00.00.00

LF Decentralized TrustLFX Mentor, Ryan Madhuwala

Experience/LFX Mentor

Command Palette

Search for a command to run...

Back as a mentor, leading the next cohort

A year after finishing the programme as a mentee, I returned as an LFX Mentor under LF Decentralized Trust — guiding two contributors through six months building Caracal, a security-first authority delegation platform for AI systems.

Remote
LFDT community on stage at Open Source Summit India

The LF Decentralized Trust community on stage at Open Source Summit India.

OSS India · 2026
Open Source Summit Japan

Open Source Summit Japan, alongside AI_dev and the Automotive Linux Summit.

OSS Japan
LFDT community at Open Source Summit India

Contributors and maintainers from across the foundation, in one room.

OSS India · 2026
With IBM's CTO at Open Source Summit India

With IBM's CTO at Open Source Summit India.

OSS India
With DigiYatra at Open Source Summit India

With DigiYatra's leadership between sessions.

OSS India
2
Mentees guided
6 mo
Programme length
LFDT
Umbrella foundation

Coming back

Having been through the programme as a mentee, I came back to run it — mentoring Ashutosh and MHD. Ali Haider over six months on secure infrastructure for autonomous AI agents.

Engineering

Caracal — authority delegation for AI systems

Problem
Humans, agents and services constantly delegate authority to each other, with nothing checking policy before execution, no way to revoke access in real time, and no record you could audit afterwards.
Approach
Led the architecture and guided the implementation: a policy enforcement gateway in front of every request, a delegation graph engine with authority evaluation over it, vault integration for API credentials, immutable audit infrastructure, and end-to-end delegation workflows tying them together.
Result
A cohesive, production-oriented foundation rather than a collection of independent features.
Policy enforcementGraph traversalSecret vaultImmutable auditDecentralised identityDistributed evaluation

What the contributors took away

Graph-based authority resolution, policy-driven request routing, secure credential management, decentralised identity, and ledger-backed auditability for autonomous systems.

Most of them had not touched security infrastructure before. By the end they were making design calls in it.

Running the mentorship

Breaking the roadmap into milestones, reviewing pull requests, holding design discussions, documenting the architecture, and working through the problems that do not have a clean answer.

The part that mattered most was explaining the reasoning behind each decision, not just the implementation. A contributor who knows why can make the next call without me.

Review is teaching. If a mentee leaves a PR having only learned that they were wrong, I wasted both our time.

Taking it out into the open

The project was presented at several open source events and summits, giving visibility to the work happening inside LF Decentralized Trust and showing a practical approach to secure authority delegation for AI systems.

Related projects

More at LF Decentralized Trust