Contributing Writer · AI Specialist

Celeste Shao

Contributing Writer, Explore Agentic

About Celeste

Celeste writes about what an agent stack has to prove after it ships. The observability work covers tracing an LLM application end to end, versioning prompts as deployable artifacts, and catching silent quality drift before users report it. The compliance work takes that same telemetry and asks what an auditor needs from it: HIPAA-compliant agent architecture for clinics, meaning the business-associate-agreement chain across every subprocessor, minimum-necessary scoping enforced at the MCP gateway, FHIR and EDI 270/271 traffic, and human-in-the-loop checkpoints on anything that touches a claim; and COSO's February 2026 generative-AI control guidance, translated into which artifact each layer emits, in what schema, retained how long, and sampled how.

The Claude Cowork piece runs the same problem at the desktop — governing an agent that acts on real files, and the shadow-AI exposure created when it arrives without governance. Expect control mappings with the log record behind each one.

LLM observabilityHIPAA agent architectureCOSO control evidenceAudit evidence schemasAgentic AI security