AI SSAG Architect · Security, Safety & Governance for agentic AI
Europe - UK - Nepal · tonywhelan.ai@gmail.com
I help SMEs adopt AI that can plan and act — with clear controls over what it can see, what it can do, what it must escalate, and how actions are evidenced.
Background: decades in enterprise infrastructure, access control, segmentation and resilience (including Cisco EMEA-scale work), plus hands-on agent systems.
| Layer | What “good” looks like |
|---|---|
| Security | Access, segmentation, logging, incident-ready controls — familiar ISMS discipline applied to AI systems |
| Safety | Bounded autonomy, human escalation, fail-closed defaults when confidence or policy is unclear |
| Governance | Policies, ownership, audit trails, and proportionate oversight SMEs can actually run |
Credential path (in progress): ISO/IEC 27001 Lead Implementer as the recognised security-management foundation, then AI-management and governance credentials mapped to capability growth — not a badge pile.
Start here when you want evidence, not a pitch:
| Repo | Why it matters |
|---|---|
| ai-ssag-kit | Public SSAG starter: control checklist, escalation matrix, ISMS→AI bridge notes |
| walk-in | Agent field-kit thinking for small businesses — how tools get fitted in the real world |
| plainly | Discipline on AI-generated text — lint, rewrite, portable skill |
| brief | Turning messy prompts into operable briefs for frontier models |
Selected other public builds (forecasting, shorts tooling, etc.) live on the profile. Operator experiments stay private on purpose.
- Email: tonywhelan.ai@gmail.com
- GitHub: anwhelan01
Remote-friendly · clearly scoped work · paced for sustainable delivery.
Security · Safety · Governance — so agentic AI stays useful and accountable
