so agents cannot query them reliably or cite where an answer came from.

    Implementation

    Scheduled connectors pull incrementally from public sources and keep provenance with each record. The data is exposed to agents as structured results through a single MCP endpoint, with a public catalog and documentation.

    Current scope

    Live public product site. Dataset coverage grows over time, so see the site for the current catalog. Source code is private.

  • Data intelligence

    EconomicIQ

    County economic intelligence built from public datasets. Figures trace to the agency that published them, shown in a report, a relationship graph and a question-answering assistant.

    • Public datasets
    • Relationship graph
    • Assistant with citations
    • TypeScript

    Source code is private.

    Details for EconomicIQ

    Problem

    County numbers from different agencies often disagree or change basis between releases, and a confident wrong figure can end up in a grant application or council packet.

    Implementation

    Each figure resolves to the source cell it came from, with its vintage and margin of error. Known false claims and data traps are written down as data and checked when the assistant answers. Views include a report, relationships, indicators, peer comparison and a source register.

    Current scope

    Public product page. Source code is private. Coverage is county by county, so check the site for which counties are loaded.

  • Data intelligence

    PeptideIQ

    Price intelligence for online retailers in the research-compound market: price position, undercut alerts, catalog gaps and a trust checklist, read from public storefront data.

    • Price data
    • Web data collection
    • Retailer portal
    • Public index

    Source code is private.

    Details for PeptideIQ

    Problem

    Small online retailers have no clear view of how their public prices and catalog compare with competitors on the same item and size.

    Implementation

    The Peptide Index publishes price comparisons collected from public storefronts. PeptideIQ is a subscription portal over the same data. A subscription buys a view of the data and never changes a store’s published rating or ranking. An AI assistant is listed on the page as coming soon.

    Current scope

    Data and software only. The product does not sell or handle any compound, and the site is research-use only and not medical advice. Source code is private.

  • Data intelligence

    DIBIQ

    A portal over open DLA DIBBS solicitations that shows the government’s own published prices per stock number, each labelled by how the price was published.

    • Federal procurement data
    • Search portal
    • Provenance labels

    Source code is private.

    Details for DIBIQ

    Problem

    A contract total repeated on every line is easy to mistake for a unit price, and blended averages hide that.

    Implementation

    Prices are shown per stock number with the basis on every row, and different bases are kept apart. No average or trend is computed across them. When no price is held, the page says so plainly.

    Current scope

    Public product page. By its own description, a per-unit price exists for only a small minority of open items, because it depends on what the government publishes. Source code is private.

03

Skills & technologies

Drawn from the technologies listed on the projects above.

Languages & runtimes

  • Python
  • TypeScript
  • Node.js
  • PowerShell

Agent engineering

  • Graph kernel
  • Multi-agent graph
  • Checkpoint / replay
  • OpenTelemetry tracing
  • MCP server
  • Copilot Studio
  • Assistant with citations

Cloud & security

  • Azure
  • Fail-closed guard
  • Microsoft Purview
  • Microsoft Graph

Data & products

  • Python ingestion
  • Parquet
  • Public datasets
  • Relationship graph
  • Price data
  • Web data collection
  • Federal procurement data
  • Provenance labels
  • Search portal
  • Retailer portal
  • Public index
  • Static site

04

How I work

Source evidence

Numbers and findings carry their origin: the agency that published a figure, the run that produced a result. When the evidence is missing, the system says so instead of filling the gap.

Scoped tool permissions

Agents get the narrowest tools their task needs. Access is denied by default, risky actions wait for a person, and destructive operations are left out of the toolset instead of being forbidden in a prompt.

Useful workflows

Automation should remove setup work and leave judgment with people. I aim for tools that fit an existing process, such as a records request, an assessment or a bid, and state plainly what they cannot do.

Contact

For projects, collaboration or questions about the work above, the best way to reach me is LinkedIn.

Connect on LinkedIn (opens external site)GitHub profile (opens external site)