HN user

ashconway

38 karma

Serial founder & angel investor. Building openenvelope.org — the multi-agent designer — and gazebohq.com — IAM for AI agents.

Posts38
Comments18
View on HN
openenvelope.org 23d ago

The composable AI thesis

ashconway
3pts0
openenvelope.org 1mo ago

Why open standards matter for AI infrastructure

ashconway
2pts0
openenvelope.org 1mo ago

Show HN: Open Envelope – an open schema for defining AI agent teams

ashconway
52pts13
openenvelope.org 1mo ago

Human in the loop and the autonomous agent problem

ashconway
2pts0
openenvelope.org 2mo ago

The Platform Trap in AI

ashconway
2pts0
substack.com 2mo ago

Narrow by Design: The Case for Composable AI Teams

ashconway
2pts1
bugwolf.com 11y ago

Bugwolf Blog Post: The Real Cost of Production Defects Equals 14x Increase

ashconway
1pts0
bugwolf.com 11y ago

National Australia Bank Partners with Australian Startup Bugwolf

ashconway
1pts0
bugwolf.com 11y ago

It’s Not 1st to Market, It’s 1st to Product Market Fit

ashconway
5pts0
bugwolf.com 11y ago

Testing Different Screen Sizes and Displays Is Critical for iOS8

ashconway
1pts0
bugwolf.com 11y ago

Application Certification Testing Must Be Continuous for iOS8

ashconway
1pts0
bugwolf.com 11y ago

Exploratory Testing Provides Value and Speed for iOS8

ashconway
1pts0
bugwolf.com 11y ago

Deciding Whether to Automate or Emulate Testing for iOS8

ashconway
2pts0
bugwolf.com 11y ago

Testing Planning and Risk Mitigation For iOS8

ashconway
1pts0
bugwolf.com 13y ago

The fog factor in software testing

ashconway
1pts0
bugwolf.com 13y ago

Social Media And Digital Wildfires – The Next Threat

ashconway
1pts0
bugwolf.com 13y ago

The Australian Government 2012 Cyber Crime And Security Survey Report

ashconway
1pts0
bugwolf.com 13y ago

Cyber-Crime And National Governments

ashconway
2pts0
www.smh.com.au 13y ago

Sydney Morning Herald: Bounty hunters hound out computer bugs

ashconway
1pts0
bugwolf.com 13y ago

88% of Businesses Think They’re Safe From Cyber Attack

ashconway
1pts0
bugwolf.com 13y ago

Bugwolf Announces: 2nd Beta Bug Bounty Contest — Starts Feb 16: BOUNTY $1,000

ashconway
2pts0
bugwolf.com 13y ago

State Sponsored Cyber Attacks On The Rise

ashconway
1pts0
bugwolf.com 13y ago

We’ve Been Busy Building New Features For Security Researchers

ashconway
1pts0
bugwolf.com 13y ago

We've created a place to find the latest bug bounty programs and submit reports

ashconway
2pts0
bugwolf.com 13y ago

Full Details of Bugwolf’s 1st Beta Bug Bounty Contest

ashconway
1pts0
bugwolf.com 13y ago

Information Sharing to Counteract Cyber Threats

ashconway
1pts0
bugwolf.com 13y ago

Bugwolf Announces 1st Beta Bug Bounty Contest -- Starts Feb 5: BOUNTY $500

ashconway
1pts0
bugwolf.com 13y ago

Ponemon Institute 2012 US Cost of Cyber Crime

ashconway
1pts0
bugwolf.com 13y ago

We’re Recruiting Security Bug Bounty Hunters

ashconway
1pts0
bugwolf.com 13y ago

We’re Hiring Security Vulnerability Researchers

ashconway
1pts0

On accessPolicy — sub-agents in Envelope are the tools: each defines its own access scope, the supervisor just knows what's available. Where the concern is valid is function-level tool calls — no first-class tool definition layer yet, so HTTP access scope ends up at the agent level rather than the tool.

On gates — the per-record model handles dynamic output you can't pre-declare at schema time, and timeout/onReject are runtime routing decisions. The action type specifically is doing real work — irreversible step, explicit approval required before it fires.

On trigger logic: agreed. XOR isn't expressible with the current set and recursive conditions is almost certainly the v2 shape.

Right — well-suited for what they do: scripts Claude generates to orchestrate subagents for a specific task at scale (audits, migrations, research). Each run completes; that's the design.

The schema here defines the team itself — roles, supervisor/sub-agent hierarchy, access policies, human gates, schedules — as a portable, reusable declaration. Run it once, on a schedule, or keep it deployed. Closer to a Dockerfile than a script.

Vendor-agnostic is part of it. Nothing in the spec ties to Claude or any specific runtime — Apache 2.0, anyone can implement a compatible runtime.