Dinis Cruz
This site measures his product team's own operational documents. Every role definition, comms file and commit this site cites comes from repositories he founded and maintains — which is what makes the claims checkable, and also what makes them worth being sceptical about.
The short version. Twenty-five years in security and software: former CISO, former OWASP board member, organiser of the OWASP Summits, creator of the O2 Platform, and founder of sgit.ai and a handful of companies that publish their source and, unusually, their strategy. Currently Chief Architect of GenAI Innovation. Nearly everything he builds ships open source — which is the reason a site like this one is even possible: the repositories the claims point at are public.
Read more, elsewhere
This page is deliberately short. The full account lives on two pages maintained as the canonical ones, and this site links to them rather than keeping a third copy that would go stale.
What is being measured
Role definitions (ROLE.md), a comms protocol, and the git history of
both, from SGraph-AI__App__Send and a second product,
sg-playwright — the teams that build and harden SG/Send, his zero-knowledge
encrypted file-sharing product. None of it is written for this website; it is the
operational documentation a live product team uses every day, published here because
the founder commissioned a site made from it.
Why this site exists
Most people building multi-agent systems write down what each agent can do.
This estate writes down what each agent must not do — a named field,
Not Responsible For, in 31 of 39 files — and states its Central Claim, at
its best, as a falsifiable failure condition rather than a job description. That is
unusual enough, and evidenced enough, to be worth a reference site of its own rather
than a paragraph on a company blog.
Whose voice you are reading
Two voices, and the site keeps them apart on purpose:
| Where | Whose |
|---|---|
A <blockquote data-quote="founder"> anywhere on this
site | Quoted verbatim from a ROLE.md file or a commit
message in the product repositories, with the source named. These are the
product team's own words, published by the project that owns them. |
| Everything else | This site's reading of the evidence, written by an AI agent from a commissioning brief, with Dinis Cruz reviewing and directing. Where a connection is this pack's inference rather than the corpus's own statement — the Explorer→Villager trigger, for one — the page says so explicitly rather than presenting inference as fact. |
Why to be sceptical of all of it
A project publishing an account of how well its own team's role definitions work is doing something with an obvious pull to it: it is grading its own homework. There is no external audit here, and every incentive points toward finding the estate's practice more coherent than a stranger's team might.
What is done about that, and none of it makes the incentive go away: every number is computed from the roster data rather than typed; the format regression and the six undefined roles are published as findings, not smoothed over; and the site states outright where evidence runs out — the open-questions queue is exactly that list, kept public rather than resolved quietly.
The full participant disclosure How this site is built
Correct it
The most useful thing anyone can do with this site is find a claim that does not match the repository it cites. A roster entry states a role's presence, claim form and commit count against the corpus; if it is wrong, that is a defect and it should be reported like one — the repository is public, releases and failed builds included.