Dan Flanagan
Security & infrastructure engineer
I've been building software long enough to have something to say about it, and I wanted a place to say it. The internet may be turning into what the dead internet theory predicts, bots writing for bots. This site is still written by a person.
My day job
I'm a security and infrastructure engineer at Amazon, working where software meets physical buildings. I build control planes for secure remote access, segment the networks that building and OT systems run on, and maintain a telemetry agent that reports fleet health across sites. Some of those sites have no reliable cloud connection, so the software has to keep working without one.
Before Amazon I built fintech infrastructure at Plaid and was a staff engineer at SoLo Funds. For the past year I've also been a fractional CTO for an ESG data product, which I took from a static demo to something customers use.
The writing
These posts are notes from building things, usually about what broke and what I'd do differently. I try to include the numbers. The topics I keep coming back to:
- Securing AI agents How to scope MCP permissions so an agent can reach only what it needs.
- Platform & infrastructure Deployment tooling and monorepos, aimed at keeping releases boring.
- Go APIs and CLIs, plus the patterns that still hold up after someone else inherits the code.
- Startup engineering Deciding when to rewrite and when to iterate, and running the numbers before writing code.
Statio and side projects
Most of my time outside work goes into Statio, a permissions layer for MCP servers and AI agents. It lets you allow or block an agent's access tool by tool, instead of handing it a whole server. Everything else below started as something I needed for my own work.
Get in touch
Message me on any of the profiles above, especially about MCP security or anything I've written here.
Opinions here are my own, not my employer’s.