Jamie Ontiveros
Blog Blog
One Auditor, Two Tribes

My internal audit team's training budget splits in half every year: half to the IIA, half to ISACA. Two memberships, two certifications, two of everything, for a job that has fused into one while the institutions stayed split. Why does the profession still run two tribes? On how the split made sense once, why AI is ending the case for it, the four futures ahead, and who really holds the power to change it. #internalaudit #IIA #ISACA #AI #GRC

Blog Blog
Curated, not algorithmic — even when it's YouTube

Assurcast's promise is "curated, not algorithmic." This month I taught it to bring in YouTube, the most algorithmic medium there is. Audit and assurance videos now embed and play in the feed, the AI summarizes the video description, sharing uses the real thumbnail, and every "Watch on YouTube" button points back to the creator. A dozen tracked slices about keeping the content and leaving the recommendation engine at the door. #assurcast #howiai #claudecode #indiehacker

Blog Blog
Launching TeachMetrics

TeachMetrics is live. Self-hosted analytics for Teachable school owners: revenue, cohorts, students, discounts, and AI you can question, all running on your own server with your own data. Founding price is $100 per school per year. The license is the unusual part: you get the source, every version you receive keeps working even if you never renew, and the code contains no kill switch. You can verify that yourself, because you have the source. teachmetrics.co

Blog Blog
The Prompt Is Not a Security Boundary

Most AI privacy stories start with the prompt. TeachMetrics' AI features assume the opposite: the model is an untrusted SQL author. It can only see 24 aggregate views with no student PII by construction. Its SQL passes an allow-list validator, runs in a read-only transaction, and every answer shows exactly what was sent. Prompt injection's blast radius shrinks to 'a different aggregate query ran.' The prompt is UX. The boundary is code.

Blog Blog
The Correction of Error

Every system makes mistakes. What separates a trustworthy one is what it does next. A Correction of Error is a structured, no-blame admission: what broke, why the system allowed it, and what changes so the whole class of bug can't return. In our harness the AI files them unprompted, against a written standard, including failures nobody would have caught. Prevention isn't maturity. Honest correction is.

Blog Blog
Humanity in the loop

We talk a lot about “humans in the loop.” But humans get tired. Humans rubber-stamp. Humans become bottlenecks. The real challenge is preserving humanity in the loop: truthfulness, accountability, craftsmanship, humility, and trust. I explore how a single AI agent can build and review its own work when guided by shared tenets and honest retrospection.

I help modern audit and risk professionals embrace data analytics and AI to transform assurance. I also build software products in the social, grc, and analytics domains.

Subscribe

By email

Get the latest news and updates in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and tag.

View all feeds →
Feeds
Subscribe by email

Get the latest news and updates in your inbox.