Azure Platform & AI Agent Engineering
Azure platforms and AI agents, engineered for regulated teams.
Outside-IR35 engineering through Weldon Web Ltd, led by an Azure Solutions Architect Expert with 10+ years building cloud platforms, integrations and CI/CD for fintech and regulated organisations.
Deliverable-led engagements, outside IR35, through a UK limited company.
Azure platform
APIM, Functions, AKS, Entra ID
AI agents & MCP
Governed tool access and audit
DevSecOps
YAML pipelines, release gates
Terraform / Bicep
Repeatable environments
Track record
10+ years, certified
Azure Solutions Architect Expert and Azure Developer Associate
Quarterly to weekly releases
Built the DevSecOps capability for a ~20-engineer integration platform at RBS
30 apps to AKS
Legacy and on-premises applications migrated to Azure Kubernetes Service
4 AI products shipped
Including an MCP gateway on Azure Marketplace and a Chrome Web Store extension
Services
LLM applications, AI agents and MCP integrations that make it to production - agent architectures, evaluation and guardrails.
AI Agent Development →Azure Platform EngineeringAPI Management, Functions, AKS, Entra ID, Terraform and the DevSecOps pipelines around them.
Azure Platform Engineering →AI Governance & SecurityControls for AI adoption, from usage policy to audit evidence - built on experience shipping AI-governance products.
AI Governance & Security →Latest posts
All posts →APIM now does MCP natively. What that changes in my reference architecture
Native products, tool telemetry, versioning and IaC for MCP on APIM - what I'd delete, keep and still build.
Privilege at the Tool Call: AI Agents Inside Law and IP Firms
Law and IP firms handle information where confidentiality is not a compliance box. It is the product. An AI agent with unrestricted tool access can waive legal professional privilege by surfacing protected material in the wrong context.
No Journal Postings at 3am: Time-Windowed Access as a Control
An allowlist controls which tools an AI agent can call. A time window controls when. A legitimate tool call at the wrong time is not legitimate at all.
Engagements
How engagements work
Every engagement is deliverable-led: a scoped piece of work with a defined outcome, not an open-ended retainer. Typical shapes are a short discovery or review, a fixed-scope build, or hands-on delivery alongside your team. You work directly with the engineer doing the work.
Talk about an engagement →Open Source
APIM MCP Reference Architecture
Production-ready Terraform modules to deploy Entra ID governed Model Context Protocol servers behind Azure API Management.
View on GitHub →