An Operational Checklist for AI Agent Identity
The non-human identity crisis is measurable in your own account today. Here's a concrete audit — admin agents, secret age, secrets outside repos — and what to fix.
I lead the product, AI Engineering, Data Science, Data Engineering, and ML Engineering teams at CP Axtra (Lotus's & Makro) — one of Southeast Asia's largest retailers — building an AI-native application platform from the ground up, and turning AI from experimentation into governed, production-grade capability that moves the business at scale.
I'm Frank Winkler — Director of Digital Transformation & AI Platform at Lotus's (CP Axtra) in Bangkok, and ex-AWS — working where platform engineering meets the operating model.
I lead the product, AI Engineering, Data Science, Data Engineering, and ML Engineering teams at CP Axtra (Lotus's & Makro), one of Southeast Asia's largest retailers, building an AI-native application platform from the ground up — custom RAG, vector-embedding services, and bespoke infrastructure on Kubernetes that enables agentic, AI-assisted development at scale. Alongside it, I own the unified-UI and systems-migration program consolidating 290 systems across five business units.
Before this I spent three years at AWS architecting generative-AI and enterprise systems across ASEAN, and a decade before that leading data, ML, and product teams from startups to enterprise. The throughline is the same: turning AI from experimentation into governed, production-grade capability that delivers measurable business impact. I write and speak about agentic AI and AI-native engineering.
Leads the product, AI Engineering, Data Science, Data Engineering, and ML Engineering teams at CP Axtra (Lotus's & Makro), one of Southeast Asia's largest retailers — building an AI-native application platform from the ground up. Owns technology strategy, platform architecture, agile delivery, governance, and C-suite alignment.
Partnered with high-growth ASEAN startups to architect scalable, secure, cost-efficient solutions and accelerate adoption of AWS Generative AI services — building relationships across founders, technical leaders, and investors.
Led technical account management at the largest ASEAN bank for AWS — technical strategy for security, resiliency, availability, and operational efficiency across cloud and hybrid architectures.
APJ Lead of the ML/AI & Generative AI field community — enablement and capacity building across the region. Co-owned the migration of a live global social-media site (90M users) from monolith to serverless AWS.
Data & AI solution architecture and full-stack delivery — machine learning, data engineering, and cloud design on AWS and Google Cloud; building teams and products in AI R&D.
Led the AI & data-science practice and data architecture — building ML capability and production data systems.
Founder-level technology leadership building AI- and blockchain-enabled platforms for negotiation training and team/venture validation.
People-analytics and smart-web technologies for precision talent identification in specialised, cross-disciplinary roles.
Native build-time cards for GitHub & Medium pull live; LinkedIn & X are curated link-outs. Every card carries loading, empty, and error states — a dead feed never breaks the page.
In-repo markdown with RSS at /feed.xml. The full archive lives on the dedicated blog page.
The non-human identity crisis is measurable in your own account today. Here's a concrete audit — admin agents, secret age, secrets outside repos — and what to fix.
No agent should ever hold a standing key. AWS STS and OAuth token exchange already make that possible — the failure is architectural, not technological.
Most AI features don't fail because the model is wrong. They fail because the product never earned the user's confidence — and confidence is something you design, not something you ship by accident.
A guardrail in a system prompt is advisory. Authorization at the MCP gateway is enforced before the tool call runs. Here's the difference, on AWS.
From data/speaking.json, with a calendar you can subscribe to.
Advisory, speaking, or just comparing notes on AI-native platforms and transformation. Messages reach my inbox via a serverless form — no third-party CRM.
POST → API Gateway → Lambda → SES
CORS locked to frankwinkler.me · throttled · honeypot
A low-volume letter on applied AI, architecture, and the craft of building products. Double opt-in via ConvertKit — no spam, unsubscribe anytime.