Applied AI · Cloud architecture · Complex systems · Worldwide

The expertise your most ambitious vision deserves.

Where hard problems become working systems.

Twenty-eight years across the first Nike+, data infrastructure for a Microsoft Research quantum program, Fortune 500 cloud architecture, and Retrieval-Augmented Generation systems running in production inside real enterprise permission models. Founded and run by Geoffrey Roth.

01

The domain keeps changing. The job doesn't.

Every few years the problem is something nobody has built before, and somebody has to make it tractable enough for other people to work in. That has been the job since 1998. The technology moves; the assignment doesn't.

2005–2009

R/GA

Consumer web, at scale

On the team that built the first Nike+, before connected fitness was a category. It took the Cyber Grand Prix at Cannes. Also the first e-commerce Nike store, and de-facto tech lead across nikerunning, nikewomen, Nike Be True and AF1.

2016–2018

Quantum

Data platform · Azure

For Microsoft Research, through GenUI: the Python CLI that pulled run data off the fridges cooling the processors near absolute zero, and the Azure platform that ingested it, so labs on different continents could share, visualize and annotate each other's runs. On-site with the physicists in Delft.

2018–2023

GenUI

Cloud architecture

Consulting architect, then Principal Engineer. Full-stack and cloud architecture for clients from seed-stage startups through the Fortune 500, and mentoring the engineers who built them.

Since 2023

Banyan

RAG · Azure

Retrieval-Augmented Generation (RAG) and Azure architecture for organizations whose accumulated knowledge is the product. Concurrently finishing an MS in Computer Science at Georgia Tech, specializing in machine learning.

02

Your knowledge is the moat. Most AI can't reach it.

Anyone can wire an embedding model to a chat box. That demo takes an afternoon and it will impress a room exactly once.

The hard part is everything after the demo: the part where it has to survive contact with thirty years of inconsistent documents, an actual compliance boundary, and users who notice when it's wrong.

01
RAG that survives your real corpus
Chunking strategy, hybrid search, reranking, citation integrity, and an evaluation suite that tells you when a change made things worse, before your users do.
02
Azure architecture, inside your tenant
AI Search, Azure OpenAI, Functions, Entra. Deployed under your governance and inside your compliance boundary. Not a vendor's, and not mine.
03
Systems your team can own
Documented, tested, and handed over properly. The measure of an engagement is how well it runs six months after I've gone.

Not every engagement is a RAG problem. Twenty-eight years of full-stack, platform and cloud work comes with the same principal, and it has taken me from New York to a physics lab in Delft. Location has never been the constraint.

03

Built for the environment you actually have.

Not a clean corpus and one permission level, but thirty years of inconsistent documents across four enterprise systems, and a security model that decides who sees what. Two years in production, described without the client's name because it is live. The interesting problem was never the model.

A large enterprise with tens of thousands of internal documents spread across a document management platform, plus a service management system carrying knowledge-base articles and years of incident history. Staff needed to ask questions in plain language and get answers grounded in the actual corpus, with citations, not a plausible-sounding paragraph assembled from nowhere.

Built on the Microsoft stack end to end. Scheduled jobs pull documents out of the source systems into object storage, where an indexing pipeline makes them searchable. A relational store backs the application itself, holding conversations and the excerpts behind every answer. The LLM generates; it never retrieves.

Staff reach it from a web application or from a bot inside the chat platform they already have open, both served through an open agent protocol so other clients can consume the same system. Single sign-on runs across two federated identity providers, and the identity that arrives is the same identity retrieval enforces against.

The hard part

Not everyone is allowed to see everything. Most RAG demos quietly assume a single user with access to every document. Real organizations don't work that way, and permissions can't be bolted on afterwards, because a model that has already been handed a restricted passage has already leaked it. Authorization has to be enforced inside retrieval, per user and per document, against the role model the business already runs on, whichever identity provider that user arrived through.

System in production · 2 yrs
Sources
Document and service management platforms · the systems of record
Ingestion
Scheduled jobs · source systems into object storage, indexed on a cadence
Index
Hybrid search · security-trimmed at query time
Generation
LLM · grounded, cited, retrieval-constrained
Interfaces
Web application · plus a bot inside the chat platform staff already use
Agents
Open protocol · so agent clients consume the same system
Application
Relational store · conversations and the excerpts behind each answer
Identity
Federated SSO · two identity providers in tandem
Authz
Role-based · enforced within retrieval, not after it
04

The systems that make groundbreaking research possible.

Research runs on software that nobody writes papers about. On both of these programs the science belonged to physicists and molecular biologists, and the engineering underneath belonged to me: the systems that captured their data, moved it, and made it usable. The links go to the programs so you can see what that work supported. My part in each is stated beside it.

Microsoft Research · 2016–2018

Topological quantum computing

Microsoft ran experimental quantum labs at Copenhagen, Delft, Sydney and Purdue, pursuing a qubit whose error resistance would come from physics rather than software. The labs shared an open-source measurement framework called QCoDeS, an acronym for the three universities that built it.

Each processor ran inside a dilution refrigerator, which the physicists called a fridge, holding it a few thousandths of a degree above absolute zero. Every run produced measurement data that had to be captured with its full instrument state intact, then somehow made useful to researchers in another country.

My part

Through GenUI, I built the Python CLI that pulled run data off the fridges, reading it via QCoDeS. Then I architected and implemented the Azure platform that ingested it, so labs across the program could share, visualize and annotate each other's runs. Some of that work was done on-site alongside the research team in Delft.

Structurally, it is the same problem I work on now: data nobody can reach, made findable.

Microsoft Research × University of Washington

Storing data in synthetic DNA

The Molecular Information Systems Lab, a joint Microsoft Research and University of Washington effort, encodes digital files into synthetic DNA. The appeal is archival: extraordinary density, and a read technology that stays relevant for as long as biology does.

The team set a 200 MB storage record in 2016, demonstrated random access across more than thirteen million DNA strands in Nature Biotechnology in 2018, and built the first fully automated write-store-read system in 2019. Its leads, Karin Strauss and Luis Ceze, shared the ACM SIGARCH Maurice Wilkes Award for the work in 2020.

My part

Through GenUI, I contributed to the encoding pipeline: the layer that turns binary data into nucleotide sequences a synthesizer can actually manufacture.

05

How this actually works.

A small practice can be honest about its shape in a way a larger firm cannot. Here is the shape.

You get the principal.

I write code on every engagement, not a discovery call followed by a handoff to someone you haven't met.

And a bench you meet first.

When an engagement needs specialists, I bring people I have worked alongside for years. The same names, engagement after engagement. You meet them before they start, and you keep working with the same faces throughout.

A handful of engagements a year.

Deliberately few, so each one gets a principal's full attention rather than a slice of it. If the calendar is full I'll say so on the first call, and tell you when it opens up.

Start with the hard part.

If your knowledge is your advantage and your AI can't reach it, that's the conversation I want. Tell me what you're building and you'll get a straight answer about whether I'm the right person for it.

Typically answered within a working day.