Techstrong TV July 30, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Visas Visas. Who's getting the visas? I think we're changing the program.
Or are we yet, we're going to kinda infl here. We'll see what the Trump administration wants to do around visas coming into the country. Broadband security.
We're gonna talk lot, a lot of great things. You're watching Textron Game. Welcome, welcome back again.
Great. Glad ahead have you here. We've got a great panel assembled folks that you know and love.
If you've been watching Textron gang, Dan O'Brien with their future and group COO President and Kate Scarcella. Chris Blask and Jon Swartz, and myself, Mitch Ashley. Good to have everybody here.
So John, you wanna kick things off talking about the discussions around visas and kind of what we think might happen or what they're talking about doing? Yeah, it's kinda like back to the future. So we, the H one B visas being revisited by the Trump administration.
There's a plan according to the new head of, uh, US Citizenship and Immigration Services, this gentleman's name is Joseph Edlo. He talk to the New York Times and told them, told the, the newspaper that the Trump administration plans to revamp the, uh, visa system for skilled workers by prioritizing those who are in higher wages. They also wanna make us, US citizenship tests more difficult.
In a sense, it's kind of signaling this direction that they've been going in terms of immigration policy and maybe even an admission that even predates them to the Biden administration. That the domestic workforce isn't large enough to support our country's ambitions in AI and emerging technology. That's been an issue for years.
Just getting back to Edlo, he insists the current randomized lottery process should be replaced with a system that prioritizes employers offering higher wages. And in terms of the current testing system, what they want to do is they wanna make it a little bit harder. They wanna ask more questions and they want more correct answers.
Uh, basically that's, that's where it all comes down to. So these are two things that are going on. They've been proposed.
They're trying to ram through, ramrod it through. And I, and I it brings me to this Dan, Dan O'Brien. What are the end goals here?
Um, where do you think this is going, or what do you think the intent is? Yeah, listen, I, I think H one Bs are, uh, a complex topic because they're wrapped up in so many, you know, larger thematic things, right? It's about, you know, not only immigration policy, it's about, you know, skilled labor and building a competitive workforce.
You know, it's about, you know, really building American competitiveness and key strategic, uh, you know, key strategic industries. Uh, and, and there's certainly a labor component, right? You know, in terms of how H one Bs affect the, you know, non-bias workforce, uh, the citizen workforce, right?
So, uh, you know, end of the day, I think the, the goal of H one B is, is really good goal and noble goal, which is, you know, we want to make America the place that the most talented and skilled labor from across the world gravitates to, you know, a lot of that starts in academia. We've got some of the best, you know, kind of colleges, universities, and institutions. H one Bs is really about trying to, you know, take all that talent that comes here to learn, um, and, you know, make them permanent citizens and, and find a way to get them, you know, kind of into our workforce.
Uh, I think, you know, there's been a little bit of, you know, kind of stray, you know, stray from the intent, I would say. And that's where overhaul may make sense. And that, you know, like anything, when you know, it gets into the hands of government and sits there for too long, things tend to stray away from original intent.
And, you know, other economic incentives start to take over. Uh, you've got lots of examples of, you know, tech layoffs and, you know, non visa workers getting laid off, visa workers getting, uh, kept on because they're kind of locked in at a, a lower salary rate, right? Um, I think it's a really timely topic, right?
We've seen the talent war in AI really pop off over the past couple of months. It's like, you know, free agency in some of our, you know, largest sport leagues. Um, you know, I think, you know, probably an apt analogy there in terms of the, the money being thrown around and, and the demand for talent.
Um, so, you know, it's a worthwhile topic to tackle. You know, I hate to see it ram through anything that happens quick in Washington always seems to, you know, have, have a little bit of an aura of something a little bit shady or nefarious, right? So I think a good open conversation on this and a bipartisan solution of getting back closer to the intent and the, again, the intent being build a really competitive labor force for American strategic industry.
Yeah, that's, that's interesting. I was just a, as a follow up, Dan, I'm, I'm really glad you brought up the idea of all these layoffs happening. At the same time, we have these acquisition wars where we have meta famously offering a hundred million dollars to OpenAI employees.
Um, we've got all these rumors of Apple and meta pursuing companies that they wanna acquire to acquire the talents. And with this as a backdrop, it kind of adds yet another dimension. But I think the intent, as you said, has always been, has always been pure, I think bipartisan viewpoint is to bring, to keep and maintain and as much talent as possible.
I'm not sure what, what the rest of you think, but that this backdrop of, of so many layoffs at places like Microsoft, while at the same time these companies are spending outrageous amounts of money, I think of OpenAI binding giant AI company. It's just an interesting, crazy time we're all in. Well, I think the Acquihire trend is really, you know, a regulatory failure, right?
You know, we've gotten to the point where some of these companies are so large that, you know, they're effectively blocked from making acquisitions, um, you know, by, by the FTC, right? And so the Acquihire trend is really, you know, free markets at work, finding a way around, you know, kind of government regulation that maybe no Longer makes sense. Yeah.
That, that was the scale ai, uh, example where you basically pick off some of the highest ranking people and most valued employees, and then you kind of dismiss the rest of the company and then let them fend for themselves, or you do a licensing agreement with them as Google has done. It's, it's, it's really kinda like a wild west atmosphere out there. And I think this in a sense, maybe they're trying to bring some sort of balance or normalcy to the, to, to the proceedings.
But we'll see, You know what I wanna point out, uh, Nick patients, uh, who's head of AI in the analyst group here at fu, we wrote a great analyst insight report about acquihires, talking about all these acquisitions, people going after talent. You, you know, Dan, it reminds me of in after World War ii, the race to gobble up all the rocket scientists. We, uh, the US had an operation paper clip, and I believe we attracted like 1600 rocket scientists, and Russia was trying to get 'em and all, you know, of course, that's what started our NASA program and Warner von Braun, et cetera.
So we're, we're kind of in that again, with the AI race. And I think it's, the thing about the random part of the lottery that I'm not so sure about it is maybe it's more fair, but doesn't mean we're getting the best people. The, the, and if you're going after people in material sciences or AI or rare earth or whatever areas that we need to kind of build up, you know, the US capabilities, I think you wanna be more targeted.
And my first reaction was, we want the most people that'll get hired at the biggest salaries. But I think that's the, the after effect, the effect is getting the right people who will attract those kinds of salaries, which is in the end, I think, a good thing. Getting Back to where autocracy Yeah, I, you know, these are all good, right?
You know. But, uh, again, let's step back back a bit. You know, I'll take a personal position on this that, uh, uh, this is part of the narrative that, you know, American needs to be pure.
We need to, you had to get everybody, get the foreigners out of our universities, get the foreigners out our business, get the people who don't agree with this out and build walls around and have a, a, a national supply chain and have no freight imbalances anywhere. Just have a completely, you know, isolationist to approach. And yeah, obviously, you know, the way I say that doesn't indicate that I think it's a bright bloody idea, but, you know, even if you do, you have to calculate these things in.
And, you know, what, how much talent, um, are we prepared to lose in service of that, that pur uh, uh, uh, and where do they go? You know, do, are we creating competition around us? You know, this.
Yeah. Again, these are all interesting issues. You know, these systems, you know, all of these systems we talk about in, in forms like this, they're all complicated, they're all messy.
They all have problems with 'em. This one I can criticize all day long, and, you know, each of these issues, you know, you bring up great issues, happy to talk about them, but personally, I don't believe that's what this is about. This time.
I think it's part of the same story. We all know that this is part of, Kinda like this isolationism. Yeah.
Sorry, Kate, you go ahead. Yeah, No, no problem. And Chris, let me like echo what you're saying because I, I believe that same thing.
And what do we, we are, we do have agriculture. I mean, we do have these other, um, vertical industries that do not necessarily, you know, bring in this higher echelon of, of people that we're looking for. So I don't think it's, it's easy.
And I think by putting regulation, we also, um, prohibit, um, companies from really trying to, to manage their own companies the best way that they know how I continue to see government stepping in, in places where it's, it's a very fine line at the end of the day. And, and I don't see this as a, as a, as the solution. Well, and as a, as an American, you know, the multinational, the multinational family, and like, I think everybody on the screen here, I'm an international life, you know, I can look at this from both sides.
You know, I'm very partisan for my country, you know, this is where I'm from. You know, I, I want America to do well, but I'm telling you, from an international per perspective, this is opening up all sorts of opportunities for, for others to make systems that may outcompete, you know, my phone country just on sheer logistics and quite often on the basis of what we've founded our country on. Well, I, you know, I, I, I'm, I understand the nationalism and the, you know, we wanna have people like us that live here, kinds of arguments or things that, you know, are, is that what it's really behind this or not?
I, if I put my, kinda, let's look strategically at what's important for our country. You know, we, we have the greatest economic engine, we have the greatest company building engine and innovation engine in the world. And I think we're at a place where, you know, rather than saying, let's overhaul the, the Visa system, why don't we say we want the 5,000 best AI people, material science people, then whatever, we'll say H one B program or not, I don't really care about that.
We want you to come, we want 'em to be here, and we'll compete against any other country in the world to get them here. And that's, that's an open fair competition. I, I don't care where you come from, whatever, now we gotta watch out for spies and things like that.
That there, there are consequences and side effects that can come from that, but I think that's what we want to go after. And we want, we want the best and brightest here. Whether they make the most money or not isn't necessarily the question, but, uh, this is the place I think the world will benefit the most by them being part of the us.
Yes, I say that out of great self-interest too. Yeah, I mean, it does look this basic, um, tinge of nationalism with involving anything around this administration. I mean, I'm, I'll, I'm gonna kind of, uh, highlight what Alan would probably say.
It's, it's like in a sense, in a sense, I understand what the, what the administration is trying to do, but the, the fact that it's from this administration always gives me pause. But I also think that we look back at the Biden administration, this was something they were trying to navigate as well. And I think the ultimate goal was the same.
I think the way this administration will probably handle will be heavy handed, but I also think that they're gonna have a fair amount of input and collaboration with the tech industry, which is basically in bed with this administration. So in the end, it will probably help tech more so than any other industry. Alright.
Anybody else? Anything to say? We'll move on to our next topic.
Alrighty. Why don't we do that? Um, thanks.
We'll, well, I guess we'll have to watch and see what happens. See where this goes and what, you know, what are the reasons that we wanna revamp the H one B program? Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Welcome back to Techron Gang. Hey, there's a very interesting thing that just went on. There's a 50-year-old Arizona woman who pled guilty in February to her role in this massive North Korean IT worker scam that generated more than $17 million for that country this week.
She was sentenced eight and a half years in prison. Her name is Christina Marie Chapman, and her sentencing is the latest step in the justice department's wi widening crackdown on North Korean workers scams, which have proliferated since about 2020. Kate, can you talk a little bit more about this and, and kind of the, the logistics of what they were doing?
Sure. So Christina, uh, so Chapman basically created what was called a laptop farm. And she was storing dozens of company laptops, configuring them to allow remote access, um, by North Korean agents posing as US citizens.
She, um, she stole, there was stolen identities from 68 plus Americans. And, you know, as you said, 17 million in illicit revenue, which is, you know, crazy. The other, um, significant point here is that it went cross vertical industry.
So what do we mean when we say that it was media organizations, which is fascinating in itself, aerospace and tech companies in this time that we live in, uh, from media, uh, and disinformation. I think it was very, um, definitely an industry that, that there was a reason why they went over that. And what the other unfortunate thing that I see with this case is that it will push companies to go back to a centralized model.
And that's concerning, um, for, you know, in order to, you know, shows the vulnerabilities of remote workers, right? And so the response is, you know, usually there's something that happens and then we have the response, and the response is, oh my goodness, let's bring everybody back to, you know, the, you know, the shop. The problem with that is it does create a centralized workforce.
And I believe in this day and age, it's really important to have a distributed workforce. So, uh, yeah. So Chris, what do you think, um, when you look at this, You know, let me, lemme start all, all the way in the outside to be clear, I'm looking at this professionally, coldly and academically.
So, uh, um, from the outside, I, I am just impressed that, that, uh, this individual did such a clean hack. So simply, you know, with a couple laptops and just sneaker net, right? That, that, you know, as, as a, as a fellow hacker, well done, um, as a, as a, as a active professional in this, I think this is a good example for us to, as you say, it, show a weakness in the system and, you know, follow the next step of your, your comment.
And we, we sort get into the last segment where you say, okay, I can put my company in Salt Dome underground and hire more employees and mine matos. You know, that point gets fragile too. So we have to have both, we have to have these remote workers, but we can't have someone literally as simple as just getting a couple laptops and a control c, control V, and all of a sudden you, you know, that breaks into our system.
So we need supply chains. The things that are going on in supply chain security and threaten talent and information sharing over the last decade have been really amazing. The last five years have been really good in supply chain, particularly, and I think they apply to this exact case.
You know, if you find yourself relying on a system like this for remote workers, then maybe it's the wrong system. And if there isn't anything else available in the market, then you should look for one that is, because I think it's possible now, Well, not only that, Chris, right? We have security mitigation controls that would have shown that, you know, like anything from identity and access to end endpoint detection response, you know, being able to show, you know, dual actions on keyboards, on, you know, on a mouse.
And there are tools today, really good tools out there, and I find that we continually within organizations choose not to put those security mitigation controls in place over and over and over again. And it baffles me. Yeah.
I kinda had the same reaction. No, I had the same reaction, Kate, which is, we have, we have technology to solve this. You would've seen that when a device comes on on board and you went through a scan or, or start doing something nefarious, and not everybody can afford to put endpoint protection on their devices, but it's not that expensive.
You can spend a lot of money on it, but it's not that, you know, out, out of the wild. Crazy. It's kind of funny, this Korean operation seems like they opened up their own a remote branch of Geek Squad in the US from Korea to That's Funny.
You're so right. You, you're absolutely right. Careful.
You do business where, Uh, Chris, I stepped on you, you were gonna say something. I was just gonna say, right, you know, because, because you're both right. You, you know, you can, you know, obviously the, the targets were not doing all the things they could have out of the box.
And there's interesting reasons for that. And when I say you can now, I mean, if you were really diligent, did the right things and had the budget and hired the right people, and they were good, and you coordinated plans, you could have done all these things two, three years ago, 10 years ago maybe, who knows? But I think that we're at the spot where in two or three years, if you were not doing these things consistently all the time, you don't exist as an organization because I don't know anything about this individual who did this, but I'm telling you, if it had been me and all these companies were doing in the top 10% of what companies do, I'd break all of 'em anyways.
Um, and it turns out any amateur can do it. 'cause I'm assuming she didn't have any great cybersecurity jobs because again, this doesn't require them. You can literally just do, uh, a random things.
And sure, if you have a whole sector to go after and there's 200 companies, maybe 40 of them, you can't get into, I'm being really generous. So it's the reality of doing it as opposed to the ability to do it. I think that we're on the cusp of Can I ask you a quick, so this, this, These types of scams have proliferated, especially in the last few years.
Is that tied into leveraging AI tools to scale their operations? Or, or is it something else? Limited extent, probably, but the speed of things, yes, it leads to that, but I don't think there anybody's using 'em appropriately.
I, on either side. So I think the defenders have an advantage if we move, right? Sorry.
And, and I think to Mitch's point, right? It's, it's literally, or, um, in both Chris, I mean, it was, it was so simple. It's remote access.
I mean something, you know, as Mitch said, like this geek squad, I mean, literally that's how simple this, and it, it's brilliant. I, I mean, you know, back to Chris's point, I mean, this was, it is brilliant and the simplicity of it is brilliant. I Think this is an area for some innovation.
And let me throw out a wild, crazy idea. There's this thing called OpenTelemetry and a whole bunch of vendors band together and said, you know what? We're not gonna differentiate by the agents that we put on our devices.
We're gonna differentiate by the telemetry information that comes from all of those devices. And yes, we'll still have agents too. I think something similar like that could happen.
Microsoft started locking down some of the things you can't do in the operating system any longer, partly in response to the CrowdStrike incident, um, that caused it to blue screen. Not only that, but they needed to do that. Apple has already done some of that.
Why isn't this protection? Why is endpoint protection built into the operating system? Just make it secure from the beginning.
Let the management systems, you know, that's where all the workload and the workflow and all the real, you know, heavy lifting has to be done. And I think that would, I'd love to see an open source project like that. I agree with you, Mitch.
I mean, I do think innovation is the way out of this. I'm not, I'm not sure it comes down to, you know, the endpoint protection, protecting the device. This, to me, feels more of a, we've gotta start to actually wrestle with how do we connect digital and physical identity in an increasingly digital world.
Like how do we know that the actions being taken online are by a real person, by the person who that, you know, actor claims to be, right? I mean, that's, that's ultimately the issue here. And, you know, feels like biometrics could be an issue, but there's a whole world of privacy and, you know, anonymity concerns there that, uh, I think we're gonna have to wrestle with as a society.
But, you know, this is in increasingly creeping into our lives. Anybody who's flown recently knows that you're getting your picture taken at TSA and they're using AI to make sure that it really looks like all the images they have of you on file, right? Uh, but I think that's increasingly the issue here is how do we make sure, you know, digital and physical identity can be tied together and people are who they say they are when they're acting in this digital world.
You know, we're not far from doing this scenario where that that person, men or women who might be, um, could actually have digital avatars that lock, you know, walk, talk, you know, interact like people. So they, they could have had, you know, 20 of them out there running around interfacing with different companies once they're good enough to not to be able to detect it easily. So it, it's gonna get easier to do this kind of thing.
To your point, Dan, connecting the physical identity with the digital presence in whatever form that is. Yeah. You know, and I, I think this whole story, this segment is, is a good example for me to try on this one, right?
You know, to be clear, North Korea and the North Korean regime can bite me. You know, I could not be immor opposed to any, uh, set of people on earth. Um, however, you know this, I like this story because this stuff happens all the time.
Doesn't matter who the threat actor is. And it, as we discussed, illustrates how sim it illustrates a structural flaw. And in, and what we were just saying, uh, Dan, right?
You know, the, the, yes, it's all true. And, you know, and in this forum we're talking about things, you know, that are happening right now. Things our audience can understand and do things with.
AI is the term we use about this new semantic systems and so forth. And you all know, you know, on the screen and maybe some of the listeners getting the, that's a big focus of mine, but I'm not gonna sit here and preach it all because we need to think through this. But for the same reason as I like this whole story, I like the idea you have everything you just said, Dan.
'cause yeah, we need to do all that. And if you think we're going to config file our way through this, I challenge that. I think we can build semantics systems.
I think what we're calling AI right now actually lends itself directly to all these issues, but it's not what we're using it for. And I think this calendar year, a lot of people will figure that out and will in forms like this, I predict for a New Year's show, we'll be looking back to shows like this and saying, oh yeah, that's right. How we, you know, so we'll get there one step at a time and we're learning, All I know is they still have to install and a anti-malware software.
That's kinda ridiculous. Really? Do I really need to do that?
Why isn't it, why isn't already there? Wishful thinking on my part. All right, well, I think we've, uh, done well on this topic.
Let's take a quick break and we'll be right back with the textron gang. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. We are back on the gang. And, uh, we're gonna talk about something moving the goalposts we're alluding to.
The FCC is set to vote to abolish a policy goal of defining high-speed internet as a thousand megabits per second for downloads and 500 megabits per second for uploads, which was proposed by the Biden FCC. Well, we're under the Trump FCC, and they're proposing to maintain the benchmark at a slower 100 megabits per second per downloads and 25 for uploads. In a sense, they're, they wanna lower the goal for a benchmark speed.
And I'm wondering, what does this lead to, Chris? What, what are we looking at now? Oh, well, you know, outta the bench.
I don't like it. Right. You know, and I can argue like, like we do in these things before against, you know, various things and policies and benchmarks and whatnot.
But, you know, this is, you know, to me it's a, it is a visual regression. We're, we're lowering our aspirations and setting our expectations lower. And as we get practical about this, bandwidth matters, you know, this is digital democracy, you know, people's access to information is directly connected to their abilities from childhood to, you know, birth to death and setting lower, uh, capabilities and access to information for ba you know, for lower economic strata.
You know, that's how you get ants. Um, so, you know, one outta 10 would not recommend We, in, in a sense, I mean, what lowering the benchmark speed is likely gonna create less investment for fiber networks and higher speeds they enable, right? Dan?
Is, it is, in a sense, it seems counter to what's going on right now in the rest of the Industry. Yeah. Listen, I think there, there's some good, there's some good motive behind this in that they're really trying to allow for what I consider to be incremental technologies like starlink and, you know, project Cooper from Amazon that are really taking and distributing what would be historically considered pretty good bandwidth to places that have never really been built out by, you know, fixed infrastructure.
But, you know, I, I think we continue to consume, you know, more compute, more data. We need more and more bandwidth. Um, you know, the, the existing regulation was actually really well incentivized to kind of drive private industry to continue invest in the infrastructure that the country needs.
Um, you know, I think it's being pulled back in order to really protect, you know, kind of this, what I again, consider a complimentary technology and that, you know, I I just feel like this would be better served by having left the existing kind of regulation in place and really try to find a different way to create incentive on building out kind of the satellite style, um, connectivity that is really, um, you know, spreading to parts of the country that had been underserved by, you know, existing infrastructure investments. Yeah, I'd agree with taking an additive strategy on this is makes a lot more sense to me. Uh, I spent some time in, in the broadband and also the cable industry.
And when they put these standard is in place, the part of the, in the motivation for doing that is thinking of the network, whatever presence it is, whether it's wireless now with satellite with the two as well as, you know, fixed cable and fiber is really having, having a substrate to innovate, whether it's businesses, people at home in school that we've got the technology, we've got the platform, we had the network to be able to do this. And frankly, competitively, internationally, we have to keep up. We can't just, well, the mo the, it isn't what the market will bear, it's what the market will tolerate.
Because unless people invest in providing new services at higher speeds, they'll just continue to kind of milk the, the revenues that we get from that. But that's how we got one gig today. 0 that's put together by Cable Labs.
I, I, I ran it there. I also had led a company called Kerio that did all the certification testing of DOIs equipment, and that's what spawned, uh, uh, spawn DOCSIS or that standard over cable and fiber to move from one gig to 10 gig. That's, that's the goal.
And there you actually borrow a lot of technology from wireless, uh, to be able to do that. Some real innovation happened from that. So I think to your point, Dan, it's, it should be additive.
What can we do to help the satellite folks or other alternatives? Uh, maybe there's a, a point of presence where we can, the popup networks or whatever kind of business model might evolve out of what the military does today. There's a lot of innovation and opportunity to happen.
I don't think lowering the standards gonna fuel that. Well, let me argue the opposite of what start with, right. You know, so yeah, as I said, everyone's really not a big fan of standards and regulations and laws and so forth if we put 'em in when we have to.
And sometimes they're really useful. But Dan, you touched on a use, um, important thing and, and starlink, you know, I'm, I'm an early starlink user. I, you know, know the nice lady that built the damn thing.
Hi Gwen, if you're watching good, good choice. Um, it, and it is screaming fast down, but slow up doing a show like this, have a long upload and it's a different thing. And both in the, you know, I can set up five miles offshore and do a show like this.
And in those environments we look a lot of high and low latency and high and low bandwidth communications between devices on, you know, uh, devices on open water and in civic ai, we're looking at the same thing. It's really a lot of low bandwidth stuff in the similar way. We overprocess, we're gonna have Moore's log get faster processed, bigger machines, bigger super computers, and at some point you say, we could distribute this and we don't need all that.
So all of that applies to my thoughts about this, because I, i, if it's always true, then we have to have exabyte downloads or something and we can't have TV anymore or something. And it, it's not how that works so well. Yes, I wanna keep this one going up to all the points I is making.
We also need to rethink how we're using bandwidth anyways, but that's a broader topic. I mean, I, I agree. Um, first with what Dan was saying, um, so sticking here with Dan, um, it's unfortunate that we have to, uh, you know, change these standards because, you know, just coming from a network perspective, uh, which, you know, many of cybersecurity people came from, you know, this whole idea of, um, of load balancing and, and I don't know why we can't create like the, like an initiative like that.
Like it doesn't take away, um, why do we need to take away from one for the other? Why can't we just keep the one running, you know, let that horse run and the other one will, will, let's incentivize it Sure. But not take away from those standards.
I I, I don't, it just doesn't make any sense to, for me, I don't agree. Yeah. I just put myself in the shoes of, you know, say a consumer in rural Appalachia who has never been able to get good connectivity, are they not going to be thrilled with a hundred megabyte per second starlink connection because it's not labeled, you know, high speed.
Uh, they are, I think that, you know, they're thrilled to, to get the innovation, um, and, and be consuming something that's still very competitive in the market. But, you know, that doesn't really go away from the need to take our, you know, massive data center buildouts and our, you know, large, you know, high concentration cities and really drive them more towards, you know, high performance, you know, fiber, uh, and, and optical connections, right? So just feels really misguided.
Um, and you can't help but wonder, you know, whether, you know, Musk's influence within the administration in play here, right? Um, you know, obviously, uh, you know, uh, a Bezos on the other side with Amazon on the Project Cooper side, but, uh, you know, uh, as we've said in the past segments, uh, very tight tie between the tech industry and the current industry. There's like this basic disconnect here.
It al Al seems to me too is at the same time where the FCC is looking into this, we've got, as Dan pointed out, we have this data center build out in places like Ohio, Pennsylvania, Texas, where, you know, the access to high speed may be wanting in some areas. So, um, to me it just, I don't know, it just isn't, doesn't quite make sense, but that's me. No, that's a good point, John, right?
Yeah. Sorry Mitch, go ahead. Oh, no, no problem.
You just go ahead, Kate. Well, I, I, I mean, you know, to your point, and even, you know, going back to, to the city, why not use fiber optics? I mean, fiber optics is proven.
It's just, it's, it's proven. It's fast. So I think, you know, and then going back to the data center, we need that type of speed in those areas.
It doesn't mean that we have to take away from those for, you know, the person in Appalachia, as you pointed, Mitch Yeah, a decade ago I had the only DSL on Douglas Lake in, in the Smokey Mountains in Tennessee. Right. You know, so I lived this.
Right. You know, and, and so much of it, and again, you know, at the topic is sort of off topic, but if I had systems back then, they would just understand that I don't really need that 20 megabyte file all, you know, just slow it down because I'm doing something else. And at the technical level, we talk about quality of service protocols and everything else, but we, again, we reach a level of complexity.
And having helped me, we have these semantic tools that are laying around that can understand you're Dan and Kate and what you're doing, and slow things down for us without us having to vi all the files by hand. No, no, I, I was just gonna say part of the, the regulatory front is who is leading and what their approach to regulation is. Wheeler who ran FCC for a while was really pushing, uh, net net neutrality and these kind of standards.
I think neutrality kind of got, got a lot of attention because, you know, now the carriers can't do anything that favors them in terms of how they run their network or what they use with the data that's traversing over it. And maybe you can, you can question whether that was a good thing or not. And Carr, I don't remember.
I think his, Brandon Carr is, his name is the FCC head Now, he was opposed to net neutrality and he was more, he was in favor of deregulation, but he did like the wireless industry. So there's biases with whoever comes in. And I think it's, yes, it's Musk and, and others, but it's also who you put in charge to lead in it.
It is a very political position, the FCC, 'cause it drives a huge amount of income, uh, revenue for, for the us. Go ahead. Go ahead Dan.
Thanks. Yeah, no worries. I I, I was just gonna add, you know, at some point I think we have to have the debate, you know, what point does connectivity become a public utility, right?
Like water, like energy. I mean, I, I feel like we could argue we're already there when we've been there for a while. Um, but you know, it's interesting.
That doesn't come up in the context of a debate like this. And, and this is exactly the kind of all my pla past po political, uh, positions collapsed into one on, on this sort of thing. Because I think if we codified that in our traditional way right now, in 10 years, we would realize it was incredibly stupid.
Right? You know, we can look at our, our recent past and say, here's how it's going to the future, but I just fundamentally disagree. So how exactly we navigate that and, you know, I don't know, you know, I may have to, you know, even burn my libertarian old hat, right?
Because it's complex. We don't know, but we need to talk through, we need to think through it. Yeah.
I mean, what's more valuable, the post office coming to your house every day, or, you know, reliable digital connectivity. Um, we've read our bets. I'm not sure they're the right ones anymore.
Right? And how do we make a, a, a, a group decision on that without investing in a legacy type technology and infrastructure that's just about to die and then, and all the other usual failure states, but maybe we're smart enough to navigate that. Well, and you have to go back to first principles of what is important about the network.
It's data. That's the only thing that traverses over a network is data, right? It's the oil of a pipeline, in this case, a network.
And if we had constrained pipelines for getting oil to different places for refineries and gas and technologies that, that deliver those goods to, you know, the nation that would star us, that would star eCommerce, that would, I mean commerce, that would star transportation. Many things. And to your point about, you know, whether you wanna nationalize it or become a ra, uh, a, you know, a utility or we, we favor it with regulation and like a utility, it really is because if we constrain it or we don't lift it up enough to grow with, with what our needs are, we will continue to bump up against constraints, uh, that we won't be able to take advantage of.
And we're gonna go get those 5,000 AI scientists to, to come to the United States, join our Visa program, but they wanna have a network to do what they can do because they're gonna think of innovative things that take five times as much bandwidth as we use today. And that's, that's about building that platform that we innovate on. That's a nice, that's a nice, that was, sorry, said that's a nice tie in, uh, pitch to the Visa thing, is it kind of is related, like how do you, how do you encourage your maintain or key people here?
Well, at the same time you're doing this other thing the FCC is looking at, I mean, is this kind of a, it's kind of a cross mixed, mixed message. Well, and I think, you know, mi Mitch, what you said that it was, was, was very good, but let me, let me flip it over or take obsession with, uh, uh, exception with it. Because I think what, you know, the most important thing about the network is the people.
And, but we've built networks for the data, you know, and how offense can I get the data and how much data and the quality of the data and everything else. And we kinda lost the fact that it was humans. And, and, and again, we made ais, but damned if they don't act, look just like humans, and we forgot about them too, right?
So we can get all the data moving back and forth, but we don't understand that my mom lives in Indiana and she, you know, does this and that. We're, you know, and our systems don't recognize any of that, then yeah, we'll just keep engineering to the, to the zeros, you know, and increasing the bandwidth and having a Moore's Law thing when we, none of us actually wanted those things, but we wanted to be able to talk to our grandkids and watch movies and, and, and, um, so we need to, you know, if that makes us sound a little hippie, then I think that's kind of the point, right? So you're saying we should go back to using Gopher and some early standards for, you know, looking at large bulletin boards.
Well, I think if we look at, at what we actually want, maybe some old stuff, he, I know things that, that I have downplayed all my life rituals and traditions and, and rhythms and so forth, you know, turn out to be very human things. And we bake those out of our systems and we get really high bandwidth, but no fidelity, so who cares, right? Well, we don't always recognize what, how important an innovation is.
'cause I remember seeing Mozilla for the first time and I thought, what would you do with that? And then I start thinking about it. You start coming up with ideas of my first reaction.
Okay, all right. Looks like a document reader. But no, it's a lot more than that really usually innovative kind of technology.
Well, we'll see whether they, uh, pull this back. Certainly, uh, that's the direction that they're heading. So.
Well, thanks everybody for being with us today. Thanks to our great panelists, uh, gang members that have joined us, and we appreciate you spending your time with us too. You know, we've got a lot of great programming that's coming up on strong tv.
You know, we, uh, yesterday we had the, uh, the VMware event really that's talking about the VMware platform platform nine and some really innovative things that, uh, VMware has kinda restructured about, we talked about on the gang yesterday too. com. You'll find a place you can go watch it on demand.
I think it's worth checking out some really good talks and presentations there. Dan, Kate, John, Chris Taylor behind the scenes. Thank you everybody, and we will see you next time on the Textron Gang.
Hey everyone, welcome back here to Techstrong tv. My next guest, this is a name I'm I Practice. I think I'm gonna do it.
Her, her first name's Easy, it's Priya. So lemme introduce you to Priya Vi Raj and John Vi. Raj and John, am I close?
Priya, Alan, that's very nice to be here. That's impressive. Vi Rajan.
That's right. Okay. If I said it more, maybe it would roll off my tongue easier, but you know, like you told me, I did it in syllables anyway, Priya is the CEO of a company called asap.
That's what, two piece A-S-A-P-P. And, uh, we we're going to hear all about it. But before we hear all about asap, let's find out more about Priya Rio.
Welcome to Tech Drunk tv. It's great to have you on share with our audience a little bit about your journey to be becoming CEO here at asap. A first of all, thank you for having me today.
Pleasure. Well, you already introduced me with my name, Priya Rajen, by the name. I come from southern part of India.
Um, as most of my peers, uh, studied computer science, strong engineering background, my fascination was solving harder engineering problems. That's kind of how I grew in the computer science career. I started with the best enterprise software companies, like SAP in Europe.
Uh, been there for almost 19 years and then, uh, pushed myself, uh, building products with AI at IBM for about three, four years here in United States. Moved from Europe to here, and then, uh, worked at Microsoft, leading the data and AI portfolio for about three years. So my journey was more towards how can I find harder problems?
There was a point in time where, uh, the solutions, um, what technology to apply and what business impact that we are we solving became my inspiration. So it brought, that's how it brought me to asap. Excellent.
Excellent. Um, well, you opened that door. Let's walk through.
Tell us about asap. Yeah. Uh, coming from me, I joined ASAP as a CTO of the company because, like I said, ASAP has been on a journey to solve one of the hardest problems in contact center.
You and I talk to our favorite brands every day by picking up the phone. Of course, you're not connected right away, you're waiting for 30 minutes, right in the phone call, uh, trying to be connected, or you're trying to have a chat conversation. This problem is a prime AI native problem, millions of customers, billions of interaction generated.
And how do you best solve it? How do you give that personalized, um, uh, Asian tech experience to these cus consumers who are calling for something to be solved? Either you could be a someone who is stuck at an airport trying to rebook your flight, or you are a customer who's trying to understand why your bill is so different this month compared to the last two months.
Or you are somebody who's waiting for your e-commerce order, wanting to track an order. The problem could have different degrees of complexity. With deep integration into this as a technologist, I, this problem was too addictive not to solve.
So that's how I joined asap. And over a period of time, I grew within the company. And, uh, this is an industry for the last 60 years wanting to be disrupted.
Not just me as a company. We're very passionate about solving the problem, going to the root cause of how do you completely redefine futuristic contact centers, putting the experience of the customer together with humans in the middle of it. That's what ASAP is solving and with the team of asap.
I love it. I love it. So, you know, I, we always prepare notes for these, uh, interviews.
And so the headline on our note for this one was the AI company that said no to chatbots and won, right? And, uh, let's tell us a little bit about that story, if you don't mind. Yeah.
Uh, you know, um, it's been 28 years I've been building enterprise software for large enterprises. I've gone through the curve of technology shifts, you know, from three tier architecture to cloud and others. So when, and I've built chat bots even in my career.
So, um, lot of us, when we said AI is commoditized, it's happening for everybody. And rightfully so, contact centers where not getting any outcome out of it because they're spending a lot of money on maintaining their infrastructure. They are hiring more and more agents, but agents are quitting also because it's not an easy job for agents, but your CSAT score, your customers are very unhappy.
Like it's a, it's a cycle of its own. Um, and out of desperation, many folks are looking for any incremental innovation, we can call it as argumentation, Hey, can I do anything to my agent? Who can service this better?
And those are abilities to deflect. You could have chat bots or you take an entire flow like Alan is calling your favorite bank to say that, Hey, I have an overdraft situation. So it's a very determined flow where you are automating some parts of it.
So it's, it's a very chosen some aspects of workflow automation. This is just, just having like a pill which eases your symptoms. It's not really solving it, it's only a bandaid to the entire problem.
It's incremental in nature. And that is why ASAP did not chose that route. It fundamentally goes into how do we scale automation?
How do you really solve the problem? And which means you need to transform the workforce. You need to transform the entire experience by having an autonomous agent in contact center, which understands the nuance of how a banking customer would call and how do you respond to them without having to work through a data workflow.
That's the power of this technology, Alan. So think of like your hiring your best agent, who is gonna be 24 7 across the channel, voice chat, SMS, any medium always available for Alan whenever you're calling. That's the pro promise That's valuable.
That's valuable. You know, you're, you're right. People tend to think that chatbots are invented with ai.
No, they weren't invented with ai. Chatbots have been around for a long time, and, and I think unfortunately for many of us, including myself, a lot of the chatbots, uh, experience was less than desirable, let's say. Right?
How many of us, even, it's not a chat bot per se, but it's an audio chat bot on the phone and we start screaming representative, representative, representative, right? Because you just wanna get through the chat bot and get a live person that I could talk to. Yeah.
I think it, another important thing is people tend to think of how, how can we use AI to replace the human, not, not make the human better, not supplement the human, right. And I, and I think this goes beyond chatbots, frankly. It goes to the whole core of the AI thing.
Yes, there'll be some jobs that the AI does instead of a person, but for the most part, at, at least now, especially the AI is a copilot, not a pilot, right? The AI is a force multiplier, but not the force, Right? And, and I think we, we need to remember that, right?
And, and those workers who embrace AI as some, as a help, not as a threat, I think are the ones who are gonna do well in today's economy. And world companies like ASAP that recognize that will do well versus the ones who say, okay, we're here to, you know, make you into a horseless carriage and we're, you're a horse that we're putting out to pasture. Exactly.
It, it's not about bringing an extinction extinction to a certain workforce. That's never going to be possible, especially in an experience industry. So ASAP has a very, very strong point of view.
Companies who are trying to solve this harder problem should not choose efficiency over empathy. That's a not a good place to be in. So aaps point of view is this landscape and the way in which we give the experience will change for sure.
To your point, there are productivity capabilities supplementing, augmenting or actually leading so that the existing human agents can go and solve some harder problems. They can actually have an oversight. They're also feeling good about what they are.
It raises the bar to everybody. Everybody needs help. The agent who's serving it needs help because he's looking at 10 screens trying to get on top of the policy and compliance.
And of course it's error prone trying to serve this. Imagine this person is watching an AI answer all of this because it's digitally integrated. The person is approving or acknowledging yes, it's the right decision to do it.
The job changes in terms of what the human agents gets to do it. And so that's why the point of view of about, um, it is a contact center with AI leading where humans are providing the right oversight, the coaching and uh, monitoring abilities. So in fact, we launched some of our very powerful capabilities, um, by working hand in hand with some of the most complex and scaled enterprises in the world like airlines and telco industries and most iconic brands that we can imagine, Alan, they appreciate the fact that human agents are available in the loop as an approver of some of the decisions AI is making because trust and explainability of AI is very, very important in contact centers.
The fact that anybody, any supervisor can monitor the conversation. So your age agent is treated like a human agent on how are you conversing? Is it the right tone, is it the right recommendation?
The monitoring? And lastly, which is the real USP of it, is how do you put such a probabilistic system in front of your consumer? The fact that you can test it.
You're not gonna wait for 1 million conversation and then realize, oops, that didn't go very well. The fact that you can simulate and fine tune it live, it's almost like a living thing which learns based on the conversation. So these capabilities make it really possible.
And it's not just a vision, it's really happening. More customers are live with it. So the, we just launched recently and yesterday we made it as a general availability announcement as well.
You heard it here. Thanks for sharing. We always like to get a scoop out there, Priya, so we appreciate that.
Um, hey, you know what we did, we didn't even mention the website once. What's the URL? com.
com. Dot com, that's Right. Is there a story why there's two P's on as SAP P?
There is no story. com. Uh, there's no, uh, story behind the alphabets.
But, uh, any of the listeners, both the technologist and the business stakeholders, I want them to know that ASAP is fundamentally rethinking customer service like an agent. Um, we are tired of waiting for an agent. We are tired for somebody not remembering why you called.
Enterprises are tired of spending a lot of dollars. Do you know an average customer service call? If you had called any brand to the, this week, it cost about $7, Alan.
That's how much really companies per on answering this. And, and sometimes the call goes to 30 minutes to 40 minutes, not just the agent time, the transcription, the recording, the analysis lot goes behind the scenes. So if we can go and scale that industry to be like, what if we are able to serve this bringing 50% more containment?
Containment is you are able to solve the problem for the customer. That's what that containment metric means. You're able to double your containment with half the labor and four times more efficient and 25% less ineff, um, uh, mistakes that it's not, could be made by human agent.
That's the promise that ex excites both technologies. So when you are building on top of the unprecedented pace of innovation, which is happening in generative ai. With all the right things about foundationally building on top of lums, having our own architecture with multi-agent orchestration, our time is well spent in disrupting this industry.
Yeah, Absolutely. Bria, thank you for coming on here and telling us a, I know short period of time, you gave us a whole bunch of information, and I appreciate that. Uh, you know, I, this, this whole help desk call center, you know, support the area is one, like $7 a call.
I think that's eye-opening to people out here. It's one that, it's a huge, a huge need. And it sounds like you guys have built a, a better, a better solution.
So keep doing what you're doing. Keep us posted. We'd love to have you come back on soon.
Um, until then, thanks for coming on Textron tv. Absolutely. Thank you, Alan.
Next time you are flying in airlines or calling at Telco, you know, you might need to, I'm gonna remember, I'm gonna say to myself, that was $7. Okay. Or you're talking to an ASAP agent, so thanks.
It's an AAV agent. Even better. All right, we're gonna take a break on Textron tv.
We're here. We'll be right back. Hey guys, thanks with Throw, we're here with Rohan Gupta, who's vice president of Cloud Security and DevOps at our systems.
And we're talking about well, chaos engineering. Rohan, welcome the show. Hey.
Hi Michael. Glad to be part of this. Right?
We've kind of been talking about chaos engineering for many years now, and yet the adoption of it has been somewhat uneven. And I think a lot of it has to do with the fact that the systems are so complex that a lot of people, well, they're just hesitant to deliberately break something and they're spend all their time trying to just make sure that damn thing works. And now you wanna come along and deliberately destroy something and then get a little apprehensive.
But from your perspective, um, it almost sounds like maybe we've reached a point where chaos engineering is now essential. So like when it comes to chaos engineering, and you've just pointed it out very nicely that it has been in the market for quite some time. Okay.
But for what I believe, chaos engineering is not about disruption. It's more about learning. Okay?
Learning about how your system behaves when an actual disruption occurs. Okay? And that is something that we have to start incorporating as a culture, uh, instead of doing it as a sidekick project, because most of the organizations love the way on how chaos engineering worked, but never integrated it as a part of culture.
Instead, they just incorporated it so that they can get some fancy dashboards, get some outage summary, and show it to the management. But now it's slowly changing with all the outages that has, uh, been reported. Uh, and even on cloud, like for example, people think that if they move from on premises to cloud, uh, the SLA objectives have, uh, improved.
They do not have to test chaos or they do not have to worry about disruptions. But that's not the case. In the last one, one and a half years, we have seen a lot of disruptions, a lot of outages, where now people have started implementing chaos, integrating chaos in their culture so that they know at one given point of time, if there is a failure in the service mesh that they have been engaged with, they know on how to fix it.
They know on what the R-T-O-R-P-O impact is. So yes, it's now a culture and it's more about learning than disruption. And we also reached a level of complexity in our systems where it's just impossible for any human to kind of keep track of all of that.
So we need a different approach. And chaos engineering kind of shows us where all those dependencies are Absolutely. For us, as the system grows.
And we have seen it with enterprise organizations, we have seen it with mid that organizations too. Now it's, it's more complicated. There's a lot of APIs involved.
There's a lot of, uh, third party integration that are involved and people do not care about on if it's a third party integration. We don't have to worry about the outages. What chaos gives you and what we feel chaos would give people the ability is to actually get the failure endpoints that nobody cared about.
Okay. Not the actual outages. Like nobody right now would work with traditional chaos experiments.
Now people have started designing custom chaos experiments, which are, which are revolving around third party integrations, which are revolving around, around service measures where nobody was able to actually pinpoint what the failure is. So all these custom experiments that people have started writing have now given them the ability and confidence to be able to say that, yes, our systems are resilient and we know on what happens if there is an outage. We have a rollback plan, sta strategy, we have an observability in and around it, and we have an hypothesis what, where it has to stick to.
So, yes. Hmm. Um, are there kinds of different degrees of chaos engineering, or are there best practices and levels of maturity?
I mean, I'm asking this 'cause a lot of folks are still trying to figure out, well, where do I get started with chaos engineering? What I feel when it comes to chaos engineering, the default set of experiments is where everybody starts with, okay, your default set of experiments include everything that has to do with infrastructure and that you would get out of the box. But where it becomes interesting nowadays is when you start writing, depending on how your architecture changes, okay, today, let's say if you've written like 10 experiments and you have come up with, let's say, a framework that keeps on running these 10 experiments, six months down the line, your architecture would change.
You would introduce 20 services, 30 services, and 40 services into your infrastructure. And that, that is where it becomes interesting. That is where they would start pulling in custom experiments.
That is where they would start writing something that would give them that confidence and give them that failure endpoint. So I think, yes, this is how they, uh, they try to deal with the complexity of the ecosystem, and then it becomes more like, more like a gamification for them. It's like, oh, there is new set of services that are introduced.
Let's build chaos, experiment in and around it, and let's start, uh, running some game days, running some postmortems in and around it and see on what the outages is and see what can we get as a technical depth output. So I think that, I think the teams, the infrastructure teams, the SRE teams are now taking it more as a competition, are taking it more as a challenge to see on who can get a better outage experiment and get a more resilient report out of it. Mm-hmm.
Is this something that I do before I deploy my application? Or has this evolved where maybe we need to do continuous chaos engineering? 'cause the environment is always changing.
It's, I would say it's a combination of both. Okay. Now, if you, if you start believing in the safe shift left approach, where let's say when you are integrating new services or when you're writing new services and there is a team or there's a parallel team that sits, which is basically an SRE, and you bring the SRE team into conversations, you bring your cloud engineering team into conversations, you tell them that, guys, we are coming up with new service stack.
And these service stack would consist of these services. These services would have integrations with our current API layers or current infrastructure that the team can start designing the experiments from day one during the planning stage. Okay.
Similarly, like when you have already done it, okay, there could be parallel silo teams that would be working on it. What happens when it is the moment you get the releases in, or the moment when the new infrastructure or new services connect within a stack, that is not where you would see outages that that kind of outages, that kind of disruptions you would anyways, uh, catch during the release cycle. So the latter would also work, but the shift left approach or proactive approach would yield more benefits.
Mm-hmm. Um, will AI make it easier to create chaos engineering tests? And is that gonna help people maybe find this whole discipline more accessible?
Interesting. And I've, I was reading a lot about on how AI can help come up with custom chaos experiments themselves. Okay.
Like for example, we, we've been experimenting with, let's say if I, if I just upload a architecture or application architecture or an infrastructure architecture to, uh, LLM model and, and just give a prompt stating that, can you give me single point of failures in it? Okay. Can you design some experiments that would, that would introduce custom outage kind of scenarios for it?
Yes, it would give it for you. But what generally happens with ai, AI would give you sort of experiments that are already in place that are like top 10 experiments, top 20 experiments, top 30 experiments, that pa that, that, that most of the world has seen. But when it comes to architecture, when it comes to infrastructure, when it comes to application layer, the internal team or the group of architects or the enterprise team knows on what could be the challenges.
And if it has like a hundred services involved or like 200 services involved, they are, the better they are, the better people to understand on where could be the outages and what kind of custom chaos experiment combinations would work. Yes, AI can help, but AI will right now definitely help to get you the first 20 or first 30, which are out of the box, which anyways you have to implement. But the next set of 40 or 50 would be best served by people who are in-house, who have designed the layers, who have designed the architecture, who are closely working with the SREs and the cloud ops team.
Mm-hmm. Should the people who built and deployed something be the same ones who are doing the chaos testing? Because arguably they might be too close to the environment and maybe we need a different set eyes.
Exactly. So the people who are actually maintaining the infrastructure is generally what I, what what I give an advice on are the ones who should not run chaos experiments. Okay.
Because for them it's more like a run book, because they know from a point A to point B to point C, these are the failures that have happened. They know on what the rollback plan is, they know on where and what matrix they need to collect and see on what the outages is. It should be a set of ingenious, uh, that are part of the development team, that are part of QA team that should run it on a, let's say a game day or a green zone and see on what the outages are.
The infrastructure team, the, uh, which could be a combination of SREs and CloudOps team can help these QA engineers or help these test engineers to create a postmortem report. That is where I would say that the help would come in and once the postmortem report comes in, these are the engineers that would help to again, stitch the system back to where it was, work on a rollback plan and work on a technical depth where, which was, which was part of the observation of the POSTMORTAL report. So my, my answer to this is, the ones that are maintaining the infra should be, should not be the ones that run the KIS experiments because they know, and we don't want to run it as a continuity of business drill.
We want to run it, uh, in a way that it, that it actually points to an ac actual outage and, and see on what the outcome is and see on what a normal engineer workflow would look like engineering workflow would look like and an actual update help. Mm-hmm. And is my goal to create, you know, the perfect system, or am I more likely just trying to figure out how to have a, a, a gentle set of cascading services that, uh, migraine and degrade depending on the outage issue, but at least my application is always available.
But I mean, to what degree am I trying to maintain absolute availability? Great. So when, when, when we design, okay, kiosk frameworks, when we design, uh, custom ecosystems for people to shoot these experiments to their infrastructure and mostly production, there are some, uh, bullet points that we generally tend to give them.
It's like one, you have to select a green zone. Okay? So even if there is an accidental outage, you know, on what would be the impact and what would be the, uh, what would, what would, what would be the sentiment, uh, when you run these experiments?
Okay? You have to decide on the green zone. You have to decide on a window where it would least impact the customer experience, where it would least impact on what your actual business is.
Okay? One is that the other, when you are designing it, you have to, you have to make sure that the set of services that you're impacting does not disrupt the entire suite of application, okay? Because there could be a hundred microservices in the ecosystem.
You design game days, you design, chaos, experiment, suit in such a way that you give a heads up, okay, to the monitoring team. You give a heads up to the escalation engineers, you give a heads up to the teams that are maintaining it, that this time around we are actually targeting 20% of the application suit and the outages to this 20% application, uh, suit will have this impact. Okay?
So you need to be ready with it. And it could be anything, it could be latency, uh, for the user experience. It could be delayed in response, it could be reports not going on time, but it, there should be a controlled, uh, a controlled ecosystem, and there should be a controlled environment where this should be run.
And primarily, as I pointed out, there should be a green zone that should be defined. There should be a time where you know that there should, uh, there would be at least, uh, it would least impact the customer experience. Yeah.
So when you see folks adopting chaos engineering, what's that one thing that kind of makes you shake your head a little bit and say, folks, we need to just be a little bit smarter than we are. Uh, when the entire suite of chaos experiments is targeted directly to production environments in the first go, that is where I tend to advise people. And I tend to tell people that the approach should ideally start with lower environments.
Okay? You have production grade environments that people use in demos for beta testing, for staging, which are pure replicas of production, okay? So when you come up with a new set of custom chaos experiments that you're designed, even if you're designing it in-house, or even if you're integrating third party apps that are well versed on designing, uh, kiosk experiments, the first target, uh, environment should always be lower environments.
Okay? It could be production-like environments, or it could be vita environments and environments. When you are confident enough to understand, uh, that the targeted chaos experiments would create a certain degree of disruption and you have on what the outage could look like, that is where you would start pulling in subsets of these experiments and start gradually pointing it to production, okay?
And then do it in a similar way, as I pointed in the last answer, uh, where you design on, uh, green zones, where you see on what the impact is, you, uh, give an alert or a notification or a broadcast out to the team so that the teams are ready in case just in case if there's a disruption to go to a rollback not as soon as possible. All right, folks, you heard it here. If you really want application uptime to be as robust as it can possibly be, you have to embrace the chaos.
Hey, Roan, thanks for being on the show. Yeah, Thank you, Michael. It's nice talking to you.
All right, and back to you guys in the studio. Hey guys, thanks. We're here with Jeremy Burton, who's the CEO for observe, and they're fresh off of picking up 156 million in additional funding, which is going into a platform for both IT monitoring and observability.
And well, there's a lot happening in that space. Jeremy, welcome to show. Thanks.
Good to be back, Coles. Good to chat. You know, when we first started talking, I think, yeah, every IT organization had some level of monitoring of a, some sort of predefined set of metrics, and then we all talked about observability as if it was gonna supersede monitoring.
And as we kinda look back at it now and kind of feel like it's clear we need both and there's different functions, but can we put all that together in a single platform? Yeah, I mean, I think, you know, because you do observability, the need to monitor doesn't go away, right? I mean, I, I think monitoring one of the, the primary functions of monitoring is, it, it tells you if you have a problem.
And in, in any scenario, from, from now, even into the glorious world of ai, we'll, we'll need to know if there's a problem. I, I think what observability has done is really allow people to investigate and, and ask the question, why? Why, why do I have a problem?
And more importantly, what was the cause or root cause of that problem? So I, I think, you know, every organization, I think some folks would define observability to be inclusive of monitoring. Like we would do that, uh, some folks would sit in on monitorings over there, that's gonna detect problems, and then observability is over here, and that's gonna allow us to investigate.
But I think it is certainly correct that organizations will, will lead both. So you've been at this a while now, um, but I'm not quite clear. How big is observe these days?
How many customers are we talking about? And, um, what is the scope of the ambitions from here? Yeah, so we tended to focus on the larger organizations.
Um, you know, I think there's a lot of players in the observability space, and, and so I think the low end of the mid-market is quite crowded. You know, you can take your pick between sort of open source or, or commercial vendors. Uh, we've tended to focus on organizations that are ingesting sort of tens or even hundreds of terabytes a day.
So a customer count now is, uh, over a hundred. Um, but what's interesting about observe is, um, you know, the, the size of customers we have about, uh, 11 customers now that pay us over a million dollars. And that's generally because that volume, uh, the data volumes are in the, in the, in the tens, as I said, in some case, hundreds of terabytes a day.
So what makes somebody wake up in the morning, especially an enterprise that's been at this for a while and say, we need a different approach to monitoring and observability. Yeah, it happens a lot. And I, I, I'd tell you that one of the key, uh, determinants of this is, is the growth in the data volumes.
Um, certainly when the world moved to, to distributed applications in Kubernetes, you saw like a three to four x increase in the volume of telemetry data. Um, most incumbent vendors would, would charge you by volume of data ingested. And so the bill that was, you know, once 500 grand a year is now 2 million and sort of on its way to 3, 4, 5.
And I think that gives people pause for thought, you know, is there a better way? Um, and so one of the things that, you know, we did from, from the get go is we, we bet on a, on a much more modern architecture, you know, if, if you could ingest data into sort of cheap S3 storage, um, if you didn't have to build indexes, um, if you had elastic compute, then you know, you could put a big dent in the cost of observability. So I would tell you that like 80 to 90% of the conversations, uh, uh, one of the, the primary motivations is, is, is cost.
Um, and then the second tends to be frustration with the lack of visibility, uh, frustration with how elaborate the troubleshooting process is. And by the way, some of this is, is back related to cost. It's, we wanted to keep our bill down, so we started sampling our traces, we started filtering our logs, and so now we have blind spots.
And so now we can't troubleshoot the things that we need to. So, you know, a a lot of, a lot of the, the, the sort of root of all evil, so to speak, is, is cost because of the growth in the telemetry data volumes. I also wonder though, are we hoarding too much of this telemetry data?
I talked to folks and they want to keep log data forever, and maybe we can just get smarter about identifying which of that data we actually need, and for how long? Y Yeah, I think that that's a factor. I mean, I, I think over the last, certainly the last three or four years, you, you've seen the rise rise of, uh, pipeline vendors, you know, uh, like kibble, for example, have done very, very well.
And the key value proposition of something like a kibble is to filter out logs that you know, you don't need. And so, you know, that that is certainly one way to, you know, put a dent in, in the cost, but the, the, the data volume keeps growing and it's not always obvious the logs that you need to keep and the logs that you can safely throw away. Um, reminds me, you know, years ago, uh, when I was at EMC, we had this whole strategy of, of, you know, the, the information lifecycle and, you know, you, it was created and then you'd store it, and ultimately you'd retire it.
And the challenge with retiring data is you don't know when it's gonna be needed in future. Um, and if you see a problem in your systems that you've never seen before, you went, you may well need to query telemetry data that you've never used before. And so, you know, it's not always obvious exactly what you need to throw away.
At a certain point, you need to keep it. Um, and then, you know, on something like tracing, you know, it's been quite common for years to sample traces. But again, you know, at some point you may well encounter a problem where you need a much higher fidelity of trace data than maybe you've ever needed in the past.
Um, so I think, I think pipelines and throw in data away is a thing. Um, but you know, to a point, you know, you, you, you don't want to do it, uh, to the extent whereby, you know, you've got blind spots or you're losing, um, sort of fidelity and you can't drill in to investigate the thing that you really want to. Um, and then there are organizations that, for compliance reasons, they have to keep it around for, for, for seven years or, or, or what have you.
Um, and, and I think, you know, in those scenarios where you have to keep it around, you want the cheapest way possible. And, and I think this is why sort of moving into just extremely low cost object storage and then compressing the data on top of it and, and leaving it in a place where it's not gonna cost you a lot of money to retain it for years on end, it it is, is kind of essential. Now you've been around data storage for as long as I can remember, maybe even to gone of time.
But, um, is there something that's different about telemetry data from other kinds of data that has unique attributes that we should be thinking about as we kinda collect it, store it, and analyze it? Yeah, I mean, I, I think the way the world is going, although probably not quickly enough, I mean, a log and a trace are not that different. I mean, arguably a trace is, is a structured log.
And I think what the world would be better for is if all instrumentation in all applications was essentially a structured log, uh, because anything that's structured is, is then much easier to query and to reason about. And if, if every log was structured, then we wouldn't need the trace. Or if every trace, you know, if our put another wave, all the, our instrumentation was trace, you wouldn't need logs.
And so, um, OpenTelemetry I think deserves a lot of credit for, uh, trying to standardize instrumentation in applications. Um, I, I think the, the longer we go here, the more instrumentation is going to be structured, uh, meaning that the, the less duplication will have an instrumentation, and there is a chance at least that the, the rate of growth in telemetry, uh, will slow down. And I think generally that, you know, that will be a good thing.
Um, on the other side of things, I would also say we, we have projects underway at observe to do this. Um, engineers don't like instrument in code. You know, they, they wanna work on building features, right?
No one wants to go back and add instrumentation to code. And as much as OpenTelemetry, uh, does have capabilities to auto instruments, um, it, it's, it's not sort of exhaustive. It doesn't give you all the instrumentation that you would need.
And so we've been, um, working with some of the, uh, new cogen, you know, AI cogen tools, uh, to, to figure out ways in which you can, you can prompt these tools to automatically generate the instrumentation. Um, or, and, and by the way, that, that could be if you've got a Greenfield project and you, you do it from the get go, um, or it could be if you've had a problem in a particular part of your code and you've struggled to do the debugging, um, there's no reason why you couldn't have a friendly agent, you know, lurking behind the scenes suggesting that you might need more instrumentation and go in and creating that instrumentation for you. So I think the world is gonna change, um, uh, to the, to a greater degree in the next few years because of not just auto instrumentation, but the ability to generate instrumentation from some of these new AI tooling.
Um, and I think that there is then a possibility that at some point here, that you could use these tools to rip out your legacy instrumentation and put in brand new structured OpenTelemetry instrumentation, which will make it much, much easier to debug on the other side. So lot, a lot is gonna change the next few years. Do you also think that maybe AI will force that issue because we want to use AI agents to help manage it, but the more structured the data is that they're presented with, the more likely it is they're gonna come up with the right answer for either suggesting something or automating something.
So are we on the cusp of kind of being, for lack of a better phrase, forced to instrument anything with a, with a level of discipline we have thus far? Y yeah, because I, I I, I think it is now possible to, to give the level of instrumentation that you need without putting the burden on developers. I, I think the, the, the, the critical, the critical thing is that like developers will, will, will instrument their code if they don't have to do any work.
And, and I, and I think the, the ability to generate that instrumentation or, or have an agent generate that instrumentation is, is the big unlock. Uh, the second thing I'd, I'd tell you is, um, no developer really wants to learn an observability tool, right? They, they, they want to be able to answer questions about their environment from that IDE.
So I think the other thing that AI is gonna change here is it's, it's gonna make observability data much more accessible. So I as a developer should be able to sit down, you know, in my IDE and I'm using Cursor or augment or something like that, and I should be able to have a workflow which says, uh, Hey, augment, look at this ticket, uh, go work with observe to investigate the 500 errors. Um, figure out which part of my code it's in, explain that code to me.
And if you can suggest a PR and, and that, that I think a even a year ago or even six months ago, you would've said, okay, that's rocket science. Like, no one's gonna be able to do that kind of a workflow. But I would tell you that we have customers today, early users of our MCP server that are doing exactly that, and, and it's only gonna get better, um, you know, in the, in, in coming months and years.
So I, I think AI is gonna dramatically change. And, and like the, the first generation of ai, which we've talked about in the past, AI ops, which I was not a fan of, this generation of, of AI tooling, I think is gonna be a, a, a big unlock for developers. And I think it's gonna change observability forever.
To that point, one of the issues that I think we've had is that developers didn't wanna maintain the, well, the agent either, it was basically an entire DevOps workflow just to maintain the agent. So will that become simpler as well? Yeah, I mean the, the, the agents that, uh, you use to collect the telemetry, I mean, um, we, we started off determined not to write our own agent.
We, we would use things like fluent bits and, uh, telegraph to, you know, collect metrics and, and, and logs and so on. Uh, the nice thing is, is in the last probably 18 to 24 months, I think OpenTelemetry, the OpenTelemetry agent has really solved that problem, right? And, and I feel like a, an open way of collecting telemetry is, is now available to everyone.
And there's no reason why vendors should be deploying their own proprietary agents, uh, into production. And I think from a customer perspective, you know, they're, they're sort of fed up with the proprietary agents as well because that, that is part of the lock-in. It makes it much harder for them to change vendors if you've gotta, you know, deploy a proprietary, you know, agent to, uh, to collect information.
So I think that part of observability is, is, is in a very, very good place. And then I, I'd even tell you that, um, and this is one of the things that, one of our big projects right now is the agent is gonna send telemetry, um, you know, to, to a product like OB observe. Um, we now are storing that data, um, in Apache iceberg format.
So, so even the storage format for the telemetry is now standard. And so, again, you know, we'd love it if our customers used observe forever, that will be awesome. But if at any point they choose to maybe go to a different vendor, at least they've got open collection in place, they've got an open format for their telemetry.
And so any vendor that supports iceberg and supports OpenTelemetry collection, then, you know, should be able to operate that. And so maybe for the first time error, your customers, and, you know, they now own that telemetry, not the vendor. 151 million is nothing to sneeze at, but it's not AI billion dollar money.
But what's the plan for this? I mean, what, what's left to be done? Yeah, there, there's, there's plenty left to be done.
Plenty, plenty to keep us busy. Yeah, I'd say, first of all, um, and we've talked a little bit about ai, um, there, there's a, a number of transitions there. I mean, I think number one, we would like to have a full AI native experience when using observe.
So I should be able to converse with observe using a natural language. Um, we, we've started to roll out via our MCP server, but there's a lot more work to do there. Um, secondly, um, for the last decade or so, we've had sort of distributed microservice based Kubernetes applications.
The next generation of applications are gonna be agen AI applications. So, you know, sort of search and replace microservice with agent, and you've, you've got a new app, a new kind of application. Uh, these agents are gonna interact with each other.
They're gonna interact with LLMs. Um, it's all great until something goes wrong. How do I troubleshoot that kind of environment?
So we, we recently released something called, uh, LLM Explorer. Um, that's the, the first release. But obviously, you know, there's a lot more work to do in, in that area.
We, we want to be the absolute best at troubleshoot this new breed of, of, of AI applications. Um, and then on the backend, um, I mentioned earlier we we're making a, a huge sort of architectural shift to, to support Apache iceberg. We want a completely open backend.
You know, we, we very much feel like observability ultimately is a game of analytics. And we want customers to be able to ingest data in an open format and store it in an open format and really allow them to purely focus on answering questions, whether that's through the observe UI or whether that's from their developer. You know, IDE so plenty of r and d work.
And then, you know, we, we inevitably have to hire more sales people because, um, revenue growth we almost tripled last year. Um, so that, that always feels good. Um, but, you know, the, the hill only gets steeper.
Um, and so you generally have to keep hiring in order to, to keep making more money. Alright, folks, while you're hearing in here, observability monitoring, it's, uh, instrumentation, it's all coming together. Finally, the question is, is now how quickly can we take advantage of it?
Hey Jeremy, thanks for being on the show. All right, thanks Mike. All right, and back to you guys in the studio.
Hey everyone, it's Alan Shimel. Welcome to another edition of the Platform Engineering Show. We've got a special edition of the Platform engineering show for you today.
In addition to Mike Compadre, who's in the Alps today of all places. org community. Is that fair?
Contributor, Contributor to the Community contributor. Okay. He's humble too.
So my co-host, Luca Galante is here with me and our very special guest today is my friend Keith Townsend. You may know Keith, he has a long career advising some of the biggest organizations in the world. Keith's company is the advisor bench, right?
That's TAB, the Advisor Bench. You could check that out. You could follow him on LinkedIn.
Keith, thanks for joining us on the Platform engineering show today. It's great to have you on. Matt, as Always wanted talking to you, Alan.
We always have a good time. Appreciate it. Alright, so today's show is really stems out of a LinkedIn post Keith made that kind of hit home with me.
'cause it's the kind of thing, you know, we were just a platform con, what was it, two weeks ago, Luca? And we had people there from Google and Google Cloud and AWS and the hyperscalers. And of course everyone's talking ai, AI platform engineering.
And Keith wrote a, a kind of provocative post, the missing link in enterprise ai, why platforms are failing to empower Dev teams. And you know, what hit home for me was, it's not the platform engineer's fault. I don't know if it's the AI company's fault, but the, somewhere here there's a disconnect.
Keith, you could frame the, the problem better than I, why don't, why don't you frame it and then Luca jump in. Yeah, so if we look at what the cloud providers, let's focus on the cloud providers. And Luca, I would imagine you know this extremely well.
'cause this is your area. They've done a really great job of standardizing, at least serving, not, standardizing might not be the best word, serving the platform engineering audience. You know, we, we've gotten to a point where platform engineering as a discipline has evolved from trying to make every cloud look like a single cloud to really getting developers what they need.
They need observability developers and operators. They need observability, they need, uh, standard patterns. They need these tools to develop and maintain applications.
So if we look at the AI services that most of the cloud providers and the big OEMs like Dell, HPE, and Lenovo are providing, it's still very much focused on that early stage of ai. Uh, the ability to just give me raw power, the ability to train models, the ability to consume APIs for the most part. But then it starts to fall off when we look at this kind of solved problem.
And I don't want to treat platform engineering as a completely solved problem 'cause it's always evolving. But for the most part, you know, some of these big problems like observability, et cetera, they're solved. We've, we've learned how to do that.
And ai, you know, we just saw it with, with, uh, Xi Xxi the other day, XAI the other day with, uh, when it went off the rails. I don't have tools internally to prevent something like that from a app platform engineering perspective. Every team has to recreate their guardrails.
They have to do their model observability, they have to do their pa the development pattern, uh, process over and over and over again. And that is where we're at today in the maturity level, uh, uh, for providing AI as a platform to develop on. Yeah, I I, I totally agree with you, Keith.
Um, I think, you know, what you're hinting at is, is essentially the space is just not enterprise grade, right? It's not enterprise ready. Um, they, I think like a lot of the use cases, and this is across like development, but also just like general, like enterprise users, right?
Like, you see, I think like, you know, the only applications that work in, in production, let's say, are really like, basically like basic customer success stuff right now. Um, you know, and some, some kind of like o gem stuff on the individual contributor level. The problem is to your point, is like when you're trying to like, tie those things together, like across different individual contributors, and especially across different teams or business units, different departments, then everything breaks, right?
Because there's no sort of like enterprise wide guardrails and enterprise wide system thinking even, right? Um, now I think like one thing that I would like slightly challenge is, you know, when you mention like, you know, observability and I guess like, you know, security and like all these things, right? Like, I totally agree with you that they are like, for the most part solved problems.
But I would, I would, you know, slightly reframe it in the sense that it is not really, like, that's not really what platform engineering is about for me. Like, that's kind of like the difference, sort of like infrastructural silos, right? And then platform engineering is really about like, okay, how do I tie this, this stuff together into, you know, a self serviceable layer that I, that I serve to developers as a product, right?
And I think that's exactly, and so this is why, you know, you mentioned this, right? Like, it's, it's never evolving problem, right? And this is why I actually, I'm very excited about, you know, kind of like the intersection of AI and platform engineering and like, Alan, you mentioned platform con, you know, we had it like two, three weeks ago.
It was definitely like the hottest, you know, very unsurprisingly the hottest kind of like topic that everybody was trying to tackle from different angles is like, you know, what does the Venn diagram between AI and PE looks like look like? And you know, how, you know, and, and then I think, like, we know, we talked last week or like two weeks ago in the show about like this dichotomy between sort of like AI enabled platforms and platforms for ai. And I think like really what, what you're attaching on Keith is like the latter, which I also would describe as actually where the money is and like the important thing to solve, not necessarily how an LLM makes your interaction with a platform better, but like, okay, what's the underlying platform for all this, like exploding AI workload workloads and workflows?
Um, you know, how does that help? And this is where this like product mindset, right? Um, is essential because it's like, okay, how do we take these new tools, um, you know, and these new capabilities that we wanna provide to developers and package them into something that actually works and that actually works.
And the enterprise means that it's like secure that is, you know, that has like governance built in that is, you know, um, that drives standardization to your point and automation by design. And I think like there's too much focus right now in this space on like, okay, how do you know this thing can like, automate all this side of stuff, you know? And, and this can like speed us up, you know, but the, you know, speed is, you know, there, there's, I think there's this like, um, I don't know why it just popped in my head.
There's like this commercial, I think from like Bridger Stone, you know, the, the tires, they're like, power is nothing without control. And it's like, it's the same thing, right? It's like this, you know, you need the, you need like really solid wrapper, uh, for, for this like AI thing to go fast.
Otherwise, otherwise speed kills. Yeah. Right?
Speed kills. Yeah. But guys, I'm sorry.
Go ahead, Keith. You're making a really great point. The, and I don't think, and I think I accept your pushback on the premise of what the problem is.
And if we look at some of the things that platform engineering has solved for enterprises on the traditional application side, there's very much a pattern that develops that we're, you know, that's very high risk when it comes to ai. So most, most enterprises don't have product groups. Like, and if it's, it's a failing, right?
This is why Enterprise cloud keeps failing. You need someone to actually manage it as if it's a product. And there's no product management group.
But there's just at this side effect, I don't think we expect with platform engineering that we kinda get in built in lifecycle management with platform engineering. Not exactly everything that we need, but some attributes of it. And one of those attributes is, you know, API maintenance, uh, and when I upgrade the what, what one of the things that we're going to learn with ai, even the models that we consume that we built are going to keep moving.
'cause we're going to reuse those models over and over again long past when the applications are past their prime and we're no longer developing those application, actively developing those applications. That's where we see, you know, we see it today when, you know, we change a API and an old application breaks, someone has to go and fix it. Well, what happens when the model changes in a way that we can't predict and we're no longer monitoring the application in the ways that we, you know, we're not putting a human in the loop to monitor the application.
How do we do that? That's the platform engineering problem. That's not necessarily a developer problem.
That is a platform engineering problem. Absolutely. And, and I think it's really comes down to, you know, how do you design this like pipelines, right?
And, and of course, like all of this stuff, I think is gonna be radically different in like two or three years from now in ways that we can't really predict. Um, but like if I look at the kind of the situation on the field today, um, I was like, some of the most inspiring conversations that I've had beyond platform con of course, or, um, at, um, at, at Google, uh, cloud next this year. Um, 'cause you could really feel like there were like every, you know, everything was ai, everybody was coming in with like a lot of energy and, and around this.
And there were, and, and it was clearly like the range was so broad, right? Like, it was like the vast majority of people had no idea. There were just like there to like, listen and try and figure out, there were a few people that were like experimental some stuff.
And then I was really, really impressed because like going into that conference, my, my gut feeling was just like, okay, everybody's in to do groups. But then I found, well, there's actually like a third group of people that are already pushing stuff to production. Um, now of course, like to your point, Keith, it is like they can't really like reduce the, the error rate to zero.
But it was like, you know, like a few standard deviations already, like in a way where it was actually like, you know, upper and, and, and it was, and it was basically done in a very, you know, simple way actually in a, in a sense where we're just like chaining like model after model after model, right? And like constantly like, you know, so that even if like one, like massively hallucinated or like if anything went wrong in the process, you know, there's just so many checks and balances essentially, right? That, um, that you would, you know, that you would basically end up with like an output that is actually to some extent almost production ready in a way, or, or, or another.
And this actually, and you know, this might be a segue to another interesting thing to explore, Alan, I'm not sure, but like, I was talking to somebody that was framing, that was reframing, I think how, you know, he was like, look, like in the last like 10, 15, 20 years, like the, you know, if you look at like developers, like, you know, the, the more, you know, the, the, the, you know, QA wasn't necessarily always like the most kind of like, Hey, that's where you start, right? Like, it was all more like, uh, like, okay, what's the necessary thing that we need to have is a, is a check, you know, that we need to have and so on in place. But actually the people like really innovating, creating new code, creating new features are somewhere, are another team.
And, and I think what's interesting is actually when you think about where we're going in the setup, like QA or whatever it's gonna be called, right? 'cause it's gonna be, you know, like AI engineering or whatever, it's actually like in the enter, you know, on the individual level is prompt engineering on the enterprise level, it's really like, you know, like, how do I make sure that like all these things like don't hallucinate, you know, and, and they're actually usable in production, right? And so it's very interesting because all of a sudden this like QA that was, you know, I'm not saying like a secondary figure, but not the primary figure, I think becomes in a, you know, non-deterministic, more probabilistic world actually, the figure of reference, right?
For how you make the stuff enterprise rate The big duck. So I, I gotta jump in guys 'cause I haven't gotten a worded. So I, I think to a certain extent we're ignoring the elephant in the room here.
And that elephant is, is that a lot of these AI platforms, if we can use that word by calling you, you know me a gentleman, but you know, a lot of these AI platforms, they weren't really designed for the developer, for the platform engineer to use. They were designed for the data scientists, for the model trainers, for the, for the people who were, you know, the initial workers or the initial audience for these ai uh, applications. org community.
Yeah, there's a lot of people who have platform engineer is their title, but there's a lot of people who have data scientists in their title. org community. Why?
Well, it, it's obvious why, right? They, they understand. And so, you know, the a lesson I learned in a lot of the startups i, I helped start was un you know, understand who your customer is, understand who your personas are, understand what you're building for who.
And so you can't say, I built something for these people and now I'm going to co-opt it for these people. Sometimes you can, but it usually takes a lot of re-engineering, a lot of rejigging, sometimes just redesigning. And, and I think that's the cycle we're in right now, maybe is trying to take something that was built for these people and make it work for this crowd.
Keith, what do you think? Yeah, so you, Alan, you're, you, uh, you're hearing on one of the first questions I ask anytime I create content is who is this for the, at the end of the day, who is this for? So as we're, you know, as we, as I put on my CTO advisor hat and Luca hit a super key point that I, I want to go down this rabbit hole a little bit.
That AI is an enterprise ready. And he used, uh, uh, AI assisted cold as an, uh, as an example. com com on this topic, which is, uh, where, how do you scale this?
Like the, I've talked to individual contributors at AWS, they had a really great conversation with, for principal engineer at AWS that's a big time title. And this is, you know, when you're talking about the most senior of engineers, this is, this is one of the big boys. This is a fame, uh, developer who's getting paid, you know, probably a million and a half dollars a year to be productive.
And they were exceptionally capable with, uh, uh, uh, uh, AI assistant to 10 x their productivity. And the question I asked them was, how do I spread that around? How do I expand that into the enterprise?
How do I scale that? And that is the, uh, essential problem that we're seeing, and this is why these personas are joining organizations like this, because they're naturally coming to, is similar to when, uh, uh, cloud native first came around and they said, oh, we're gonna show the enterprise how to scale applications. Oh, okay, thank you very much.
We've never, we've never scaled applications before. We don't know what we're doing. But they soon discovered that they were solving the same problems that we had already solved, uh, time in and time in again.
So, uh, Luca, I think you really hit on a keynote, uh, here that scale breaks everything. It especially breaks, uh, platform things that should go to platform engineering. Yeah, yeah, absolutely.
And, and, and, um, and I think like where we, I, I don't think it's the answer, but I think like where we need to start here is to your point, Alan, is like, how do we bridge this gap? Because yes, like the fastest growing segment in the community is data engineers and then, you know, security people. And now of course there's gonna be all sorts of like AI titles coming in.
Um, but the, you know, people are trying to figure out, okay, how do I, you know, I need to interface myself increasingly. So with the, with the platform engineering or with the platform team, you know, there is this like platform, so how do I leverage it for data? And to your point, Alan, right?
Like the, the, the, the, the issue thing is, you know, right now there's two, uh, you know, these are two completely separate siloed worlds, right? There is this kinda like SDLC platform engineers, how do I deploy workloads with their dependencies and so on. And then on the other side, there is, you know, like datas and like data, data, data like data lakes and models and like, you know, yeah.
Like the, and, and, and you know, the user over here is application developers. The user over there is like, you know, ops, uh, MLOps engineers and like, uh, data scientists and, and whatever, right? Um, and so like one of the, I think like interesting exercises that we've started doing in the, in the community is actually, uh, trying to map out what does a joint reference architecture for a data platform, um, kind of look like, right?
So like a platform that servee both these users. And, you know, to be honest with you there, I don't think there is an answer there yet. There are a lot of questions, but I think we're starting to at least pin down, okay, what are the key things that we need to answer to figure this out?
Um, and, and, and kind of put in the different, you know, uh, puzzle pieces together. Um, because, uh, otherwise, um, you know, we're gonna, and, and, and I think like, you know, I've, I've always, um, used as a guiding principle, you know, you mentioned Keith, like, you know, where do you start when you create content? Like, the way I think about one of the, one of the, uh, key things that I think about when creating content is, is is this sort of like, okay, what can I learn, um, from sort of like top performing organizations that I see is, is gonna trickle down to the rest over time, right?
Um, because it's, you know, it's, it's, it's that quote of like, the, you know, the future is already here. It's just unable and distributed. It's like, it's, that's always true across, you know, any sector, any like, new technology.
Like it just gets earlier somewhere, um, and you just need to like go and listen there, right? And so, and so I think like if you look at top performing organizations, they're already thinking of this as just one unified layer because of course, why wouldn't you, right? Like, I mean, platform engineering I think is just like, yeah, another permutation of what we've been doing in software engineering for all the last decades, which is just like progressively abstract, like one level higher, right?
And the thing is right now, you know, you have this like two levels, they're kind of like next to each other, but, and, and so the next level is just like one thing that sort of like pulls them both into, into, into one platform layer, which again, is, is I what I wanted to say earlier. And I, I, I, you know, I, I always end up in tangents, but what I wanted to say earlier is, um, you know, I'm really excited about this whole AI thing because I think like, while as a trend, it is overshadowing and overpowering a lot of outer stuff in the industry, you know, industry meaning like cloud native, whatever, right? Like enterprise, like, I actually think it's, it's really powering platform engineering because you need this, you need to figure out this platform, um, thing, uh, to, to, to make everything else possible.
Fair, fair guys, we got maybe time for one more round of comments and we gotta close it out. Keith, what, what's your, what's your summation here? Yeah, so we need to give practical advice, right?
The, at the end of the day, the people who listen to this need to understand, well, okay, I hear that the big boys aren't taking care of my knees. What should I be doing? And I think that's where the last piece of the stuff at is one, you know, I will approach this like any other engineering solution, measure what I can measure, understand where the gaps exist, and this is going to be unique for every, or organization.
What do you need as you're building AI ops? So you need to understand the problem and the gap in which you have. Then you start going down the, uh, solutioning of talking to your vendors and, and making sure, validating what we are saying.
You know, from a high level, we talk to the vendors, but, uh, I'm not a practitioner anymore, so I, you, you really do need to talk to the vendors and understand where they're offering potential solutions or understanding what their roadmaps are. 'cause we haven't talked about the vendor's roadmap when it comes to serving the platform Engineering audits, there's going to be gaps because this is not where they're focused on. They're focused right now on this building, the biggest, uh, clusters, the most through throughput.
They can, the best models that they can build, and that they're cap, they're focused on building the capability around the infrastructure and the compute, and not necessarily operations and deployment and management, et cetera. So there's going to be gaps. Understand those gaps and then reuse some of the patterns that you've already have.
You might already have solutions for the most basic of things. Why predict that? You're going to find the most problem is around this whole lifecycle management piece.
Because we haven't gotten to the right, we, we haven't gotten to what happens when an AI app has passed this youthful development lifecycle. Eh, we're pretty, we're very much too early. I can't predict that.
I don't think any of us can predict that, but we need to be thinking about the problem. Fair enough. Yeah.
Luke, I'm gonna give You the last word, and I, I, yeah, I would just gobble down on what Keith said. I think like the, the TLDR R is like, nobody's coming to save you. Like, you know, you, you need to, and which I think goes nicely, like full circle with where we started.
Like, you know, this big, uh, cloud providers, the OEMs, like nobody's is building a solution for you. Nobody ever had. Um, it's like platform engineering is about like taking whatever it's out there.
So don't go and reinvent the wheel from scratch, so you don't have to build entire stack leverage, whatever this providers give you. But then you need to put in the work to like really make it sensible for what your use cases are. Um, nobody's gonna do that for you.
And if you don't do it, you know, to Keith, to Keith's point like this, this stuff is not gonna be usable. It's not gonna be enterprise ready. Um, and you're gonna fall behind.
Excellent. Gentlemen, thank you both for coming on. This was a great platform engineering show podcast, Luca, I have, I'll see you in two weeks.
Keith, for people who wanna follow you and, and grab more, what's their, what, what, where, where do we point them? com is the content machine. That's where, that's where I'm creating content.
Go back to the blog. It is where I always create content. The advisor bench.
If you want the that next level help, that's where the hit the contact us on the ct Advisor, uh, dot com. I love it. All right, Luca, Keith, thank you.
Thank you. By the way, we didn't mention thank you very much for Check Marks sponsoring our podcast engineering show. So kudos to them and thank them.
Uh, we'll be back in two weeks with another show. I think we probably have a live round table coming up soon too, on this. But until then, this is Alan Shimel for the Podcast Engineering show.
Thanks everyone. Have a great day. Hey everyone, welcome to Control Alt Deploy.
This is episode two, and we're glad you've joined us. I'm Alan Shimel of Techstrong Control. Alt Deploy is a video show we do with our good friends at OpenText, where we talk about cutting edge, leading edge stuff, topics around DevOps of all things.
Um, we're really glad you're joining us. We have a great panel. How often does this happen?
I'm the only guy on the panel. I have three amazing women to introduce you to who are on our panel today. Let me introduce you to them right off the bat.
First of all, joining us, uh, from New Mexico. She's the CEO of Deploy hub, open source CBF board members, uh, on several boards, our friend Tracy Reagan. Hey, Tracy.
How are you? I'm doing great. I was gonna mention this.
I think that this is the first time I've been on an all female panel. It's very cool. I love it.
Did not that I don't like the, the dudes on the panel as I'm not saying that. It just is extraordinary. It's all women.
Yeah. Now, you know, we didn't plan it this way, to tell you the truth, but tell the truth. Hey, more power to you.
Good for you guys. And it's, it's, I, I feel flattered to be here joining us from Canada. She runs the, uh, one of the leaders of the Canadian DevOps community, but really a worldwide, uh, person in the DevOps world, as well as top contributor at the CDF.
We've just been informed my good. Fred Garima Boal. Hi, Garima, how are you?
I'm good. How well you, Excellent. I'm glad to have you here.
And then last but not least, but from Open text, Hillary Johnson. Hillary, welcome to Control Alt Deploy. It's great to have you on.
Um, I give a little bit of background. Um, I'm sure I was Gonna say I'm the new person. Tell us.
Yeah, I'm The new person. I'm the senior industry strategist here at OpenText for manufacturing. I've been in manufacturing for over 14 years now.
Um, and so I've got a vast background from really small job shops to really large enterprise like me, medical devices. So been in this for a hot minute. Got it.
I appreciate you being on. So, so panel, today's, uh, title is, uh, compliance and code security and DevOps navigate regulations and supply chain risk with ai. Well, everything's with AI today, but really as we get into, it's a how can, how can our DevOps teams and, and let's not just confine IT to DevOps team could be platform engineering teams, developer teams.
How can we stay audit ready and secure the software supply chain, you know, leveraging things like AIS and SBOs and of course automation. And, you know, this was a hot topic before AI was hot. Of course, we weren't talking about using ai, but securing supply chain has been a problem.
Certainly, you know, it first burst on the scene, I guess, with the SolarWinds breach back during COVID, right? Where there was a, the malicious code inserted into shipping product. Um, Tracy, I know you spend a lot of your time focused on this, where, you know, ha has AI changed the game here for us?
Where, where do you see, pretend, where do you see progress? Where do you see we still need to make a lot more progress? Um, well, um, before last week, I would be far more optimistic.
Um, uh, I was at CD Con and we did a, a, a focus group around CI/CD cybersecurity. And I discovered that many of the DevOps engineers are not interested in adding security to their pipelines. In fact, they're flat against it.
They don't want to do it. Um, and that's because I, I don't think that there's, maybe, I don't know what the reason is. I don't think they wanna be disrupted.
Again, I don't think they wanna touch their workflows. Uh, so we have some work to do in DevOps around the understanding of why security is important. You know, I, I keep my foot in two different worlds.
I'm on the board of the open source security foundation, so I understand and hear what they're working on. I know about their new tooling, like proto bomb, and then I have the other foot in the, in the C station, and I'm on their technology oversight committee. And I see that there is a very, very large gap.
I'm practically doing the split sphere folks between the two worlds, because there is such a wide gap. Um, at our focus group, one of the most concerning things that I heard, but I heard many of them that the first one was, they don't believe that SBOs are important to incorporate into DevOps pipelines, because they're not always accurate. They're just a checkbox.
And without consuming the data, it's useless. Which I agree, that's why Atill is around. We're consuming that data and making it as actionable.
But the point is that they don't see a strong need for securing the code base through the CI/CD pipeline that somehow is an engineer's job, a software engineer's job, and not something to be automated. I, I, you know, this, this concerns me because if we're not looking at disrupting ourselves, we will be disrupted. There will be younger people come along and do things differently, and AI will be part of that solution.
There's just no way to stop it. It's a freight train. Get off the tracks.
Yeah. Karima, I'm, I got tell you the truth, I'm, I'm shocked. How about you?
I'm not that shocked. I think that, you know, I understand where Tracy is coming from. I am also associated with the Cortes Delivery Foundation.
We have a lot of ambassadors who are trying to steer the needle in the right direction. And I also see that Tracy is heavily invested in, uh, open source security. But I understand, uh, the community kind of sentiment and, you know, not overlooking the recent past.
Right? You mentioned about SolarWind. We have seen log four js and we have seen x uh, Z back doors, you know, so the regulatory pressure is intensifying on us, whether we see it or not, right?
Regulations like EU Cyber Resiliency Act, or even the N two and Europe or executive order in, you know, us. I think they are all reflective of the fact that we have to take security seriously. And SBO m is comprising of one of the biggest pieces of the puzzle when it comes to contest monitoring, the vulnerability scanning, and maintaining that transparency in the system.
So, I would like to have more discussion on this topic and raise awareness and see what we can do from a practitioner's point of view or community point of view to ensure that we, uh, move the needle in the right direction. Hillary, help us Labor shift going on right now, right? You've got old labor kind of coming towards the end of their career, younger labor, who doesn't quite understand some of the, the trades or some of the manufacturing world.
Um, and they're looking for new tools. So I think it's gonna be, at least from what I can tell, is there needs to be a shift in thinking from upper management and from owners, and even SMBs. You know, nobody likes change, but it's inevitable.
Kind of like what cybersecurity was when you were breached and, and manufacture, I know from manufacturing point of view, they didn't think it was gonna happen to them. Um, and so they, their, their guard was down. So eventually, maybe it's, you know, um, where they need to see it, that it's happening to somebody else, or, you know, okay, I, it hasn't happened to me yet, so maybe it won't happen to me and I can focus on getting some other things done with my business.
And so there's, there's gonna need to be a shift with the different kinds of people who are coming into the business full stop. Um, and whether or not you like it is one thing. Um, that's, I mean, my 2 cents, but it kind of, it needs to be a shift in mental, Well, we that, and that's part of the problem.
We've been shifting. We've been shifting left, shifting left, shifting left, shifting left to the point that DevOps engineers are not shift, they're not left, they're not software developers. So we've been pushing it all to the software developers and the DevOps engineers are like, that's not our job.
We shifted all that to the, the, the developers. They're the ones that should be protecting their software supply chain. But that's exactly the point.
It's not the software dev software developers want to develop quality code, but they're not security experts either. It's the security people or the security experts. But that's one of the, you know, I was at while you were at the Open Source summit last week, I was in New York at the platform Engineering Con.
And, and that's, you know, what a, what a dynamic community with lots of buzz and lots of, a lot of young people, to your point, Hillary, right? A lot of young people coming in here. Even though, you know what was funny?
I interviewed a lot of folks that were closer to my age and they said, I've been managing platforms for two, three decades. Managing platforms is not a new discipline. Calling a platform engineering maybe is newer, but managing platforms is what we've been doing.
And I think one of the reasons that platform engineering has struck an chord and, and gotten as popular as it has, is that part of that, not manifesto, but part of their reason for doing it is you can't just keep shifting left and saying, it's the developer's job to do. Developers wanna develop, right? Developers wanna develop code.
They're not security people. They're not DevOps engineers, nor are they platform engineers telling developers that you're responsible for security. Oh, and by the way, you're also responsible for building the platform that you develop on because we're shifting everything left.
Well, that's not, that doesn't scale and doesn't, when you get to enterprise levels, that doesn't scale. However, I am surprised to hear that DevOps engineers would wanna sort of abdicate their responsibility in terms of, because it, in terms of secure code. 'cause it's not just the software engineer who makes sure it's secure code.
What about testing, right? That to code, code needs to be tested. Whether it's, it's whether the code's written by AI or people or both, it needs to be tested, right?
We, there should be a pride in what we are in what we are doing at our jobs where, no, I'm not gonna release shoddy code, I'm not gonna release insecure code, I'm not gonna release code that doesn't comply with regulations and compliance. Right? I think what we're hearing is more what Hillary said is it there is sort of an old guard that wants to stick their head out the window and say, I'm fed up and I'm not gonna take it anymore, right out of a movie.
And there's also a lot of people in, in the workplace who, you know, this is their fifth disruption in the last three years. And, and they're shell shocked, right? They just want to dig their heels and, and honestly, I'm fed up, I'm not gonna take it anymore.
But progress waits for no person, man or woman or what have you, right? No person. And so they could, they can protest all they want.
That doesn't mean that SBOs aren't gonna be required. That doesn't mean that AI is going to stop writing more code and having as big a bigger impact. Wait, wait till the agents come in.
Yeah. Right. We, we spoke about that earlier in our episode, one of control alt Deploy.
And I apologize, Tracy, Hillary, you weren't on that episode, but Reemer was on with me. And, and, um, you know, we spoke about what agent AI is going to mean for DevOps engineers, right? So thinking your head in the sand and your head and your, and your heels in the sand, I don't think that's a, I don't think that's gonna work here.
Yeah. So I think what I, what I, what I saw what in that meeting was a lack of curiosity. Um, because I am one of the most curious people.
I know, me and Brian Dawson were kind of OCD about things, and we'll get on something and we really will research it and have fun playing with it and trying to understand it. And I, I saw a lack of that curiosity in that group. Um, and I understand that they probably have a lot of work on their plate to keep those brittle workflows up and running.
And the thought of trying to create something new, maybe an overwhelming task. But what one person said, struck with me, stuck with me, is he said, PE people will start generating SBOs when their bottom line depends on it. And he was a company servicing the, the, the public sector.
Uh, he said, we don't have a choice. We have to, but we still feel it's like a checkbox. And I could submit the same SBO m over and over and over and nobody would know the difference, which is a true fact.
Totally true. So that, that is true, right? Yeah.
To me, the SBOs always seemed like the tag on my pillow, that if I tear it off, it's a federal offense. But whoever reads what's on that tag, right? And I'm always eager to tear it off just so I can break the Law.
So that's, that's the kind of person you are. Exactly. Who else here, Hillary?
Do you pull the tag off? What do, do you read the tag? No, I don't want the tag in my ear if it pops out of my pillowcase.
Um, I think, I think the thing is that is so true. People are learning AI out of necessity. I learned AI out of necessity.
'cause I was doing the job of four people. So as we're, as all of these companies, companies are still running lean. They're gonna have to figure out that, that to dig their, their heels in and start testing it.
I think the other thing about AI is it's not a hundred percent accurate. Um, right. You know, so you've got that, that cautious behavior behind it.
Like, well, what if it isn't? I can't trust it fully. Yeah.
You still need a person to verify some of this stuff. And so how do you, how do you start progressing, um, still knowing that there's, you gotta have somebody who, who's checking all of this. So, um, just 2 cents.
I, I agree. See, so Tracy, I'm more like you. I started using AI purely outta curiosity, and now I find it an indispensable tool.
You have a point. Yeah. To your point though, you were doing the job, you had to do the job of before people, so you had to use AI as a force multiplier.
So I was reading an article, I think I mentioned in the earlier episode, uh, mark Benioff from Salesforce claims that maybe up to 50% of the work being done at Salesforce that was being done by AI and agents and stuff. I don't know if I believe that to tell you the truth, but that seems, you know, is, is this where we're heading? Are we, let's say it's not 50%, is it 25% Garima?
You talk to people in DevOps all over the world, there's more than anyone. What do, are we, are we already using AI that much? As I said, uh, in the first episode?
I will stick to that. I think we are in the experimental phase for ai, right? I mean, we are using AI for experimenting around a lot of productivity and efficiency gaps, which we have, right?
And then we are also thinking about using it in different dimensions when it comes to like, um, exponential scaling. But we are not yet there. And I, as I pointed out earlier in the episode as well, that, you know, when we look at things around, you know, we are building things with ai, like what type of code are we referring to?
What kind of enterprise we are, like comparing it to? Because if it's a large enterprise, we have a lot of legacy systems, right? So it's not easy to refactor, rebuild, you know, repurpose code, um, even for humans.
So, I mean, AI is, uh, something which we should have a secondary thought on. If you are an AI native company, you are building an AI native platform, I would believe that there is a substantial amount of, you know, excitement, enthusiasm, as well as potential what we can do with ai. But again, you know, uh, we haven't substantiated this.
Nobody has producted it in a larger scale. So we don't know how much technical depth we have built around this, right? So there's a lot of questions around, you know, how AI is enhancing the productivity for DevOps pro professionals.
This is yet to be seen. Hillary, what about your experience at OpenText? And don't say anything that's going to get us all in trouble, but, you know, is, is AI doing that much of the work around there?
That's what part of the company you're in. Um, you know, from, from a marketing standpoint, probably more so. Really?
Um, yeah, very much so. I mean, it does all the research for me. It, it, it writes a lot of stuff.
It gets me started. I'm not a writer. So, you know, there's plenty of times where I need someone to get, um, my thought process going.
Um, you know, in a manufacturing, uh, in a manufacturing perspective. I know of friends who have smaller manufacturing business. Let's take this from the size of the business.
You were saying. Enterprise has a harder time. 'cause they have legacy systems, they've got disjointed, you know, Salesforce, half the time, one's in Europe, one's in the us and one, you know, they're all over the place.
Um, smaller companies are really starting to explore this more. 'cause they have the bandwidth to do it. They don't have as many legacy systems.
So I would say almost reach out to those smaller innovation businesses and see how they're handling it. Maybe let them be the Guinea pigs, create some friends, create some networks, right? And figure out how they're using it, because it's gonna need to scale.
Enterprises is incredibly disjointed and it, there's so many processes. I think small, I think the smaller to medium sized companies are actually gonna kind of pave the way on this. And this is just my prediction if I get my crystal ball out that, you know, they're gonna be the ones helping this.
Yeah. You know, we saw this in DevOps, right? When DevOps first burst on the scene, there was this whole argument, is DevOps better for small medium companies where they have to do it by necessity?
Or is it better in enterprises where you can do it at kind of great scale? And, you know, counterintuitively, I I think it was both, right? It worked, it worked at both.
Now, if you talk to the platform engineering people, they'll tell you, it's when you really start scaling up that DevOps runs into scale issues. And that's why you, you can help with platform. But let me, let me put something else in front of you, the three of you, and see what you think about this.
If you are gonna believe that SBOs and, and like a lot of security, it's what we call checkbox security, right? Compliance is the least common denominator type of security. It's doing the minimum you gotta do to comply with whatever your regulations are.
But if, if SBOs are part of that least common denominator security that we need, isn't automating that with ai, the easiest thing to do then, because if, if it really is not that important, but we still gotta comply. Wouldn't I wanna just automate it and get it out of the way? Tracy, I'll go it to you first.
Yeah. Generat, generating an SBO is easy. We don't, there's many tools out there that will generate an sbo.
It's a very simple, uh, command line to add to your workflow, by the way, folks, very simple as about as simple as they get, it's probably four words. So generating SBO m is not necessarily the issue. I think what the issue is, is touching the scripts and dealing with, um, any modifications to the workflows themselves.
That's the, that's the real issue. Unless it has real benefit. And that is the problem with SBOs.
Yes, everybody should be doing 'em because it's the first step down the road, right? But then there should be a second step. Evidence stores are important.
Let's start gathering that information. Let's start watching for changes in the sbo. M What is different between this, this build and the last build?
Are we bringing in new package versions that we were, um, that the, the developers have have updated now we need to make sure that the testers go through that. Make sure that it's properly tested. How can we make the data actionable?
If we do that, then DevOps engineers will be more motivated to use an SBO m because it has a purpose. Right now it's just a government regulation that says you have to have one. So why, if I'm a, not, if I'm not delivering code to the US government, and I don't have customers who are demanding an sbo m why would I bother?
I, I totally understand the sentiment. I understand why I would bother, because I, I wanna know what, uh, I, I really do wanna know how compliant those packages are that I'm consuming because I'm delivering code to customers. So I need to protect myself.
And the way to do that is to know, again, I'm curious. I'm a curious person, so I wanna know what's happening. I wanna know what's coming through the pipeline, but not everybody is.
And you know what's really gonna change DevOps? It's when DevOps engineers are gonna start having to manage AI agents and LLMs, that means that they're going to have to change the way they, you know, our, our DevOps pipelines are pretty traditional still. The two, the two pieces that we do is we run a build, right?
We take code and we turn it into binaries, create a container, and then we call a deployment tool. We, you know, DevOps pipelines themselves don't do deployments, and they don't do builds. They call scripts that do that work, or they call external tools.
So we're doing build and we're doing deploys, and we're happy. And that deployment go out and may go out to testing, or it may go out to production. We don't even have to worry about that because the deployment tool deals with that.
And most of the time we're consuming something that's a helm chart for that. Or where we have GI ops, that's, that's supporting the de the, the deployment. So we really don't have a lot in the pipeline anymore.
We just have a ton of pipelines. Thousands of them. Thousands and thousands of pipelines.
So when we start asking for things like what version of the LLM was used in this build, that's when they're gonna say, well, I don't have an AI bomb to tell you that. And that's when we're gonna start seeing changes in the pipeline. In the pipeline itself.
It has to be driven by a serious need that's going to motivate a DevOps engineer to dig into thousands of workflow files and start updating them. Or guess what they might do. They might use AI to do that.
So they'll, And and if it, if it checks the box, they will, right? If then it's Yeah. If it's just a check box.
Yeah. And so, you know, maybe compliance isn't the right driver, is what I'm hearing you say. I don't think compliance is, is something that they really are focused on.
The compliance is being forced at the dev, uh, at the shift left side, there's quite a bit of work that developers are doing. They're taking classes. They're trying to learn to write better code, make sure that they don't have stack overflow issues, for example.
They're working at that. But the DevOps pipeline, there is tooling that can be added to it that's not necessarily being added at the CD foundations at our focus group, I asked if anybody knew what proto bomb was, which is a big tool that the CI that open SSF has been working on. Nobody understood what it was.
They had no idea. That's a big, there's a big disconnect between the two. And I wanna p point out that these tools are coming out on a very fierce, there, there, there's new ones all the time for security that can be added to the DevOps pipeline.
At the CD foundation, we're working on something called the ci cd cybersecurity sig. We're putting up a website that will have defined for achieving, um, the software, the secure software development framework, for example, NIST 800, whatever it is. Uh, we gonna, we ha we are working on every single task and we're finding what open source tool could be added to the pipeline in order to achieve that NIST task.
Because develop DevOps engineers don't have time to go hunt down tools and understand exactly every single task that you have to comply with, which is numerous, and what tools you have to add for that. So we're trying very hard to understand what the DevOps teams are looking for. And what they're looking for is just gimme the information.
What do you want me to add to the pipeline? I don't wanna go sort out security. I manage the pipeline.
What do you want me to add to it? And how will it benefit you? So that's where we need to get to.
Fair. You know, I remember being a little boy in school in some sixth grade philosopher told me, all spaghetti is macaroni, but not all macaroni is spaghetti. Okay?
Bear with me. AI helps us with automation, but not all automation is ai, right? And automation is something we've been trying to do in DevOps from day one.
'cause the very idea of automation seems to at least, you know, the idea behind it is, oh, we could go faster because it's automated. We get humans out of the way. We, we could go fast.
It just runs as fast as it can. It's automated. And that's very much like AI is part, is a, you know, automation is a big part of one of the, the, uh, you know, the things that attract us to AI is it can automate stuff.
Take humans outta the equation and just do it. And we spoke in episode one that automat and autonomous, right? Is autonomous ai.
AI does more than automation, right? AI could bring autonomy, AI could do. It replaces humans in, in so many in some ways.
Um, what about non-AI automation and DevOps helping to navigate compliance and regulation and, and supply chain risk? Is it all AI is, is that, has all all automation now become ai? Hmm.
No. Kareem, or I see you wanna talk or thinking? Yeah, I, I think, um, and, uh, you are right that automation is different from what we are seeing now.
Because if you think about sbo OM management, for example, we can automate a lot of sbo om management stuff, uh, in the CI/CD pipeline itself, right? Versioning of SBOs, for example, vulnerability management scanning tools. There is also BU platform management.
If you're a fan of Plat platform engineering, you could appreciate that. But when we talk about ai, it is, uh, I would say there are four aspects which we have to consider, which is different. First of all, timing of when and how we are putting automation into the stream, right?
So that is very important because when we consider secure by design with respect to ai, it makes a lot of difference. You know, throughout the lifecycle, we are considering ai. And that, uh, also kind of helps us understand that why timing of security is important.
Our approach is also another factor because, you know, automation is often reactive. Um, uh, from AI perspective, we are more proactive, right? They anticipate and mitigate threats before they occur, right?
Integration, for example, is another, uh, aspect, which is also different because you're not only considering code, we are also considering data processes and all other aspects of like, modern model training, deployment, as Tracy mentioned, you know, what version of LLM you have used in the pipeline. So all those kind of things also become important. And lastly, I would say adaptability.
Adaptability becomes, uh, more critical. Because, you know, when you're talking about AI in the mix, it's more real time, you know, self-learning loops, you know, they, they can kind of enhance itself. So it's a lot of other factors which you have to think about.
And again, that's the reason why I was thinking that, uh, you know, the AI integration and the, the, the journey of AI integration and SOM in security management is still at an experimental stage. So I think RIMA used a very important word in that. And that's adaptability.
So right now, we have, we have job schedulers. Let's just, CI CD is all driven by job schedulers. Jens Jenkins, a job scheduler, harnesses job scheduler, they're job schedulers, and you pass things to them for them to execute and order.
That is what we call workflow automation, right? That is what we do. The problem is adaptability.
Because of the fact that we use scripts to build that automation, it makes us less agile. Even though we preach agility all the time, we ourselves are not very agile because we can't adapt easily, which is why we can't add a lot of security steps to the pipeline. So that takes me to why l uh, the potential for AI to manage our workflow instead of having a job scheduler.
When we start moving into AI and having an LLM actually manage the workflow like a, like a cloud Opus four, then we can be more agile, we can be more adaptable. We can ask it to change faster. So right now, humans are struggling with the, with being adaptable and changing what AI has and could offer to DevOps in the future, or platform engineering, whoever takes it on first is a more adaptable way of managing the automation.
That's where we're stuck. Fair, Fair. Sorry, as I'm listening, um, I'm thinking about machine, uh, monitoring and lin learning, and then what is, what can come from that?
So, you know, when you have a lot of information coming in machine monitoring, it's just putting the data out, and then you have a human who's, who's reading that information, the next step then is to take that information and have, um, your AI then analyze that information and say, oh, I'm seeing a forecast here, or I'm noticing a, a trend here. And then you can align it with things that are going on in, in the natural world. Uh, I'm wondering if it's just a lack of like, curiosity, like we're saying, and they don't even know that there's this capability out there.
As I've talked to people about ai, one of the biggest things, I, I talked, I talked to the president of an old company I worked for, I was 3D metal printing. He's fantastic. But I, he asked me, he said, Hey, how can I use ai?
And I was like, you are one of the smartest, you're, I mean, really, really smart gentlemen. But we had a lunch meeting and I said, this is how you can use it, personal and professional. It goes a whole, I didn't even know.
And the amount of platforms out there. So I wonder if it's more or less like opening it up and saying, here's what the actual capabilities are, versus just saying who's gonna take it first? Maybe you point out both you, you, your POS particular position can do it this way.
And here's an example. I just think it's lack of understanding a lot of it, um, and not actually knowing what the different capabilities are because they haven't had the time to jump in. Everybody's working lean.
Um, so sorry, 2 cents there. It's almost, it's a progression one, right? You get, you get in all this data, but what are you gonna do with all that data?
Right? We got data everywhere. Everywhere, right?
But I think a lot of it is maybe they just don't know what the capabilities are and they need someone to show them Well, but also their attitude. You gotta be open to learning about the capabilities. I'm sorry, go ahead, Tracy.
We, we don't keep data in DevOps. That is a big problem. We, uh, so the data that we keep in DevOps is stored in log files.
Okay? Um, sometime they're checked in, but generally they're probably left on the, in the directory where the, the deployment was, uh, executed or the build was executed. Uh, we don't even create, uh, historical records of how, what a, a workflow look like when it executed.
That's not stuff that's a DevOps pipeline, uh, gathers. So we have a problem with actually implementing AI around DevOps with a lack of, of data. So we can't, so let's say we, we take a large company, I don't know, standard oil, whoever we wanna think about and watch their DevOps pipelines over the course of time and store that information in an evidence store, we could absolutely start watching a model and, and having that model make predictions, but without the data, we struggle.
Um, so these pipelines don't have that kind of information. Now, what we do have is we have workflow files that are checked into gi. We have, um, build files that are checked into gi, we have POM files that are checked into gi and we have, uh, helm charts that are checked into GI and they, existing models can go look at those to regenerate things for us, right?
But we don't have historical data to do predictive work because we are, the data is fragmented in log files everywhere. Every tool has a different log file. They just get stuck in the director that they executed.
And we're not doing anything with them. Kind of like an sbu, exactly, like an sbu. So without that, we as DevOps engineers are going to struggle with having the ability to do anything more than generates a, a new helm chart or a new, uh, workflow file from ai, which you can already do today.
You know, God helps those who help themselves. And I think people, I think there's so many things that AI can do for us, not take our jobs or replace us, but augment us and extend us and make our lives easier, better that, you know, there's gonna be, there's going to be people who work because of ai, and then there's gonna be people who don't work because they just don't want to recognize ai, if you will. So I would, uh, also add something here, because we have been talking about this for a long time, that, you know, there's a la lack of awareness at every level that, you know, how AI is adding value to our ecosystem as a software developer, I did a talk, uh, at, uh, DevOps con, uh, in Berlin, and I started with this, that in 20, 35 years down the line, do you think that your software development, uh, would look the same?
Is the job the same, you know, five years down the line, what could change and what will be the challenges and risks? And when you start thinking about it, there is like a change in how practitioners would see, you know, software development and what skills are needed, how teams will be structured. Because there will be, if you like it or not, there will be a lot of AI assisted software development in the ecosystem.
There will be teams where you'll have like five code assistants as well as, you know, four senior devs in the same team. So how do you cope up with that? And then from an enterprise perspective, do you think that all the big bank changes which are happening, they're not human led anymore.
They are AI led micro changes which are happening in the ecosystem. You know, if you open your eyes, you see you, you're using copilots, you are using, you know, all these tools and time has come, you know, people have to realize that their job is changing. So now you have to think about your left hand side and right hand side of the brain, like what needs to be getting added to your left hand side of the brain, which is like creativity, you know, your co-creation with AI tools and capabilities and right hand side of the brain, like what computational logic, statics stakes and LLM models and all those kind of things, which needs to be up, uh, you know, upgraded to your skillset.
So this is like, you know, this is a self re reation, you know, you have to think about what, how the industry is changing and what is in for me as an individual, as a team, as an enterprise, right? As a leader. Agreed On.
Hold on. Yeah, you agreed too, Hillary. All right.
Hey, you know what, though? We're at, we're about outta time here. This has been a great conversation.
Look, I, I think every day the way how fast this AI stuff is moving and, and compliance will need to catch up, what's doable with AI too, right? Compliance is, is in, in and of itself will become a moving target. So this is gonna be something we're gonna be watching going forward.
But for now, Gima, Tracy Hillary, thank you for joining us on Control Alt Deploy. Thank you to our friends at OpenText for sponsoring. This is Alan Shimel.
I hope you've enjoyed this episode. Stay tuned for more. Hi everyone, and welcome to the six five Summit AI unleashed for this channel ecosystem spotlight.
I'm joined by my friend Dan Wesley, the CEO of Global Technology Industry Association, more commonly known as GTIA on how AI and community are reshaping the channel ecosystem. Welcome, Dan. Thank you Tiffany, so much looking forward to the conversation today, and appreciate you having me here.
I know we have known each other for a really, really long time, but for those of you who don't know GTIA, let's start there. Maybe you could give just a quick, you know, overview of what you guys, uh, do and all the great work. Sure.
Well, we, we are a, uh, not-for-profit, uh, vendor and member and channel industry association. Um, many would know us from our former brand of CompTIA. Uh, we rebranded under the GTIA moniker, uh, just within the last, this year in 2025.
Um, and continue our work in driving membership value in the IT global channel, uh, and doing a lot of good charitable work along the way to help, uh, make sure that we're having a positive impact to the future of our industry. Absolutely. And such a valuable resource for everybody.
And, and I think more than ever, it's kind of like, I feel like we need it because, uh, we have been through a couple of big transitions from, you know, reseller to value added, reseller to managed service provider to solution provider to systems integrator, to cloud brokerage. Like we've sort of pivoted, pivoted, pivoted, and the channel has had to kind of keep up. But we are in this amazing time where, you know, what used to be 18 months, might be 18 days or 18 minutes or 18 seconds, how quickly the market is moving, especially around ai, you know, as GTIA.
What do you think the role of the community and the association is gonna play in this next transition? Because it's just moving so quickly. Yeah, You're, you're so right about the acceleration of the innovation that we're all experiencing.
I mean, when I joined this association over 20 years ago, Tiffany, as a member, uh, I came into it because of all of the, the, some of the components you just talked about, the speed of innovation and change even 20 years ago. The, uh, need and requirement for us to come together as an IT services industry to understand the next evolution of technologies that we're impacting us, the new business models that we're, you know, paramount to the long-term success of IT service delivery to both small, medium business and enterprise. So the association for me personally, was a way to stay as a student of the industry, stay connected, stay educated, uh, work with peers, work with competitors, understand the market, uh, better than you can do from your siloed position in any emerging technology organization, which I've been blessed to be a part of over 30 years.
It really was a paramount foundation, uh, for all of us in the IT services channel to come together and talk about these, these, these evolutions we all went through. You talked about a few of them, reseller to value added, reseller to solution provider to manage services to the impact of cloud, obviously cyber and, and what we're seeing now in ai. And, and you're right, uh, that today, and it's, it's interesting to say this 20 plus years later, but uh, today it might be even more important to be a part of the community and part of the conversation to try to keep pace with this incredible innovation we're now seeing across the globe.
And the, the pace isn't gonna slow down. I was at an event a, a number of weeks ago, Dell technology world, and Michael Dell is the keynote for this entire summit. Uh, and he said something really that has just stuck with me, and I've said it a couple of times now since I was at that event.
And it was like, well, what we know today is gonna be almost irrelevant tomorrow. Like, how slow we think or how fast we think it's moving today, it's gonna be faster tomorrow. Like, it's just not gonna slow down.
And I know that that has been said a couple of times, um, in our world, but, you know, from an enablement, from an education standpoint, how are you tackling the fact that it is moving so fast? Because having a conversation is one thing, but like there's a talent shortage in this area. 'cause we don't have thousands of people that have great, vast knowledge around ag agentic AI and, and how that's really gonna to change the market and the businesses.
And so education is big and that enabling this transition, that's also big. And, and I think that's, as you just said, the most important part of what you bring to the, to the industry. But how can you help our community, our partner ecosystem, keep pace in in this time?
Well, it, and it's an interesting crossroads as as there, you know, at this stage of our evolution, we are at an, we're in, in an arena where information is is arguably readily available. You can get it from multiple sources, everything's available on the net. The podcast, the, the stories around the innovation are, are easy to come by, but are you getting siloed?
Are you getting the full wholesome picture that you're looking for? And most importantly, I think Tiffany, the ability to sit with a, a peer, a counterpart and, and, you know, a competitor and understand how these new evolutions are affecting businesses and what, how we're gonna apply them to our own business. Everybody's in a different vertical when it comes to the IT services channel.
So they want to talk to other channel providers who are maybe are in that vertical that these technologies will impact differently. Um, much like the days where applications were king, right? You were verticalized inside your IT service delivery model based on the applications that were applicable to the, to the silo of services you delivered or the market that you service today.
We're going through that same thing, but there's I increased pressure, there's increased pace, um, and it's all coming very, very quickly. So again, I think the opportunity for us and the requirement for us to stay more connected and collaborative is, is at an all time, you know, pinnacle for our industry. Yeah.
And this isn't just about us talking about pace from an ecosystem standpoint, because we think it's really the shiny new technology in the corner that we're talking about pretty nonstop around, uh, AI and AgTech. It has everything to do with what customers now need, especially in the s and b segment, where the channel ecosystem tends to be the IT resource for those companies that don't have that, you know, internal bench of talent, right? They, they've chosen to outsource that part of the business.
And so it's really incumbent upon the partners to bring forward to them, kind of like first responders. Like, we know that you are going to be at risk if you're not starting to make these investments. And if, if, if there's any hesitation from the channel at all, it means the end user will have hesitation.
So we really need the channel to kind of jump in with both feet. Um, why do you think it is, if at all, in your conversations with so many partners out there that they may be a little resistant to this next change? Like, ah, we've seen this before, it's nothing new or nothing different.
What, what do you say to those partners? Well, this is what I love about the industry, because those partners are few and far between. One of the things that I appreciate, uh, by, you know, the necessity frankly around our, our industry because it is driven by innovative technology, is the appetite for these suppliers, these IT service delivery businesses to stay knowledgeable, to stay in the conversation.
If they didn't get into the conversation about cloud, they missed it. If they didn't get into the conversation about managed services, they fell behind. So there is almost a predetermined requirement to stay hungry for innovation.
So it it's a struggle. Absolutely. I think you're, you're absolutely right.
It's, they will say, oh, do I need to look at another one? What's what's happening now? And that's why it's so important that we actually get factual about what the impact is going to be and, and how it's being adopted.
Uh, but by necessity, they have to stay aware of emerging technologies and innovation, and they must pick up the cause on behalf of their customer. Their customer didn't run to them for cybersecurity. It was really brought to them by innovation and the challenge and the threat of cybersecurity that was then evangelized by their, the IT service provider fulfilling their role to their customer saying, no, this is real.
I know you're a small medium business. I know you don't think you are going to be impacted by by cyber, but you are, and here's why. And I think the analogy you just provided is twofold for the end user, the SMB customer.
And that's, you know, what makes this industry and the IT channel so incredible that they have to pick up, you know, this cause and take it to their customer and really take 'em and show them why it's so important. And I, AI is gonna be very much like that. Well, the theme of this summit is AI unleashed.
I'm gonna sort of lean into a question I've asked a couple of the other guests as well, is, you know, there, if you could sort of advise someone who goes, you know, I wanna, I wanna start a new channel company, or I'm leaving my existing channel company, I wanna stand up a new channel company, right? And I say that in air quotes, yes. And you, and you could say to them, oh, like, if I were gonna start a new channel company today, I would do what, what, what, what would you, what would you do if you were to double down and you said all the things you know, right?
You've been watching for a long time. Uh, where would you place your bet? Well, It's interesting, starting new, it brings added advantages and some disadvantages.
Um, setting up the operational infrastructure of a business is no small task and often overlooked. So the first thing I would do is say, look, are you sure you want to, are you sure you wanna not, don't just wanna innovate inside an existing operation, uh, because that typically would be easier than standing up new. Now it does come with some advantages.
You can also shed yourself of legacy processes or thinkings or infrastructure that has held you back for growth. So if you're going to do it, be aware of the efforts it's going to take on the administration operational side that, uh, you know, a legacy incumbent has already in place, but also take advantage of the ability to move arguably more swiftly, uh, into just the best in class operational maturity curve. Uh, rather than trying to, you know, uh, adopt or, or evolve into that maturity curve.
Try to take advantage of that, getting that step ahead. But, uh, I think both are viable and both are positive, but they'll come with their own challenges. I agree.
You know, uh, I would say data management is one drum I keep really banging on, right? Because AI is only as good as the data. So data management to me, right?
Breaking down the silos of multiple data sets, right? We've got so many applications in both SMB and enterprises. There's a lot of sprawl.
There's lack of integration between those data sets. And if you really are gonna maximize what, what agen and AI brings to bear, you have to get that right. And that's where I think channel companies have an opportunity to actually use what they sell.
I always say to partners, if you're not using what you sell, it's harder to sell it. And so, uh, have you seen any really great use cases of partners coming to market with a great, uh, you know, I don't wanna just bulk in AI as one big category. It's not like AI as a box and you sell it and it just works.
There's so much that goes in it, but actually come to market with something you felt was unique or different, uh, or, or a great a customer story where one of the partners as part of the GTI community has really been successful. Yeah. And we're, we're highlighting many of those now and, and you know, as we're looking to provide guidance and resources for, for the larger community and the membership, you know, the quick guide to ai uh, reminds me of the quick guide to cyber and the quick guide to manage services.
Um, but those are the jumping off points. What, what I think is, is really a, a valid point that you make is around data. Uh, you and I had conversations a few years ago about the importance of data that was a part of our vernacular and our conversation.
Uh, and I think it's come full circle now. It's, it's mission critical importance to really leverage what we're gonna see in the opportunity for ai. At the end of the day, it is access of data, the manipulation of that data, and the ability to take that data and, and be more innovative and be more automated and provide maybe autonomic computing for the, for, for truly maybe the first time into our industry.
We've been talking about it for decades. Is it, is it here? So I think in some ways, you know, to our earlier points that we talked about on, on this conversation, uh, the sometimes we're ahead of our skis on the terminology by years or decades.
And, and some of those things you and I talked about and, and you've been so good about explaining to the industry, uh, as an analyst are really starting to come to fruition now with, with what we're seeing. And that's an exciting, exciting time because, uh, I do think it takes time to catch up, uh, uh, whether it's technology or adoption curve by the customer or, or this provider themselves. Well, what I love most about the channel, the ecosystem, the partner, community, whatever you wanna call it, is the fact that it's all about community and connections.
And, you know, for those that are watching this, that are in it, you know exactly what I mean. For those of you who are watching this that aren't that familiar with it, you know, it is some massive percentage, you know, some vendors are 50%, north of 50%, some are north of 85 or 90% of all their technology goes through some part of the indirect channel, whether it be distribution, whether it be managed service providers or resellers or any of the terms that we've tossed out there today. But really that community and connection is what it's all about.
And I'm, I'm hopeful, I'm hopeful that the partner to partner community and collaboration and connection really takes off this time because I think this is an opportunity where partners working with other partners in whether it's coopetition or in an alliance way, or really strategically can take advantage of their individual skills and capabilities, and then one plus one equals three versus trying to go at this alone. Would you agree? I I do.
And, and we've talked about these themes for, again, many, many years. You know, managed services was, was the first sort of sort into the ability to expand outside your limited GE geography of where you could drive to, to provide IT services and the ability to do some autonomic computing and some remote remediation provided that, hey, my market can open up. And we talked a lot about in those years about now it opens up the ability to partner with other IT service providers across the globe where you met, or across the geography, at least state to state or frankly even globally, to be able to provide the, you know, on, on site services that are still a requirement or interaction with the customer.
But to be able to own that. So that, that to me was the genesis of the partner ecosystem that did develop. But I think you're right.
I think this is going to accelerate that, uh, and provide new opportunity on, on even a grander scale. So as we wrap this up, Dan, what, what would be your message to those vendors out there and maybe even partners and, and, uh, integrators and ISVs, et cetera, that aren't part of GTIA or aren't taking advantage of everything that the community can really offer? What, what would be your message to them and, and how they could approach, um, you and the organization in a way that, you know, really is advancing enablement and education around some of these new innovative technologies?
Yeah, It's, it's really our obligation. I mean, we, we have been the best kept secret in many ways in the industry for, for a long time. I sat on the board of this organization over a decade ago.
I've been a member for 20 years, and now we have a renewed sense of responsibility to expand the membership. Uh, we're doing this in so many ways at GTIA with the Global communities expansion, with the Spotlight Awards, with, uh, really the resources that we're now developing and delivering into the market. So I encourage everybody to, to check us out, um, come see the value.
I've been a member again for 20 years and, and it certainly paid dividends for all of the businesses that I've been a part of as well as my career personally. So, uh, I think we have nothing but great things collaboratively to do together and, uh, come join the community. Excellent.
Well, thank you Dan, so much for joining us for this channel Ecosystem spotlight at the six five Summit. com slash summit. More insights coming up next.
Hi everyone, and welcome to the six five Summit AI Unleashed. I'm joined today by Dave Shaw, president of HP Solutions, and he's gonna be our keynote speaker to open up our modern work track. We're gonna be talking about the future of work.
Dave, it's so good to have you back again, it's been a minute, but to always love you joining here on the six five. Looking forward to it, and I'm sure it'll be fun. It's been a great summit so far.
Um, you know, work is changing really fast. Like I think everyone out there can appreciate just over the last couple of years, the new tools that have been introduced into our lives. Um, you know, we went through the period of time where we went remote and then we got really used to video.
It was a major boom for your business. And now we've seen this AI proliferation happening at breakneck pace, uh, introducing and forcing all of us in the workforce to kind of rethink how we interact, how we do our jobs day to day, how companies are gonna grow and how they're gonna scale. So I wanna talk a lot about that, but let's just start out with a little bit about, you know, how you're thinking about it leading HP solutions business.
You know, how are you guys thinking about this vision for the future of work and how are you positioning yourselves to deal with this kind of parabolic change that we are all experiencing? We, we think, first of all, you gotta start with the customer and, and we've been surveying every year, sort of the employees and, and how they're feeling about the future of work themselves. And, and what's remarkable is still only 28% of employees feel like they have a good relationship with their work.
And, and that's up a grand total of 1% over last year. It's like that, that's really disturbing. So I, I think the, the first thing to acknowledge is, boy, we have a big, big problem and HP is saying, okay, we, we wanna lean in hard and we wanna make sure that whether it's a, it's a video camera or a PC that I have here, or a printer that I have out there, we wanna make sure that every aspect of what the employee needs to be productive is something that we address.
And, and then making sure that we're solving the problems for their employers, for the CIOs so that that employee base is, is as happy as engaged and as focused on growth as possible. And, and as you just said, hybrid and ai, boy, they, they, they really twist things up and they create all sorts of opportunities, but also a lot of challenges. Yeah, that's really interesting.
I'm listening to you say 28 or percent or 1% better. Um, you know, as a, as a founder, CEO as a president of a business unit, of course your business is probably better, but it makes me think, gosh, you know, how is the relationship and you know, just because chat GPT can do some of your work for you, and I say that somewhat facetiously, um, doesn't necessarily mean people are happier. You know, we as humans are conditioned.
We get adapted to things, we get adjusted to things. We're constantly, most of us are constantly seeking more. We wanna learn, we want to grow, we want to evolve.
Um, and that's, by the way, one of the things I'm really excited about about this era is I do think it's gonna uplevel us as humans and the things we're gonna do. The other side of it, of course, is some of this like, well, what are we gonna do when you don't have to write a press release anymore? Or you're not doing the same exact kind of research that we do, or the analysis can be done really quick.
There's lots of questions here. So talk a little bit on your side though. 'cause HP whether it's the work being done on the workstations, whether it's, um, things you're doing in AI studio and AI boost, you're building a lot of advanced compute solutions to sort of take some of the consumer things that of course people on your devices do every day, but you're also trying to make it enterprise centric, enterprise friendly to help people bring innovation to work, um, and make your customers more productive.
How are you sort of addressing that and putting that into place? Yeah, so let's go hardcore into sort of AI modeling as you, as you kind of indicated, right? You think about a 4G PU machine, our our Z eight workstation, and it's like, that's a powerful machine.
But, but, but if you're coming in new into the world of AI or data modeling, how do, how do we set up the libraries for you? How do we make sure that the, the outputs that come out of that are being checked as much as possible? And so AI Studio is a set of tools that says, let, let's bring the power of these GPUs to the masses and make sure that it's as scalable as possible.
And then when you're, when you're on the road, of course we, and you might be using a, a, a laptop, I have an amazing laptop right here that can, that can actually run some massive, massive models, but I might also wanna be able to reach out and grab some other GPUs where I wanna scale. And so that's the power of boost, which says, okay, let's, let's, let's make all that possible at the edge. So I don't necessarily have to hit the cost of a cloud or don't, don't necessarily have to worry about the security of that data.
And that's a pretty exciting place to be. So we're talking to a lot of manufacturers and engineering firms and product designers and forecasting agencies saying, Hey, we, we, we wanna make sure that you have the best of these AI models actually practical and usable to you because that, that really is so core to people feeling productive and feeling engaged. Yeah, you bring up a lot of great points and, and some of it's also the scale and the usability.
Like so much of the focus these days, like AI has been explosive, but we do tend to focus a lot about kind of rack scale, the data center, and so much of the use and the consumption is happening on our devices. Very small GPUs or NPUs, some of them are even a little bit older, and we're using 'em right in the right on the, you know, application on our browser. We're using these things every day and you, you've been really focused on building these workstations that kind of are kind of the intermediary, right?
Like, yeah, you don't have a 72 node rack with, you know, GPUs and a, but you can do some really advanced modeling, um, you know, for, for data set on things like customer product design. So that's, that can be done right in-house and by the way, no latency and lower and more predictable costs. So those are all things that are kind of going on there.
You know, I alluded to David early in the conversation, I kind of alluded to, you know, that period of time where we were all home and all on video all the time, and we of course have seen this kind of ebb and flow. We've seen some companies have gone to hybrid work, some companies have told everybody to come back to work, other companies. And by the way, this is a debate.
This has not been answered yet, whether Constant debate, constant debate, yeah. And, And I think it's also cultural. I think some companies can really make it work.
I think other companies struggle probably has a lot to do with leadership. It has a lot to do with the tools. But how is collaboration sort of playing a role here?
Because it's still like every one of us, I dunno about you, but like every day I do like five of these. Even when I'm traveling and I go to events, I'm still like peeling off to go into a cafe somewhere to get on a video in between my in-person meetings. I mean, it's pervasive now.
So how is HP sort of, it's made a lot of investments kind of building on this and continuing the momentum as we've sort of seen it somewhat normalized in terms of how much we talk about it every day? You know, it's interesting, we're asking our, our leaders to be back in the office a couple days a week. And, and we think that's important to model to all of our employees.
I'm sitting here today in our headquarters and, and, and that's really important, but if you think about it, we, we have locations in dozens of countries. And so it doesn't matter if I'm back in the office, I'm still talking to people all around the world. And so this, this video networking, this video, collaboration's really not going anywhere.
So therefore you wanna make sure that you show up the best. You wanna make sure that when you first walk in the room, that first five minutes is productive. You know, we're, we're, we're years into this journey now, and, and, and how many times do we still walk into a meeting and say, am I on, can I share content?
Am I connected seamlessly with my PC and the video devices? And so we're, we're all about sort of that, that layer of making sure that the devices work seamlessly. And then of course, once you get into the meeting, you wanna make sure that the, the video quality is as natural as possible.
So if I had colleagues here, we're seamlessly pulling it together into a conversational mode. And so we, you know, poly HP Poly's been doing that for, for, for many, many years now with the audio technology and the video processing. But ai, boy AI just supercharges that, right?
And, and you want, you want the information that's coming off of these video devices to be so much more translatable into real productive results as well. Yeah, and I love some of the, the, the features that we've seen evolve too, like real time translation, you talked about being all over the world, like as we've seen almost zero latency, the ability to have two people speaking a totally different language with no, uh, no latency, no gap. I mean, things like that are so powerful.
And the other thing is like, talk about a productivity hack, but when we started being able to kind of record meetings, summarize them, capture, I mean, gosh, I can't tell you how many times I come off a meeting and be like, that was a great meeting. I don't remember anything we talked about. But those new, What am I supposed to do?
Can you please tell me what I'm supposed to do? What are my actions? Right?
I mean, that's, that's what we all want. Coming out of these meetings is perfectly, but I mean, when you're having as many as we have, it's so easy to be like, that was just great. Um, and then you get a day, you run straight to the next meeting, straight to the next meeting.
It's like, I had 13 meetings yesterday, I need a quick summary. So these tools have become really, really powerful. Another thing that you all have been very focused on is sort of driving that workforce experience, um, using tools.
And, and this is one of those things where it's kind of like how technology can be used in a way that is, it's involved in people's every day, but it's not overly intrusive. Um, but at the same time, it helps sort of monitor behaviors. It monitors things like when people need rest, when people are most productive, um, by the way, when they're safe, we know security is going to be an exponentially bigger problem, uh, in the era.
And not just security, but also just how we use data. So there's a lot of reasons for companies to be sort of guiding employees along. And it isn't all for just watching Big Brother stuff, it's also to make sure employees are having a great experience.
Talk a little bit about how you are thinking about workforce experience building this workforce experience platform to drive employees to better outcomes. Well, I, I think, I think the name itself is actually very important that, that workforce experience means we're really focused on the employees and what's their experience of the technology. That that has to be the primary metric.
But then if you flip it around and think about it from a CIO point of view, if you have a hundred thousand or 200,000 employees around the world, first, of course you gotta get the devices to the employees. But then when, when the devices get set up, you wanna make sure it's set up properly, it's been secured properly, and, and is ac is it actually being used, right? If, if you, if you ship conference room equipment around the world to, to a remote location, is it being used effectively?
Are they having network problems? Are they having camera prob, you know, camera quality problems? And how, how do you address that real time?
And so the, this workforce experience platform, or WXP is our acronym is, is really targeted to the CIO saying you want your employees to be engaged, you want 'em to be focused on growth. How do you remove the digital friction? How, how do you remove these frustration points that we all run into?
Whe whether it's for a PC or a printer or a headset or a video camera. And, and, and so HP's committed to doing that on a multi-vendor basis. We don't care who makes the pc, we don't care who sort of outfitted the conference room.
We wanna make sure that we're providing insights. And then really what's what's fascinating with AI is not just running scripts to fix problems, but really using smart AI agents to mitigate problems before they show up. And to make sure that the CIO has a almost a realtime dashboard of this is working, this is not working, here's where you need to put your attention.
So it's, it's powerful. And I think it's gonna goes back to that 28%. How, how do we remove the friction so that more people feel like the tools are enabling them to do their jobs?
Great boy, that, that's, that's transformative for us in a world of AI and hybrid. Yeah, I, it's kinda like when my watch tells me to stand up and sit down, you know, I wanted to tell me, Dan, you've done a lot today. Take a nap.
Um, by the way, I don't think it'll ever do that, but it's, it's a dream. We should Work on that app. I don't know.
I mean, workforce experience is a whole holistic view, right? I mean, have a glass plan afterwards, have a cup of coffee in the morning. It Works.
I know it sounds a little silly, but I mean, I, I don't know about you. 'cause I, I basically, you know, I work like two 12 hour shifts. I I have twins.
There's two of me and I work in 12 hour shifts. But in all serious, like sometimes I'll have a morning, I'll be up at five 6:00 AM 3:00 PM you know, you start getting that fatigue, 10 minutes, you go sit down, you close your eyes, you open your eyes, you feel like a million bucks. You can get that next 12 hour shift started.
Off you go. Um, let's wrap this up and talk a little bit about kind of the big future of work. So, you know, we know the future of work is gonna look different.
We know the jobs of the future are gonna change. We know that with every revolution has come more not less opportunity. So for everybody out there that has that kind of what's gonna happen with ai, I think there will be some jobs that we know that probably will go away, but there will be new jobs created.
And, and by the way, we're just starting to see how this is gonna gonna play out. Um, but you have to stay nimble. I mean, you as a company, um, have to continue to stay on the forefront.
So how are you thinking about enabling the future of work, uh, to make sure that, you know, employees are ultimately, um, you know, powered by tech, fueled by passion and inspiration and that, you know, companies can continue to grow even in a very different era. So it's interesting, I have a couple teenage kids and so I'm thinking about this of course from a business point of view 'cause it's my job, but also from their generation point of view. And, and you see how natively comfortable they are with mobile technology, how natively comfortable.
They're with all the different varieties of AI and, and the power of AI as, as we all know is not automated in a task. The power of AI is that it's bringing in all the world's knowledge into sort of this easy to navigate and interrogate and have a dialogue with intelligence and, and that, that transforms it because it, it, it allows me to become an expert so much more quickly in a number of topics and then make decisions that are much more well informed and much more oriented to, to, to the future, right? And, and so that's, that's exciting.
So I think, I think first of all, we all need to make sure that we, we keep that perspective, which is the power of the world's information at your fingertips, and you can just talk to it, right? And, and that's, that's a new world now from an HP point of view, how do we make sure that the devices that we put out there fully benefit from that? So, so let's say that you and I are not in a Zoom meeting, right?
I what, whatever, whatever microphone or whatever camera's in the room, I wanna be able to interrogate that device and make sure that it provides the power of the world's information back to me. And if I have two of them together, I wanna make sure that it's doubly or triply good. And, and then as I walk from room to room and have a device with me, whether it's a headset or a computer or a video phone that knows who I am and is able to bring the context of my day with me and provide information that's based on my private information, right?
Uh, my secure information, but allows me to do my day better. And, and that to me is a really transformative vision for how we all will be working in the future. Then you apply that to industry verticals and frontline workers who may be in a retail environment or a healthcare environment.
We're, we're already processing visual information on more than a billion patient records a year. And you, you think about the power of that and how you, how you use petabytes of data to, to kind of create a better diagnosis or a better outcome for the customer interaction or the patient interaction. That's, that's really exciting to me going forward.
Yeah, you made a great point. We didn't really even touch on it here, but so much of the opportunity sits in data that's barely touched AI yet, and that's been a big theme here of our six five summit. I'm sure it's gonna be one that you're gonna be thinking about a lot, unlocking all the power of all the tools, all the tech, all the data all the time.
Dave Shawl, thank you so much for joining me here at the six five Summit. It was great seeing you. Let's do it again soon.
Always fun, Dan, thank you so much. Appreciate it. And thank you everybody for joining us for this modern work track opener at the six five Summit.
com slash summit. We have your access to thought leadership shaping the industry with more coming up next.