Government programs I've led and shaped

What each program is, who it serves, my role, and what the public record shows. Results belong to the teams that built them; my part is stated as scope.

  • Exygy · 2026–present

    CiviForm

    Open-source software that lets a government offer one application for many benefit programs, reusing what an applicant has already entered.

    Who it serves
    Residents applying for benefits from the four city and state governments that run it in production, including Seattle and Arkansas.
    My role
    Director of Engineering since August 2026, leading engineering for the platform. The four-person team ships on a biweekly release train.
    Record
    • In my first month: a security posture audit, cloud cost actuals, delivery metrics, and a team assessment with a staffing recommendation.
  • Coforma · 2022–2026

    MyCareer.NJ.gov

    New Jersey's statewide career and training platform, in English and Spanish: career exploration, training programs with their outcomes, and job search.

    Who it serves
    New Jersey residents exploring careers, comparing training programs, and looking for work.
    My role
    Engineering lead and principal engineer from an early prototype to a statewide service, and primary engineer across its three production codebases.
    Record
    • 1.8 million active users recorded since December 2023.
    • I did the 2023 data modeling that began the state's move to Credential Engine's CTDL standard. Its training programs are live in the Registry today.
  • Coforma · 2025–2026

    Medicaid and CHIP Data Collection Tools (MDCT)

    CMS's open-source suite of seven applications that states and territories use to report Medicaid and CHIP program data.

    Who it serves
    State Medicaid and CHIP agencies reporting to CMS, and the CMS staff who use that data to monitor the programs.
    My role
    I owned engineering for the suite within Coforma's healthcare portfolio: direction, standards, and the conditions for delivery. Feature leads did the hands-on build.
    Record
    • The team took a new CMS Rural Health Transformation application from zero to first production in about eight weeks.
    • All seven applications shipped production releases in 2026 while I led the portfolio.
  • Coforma · 2025–2026

    Medicaid Drug Programs (MDP)

    The CMS system behind the Medicaid Drug Rebate Program. Drug manufacturers report product and pricing data through it, and CMS uses that data to calculate the rebates owed to state Medicaid agencies.

    Who it serves
    About 780 participating drug manufacturers, the state Medicaid agencies that receive the rebates, and CMS.
    My role
    Oversight within the same healthcare portfolio. A partner's technical leads ran implementation.
  • California Energy Commission · 2019–2022

    Data Submission Portal (DSP)

    The Energy Commission's secure, cloud-based portal for filing regulatory energy data, starting with petroleum and quarterly fuel-and-energy reports.

    Who it serves
    Companies that file petroleum and fuel-and-energy reports with the commission, and the analysts behind California's energy-demand forecasts and Integrated Energy Policy Report.
    My role
    Lead Software Engineer. I architected and shipped it on AWS and helped lead the commission's cloud modernization.
    Record
    • The commission later expanded the platform across the agency and into residential solar-permit reporting.

Earlier California government work: social services, utilities, and energy

Public projects I build and run

Independent work on my own time, built in the open on public data. The status beside each one says how far along it is.

Live products

Open-source scorecards and validators

Case studies

Longer write-ups, each with my role, what was built, what was observed, and what the evidence does not show.

  • 2026–present

    CiviForm: the public record, and my role in it

    CiviForm is the open-source benefits-application platform four city and state governments run in production. I was recruited in August 2026 to lead its engineering. This page is what the first month held, and what remains the platform’s record rather than mine.

  • 2022–2026

    MyCareer.NJ.gov: evidence for the next move

    I led engineering from a 400-file prototype into a bilingual statewide decision service, built its program-level evidence, and did the 2023 data modeling that began the state's migration to Credential Engine's CTDL standard.

  • 2026 · unlaunched POC

    AI career guidance, accountable to evidence

    I shipped the shared safety infrastructure behind MyCareer.NJ.gov's applied-AI portfolio, then built an unlaunched career-coach POC. Executed QA improved sharply and still exposed pilot-blocking gaps.

  • 2026

    GTFS Scorecard: plain-language quality for transit feeds

    I run GTFS Scorecard, a live service that reads more than 2,100 published GTFS feed records and turns each one into a plain-language scorecard with a first recommended fix. Structural correctness comes from MobilityData's canonical validator; the scorecard adds freshness, rider-information, and realtime checks on top. Feed records are not necessarily distinct agencies, and no agency is known to have adopted a scorecard into its workflow.

  • 2026

    TODS Validate: findings a scheduler can act on

    I build tods-validate, a beta validator for the Transit Operational Data Standard, the open standard for crew runs, deadheads, and vehicle assignments that rides as an overlay on an agency's GTFS feed. It checks a package against TODS v2.1.0 and reports what is wrong, where, and what good looks like, with the spec section cited behind every finding. No agency adoption or production use is claimed.

  • 2026

    Permit Bearings: know the path in

    I designed and deployed a California housing-permitting prototype that screens a bounded statewide ADU, JADU, and SB 9 baseline across 541 recognized jurisdictions and produces a printable handoff for local staff. Woodland remains the deep synthetic packet fixture; no applicant, planner, or jurisdiction has validated it.

  • 2026 · alpha

    Habitable: keep the repair trail in tenants’ hands

    I designed and built a working local-first alpha that turns conditions, repair requests, responses, and captured media into a source-aware repair trail and deliberate review copy—without a project-operated tenant-case database. It has only synthetic examples and is not ready for real legal matters.

More open source

A curated set of public repositories, grouped by the work they support. Maturity labels describe the evidence available today, not adoption or guaranteed outcomes. Several of these share the same shape underneath: a deterministic checker reads real published records against a cited spec and reports what it finds. Applied so far to transit data, credential records, FHIR endpoints, and hospital price files, it has turned up a real finding every time rather than a clean bill of health.

Transit data and public delivery

  • NearMiss

    Maturity: Public beta

    A beta road-safety toolkit and public FARS evidence atlas. The live atlas presents reviewed 2020–2024 NHTSA fatal-crash counts for all 50 states and Washington, D.C., labeled as burden rather than exposure-normalized risk. Separate local workflows use synthetic reports to demonstrate privacy-preserving intake, exposure normalization, uncertainty intervals, and hotspot analysis. Manual screen-reader review remains pending.

    • Road safety
    • Spatial statistics
    • Open data

California energy and utility data

  • qfer-preflight

    Maturity: Beta · v0.1.0

    An offline pre-submission validator for California Energy Commission QFER consumption CSV filings: a filer runs it on their own file before uploading, and every finding cites the published instruction it came from. Anything the tool cannot check is reported as not evaluated, never as a pass, and filing data never leaves the filer's machine. Independent and unaffiliated with the CEC; the Commission's portal remains the authoritative validator.

    • Energy data
    • CSV validation
    • California
  • power-content-check

    Maturity: Beta · v0.1.0

    A deterministic conformance checker for California Power Content Labels against the format prescribed in Title 20 CCR section 1393.1. It reports which prescribed elements a label carries, which it lacks, and which it cannot judge. It makes no judgment about any supplier's power mix, produces no ranking, and makes no compliance determination, which only the Energy Commission can make. Unaffiliated with the CEC or any utility.

    • Energy disclosure
    • Title 20
    • California
  • ca-tariff-parse

    Maturity: Beta · v0.2.0

    A deterministic parser that turns published California electricity rate schedules, including SMUD and PG&E documents, into structured data with a citation for every value: document, page, section, and line. A coverage command reports exactly how much of each document was accounted for, so what the parser missed is as visible as what it read. Not rate advice, not a bill estimate, and unaffiliated with any utility.

    • Utility rates
    • PDF parsing
    • Structured data
  • inspected

    Maturity: Beta · v0.1.0

    A measurement over two public datasets: CAL FIRE's 132,522 wildfire damage-inspection records and the CEC's published electric service territory boundaries. 37.9 percent of records fall inside more than one published boundary, every rate carries its denominator and a confidence interval, and no utility is ranked. Figures are pinned to dated retrievals and move only when those retrievals are deliberately refreshed. Unofficial.

    • Wildfire data
    • Geospatial
    • Uncertainty

Responsible AI and inspectable decisions

  • Permit Bearings

    Maturity: Deployed prototype · external review not run

    A source-linked California housing-permitting prototype. Its bounded statewide ADU, JADU, and SB 9 baseline is screenable across 541 recognized cities and counties, each with a bilingual printable staff handoff. The deeper 25-item packet workflow is one synthetic Woodland fixture, not a statewide local checklist; no applicant, planner, or jurisdiction has validated it.

    • Housing
    • Source integrity
    • Decision support
  • Outcome Receipts

    Maturity: Beta · v0.1.0

    A beta nonprofit reporting tool that ties every figure to its SQL, row count, data-slice hash, definition, and timestamp. Its offline default applies example small-cell safeguards, refuses ungrounded numbers, requires named human approval, and emits verifiable bundles. Optional Bedrock drafting is off by default and never supplies figures. The sample suppression policy is not a compliance determination.

    • Evidence
    • Data lineage
    • Fail-closed AI
  • Constituent Reconciler

    Maturity: Reference implementation

    An offline-first pipeline that turns intake PDFs and spreadsheets into deduplicated constituent records for an existing CRM. A person approves every uncertain match, nothing merges silently, and automated tests enforce privacy rules for domestic-violence records.

    • Civic tech
    • Entity resolution
    • Privacy
  • Fare Policy Assistant

    Maturity: Deployed beta · reference implementation

    A retrieval-grounded assistant that answers rider questions about fare and reduced-fare policies for a dozen-plus California transit agencies, built so its public evaluation harness has something to grade. Merge-blocking suites cover citations, refusals, forged conversation history, and English-Spanish parity, with versioned prompts and a committed regression baseline, and properties the harness has not measured are reported as not measured, never as passing. Ingesting real fare pages keeps surfacing findings: a current fares page still listing a pass product retired weeks earlier, and an inter-agency transfer published as good for 60 minutes on one agency's site with no window published on its partner's. It never determines anyone's eligibility.

    • AI evaluation
    • Public transit
    • Retrieval grounding
  • plumbline

    Maturity: v0.2.0

    A fail-closed evaluation harness for government-facing chat systems: reproducible, provenance-stamped audit verdicts, byte-identical across Python versions, with no third-party dependencies. A silent or unreadable target scores zero rather than passing by absence, which is the defect an earlier version had: 174 empty responses once scored a perfect mark on every check phrased as the absence of a bad thing. The bundled dataset is synthetic and measures nothing about any real system; the harness is the product.

    • AI evaluation
    • Government chat
    • Fail-closed gates
    • Provenance
  • gauntlet

    Maturity: v0.1.0 · on PyPI as gauntlet-evals

    Merge-blocking evaluation gates for generative-AI features: YAML suites run against any HTTP endpoint or Python callable, fail the build on a miss, and emit a diffable JSON pack plus a reviewer document cross-referenced to California’s published GenAI risk framework. Aligned to that framework, never approved by it; the State has not reviewed or endorsed anything it emits. It evaluates a deployed feature in context, not a model, and it cannot verify a dishonest target.

    • AI evaluation
    • CI gates
    • California GenAI framework
    • Evidence packs
  • cairn

    Maturity: v0.3.0 · reference implementation

    A grounded-or-silent reference assistant for public agencies: it answers only from a corpus the operator supplies, cites every claim, and refuses plainly when no source clears the threshold, with no model and no network at answer time. English, Spanish, and right-to-left languages. Its own front page leads with the configuration that once let an unsourced answer through, and the test that now fails without the fix. A demonstration of correct behavior to read, not a product to deploy.

    • Grounded answers
    • Refusal
    • Public agencies
    • Reference implementation

Evidence, rights, and community control

  • ExitDrill

    Maturity: Technical alpha · synthetic only

    An offline, zero-runtime-dependency structural-normalization experiment. Synthetic Directus and CiviCRM canaries compare declared baselines and exports against a neutral in-memory SQLite reference model, then emit gap evidence. It does not establish operational equivalence, behavioral recovery, or migration readiness.

    • Data portability
    • Structural recovery
    • Offline verification
  • Habitable

    Maturity: Working alpha

    A local-first tenant-union reference implementation that turns conditions, repair notices, responses, and captured media into a source-aware Repair Trail and independently checkable review packet without a central plaintext case store. It has no real tenant-union pilot or independent legal or security review.

    • Tenant rights
    • Cryptography
    • Local-first
  • Ledger

    Maturity: Beta reference implementation

    A beta reference implementation for a community-governed archive of queer histories and mutual-aid knowledge, using established preservation formats and revocable consent. Its synthetic test suite is designed to catch identity leaks to unauthorized viewers, but it has not had an independent security or cryptography audit and should not yet hold high-stakes records.

    • Digital preservation
    • Privacy
    • Open standards
  • disclosed

    Maturity: Working alpha

    Grades US higher-education institutions on what they disclose rather than how they perform, across two federal datasets. Every value is classified before use as reported, implausible, suppressed, not applicable, or missing, and suppression that protects a small cohort is never held against anyone. Snapshot-to-snapshot drift reporting distinguishes a field that was never collected from one the public recently stopped being shown, in both directions.

    • Higher education
    • Open data
    • Disclosure integrity
  • mrf-honest

    Maturity: Working alpha · first graded cohort

    Deterministic, spec-cited grades for hospital price-transparency files, published with the evidence attached. The first cohort is deliberately small: six machine-readable files across four health systems, five graded A and one C. That C is the launch finding: an 884 MB file that still declared the superseded 2.0.0 template more than seven months after the effective date CMS documents for v3.0, verified against CMS's own schema documentation, pinned to the file's content SHA-256, and written up alongside what cuts the other way. It grades files, never institutions, and never determines legal compliance.

    • Health data
    • Price transparency
    • Data engineering

Climate, community data, and product systems

  • Swelter

    Maturity: Reference implementation

    A maintained reference implementation for community-owned heat and air-quality sensing. Its bilingual dashboard shows daily Copernicus model data for 337 California cities and provisional readings from physical, uncalibrated low-cost sensors in Stuttgart. The pipeline keeps raw and calibrated values separate and exports OGC SensorThings data. It is not an established community sensing network, and manual accessibility review remains a separate gate.

    • Climate
    • Open data
    • Python

Browse every public repository (opens in a new tab)