Projects using NotebookLM in SuratProjects using NotebookLM in SuratWhen the “User” Is an AI Agent: A Zero Trust Case Study
This independent research case study looks at what changes when an AI agent moves beyond answering questions and starts taking actions through tools, APIs, workflows and enterprise systems.
Using public cyber-threat reporting and Zero Trust principles, the report examines why AI agents need to be treated as a new type of non-human identity, with limited, traceable and revocable access.
The research focuses on practical questions security leaders need to ask:
What is the agent’s identity?
What can it access?
What can it change?
How is its activity monitored?
And who can stop it when something goes wrong?
The case study covers AI-agent identity, least-privilege access, segmentation, continuous verification, monitoring, access revocation and human control.
It also demonstrates my approach to cybersecurity research: finding and checking sources, connecting emerging threats with established security principles, turning technical issues into clear analysis, and presenting the findings in a way that business and security leaders can understand.
This sample is intended for security teams, CISOs, risk leaders and technology executives looking for clear, evidence-based research on AI security, Zero Trust, identity and access management, and emerging cyber risk. The Supply Chain Beneath the Supply Chain
Evidence-Based Supply Chain Risk Research
How hidden upstream dependencies can make a diversified supply chain much less resilient than it appears.
A company can have four suppliers for the same critical component and still have a serious supply problem.
Why?
Because those four suppliers may depend on the same upstream material, manufacturing process, piece of equipment, or geographic region.
That is the question behind this SourceTrace research project:
When we look beyond the suppliers we can see, how many genuinely independent supply routes are actually left?
What I investigated
I looked beyond the usual Tier-1 supplier view and traced where critical dependencies can come together further upstream.
The research examines:
Why having more suppliers does not always mean having more independent supply routes
How several suppliers can share the same hidden upstream dependency
Semiconductor supply chains and concentrated manufacturing equipment
Pharmaceutical supply chains and concentrated upstream inputs
How one upstream disruption can affect many companies at the same time
Why technology lock-in, qualification requirements, capital costs and geography create hidden bottlenecks
When deeper supply-chain research is worth the time and money
What boards and risk teams should ask before assuming a supply chain is truly diversified
The research approach
I did not try to map every company and every supplier in a global supply chain.
Instead, I used selective depth.
The idea is simple:
Keep tracing a critical dependency until the information can change a real decision — such as finding another supplier, increasing inventory, redesigning a component, or accepting the risk.
The research was then turned into dependency maps, evidence cards, industry examples, comparison tables and practical questions for decision-makers.
The central finding
Supplier count is not the same as dependency count.
Four suppliers may look safer than one.
But if all four ultimately depend on the same upstream constraint, the apparent diversification can disappear when that constraint fails.
This is what I call common-mode exposure: different suppliers can be affected by the same problem because they share part of the same upstream system.
What I created
Evidence-based research paper
Multi-tier supply-chain dependency maps
Semiconductor and pharmaceutical case analysis
Supply-chain risk framework
High-value vs. low-value mapping matrix
Executive and board-level questions
Visual evidence cards and comparison tables
SourceTrace research methodology
My role
Researcher + Investigative Writer
I researched the evidence, followed the dependencies beyond the obvious supplier relationships, tested the assumptions behind conventional diversification, and turned the findings into clear, visual and decision-focused research.
The goal was not to make the supply chain look more complicated.
It was to show where the real dependency sits.
SourceTrace principle: Truth before persuasion. Evidence before opinion. Greenwashing Risk for Mid-Size & SaaS Companies
How Weak Environmental Claims Create Commercial and Regulatory Exposure
Environmental claims are no longer just a marketing issue. For mid-size and SaaS companies, a simple phrase such as “sustainable,” “eco-friendly,” or “carbon neutral” can create regulatory and commercial risk when the evidence behind it is weak or incomplete.
This Source-Trace white paper investigates how greenwashing risk is changing across the UK, US, and EU, and what businesses can do to make their environmental claims more defensible.
What I researched and developed
Investigated the regulatory landscape for environmental claims across the UK, US, and EU
Examined primary regulatory guidance, enforcement records, court decisions, and agency sources
Analyzed real-world cases involving environmental claims and misleading marketing
Identified 7 recurring claim patterns that can create compliance problems
Developed a 6-level evidence scale for evaluating environmental claims
Created a practical 9-point pre-publishing checklist
Built guidance for turning broad environmental statements into specific, evidence-backed claims
Developed recommendations for founders, marketing, legal, compliance, and sales teams
Designed evidence tables, case-study analysis, and practical decision frameworks
My Role
I worked as the investigative researcher and sole author, taking a complex and evolving regulatory subject and turning primary-source research into a practical business-risk framework.
SourceTrace Investigative Research & Writing
Author: Nutan Navsariwala, Founder
The project demonstrates my ability to connect environmental regulation, evidence, commercial risk, and clear communication, and to turn complex research into useful decision-making tools.
Full whitepaper: [Link will be added here]👇
Who Is Actually Ahead in SMRs in 2026?
A reality-based diagnostic of the companies moving from reactor designs to physical deployment.
The small modular reactor industry is full of impressive reactor designs, ambitious timelines and billion-dollar announcements.
But there is a much harder question:
Who is actually ahead?
This research project examines the leading SMR developers through a different lens: verified progress toward physical deployment, not company claims or design maturity alone.
I built a reality-based comparison of companies moving through the difficult chain from reactor concept to an operating commercial plant:
Design → licensing → construction → financing → supply chain → grid connection → deployment.
The result is a competitive diagnostic designed to separate what companies say they will build from what they have actually demonstrated.
What the research examines
Reactor design maturity
Regulatory progress
Construction status
Financing and project backing
Manufacturing and supply-chain readiness
Customer commitments
Expected deployment timelines
Grid and site development
Commercial readiness
Evidence behind each major company's claim
Rather than treating every announced project equally, the analysis gives greater weight to physical and regulatory milestones that are independently verifiable.
The central finding
The SMR market does not have a shortage of reactor designs.
There is a shortage of companies that can demonstrate the complete path from design to a licensed, financed, constructed, and connected reactor.
That distinction changes the leaderboard.
A company with a technically advanced reactor but no construction project should not automatically rank above a developer that has already moved steel, concrete, and regulatory approvals into the real world.
The solution: an evidence-based deployment framework
I developed a practical comparison framework that evaluates companies across the deployment chain rather than relying on a single headline milestone.
The framework asks:
Can it be licensed?
Can it actually be built?
Is someone financing it?
Is there a credible customer or site?
Is the supply chain developing?
Is construction physically underway?
Is there a realistic path to grid connection?
This creates a more useful distinction between technology potential and deployment reality.
What I produced
Competitive SMR leaderboard
Company-by-company evidence analysis
Verified milestone comparison
Claim-versus-evidence assessment
Regulatory and construction-status analysis
Deployment-readiness framework
Data-centre suitability comparison
100 MW and 500 MW application analysis
Visual comparison tables and charts
Evidence hierarchy and source register
My role
Researcher • Investigative Writer • Analyst • Information Designer
I researched and structured the evidence, challenged the company's claims against verifiable milestones, built the comparative framework, and translated a technically complex nuclear energy market into a clear decision document.
The objective was not to predict who would win the SMR market.
It was to answer a more useful question:
Who has actually moved furthest from reactor design toward deployment?
Read the comprehensive research 👇