Techstrong TV March 23, 2026
The rise of agentic commerce and how AI is reshaping fraud detection and digital trust
Why AI agents need real infrastructure access to move from sandbox experiments to production workflows
The battle over AI compute and how decentralized models are breaking hyperscaler dominance
How ambient AI is transforming healthcare by reducing admin burden and restoring patient interaction
Tackling database sprawl and governance with modern DBaaS and automated infrastructure
Transcript
Hey, everyone. Welcome back here to Techstrong TV. I want to introduce you to our next guest.
He, he comes to us from Vegas today, but that's not where he's-- You're gonna tell... You're gonna know as soon as he speaks. He is from the land Down Under in a place called Bondi Beach, Bo-Bondi Beach, very famous surfing area.
Uh, Alistair Falknerr. Alistair, Alistair is the CEO of a company called Darwinium. And there's an interesting story behind that we'll touch on, but let's welcome Alistair to our show.
Alistair, welcome. Thanks for coming here on Techstrong TV. Alan, what a pleasure.
Thank you. Um, looking forward to the conversation. Very, very exciting to be here.
Absolutely. So Alistair, I always like to give our audience a sense of who they're talking... They're actually, truth be told, they're not talking to you, you're talking to them.
But I'd like to give them a sense of who they're listening to, who, who's speaking. Yeah. If you wouldn't mind, I, I mentioned you're from Australia, but give us, give us kinda your life story, if you don't mind.
Yeah. My, my life story is, I was born in a small town called Darwin in the Northern Territory in Australia. Uh, hence, the name Darwinium, was born from, that place of birth, but it was also named after Charles Darwin.
And so, I'll get into Darwinium i-in a little bit, but essentially it's the next evolution in fraud a-and security in the AI era. Um, previous to co-founding Darwinium, I co-founded a company called ThreatMetrix, which became the leader in online fraud prevention and was acquired by LexisNexis. And, it's been my life journey really trying to figure out how to stay ahead and make sure that the technology promises of the internet are delivered to all.
And, you know, and that really relies on us being able to trust and do commerce online. And, you know, I've been anticipating this time where everyone's talking about agentic commerce and the AI economy and what does that mean to them, for a long time. And it's been clear to me that unless we use AI to fight AI, we're gonna be in a world of pain.
No, no, no doubt about it. It's funny you mention LexisNexis. Actually, LexisNexis Risk Systems is like the building just down the block from us, from us here- -in Boca Raton, Florida.
And, uh- Oh, you're in Boca Raton? Yeah. Yes.
Yeah, great company. Great people. Yeah.
Yeah. Had a fantastic time. Good people.
We, I... We, I know a bunch of the people who used to work there, still work there, I'm sure. Anyway, look, AI has certainly changed the game.
Mm. Uh, it, you know, my background is in cyber and, and e-commerce security is part of that- Mm. -cyber mission.
Uh, we are seeing, you know... Uh, the, the, the problem is, is that the bad guys are just as smart as the good guys, and they use AI too. And, and, you know, and as you said, we're at the point now where you kinda need AI to defend against AI.
One hundred percent. So Darwinium, is an AI fraud prevention company, so we were born in the AI era, to solve this problem specifically. using stolen credit cards and such.
And then, you know, we saw the rise of bots and automated attacks, and these bots were relatively dumb, but pretty, dangerous or impactful to organizations because they could drain resources or take websites off-offline. But the problem is, and because of that, today, we did a survey of about five hundred, security and fraud professionals, and they found that thirty percent of all organizations just blot-- block any automated activity outright. " When I say most people, many org-- large organizations are trying to wrap their head around how do they operate in this world of agentic commerce, where even if they're not sure yet that they want to be able to, you know, allow online, you know, agents to be able to do transactions on their website, you know, they have some nervousness about that, obviously.
But, when you think about that every company's forced to be an AI company by the virtue of the fact that their consumers are adopting AI faster than any technology that's happened before it. And so, you know, AI is where consumers are increasingly discovering what services, you know, they need and, recommended services by that, by that AI. So you're forced to participate in the AI economy, whether you're a plumber or you're a digital business.
And that's a problem that, you know, a problem and both an opportunity that Darwinium is, working to help large e-commerce, large banking companies, airline companies to try and solve. How do you bridge this gap where in the previous generation of online fraud, anything that was an automated credit card transaction or an automated account being opened or an automated login was treated as being suspicious, and now that's just no lo-longer the case. So Darwinium has released this ability to understand agents and their intent.
It's not just, are you a good bot? Are you a bot and you're bad? And you know, what are you trying to do?
Are you a good bot being used by a good human being, or are you a good bot, let's say you're a ChatGPT or other that's being compromised or running on a compromised computer, or, le-leveraging stolen credentials to then use something like an OpenClaw or something like that to then attack a website. So Darwinia has provided a set of tools where we've said, "Let's take a step back. " The big challenge today is that in large organizations today is that security and fraud prevention systems are siloed.
" But they don't really have the tools or the ability or the nuances to understand, you know, is this a, a good version of ChatGPT or is this, you know, someone using ChatGPT in a bad way? Um, to understand the intent of an, of an agent or a computer or a human, you really have to understand their entire... how they interact with you across the entire user journey.
How did they discover you? Did they come directly to your checkout page? Um, do they browse for products first?
And in the human-- So that's, you know, in a human kind of scenario, that makes sense, right? You would typically assume that new consumers come, have a look around, before they decide what they wanna buy. Whereas scripted attacks or fraudsters know exactly the product they want and, you know, go directly to the checkout, often with stolen credit cards.
And that's also the case with agentic AI. What most people don't appreciate about agentic AI is that user consumption is no longer a straight line. By that I mean you s- you start on the browser and you finish that transaction on your browser.
Agentic AI has a combination of both API integrations or interactions and also, you know, interactions with browsers and potentially mobile. So for example, if you're searching on ChatGPT for an e-commerce site to be found or discovered by ChatGPT, it typically uses something what's called an NCP server. So I don't want to get too technical for the audience, but you know, it's just a protocol- No, we, our audience is technical.
It's okay. Okay, fantastic. Um, so you have these NCP servers, right?
" Um, some organizations might say, "Yeah, you can even do a credit card transaction, a purchase for us. You know, we're all on-- we're all for it. " Others won't.
So from a, from an e-commerce fraud perspective, no one has any visibility into these API interactions. There's a complete black hole when it comes to understanding, did this person just land on my checkout page directly with a product because they're a fraudster? Or did it come from being searching through, you know, ChatGPT, discovering here's a product I want, and then, you know, essentially clicking and landing on my website ready to transact as a human even, even if it's not an agentic transaction.
So that is to say, you know, in the age of agentic commerce, it's no longer just a straight line. We cannot just look at, you know, things in isolation. We need to have full context.
I, I did mention something too as well, Alan, that, you know, to fight AI, you need better AI. And from a Darwinia's perspective, what does better AI mean? Well, better AI, AI comes from having better data.
So it means breadth of data. So I gave you that example that if you're not even monitoring your MCP servers in the context of a total of a user's transaction, then you're not even seeing the full picture. How do you fight something that you can't see?
So Darwinia released the ability, and it's the leader in this, and the only company that I know, that I know of, that enables you to deploy your fraud detection and your security policies on the edge. What do I mean by the edge? Edge computing, things like content delivery networks, companies like Cloudflare, Akamai, and others, have this infrastructure which enable organizations to deliver applications seamlessly, quickly, without latency to their customers wherever they are in the globe.
Darwinia leverages this kind of idea, this concept that says every digital interaction with your brand happens over a network. So if you're placed in the network, you're in the best place to see where these agents are going, whether they pivot from APIs to websites to mobile. You have that full visibility of that customer journey, whether that's by agent or human or both.
So that's first problem. Problem number one, breadth of intelligence. You need to be able to have full context of where that consumer's going and their touch points.
The second thing, when you have AI to, to fight AI, you need depth of intelligence. So you need to understand, is this an agent? What's the fingerprint of...
What device is that agent running from? Can we fingerprint that device in a way to re-identify it if they try and change cookies? What kind of behavioral biometrics can we collect from this interaction to understand whether this is really human or whether it's a bot?
You know, if you see something click, you know, agents tend to click, you know, in the middle of a button, for example, when they're interacting with a website where no human typically, you know, is that accurate or consistent over time. So there are ways. The good news is folks are very concerned about how to authenticate these a-agents, how to verify it.
If you have the right detections and the right, instruments, you can, build a better picture of is this human and an agent. But ultimately, what you want to understand is you want to go beyond this concept of identity. You want to understand intent.
And the reason why intent is so important is-Alan, someone can steal your s- your credentials, your identity, and they probably have many times over in your lifetime. I have, and I'm sure many of your- Mm-hmm ... lis- lis- your listeners have as well.
So, you know, if someone uses your, your name, your reputation, but it isn't you in that transaction, it's not you being, you know, Alan being good or bad, it's the fact that, hey, Alan's name and credit card are being used, but in a location he's never, you know, used it from before. Um, you know, the transaction amounts are totally different. They're a different product set than what Alan normally, tends to buy, that maybe there is something wrong with this thing that's pretending to be Alan.
So it's really about trying to go beyond identity and understand intent. So you have this breadth of data, you need the depth of data, and the depth of data, when I said about, you know, d- understanding that device, understanding the behavior in an interaction, it's also understanding that full user's journey, and I gave you that example of do they do a beeline for the checkout or, you know, if someone compromises your bank account, do they instantly add a new beneficiary, which is a mule account that they're gonna try and wire your money to? So it's very important to have that full journey visibility.
But lastly, what's important about the best data is you need it to be adaptable. And so, that means because agents, what they're doing in the age of adversarial AI, is people really aren't prepared for what's coming, and what's already here in the sense that AI's able to evolve much faster than organizations and humans are able to keep up with, especially if they're siloed. 'Cause if you can think about it, if you have an onboarding security solution and, and department, you have an authentication security solution and department, you have a payment security solution department, you have a bot solution se- you know, and, and department, if you need to make a change in a way that's coordinated that doesn't interfere with good customers, all of those things have to sync up correctly and be in alignment, otherwise you're going to reject good users, and accept too much fraud.
So that's really what Darwinium provides, is a platform we call a cyber fraud prevention platform that gives you that visibility across all your digital touchpoints, across all those points in the user journey, abilities to understand intent in real time, and then progressively rescore that user so that you can allow as much of the top of the funnel in without proactively blocking them or, or, or annoying your customers. And, you know, as they reveal more about, about themselves, be able to provide more fine-grained policy decisions to either interject some friction, maybe step them up, ask them for identity verification, or allow a streamlined checkout, you know, instant checkout, experience, which most companies are, are looking to provide. I'm moving territory.
Excellent. That was a long answer to your question. Alastair, that was...
Yeah, that was. " We c- we covered the whole thing in one question. That's a first for me.
Usually I gotta pull it out of people. Um, you know what we didn't give people, though? The website- Oh, yeah ...
of how they can go find out more about Darwinium and maybe sign up for it or check it out. com. So yeah, please, please contact us.
We'd be very happy to work with you. I mean, the question, you know, we'd love to help answer for many companies is what's your agentic AI strategy? And that could be, "Hey, we don't want anything to do with it.
" And we can help you with that in terms of, well, how do you verify that's the case? How do you make sure you have the systems to be able to, block and deny? And we can, yeah, very happy to consult with, with folks that are trying to struggle with those questions.
You know, I, I think, as time goes on, you're gonna hear less and less of that particular one. I think it's gonna be more about how do we embrace agentics and use it securely and... but to increase the amount of commerce we give.
100%. Right? I, I- I mean, that's, you know, one of our taglines, you know, is enabling agentic commerce instantly with confidence.
Yep. So it's all about- With conf- ... you know, not, not just stopping the bad.
Sure, there's fear and uncertainty and doubt, but, as you know, know that most people want to be in the AI economy. They know they need to figure it out. Uh, you know, we ha- No one wants to be left behind, correct?
No one wants to be left behind. And that, that's where it's at. Alastair, Alastair, I appreciate you coming on.
Enjoy your show in Vegas. Safe travels back to Sydney. And, best of luck with Darwinium.
Yeah. Hope to see you in Bondi. I'd love to.
Next time I'm there I'll look you up. We'll do it. It's been...
I... Actually, it was probably... It was after COVID, so it wasn't that long ago.
Oh, yeah. But, well, anyway. We'll, we'll have a chicken schnitzel at Augsburg.
Sounds good to me. Take care. Yeah, absolutely.
All right. Bye-bye now. Alastair Faulk- Alastair Falkner, CEO Darwinium, here on Techstrong TV.
We're gonna take a break. We'll be back. Hey, everyone, it's Alan Schmelzer at Techstrong again.
Hey, for this next session, you know, we call it Agents + Apps + Chat. It's features Richard Riley, who's GM of the Power Platform Marketing at Microsoft, as well as our own Futurum analyst, Dion Hinchcliffe. Dion and Richard will build upon the foundational vision of Agents + Apps + Chat, creating a solution-orientated view into the heart of agentic business transformation.
In this session, you're gonna learn how agents are enhancing workflows and redefining the architecture of business value today. You're gonna hear about practical applications for agents in terms of UI, logic layer, and decision engines across business functions, everything from finance to HR to sales and even customer service. I think you're gonna enjoy it.
Here's Richard and Dion. Thanks, Alan. This is Diane Hinchcliffe, VP and, practice lead for our Chief Information Officer, Research Group, and I'm with the Futurum Group.
I'm here with Richard. Richard, can you give us an introduction? My name's Richard Riley.
I, lead the low-code go-to-market team at Microsoft, so that covers all of our low-code portfolio, Power Apps, Power Automate, and includes Copilot Studio, our, our agent building platform. Well, it's great to have you, Richard. And what's interesting, the CIOs I talk with, they're undergoing all these changes with, with AI, and now agentic has arrived, and they, they're under this realization that they are going to have to transform their organizations using AI agents.
And so I was wondering, you know, to help them understand this, how do you define agentic business transformation that, goes, beyond just mere automation and is really ex-explains kind of why it's a new paradigm? Well, I mean, I think agents can do lots of things. We, we tend to think of them existing on this kind of, spectrum.
So you can have very simple agents on one side of the spectrum and very complex agents on the other. So to give you a bit of an example there, I would say on, on the left side, on the simple side, we kind of say agents that just do, you know, regular Q&A. They're grounded on a few documents, and you ask them a few questions, and they can give you answers.
They're super useful in certain situations. And then on the right-hand side, you've kind of got things like autonomous agents that they can work off triggers, they can run business processes, they can, they can literally work autonomously and have very complex logic, complex instructions, and run very complex business, business processes. So, and then you've got everything in between.
So we kind of think it, it, it really depends, on what the-- who's asking the question and what they're asking, the context they're asking the question in. But it's helpful to think about these as a, as a spectrum of things versus, an agent is just a, is just the same agent. We appear to be on the cusp of a massive wave of agentic solutions.
Uh, some are narrow, some are broad, and, some are open source. What makes Microsoft's approach defensible and distinctive in the flood of agent frameworks and offerings that we're seeing show up? Yeah, that's a good question.
So I'd probably start with the breadth of tooling that we've got. We kind of span from the very easy-to-use experiences that are built into M365 Copilot with Copilot Light. You can literally describe an agent that you want, you can give it some grounding content, you can tell it to go talk to, to SharePoint and a bunch of other kind of content sources.
Super easy to do, super easy to share, very valuable. We then have Copilot Studio, which kind of takes that a step further. You get access to a lot more capability, in-including things like triggers.
And then we take that an even step further when you think of, Azure AI Foundry. All of these things are kind of tied together in a, in a very integrated way. Um, so it's very easy, very easy to move from one to the other and incorporate one or the other in, in your solution.
So I'd say our, our breadth of toolset is probably number one. Uh, number two, I would probably talk about access to data. Any customer that's an M365 customer of Microsoft, has an enormous amount of kind of that tacit knowledge, that data in Microsoft Graph.
We make it very easy for you to get at that to make your agents, more intelligent. You know, it's one thing to be able to run off a, you know, rows and columns in a CRM, database or, you know, ERP or FNO kind of, service. It's something else when you can marry that with, that tacit knowledge that you've got in your enterprise to bring intelligence, much more intelligence to what the agent can do.
And then thirdly, I'd say, our kind of core strength in security, governance, and compliance. You know, we, we've, we've invested heavily for a long time to help customers, secure and manage their, their enterprise data. All of that investment flows through to, to your investment on the Microsoft stack for agents.
Agents respect all of the policy, the labeling, all that kind of stuff that you've already deployed to manage your data. If you're building your agents on the Microsoft stack, that stuff just flows through. So I say those, these three things are probably the three primary.
Yeah, that makes a lot of sense. And so, so let's zoom in for just a moment. You know, help people understand, how do agent-powered interfaces change the way that workers interact with business systems, you know, compared to traditional user interfaces?
There is a lot going on in the ind-industry with how kind of apps and agents are coming together in, in super interesting ways. Um, I think over time we'll see agents starting to adopt some of the app modalities that we expect from apps today. So think of a time when, when an agent can actually start to build an app or even just a UI, like a, a form, on the fly for it to solve a business process or to, to, to help you, you know, move forward with whatever the thing is that you're working with the agent on.
I think we're gonna start to see that show up. It's not today, but, over, over the, over the, over the course of time, I do think the app modality and the agent modality will start to mix. And ultimately, if you think about it, there's a, there's a, there's a very good reason for bringing those two things together.
The, the example that I like to use is around, you know, a, a procurement process. Like, every company has to buy stuff. Today at Microsoft, you know, you have to know three people.
There's three different tools. A bunch of approval stuff happens. That could be s- the couple of apps you have to go use, that could be built into a series of agents and Copilot kind of marshaling the whole process.
" Copilot could know the agents that it needs to go talk to, to be able to do that. There could be, like, a legal agent to check the, the, the statement of work that you're trying to, trying to kind of, work through. Um, there could be a procurement agent that could go make sure you've got access to the right, and you're hiring the right vendors.
Like, every step of the way, Copilot could run that whole processYou don't necessarily need to go through three different tools. If Copilot needs some data from you, it could create a form if needed, if it's not a conversational type of, thing that it's, it's asking for. So you can see how these things start to s- really blend together when you start to think about agents working with other agents, and then having something like Copilot kind of manage that interaction for you.
So I'm glad you brought up talking about different agents, working across the business, and, and that's something we call orchestration. And one, challenge enterprises face is orchestrating multiple agents across different domains, finance, HR, customer service, without chaos, integration or security issues. How does Microsoft envision enabling agent orchestration across the enterprise, and what governance mechanisms will make it all work and safe?
Uh, that's a good question. So there are a couple of things that, I don't think we're particularly unique in the industry with, you know, like supporting MCP for agents to be able to use tooling, and, supporting A2A for agents to talk to other agents. That's kind of table stakes these days.
The things-- The thing where it starts to get interesting with Microsoft is our ability to use capabilities like Agent 365 to provide kind of end-to-end observability across all of the agents that you've got running, in your, in your organization, to the extent that you can even give an agent, you know, an agent ID and treat it like a, like a user, things like conditional access, all that kind of stuff, just work. And then I also think, like once you give, organizations the ability to kind of observe and manage and govern agents, it starts to open up new kind of frontiers of where they can use agents. It allows them to think about business problems that they've had in the past that have historically been kind of unautomatable.
Maybe they're too determi- non-deterministic or, too complicated to, to do with traditional automation tools, and apply agents to those problems. And we've seen a ton of customers kind of look at existing business pro-processes and decompose them and figure out where they can replace certain parts of them with an agent. They don't replace the whole process, but they start to replace parts of that process, and over time, as the technology matures, as their understanding and confidence with the technology, matures, they start to build out more, but also look at brand-new problems that they've faced for a long time that have just been very difficult to address with technology.
And that's when if you kind of bring all the, all of the, all of the assets together, the things like A2A and MCP, things like Agent 365, things like the security and governance and compliance capabilities that the Microsoft stack offers you, it really does let you start to look at these problems in a very different light and start to apply technology to, to things that you just previously wouldn't have tried to because it was too hard. So let's talk about really getting started with agents. You've talked about agents being on a spectrum.
How should organizations assess where they are and what kind of agents do they need? Uh, you talk to a lot of different customers and you have a good sense of that. Can you share that with us?
Yeah, totally. And there's no single answer to this because everybody's different. But I think it's important for people to start in a place they feel comfortable with.
It's very easy to run into this too fast, not be super successful, and then, and then feel, you know, a little bit terrified for, for trying to scale it. So, it's actually very similar as well to the way that people in the past, over the past six, seven, eight years have deployed low code. The deployment patterns that we see with things like Power Apps are very similar to the customers that we see deploying, you know, agents in any meaningful way.
I mean, actually, the comp-cu-customers that have already deployed low code at scale seem to have a very familiar pattern to follow with, with how they deploy agents. So it really does fall into that pick a business process, maybe it's the... Maybe just pick one.
Find the one that's the most inefficient, the most expensive, the most painful, you know, it's, it's creating the most work, and then break it down to, into its com- decompose it into its component parts and start to figure out where you could apply agent technology to those component parts. Don't try and replace the whole thing. " Now, that may be possible, but it's really difficult.
So basically, figure out what that recruitment process looks like and break it down, and then attack it in chunks. And then you'll learn what the product, the, the technology is capable of. You'll learn what your, you know, your teams are capable of.
And as both mature, you'll be able to expand and e-expand it within that process and expand it outside of those to other processes as well. So it really is a, it really is a journey, and, and most people will find their own way through it. We have a ton of best practices, guidance, patterns and practices, that kind of thing, thing, and templates that we, that we can share.
But, but ultimately, every customer is different, and everyone's gonna look at this differently and figure out which, which is the best place to start. So when we talk about agentic business transformation, we see a lot of organizations are trying to figure out, well, how does this fit into my legacy, systems, the architecture I have today? Uh, what thoughts do you have about how do we, how do we bridge that gap between, you know, the modern agent stack and, legacy IT?
Yeah. There's a couple of things there. The first one would be find ways to integrate, like MCP is a perfect way.
The, the, the rate of adoption, for MCP has been phenomenal. So go learn about that. Go figure out like how you could stick an MCP server in front of the services that you want to expose to, to your agents.
That's step one. And then step two is, if you already have, you know, deterministic workflows, which I'm certain everybody does, there are ways you can start to pull those in to things like Copilot Studio, keep them deterministic, but build them as agents. So you can actually replicate what you've got in an agent, and then over time, you can start to create, you know, replace pa-parts of it so it's more agent dr- like AI agent-driven than deterministic.
So there's lots of ways you can start to bring these two worlds together without kind of diving in or, or not. Agents will become the core logic and decision-making layer in businesses, business processes soon enough. How does agents as the new logic layer, change the way that, enterprises think about their core systems?
What are the implications there? Yeah, I think, there, there's gonna be a, a meaningful change with how people interact with core line of business systems like ERP, like, like CRM. Um, traditionally today, there's a, this is kind of a forms over data type web experience.
You have to go somewhere, fill a bunch of forms in, input a bunch of data, and, you know, press submit. I think fairly soon that, that there'll be kind of an inversion of where the IP and the logic sits. It'll be less on the database and forms layer.
It'll be much more on the agent layer. And what that means for users is they're gonna get faster access to data. They're gonna get smarter answers.
They're gonna be able to use multiple data sources to, to assess a certain situation. You know, if you're a seller, why am I sending you to the, to our serv- customer, you know, our customer service, solution plus your CRM to go figure out what the customer you're about to meet, whether they've got any open support tickets and they're angry at with you. Like that, that it should just be able to ask an agent to be able to do that.
Um, if you're a salesperson and you've just got off the phone with a customer, maybe the call's transcribed, maybe there's a bunch of email traffic between you. Why am I making you go repeat that, cut and paste it, make it up again, and submit it into a, into a CRM system somewhere? An agent should just be able to do that.
So I think, I think there's gonna be that switch from people laboring away in, you know, web forms and web services to, to an agent proactively, in many cases, working with these systems, and helping the, the salesperson or the service person, whoever else it is, to get more done, and be way more productive. So how are agents enabling organizations to leapfrog, traditional low-code development and go straight to intelligent orchestration? So I'll give you a few examples.
The first one is I wouldn't exactly say leapfrogging. I would say we're using agents to make that kind of low-code paradigm even stronger. Uh, so things like the ability to use plans in Power Apps where gone are the days where you're trying to describe an app and build an app.
What you do is describe a business process, and then Power Apps plans can use, several agents. There's an architecture agent, there's a data agent, and it can actually go build a business solution for you. So...
and that business solution could be two or three apps, some workflows, a couple agents. It'll actually do the end-to-end thinking. Like, if you were a business architect, what would you build versus just building an app.
So that's number one. We're, we're leveraging agents to help you build kind of better low-code, solutions. And then number two, you know, we have new capabilities in M365 Copilot, like Workflow Builder and, and App Builder, where someone with absolutely zero coding experience can come and literally describe an agent or a workflow, and App Builder and Workflow Builder will go build it for you and run it.
Uh, and then you can-- it, it, it can store persistent data in SharePoint. It, you can share that with other people. Uh, you can even start to modify it.
So if it's not exactly what you want the first time you kind of describe the app, you can modify and change it as much as you want conversationally. And that really does open the door to many more people being able to kind of use this technology. These aren't gonna be apps that you end up running your business on.
They can help a team, an individual achieve more, be more productive, using AI, to build apps, things like apps and, apps and workflows. So what we're seeing is companies, plan for the role of the maker evolving, where that maker has really been that low-code developer who's been using things like Power Apps, to build point solutions in their corner of the organization. What we're seeing is that role is growing up, and it's becoming, one that, that's gonna take advantage of this, o-of these, all these intelligent agents that are, being built inside the organization.
And now they can build new solutions that span departments and, and cross, silos, in terms of the business processes that they can integrate. And so creating higher order, more strategic solutions out of that agent landscape that's, that's forming, and these are things that, that, you know, now will automate and run on their own. But is that, that we do see that, that maker still has a role and, in fact, an even more important one.
I was wondering what you thought about that. Yeah, it's a really important point. I also think IT are gonna play a very important role in this as well.
You know, they're, they'll be the ones building the MCP servers, so they can provide access to, you know, data and, and, and logic to, to business users units that, that wanna go build their own agents. They, they'll be the ones that are building the kind of high order bit agents so that, business users can take advantage of those. So I think when, when you bring those two things together, you know, you create a, definitely create a, total is greater than sum of the parts type math for, for customers.
So in this new world of agents where it, it's, you know, the code, the, the AI is touching your business and your data, the, the concern is around compliance, and security. Uh, I was wondering if you could speak a little bit to, how does Microsoft ensure that these very powerful agents that are working with your business, are following the rules and are secure? Yeah.
It comes up a lot, in conversations that I have. The thing to remember though is, agents only have access to the data that you give them access to. They also respect all of the policy, all of the governance controls that you've got over the data.
And I think that's fairly, unique to the Microsoft stack in the sense that all of the investments that you've made on things like Purview and, and managing SharePoint, that kind of stuff, that all just flows through to agents. Uh, when you, when you go outside of the Microsoft stack, you essentially have to kind of copy paste that data somewhere, and at that point you lose all of that governance control that you once had when it was in the kind of your M365 security boundary. So it's a super important point, and one where I think, we have a, we have a fairly meaningful differentiator for, for customers.
Everything just works. I think it's, it's fairly just pretty much as simple as that. And so thanks so much for, for being here, Richard.
It was, great to talk with you. Thanks, Leon. Yeah, it was a really full conversation, and I appreciate your time.
So what was really interesting to me is, is seeing how far Microsoft has come so quickly with agents. As, we see this as, you know, a whole new stack that's forming inside the organization. It was really fascinating to hear that, that, that, you're spending so much time, looking at, how do I make agents work across the business?
Uh, I think we've looked at a lot of, individual automation, in, in the past in low code, but I think it's that, it's understanding that Microsoft has that big picture view, and it's the breadth of the tooling. Um, it's the, the scope of, of understanding it's, you know, not just departmental. Of course it's departmental, but it's also, how do we make this enterprise-wide, and how do we elevate the thinking so that, we're preparing those inside of our organization, to, to take advantage of the big shift that's happening, going, you know, m- from building maybe those point low code applications to orchestrating across the business.
Um, and a lot of the pieces around m-making, you know, agents work together, providing that security and compliance, that assures that y-you can do all of this safely and not constantly sweating, "Am I going to go outside the security boundaries? " And knowing that all your agents can do that. It, it really is gratifying to see how far Microsoft has come in, in assembling this vision, and then offering it in, you know, it's-- n-no, no one can say this is mature, yet, but, you know, hearing about, how the, the stories, we see at your events about how far the customers are coming and already getting a lot of these things out there.
So, that was the takeaway I had, is just, you know, getting a sense that Microsoft is really trying to make sure that they're leading this, this agentic transformation. Hey everyone, welcome back here to Techstrong TV. Um, my next guest is Sumeet Va- Vaidya.
Sumeet is the CEO and one of the founders of Crafting, and, he's here to talk to us about their announcement around seed funding and launching their agent, or, or their platform for agents. Sumeet, welcome to Techstrong TV. It's great to have you on.
Thank you, Alan. It's great to be here. Well, it's exciting times for you, I'm sure, right?
Having started a couple of businesses myself in the... over the years, it's, you know, it's kind of like buying a boat. You know what they say about buying a boat, right?
The best two days are the day you buy it and the day you sell it. Um, starting a company is exhilarating, right? It, it, it, it almost you...
As the, as a founder you're, y-you give it sort of the mother's milk of what it needs to survive, right? You breathe life into it. And then, you know, we all want our companies to do well and, and well can be financially do well, you know, or in many different ways.
But, you know, it's part of, it's part of that life cycle, the circle of life, if you will. But Sumeet, give us an idea of what you've been doing up until, you know, founding Crafting and being involved in that. What, what's your career been like?
Sure. 0 to one of the juggernauts in the industry. Uh, later joined Uber, was managing a bunch of different teams over there, ranging from international growth to some of the micro mobility stuff.
Again, saw growing pains, scaling engineering organizations. And then most recently, before Crafting, I was an engineering director at Discord, working on a lot of things ranging from communities, developer platforms, and everything in between. Very cool.
Well, those are certainly some Silicon Valley blue blood names, right? Sumeet, over the years, I mean, in addition to founding a couple of companies, I've interviewed and done partnership deals with literally hundreds of, of founders. It's not something that you take on lightly.
It's something that you feel driven to do. Passion, even. What was the passion for you in, in founding Crafting?
Yeah. So, when I was considering my next steps after I was leaving Discord, one of the things that had been bothering me for a while was consistent challenges I've seen for engineers, specifically at enterprise organizations. There's certain challenges you run into when scaling, coordinating with a bunch of other teams, dealing with all these different dependencies and these complex architectures.
Uh, and I, I met my co-founder, Yi Xue. He actually was a tech lead at Google, VMware, been an industry veteran for a long time, and we've both seen the same challenges play out over and over and over again. And it was something that we both cared about, but nobody had really been solvingWe've seen friends build this at Airbnb, Uber, Google, and a bunch of other places, and we figured that it was time that somebody actually built a solution that worked generally for everyone and bring the best in class tooling you see at the best tech companies to everybody else.
I love it. Kinda like bringing the Amazon experience to everyone, right? That, that's what they used to say about AWS back in the day, right?
Yeah. Get that Amazon infrastructure. Yep.
Um, so talk to us about founding... So you, you, you said you want to bring this to everyone else. You want, you know, people out here w- I'm sure there's plenty of them who are thinking about starting their own companies, es- especially today with AI and job displacement.
" Um, talk to us about, you know, kind of what you and your co-founder went through in building Crafting. Yeah. So I think for us it was a bit different from what a lot of people are looking at today, where there's a hard problem around making infrastructure accessible and available to lots of teams that candidly a lot of people weren't trying to solve, and those who were, were doing it very specifically for a given company.
So we spent a lot of time really digging in to understand how do you provide best in class tooling that is cloud provider agnostic and now agent provider agnostic. And I think the flip for us was how do we solve the hard problem of infrastructure and then make it accessible for engineers and then agents? Whereas today I think a lot of people are starting from, "Hey, here's something we could do for agents.
Let's start with that," and then try and back into the infrastructure problems and unique challenges they're facing. So there's a lot of excitement that's here, but I think what makes things sustainable and a healthy business is figuring out what is the hard work you're doing that other people are unwilling to do or would be too hard for them, especially when AI tools make it so easy to, you know, get a website up and running pretty quickly. To say the least, right?
Um, so, well, you know, I didn't even ask you, when did, when did you guys start with Crafting? You know, I mean, officially it-- now it's seed funding now and launch, but like how long have you been working on this? So I've been working on it for almost a couple years now, and my co-founder, Yisui, was working on it for a year or two before that.
He was exploring different options, building out infrastructure, taking the knowledge that he had built at Google and VMware and trying to figure out how to make it universal. And when I first chatted with him, he was looking for a co-founder who he could work with, someone who was technical but also understands what these engineering organizations are dealing with. And within the first 10 seconds of him describing the problems he'd been tackling, I instantly saw this is the thing that has been frustrating me at every single company I've been at.
Um, I don't wanna name any names, but companies I've been at and companies friends have been working at, I've been trying to talk about the value of having really high quality developer tooling, especially for complex architectures. And a lot of companies don't... They don't get it because they don't know how much better things could be.
" You know, that's a pretty common fact pattern I've seen with founders is oftentimes the problem they're solving is a problem they themselves had, and then they come to the realization of, "We're not the only ones with this problem. " But, you know, it, it's interesting how the pendulum swings, Sumit, because if you go back to like, let's say, you know, peak COVID times, 2020 into 2021, hiring engineering talent was damn near impossible. The, the m- money you were paying for coders and, you know, technical folk, and it, it got beyond the money 'cause they could get paid as much money virt- I mean, you were paying coders 300, 400, $500,000.
But then they wanted to get some, you know, freedom, creative freedom, if you will, like we're all into Hollywood or something, and they wanted to have a say in picking the tools they use, because after all, they're the ones using the tools. They know what is quality and what's garbage. And, you know, I spoke to a lot of CIOs, CTOs, chief product officers, chief development officers, chief data officers, and, and at least back then, the feeling was, "Hey, I'm paying these guys a small fortune.
If, you know, if, if they're really that good, we should be using the tools they say to use," right? Because they're the ones on the front line, and they're the w- the high performers. And so of course we wanna give our high performers the best tools to, to make it happen.
But somewhere along the line we lost that, it seems, right? " You know what I mean? The, the, the, the leverage here has, has swung back to the upper management who then makes the choice on what tools you're gonna use, what platforms we'll use, and I get why, don't get me wrong.
I'm not, not here banging anyone for it. But we've certainly seen, I think, a reduced role for the engineer, for the coder, for the doer, the jobber, getting to pick their own tools. I might push back on that a little bit.
Go ahead. That's why I ask it. I don't- Yeah.
The last thing we want is violent agreement, right? Yeah. SoI think that the top-down direction is more about the overall vision and what they're trying to do.
So what we're seeing in a lot of companies right now is execs and founders and investors pushing for, "You must use these AI tools," right? I think that's the most obvious one that everyone's dealing with today. Yeah, yeah.
" I think at the end of the day, the engineers still have control over what tools they use, but the execs are the ones who are driving the outcomes that engineers need to deliver on. " But over the past couple years, everyone's saying, "Well, AI is fundamentally changing everything. You have to use it.
We should see efficiency gains. " And I think a lot of companies are, are chasing a vision that has been sold to them, but a lot of them haven't been able to realize it, to be honest. And I think we have something that addresses that, but there's a lot of tools out there that are making very lofty promises that haven't really been met.
Yeah. A-and that again, you know what, that's another mistake that like maybe first time entrepreneurs make, right? Is the, the overpromise, underdeliver.
Uh, you know, I'm not saying be humble or don't say, you know... don't, don't let anybody know the full extent of it. But the problem is, is when you overpromise something, you overhype it, I mean, you can fool some of the people some of the time, right?
But you can't fool them all the time. And then once, once they feel like you overpromised and underdelivered, it's hard to get a, a second chance, right? You only get one- Absolutely ...
first chance. Yeah. I, I think we- I agree ...
take this to heart, at Crafting right now too. So one of the things that we try to do is we believe we have a best in class solution. " But that's a pretty lofty sell, and one thing we try to do for every single one of our customers, we say, "Hey, join us.
Do a free pilot. Take a couple months. " And we help them understand, if you wanna remove us, it takes 10 seconds to rip our, our agent out, and you're good, and we don't have access to anything.
But if you do wanna test this out, see what's available on the market, and we've actually done heads-up pilots with a lot of other competitors, and things have gone well. Good. Let's talk a little bit more about Crafting, though.
Let's dive into it, right? So it, it's a platform, right? That allows AI agents to validate code against real production dependencies.
Sounds good, but translate that for our audience, Sumit. Yeah. So let's start with the original vision, right?
So for, for Crafting, originally we built it for engineers. You have a lot of engineers who are trying to build things in complex organizations. Uh, this meant that they needed ways to actually test things against real data, against real services.
And so the first version of Crafting provided that for engineers. We powered the end-to-end experience for coding, iterating, getting feedback, sharing and collaborating with stakeholders, and then validating things before they went live. Agents need the same things, and so today you see a lot of people talk about these agent sandboxes.
But they just kind of enclose these agents in a safe little space, but the agents can't actually do anything. And the second challenge is that agents are producing so much code today, and a lot of the biggest companies today are dealing with this backlog, this bottleneck of all this code that's been generated, but they have no idea of how to say, "Okay, it's good. " And so with Crafting for Agents, we tried to take that infrastructure we made available for engineers and make it available for agents, where now you can have an agent actually validate changes from AI-generated code against real third-party services, your internal tech stack, and basically spin up just in time whatever part of your tech stack you need to actually run and validate instead of relying on some, you know, local scripts or tests.
Um, there's a broader vision for this around agent capabilities that we can kind of get into, but that's more of the midterm thinking. I love it. Um, I, I mentioned you guys announced seed funding, but we never really gave details.
You know, and, and look, our audience is not the finance audience. We know that, but still give them an idea what, you know, about funding and because it gives legitimacy, right? If people are willing to write checks, as they say.
For sure. Um, so we raised our seed round. We've got investment led by Mischief and Wonderco, both of which are really solid funds and have been great partners for us.
We also have a lot of angel investors on our cap table, including, you know, the founder of Dagster, the founding CTO of Dropbox, former VPs of engineering from Airbnb. So really, it's people who understand the technical challenges these organizations are facing, especially as we go through this evolution with AI agents kind of taking over. Yeah.
Yeah. So look, I, I... there's not a doubt in my mind of AI agents taking over at this point.
We, we're living it here every day, and we're hardly cutting edge, though we do cover the cutting edge. Um, what do you see? I mean, sometimes, you know, you-- one could breathe their own exhaust fumes.
You know what I mean? Yeah. Read their own press releases and reviews.
But, you know, as you sit back and you see sort of the rise of agentic kind of, you know, cascading through the, the system, what do you, what do you see? So we've actually seen this with a lot of our partners, where they went from single-digit percentages of their code were written by AI to upwards of 70% over the past yearThere's been a dramatic acceleration and increase of adoption of these AI tools. Um, we're seeing a lot more code being generated, and companies we're talking to that we haven't partnered with yet are running into this problem of they don't know how to deal with this bottleneck that I was mentioning earlier.
Um, companies we partner with have actually been able to deal with that bottleneck a bit, so they're seeing pretty good increases in throughput. So I think, one thing we're consistently seeing is 25% increases in shipping PRs after a single quarter. So the acceleration is there.
The adoption is there. Um, there is this question of what does it mean for engineers and how they play nicely with agents and how agents play nicely with engineers and what collaboration looks like. Um, but yeah, the adoption is definitely real across the industry.
So Sumeet, I don't know if you're familiar with the book "The Goal" by Goldratt. Sis... So "The Goal" was, like, required reading in MBA classes in the '90s, even maybe the '80s.
Actually, Gene Kim's "The Phoenix Project" is actually based on "The Goal," but "The Goal" introduced what they call the theory of constraints, right? Which is-- And, and it was more in a manufacturing context than, let's say, software context. But, but, but parallels are the same, is that, you know, you run into a bottleneck and you overcome that bottleneck, and then what, what you didn't see over the horizon is the next bottleneck, the next constraint, and the constraint after that.
And a lot of-- And I'm-- You know, I see us running into that, n- and by us I mean as an industry, as a market, is that, you know, all of a sudden, not only are we having 60%, 70% of our code being generated by, by agent or by AI, but the sheer volume of code is through the roof, right? It's two X, three X, four X the amount of code we were generating. So it's, it's majority generated by AI, but a lot more of it, and that, that moves the-- that moves us to the next bottleneck.
The bottleneck is no longer generating code. The bottleneck is the governance of it. The bottleneck is the testing of it.
The bottleneck is the deploying and monitoring and observing it, right? These are all bottlenecks over the next couple horizons, right? Now, it sounds like Crafting is a bottleneck remover, right, at some level, right?
You're, you're-- So as you look over the horizon, what, what other bottlenecks do you see Crafting kind of tackling, if you will? Yeah. A- and to build on your point really quickly before I answer that, I think the bottlenecks we tend to not see as an industry are generally ones of scale and maturity, right?
Yeah. It's easy for us to figure out what are the challenges we're facing as an individual developer, right? Like, OpenClau has been great.
Let me get this agent up and running. Am I using a sandbox or a Mac Mini? Um, but things fundamentally change when you have dozens, hundreds, thousands of agents running simultaneously, when you're dealing with payment processing, when you're dealing with PII.
So the way we're looking at it is what would the most sophisticated companies or the ones with the most complex needs end up facing in the next couple years? So to your question about removing those bottlenecks, right? Uh, the first one is validation, which is the main use case that we're actually working with our partners on.
So we've got, you know, Brex, Faire, Instabase, Verkada, Persona, and like other large companies that have very serious data they're processing, really interested in what we're building, and we're partnering with them to actually ship our validation for them. And so the first step is remove this bottleneck by making it so that AI-generated code can be validated efficiently at scale using these AI tools, using real infrastructure. But what's next, to your question.
" So then the next step is how can agents be a bit more proactive? " They'll message you in Slack and say, "You should look into this. You might want to investigate this.
" The next step is actually this agent saying, "Hey, I saw this issue in production. I generated this PR. I tested it against shadow production traffic.
" So it starts acting more like a teammate, and you can imagine that as you have these capabilities added for either access to infrastructure or access to internal data or third-party providers, they can do so much more, and that's when they start actively acting like teammates. Agreed. Very cool.
Sumeet, we're almost out of time. You know, we mentioned Crafting a number of times, but we-- I don't think we mentioned the website. Yes.
dev and reach out to us from there too. That's C-R-A-F-T-I-N-G dot dev. That's correct.
Very cool. Sumeet, look, it's heady times, you know? And, and, I wish you guys nothing but success.
Come back, keep us posted. It's in, you know, so much exciting stuff going on, and it seems like you're right in the middle of it, so- Yes ... it should be a great ride.
Appreciate it, Alan. Thank you so much for having me on. My pleasure.
We're gonna take a break here on Techstrong TV. dev, right? That's right.
Check it out. We'll be right back. Hey, guys.
Thanks for the throw. net. Mm, and we're having a little chat about, well, is there gonna be enough IT infrastructure to go around because, well, the big tech companies seem to be, well, buying it all up.
Jack, welcome to the show. Thank you, Mike. Good to have...
Good to be here. Thanks for having me. I think we've seen the spend now on AI infrastructure is somewhere north of $650 billion or so, or will be.
Um, and the question then becomes: is there gonna be enough infrastructure for everybody else? Because it seems like everybody who builds those foundational models is gonna buy up a massive amount of it, but it's not clear to me that there's enough capacity in all these data centers, and we're making some major investments in that area, but they might not come along for another three to five years. So what's your assessment on what we're gonna see?
Yeah. It's a, it's a huge problem in AI. And actually to me, it all boils down to access and, like, true innovation with, with the people.
It's... What we're seeing at the minute is the, the three main providers, cloud providers account for 70, 80% of all global compute. And what that means is, you know, it's a, it's a little, uh...
like a special club at the top there. Big companies work with those hyperscalers. They, like you said, block up a load of compute, load of machines.
Um, and what we actually see is that most of global compute isn't actually utilized because of that exact reason. Uh, 10 to 15% of, global compute power is actually utilized at any one moment in time. So what we see is that 85%, say, redundancy within the whole global compute network.
And the people that lose out are the developers, the startups, the people that are trying to innovate, get access to this space. And so what it creates is, like, an inequality for, for people to get going. And, obviously the, the, the main hyperscalers have little interest in letting the little person, innovate.
They want to get the run on everyone. They want to build these big, huge mod... like, you know, huge organizations and dominate the AI, AI landscape.
net where I, where I, where I work, is we're trying to think about how we can solve that utilization problem and access problem in, in novel ways. So what we see is that, you know, we, we want to be able to utilize that 85%, you know, the, the data centers that the hyperscalers haven't dominated, like, and give access to people, in a fair and, and, uh... in a fair and cheap and accessible way so that they can innovate.
And so at IO, we essentially work with all of the, the data centers that aren't the top three. We aggregate their supply in a common place, on our, on our network, and we serve that back to end consumers. And so, you know, whether...
even if someone's blocked a, a, a, a, you know, a, a data center for... or blocking a data center for 12 months, and they only need it for, you know, a, a day a month or something, they can offer up the rest of that, capacity to people and monetize that. So yeah, we're trying to, instead of mining a lot of new resources, building a lot more data centers, et cetera, which I think inevitably we'll have to do, but we actually want to solve this problem in a different way and actually get that utilization up closer to 100 so that we're getting more out of the stuff we're extracting and being able to a- give it back to startups and innovators to be able to, you know, get, get access to this space.
Because, because if we don't do that, then AI will be controlled by a very few, organizations, and it will be, at the end of the day, the people that lose out. Do you think that the shortage of infrastructure resources will drive people to shop around more? I think there's a bit of a default mindset where people are like, "Well, I'm going with AWS, Google, or Microsoft," and maybe they'll start to consider other options.
Yeah. Absolutely. I mean, I don't know if, if you've, if you've tried to get Compute from those guys, but it, it is actually a bit of a nightmare.
It's... You know, you're often on wait lists for the best type of devices. I mean, just look at what happened when the H200s came out.
It was, you know, all of the main, the big tech companies got the first access, got the run on everybody with the latest, and then it's like, yeah, we'll serve the remainder to some companies at some crazy price, you know? So you're on a wait list. You're paying loads for the access to it.
Um, you're also putting all of your data through one location, which is a, which is an issue, you know? If that... If...
We've, we've seen AWS go down. We've seen GCP go down. Um, and so, you know, if you don't have...
I think people are now looking for ways where they can protect themselves against that. And so companies like IONET, we're, we're trying to solve this in more novel ways, you know? Like, you don't need to book yourself a six-month block in a data center anymore.
You can literally spin up a cluster in, you know, in a sec- in a, in a minute or two and provision it for as long as you need to do that job. And so what that means is you're able to be more cost-effective. It's more flexible.
You can spread your risk out. You can spread your compute out over many different locations, many different devices. If something does happen to go down, it's not like your service goes down.
It moves to another, you know, location. You can move your compute to another location. And so it's that flexibility and, and, and that access that I think really turns people to other providers because, you know, i- if...
the more the hyperscalers try and control access, the more people will, will look out there for more novel solutions. And so, you know, that's... again, that's what we're, we're trying to do with IONET.
I think some organizations may be falling into what y- s- I might call the volume licensing trap, where they think they're getting a good deal from AWS or wherever, and they might be, but then that requires them to consume compute resources from them, and they force that down on everybody else in the organization. And-Then when those resources aren't available, everybody kinda like sits on their hands and winds up doing not as much as they could. So do you think that, there's a different way to think about licensing compute resources in the cloud these days?
I mean, I know we have spot prices and reserves and all these other things, but a lot of folks I talk to find it hard to manage all that stuff. So what's the smart way to go about doing all this? Yeah, it's a good question.
I think people were stuck in the way that tech used to work. You know, you used to have to like buy software for six to 12 months in, in time. You used to have to provision the tech stack for that, because you needed reliability and you needed that security that all of your tech would work.
And it's the same, I think people just rinse and repeat that when it comes to compute. It's like, right, I need to... You know, especially when they read all these articles out there about there being a compute shortage, and, you know, prices going through the roof if they don't lock them in, and 'cause energy prices are going up and all this.
And actually, I think what, what generally will happen if, if medium, large i- businesses fall into that trap is, especially in this, the AI space where d- you know, the inference costs cost so much for those organ- for that organization, they'll start to lose the competitive advantage because startups, like we've seen lots of startups come to, to solutions like IO, they're saving 70, 80, 90% on their compute costs because they're thinking novelly about the s- about the problem, right? " And so they're, you know, provisioning through IO Net, for example, would provision devices for a day, two days, spin it down, spin it back up again. You know, so they can actually use on-demand what they require.
Um, and I think that gives... That saves them money, it saves them time, it, it means that they can get the devices they require for the job at hand. You know, not everybody needs H200s all the time, you know?
So maybe they need more consumer grade, or maybe they just need, you know, not the latest chipset to train their model or whatever it is. And so those companies, I think, will have the time and cash advantage over some of these larger organizations, and, and that means that they'll be able to get the run on, on businesses that still think about the problem in a, in a traditional way. Do you think a lot of organizations are also defaulting to GPUs and not considering other processor classes that have emerged lately, or are they starting to find those and use them?
Um, I mean, on IO we, we s- we stick to GPUs at the minute. We do... Especially when new devices come out, they're very difficult to...
You know, there's always the cutting edge of that, that are often provisioned by just the large scale organizations, you know? The... There's...
It's a little club at that sort of level, you know? Chip- the latest chips created by Nvidia are sold to the companies that Nvidia have a vested interest in, and it's all one big sort of web. Um, but eventually they become available, and, and, you know, it, it's often just a few months, and then they, they'll be p- they'll be bought up by the other, the other hi- the other data centers and then served up on, on IO.
I mean, very few... I'd say the ma- large majority of organizations don't require the latest tech all the time. They don't need to be on the edge when it comes to processing.
You know, what they need is good, reliable inference, often with open- open source models or models that they've trained themselves, and they need it to be served up to consumers in a fast and reliable way, and that problem has been solved for today, you know? And so unless you're sort of at the frontier and the pi- like pioneers of what a model can actually, can do or process, I, I don't think... I think, you know, saving a tiny amount on speed in the grand scheme of things is, is not really that interesting to you.
Are people also starting to revisit their data strategies in the era of the cloud and AI, and are they rethinking some of the services that they might use over there? We live in a world, or lived in a world, where all, like all of our data was ring-fenced and secured, and, you know, v- we're very protective over it. And with what we, what we've been seeing is, like people have become a bit more fast, not necessarily through, through our, our protocol, just as a global trend, that people have become a bit more fast and loose with a lot of their data.
I mean, people are very happy to plug Copilot or Claude or OpenAI into their organization and don't fully understand the consequences of what that actually means. You know, when you're getting Claude Code to find a bug in your code, you're essentially giving all your code to Claude. And, and, you know, there may be agreements in place from, you know, that, that, that these organizations, you know, won't necessarily actively read your data, but you're training their models, you're training their infrastructure, you're training all of their systems.
And so I think it's a real risk. I think what people need to, to... And, and we're seeing definitely a trend on this, is people are starting to realize that that is a r- a risk for th- them and their organization, and they're starting to reali- starting to figure out, "How can we actually build this type of technology in-house?
How can we bring... Instead of leveraging these super models that, you know, the big three have created, why don't we use some of those open source models? Why don't we train our own models?
Why don't we self-host them? net is really important because we have all of that. It's secure.
You know that you can spread your compute out over many different devices. You can host whatever models you want on those devices. You're not training other people's systems when you're using those models.
And so I think then people are coming back to the secur- like they're starting to realize that, you know, their IP and their cons- customer data and all of that, they need to try and protect it and ring-fence it again. net as well. It's very much a privacy first, a privacy first infrastructure.
Are you also seeing something that feels like maybe sticker shock when I start to use some of these services in the cloud where I'm consuming a boatload of tokens all of a sudden, and then I get a bill and I'm like, "Holy crap, I didn't think it was gonna cost that much"? Yep. Yeah, I mean, I, I remember playing with Claude Code, back in the day, and, just left, left an agent do a bit of research for a little too long, and, you know, you look at the bill and you're just like, "Oh, damn.
" Um, yes, and I think again, that's where, you know, at IO we have, we have the cloud platform, but we're also trying to develop other solutions which, give people more protection, like, who-- people who don't really know much about token usage or, like, they're just getting into AI. Like, we're trying to create tools and services that, bring them in. So we have our IO Intelligence, our IO Intelligence product, which is our inference product.
We self-host all of the open source models, the ba- main open source models out there. Um, you pay a subscription and you get a certain amount of tokens each, you know, hour, day, et cetera. Um, and then people can implement those models into their product or service using our API.
Um, and what that does is it just gets people, you know, used to playing with the models, exploring. You know, if they hit their daily caps, they can see why tokens were being consumed and, and they can then play around with, web... You know, their prompts can play around with their, the training loads, et cetera.
Um, and so it gives people-- it teaches people more about how to use AI more responsibly. Because at the end of the day, if you're using a pure API, say, on Claude, there is no cap. The cap is how much money you have.
Um, and so one wrong training run can cost you a lot of money. Um, and so what we need to try and do is give people safe environments to be able to test in to understand how all of this works, so that they can, you know, get it right first time or get it more right first time so that they can save on cost and some can ultimately save on energy at the end of the day. So what's the one thing you see organizations doing that just makes you shake your head a little bit and go, "Folks, maybe we wanna be a little bit smarter than that"?
So I find that people implement AI in their organizations in a patchy way, right? It's kind of like a legacy organization. They're using s-spreadsheets or whatever it is.
" Um, and what then happens is it spreads horizontally. People do that, that same thing. They just rely on a single agent to do that type of stuff, and nobody's thinking about the power of AI holistically within an organization.
Like, how do we implement this in a way that's data secure? How do we implement it in a way that isn't feeding these massive models and, you know, leaking our data to these big organizations? How do we do it in a way that's most cost effective?
How do we do it in a way that's sharing context of the business and each department and each use of AI with each other? You know, and the learnings within AI being captured. Like, that's definitely the next theme that we're gonna see in AI, and we're already seeing it sort of now, is context.
Context building, context management, like being able to, to be able to effectively create a memory for an-- for the organization and for it to self-evolve. Um, and so really, it kind of needs s- like, conscious AI strategy within an organization to really think about all those things, think about, you know, how we implement this and the infrastructure also to provide to it, you know? I think, like the stuff we've talked about, a lot of people are worried about rising costs.
They are worried about data security. They are worried about reliability. And so yeah, it needs...
It just needs a conscious effort from an organization, I think, to put all those pieces together and almost marry that bottom-up AI discovery with, like, a top-down AI, well, you know, or emergent AI strategy within, within an organization. So do you think that this all is conspiring to limit the pace of innovation? Because ultimately, organizations are gonna have to maybe pick a smaller number of projects that they can either, A, afford or, B, find the infrastructure for.
Um, I think ultimately the big issues in AI will continue to get bigger and surface, and surface their heads in weird and wonderful ways. I genuinely think that, there will be data breaches in the large organizations. There will be big shocks.
You know, people's data will show up in a place where they didn't expect it to. There'll be big outages. There'll be...
Like, the reliability problem will become more prevalent. And so, you know, I actually think that people will become more curious in it. I don't think there'll be-- I think, I think the days of, like, homogenous AI where everybody's just using one particular model or one particular data, like, data pr- center provider, I, I genuinely think those days will fade out, and people will want a more distributed version of that.
People will be using lots of different types of models for lots of different use cases. Uh, people will... Like, AI g- like, to use AI the most effectively, you have to be curious, you have to be, creative, and I think people will start to break away from the, the big companies unless they learn to adapt and offer, offer people a fairer and more flexible and cheaper way to get involved.
Um, we always see it, like I always say, like, open source always wins. You know, I, I genuinely think that in the long run. Um, and I think that's the same with models, and I think in terms of infrastructure, you know, these models will become more effective.
They will become easier to run, and with, with novel solutions like IO, people will be able to, to get the infrastructure they need at a fraction of the cost. Um, and so yeah, I genuinely see it becoming more of a mosaic of infrastructure as opposed to, you know, you can pick from these two or three providers. All right.
Well, folks, you heard it here, the AI ride, well, it's already been bumpy, but it might get bumpier still, so buckle up. Hey, Jack, thanks for being on the show. Oh, no.
Cheers, Mike. Appreciate it. Thanks for having me.
All right, and back to you guys in the studio. Welcome to Reality Check. I'm Dave Nicholson, and this is a program where we dig into subjects related to the deployment of information technologies, yes, AI, which is all of the rage this decade.
Uh, we talk about how real people are making real decisions about how to deploy these things and what the ramifications are. Uh, often we're talking to business leaders, and often those business leaders are making decisions with, with real money and real reputation points on the line about how to deploy these things. Um, this conversation is frankly gonna be more interesting and more impactful because we're not talking about maximizing for profit necessarily.
We're talking about maximizing for outcomes, specifically, human outcomes in the field of medicine. And I am very, very delighted to have, Dr. Julien Sanon.
Uh, Julien Sanon. Dr. Sanon, thanks for being here with us.
Thank you, Dave. Thanks for that invitation. Um, it's a real pleasure to be here.
Yeah. So we're gonna talk about, you know, sort of the, the intersection of AI and, and medicine. And, Dr.
Sanon has, has done a fair amount of study of this subject, and he lives his life at the front line of medicine. Um, Julien, can you share with us a little bit of your background in terms of the specialties that you're, that you're involved with? Well, I am a internist, basically.
I work mostly as a hospitalist and as a nephrologist. I'm trained in both of them, so if I'm not working as a nephrologist, I'm working as an internist. I have a license in nutrition, a master in public health nutrition.
Um, I am involved a lot in cardiovascular kidney metabolic syndrome. This is a new field in medicine. It's basically not new, but the American Heart Association came out with that, guideline, that framework, in a sense that most of our patient that we have who have heart disease, kidney disease, and metabolic disease will end up having, cardiovascular disease from heart attack, stroke, peripheral artery disease, heart failure.
And I have been involved also in digital technology, mostly AI. So I, I've had some training over, in healthcare transformation with, Harvard in terms of, how do we use technology, how do we use AI. And, so I'm, I'm very much involved in that.
And as you know, I, I, I met you, and I learned a lot from you, extending my, my realm outside of, medicine to go into business and see exactly how the business sector, how we can use, what we can use better yet from the business sector and medicine. So that's how I got, I got here. Yeah, very interesting.
So fair to say that, what you describe is, yes, I'm sure you're dealing with acute disease, but often this is a, this is a long-term, chronic situation that people are dealing with. Um, I have personally, had the joy of experiencing kidney stones. Joy obviously is not, is, is not the right way to describe it.
But, but, but, but, but all of the things that we can do from, moving our bodies to pro-- you know, proper diet, proper sleep, all of those things, it's, it's a fascinating field. And I'm wondering just on that front, just to start, where do you see physicians being enhanced by using AI technology? Uh, what would you say the current state of the, state of the state is for physicians actually using any kinds of AI tools in practice?
What are you seeing right now? Very enthusiastic, and I think, from a year or two years ago, I've been involved in that field, more so AI in, in healthcare about two years. It's, it's a huge difference.
I think it's about eighty percent of the physicians now, into it, whereas before it wasn't the case. Everybody was reluctant and worry about that AI will come and take their job and how i-i... that there was so many different, misconception about it.
I can see that, physicians, and when I say physicians, I also will also include outside of that, nurse practitioners and, physician assistant. We all basically part of the same group. So we are embracing it a little bit more.
There's still reluctance, and people are worried that first, that it'll take their job first. Uh, the second thing is that it will not be accurate. So it's, it, it is, we are embracing it.
I think it's, um-- And there's the idea also that will it come and replace us, that I think we've come to understand it's not gonna replace us. It's gonna augment our job. It's gonna make our, our job better.
And we can see that. We've been seeing that. And other point also is that there are some pain point that you get exhausted, tired of using, administrative work that should be done by other people, and it's being done.
So you get AI being able to do that for you. So it, it's very exciting. It's a very exciting time in medicine.
I've talked to quite a f- a lot of my friends who are in the field. They are very excited about it. I've taught them, or at least like I've showed them what I've been using, and they've been very excited about it.
So once people get beyond the concern that it will be, an impediment or, or seeking to replace them or, or not up to the task, you know, inaccurate, especially when you're ultimately taking responsibility for the decisions that you make, and again, and, and I say physician, but yes, absolutely the entire teamUh, I must say that one of the most meaningful moments for me during my little kidney stone adventure was the nurse that held my hand as I was put under general anesthesia. Uh, I will remember that as long as I live. Uh, I was asleep for the part that the real technician performed.
So, so yes, it's a, it's an entire team. Um, but once, once, once doctors and, you know, healthcare practitioners have gotten past the concerns, y- if we look into the future, is there a concern that maybe this will cause the diagnostic muscle to atrophy? Uh, will, will people become over-reliant on these tools, in a way that lessens their-- that sort of dulls their intuition that might be important?
Uh, any thoughts about that, or are we ways away from worrying about that? We are worrying about it. We definitely have to worry about it.
Uh, we have to look at the future and see exactly, even our trainees, people that we are training right now who are in medical school and residency, how do they learn? I think we are making some progress. Some big, hospital, big centers have been working on that.
I know, for a fact because I partly trained at Mount Sinai in New York, and they have a program where the residents are already using that. So i-it, and, and the medical school, so it's basically available for everyone. I know at other places also what I've taught and basically course-- that I've heard from my Harvard course is that, a lot of times now we've come to understand that we don't really have, in terms of knowledge, we don't really have that knowledge, that we don't really possess that, so we have the resident understand they're coming with information, so they have most of those big medical school and big hospital have arranged a way for people, things that the, the clinicians, everyone to be able to use it.
So it, we're gonna be using it. It, and it's not there that it's gonna replace us. It's not there that, we can, we cannot go back.
We, we basically, it's a whole different way, of... It's transforming medicine, and we have to adapt. Ultimately, people will have to upscale.
There will be changes in their job, but it is, it is here. Do you think that it'll change the profile of, what constitutes an effective practitioner or an effective physician in the future? And m- I'm asking this from the perspective that, my roommate in college, who I would say is my best friend from college, he's, he's an, he's an emergency room doctor.
And he explained something to me that I thought was really interesting, this dynamic, associated with alternative medicine. And I'm not ta... And, and I'm talking about truly fringe, let's say illegitimate things, but people will be, will gravitate towards them.
" Whereas the eleven and a half minutes that you might get with your primary care physician, des- despite all of their education and j- despite all of their skills and, and their technical capability, a person leaves that experience feeling like they didn't get as much out of it. I'm wondering if, if augmenting students coming into medical school is going to allow for m- on average, better bedside manner in the cohort of physicians. And I don't mean that disrespectfully, but I think all of us have experienced the brilliant clinician, the brilliant technician, that's the person...
So when I was asleep, I don't care if the person doing the procedure on me is capable of having a conversation with another human being. I don't care. I wanna know that they do what they do effectively.
But do you think that these tools are going to change the nature of people who will go into medicine over time? It definitely should. It, it will.
And it's changing already. I'll say exactly from my own perspective when seeing patients, there's, I'm not gonna drop names, but I'll give you in general, we call ambient AI. There's a number of different tools that we have out there that I can go in there and basically be able to talk to my patient and, look at them in the eyes and not have to deal with the computer.
It's basically recording everything that I'm doing. And I can talk to the patient and really have that conversation that we long did not have. So we can train the resident, we can train the people now to kind of really do that and, and focus on the patient.
And patient are liking it a lot because, you don't have to be on the computer, and then I'm able to explain to them more what my plan is, and seeing them. I don't have to go to, back to the computer and see exactly what is my plan for the patient. " So this is what AI will not be able to replace.
It's, it's basically my co-pilot. It's my companion. It doesn't replace that trust element that I have to bring to the patient.
It doesn't replace that context that I have to bring to the patient. It doesn't replace that sympathy when I see the patient. So this is, it's gonna be, I think medical school will be taught differently.
Uh, resident will be learning differently. Uh, having, it's just like having your car basically and know what to do with it, how much can you do with it, how much can you rely on it. So that will be the idea.
But this is exactly, this is how I think medical school it is. That's how we're gonna be able to use it. As you said, having someone holding your hand, that part, that component, you can't replace that with AI.
So- No ... augmenting, yes, it is. And a-as I said, basically, it's, it's a new way of learning.
As you said, even going back to learning in medical school, not having your brain atrophied, you have to, you have to do both of themAnd it, it's just a higher level of cognition. You're using your cognitive facilities at a much higher level. You'll be able to do that and not have to really have the, all the clicks that you're doing on the computer to see your patient and things that are administrative that are basically not necessarily, providing you with the best skill set that you could use at that point for the patient.
So I think it, you have it as a mix, as a mixed baggage. Um, things that will not be replaced, as you said, the trust, someone coming to you and talking to you, someone as you see exactly in the emergency room that come, as your friend will say that, will come to you when they having, their kid is sick. AI can't really translate that.
It can really help me with the information, but that part, it cannot be translated. And there's also the aspect of context, and that's also a new way of teaching medicine. We do take that into context what we're saying to a patient, but with AI even more, because if I don't really give the right context to AI, it will give me the wrong information.
It could even be dangerous. So it, it's a new way of teaching, new way of learning. It's, it's a different way.
It is exciting from my perspective because there are things that we get to do that we don't have to worry about. That is, I'll give you a very simple example that we use AI a lot of times now for, discharge summary or, hospital course. You could have a patient who's been in the hospital for 20, 30 days, and then you're coming and you don't have time to read all those 30 pages.
But if you get AI, and we have that at our disposal right now, if you get AI to do that for you, then you can have... You can function at a higher level of cognition where you could think much more about what's coming out of that, what did I get from that, or the discharge summary that you'll have for your patient. So all of those are out there and they are very, very useful, to say the least.
So it's interesting because a lot of the discussion around AI, e-expresses concerns about how humanity will fare in this equation. And it sounds like at least in the, kind of practitioner-patient relationship, area, we have an opportunity to introduce more opportunity for empathy as we get that sort of note-taking responsibility out of the way. Uh, and maybe a lot of the negative bedside manner, criticisms have been levied a bit unfairly because the, because you're thinking that, that your doctor has, i-i-it needs to be there and be present and listen, which they do.
But you have to remember that they also have to meticulously pay attention and, and record everything that's happening. So on the, on that front, that sounds, that sounds like AI is going to enhance humanity. Now, in any sort of clinical setting, you have the people who are on the front lines with patients, and then of course you have an administration.
So, do you have any insights into what, say, hospital administrators are thinking when they think of AI? Um, I know that they have, you know, they have a, a resource allocation mandate, however you wanna look at that. Uh, you know, whether there are shareholders or it's a, or it's a not, a not-for-profit entity maximizing for service delivery.
They, they are looking at efficiency being enhanced by AI. Are you seeing any conflicts in that space? Yes, there is some conflict.
Uh, but at the same time also, in the best places, you have the administrators working with the frontline workers to make it work. Uh, it start with working on some pain point for the, practitioner. And I think administrators are recognizing that at the very least, if they can remove some of those pain point, as I said, charting and, seeing patients and then having to go home and having to write those chart are more steady.
Exactly. With the new ambient AI, most physicians are very happy. And administrators are very on that.
Although they might say that, you know, you might need to see more patients, that's probably not being said- That's, I was, that's what I was I'm sorry, I was waiting, I was waiting to jump in and ask you that because I can imagine a situation where you've just described this wonderful world of better patient interaction, and I, the administrator, say, "That's great, Dr. Sanon. " And, and now we're back to where we were before.
Um- Yeah, that's- Who, who, who, who pushes back on that? I mean, is it, is that incumbent upon patients to demand more? Um, h-how does that feedback get up to the administrators who are ultimately sometimes making decisions about this?
Well, it has to be, there has to be some champions, I would say. There has to be some people that both side can trust that can bring that information back and forth, that can really close the loop in there, because, administrators will tell you that, you know, we're operating at a very close margin, and we have to push the boundaries. And AI is one of those where they could probably get some of it.
Although I'll say that there's some hype to that because sometimes you invest and you expect some outcome from the investment in AI or the technology, it doesn't really come out that way. But yes, usually, hopefully you will have some clinicians, some, physicians, or anyone in healthcare that is not administrator or direct, who has some, I'll say exactly, patient care also who can convey that. And that has to come from someone who's trusted on both sides, by the administrators and also by the clinicians.
So that's, that's the balance that has to be made because, yes, we're getting more out of AI in terms of the workflow. You're organizing the workflow better. Um, scheduling is better.
Um, you could even have, again, this is, very dangerous, like with the chat box, having the patient getting informationDirectly from the chat box. That's coming. So that's also dangerous, but again, like it kind of re-relieves some pain point for the physician, for the whole hea-whole health system, and, also help from what I learned from, Wharton classes, the, the healthcare journey, that the patient basic- that they can navigate it better.
So that also helps. That helps the administration, that helps the hospital or the healthcare system to attract more patients because they know that they can trust that. Trust is one that AI cannot replace.
Context is one that AI cannot replace. And sympathy, empathy, AI cannot replace that. Yeah.
Okay. So now we have, let's say we have a perfect synergistic, relationship between administrators and frontline practitioners, and, and AI is helping that, and it's all wonderful. What about continuing education, let's say n- in nephrology?
So, things related to, kidneys. That's my, my lay person's understanding, although I have some experience direct. Uh, but, but so, so what about, keeping up with, developments in therapies that may be an outgrowth from using AI technology in, in biotech or pharma?
Uh, as a, as sort of a casual observer, I read stories constantly, as everyone else does, about things like the guy and his dog. Uh, he, if, if you're familiar with this story, I think he's in Australia, his dog had a tumor, pretty bad situation. He sequenced the, DNA from the tumor.
He sequenced the DNA from healthy blood, AlphaFold, which I, I know what it is, but I don't know what it exactly does. Um, somehow they were able to then compare the two, again, in my lay terms, I will say. It's like, "Here's the healthy stuff.
Here's the unhealthy stuff. What's the difference? " And in this case, it was an mRNA therapy, and, they got the approval, and they injected the tumor and, and, and the tumor reduced, like, by fifty percent within a short period of time, and now they're going back after the parts of the tumor that, that, that did not respond well.
And so we hear about these cutting-edge things that could be years away from actually being part of a clinical setting that you're in today. Do you have to kind of ignore that background noise at this point, or is there sort of a mandate that you keep at least an ear open for these things as they're coming down the line? How does that affect your frontline, engagements?
No, very important. I mean, you have to keep an open e- ear. You have to really be listening.
You have to be out there and know exactly what's out there. " Like, yeah, I think you, you, your analogy was basically having the land, the big land, and you, you giving me that land and how do I really use that? If you have a tractor, that's one way.
If you have to do it by yourself, that's a different. So the same, you have to be able to follow that and see, because some of it at some point, you have to... And, and it, that's what AI is also helping from that, pharmaceutical company and bio.
It, it, it accelerates a number of things, basically. So it, it's extremely important that we follow it. Um, it may not be ready for frontline yet.
It may not be ready for primetime, but you have to be ready. You have to be open-minded. It's the same thing with AI.
If, I'll say exactly, a few years ago, most physicians were like, "Nope, I don't wanna hear about it. " But right now, many of them are basically have an open ear and then want to hear about it more. So the same thing with that, that experiment also.
Um, some of them I can say exactly, some of them it will take a long time before they materialize. It's not really, there's a lot of hype. There could be a lot of hype going on from there, but I have to be ready and, and, and we from the medical field have to be ready and be able, willing to embrace that new technology and, and what AI can bring with that also, because there's a lot of potential, basically.
From, as you mentioned, from the research perspective, from being able to accelerate a number of, discoveries, medications, a number of this, it, it's tremendous what we can get from it. It's just like at the same time, we have to be able to separate, the hype from what's real at that point. Yeah.
There might be a lot of potential, but the potential that it is, that we're seeing may not be there yet. Yeah. But we, we are looking for it.
Yeah. And speaking of AI, I just consi-- because, in, in anticipation of our conversation, I think I'm clever. I put my notes together on what I think would be interesting to discuss.
And, and I go to my chat assistant and say, "What else? " So con-consulting my notes on, on, on things, you know, what, what about... Because you have this, you have a background, that includes, nutrition.
Yes. Um, yes. And- I'm a licensed nutritionist.
Yeah. Yeah. And so on either that subject or any other, are you, is there anything that you've seen recently that particularly gets you excited about either, novel s- studies, therapies, tools that are coming out of the technology space that might improve our lives?
Anything that gets you particularly excited? There's so much excitement, in a sense that, and that's using AI and using all those technologies, being able to see exactly in terms of designing your meal plan. I'm talking about just from nutrition perspective.
From nephrology, Mayo Clinic, there's someone over there, Wessy, I have to give it to him. He's really, really good atDoing AI and nephrology. So we're using it a lot even, like, for predicting exactly who, which patient's gonna be really being overloaded and how we use that.
Uh, there's so much more that we can do. Um, there was something as I was talking to my friend, I have to tell you about that also that was, I thought that was amazing. Um, let's say here we are, we're wearing our clothes, and we paying, and that's what we've been doing.
But what if we get a lot of information from the clothes that we're wearing, from the watch? I mean, we already have the watch and how much we can get from it, from the tattoo that people are-- So there's a lot that you can learn for personal, growth of, of patients. So that will be much, much healthier, be it from, from the hospital perspective, exactly learning about the patient, what works, what would be the best therapy for that patient.
'Cause I could have it, coming from a number of different people, but again, if I can find the right treatment for that right patient, there's nothing better than that. So there's a lot that from that positive. Uh, there's something else I'm also being involved in, in is medication reconciliation.
How can I use AI? Because a lot of times you have your patient coming in, you have the medications in. Is that the right medication?
Is the, the list that you have, is that the right list? So being able to use that as well. Again, it-- you will not be able to just use AI.
You could use other, technology like Internet of Things or, blockchain and all those. You could use all of those, but AI is gonna enhance that. So, everything should be, or at least like we hope that everything will be much better basic 'cause you have more information.
The more information that you have, if you use it correctly, you'll have better outcome for your patients. So, so it's very exciting from our perspective, but at least from my perspective, it's exciting. The key is to be able to, channel that information quite clearly in the right directions that nobody's using it in the wrong way, and being able to recognize exactly the limitation of the technology also 'cause just having it, I was, I use-- I, I'm gonna say the name because I use it so much, Open Evidence, one of those that we use a lot, a thing that really has enhanced patient's care.
It's amazing to see exactly that I might have that technology that I have in there that I can search and research information that will be with-within context. But if you don't have the right context, so you'll be out, you'll be getting the wrong information. But if you know how to use it, it's, it's, you can't really have better tools than those.
Yeah. Yeah. So it- And it's interesting because, you know, probably the, you know, more educated individuals are more guilty of doing the Google search and self-diagnosing and things like that.
Um, and of course, we all know about delusions that come along with large language models. Um, you know, my, my personal experience, and now, now having, to be fair, I'm pretty good at prompting these models. I'd spend a lot of time- I think that's key, Dave.
That's what, what, what we have to know. You have to know how to prompt, because if you don't know how to prompt, you're getting the wrong information. Yeah.
Yeah. But I fed, and, you know, not, not to, not to have this be the story of my kidney stones, but, but once I had my, extensive lab results back after, you know, the actual material was analyzed and every blood and every fluid test they could come up with, I fed that information in, along with information about my diet. And I had been paying very close attention to my diet because I had been, I had been trying to improve a lot of other metabolic numbers, over time, and it was crazy.
" And so when I actually had my consultation with my doctor, who was going to share those r- you know, those results, 'cause I get the results immediately in my inbox. This is the crazy thing, right? Yeah.
And then a week later, I'm meeting with, with, with my, with my doctor. I'd already gone through this, so I, so I was armed at least with the right questions to ask. And, there was a funny moment where my doctor, I had not shared any of this information with her.
" And so, so the good news is, Dr. Sandin, after a year, a year later, after modifying my diet, I recently had the, you know, ultrasound that shows no, no new stones coming. And, and, and, and I would consider that absolutely an indirect collaboration between the team at UC Davis, thank you very much to all of them, and, ChatGPT.
Um, absolutely a collaboration. I've been able to put meal plans together and things like that. So speaking from the, from the patient's perspective, and again, I can only speak to you-- to the, to the, University of California Davis Medical group.
I call them the Disney World of medicine. Uh, they're amazing. And, and so my experience has been there's been a lot of really, really good collaboration, and I haven't met a doctor who has had the, the sort of real pushback like, "Ooh, that's scary.
" Um, it feels like we're all in this together forging ahead, which is, which is, which is really, which is really interesting. But what would, what would someone be surprised to hear about the intersection between medicine and AI from your, from your vantage point? Or where do you think maybe the public narrative is getting things wrong?
Do you have any thoughts about that? A few of them. I was gonna tell you a good story that I think I told you in private about a patient, but I, I'm gonna, I'm gonna answer yours first.
Uh, there's, there's, there's a lot basically that the misconception is that we're gonna have those doctors or at least like the AI will replace doctors, will replace all of those, healthcare professionals. It's gonna transform them. It's gonna also help the patient in a sense, but they have to know exactly e-e...
The fact that getting your information, also you have to make sure that that's one of the thing that we do in AI, in a sense. I get everything, but I don't trust anything. I always, I'm always questioning AI because if you don't question it, then you'll get the wrong information.
But again, just like you said exactly. So at that point, it's great that the patient comes very informed with the information that you have already and then that we can have a better discussion about it. So it takes it to a whole better level and a higher level, and the fact that they can really have that information about them specifically, assuming there's no hallucination when they're putting those information in there, that comes out of it.
I think it's, it, it makes for a great conversation. It kind of really enhance the, the, the, the, the treatment of the patient and instead of, I mean, you get much more information, and information, that's what we deal with. That's our currency in, in medicine.
The more information you have, the better it is, and that's why AI is helping a lot because you could basically from what you'll be having as silos coming from different sources, you could put them together and come up with what is the best approach for the patient. But I was gonna go back. That's a very good story that I think I told you.
A lot of people have been hearing about it, and I heard it from when I was taking one of my courses, a-about that patient who's, who's, not the patient actually, a mother who had their son who was four years old, and, at four years, the kid was not doing so well. He was doing pretty well up to four years and then started to deteriorate, and then over three years, had to see 17 doctors and, couldn't really find the right information, and some people were saying that the kid was, being psychotic. There was something else really going on, so she's seen a number of different specialists.
" And it did come out with the right diagnosis. Was able to take it to a neurosurgeon. Neurosurgeon said, "Yeah, it's Tetralogy of Fallot syndrome.
" But again, that's where the mom was empowered to do it. Uh, from, that's from the patient's perspective. I just wanted to see exactly where, where you were saying exactly where we could see the two of them coincide.
At the same time also, there are a number of those big centers in the country where you have, specialists. What they do is look at rare diseases, diseases that people, nobody have an answer to them, and that's where AI also helps tremendously. And, one of those expert was saying that he had a patient that was referred to him that he had no idea.
It was a rash. He couldn't really figure exactly where that was coming from, and then ultimately, he fed that information, but again, as you said, prompting is the key. You have to know how to prompt the, the system.
" And then it did say exactly there was an association. I said, "If, you know, patient who ate that kind of food," just going back to what, just tend to have that disease. " So it's just to show you exactly that inter- I mean, like, not just the patient, but from the clinician also, it can help tremendously, even at the highest level of cognition where the, biggest expert, the most expert in the country are really looking at it.
They, they're able to, to bridge that and, and, and come out of a lot for their patients. So it's augmenting our, our work, making it better, and I think humanity will come out better. I mean, there's...
We're always gonna have other questions, basically, the ethical aspect of it, bias, and all those things. You have to look at that also, because, like, even when I get those tools, I have to make sure exactly that I know exactly where that tool was trained, what kind of patient did they use to train it, because it's not gonna be the same with them as with some other patients. So you have to know exactly is it appropriate for my patient.
It's the same thing that I do when I read a paper on, you have to know exactly that information that I'm getting, is it applicable to my patient population? So that's, that, these are other things that needs to be done, bias, call it, ethics. All of those have to be, even, like, doing papers, research papers, you could have much more coming out, but you have to look at that ethical aspect of it.
So a lot of transformation, but I think it's all for the better. So you, you mentioned something. You used the word silo, and, silos are interesting in all sorts of realms, but in particular in the field of medicine, it's interesting because it turns out, the more we think we understand the human body, the more we realize how miraculous it is and how much we don't understand.
And, and, and over, and, and traditionally, so like in your case, an incredible amount of time and, discipline to gain a level of expertise dealing with certain systems in the body, and we have that expertise is sort of fragmented in a variety of fields. " Eventually, he needs a proctologist. " And so the, the who- this whole, this, you know, the silos of information, I'm wondering, how much are we gonna be able to cross-pollinate and create kind of a holistic understanding of a patient with this technology where it was just not possible before?
Um, is it, you know, can you envision a situation where each of us walks around with a thumb drive that not just, doesn't just have our entire decoded genome, but has all of the information about all of our body's systems that we can get information about that then can be correlated in a way that just wasn't possible? You know, maybe, maybe the brain guy's not talking to the elbow guy, to use the technical terms for those specialists, and so, but there is in fact, it turns out, wow, there is a brain-elbow connection that we never knew about. I mean, what do you...
Is it gonna get better that way, do you think? I think it's getting better already. Actually, I think just this year that they came out, there's actually, there's one of those tool that they have where you have, I think it's more like for rare diseases.
It's exactly that, where instead of silos, you get those information silos, so there's different aspect of that tool. There is the, one of the tool who's basically kind of coordinate everything, but really send it to other sectors. One that's has to gather information from different places, different, charts, different specialists.
There's another one that has to look at the medical records. So there's, it, I think it's there already. It's, it's not really so futuristic.
It's, it's, it's, it's coming. Okay. And, and we, a lot of us are already thinking about it that way as well.
Um, the connection between different organs, like one of the field that I'm very fas- passionate about right now, and I kind of really am doing a few presentation on that, is cardiovascular kidney metabolic syndrome. It's a new way of looking at, patients in a sense that you go to the doctor, it's the nephrologist, they see you from one way, you go to the heart doctor, they see you one way, and then the endocrinologist see you one way. How do we connect all of them?
And we kind of really looking at that connection and know exactly that, you know, it's not one organ, it's a system that we have to look at. And if we treat the patient as a system, you know, you treat the patient as a whole as opposed to, "Okay, don't eat," I'm giving that lecture to the, dieticians recently. " The nephrologist say, "Don't eat the potassium.
" And so patient is getting different information, so if we could really get it and remove that silo, that definitely will help tremendously. So we, we, I think we're getting there. With AI, we can get there.
We can really gather information from different sources and make sense of it, as opposed to, like, just from one, one specialty, one, one organ. Just remembering that the whole, the whole system, it's a system, and when it fails, it's not just one organ failing, it's a system failing. There's one that I, I basically got involved a lot in cardiorenal, how the heart talk to the kidney, and also how the heart and kidney and liver talk to each other.
It's interesting if you look at it, one basic, it's a domino effect, and if you take it in silo, you're not gonna get anywhere. But if you really put them together and look at it from a system perspective, then you, you get better outcome. And you believe that AI, using the broad term AI, can help us move in that direction dramatically?
There's, there's no doubt about it. There's no doubt about it. AI, I, I would say is that the AI is one of them.
I'll say there's a number of different things, Internet of Things and, using, like, sensors. I think that's what you were saying earlier. Yeah, yeah, yeah.
Using sensors. I, I, I learned that from... It's, it's a nice analogy that, very, was a very, a, a chief of a big hospital, big health system, left and got into the technology.
I was watching him, and he said, like, "You know, it's interesting that we have cars, we have... So our cars, before we get to the mechanic, we know exactly what's wrong with all those sensors. " And so that's where we kind of really...
So if you get that information that is basically, instead of really getting something in silo, you could really get the whole information about the car, just the human being. If we get that, then we'll, we, we'll be better in the sense that we'll know exactly before things happen, we could predict exactly where we're going from there. So it- Doctor, that's called an onboard diagnostic system, OBD in the car world, and the only problem is, if you live in California, it's also something that's used to manage emissions, so there's a whole great, there's a whole joke there I'm sure that can be made for if we put these OBD, onboard diagnostic, devices for humans.
But so speaking as the officially designated representative, representative of medicine, designated by me, as being that- That's, that's a tall order. That's a tall order. You have, you, you are officially the spokesperson now.
So you're saying that, that, that medicine believes that these technological advances are actually going to help improve our lives? Yeah. There is no doubt about it.
It, it has- Yeah ... gonna help to improve it, and it's just how we use it. But it's def...
It's already improving it. It's already improving the workflow and, and hospital setting, communication with, um... I'm, I'm, I'm thinking about, like, in terms of digital technology in a sense, telehealth, the, it's already improving in a number of different ways.
As opposed to waiting for two or three months, you could really get to see your doctor. I mean, like, there's telehealth that you could see the patient. There's so much more that you can do, and, and then AI can gather a lot of the information for you before you see the patient.
There's a lot that is out there that we can do. AgainIt's not all gloomy. It's not all like, oh, everything is just like so there's no problem.
There is definitely things that we need to solve, but it is moving us in the right direction, and that's what I like. Well, fantastic. I, I, I would like to, I would like to end this installment on that very, very, cheery assessment.
And then, and then maybe Dr. Sanon, next time you and I get together, we'll talk about things like privacy concerns and the dark side of, genetic engineering, but that's for another time. Uh, for, for now, Julian, Dr.
Sanon, I wanna thank you so much for spending this time with us on Reality Check. Really interesting conversation from someone who, is, is living this revolution on the front line. And, and as, and on behalf of patients everywhere, all of the things we care about are meaningless when we don't have our health.
And when you are in, and you are in the hands of wonderful healthcare professionals like yourself, I know for myself, I am convinced that you are, you are one of the angels descended from heaven for us. So, just want to appreciate you for what you do, and again, thanks for joining us here. It's always, I say, it's always, teamwork.
That's what I tell my patient. That's what we like. We do it together.
Um, we have the knowledge, and we share the information with the patient. Now we have more information that we can share with the patient, which had come with information for us also. And, we, we basically, I think all of us who are in the profession, we love doing it.
I, I can't really... I haven't met anyone who's not a hundred percent in, in their patient. Like, there must be, but I, I mean, everyone that I've known and they fill in that profession, they love it, and there's nothing else that we'll do than that.
That's, that's, that's, that's, that's where, that's where our, our heart is right there. So, and, and I, I, I will tell you, since you're really looking at that, I was telling you exactly how we, a lot of people that are in the healthcare envision medicine. Imagine that you go to your doctor, your, provider, and, when you go there, the idea is that the AI, make it AI, digital technology, knows the provider, knows exactly their prescription, knows the patient also, because they have that information in the computer, knows exactly where the patient is living, and being able to prescribe a medication or give the...
You have that interface. The computer is your interface. AI is telling you exactly what.
And you could basically coordinate the two of them, with the computer, the provider, and the patient, and the environment, being able to design treatment for those patient. There's nothing better. That's futuristic to some extent, but it's not far from there.
Yeah. We'll get there. We'll get there.
Well, for Reality Check, I'm Dave Nicholson. Thanks for joining us. We'll do our best every week to, to bring you m- increasingly interesting guests to talk about this subject.
Thanks again. Hope to see you all soon. Hi, everybody.
My name is Eric Gray from VCF Tech Marketing. VMware Cloud Foundation is the flagship offering from VMware for building your private cloud. It's what you...
It's where you get your compute, your storage, your networking, everything you need, management. Uh, but there are also some advanced services that you can optionally, layer on top of your VCF private cloud to give you additional capabilities, and that's what we're gonna be talking about in this session. Uh, Data Services Manager or DSM.
It- it's Database as a Service for your private cloud. Today, I'm gonna give you an introduction to DSM. I'm gonna be presenting it mostly from the perspective of a vSphere administrator.
How does, how does it integrate with my VCF vSphere environment? Talk about some of the RBAC access controls, and then we wanna leave some time ... Gonna go through a demo scenario, show you the product in action.
So it should be very interesting. You might be wondering, "Hey, this DBaaS thing is kinda new to me. Why do I even need DBaaS?
" Well, the truth is there, there's a problem with that. You don't really want your developers spinning up virtual machines arbitrarily throughout your data center, installing, databases, whether it's open source, Microsoft SQL Server. There's licensing implications with, with the latter.
Uh, it can lead to sprawl, and you have no governance over those controls. You have configuration drift. Those developers who set up those virtual machines with databases, they're not gonna keep on top of the lifecycle management of the database engine itself, keep the patching.
Uh, they're not gonna be taking backups. And so in order to put some control on that, most organizations will result, resort to requiring tickets with IT. So if you want a database, you open a ticket.
We'll give you a database in a VM. Uh, we'll take care of it. You want it upgraded.
You wanna make sure it's backed up. All that's gonna be done through the ticket. And of course, that's a bottleneck.
So the developers don't like that, so what does that lead to? Overprovisioning. They say, "Oh, I don't wanna have to open another ticket next, next time I need more RAM.
" So those are the kind of things that are probably familiar with a lot of, organizations today when it comes to databases running on your virtual infrastructure. But we can address that with VMware Data Services Manager, DSM. Now, Data Services, we call it Data Services Manager maybe because it's aspirational.
Right now it's a database manager. It manages three databases, two open s- the two most popular open source databases, MySQL and PostgresAnd in tech preview right now, we cover Microsoft SQL Server, very popular database to run on your VCF environment. DSM covers the full life cycle from initial provisioning, even through self-service access, if you like it.
Uh, we have backups, and I'll show you that a little bit later. You can clone a database. So if you need to reproduce an issue, scale out, we can do that very quickly all through, user interface or API.
Uh, you can make sure that your database engines are kept up to date with the latest versions. We, we can patch that all, without, having to go into the individual VMs and do any work. It's all done, through Data Services Manager.
And of course, we, we handle clustering as well, so you can spin up a three-node cluster of Postgres instead of just a single, instance, and that'll give you better availability. Just if we take a very high-level look at what DSM is and how it works, imagine this is your VCF environment. You typically have a management domain where you're running your vCenter, your VCF automation operations, all those things, and then you have one or more workload domains in your data center, and that is where your actual VMs are running.
So we can use that same model with DSM. We just layer on top of your existing VCF environment. We'll add the DSM appliance to the management domain.
You connect it to your vCenter that controls your workload domain, and then you as the administrator, you'll go out and set up resources that you want those databases to consume, and that can be either a resource pool or cluster or a supervisor, if you have a supervisor set up in your VCF, environment. If you're using a supervisor, you'll create a namespace, and that namespace will be the destination for those databases when they're provisioned. If you're using a cluster or a resource pool, they'll be, be deployed on top of those just as expected.
O-once you've set all that stuff up as an administrator, the rest can be done through self-service, automation, API. Uh, the databases will run on top of those. Now from a vSphere administrator point of view, DSM is deployed as an appliance, and then there's a plugin added to vCenter.
So you can see on the screen here, you'll have this additional new menu when you look into the, the configuration for that particular vCenter where this has been deployed. And you'll, you'll see these terms here. I'm gonna go through them later, so we won't talk about them right now.
But this is, this is the, the basic experience here, and it supports a VCF single sign-on if you're doing that. So if you have multiple vCenters, you can log into one. You can...
You know, so that's how you would have your, your, appliance in one management domain, and you can still access the, DSM, interface itself in another, w-workload domain. So it all works great with all the VCF 9 features. Now, as a vSphere administrator, you are still in control of the infrastructure.
You're gonna use all those familiar constructs that you use every day for all your other applications to control w-where these databases can run. So, for example, in-- for compute, you, as I mentioned earlier, you can set up a whole cluster that's for databases. Sometimes customers wanna do that for licensing purposes, for like Microsoft SQL Server i-in particular.
Or, or maybe you have a resource pool on a cluster or a supervisor namespace. Okay? For storage, you'll be targeting a, a storage policy.
So you could use vSan, you could use NFS, what-whatever you like, whatever is un-- is compatible with your environment. If you have a storage policy that we can target, that can be set up in your infrastructure policy, and, your databases can land there. And then networking is also very flexible.
You can use the good old-fashioned VLANs and distributed port group. You can use the new, virtual private cloud subnets if you like. Uh, DSM takes care of the IP addresses, so you don't need a DHCP or anything like that.
It's gonna assign static addresses to the, the databases as it deploys. Okay? And we also give you, as the administrator, a lot of control over who can access it, and that'll be part of my demo later, so I won't go into it too much right now.
You control who can access it, where they can run it. We can pull in the permissions from LDAP, or we have a local user database, in DSM maybe for smaller deployments that need that. And you can also control which database engines, individuals can deploy through the policies.
So this is all... It all makes a lot of sense. You still have control, but you can give a little bit of the, this, the database as a service, self-service to the people who need it.
And those people who need it, by the way, it, it's not necessarily end users, developers, although it could be, but it might just be the DBAs. So you just, you don't wanna let the DBAs into vCenter to have free reign. Give them this, put some guardrails around it, then they can own all of the databases and, and the resources and who, who can access it that way.
All right. So this is just a, a quick overview of something I'm gonna be showing you in the demo, 'cause it's some new concepts, so I wanna make sure everybody's not just caught unaware here. We have some new constructs because this is a, a, a new initiative, within your private cloud.
So we have these infrastructure policies, and that's where you as the vSphere administrator, you go in and you assemble all of these things into a policy. You can also specify which specific versions of the database engines you want to, to be allowed in there. Next, you'll create a data service policy.
The data service policy specifically says, okay, this is the database engine that it applies to. It can be used in these namespaces, which... Namespace is just an, another form of grouping things together.
We're just using that word, namespace. And then these are the things you're allowed to do there. You can use this particular infrastructure policy, this backup location, or multiple.
Okay? And then we bring it all together by pulling in your users from LDAP or local. We assign them to a namespace, and that is what controls everything they're able to do.
So now I'm gonna jump over here. I'm gonna sit down for this. This is DSM.
This is the user interface for DSM. Now, we're not gonna get into it day- today because we just don't have the time, but you can also integrate with VCF Automation. So if you're using VCF Automation, you can integrate it with DSM and give access through that mechanism.
But this is the local, DSM user interface that you get when you deploy that appliance. Now, I'm gonna walk you through a little bit of a scenario here. Let's imagine we have a company that we've just set up DSM.
We- we're kicking the tires. The, the DVA team has tried it out a little bit, and they're saying, "Okay, this, this works. Let's, let's go one step further.
" So in this case, we're gonna be talking about MySQL databases, but, almost everything I'm gonna say today will apply to all the database engines i- in, to some extent. Okay? But we're gonna be looking just at MySQL right now.
So I'm the administrator right now. I'm logged in. I have, I have a lot of menu options here.
I have, the configuration settings. We're gonna take a look over here. This are all the one-time things that you would set up when you first deploy DSM.
You know, if you wanna have signed certificates, set up, you know, all your network information, everything like that. Um, now, the next thing you'll do as an administrator is y- you'll set up your backup targets. Now, this might be a new concept to a lot of vSphere administrators because typically S3 storage is something you see with cloud native applications.
Now, DSM is built using cloud native technologies. Behind the scenes, it's built using Kubernetes and, and all, all, all of those modern, architecture, technologies. You don't need to know that as an end user of it, but that's what's happening behind the scenes.
And so therefore, they chose to use S3 buckets as a backup target, and a lot of times you can get S3-compatible storage buckets from your backup or your storage vendor, your array vendor. Or you can set up, any number of commercial or open source S3 services for this purpose. The good thing about this is it gets the backup of the database outside of the environment where the databases are running.
So if there's a disaster, you've got a copy over there. You can restore it to a new environment. Can I point it to a real S3 bucket, or do I have to use- Yes.
Okay. You can. You can, you can back up to the cloud if, if you have the bandwidth and you wanna do that.
Definitely. Um, so l- in this environment, we've already set up the, a bucket for production databases. The DBAs set that up.
So what I'm gonna do as an administrator is I'm gonna set up another bucket. So I, you know, I go to my service internally, I create a new bucket, assign the access key, put in that information here. It's just, just a very simple...
Boom, set it up. So now I've got another backup target. Maybe those are on, you know, different tiers of storage, different performance, whatever.
A question. You know, Talera from InfoSec. Uh, we are, you are using a, credential there.
Is there any zero trust or stuff like that that you can implement in order to avoid any, you know, credentials inside, inside the, S3 bucket or stuff like that? Hmm. Okay.
So the question is about zero trust to avoid- Zero trust ... leaking the credentials. Yeah.
Well, right now, the way it works is what I've shown there, and so, you know, it's all en- we're all encrypted here. Oh, you know, the, the connection is, is, encrypted. Yeah.
And then we're going to be, storing that as a Kubernetes secret on the back end. Uh, but, but, that's the extent of it that I, that I can talk about right now. Okay, great.
Mm-hmm. That's all. Okay.
And thanks for the question. Now... All right, I've done this one-time thing, and now I'm gonna go over to MySQL, and let's say in this scenario, you know, we have a, a number of different MySQL versions that we can deploy in here for, for whatever reason.
Sometimes you need a specific version. And we've already enabled the two latest versions right now. But in the, in our scenario, oh, we need to give the developers access to this older version.
39. Let's go ahead and enable that for them. Okay?
So we'll click that. We'll enable it, and now that'll be another, potential database that we can target when we set up our, policies. So the next thing we're gonna do is we're gonna go and set up a namespace.
Now, we've chosen the word namespace here because behind the scenes it really is a namespace 'cause this is all built on Kubernetes. Okay? Uh, now, in, in VMware land, we have several different things that are called namespaces.
You know, I'm sorry, I apologize for that, but, this is not like a supervisor namespace or anything like that. It... We do have different things called namespaces because that's what they are.
Uh, but in, in this case, we're gonna create a DSM namespace. We're gonna call it, devteam, and we're gonna apply a label here. The labels are gonna help us scale.
Later on when we wanna target these namespaces, we might get tired of having to select them individually if there are many, or we wanna be able to add new ones without having to go through and reconfigure things. Okay? So for now, we just have two namespaces.
We got the DBAs who are already using it, and we got the developers who we wanna add to the mix. All right, so we go, and we're gonna give them permissions here. Here's where we link what's existing in our corporate directory under the directory services.
We're gonna add a DSM user role, so not admin. There's, there's very few admins in, in DSM. It doesn't mean you're a database admin, it means you're an admin of DSM itself.
So DSM user is where the d-the database administrators and end users are gonna be accessing. That's their role. All right.
So I'm gonna... I have a, a directory group called Developers, and I'm going to add the dev team namespace that we just created to be linked with that developers group in LDAP. Okay?
That's LDAP. All right, so that was easy, very simple. Okay, and then the next thing we'll do is we'll just review the infrastructure policy just to remind you what it is.
Uh, we don't create it in here, we create it in vSphere 'cause that's a vSphere administrator task. The vSphere administrator's in control of the storage policies, the compute where this can run, the port groups where you're gonna connect, specifying a range of IP addresses called an IP pool here, and also setting up things like VM classes. This is another nice thing about DSM.
The end... The user of DSM doesn't get to specify arbitrary CPU and memory combinations. The, the v-administrators go in and set up VM classes, small, medium, large, extra large, extra memory, whatever you want in your environment, and then those are the ones that can be chosen by the end users of the system.
So that is just another guardrail that we can put on this environment. And then the policy is where we actually glue it all together, and just we show who can do what and where. So we've got this existing one, the MySQL, production policy.
We're gonna make a new policy. This one is going to be called MySQL Dev, and in this case, we're gonna choose MySQL. If we wanna make one for Postgres or SQL Server, we would do it right here.
Okay. Choose one data service, and then you choose w-which namespaces can use this po-- this s-data service policy. We are going to choose the label that we just made.
Uh, so if there's a label, key value, in-infrastructure developers, that's gonna apply to this one. So the great thing here is if I need to make another, namespace and everything later, as long as I put that label on there, this thing will apply to it. Don't need to go back and edit this or update it or anything like that.
So that's just... It's better scalability and, and management. All right.
So then we're gonna choose the database version. We enabled these as administrators earlier, but now we're going to decide who can actually use it. " They have reasons, we're gonna let them use it.
Okay, which infrastructure policy am I gonna use? Just one. You know, in a larger environment, most likely you would have many of these, different clusters, different types, different...
back by different storage, whatever. So we're gonna do that. And here we're gonna say, "Yeah, the developers are only gonna back up to that new bucket that we just made for the developers," and, and that's it.
So the... It's, it's a pretty lightweight operation to create one of these, and you can go back and change it if you have to. All right.
All right, so now I'm logging out. I was an administrator back there, I could do everything, I could see everything. Uh, now I'm gonna log in as a different persona, and this is a person we call Scott.
He's a developer, end user. Any Scotts in the room? I don't know.
Okay, so I'm Scott. I log in, and his view in DSM is very different. He doesn't have all those configuration options.
He doesn't get to set things up. He can just see what he has been granted access to, which is great. So that, that is the guardrail we're putting, the governance in the data...
in the... for database as a service. All right, he is working on an app.
He doesn't care much about what's going on here. He really just wants to get a database up and running so he can do his work. All right?
So we went over to MySQL. We can do Create Database. The namespace, the one and only namespace that I as Scott have access to is called Dev Team.
It's already preselected, I can't even change it. Um, I choose my version. I'm gonna deploy one of those, eight zero three nine.
I'm gonna put in the name of the database that I wanna use here. A couple things about passwords. It, it'll auto-generate a random password by default if you don't put one in there, which is pretty good, so I...
that's what I usually do, just let it auto-generate a random password. You can look it up later when you need it. Um, I'm gonna deploy a single server.
If you want, you can deploy a cluster, a three-node cluster so you have some redundancy there that live on different hosts in a vSphere cluster, so you can to-you know, tolerate an outage. It's, you know, good practice for high availability. Right now we're just gonna go with a single one.
We have our database, backup bucket pre-selected there. We have our infrastructure policy. It's the only one we have access to, and then we'll choose a VM class.
In this environment, we just have the default small, medium, and large. You can make others if you like. We're gonna just choose this one.
It's a four, four cores, eight gigs of memory, perfect for a developer. And then you can throw in a few options if you need them. And, you know, depending on how familiar you are with databases, if you're a developer, you know that you probably need to do something, which is load some data into this blank database once it's provisioned.
And in MySQL, you need a parameter set on the server side that's called, local in file, and so you can do that right here. And if there... There's some other parameters you could supply in here but, you know, this would be a common one for a developer to request on the server side.
This, this enables SQL, MySQL to have bulk data loaded in. Okay? So th-there's our summary.
And it takes several minutes. I've obviously trimmed out some of the waiting, but it is relatively fast. We go take a look here, and here are some details about the database that's been provisioned for me.
And the thing I really care about, which is really what all this effort was about, is to get a database connection string. Connection string, I'm gonna copy it to my clipboard. I'm going to pop open Notepad here just to show you what it looks like.
This is a c- you've probably seen this before. It looks like a URL, right? Could...
MySQL in this case. It, it could be Postgres. Username, password, the host name, port, and the database name.
That's what you need. If you have that, you're a developer, that's what you want. Y- you don't really care about any of this other stuff.
You really just wanted that, and then I'll show you, you can use it from a command line, the MySQL client. You throw this data in here. I'm just loading the sample database of a list of cities just so we'll have something to look at.
That's using MySQL client. But then there's another client, many clients exist that use these URLs, these, these connection strings, and so here's one called mycli, and I did that. And then now, you know, I, I've got a little, script there.
I can just pull up some random cities out of the database just to make sure it's working. Everything's looking good. Okay.
So let's say I'm the developer. I'm satisfied with how that went. 39 version.
Okay, I'm ready to bump that up to the latest one now. And so and here is where y- the, the end user can do, can initiate the life cycle management of his database. So I go over here, and I notice I have two available upgrade options.
I'll just choose one. Yes, I know there's gonna be a little bit of, downtime when I do that. It's actually quite fast to do this.
So behind the scenes, DSM is going out, changing the underlying data service engine, you know, remounting the data. Boom. Back up and running.
Okay. So we're gonna jump back over to the list of my databases, and you can see it did the upgrade, and now it's ready. Can come over here, take a look at this.
Now, t-the next thing we're gonna show is... So we, we've done the first test. Now we wanna add some availability to this database.
We just did the single node. Uh, we can do better than that. So we are going to change this on the fly to a cluster, so now this will become a three-node MySQL cluster.
And then we're gonna do another thing. It's unrelated, but also good, is we're going to e- enable the cluster to be the source for read replicas. So I'm gonna later show you how to spin up some read-only replicas.
So if you wanna scale out, your developers might wanna design their application so that writes go to a certain database, reads can come from these other ones. That way you can definitely scale, to much higher, loads. So I'm gonna enable both of those features in that dialogue box.
Okay. Gonna go back over here, and then it's scaling the replicas. We'll switch over to vCenter real quick, and you can see what's happening behind the scenes.
We have... I called it Oxygen, and now we have three of these database VMs called Oxygen. They work together.
They have a little, you know, a little random tag gets appended to the name to make 'em, make sure they're unique. Okay. So now if I go back to this diagram, you can see, oh, yes, we have three primary re- and two replicas, over there.
Okay. So now we will use this feature that's built in to create a read replica based on a, a source. All right.
So we're gonna... We can specify different versions. We might as well choose the same one, and I'm just gonna call this one Oxygen Read Replica 1.
Okay, and some of this stuff is pre-filled, because it already knows what's going on. I'll use the same size in this case, and I'm gonna spin up this read replica database. Now, take a quick look back over at our original...
This is the, the, the source. Now there's a little helpful diagram to understand what this really looks like. You've got the, the three-node MySQL cluster here, and it's being replicated over to this read replica, okay?
And then monitoring, you can also take a look at this. Some basic monitoring just, just to help you understand is the database healthy. You know?
Obviously, you can also send metrics over to VCF operations, but that, that's a whole nother topic to cover. But, you know, you can correlate all your VMs in your database and what's happening on, on the ops side. But here is just a quick, you know, is this thing healthy or not healthy?
Is it, i- is it have enough resources? Things like that. Okay.
So we are gonna also just verify... We enabled backups when we deployed this thing, and, you know, sure enough, the backups are configured. They're gonna, you know, run on a default schedule.
You know, every Saturday it's gonna do a full backup, things like that. Okay. Is the only option the full backups?
Or- No, no. We have, uh- ... as well ...
we, we can do the incremental as well. So there's a whole section on the backup schedules that you can set up, so y- you can tune it to your needs. Mm-hmm.
Also, I was gonna ask, like, how granular can you get with permissions? Me personally, I always get nervous when my developers are touching the database, like... Uh-huh.
Um, well, what do you mean by granular? Like, in terms of, let's say, like, are you able to have... Designate maybe there's just one particular developer who's able to go and, like, do a upgrade or not.
Mm. Stuff like- I see ... that always makes me nervous.
Yeah, yeah. Okay. That's a good question.
We... The, the granularity is what I showed. So it's a group in LDAP maps to the namespace, and then they have access based on the namespace as sort of a group membership.
So we can't really control who can do the upgrades. Okay. So if, if that doesn't work, then pr-probably the model you would wanna use is have your DBAs using this.
Mm-hmm. You know, and they are responsible for... I mean, if it's a production database, you probably don't want the developers doing that anyway.
No. So, you know, I think it's okay. You know, let the DBAs run the production ones.
Let the developers do what they need to do over there. Yeah. Okay.
Okay. Thanks for the question. Um, on the ba- on the backups, how are the restores done?
Uh, what limits do you have on restores? H- what kind of restores are supported, and can you restore to other places? Yeah.
It's a... It supports a point in time recovery, and so if you do go into the backup and you wanna do a restore, you can put a time, a date and time, that you wanna restore to, and so it'll... It- it's, it's collecting the transaction logs in a, you know, pretty regular fashion.
It's not just one big chunk. Mm-hmm. So it's able to go back and do that.
You can restore to a new database, yes. You can say, yeah, uh... " Yeah.
For troubleshooting or something. And who's got access to those backups to do those restores? It, it's gonna be the same model.
Whoever had access to provision it will be able to, will... They will be able to see the backups. Okay.
Yeah. But not everybody can see everything. Jim Kremensky, General Y Guy.
Um, back to backup for a minute because that's what DBAs should be very worried about. Transparent data encryption. If the database, MySQL database in this case, is using TDE, is that also supported for the backups, or I should say enforced for the backups?
I don't know the answer to that, Jim. Okay. So- That's fine ...
I don't wanna guess. Okay. But, you know, we're, we're, we're using existing constructs to, you know, generate backups from- Right ...
within those databases. So if- Okay ... if this feature is supported by those processes, then it would work.
Okay. So, uh- Okay. Perfect ...
we c- we can, we, we can look into that another time. Yeah, for sure. Thanks.
Are those... The backup's just native then? The...
It's... Well, they're... It's using...
I don't wanna go into all the details of how it's implemented, but, you know, they're using some standard, backup, technologies that integrate with these open source databases that allow them to do backups to S3 compatible storage. Right. It's not, you know, it's not all proprietary.
It's, it's, it's standards-based. What about SQL Server? Yeah, SQL Server is in tech preview right now, and I don't really wanna go into all the details of that, but, but it will support backups to S3 buckets, yes.
So what versions is it gonna support then? What versions of SQL Server? Yeah.
Um, I'll say that it- it'll initially support SQL Server 2022. Okay. Okay.
Yeah. Thank you. And a quick question about the metrics.
Is it possible to export the metrics in another, monitoring system? Yes. You can send them to, VCF operations or to Prometheus.
To Prometheus? Yeah. Right.
Thank you. Yeah. Pleasure.
Okay. So then I wanna get, one more thing just to show you. We- we're in the read replica now, and we're gonna do the same thing.
We get the connection string. We can just paste that connection string into our command prompt, and we can see we're pulling out data from the replica. So now the developer can go and, you know, update their app to scale.
Pull from the read replicas and not overwhelm the read-write, master cluster. And you can see a- again, it's just its own little database there. Okay?
And I think, you know, that kinda leads us to the conclusion here. The last slide. DSM is, is Database as a Service for your private cloud.
If you look at all the public clouds, they all have a Database as a Service because it makes sense. We don't wanna just run databases inside VMs. You can do it, and that's what everybody has done, and it works fine.
But why not make it a first-class citizen, give you those additional goverm- governance options, the ability to do life cycle management of the databases, and also puts, you know, controls and self-service access there. So I hope you'll take a closer look at DSM. It's a new offering, and not as familiar as some of the other, features of VCF.
But I really think it's gonna take off. Thank you very much.