Bringing technical clarity to the unknown

Attempts to make fetch -- I mean GovOps -- happen

30 Aug 2026 🔖 iam security databases devops professional development prompt engineering
💬 EN

Somehow at Open Source Summit North America 2026 (my #OSSummit recap here), I ended up in the LinkedIn identity and access management ecosystem (maybe through Okta’s Jennifer Mulford?), and I’m hooked (hi, come find me 👋). It’s a bunch of standards committee member type wonks pondering and debating the issues I blogged in May 2025 in “Securing Authenticated Agentic AI, one of whom is named Mike Schwartz.

Today he published an article titled “Least Agency, Governed,” replying to Anthropic’s May 2026 post titled “Zero Trust for AI Agents” (ahem – ya think you shoulda figured that out BEFORE you told everyone to go use agents, or demonstrated giving a hoot about the concept by actually freaking airgapping your model tests, Anthropic?! grrr, insert #TimnitGebru commenting #PressReleaseAsAService … anyway …), in which he opined that it’s just the kind of idea the GovOps Working Group is trying to solve.

Upon seeing that, I wrote in my journal:

“Like ‘FinOps’ is an amalgam of accounting, cloud sysadmin work, and data science, ‘GovOps,’ it seems, is going to be the jargon for the upcoming work to be done wiring up data warehouses (to store what it’s desired for authZ to look like), machine learning / predictive analytics (to support automations at machine speed, as real-world data about GenAI LLM agents’ machine-speed actual authN’ed nondeterministic privileged behaviors feed in), and ETL / automations (to get the predictions actually firing triggers) for the purpose of very quickly toggling authZ grants / revocations.”

(Pssst – some random asides that reminded me of:)

Anyway, back to the topic at hand.

I proceeded to Google “GovOps” to learn more about the field, got a bunch of results about government procurement contracts and government program oversight, and realized this is not an available term. I added to my journal:

“Correction: ‘GovOps’ is, thus far, Mike trying to make ‘fetch’ happen. But I appreciate that he got me thinking about it from his ‘Celestial Emporium’ point of view!”

GIF from the movie "Mean Girls," captioned "Gretchen, stop trying to make 'fetch' happen.  It's not going to happen."

I very much appreciate that Mike’s choice of name helped me see this as a “yet another data science meets IT operations problem,” like FinOps.

I think I’d been a bit in denial about that to myself, because I’ve always preferred “small data” and the kind of set theory you can get your mind around as a kid, over “big data” and probability / statistics / vectors.

I probably lament too deeply for my own good that every 10 years, the statistics-ey-ness of what math and computing means to “being human with each other” increases another exponential explosion.

  • (Brendan Burns pointed this out nicely in the intro to Designing Distributed Systems. At 21st-century scale, server failure becomes guaranteed. The new business-level definition of monitoring for technology service “failure” had to be a question of measuring how often things failed, not whether they failed, which meant dusting off statistics textbooks.)
  • (And Annalee Newitz, in “Stories Are Weapons,” and Chris Wiggins & Matthew L Jones, in “How Data Happened,” point out that if I have gripes, I need to take my complaints about over-statisticalizing life on Earth up with physicists in the 17th century, Guinness executives in the 19th century, and Charles Darwin’s terrible nephew. Computing was just a weird 20th-century holdout where you could tinker with “small math” until we got chips tiny and laid undersea cables and put up cell towers. Once those were all in place in the 21st century, it started getting really, really, really hard to reason about solving interesting business problems with computers, yet professionally take shelter from having to devote day-to-day brain cells to data-at-statistics-required-scale solutions and their fuzzy, probabilistic nuances.)

But my denial doesn’t mean Mike’s wrong. I don’t think this label will stick due to abbreviatability overlap. However, now that he’s opened my eyes to this conceptual space as a boundable domain, I won’t be surprised if some sort of “Catchy-Word-Here-Ops” label does stick. And roughly around this boundary, encapsulating solutions to the same questions all the other “*-Ops” buzzwords try to answer:

“How do we handle ‘XYZ’ new business problem, at scale, in light of ‘ABC’ new technology blowing everything up at scale?”

Using data science to flip the authZ grant / revoke lights on and off, at machine speed, is definitely gonna be a career area.

(And as for me, if I’m really lucky, I might manage to avoid having to get that probability textbook out, and wait to jump in until people who deeply enjoy statistics have as-a-service’d this field, at hyperscale, on Gartner’s “Plateau of Productivity. We’ll see – I might end up somehow getting to keep chilling in my beach lounger, getting away with specializing in the relatively deterministic, small-scale-noodling career area of discovering and socializing best practices about how to put those as-a-service parts together correctly. So thanks, Mike, for drawing a useful map of the terrain, whether it’s because I head for it or run from it. 😜)

--- ---