Techstrong TV October 20, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, don't, uh, secret agents have to deal with security too, or is it security have to deal with agents. We're trying to figure that out. What's the security with all the agents that we're creating here on the Textron gang?
Well, welcome back you for joining our elite team here of Textile Stack Strong Gangs. I guess we are gang members. Uh, Mitch Ashley here with Futurum.
Great, great to be joined by, um, our, our crew of Jack Fowler and Steven Foskett. Guys, welcome, welcome. Thank you.
Great to be here. I am definitely a secret agent. You are.
Well, that's what I was thinking about agents. Aren't they like secret and don't they deal with security? And suddenly, now, I, you know, we talk about secrets of agents and that's what we're gonna get into.
com, talking about security around MCP servers. Um, are we, it seems like the topic has been, uh, come up but not been addressed. We talk about security for agents.
We talk about identity here and there. You know, the team members, are they, whatever, you know, how do we, how do they get their permissions? But there doesn't seem to be any, uh, like real solid frameworks around agents today, at least not yet.
Now, you can look into some of the open standards and say, there may be some things there, but I don't think Jack, somebody in the security community is gonna say, yeah, I'm happy with everything looks good to me. No, I think it's the exact opposite. In fact, uh, the, uh, entire security, uh, identity security world sort of shakes their head and looks at it.
Like, does the face ballman? You know, what are you thinking when you created MCP and had no concept of identity and MCP and said, oh, we'll just wave our hands and do some OAL tokens or something else and let somebody else deal with it. Uh, the the challenge is really that we're moving from a human world to an agent world where agents act on behalf of humans.
And it's important to understand, uh, the agent's identity, the server's identity, the human who's the agent is acting on behalf of, or for the benefits of identity in every single action transaction that occurs. And right now, there's a lot of anonymity and anonymity in security is a bad thing, right? So there's a lot of talk about at the high level, here's some high level constructs we need to think about.
And so I wrote an article about some, uh, uh, identity security folks coming out and saying, you know, there's a lot of issues with anonymity with, um, how you communicate the information back and forth. Uh, how often you go back to the user to re-authenticate, to get permissions, and how to make that cleaner. And here's some high level thoughts to think about it, but we haven't moved beyond that to here's an actual protocol that actually thinks about and cares about it.
And the big concern is we're running at a million miles an hour trying to make agents of useful and get money out of them without thinking about the security. And that's just generally a bad thing in my book. And we can't wait for them to be agentic.
Right. Stephen, at the same time, you know, we, you host AI infrastructure, uh, field days and, and AI oriented things. I'm wondering how much, how much is security coming up and what are vendors saying about this?
Yeah. Well, for, to be clear, yeah. Alistair hosts AI infrastructure Field days.
Yes, that's true. I, I host AI Field Day, and that's where this stuff comes up. Uh, AI Field Day.
I know it's confusing 'cause there's two that sound a lot like, um, and in fact, actually the last week I was at NetApp Insight and there was a lot of conversation there as well about this. Um, first off, let me just say that that article on Security Boulevard that, uh, about this topic is just really excellent because it goes over a lot of the potential issues with agents in a very clear, straightforward way. And it's so true.
I mean, think just, just think about what is being pitched at us about agentic ai, you know, oh, it'll automatically, you know, find the right flight for you and book it. Um, wait a second, right? Do I really want my browser?
You know, do I really want perplexity to decide how about, or, or even better, do I really want Google to decide which flight to buy and buy it without any approval? Or alternatively, as it says in, in there as well, there's that chaos of approvals. Or alternatively, do I really want to click the little button and say, buy me a flight, and then have it say, do I have your permission to access your calendar?
Do I have per your permission to access your email? Do I have your permission to access your, uh, frequent flyer accounts? Do I have your permission to, you know, because again, that's, that's another issue.
Um, uh, another other issue I wanna point out. I was reading the CloudFlare blog, um, last week, and they were talking about, um, you know, their, their, uh, one of their articles, uh, using, uh, MCP in code mode. Uh, their, their thesis is we've been all been using MCP wrong.
Their suggestion is that instead of calling tools, what we should do is have MCP dynamically recode the calling and the APIs on our behalf automatically, and then run it as code instead of in MCP. And the whole time I'm reading that, I'm just thinking, but what about security? So essentially we want to, we want to just tell AI every time the agents do anything, Hey, go ahead and just rewrite this yourself.
Like, just figure out how to do it. Would you? And yeah, I mean, it's, it's just, it's just a complete total nightmare.
And, and so I wanna point out what, what, um, the clever thing that NetApp announced last week, and this is not gonna solve this problem, but I liked one aspect of it. They are in their new, um, AI data engine. They are using, uh, AI tools to do data classification and to then use that to enforce access controls on data.
So instead of, um, instead of just saying like, uh, I think you can access everything on that file share, you would be able to say, you can access, you know, data related to ACME Corporation client, but no financial information. And then that way, and, and their, their idea was, and I completely agree with this, that the only way to keep an LLM from leaking data is to never let that data into the LLM to begin with. And, and their, so they're using ai, but in no way that actually is exposing anything.
They're just using it to create metadata, and then they're enforcing access based on the metadata that was created in a sort of a standard deterministic programmatic API type way. So there it is not AI talking to ai, it's actually, you can't access this. You can only get this subset of data.
And I love that idea. Interesting. I was also at, uh, at the Oracle last week at the, uh, a now renamed AI world, um, and similar kind of approach of not only is it the data store, but that's, you know, they have databases, massive databases, uh, business applications, E-R-P-C-R-M, et cetera.
And their approach is something similar where they said, look, the data never leaves this platform and AI will access it through MCP, but that MCP will be controlled by all of our existing security and privacy policies. So you already implement in those products. Um, so That's like the same idea except for structured data, whereas, and NetApp was talking mm-hmm.
Specifically about unstructured and mot multimodal data. Yep. Makes a lot of sense.
So it, it's interesting, you, we, I wanna go back to the, the, the polymorphic topic you brought up of code creating code, right? And that's, we're already doing that. We just have it in the developer's hands when it's creating code for us, right?
Um, but that's very much where, where this is heading, is that agents will be able to create agents, agents will be able to create code dynamically. Um, and in doing, doing, so, yeah, it might be minor things, but still that's how, how things get linked in. That's how c credentials get lost.
All kinds of issues kind of come up. That article you were talking about on Security Boulevard, by the way, was, we'll put a link to it beyond chatbots, why, uh, agent security is the industry's next major challenge. And there are like 10 items.
I think there were, that came from the artificial intelligence, identity management community group that, that had a number of, of these issues that they talked about that need to be addressed. So, yeah, I'm sure it's not everything, but I thought that was a good list too Point. The, the interesting thing about all that and sort of the polymorphic is we, we do that a little bit today in a very subtle way, which is when you think about infrastructure as code, that really is mm-hmm.
Uh, another form of that where we say, here is some code that defines the desired state of our environment. Now you go figure out how to write code to talk to agents that are, or to have agents that go talk to different types of systems, whether it's servers or routers or storage devices, to get 'em configured the way you want them to, to operate. And in that environment, we still have a very big problem with anonymity of access, right?
Every, if you think about those types of environments and infrastructure as code, everything you're doing is a privileged to access. You're operating as a super user or in a system administrator where you can go change any configuration. You can, uh, delete hosts, delete servers, delete virtual machines to start 'em, start multiple instances.
And with the anonymity in there, it's very hard to audit and trace back who's doing what and why something actually happened. And hey, you know, we just shut down our entire production server. What happened?
Well, this agent turned it off, but why did that agent turn it off? I don't know. Because, you know, somebody somewhere made a typo in an IAC file, but there's no way to tie all of that back together without a lot of manual effort.
And very often, because it's all anonymous access, you can't, and that's part of the problem in the MCP world as well, is agents can take on and work for multiple people simultaneously, and they can do things, uh, autonomously, right? Where you say, Hey, I wanna buy an airline ticket. But that triggers many different actions, which could trigger many different agents to do things, as you said, access your calendar, put something on my calendar, or delete a meeting off of my calendar by mistake.
Right? Hey, that meeting disappeared. I don't know why it disappeared.
Who made it disappear? Where's that, uh, log? You know, I feel like I'm reliving the, uh, dipping back here in history.
The, uh, the 12 blinking clock on the VHS tech tape deck. I can barely keep HubSpot and LinkedIn connected all the time. Have to go back and relink it.
Yeah. Um, so how are we gonna do that? That's the thing, right?
And, and again, in Cloudflare's defense, I mean, they're not talking about zero authentication. I mean, they just use conventional, um, au authentication tokens. Um, and MCP is fully, uh, able to do, you know, standard authentication tokens.
But, um, like you said, I mean, that introduces a sense, a a sense of fragility and, and sort of a black box nature to it, where you're just not sure, uh, where did it get this token? Who's it authorized as, you know, how do I control this? Um, and, you know, yeah, the, the blinking 12 o'clock problem, um, we are all gonna face that problem, because it doesn't matter how smart you are when you're, I said black box now twice here.
I'm gonna say it again. Um, when you're faced with, you know, fundamentally, um, agents, agent to agent is a black box, you know, you're saying, you know, here's some tools that you can use. Now they do, again, to cloudflare's defense.
They're running these things in a sandbox. Um, they're using authentication tokens, but it's the step of having the agent create its own code. That gets me a little scared.
Um, you know, their justification is that LLMs, um, you know, the trouble with MCP, and this is actually kind of a clever thought, the trouble with MCP is that LLMs were never trained on any dataset that contains MCP calls because MCP didn't exist when they were being trained. Hmm. And so it doesn't understand fundamentally how to deal with special, the special MCP tool calling token and how to call tools.
Even, even if it's been, um, fine tuned and to, to, to handle MCP, it's not fundamental to its training, whereas allowing it to reach, redo everything in TypeScript, it's, it has a huge experience with TypeScript, and it's able then to more effectively execute all that I agree with. It's just, but that doesn't change the fact that we don't know what it's executing and nobody knows because it's executing in a sandboxed environment that's ephemeral and then it evaporates. It also doesn't change the fact that right now, code generation capabilities are at, at the infancy.
Right. Very, very, uh, immature stage. And so the probability that it generates code that does something wrong is relatively high today.
Yeah. Go generate some code and go execute it. And don't ask me and don't show me.
Exactly. Now, go. Exactly.
And, and AI likes to generate a lot of code for you on your behalf, even if you don't want it to. You have to be careful with it. Well, good, good stuff.
I mean, we've covered a range of, you know, what about the MCP? What about MCP, who's, it's like the weather, who's doing something about it? Uh, or agent security?
So, uh, I have a feeling we're gonna talk about this topic a lot more. So stay tuned, we'll be back and we'll be, uh, jump to our next topic. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included, that work you are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity, your digital front door is wide open. And what compromises your home can breach your board with, because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black Club, digital executive protection, defending the new attack surface your personal life. Well, we're talking about security day.
It's security day on the Textron Gang. com talking about the, the big secrets leak, if you will. Uh, that has to do with vs.
Code visual studio code, developer tool, IDE, uh, through extensions leaking secrets. Um, Wiz had earlier this year, uh, announced the discovery about, about how many supply chain security supply plane leaks that were due to these extensions, not only in DS code, but also open BSX marketplace. And then Microsoft researchers found that publishers of more than 100 vs code extensions leaked access tokens.
Hmm. That would've enabled a, a bad actor to distribute malware to more than 150,000 users. Yeah.
What's a, you know, that's not bad. It's kind of a small number, isn't it? So, so it, it just shows you the, the attack or the leakage surface of data and security credentials, secrets is as far wide and as deep as as you can make it.
And now we're talking about developer tools. We're, we're talking about MCP, you know, that's now also part of the developer tool space. So what are the security folks gonna do about this?
Jack, when are you gonna fix this for us? When are we gonna fix it? No, when are you gonna fix this, Jack?
When am I gonna fix it? There you go. Personally, gonna fix it.
Well, I, you know, I'll, I'll use a very simple analogy that the IDE, the integrated development environment is effectively the web browser for developers, right? It's their main way of they interact with things and extensions in the ID inter, uh, interface are the equivalent of the extensions in a web browser. And so we sort of have the, it's the exact same problem we've had in web browsers for a while.
If you have rogue or malicious or poorly programmed extensions, they can come in and get access to your password, see where you're typing, yada, yada, yada, the same sort of security things. And so, uh, you know, uh, we have a couple of, in the security world, we now have a couple of, um, startups doing browser detection and response, which I wrote about recently, like Square x, who has an extension that goes out and tries to, uh, protect the user of a web browser from malicious activity by, either by either websites or other extensions. And now, or maybe we'll go and see developer, browser developer environment, IDE security tools that are gonna have to be third party tools to come in and look at this.
Or, um, the other option is to go towards more of the Apple model, where you have a, uh, walled garden and somebody Microsoft for visuals, uh, studio and, uh, goes out and vets the extensions to say that this is behaving properly or not. And that's an awful lot of work on both cases. So I don't know.
Yeah. On the square X thing, I, I, I have to say, uh, we did just have them present at Security Field Day. So if you wanna learn how, what that's all about, you can just Google Square X and Security Field Day and you'll find a video, which is a, a deep dive demo of, of exactly what they're doing.
But absolutely, um, the thing that, that gets me about this kind of in relationship to the previous discussion that we had, the, the leaking of secrets. I mean, we just talked about tokens and secrets in MCP and how that works. Um, the leaking of secrets is one of the primary things that, um, jail breakers are trying to do with AI models.
Um, basically figure out how to make it leak secrets for me. And there are many ways, and, and, and you cannot and fundamentally prevent that, except by having sort of a convoluted calling process. Like I could see a situation where somebody could have an MCP tool that exists that is only a secret's vault, maybe one password should do that, and, um, and basically have the agent call a tool that it doesn't have visibility into.
And then that tool then basically just provides the token on your behalf or something like that. Because if, if it can see the secret, then it can leak the secret. And that's the problem with this v code story, is that essentially people left the, the token, the secret in the code.
And the thing is, um, you know, black hats are literally, I mean, they, they basically just have regular expressions searching for, you know, tokens and secrets on GitHub and VS. Code and everything constantly. So if you do it even for a moment if you like, oh, commit that.
Oh man, oh, no, no, no, nope. Lemme get rid of that, you know, well, guess what? You know, you just, you know, it's gone.
You know, as soon as you say it, it's gone. It reminds me of the situation back in the day when we would set up, you know, windows servers and within literally 30 seconds, somebody was hitting, um, known vulnerabilities in Windows to try to, uh, you know, hack into those servers over the internet. So you had to like, like install, you know, windows servers, uh, disconnected because otherwise somebody would hack it before you could even apply the patch.
It, it's kind of the same thing here. And, and in vs code what it sounds like too, people didn't even do that. They didn't even get rid of the, the stuff quickly.
They, they just did it and didn't know that they did it. Um, at the end, you know, you're talking about, um, you're thinking about vibe coding, you're thinking about AI written code, uh, I think there's a very good chance that AI is gonna put some sloppy code out there that's gonna include tokens and secrets and that aren't properly managed Well, and, and it's not, you know, rookies doing this too. I mean, they found, you know, extensions that came from open AI and Gemini, Google, Gemini, philanthropic, you know, perplexity even as well as AWS and GitHub, et cetera.
So there, so these are, you know, are weren't just kind of rogue actors out there that who left their secrets in their extension. And there are things to do exactly like you're talking about and development world, one of the popular open sources, one is called Vault, and that's the way it is. The secrets is stored there, and it's only because the trust relationship you set up between your code, your system, and that vault that gives you the access token yet to get that credential, that secret, um, I, I kind of faulted at, at the IDE level.
This should be built into the IDE, right? There are, and you can use secrets managers in VS code. Um, but that should be part of it.
It should be very easy to manage secrets already, just right in the IDE pop it right there. It already has, you know, I built the trust relationship when I installed it. This is my test environment.
This is, I hook up to my corporate environment. That should be part of how that's set up. I mean, it's, Jack security is set up from the beginning, not after the car leaves the factory.
And we want to add airbags, which is, which is why I, my call is secure by design. I really fundamentally believe we need to think about security at day one. When we talked about MCP earlier, we didn't think about the identity portion of the security of MCP.
When we look at the IDE, the IDE is something that has grown organically over 40 years, right? You know, when I was an engineer many, many years ago, we used a text editor, right? There was no integrated development environment.
You didn't have all the tools integrated. You ran me outta screen to do, you know, you red typed your code, you exited the editor, and then you invoked the compiler and then you invoked your test environment. Uh, so in systems that have grown organically, we haven't really thought about security at, at the beginning.
And I think it's now time, it's clearly time to sort of take a pause and say, how do we build, how do we sort of rethink this so that we can import the security tools that we need into it? Such as, um, uh, secrets managers, you know, built into the ID environment or, and, and, and not only that, but how do we make it a standard operating procedure of how we teach programmers and engineers to develop, is to think about that and to use the secrets manager rather than the hard coding it. Yeah.
But I wanna say, go ahead. Maybe the IDE could enforce that and basically refuse to allow you to put secrets in your code to start with. I think it's something, something you brought up earlier, Mitch, was that, you know, you named, you know, the, the rogues gallery who, who of, uh, who's who of AI as part of the, the group that created extensions, that leaked code.
And my question is, and something Stephen brought up is, was that code that leaked the secrets written by a human or by ai? Well, that, that's a good question. I, I'll, and was it the same code for all of 'em?
I bet money is by by both. Yeah. Was it written in 2025?
Probably ai. Ai. No.
And I didn't, name didn't, I didn't name all names. I'm holding some of that. No, no, absolutely.
There was a lot more, but, alright. Well, you know, I think, so the, the, the parting thought is when we talk about software supply chain security, we're usually thinking about SBOs and package managers and things, source source images and things like that. We have to also think about the tool chain.
We're now using AI based browser tools to do development and running agents in browsers, right? So all of all of that execution environment, either for development or production, all that has to be secured. So it's the tool chain too.
The whole part of it. That's how SolarWinds happen. So we'll be back.
We're gonna finish up on security theme. One more topic. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Well, welcome back. We're gonna shift a little bit and not just pick on AI security. That's a little bit too easy at the moment.
I think in some ways we're gonna talk about really the runtime environment for cloud native applications with AI powered security. Hmm. Okay.
There's an interesting thought. Now, of course, when we talk about cloud native, we're usually talking about Kubernetes, at least as one of the technology that's pretty common to run. Um, and we also, we also look at, you know, visibility through things like, um, observability type tools, uh, things like that.
I know this is an area that you looked in to in prepara preparation for today's segment. Jack, give us kind of your rundown. Um, well, I think, you know, in one of the articles that Alan wrote, and I think he said it best, which is you can't secure what you can't see, right?
And so we really need to think about in a, in a cloud native Kubernetes environment, how do we understand what's actually happening in the running environment, not necessarily in the development or code environment. So you'll have, and as we talked about with or the first segment in MCP, you will have instances of your application either talking to other instances, um, or talking to other resources in your environment. And you may not, you probably won't have visibility into all of that because it might be either in a process, communication on the same server, or, um, going across a, a local connection that's not part of your outbound network security protocols and what you're looking at for network security.
So if you're not observing what's going on, you can't understand if something bad is happening. I think that's the crux of the problem. And so as you start having AI developed code and AI running in your environment, now, there's a whole lot more happening that you don't know about.
And so understand, trying to get a handle on that invisibility into that, I think is critical. There's an interesting thing too, and Alan's and Alan's cumy take at the end of this article he's talking, he talks about it's not humans versus machines for security. It's humans and machines working together.
And with ai, since agents and AI often mimic or do things that are essentially what a user would do, whether developer or, or an end user. So machine identity doesn't kind of cut it anymore in what we traditionally think of a machine to machine identity security mechanism. 'cause the actions it's taking is actually looks more like an end user or is, frankly, it's just a digital user.
It, it's so interesting how similar this is to our discussion of MCP in that, um, you know, the, the, this whole idea that, uh, cloud native applications can and absolutely do spin up and, uh, then destroy, uh, containers that are basically, I'm gonna call 'em agents, uh, you know mm-hmm. Microservice could have, could be an agent. Absolutely could be.
And uh, you know, that they create these agents that they run an something on them and then they destroy the container afterward. Um, it's the same challenge. Uh, and I do like the idea of, you know, kind of turning it over on its head.
It's kinda like what I was talking about with NetApp and their MCP kind of protections by doing automatic AI based data classification. The idea of using ai, not, you know, it's not like running AI applications. It's basically just throwing some AI at the problem by saying, Hey, ai, keep an eye on what's going on in this environment all the time.
Um, it's ac i, I like the idea because it's just another tool, it's another quote set of eyes, even though it's not really a set of eyes, but it's another, um, opportunity to discover something going on in this environment. So, you know, by having AI watch non-AI things, I think that's one of its better uses. Um, I've been pretty excited about, uh, AI assisted firewalls.
Um, I'm pretty excited about AI data classification. I'm pretty excited about, you know, AI assisted security generally because, not, not that it's gonna solve the problems, but that it has a chance, it has a shot of detecting things that we wouldn't normally detect. Um, do you see that too?
I, I definitely do. I think the, for me, one of the differences here is when we think about, you know, AI is a very broad, encompassing term. One of the challenges when you think about an LLMA large language model, it is designed to be non-deterministic, give it the same inputs, and it gives you a different answer when we're doing analytics, which is essentially what we're talking about here, is looking at, uh, a series of data that's repetitive, the same type of data, and really looking for an anomalies, right?
That is what traditionally is called machine learning, but is designed to be very deterministic. Give it the same inputs, it will give you the same outputs. The advantage that machine learning has is that it can operate at a speed and scale that humans can't.
So it can look at a vast amount of data that humans can't deal with in our heads and can do it at very, very quickly. And that allows you to look for, um, anomalies bad behavior or strange behavior over a greater period of time. So one of the things that attackers try to do is they try to operate, um, low and slow, like cooking, right?
Where ACP attacks, right? I'm sorry, a CP type type of tax. Yeah, yeah, yeah.
A CP tax where, where basically you're trying to exfiltrate data, but if you send, uh, uh, you know, a couple packets every second, rather than a couple of gigabytes every second, you might escape notice. And so they can operate over very long periods of time, 30, 60, 90 days before they're discovered. And at that, during that time, they're able to, you know, exfiltrate a lot of data.
It would be very hard for a human looking at the data, the, the telemetry that you have about what's going on in your network and find something like that. 'cause it's literally the proverbial needle in the haystack. But it is something that, uh, machine language, uh, sorry, machine learning program can do.
And I think it's a very good application of AI to look at these vast amounts of telemetry about what's going on in our environment to identify things that shouldn't be happening. Well, you know, it, it, I, I like the promise of where we're going because, you know, we, we've gone from let's do log aggregation, get a whole of logs in one place so we can find them. Let's put 'em all into one system so we can do analysis and application performance monitoring.
Let's put more sophistication to it and, and have observability. So we could do more analytics on it and connect the dots across, uh, the organization applications. So the next layer, in addition to AI being part of the solution is graph technology, which is adding context to that.
Um, Hashi Corp announced kind of, they're claiming the moniker of the agentic infrastructure, um, adding AI capabilities into, into what we do with, uh, Terraform. And, but what it's informed by is something called infograph, which is a graph technology that is the state of what the infrastructure looks like. You know, we were talking earlier about code, generating code.
Well, and you use the infrastructures code example, and that's a perfect one. If you're doing it in isolation, co-create this. That's one thing.
If you're doing that in, in the context of a larger system, well, how do I find out what that is? How does AI find out what that is? That gives you a lot more, uh, I think validity to be able to handle the, not only the volume, but the breadth you were talking about, Jack.
I think there's a lot of promise in that, in, in helping solve some of these issues. Well, I'm, I'm glad you brought up sort of the graph concepts because that's something that Microsoft itself, uh, is also thinking about. Um, Microsoft gave a, participated in a tech field, a exclusive event, uh, and they talked about how their integrating, uh, graph, uh, the concept of graphs and graph database into their, um, uh, si their, their sim and their entire security AI security platform.
Mm-hmm. And part of it is that attackers think in graphs, right? They think about, I'm, I've penetrated this particular server or a host or device endpoint or user now from there, how do I, what's the graph look like that I get to the next part and the next part to explore?
Because they don't have visibility into the entire infrastructure at once. So they sort of have to build that out and they think about it in terms of graphs. So if you can build your tools around the same way that the attacker thinks and understand the graphs of how your systems are interacting with each other, it gives you a leg up in understanding what's going on and, and trying to be one step ahead of the attackers.
Steven, how much is graph technology coming up in the vendor events that you're doing with field days? Yeah, we're hearing about it a lot more. And, um, yeah, this, this whole idea is absolutely coming up from sort of people who are i companies that are ahead of the, ahead of the, the trends instead of, uh, you know, sort of looking at things the, the old way.
Um, I don't know enough about it yet, but I do know that we have seen it and heard about it from a wide variety of companies at Field Day. And, um, yeah, I'd be really, uh, interested to see where it goes. Oh, you'll have to get, uh, Neo four J or somebody like that into a field day and, and love to have somebody or anybody else.
By the way, if you're interested, contact Steven or anybody here. We'll, we'll set you up. And I think that'd be a fascinating set of conversations, so.
Well, good. Well, well, gentlemen, it's been, it's been fun. You know, I feel like we were, um, we're, we're missing the, the Allen drummer and, uh, so, but, but we decided to do the Rush Band and just kind of fill in.
So we've got the trio back together just with some new players. So good to have you here, guys. Have a good week everybody.
Thanks for watching today. Be sure in Tech Out, we talked a lot about Tech Field Day and fully, uh, Steven was here. We could touch on them.
com. tv. Fantastic.
So stay tuned. So starting tomorrow, right? Wednesday, what'd you said?
Wednesday, Thursday? Yeah, it's, uh, yeah, Wednesday, Thursday 22nd and 23rd. Very nice.
Very nice. Excellent. Well everyone be ready 'cause we're gonna be talking about agents and CPS and runtime security a lot, I'm sure.
Alright, well be safe out there. And, uh, please check out the rest of the program. We're out here on the Techstrong tv, uh, the great shows and interviews and conversations that are happening, things like Tech Field Day as well.
We, we will talk to you soon. Hey everyone, welcome back here to Techstrong tv. I've got a, uh, new company, first time guest introduce you to let me introduce you to Gabriel or Gabe Bian.
Coney. Gabe is the, uh, co-founder and CEO over at a company called Tensor Zero. Gabe, welcome to Text Trunk tv.
It's great to have you on here. Thank you. Thanks for having me.
Pleasure. So, you know, we're gonna talk about Tensor Zero, but before we do Gabe, let's, let's talk a little bit about you, right? How, you know, you don't wake up at four in the morning and say, I wanna start a company.
What, what, what kind of, you know, what path did you take to co-founding this company? Yeah, so I started this company with my friend Vira that actually met back in college over a decade ago. We, in the same dorm where we were both at Stanford, uh, had gotten to work together since then.
I, I worked at a number of startups most recently. This company called Ono, uh, barrage went to grad school. He was pursuing his PhD and Penn do was actually an extension of some of the research he was doing during his PhD.
He was doing A-P-G-S-U on reinforcement learning. And the main topic there was like how to get machine learning systems to learn from experience in the real world. And as LMS were ramping up back in like 20 22, 20 23, we started asking the same question about LLMs.
How do we get LLMs to learn from experience in the real world experience being metrics from your product and your business being human feedback, user behavior, whatever makes sense in the context of what you're building. And we realized that the tooling that existed wasn't perfect for this, uh, feedback loops for the systems to learn from what they're doing from the consequences of their actions. So we decided to kinda redesign and rethink the stack on they ground up.
And that's how 10 RO came together. Excellent. Now when you say reinforce learning, like, so for instance, deep seek, you know, the Chinese, uh, ai, gen AI LLM model, you know, they, they claim that they did a much better job with reinforced learning and and so was a, they were a lot more efficient in training their model.
Is that the kind of reinforcement you're talking about here? Yes and no. So I, I think when comes to alums, there are different kinds of reinforcement learning at like, also like different stages of the, let's say, pipeline to train a model like that.
If you think about foundational labs or companies like, uh, deep seek, they start all the way like pre-training where they're sending like massive amounts of data to those models and spending hundreds of millions of dollars. You can billions of dollars to train them. But once you have, uh, a, a model that exists, anything from GP D five to deep seek, those models and so on, application companies have to take those models and tailor them for specific use cases.
You can start very simply by just using prompts and prompt engineer and so on. But if you really wanna squeeze the most out of those models, there are a number of different techniques that you might want to try here. Uh, so when we think about reinforcement learning, there are reinforcement learning techniques about like specific techniques you can apply to those models.
But we're thinking about the broader LLM engineering loop. So how do you think about like the whole application or the whole LM system to improve from like the downstream performance? So we do use reinforcement learning, but that could also mean other techniques.
Anything from optimizing the prompts to fine tuning to dynamic context learning and many other buzzwords I can share here. Absolutely. Now, so you got my attention right, because you know, IIII use chat GPT as my main go-to for, for, uh, ai and I've done a fair amount of prompt engineering with it over the months and years now, where it does a good job for me, right?
com and our tech strong it AI sites and, you know, a lot of material there. So that it really, I feel like I'm starting off halfway through the thing rather than at the beginning. And I'm sure there's a lot of us out here doing that, but that's not really what 10 to, is that what 10 to Zero is doing?
No, you're, you are really, uh, training these models or better training the reinforced training for applications that are using them, not, not for people's use. EE exactly. So the end user of 10 zero is typically an LLM engineer or a software engineer or maybe a product manager at a company that is building an AI product.
So in your case, you're already using an AI application like chat pt. But for us it's typically companies that are building their own products that integrated the open AI API or any of the other similar APIs across all sorts of domains. So we have users, anything from, you know, healthcare, back office automation, all the way to, you know, education and tutoring and, and so on, all the way to, you know, compliance in banks and the like, but they're building software systems that leverage those LMS under the hub.
And for that, there are a number of complexities you, you might want to do deal with where you're not manually looking at each of those conversations like you're doing. Sometimes there's quite like high risk use cases, for example, in healthcare and compliance and so on, where it's actually interacting with the real world. So you need a lot of additional safeguards, better observability ability to plug into all the different model providers and the like.
So that's where a, a tool like ten three zero can come in. Excellent. And you're doing this through an open source called an LLM Ops platform.
Talk to us about what that is Exactly. So we have this open source project also called Open Source Zero, which has five major components. Uh, first is a model gateway.
So this unified API that lets you integrate with every major model provider, be that open source or full source providers using the same API. So you can very quickly try the different models as you're using this inference gateway. We're collecting various structured data about those inferences as well as like downstream metrics and human feedback and so on about what happened there.
And with that, like providing both observability so you can really understand what happened there at the microscopic and macroscopic level, but also curating data sets that you can use for optimization workflows, be that optimizing your prompts, optimizing the models, running reinforcement learning, and so on. And finally, uh, once you're, as you're iterating over the system, we can do evaluations of sanity checks that things are working as expected before you put that in production. And also experimentation.
Once it is in production, we can ab test different choices of models and prompts and parameters, and I like to make sure it's moving the needle in the right direction. So basically, once you have this whole stack in place and it's all open source, you're, you basically have everything you need to, you know, uh, try all the different models, see what's happening with them, iterate on the prompts and models and so on to make them better, and then send it to check and confirm they're working as expected and, and moving the needle in the right direction. Very cool.
Very cool indeed. Um, let's get some housekeeping out of the way. com, not, not the number zero.
Um, and then Gabe, how do, how do people engage with you? How do they get started here? So it's fully open source.
So most companies will go straight to GitHub and try the project, follow the quickstar and tutorials, and a lot of companies use it without ever having spoken to us. We're also very happy with support, so we have channels on Slack and Discord and, and social media, so very happy to answer your questions and help with onboarding and so on. We also have a number of design partners or companies that we work very closely with to, you know, take on feature requests, provide support and the like.
So this can really vary on, on the user here. If they just wanna try it out and not talk to on anyone, they can just go to GitHub and download it. Uh, if they want help, if they want support, very, very happy to chat it and support it on this journey.
And, and what, what's the commercial model like? We're pre-revenue right now, so we're fully focused on the open source. Oh, just fully open right now.
We, you know, we're getting users delivering delight. I imagine at some point there might be a hosted version or some premium features or something like that. Yeah, that's great.
How long have you been at this? Well, I works outta your part, your co-founder's PhD in 2223, you said? So it's been, Yeah, so pretty much we started the company, uh, beginning of last year, and we launched open source about a year ago, so we just turned one for the open source.
Very cool. And, um, are you pre, do you pre-revenue, obviously? What about pre fundraising?
No, We, we recently raised, uh, a seed round, so we raised just over $7 million, uh, which we're very happy about. And that's A very healthy seed round. Congratulations.
Yeah. So this will support no continuing to accelerate the, the engineering and growth for the project and starting to grow the team now. So early on was just me and my co-founder, now we're six people and they go through, hopefully get to 10 or so by the end of the year.
Excellent, excellent, excellent. You know what, it's good to see, and, and I love the open source model here, and it's good to see there's so much going on in AI and there's so many different aspects and facets of, of how we are going to do this. Here's something that I think everyone out here can wrap their head around and with a, a really sane business model, right?
Of sort of your traditional open source was delivered to light and then, you know, go from there. Um, so Tensor zero is the website, it's available on GitHub as well. Is there a GitHub?
com/tenor source or something like that? com/tenor zero. And you, you can find the whole project there.
It's all open source. Yeah. Tenor zero, excuse me.
Well, Gabe, I wanna wish you the best of luck. Oh, thank you. Now with tenor zero, this is isn't an interest.
You know, it's funny, I, I'm in our studio here where we have three different, well, it's a sound stage, we have three different sets. So I was, I came here from the Textron Gang set down the studio there, and, um, we were just talking about sort of, you know, there's a feeding frenzy right now. I'm building data centers and I'm going to use your chips and you'll use my chips and you'll put your stuff on my chips and I'll put my chips on your stuff and all of this.
But what we're looking for is the next growth phase, the next evolutionary stage where, okay, you, you've got the, the data centers and the chips in that infrastructure and you know, you have these frontier models, but now how are we going to that next for every med, for every company? And it's not just going into chat GT five or philanthropic quad four or whatever it is, it's really customizing, you know, for your needs. So this, this is that next gen.
Good for you, Matt. Congratulations. Thank you.
And I appreciate that. All right. Gabriel Biancone, CEO co-founder of Ted Soze.
That's T-E-N-S-O-R-Z-E-R-O here on text Drunk tv. We're gonna take a break. We'll be right back.
Hey everybody, we're back at Atlassian Europe and we're talking to my good friend Andrew here, who's the customer, CTO for the Atlassian Williams F1 racing team. Andrew, welcome to show. Hey, Mike, thanks for having me.
How did this whole relationship between Atlassian and Williams come about? And, and, and, and why Atlassian and how did you guys like decide that Williams was the team to be? Yeah, so, um, earlier this year we signed on as a title partner and technology partner for, uh, Williams Racing.
Uh, and, uh, initially we, we were having a look at many teams and, um, it was clear that Williams had a great culture. They were, um, on the, a similar journey to, uh, to the top. Uh, we felt like we could support them in getting there.
Uh, and they really felt like teamwork and technology was gonna be the key to help them get back to the top of the grid. And when you're looking for better teamwork, who do you come to, I suppose? So what were they using before they found you guys, and what have you done as the technology partner to upgrade their environment?
Yeah, so, uh, if you look at the history of Williams racing, they haven't really invested too much in technology, uh, in terms of knowledge, work, technology, uh, over the past 10 years. Uh, and so they were using a variety of, of different tools. Uh, however, if you look at the different software, the different collections from Atlassian, uh, we are leaders in, in every market that we play in.
Uh, and so we came in and we had a look at, um, how are they working? What kind of products are they using? How could we help?
Uh, and so we've started rolling out our teamwork collection there, uh, and they re uh, Williams are really seeing a massive uplift, uh, as a result of that. Yeah. So are they wor, are the engineers working differently now together?
I mean, you know, gimme an example of what they're doing that they probably weren't doing before, or should have been doing before. Yeah, I mean, uh, a good example is what happens at the track. Um, so a lot of people dunno that when a Formula One team turns up to a track, uh, they have a garage.
When you see it on tv, it looks great. It says Atlassian everywhere, lots of shiny cupboards, two beautiful cars inside. Um, but the reality is when a team first turns up there, it's an empty concrete box.
They, they start off by painting the floors. So that's the level of work that needs to go into it. And a lot of people don't think about what does it take to get all those things there and set it up.
Uh, and one of the, one of the things that they were doing we're tracking basically in a notes app, all the tasks that had to be done to set up a garage. Uh, and as a part of that, there are incidents and things that go wrong, uh, that they also need to keep track of. So rather than using a a Notes app for that, which, uh, wasn't really giving them a lot of insights about repeat issues and, and ways they can improve, we transition them onto Jira.
Uh, where now we have a repeat, uh, uh, repeatable cycle. Uh, the tasks are assigned to people when something goes wrong, they're able to, uh, log it as an incident, talk about what's happened, uh, and that way after the race, they're able to go back and see how they can improve and how do they avoid those things from happening again. Uh, an extension of that actually is they can ask Rover at the end of the day, how was the setup today in Singapore?
Uh, and Rover will give a report about what's been done, what's outstanding, uh, how many incidents happened, uh, which really helps, uh, in terms of continuous improvement, How big is the team and is it the same team that goes to every one of these cities where the race is At? Yeah, a lot of people don't really think about the size of a Formula One team, and they're surprised when I say there's about 1,100 people who work at Atlasian Williams Racing. Uh, I don't remember the exact number of people who traveled to a race, but I think it's like 80 people go to a race.
Uh, and so it's not always the same 80 people who go every week to different races, but, uh, they have different teams. So for the, for example, the Garage team that I spoke about earlier, uh, they have, I believe, an A and a B team. Uh, so they're setting up two different tracks at the same time.
Yeah. So how is the team doing from your perspective? Yeah, they're doing great.
I mean, it's been six months since we, uh, started working and we're already seeing massive improvements, uh, in the way that they work. Uh, we've reduced how many meetings they're having. Uh, we've been unlocking knowledge between the different teams, uh, at a, at the, at the race team, uh, predominantly using Confluence and Rvo.
Uh, they're seeing great benefits from using Loom. Um, that was one way of cutting down meetings, but also recording meetings, uh, which gives you a nice summary with nice actions, uh, automated as a result of that, uh, is also paying some big dividends for them. Um, are the engineers discovering anything or they, they didn't know before or are they finding duplicate efforts or anything like that?
Yeah, I mean, if you look at any company they, they problems that happen, uh, in any company where you have people working on the same thing or the same thing in different ways, uh, I think it comes down to a few things. It comes to prioritization and to, um, visibility across what people are doing in different teams. If we, if we talk about prioritization for a second, um, their, their top level goal is to improve lab time.
Now, the thing about Formula One teams is they have a cost cap. And so nearly all the people they hire are trying to contribute to reducing lab time. Uh, and so then it becomes hard to prioritize because everything is contributing to the overall goal.
Uh, and so what they've been able to do using JPD is define what is value for them, uh, what does it mean to reduce lap time. They put all of their ID in one place with all of their data that supports that idea. They can track how much effort something will take and the impact they think it's going to have.
And it becomes a really nice way for them to prioritize what's important for them to work on right now versus something that we can work on a little bit later on. I would imagine that they're also trying to prioritize their own efforts, but a lot of the knowledge you seem to be capturing used to be, you know, what we call wet wear between somebody's ears. So have they kind of figured out that they can now maybe, um, you know, if somebody leaves the team, it's not as catastrophic an event because there's a, the tribal knowledge is captured.
Yeah, absolutely. I mean, um, as a part of the design of the car and when they, when they're doing their aerodynamics, uh, a lot of the information was captured in places where it was only accessible to one or two people or, or a very small group of people, uh, which is problematic when, um, that's the very beginning of a process. 'cause that that information, uh, results in the design, which ends up in the wind tunnel, which eventually ends up as a part of a car.
So there are many people who need to contribute to, um, that process. And so having the very beginning of that process locked away, uh, doesn't enable the, a nice collaboration flow, uh, throughout that value stream. So now that it's being captured in Confluence, it's indexed by ro uh, and people are able, are able to surface the right information at the right time throughout the, uh, the end-to-end process.
And the thing that's different about all this with the AI is that, as least as I understand it, it used to be somebody would stand around with like a clipboard and then capture data and then type it in somewhere that nobody else could access it. Um, now it seems like the AI agent is actually capturing all that data and then sharing it with the team. So I'm not sitting there doing a lot of data entry.
Yeah, I mean, so with, with the Atlassian platform, the, the most powerful thing is actually the teamwork graph. So people don't really have to go too far out of their way to put information somewhere. We try and connect all the different elements into the teamwork graph so teams can put the information where it works for them, uh, and, and it'll still be accessible through the platform and through Rvo.
Yeah, Because I think half the battle we've seen with any application is nobody actually wants to spend time putting the data in there, which kind of defeats the purpose. So, um, are we gonna get the value out of the software investments that we've been making all these years in ways that we never could before? I think there's a different way to think about things now.
Uh, I've been speaking to a lot of customers at this conference, uh, about standardization and why they wanna standardize the way teams work. If you think about what a why people wanna standardize is so that information is stored in a consistent way in a, in a place that people can find it and digest it easily. But teams don't want that.
Teams wanna work in a way that works for them in a way that supports them to go faster and get to their outcomes faster. The beauty of teamwork graph and robo means teams are able to work in a way that goes faster for them, maybe with minimal standardization, uh, but other people in the company can still find that information without knowing exactly where to look and in an expected format. Uh, and so now we, we kind of solve that problem around standardization and, uh, limiting the way that teams work through the use of rvo and the team of graph.
Are they consolidating the number of tools they have? At least I know in my job, my issue isn't necessarily that I don't have a tool. It's more like I got too many of them and I can't quite figure out how to make them all work together.
Yeah, I mean, obviously, uh, they're huge advocates of the Atlassian platform. Uh, and so it's more around enterprise architecture and what products should we use for different things. Uh, and so they are centralizing on Atlassian.
Right. Um, are they playing around with AI agents? Are they gonna build their own or what are you guys thinking?
Yeah, they've built, uh, they've built many different Rover agents. Uh, we had a session this morning where, uh, Richard Slaughter from a WR spoke about, uh, a wind tunnel tapping agent that he built. So he had a lot of knowledge in his head, actually.
He used to be an aerodynamicist. And, uh, he's captured all that information in the platform and built his own rover agents so that he can reduce the number of questions he's being asked, uh, about this particular thing. And people are going to the agent now, he's actually been tracking how many people are hitting the agent, and he counts that as a benefit to him.
'cause all those people would've come to him in the past. Yeah, You hit on an interesting point, right? 'cause there are people who are specialists and they have a lot of knowledge, but I might argue they spend half their time just answering questions from the rest of the organization rather than doing what their real day job is.
So will that change the way we think about general purpose workers versus specialists and, um, the way we might even organize our companies? I, I think about it in, um, this concept of low value collaboration and high value collaboration. So low value collaboration is something similar to what you described, where you have someone with deep expertise, people contact that person to extract information that's low value for the person who has the information, even if it's high value for the other person.
So overall, that collaboration is low value. 'cause only one party gets, uh, gets benefit from it. High value collaboration is, uh, what I think is being enabled through ai, which is, um, they can go to an agent, they can get the information they need.
Then if they need to work together on something, both parties will get information because, but get value, uh, because the person originally asking the the question has enough information to have an informed conversation rather than asking basic questions. Yeah. So at the end of the day, um, am I gonna get more work done or am I just gonna have less stress in my work life, per se?
Uh, I think about it in terms of value, right? Like if we think about the person who is answering questions, that's low value for them. If they're an expert in something, you want them spending as much time as they can working on whatever's, whatever's their area of expertise.
Uh, so I think by uh, introducing ai, we're able to free up that person's time to spend more time probably on the thing they like doing rather than answering questions. If that reduces stress or not, I don't know. Depends on the individual.
Is Williams trying to figure out, you know, how much of a productivity boost they're seeing? Or are they just kind of accepting the fact that everybody seems to be working more cohesively and with less toil and that's the benefit in its own right? Yeah, productivity.
Productivity is an interesting one. Uh, academics have been trying to measure productivity for decades unsuccessfully. Um, but absolutely we're looking at how can we be more efficient?
Uh, so where is their time wastage, uh, in the things that they're trying to do, and how do we reduce that? And that shows up in different ways. Like it shows up in number of meetings or effective meetings, uh, you know, how many emails are being sent, things like that, uh, where we often see efficiency traps, um, showing up.
Yeah. So you've been working with them for a while. What's that one thing that you know, kind of surprised you to discover?
Yeah, actually their culture is very similar to the Atlassian culture where, uh, people are very supportive. Everybody who works there really loves their job. Uh, they're all happy to be there and, uh, they're teams who want to collaborate.
Uh, and so for me, it's an absolute pleasure to be able to enable them to do what they already want to do. All right, folks, you heard in here Atlassian Williams is a winning team, and when they actually win the next trophy, we'll see. Hey, thanks for coming by.
Thanks a lot. All right. Hello and welcome back to Atlassian Europe, and we're having a chat here with Asha and we're having a discussion about strategy collection, which is a set of tools that Atlassian has developed for well changing the way we manage our companies and our organizations.
Asha, welcome to show. Thank you. So explain this to us a little bit.
I know it initially came out at the US conference, but now you've updated it a little bit and it's generally available to folks, but there's, as I understand it, three applications. But walk us through the portfolio a little bit. Yeah, totally.
Strategy collection, first off, helps leaders do strategic planning, also helps you do talent management and helps you track your strategic initiatives all the way down to your day-to-day work. We have three apps in the collection. First is focus, it's our app that helps you do strategy planning and helps you see your strategic priorities in real time.
Then we also have talent and app that we just gad a couple of months ago that lets you do knowledge workforce planning. What I mean by that is you can always make sure the right teams are working on your most important priorities, and we also have the Align app as a part of strategy collection, where your teams of teams can plan and track work and you can make sure that work ladder us up to your strategic priorities. So that's the strategic collection offering that we have, and we continue to add improvements to the collection as uh, time goes on, Right on the face of it.
That sounds almost intuitively obvious, but what were people using beforehand? It seems like, what did they have a bunch of spreadsheets that they were just trying to manage stuff with? Totally great questions.
Guess where most companies document their strategy? Take a guess Word document. Uh, Close Word documents and PowerPoint.
Like when I ask customers, where are your strategies documented? You know, majority of them will say that, which is like, it's in a PowerPoint, but we all know that strategies that go into PowerPoint end up becoming shelfware. I kind of always joke that they go there to die.
So that's where the focus app actually comes in. It helps you convert like a static plan into like a living, breathing strategy. So think, uh, you are a company, you have a couple of line of business units, so each of the business units can have their own strategies and then the departments under can have their own strategies.
And then you have execution priorities under, so focus lets you map the entire strategic planning hierarchy in the app. So you no longer have to worry about it being dead in a PowerPoint or a spreadsheet. It's always tracked in real time.
And that's kind of important because at least in my company, the strategy kind of continuously evolves and communicating that to everybody is often difficult. And then they have to align their department strategy. So as part of the whole effort here, some way to kinda streamline the communications of the intent of the strategy.
Yeah, totally. And also track it in real time, which I don't think like a customer of ours said this really well. Um, for example, Lloyds, let's say where they say there's not another tool where you can actually track your strategy, your goals, and your work, as well as the funds think budget all in one place.
It's the one collection that lets you kinda manage the entire portfolio. Mm-hmm. And at least in my experience, we don't always know who we have working in the company and what skills they have and what expertise they have.
And sometimes we go out and hire somebody else when we already have somebody who has that skills and expertise. So as part of the exercise here, just to manage my talent better. Totally.
And that's what the talent app does, right? So think about your traditional HRIS tools, which are amazing, but they give you job title org structures, all valuable information, but not real time information and not what projects they're working on. So none of the HRIS tools have the work and the people mapped to the work.
So what talent does is it maps every person in there and what funds does, is it actually, sorry, what focus does is it manages all of your projects or your initiatives or your strategic initiatives. Now you can see your talent mapped against the initiative that's in funds. So that's what strategy collection lets you do.
We've been talking about AI all week here. How will AI get applied to all of this and what should people kind of expect going forward? Yeah, like you heard in our keynote, RO is also in strategy collection.
So RO helps you bring insights. It also gives you like predictive recommendations and the system and strategy collection where it helps leaders basically figure out what is the next action that they need to take if they figure something is off track. So it helps you summarize as well as give you predictive insights into what you have to do next about it.
Yeah. So will I be able to, I don't know, ask Roe, which projects that we've funded that are not aligned to my strategy and therefore maybe I might wanna reallocate those resources to something else? Totally.
So what Roho will let you do is it'll kind of say, Hey, these are the initiatives that are off track. Mm-hmm. And it'll help you identify smart recommendations as well.
So for example, it can tell you, Hey, this initiative is off track. And to bring it back on track, you may need to add senior engineering talent in US West, let's say. Then you go into the talent app and you can filter down for the very first time on, give me all of the senior engineering talent that's in US West, and the talent app will narrow down that list for you, and now you can identify what focus areas are they working on.
If all of those focus areas are on track, it probably gives you an opportunity to say, I'm gonna identify some people and bring my other initiative back on track. So that's the beauty of strategy collection. The other thing that business leaders routinely struggle with is there's dependencies between projects.
And so suddenly I think that, you know, these projects are moving along, but then I discover that there's a bottleneck because this other project is way behind and nothing's gonna move forward accordingly, but I never know that until it's too late. Can I see that now? A hundred percent.
So we have a app called Jira Align, like I was saying earlier, that's the app where across your enterprise you can do work planning. So that particular app has dependencies and ask in there as well. So you can see not just your projects, you can also identify what is the dependency that each of the projects have on each other.
And then ro on top of strategy collection helps you draw insights, um, which make all of our leaders a lot more intelligent. So I kind of always look at it as Atlassian's mission is unleash the potential of every team, and I think of strategy collection as unleashing the potential of every company. Ah.
So what does it take to get started with all this? Because to your point, I do have all these PowerPoints and spreadsheets and Word documents. How do I get from there to this strategy collection that you're talking about?
Do I import all that stuff that I already have or do I gotta reenter it? Or how does that all come together? Yeah, totally.
Um, our vision ultimately is that VU one day helps you just upload all of your PowerPoint and spreadsheets or wherever your structure is, both of like people as well as the strategic priorities that I'm talking about. And the product, you know, during the onboarding phase helps you set it up. But for now, you can also choose to kind of manually set that up.
So as we onboard customers, we actually work with them on what is the structure of their company, so what are the lines of businesses they have, what are the portfolios under each one of them? What are the biggest strategic or marquee projects as customers call it, that they're working on? And then we also ma the work in Jira to each of those initiatives.
We then help the leaders identify their goals and they can set up goals against each of those initiatives as well. And then the product tracks that end to end. And then VO on top of it helps you give insights.
Every company that I know has owners and investors, and there's usually some sort of quarterly meeting where we all get ready for and we give these giant preparations for, and, and we, we spend an inordinate amount of time getting that together. Will that become easier? Because it sounds to me like all those documents are now living documents within your system, and I can be ready for that meeting in a couple hours.
A hundred percent. I promise I didn't plan this question, uh, but totally. So what strategy collection lets you do, and we do this in Atlassian.
So we run Atlassian off strategy collection, like I was saying earlier. So every month in our monthly business review, all the leaders in the respective portfolio put in their updates on what's working well, what's not working well, how are they tracking against the portfolio's goals, and we actually run our monthly exec reviews of the product itself. So that's how we have been running Atlassian on Atlassian on strategy collection.
And most definitely it gets easier because now these are not documents that are one and done and they get lost in a shelfware. You can track progress in real time. And more importantly, I'm also excited to introduce, we have strategy events within the product.
What that means is every quarter, or it could be every half, or it could be every year, depending on the planning cycle for the company, every company looks back, let's say at the last quarter, which I always call as an inspect phase, and they adapt the next quarter or the next half or the next year. So what strategy events lets you do is every portfolio, or every leader or every unit leader can make proposals that cannot get tracked within the system, be it proposals for change in headcount, change in goals, change in projects, and then the leaders of the company can decide to approve or not approve. So even the quarterly planning has gotten a lot more structured and efficient with both strategy events as well as the product as a whole.
Yeah, The only other activity that's similar but even less fun is a lot of organizations are public and they have to deal with auditors and all kinds of folks come through. Is that gonna get simpler too? Because all this stuff is already organized and kind of easier to present?
I would definitely argue that strategy collection is the organizational capability that you need to help yourself get organized to lower the leaks in the system, and most importantly, unleash knowledge and insight. So you kind know how is your company's operating model actually working? Is the company efficient, not efficient?
And like our sharing with the fund's view, you can now track budget or suspend too. And when I say spend, you can truly understand how much of your spend is in change the business versus run the business. You can double click into your spend into labor and non-labor costs, as well as double click into your labor spend so you know how much of your spend is in product versus data engineering versus let's say marketing versus sales.
So it gives you insights and visibility that you have never had before. There you go. Hey, folks, you heard it here.
Running companies is stressful. There's no two ways about it, but it could be a lot less stressful if we had different software to manage the workplace and everything that goes with it, including the talent. Asha, thanks for being on the show, being A pleasure.
Thank you all And we'll be back in a minute. Your Edge Fleet, your Edge project, you need to make this successful because you're investing a lot of money in it, not just today, but tomorrow, next year, and probably five years from now. Join us on this special episode of the Tech Field Day podcast as we talk with a session from zaida and also Guy Courier.
Welcome To the Tech Field Aid podcast, where we bring together a group of IT technical experts to discuss a single idea around key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and it's often recorded in association with one of our events. Tech Field Day is part of the Futurum group, and this podcast is also published on our sister company site Text Hong tv.
On this episode presented by Zaida, we'll be discussing the premise that without Fleet Lifecycle Management, your edge projects will fail. Before we start the discussion, let's meet who's on the panel today. Uh, hi, I'm Guy Courier.
I'm an analyst at the Futurum Group. Um, ai, AI infrastructure edge, um, as well as, uh, some of the things that fuel, fuel, those like chip sets, containers, and so forth. Those are my areas of coverage.
Hey guys, I'm Sachin Vasudeva. I am the VP of product here at Zita, and I am responsible for driving the product strategy pricing as well as driving the portfolio around Edge AI as well as management and orchestration solutions. And of course, I'm Alistair Cook.
I'm an event lead here at Tick Field Day. And what to look at the kind of context of edge deployments and some of the things that make edge deployments quite different to how we might sort of view things. Sometimes we view, uh, edge deployments as an, an edge projects as being a, a cross between being a, a cloud platform and being, uh, like managing a fleet of laptops.
And while it has elements of both of these it's own quite unique complexion, there's projects to deploy, uh, intelligence and, and applications out to the edge are very different to giving a a, a group of traveling salespeople their laptops or using cloud services. We have near infinite resources available in front of us. Um, one of the other elements on this is that that edge deployments tend to be characterized by a huge number of very small deployments.
We end up with devices at every branch or attached to every oil well or to every, uh, ship that we have traveling around the world. And that, that, that's, um, lots of small deployments is very different from dealing with clouds that are, that are massive. And so things that sort of make sense in the public cloud and make sense if you, you have a, a small number of laptops that are in the hands of skilled and experienced staff don't necessarily translate to where you are putting a whole lot of devices out in hostile locations with potentially staff who really don't care about those devices at all.
And, uh, but makes things quite difficult as we scale and deploy these applications. And particularly as we're running these edge locations for longer periods of time, as day two, operations start to dominate. What we're actually doing, uh, moves, ads, changes to the applications, setting these things that are out at the edge.
UHS is you are working with customers, particularly those who are adding functionality like the AI that you're focusing on. Um, what are the sort of challenges? Are they, they hitting with managing their fleet of locations as changes have come, come in?
Right? Uh, there's actually quite a few challenges that we are seeing, uh, especially with, uh, AI coming more and more, uh, apparent and, and, and more organized and more structured first, uh, and foremost, you know, so fleet management is about managing total cost of ownership of your devices, the lifecycle. And, uh, that includes also the, uh, not just updating this office stack, but also updating the applications that run on these devices.
So the, with ai, what's going on is the, the applications are iterating faster. They're AI models that are coming around, uh, with, with newer technology, uh, you know, interfaces, um, without even talking about gen ai, if we take the classic machine learning models, they are, uh, now starting to be fully commoditized. And so we are seeing the, uh, challenge, uh, of taking and packaging these models in a way that they're lightweight and they're easily deployable.
Second, uh, the version management of these models, uh, becomes super important across the fleet. Uh, you might have different versions deployed for different application types because one version sort of exists and continues to operate as it was trained, but another version might be required because, um, you know, uh, the data has changed for a particular region, for a particular site. So within the fleet there, uh, you know, there are, um, parts of the fleet that will require, uh, you know, the, the sort of, uh, model management, uh, to be different versions version.
Uh, so packaging will change accordingly. Uh, uh, the, the ability to then coming back to like back to lifecycle is automation, right? So how do we easily drive, uh, uh, changes that are maybe driven by the IT team for security purposes, but the OT team, uh, does not want to apply the change right away.
So there's a, a, a management, uh, for the edge when it comes to feed management to actually hybridize this IT OT bridge and make sure that, uh, there's a right level of approval that's built into this fleet orchestration solution as well. I think that, um, when I think about, I mean, this is really good insight, uh, sien because when I think about, um, let's take the word fleet out for just a second. When you think about managing, um, edge applications to start with, there are at least three basic dimensions to this because there's the management of the physical device and, and its physical environment.
Um, there is management of, uh, the payload, um, and then there's, uh, management of, uh, uh, communications, uh, whether it's, uh, it could be a data collection device or it could be a data utilization device, um, uh, you know, a drone or something like that. Uh, data utilization, just meaning, uh, the application performing, uh, functionality of some sort in the field. But when you add AI into this, um, that creates an added level of complexity and, and variation.
The variation of, I mean, you talked about machine learning. There's a certain amount that can and must happen for disconnected devices in the field. There's data collection and training back in the core that's required.
You might wanna do pre-processing for that. So, so, um, the, uh, the relationship of the ultimate application to the ai, um, is an added area of management. And it was helpful to me for you to open up this idea of the provisioning and the payload and the application and versioning position in the lifecycle.
That also all needs to be considered part of fleet management as well. And I, and I suppose, and this might be my question back to you, Sachin. Um, I suppose that, you know, part of the game here, uh, for customers is to understand where they need to focus.
Because you, you, you can't focus on six things. You, you need to focus on, on the most important elements of that, that that management part of it that comes after development when you're on day one and beyond. Is that, is that right?
And what sort of shape does that focus take? How do you advise your customers where to focus? That's a, uh, that's a good segue, right?
So back to sort of, um, let's, you know, when we talk about fleet and lifecycle, right? All these, uh, um, words are sort of interlinked. Let's talk about the lifecycle and the anatomy of an AI application, right?
Let's start there and then, and then we can talk about the focus that we need customers to sort of really put energy on. So first and foremost, um, you mentioned, right, there's a, there's a training that happens. Uh, there's data that's involved, right?
All of that can happen in a centralized location where all of the centralized data lake, uh, is connecting all this info. Um, and once this training has occurred, however, there is a, a need for the customer to take this package it in a way that it's lightweight, so it fits the edge form factor might be deploying this on a small, sort of, uh, Nvidia Jetson based platform, which has, uh, you know, limited, uh, resources. Or we might be deploying this on a high-end GPU AI server, which has a, you know, lot of resources.
So, so there has a, there has to be a deterministic or there's a determination on the resource at the edge. And, and ideally, you don't want to think about it at the time of, you know, thinking of deploying this. So ideally you want to sort of push that decision to somebody else, like where does it go in a consistent way?
And if the resources are not available, what happens then? Uh, then if you continue on the lifecycle, right? Once you move into a deployment, then there's monitoring, which is, uh, observability.
You know, how is my application performing? How is this AI model accuracy? You know, is it up or down?
Is it data drift? Uh, to your point, right? Data collection has to occur.
Uh, typically that, um, ecosystem is driven by, uh, data collection, not at the edge, but data collection all the way making data, making its way all the way back into the cloud. So there's an office cost to pushing data all the way back and then figuring out if the model drift occurred or not. So, uh, let's, uh, take this apart, right?
So on the deployment side, uh, the, um, identifying the target, identifying the right environment, and then packaging it to the right form factor, and then monitoring means, um, maybe collecting the data at the edge and then having, you know, something to do with retraining the model at the edge. Uh, those become sort of really sort of big drivers for driving this. So now, um, what we are starting to talk about with customers is their focus needs to be on the model itself.
I mean, they have the domain expertise on the business logic that gets attached to the model. The model is doing its bit, which is the inference part, but once the output of the inference comes in, right, they have to bring, bring some post-processing logic that helps, uh, you know, conclude to certain business decisions that happen either at the edge or happen maybe centrally. And so, let's, uh, help you, Mr.
Customer focus on solving those problems within the application and take the rest of the application challenges around packaging, deploying, fitting it to the right form factor, observing or collecting data, uh, leave it to, you know, an infrastructure provider to help you get all that info, uh, so that you can actually come back and then decide whether your model actually worked properly, whether you able to glean the right information to make the right business decision, whether you can automate around it deterministically, or whether you need to continue to sort of iterate and, uh, and continue to, you know, uh, what we call test, uh, and, and deploy and iterate, right? So, and, and we know with ai, uh, iteration in testing, and you know, what we call AB testing is, is the norm nowadays, right? Because a single model doesn't fit all use cases, whether it's overfitted or unfitted.
Uh, but, and so, so you know, these, um, so focus on the business logic, focus on the outputs of these models, and let us take care of the rest. I mean, it starts to get really interesting when you're thinking about variation, um, based on local conditions and, and learning and, and, and maybe some sort of, you know, automated or, or, or not fully automated iteration and versioning. I mean, that's like the mother of all forks.
I mean, uh, that's not necessarily something that, uh, that, that it's, it's the sort of thing that can give a customer pause. But it sounds like Aida's point of view here is that there are certain elements of that that are more technical than domain related. If you're an ag or if you are in energy, um, you wanna focus on, um, you know, uh, applying your, what you call the business business, I think, business rules.
But it's really about how you're operating your company, what your go-to-market model is in energy, in ag, um, and, um, certainly focus AI development, data management and all that sort of thing on that domain. And Aida's point of view is there's, there are technical elements of this that can and should be handled by provider tool software. Yeah.
Is that right? That's absolutely correct. I think one of the things I wanted to hit on was quite a lot of what you've talked about, sachan is true for people who are doing AI deployments that are not edge deployments, that are doing this in, in their own data centers as well.
A lot of that, that same process goes on for a deployment in your own data center, but that's quite different from where the actual business logic is being applied at hundreds of locations spread around the world. And that decisions need to be made locally inside each of those locations for speed and cost reasons. Uh, and particularly one of the things we see is the intermittent connection of some of these locations.
And that adds another dimension that maybe the, the model that we believe is our, our best, most accurate model is only in 90 of our a hundred locations, because 10 of them have been offline during that update, and maybe two of those were offline in the last update as well. And this is that, that perspective on fleet management and wanting to have policy-based management across it rather than having to manage every single site individually. And I think that's really where you're talking about handing off this responsibility for the, essentially providing a, a platform and an infrastructure layer in a consistent and predictable way.
I think that the difference between doing this in your own data center to doing it across lots of potentially intermittently connected low power locations is what's really different in edge deployments versus cloud or on premises. Yeah, that's a, that's a great point. And, um, two words come to mind when, you know, we talk about these two items where you start off in this centralized mode of operations, and then you're trying to really deploy something at the edge, which has different constraints.
And you may not have tested for it, you may not have thought through all the implications of it. Um, so quantization and optimization, right? So, so we believe that, um, that is a significant effort, uh, in, especially as, as the edge, as you're aware, there are a variety and diversity of platforms out there, right?
So, and, and we know there's a constant sort of, um, uptick on the number of, uh, systems or platforms or chips we are seeing now in the market. So, you know, for example, Nvidia is pushing, uh, the Jetson infrastructure and the Jetson chip, uh, platform, and it's actually revving, its super fast. So, you know, within, uh, a couple of years, we've already seen, like within this year, we've already seen two versions, two variations come out.
And, and the last one, the Jetson Thor was based on the Blackwell GPU, but that's not alone, right? I mean, you've got Qualcomm with, with, uh, with their NPUs, and then you've got custom chip makers, um, um, like Halo and, you know, with TPUs, and then you've got the hyperscalers bringing their own flavors of the chips that they're also building, which they might wanna, and also push towards the edge. So we are seeing a plethora of all these systems.
And, and so when you start thinking about quantization and optimization, you have to think about the common el, common el, you know, elements that exist from an infrastructure point of view to help you deploy this in a consistent way without worrying about, um, uh, you know, getting, uh, a hit on your accuracy or hit on your performance. Now, um, it is a tough problem. It's not an easy problem, but, you know, we love to like try to like address this in a, in a way that we can address it, uh, one step at a time and, you know, ensure that we can actually move towards some level of standardization.
Uh, there's a lot of open source efforts going on towards taking the work that, uh, is being done, um, for one specific chip set maker, and then bringing it as a generic, uh, you know, approach to inference, for example. And inference engines are, are sort of, you know, um, are taking on that the open source community is taking on that effort as well. I wonder though, uh, if I, I rather feel like this is an issue that's not talked about much in edge, um, and maybe it's because it's a non-issue, but that's diversity of, of platform, uh, meaning hardware platform, meaning edge device platform.
My, my general sense from talking with customers and, and especially, uh, application managers over the years, um, because this has been going on for a long time, including AI at the edge going on for quite a long time, is that, uh, any one application actually can have several different types of edge devices. Um, it's not just a question of architecture, it's a question of size, rugged, non rugged. Is it a, does it have a human interface?
Does it not? Is it collecting, is it, in other words, is it, is it mobile or is it fixed? You know, what kind of connectivity that single applications have, diverse hosting environments, and, you know, I'm sorry, but you know, I, I don't see K two s as really solving this.
I don't see anything solving this other than, uh, a way to, I, I'm gonna use the word centralized, but I just mean sort of in a virtual sense, centralizing development, so that there is a way to develop one application, but that can have its various functionalities deployed into diverse, um, onto diverse hosts. So, so I, I just wonder if, you know, from, from the analyst perch that I sit on, if that's just me speculating or if that's actually a reality, and if so, why isn't it talked about more? So it's the same idea that, you know, um, a lot of companies in the networking space talk about when they built, uh, hardware abstraction layers, right?
The hell. So you're right, uh, at, at some point, you know, when the rubber meets road and you're actually trying to bring a hell that actually works on a specific platform or device, right? Uh, you've gotta make sure that it actually works, end works end to end.
So it's the same concept for us, right? We, we will handpick a few that are most predominant in the industry and start with them. And then as, as adoption occurs across, you know, other, uh, players and emergent or existing players coming in, uh, and, and so customer driven, right?
Adoption, then, you know, we'll start to address it as part of, uh, this, uh, this notion of a hell or this notion of an abstraction interface, which, uh, starts to abstract it. What we are, what you are correct about is that, uh, we would have to pick and choose. Sometimes, you know, sometimes it's not feasible, you know, the portability is a, is, is a, is a desired sort of inconsistency of workflow is a desired end state.
But, you know, for some applications we may never achieve that. So especially like where we, we are seeing a very diverse, uh, set of, uh, applications, but I think our, the vendors we're working with are also trying to address that. So HMI related, like where you have touch screens, uh, the apps are gonna be very different.
There's gonna be a lot of sort of, you know, um, um, interfaces, uh, that built in around the touch screen and the actions, and then versus, you know, an, an industrial pc, which is not, uh, you know, looking for that interactive mode of operation. So, uh, we do, you know, it's, it comes back to the anatomy of, uh, of the application itself and what you're trying to do. Um, you know, and if you break it down into a series of microservices with accompanying models and accompanying data for managing drift, uh, we can argue, yeah, we, you know, how we then package this, uh, whether there's a UI or not UI component or not becomes an interesting conversation to your point.
Um, but yeah, I mean, the, the, the model will certainly have a dependency and the runtime of the model will have a dependency on the type of hardware you deploy. That that Is, yeah, that's, that's the real, I mean, Alistair, you, you, you've lived that, that it's the, these, these reference platforms and everything, they just sound really great when you're in buy mode. But then when you're in use mode, that's when you know, you have the company breeding down your neck and, and yeah, setting off your beeper in the middle of the night, right?
There's, there's also the element that your edge, each deployment is not gonna be a rip and replace everything when there is an update that you'll end up as, as you said, with the diversity of hardware, even if you have multiple sites that have exactly the same requirements as the same application set, you may have one site that has hardware that's six months old, another site that has hardware that's four and a half years old, and managing that diversity, making sure that we're not pushing down a model to that old hardware that is so, uh, heavily quantized, it'll fit on the hardware, but no longer produces a useful result. There's absolutely some challenges around fleet management across that diversity and, and then flagging back to the hardware lifecycle as well as to the application. And the, the infrastructure underneath the lifecycle of these things are all tied together and driven changes driven by the business need.
But there's a very high change for, uh, high cost for changing the hardware at all of these each locations compared to trying to shoehorn whatever application we can get into the hardware that's already there. Uh, this is what leads us to four and a half year old hardware sites, because it's sitting out in a, an Alaskan mine, uh, and it's just monitoring as, as one of the, the examples I've seen is monitoring a conveyor belt to see if one of the staff has, uh, gotten onto the conveyor belt because they're, hmm, not in good working condition, uh, the staff that is not the conveyor belt. So yeah, that diversity is a challenge That that is exactly right.
So, uh, you know, there's a promise of, of an abstraction and a reference, uh, you know, uh, platform. But the reality is there's diversity to manage, and it becomes half process and half technology. So, you know, so yeah, one of our customers, uh, you know, has more than 18 vendors.
I, I don't think, I don't think customers are asking for this problem to be eliminated, but that's what vendors are offering. We have this magic potion that's gonna eliminate this problem. I think customers are looking for a way to rapidly and relatively simply respond, be responsive to these scenarios and situations.
A node goes out, they need to be able to do something about it, um, in a reasonable, because, you know, as they say, stuff happens. Yeah. So, so I would argue that, uh, for ai, right?
It's wild, wild west. So, you know, and so there is some level of standardization that can happen. Uh, for example, you know, the inference engines, uh, out there like open vino inference, you know, uh, the, uh, your, uh, tensor RT or, you know, like the new Dynamo or, um, on nx, right?
So, so, so we will see some level of settling and, and our customers asking us, well, tell us upfront if you are comfortable driving on nx, then we'll align to on as a format for packaging. And so there is that level of conversation also happening at the same time. So, so I, you know, while, while there is no magical cure for, for the diversity of hardware, there's definitely a, a a, a runtime that can be, uh, you know, the, the format, uh, for example, could be agreed upon.
It could be an agreed upon. It doesn't mean it's, uh, it's an industry wide standard that's adopted, but, you know, adoption and sort of this goes hand in hand. So, so I think if you can agree upon one or two or a couple versus, uh, bring a lot of flexibility into your fleet, uh, management, then, you know, then, then you can really sort of own and manage it.
I think it really frees the, um, the, the, the, um, let's say the device management team too, to respond to, uh, more quickly to, uh, new opportunities, new, not just new applications. I'm thinking, you know, uh, um, you know, entering new fields, new operational zones and areas, whatever it is. I'm, I'm losing my lingo here because I don't have that domain expertise necessarily, but it allows them to, um, to be more creative At, as always on the Tech Field Day podcast, our guests could continue to discuss and learn from one another for hours, possibly days, Frank.
That's probably why we have longer events at Tech Field Day. But I'd like to thank you all for joining us today at the Tech Field Day podcast. And before we go, where can the people watching people listening connect with you and continue this conversation?
com. Um, and, uh, as I attend events and conferences or do, um, uh, shows like this one I tend to post in LinkedIn, that's a good place. And I'm also at Blue Sky at Guy Courier, bluesky, whatever.
com website, um, where you can reach out to the Zita team as well as on LinkedIn. Um, so yeah, happy to provide more, uh, more insights as needed. I'm looking to engage.
Yeah, And of course, you can find me Alistair Cook on, uh, many of the Tick Field Day and Future Insights, as well as on LinkedIn. Uh, do make sure to check out the previous presentations that we've seen from zaida. You'll find them all on the Tech Field Day website.
If you just, uh, go to Tech Field Day slash company slash zaida, you'll find all of the great, uh, presentations from zaida. And so thank you for listening to this episode of the Tech Field Day podcasts, uh, showcasing Adidas Edge expertise. If you've enjoyed this discussion, subscribe on YouTube or your favorite podcast application.
So don't miss a single episode. Uh, do also remember to give us a rating, a very positive rating, and a nice review. This podcast was brought to you by zaida and Tech Field Day, the home of IT experts from across the enterprise and a part of the RUM group.
For upcoming events and more episodes, head to TechDay com slash podcast or view us on text on tv. Thanks for listening, and we'll see you next week. Hey guys, thanks with Throw, we're here with Inmar, apple Blatt, who is the CEO of Token Security, and we're having a little chat about AI agents and non-human identities.
'cause well, we've been trying to manage these things before and we're not so good at it, and it might get worse before it gets better. Inmar, welcome to show. Hello.
Nice to be here. Walk us through this a little bit, but I think people can understand the idea that there are these non-human identities. They're machines, there's software applications, there's more of them than there are humans, and now it looks like we're moving and exponentially increase them with the number of AI agents.
Is that a fair assessment of what we're looking at? Oh, yeah, absolutely. Today, by the way, we have 98% of our identity, uh, infrastructure is our non-human identities.
So it's one to 50. The ratio between human and non-human now that, uh, CEOs and board members asking for, uh, security team to adopt agents and have this AI transformation, the amount of non-human identities of identity or meant automation gonna go even more. And we, we already seeing it happening in, in a lot of our customers environment.
Yeah. So it also seems to me that we're not very good at managing them as they are. So how are we gonna manage 'em when there's gonna be exponentially more of them soon?
Are we prepared? Yeah, yeah. I think that, uh, right now, uh, uh, the piece, uh, we have a lot of solutions for human identities when it comes to non-human.
Um, we, we overlooked that for a while and cloud and our AI really created an acceleration of the amount of identities. So the first biggest, like, I think the, the first challenge is understanding, uh, and, and gaining visibility into those identities, right? Knowing about them, knowing about the risk, and then also understand who is accountable for that.
You have an AI agent who is responsible for that. Uh, so I think those are the first few gaps that you want to tackle. And then also understand how, how to support those, those identities in scale, manage their lifecycle, and, uh, and improve their security posture.
Mm-hmm. Is the risk level gonna be higher? Because, at least as far as I understand it, a lot of these AI agents are going to be somewhat autonomous, and if somebody compromises them, they might take over an entire workflow.
Yeah, yeah. Um, the risk is, is is similar but also different when it comes to, uh, identities of, uh, of AI agents and, uh, agent ai. What we see is that one of the biggest challenges, so historically you have human identities and non-human or workload identities.
So for human, you have, uh, identities that running in a very low scale and taking, uh, actions. The permission is best based on their roles in the organization, right? Then you have workload identities that are deterministic.
It's very hard to predict what they're gonna do, but they're doing it in scale all the time. Now, AI agency is a bit of a combination of the two, right? It's on one hand, has the flexibility of a human, but then the scale and the robustness of, of, of for called identity.
And that create a, a, a, a much bigger challenge to, to manage and to, and to manage their boundaries and se secure them. Mm-hmm. So what is your best advice to folks?
'cause I also think people are kind of, at least historically, they had had one platform for managing human identities and they had other platforms for non-human or, and does all that need to converge now when we have these hybrid identities that are sitting in the middle of it? Or are we gonna have a separate platform for the AI agents alongside the other platforms we're using for other identities? Yeah, so, um, my first advice, regardless to the type of a platform, is to really, um, gain, uh, before running into, um, creating architectures of how agents should interact with one another.
You need to understand what you have, you need to look and gain visibility into all of your agents gain, uh, uh, um, traceability into their actions. Logs collection is very important here. The other thing is try to separate between, uh, regular identities for human regular identities, for workloads, identities, and identities for ai.
Edges don't use singular identity for different actions from different workloads or operations. We see that today, quite often, that you see a human identity that an agent is running on their behalf. That's, that's really problematic when you want to manage those in scale.
So my, my first advice, gain visibility in what you have, have, uh, improve your log retentions and collection in order to gain traceability and adaptability. And the third part is, um, separate between the identities. So you will have a, a, a very good source of truth.
I also can't help but wonder how sophisticated these attacks might get in this regard. Um, today, cyber criminals will steal your credentials and pretend to be you, and they'll hang out for a while, and they'll even start to look like insiders. Well, won't the same thing happen with AI agents?
Somebody will create a fake AI agent that may look legitimate for an extended period of time before somebody decides to actually, um, invoke its more malicious capabilities. Yeah, yeah. That, that's a good point.
Look, today, uh, most attacks are identity based attacks, right? Hackers don't break in, they log in to also be with an, with, with agents. So I don't, I don't think that it'll, the first ways of attacks will be generating those new agents.
'cause you already have a lot of them. They're not monitored well enough and they're not secured. So threat actors now have like, uh, a real, um, good variety of types of identities that are mismanaged that they can, uh, uh, uh, take advantage of.
Mm-hmm. Um, are we waiting for some sort of cataclysmic event to occur before we have to get serious about this? It seems like, once again, there's an emerging technology and the cybersecurity folks are chasing after it again.
Yeah, yeah. Uh, look, in, in the energized space, we see attacks happening all the time. And the market in the past couple of years started to, to, uh, um, be more aware of these challenges and, and, and have, uh, an architecture for that.
I, we are gonna see it part of, uh, agents as well. But what we need to consider is that the pace of adoption is just much faster than ever before. We see Fortune 500 that five months ago didn't have any agents and now have thousands of new agents that's running in their environment because every organization understand that this is, uh, um, um, a business enablement and, and that that could really help them succeed.
And also a competitive advantage. So we will see it, uh, um, being adapted faster. The other thing that I want to mention is that we see a lot of times the security teams adopting agents for them to be more, uh, efficient.
So the awareness for, uh, threats and, and lifecycle management is a bit higher. I just, I don't think it'll be just from the incident perspective, that only then, uh, security teams will start, uh, uh, uh, look for that, uh, for a solution. They're already looking for that.
Mm-hmm. Um, will we need to update or maybe they already have, or the regulations and compliance frameworks that we see. I mean, we have things like HIPAA and all kinds of stuff that's out there, but, um, I don't think we're gonna write new regs, so we just need to update the ones we have for the age of AI agents.
Yeah, I, I, I, I agree. I think that that's, that's the way to go. The, uh, um, I, as I iso and different compliance, uh, uh, and regulations that are well meant for managing, uh, a AI and securing ai.
But I do think that the, um, that the regular regulations that we're following should also consider a worldwide organization adopting ai. 'cause it's already happening. Uh, and also giving tools for the auditors to actually validate some of those, uh, compliance, which I think it's, it is part of the problem when you don't have visibility to those agents, then how do you validate that you are following some of those compliance could be a bit tough.
So we need to update those, Right? So once that one thing you kind of see folks doing today that makes you just shake your head a little bit and go, folks, we might wanna be a little bit smarter than that. Yeah.
Uh, I, I, I think that, that on on one side, we see organization that says, uh, uh, and security teams that say, you know what? I don't understand the threat. I don't, I don't want to, I don't allow any adoption of AI agents.
I actually, uh, uh, also as a, as a CEO of a company, I feel that this is not the right approach. You do need to iterate fast and be, and allowing your business to move forward and support the migration and not just block them. On the other hand, we see some teams that are, it's really the wild, wild west, and there is no any visibility into their agents.
And, and, and that's the other way. So there's always a spectrum, and you want to be somewhere in the middle enable allowing your organization to move fast, but at the same time, uh, um, um, um, have some philosophy and support the phases of their adoption and add controls as you're growing, uh, uh, in your AI journey. The, my, I think that today, the biggest issue that I see for organization is using the same identity for multiple different, uh, actions consumers.
So you see both human and AI using the same identity, and that just can create a, a, a chaos. Alright. And to your point, are we likely to see the rise of what we might call shadow AI agents?
And might those shadow AI agents outnumber these so-called legitimate AI agents? Is that where we're headed? Yeah, a bit similar to shadow it, right?
You had, uh, uh, uh, a decade ago, one of the biggest problem is that organization just adapted a lot of shape of forms of it. That one part of the security visibility and part of their controls. We see that also with shadow ai, where organization are leveraging some AI agents, AI mechanisms, uh, that are not part of their, um, um, framework and how they wanna manage.
So I think this visibility into those all types of ai, uh, agents is, is the first step to go. All right. Yeah, folks you heard in here we're just beginning to understand the scope of the issue.
And AI agents, if you don't have 'em in your organization already, they're coming and well, they're gonna be some of the richest targets out there, so you might want to think about how to secure them now. 'cause if you do it later, it might be too late in Amar. Thanks for being on the show.
Thanks, Mike. It was a pleasure. All right, back to you guys.
Hey everyone. Welcome back here to our live coverage of RSA conference 2025. We are in Moscone West on what they call Broadcast Alley, and we've been doing mostly interviews of people here at the show, and we're gonna do that today.
But really, this is a special edition of our DevSecOps Show, cracking the code, which we do like every other week. Anyway, um, cracking the codes available on your favorite podcast, uh, platform, whatever that may be. Exelon, Textron tv, YouTube's Textron TV channel.
And by the time you watch this, probably our Textron TV OTT channel. So you could watch this on Apple TV or Roku or Amazon or whatever you'd like. The important thing is to watch it on cracking the code.
We explore the frontiers of DevSecOps. Um, and just yesterday we had our 10th annual DevSecOps event here at the RSA conference, and it was about ai, AppSec and app dev. Great, great show.
We have actually some of our speakers here today, were there yesterday. Um, but let me introduce you to today's panel for this episode of Cracking the Code. I'm gonna start to my far right, this gentleman here, Aaron.
Yeah. Hunsberger. Yes.
Aaron is, um, with Check Marks, who of course is the sponsor of our Cracking the Code show, our partner in producing it. Iran, it's great to have you on in person across the table from me. Yeah.
Thank you for having me. Uh, thank you. Uh, I run the product marketing for check marks and, uh, excited about the show.
We are hearing ama hearing amazing things, uh, at, uh, RSA so far. Good. Happy to share them with you guys.
Absolutely. It's great to have you on. I've said this before, Aaron on, and I go back a little while, even before check Marks and everything else.
So it's great to be working with him again next to Iran. This little lady right here is a firecracker. She came to our show yesterday and lit it up at the, on the stage there.
And she was up, she was in the panel with the CIO, the CISO CSOs of Open AI and anthropic and senior Security people from Meta, but she had the most to say her name is Morran Ashkenazi Morran, welcome and thank you. Thank You everyone. Pleasure to be here.
Thank you for having me. Pleasure. Yesterday was amazing panel.
Super interesting to get everyone's thoughts, so excellent. I happy, happy to be here. Tell people a little bit about you.
Yeah, so I'm j ffr, chief Security Officer. I'm within Jfr for five and a half years. It's amazing because we're doing our own journey into the security and we're at a DevOps company, and now the DevSecOps company that's providing a whole solution for the supply chain insecure with ai.
Uh, everything simple. Absolutely. Of course, our audience is no stranger to check marks or Jfr for that matter.
Well, let me introduce you to our third, third guest. Tyler, I blanked on your last name, I apologize. It's all right.
How do you pronounce it? Egypt. Egypt.
Mm-hmm. Tyler, Egypt. Tyler, why don't you introduce yourself?
I Appreciate it. Thanks for having me here. So, my name is Tyler Egypt.
I'm our Vice President of Global Enablement at Check Mark. So I work closely with, uh, enabling, uh, not only the field at check marks, but also our customers and partners bringing awareness around AppSec, uh, and the great capabilities that we have and offer. So, very excited to talk about DevSecOps and some of the advancements we've seen and, uh, especially at this event of, uh, learning more and more about trends across the products.
Absolutely. So let me kick things off. You know, as I mentioned yesterday was our 10th annual DevSecOps Connect here.
I remember 10 years ago, It was like having a wedding where the in-laws didn't get along, right? Yeah. So on one side of the audience sat, the security people on one side of the audience sat the DevOps people.
And I like, I could build a wall in the middle. Yeah, right? True.
You could. They just wouldn't come together. A lot's happened in 10 years.
They have come together. DevSecOps is real. We all realize that we all want to have better code, more secure code.
I've never met one developer who raised their hand and said, I don't care about the security of my code. They all care. It's quality.
They have pride in what they do. Security people, they're the old, and I'm a security person, I should say. We used to say, no one cares about security, but us, excuse me, only we can care about security.
But we realize now everyone cares about security from the highest levels of our companies on down. So we made a lot of progress, but we've also made some mistakes. I think one of those mistakes was like we do with everything else.
We, we took our security tools designed by security people and said, here, developer, Good luck. Good Luck. Enjoy.
Yeah. Well, that, that didn't work out so well. Did it.
Right? No. And and the reason is is they're not security people.
Yeah. So a lot of DevSecOps companies died on the side of the road with that. Right.
And it's interesting because we got two different companies here, check Marks. You are an absec company from the day you were, I remember when Check Marks was founded. Yep.
Mm-hmm. Jfr, you weren't No, you were a developer company and, and a Artifactory. Right?
Right. But you've come, you know, parallel evolution to the same point of what do we need to make developers successful? Yeah.
And so I, I'll ask all of you Yeah. What, what is this magic formula? What's the secret sauce to enabling developers to develop more secure code?
And please don't tell me it's ai. No, it's not. Okay.
It's who wants, who wants not today anyway. Yeah. Who wants to go first?
Tyler, we're gonna make you go first. Absolutely. So we, like you said, developers take pride in their work.
Uh, they want to deliver code on time, uh, with security in mind, but they need to be empowered to, uh, understand the risk that's involved. And they need to be guided and helped with, uh, how they address those, the risks that's created. So we found understanding that developer experience, uh, working in their existing workflows within their existing tool set, um, is extremely important.
So we're not disrupting their flow. We're giving them the right information at the right time. So they're the catalyst to change, uh, and, and improve their DevSecOps footprint at the company.
So we know they're a key part of DevSecOps and the ones that are gonna be driving the majority of the fixes. So really meeting them where they work is a common theme. We've seen, um, more codes being generated by AI and productivity's going through the roof right now.
We're seeing, but that also adds layers of complexity, uh, uncertainty. Um, so we need to really understand, again, how they're writing modern code with modern applications, what risk that presents them, and then let's empower them to, uh, address that risk with the right kind of information and guidance. So that's kind of where we've seen that collaboration come together.
And, uh, yeah, both parties need to work together to make a, you know, advancements within software delivery. So it's, it's, they need more on, I think that, uh, we learn from mistakes. That's, uh, that's something that both humans and we Learn more from mistakes than we do from success sometimes.
And absolutely. And I think that both side understand that we depends on each other. We cannot do that independently.
Security cannot do anything without the right partners to drive it. We can bring the product, but it's a banner of, uh, uh, democratization. Developers need to have the platforms and choose the right tools that will accelerate their day to day and not like find them, like we're, we're talking about like the shift left.
So it need to be like in their IDE, something very natural, very native, not go to a different interface, try to find a CVE, try the vulnerability, try to fix it, go back to the code, go back to the malicious package, go back. It need to be very na natively, not extra work and mean to be very effective. 'cause, uh, by the end of the day, they want to like, focus on releasing a product, a perfect product and innovative feature.
And that's it. They don't care about security. Yeah.
But on the other hand, they do need to like implement that. They need to release secure software, right. Because it's their, it's your code.
You, you own it, you own it. So both side need to come together. So that's, I think that that's the point.
I, I agree. They, they do need to come together and they have let, let's, I don't want to give a false narrative, right? We've made a tremendous amount of progress.
If you were out there yesterday, you couldn't tell who was who, where they were sitting. They're all mixed in. So we've made progress there.
I wonder, it's funny. So you come from the security side, you come from the developer side. When you are talking to security folks, did they say, but you're not a security company, right?
And vice versa. Well, you are not a developer tools company. You're a security company.
How do you get credibility across the aisle, Aaron, around any thoughts? Of course. Uh, so I think, uh, and you mentioned like 10, 10 years ago and now, okay.
I think that today you're no longer working in silos. Okay? So it's not you developer, US security, they all have the same objectives of releasing high quality software highly secured.
And what is changing is the scale. Okay? More pipelines, more development teams, higher, higher sized developer teams.
Uh, and these guys need to trust what they're using. Okay? So the word trust here, I think is a key word, because these guys, whether it's, uh, they we're the head of a security or developer or quality engineer or platform engineering leader, they need to have the trust in their tools that will get them towards their objectives.
And their objective are the same. Zero fibers in production, higher security. Because we know that these guys are dealing with, I dunno, 60, 70, 80, sometimes 90% of open source code.
Most of the code that they're using is not even theirs. Okay. So if they, maybe they don't trust the code that they're using coming from others, they should trust the tools that we are giving them with check marks, with J Fog that will get them towards, you know, uh, the finish line successfully.
And another keyword is trust and continuously, right. Okay. What you see today is not what you see tomorrow.
Every, like, the minute, the minute I'm speaking with you here, Ellen, someone is working on a new malicious package. Right? Right.
So, uh, it's a moment in time if you like Miranda. Any thoughts on that? Yeah, I think that, uh, totally agree with you.
It's about the speed is just, uh, something that we cannot control anymore. It's just, it's, it's there. It's running super fast, and you need to have like, automation as part of it.
So that's the part of the lifecycle need to go grow and fast. Therefore, it's like different motivations. I want the security, I want the product to be super secure, and r and d want it to be fast, and we need to collaborate to make it, to make it happen.
So it's different motivation, but single target to get this done. Uh, and it's okay to have like different motivation in order to, to make it happen. Definitely.
Yeah. I want to talk about another DevSecOps principle that I think has undergone a big change. Yeah.
com 20 14, 20 13, actually shift left. Everything was shift left, right? I gotta tell you the truth.
I'm of the opinion now, you gotta shift everywhere. Mm-hmm. But what do you think about shift left as it was, let's say eight, 10 years ago versus today?
I think it has been changed because we understand that it's not just the shift left, it's also shift right to the runtime shift up to the cloud. Yeah. It's like, like Shift out to the Us, turn around and around.
It's all over. That's the, it's w wrap. Yeah, it is.
And that's the security mission. Now, Every chain in the, in the lifecycle. Agreed.
Right? So I think we've recognized these things and, and they've manifested themselves into tools, security tools that are easier for the developers to use. Built into the IDE for your instance, I know check marks they made, I think you made an announcement here at R-S-A-I-I got the, uh, yes.
We embargo. Yes. You're building, uh, into IDE.
Correct. So we've had, uh, integration in the IDE on understanding risk, whether it's the custom code you wrote, your open source software, infrastructures, codes, that's all been available. What we recently announced was, uh, our application security, posture management, right.
View of those results. So now not only do you have this large, uh, list, hopefully that's reducing over time, but this large list of findings, but we're helping the developers prioritize on which actions to take on which items are most critical. So that's, this goes back to balance.
If you look at what we're asking the modern developers to do today, their responsibilities have grown. So they need to be understanding way more, you know, whether it's new languages and frameworks, whether it's, uh, cloud native development, and understanding how, uh, the application will be deployed. That's, we're getting faster, but we're also, we adding more complexity as a result of it.
Um, so what we introduced in the, uh, IDE is a giving 'em the, a very, uh, condensed and focused view, so we're not overwhelming them and to what you were alluding to earlier, um, meeting them in the IDE. So it's, there's no context switching. So as a developer, I'm doing my day-to-day activities trying to produce quality, quick quality code quickly.
Um, and this allows me to address risk along that process. So it's not switching to different products or different views logging into different systems. And we've seen as a result of this, that developer time to fix is drastically decreased.
So now we're helping in, uh, not only prioritize, but the speed to fix is a new concern that we're addressing as well. Yeah. Fair, fair.
Now, Maran, I, I know, I know j Frog's history and story, right? You didn't just make a developer tool friendly for security people. You j Frog's actually acquired several right.
Security vendors, correct? I think you Yeah. Come For what we acquired Yeah.
Vision that became jfr advanced Security, which I'll talk about it. And also quack that became J Rog. Ml.
Ml. Yeah. And going back to the shift left, the, the reason that we're, I super like support that it's because it's about efficiency of the software development lifecycle.
When it's shift lab, when you identify the true issues that you need to focus on, that will really save the time, right? So be effective with that and understand the full lifecycle, but as, as, as soon as possible, if it's like malicious package, or there is like malicious even model in LLM now. So think about the full dimensions that is, is operating in order to create a new application and try to push it as soon as possible.
So it'll be like time, it's time consuming. So if you can do that as fast as you can, it's a plus for everyone. And developers want it, but it must be very focused and not like spam, uh, different tools on the ID plugin, but consider everything, prioritize that, make sure that it's, validate that it's applicable and save time.
Yeah, yeah. Agreed. If I can just add on top of that, I think, uh, what Tyler and Morani was saying, it's exactly, you know, we, we are seeing today, uh, with the advancements of technology, uh, developers being overwhelmed with so much findings, okay?
They dunno where to start. Okay? There is too much noise.
In some cases, a lot of false positives, okay? At the end of the day, they need to get the job done. Okay?
They have a feature that they need to fix, they have a bug they need to fix, they need to manage their pipelines. The more you reduce the noise on their end and walk within, of course the ID like serving them where, where they are, you are actually talking, going back to the trust, right? You are building the trust into the workflow of software development.
And that, in my mind, can transform developers into security champions because we know developers are not security champions by definition. Right? But if you feed them with the right amount of security training, security findings, prioritization, risk management, right?
Uh, with this A-S-P-M-D-I-D, we actually also introduced vertical, uh, very, uh, modern scoring, uh, algorithm. So it's not just that you're prioritizing that based on, you know, the severity of any findings, but actually what matters most to the developers so they can actually get their own unique report that they need to take, take care of the most unique CV that they need to take care of and whatever. So, uh, dev experience, user friendly, reduction of noise, these are the things that in my mind matter and allows developers to adopt more user security tools.
Yeah. And, uh, the company tools. And that's the power of platform.
I think that is, we're talking about like platform engineering. Yes. That's the power of platform to unify and give a context.
So it'll be very clear, very like, precise. We're gonna jump into platform engineering in a moment, but I want to focus just on platform for a second. You know, I, I did an interview, I did a few interviews over the last couple days, and this whole concept of platform came up.
I've been in security 30 plus years. One thing I've learned about the security business is small companies, little fish, they make what they call products, right? Then medium sized companies, they look at those products as features.
Mm-hmm. And they buy the little fish and they roll those products up as features into their products. And they think they have the product and we sell point products, but then the bigger fish, they say, no, we don't want products.
We want platforms. Yes. And my platform has multiple products in it, and not just my products.
We plug in, we connect API, whatever, we connect other products into this holistic platform. And that's really where companies want to be. And not only vendors.
Yeah. But end user companies. Yeah.
Consumers. Yeah. Consumers.
They don't want 27, 36 integrations point products. Yes. They want a platform that handles this mission for them.
And so I think it behooves all of us. You know, of course everybody wants to be the platform. You're a platform, you're a plat.
We're all a platform, right? That doesn't work either. Right?
But we want these tools to work together better. And that's, I think a, a, a key piece of it. I want to turn to platform engineering.
Sure. com about, uh, eight months ago now. org.
Very big. He's a great guy. Yeah.
200, 300,000 members there. Luca and I, and the check marks people do our platform engineering show every other week. Yeah.
And round tables and stuff. And we've spoken about this on that show, right? That if we could give the developers a platform that is both secure, tested, stable, scalable, and just say, developer, do what you like to do.
Exactly. Develop, focus on that. Develop, just develop, Go code, go as fast as you could go.
That's what we need. Right? That's, and that's, I think at, at the Nugget, that's the appeal of platform engineering.
Yeah. I know how check marks is working with them. How does J Rog view that platform engineering?
That's, that's j Rogs story. It's about DevSecOps for real, right? Come from a company that did like DevOps and get into security world, but in a very natural way for the developers.
It's bring developers into the security and, and really connect, be the glue that connect between them. And that's exactly the power of the, of the platform. Because you don't need to go to a different, you just got everything on a single place.
And that's trusted releases. Um, combine those two together. Yeah.
All. So I think within platform engineering and what we call an IDP, right? An internal developer, uh, platform portal, everyone is using the p in a different way, by the way.
Uh, so I think if you give these guys the developers, uh, a centralized portfolio, if you like, of the best of breed platform for security, for, uh, I know for cloud, for whatever they need to get the job done. Uh, that's also how you build trust. But also that's how you take, um, people look at platform engineering as the next level or next evolution of DevOps.
Okay? It doesn't replace DevOps. It's kind of built on top of DevOps to optimize these pipelines to optimize the software development life cycle.
But also, I've spoken with one of the analysts the other day also to put some safeguards on the tools that are being used, uh, and governed and controlled within the, the, you mentioned earlier, Alan, these different point solutions, right? Right. So with so many platforms, so many different tools, especially when you're dealing with enterprises, you need a governed approach to different tool chains within, uh, the organization.
And when you're dealing with, I know, 100 dev teams with thousands of pipelines, what you don't, you do want to give them, uh, the freedom of choice of tools and platforms, but you also want to control that. And platform engineering brings this governance into the software development lifecycle. Yeah.
I think that they're not, you know, dedicated as the knowledge, the right knowledge to do and accelerate that and give them that as a platform. They don't need to be security expert. They don't need to be, uh, even like, uh, legal expert or privacy expert, especially in ILLM.
But they do need to, to just consume it, consume it as a service. And that's the change I think that we are going to see. I think the service that's the right, the right word here, Right?
The service and application, which is like, it's the higher level. It's not just the DevOps, it's just application that combine everything together, the security and the DevOps. Agreed.
Let me turn now to another topic. 'cause we are going low on time. But look, we're here at RSA.
You can't walk more than five feet without tripping over ai. There's AI agents, there's generative ai, there's that ai, there's ml, there's everything. Both of your companies at Jfr and Checkmarx have news around AI and have put big bets, right?
Uh, JI Jfr ml, Right? You have AI agents. Yes.
I just spoke to Sandeep, the, uh, CEO about. Yep. How real, how big is ai?
So is AI taking any jobs away here, or is AI making us better? If not, when will it, is it more talk at this point than real Rio thoughts? So, I, I I can start.
So, ai, uh, serves a specific use case, okay? And each, let's say, agent serves a specific use case for the developers, for the security engineers, whatever persona is using that. So a AI is not going to replace anyone's or take anyone's job.
I think that what we're going to see eventually, and we, we need just put it on the table, AI or people that are using AI are going to replace people that are not using ai. Okay? So if you are today in the software development lifecycle, doing anything like from QA to dev to security, production monitoring, observability, I'm coming also from a previous observability space.
They are all looking at ai. So if you're not going to start getting used to the fact that AI is kind of your co-pilot, your, uh, supporter in everything that you need to do, someone that uses AI will replace you. So AI is going to be driven by engineering, okay.
By engineers, uh, as part of the software development life cycle. Okay? But it's not going to replace jobs for people in my mind.
That's just going to aid, uh, you know, bottlenecks or whatever challenges that these guys have and support them, uh, through their journey. So that's a, a short answer. I think they will replace humans in a lot of, uh, manual work.
People that are, that they're doing it today. It'll get into every position, not just like engineering. It'll replace in every, like, uh, every job in a company.
We're going to see, um, displacement, uh, for sure in support, uh, chat bot, replace support, you know, humans. So think about what AI will do, uh, about related to documentation. So many different aspects of service providers that will be totally improved and accelerate.
But I said it yesterday, I do think that the human factor is still very strong. And this is like our responsibility to make sure that we're doing the right thing. We're using it carefully.
We're putting the right guardrails, we're putting the right foundations. Yeah. Um, and it's in every several dimensions.
Like the infrastructure need to be like aligned. We have to put the right skeleton, the right model, um, due diligence, the models to make sure there won't be like data exfiltration and data poisoning. And then it's continue with AI agents, understand what are their guard drills?
What is the identity and access management, if it's like something that we implemented, reduce the, the actions that they can do, especially for various critical service and critical commands and operation or with sensitive data limit that align with the regulation. Make sure that we are aligned with the law. Um, if, if autonomous AI agent will share data between us and, and, and, and uk, what about GDPR?
How can I confirm that this identity is doing what it need to be done from legislation perspective? And that's a lot of things to do, or different dimension that will need to take care of them. So we are going to focus on control them, manage it, do it the right thing, take it slowly, but it, it'll run fast.
That's what I think. Fair. Yeah.
Fair. Tyler, what about you? Yeah, I'll just add, so it's gonna, the jury's still out.
It's obviously, uh, AI's here to stay. So that ship has sailed, but how it's being used, I think we're still waiting to see what's truly, uh, impactful and making a difference. There's a lot of noise around adding AI to certain product capabilities, but it goes back to what problem are we actually trying to solve, and how is it really, uh, empowering, especially in our case, the developers and security teams to work better together and remove a lot of what they call, like developer toil or those mundane tasks that, uh, can be easily replaced by something like an agent ai.
So, uh, we're excited to see, and, uh, we, we've launched a, a concept that we're working with our customers to really fit into their needs and understand their workflows. But it'll be, uh, I think pretty groundbreaking, exciting to see how that plays out. And then, uh, if, if I could boil down, you know, the DevSecOps movement and, and focusing on the people and the processes, uh, AI's really gonna focus on the processes, and I think that's a good movement for understanding, uh, the model of DevSecOps.
So everybody's kind of singing off the same sheet of music, and there's alignment as far as how the processes work together and what everybody's role in that is. So, uh, yeah, definitely exciting times and seeing how it plays out though. Fair enough.
So one last question, we'll wrap up as we sit here today, really the first full day of RSAC in terms of keynotes and sessions, expo hall, are you bullish on DevSecOps? Do you think the best is yet to come? Or do we, is there another direction we need to go in?
What's your thought? Uh, I think it's evolutionary. So it, it will build on what we are doing today.
We're learning from what works and where we failed and where we can improve. I think we're only getting faster with the new, uh, AI capabilities and really having us look internally on what is working and what isn't. Um, so I think, uh, it's exciting to see a lot of the consolidation around what's happening in our space.
Um, and a lot of the great insights or context that we can derive from that. Uh, so I do think anytime you can get people together to solve the same types of problems, it's a powerful thing. So I think, uh, I don't think there's a way around it.
I think it's the right trend. It just will grow and, uh, evolve over time. Well, I'm gonna give you the last, Yeah, I don't think we are bullish, but I think we are reacting to the trends for sure.
'cause uh, just like cloud, it just started and everyone just start, you know, syn up and, and, and that, uh, same goes with ai. So everyone are talking about MCP right now, right? Because it just started and then it's like a storm.
Everyone are doing it. So I do think that we're reacting to new trends and new technology and that, that makes sense. So reacting to that, just focus on doing the right thing and do, and provide an holistic solution to drive that.
Yeah. Love it. Alright, that's gonna wrap us up here.
You've just watched another episode of cracking the code, the DevSecOps Show. We'll be back live with more RSA conference coverage in just a moment. If you're not watching this live, you catch it on Apple or Spotify or YouTube or something.
I'm sorry you weren't here to see it live, but we're doing our best to bring it to you. I'm Alan Shimel. We're out.
Hey, don't, uh, secret agents have to deal with security too, or is it security have to deal with agents. We're trying to figure that out. What's the security with all the agents that we're creating here on the Textron gang?
Well, welcome back. You're joining our elite team here of Textile Techstrong gangers. I guess we are gang members.
Uh, Mitch Ashley here with Futurum. Great, great to be joined by, um, our, our crew of Jack Fowler and Steven FoST. Guys, welcome, welcome.
Thank you. Great to be here. I am definitely a secret agent.
You are. Well, that's what I was thinking about agents, aren't they like secret and don't they deal with security? And suddenly, now, I, you know, we talk about secrets of agents.
I know that's what we're gonna get into. com, talking about security around MCP servers. Um, are we, it seems like the topic has been, uh, come up but not been addressed.
We talk about security for agents. We talk about identity here and there. You know, they team members, are they whatever, you know, how do we, how do they get their permissions?
But there doesn't seem to be any, uh, like real solid frameworks around agents today, at least not yet. Now you can look into some of the open standards and say, there may be some things there, but I don't think Jack, somebody in the security community is gonna say, yeah, I'm happy with everything looks good to me. No, I think it's the exact opposite.
In fact, uh, the, uh, entire security, uh, identity security world sort of shakes their head and looks at it. Like, does the face paulman? You know, what are you thinking when you created MCP and had no concept of identity and MCP and said, oh, we'll just wave our hands and do some OAL tokens or something else and let somebody else deal with it.
Uh, the the challenge is really that we're moving from a human world to an agent world where agents act on behalf of humans. And it's important to understand, uh, the agent's identity, the server's identity, the human who's the agent is acting on behalf of, or for the benefits of identity in every single action transaction that occurs. And right now, there's a lot of anonymity and anonymity in security is a bad thing, right?
So there's a lot of talk about at the high level, here's some high level constructs we need to think about. And so I wrote an article about some, uh, uh, identity security folks coming out and saying, you know, there's a lot of issues with anonymity with, um, how you communicate the information back and forth. Uh, how often you go back to the user to re-authenticate, to get permissions and how to make that cleaner.
And here's some high level thoughts to think about it, but we haven't moved beyond that to here's an actual protocol that actually thinks about it and cares about it. And the big concern is we're running at a million miles an hour trying to make agents, uh, useful and get money out of them without thinking about the security. And that's just generally a bad thing in my book.
And we can't wait for them to be agentic. Right. Stephen, at the same time, you know, we, you host AI infrastructure, uh, field days and, and AI oriented things.
I'm wondering how much, how much is security coming up and what are vendors saying about this? Yeah, well, for, to be clear, yeah. Alistair hosts AI infrastructure Field Day.
Yes, that's true. Does I host AI Field Day? And that's where this stuff comes up.
Uh, AI Field Day. I know it's confusing 'cause there's two that sound a lot like, um, and in fact, actually the last week I was at NetApp Insight and there was a lot of conversation there as well about this. Um, first off, let me just say that that article on Security Boulevard that, uh, about this topic is just really excellent because it goes over a lot of the potential issues with agents in a very clear, straightforward way.
And it's so true. I mean, think just, just think about what is being pitched at us about agentic ai, you know, oh, it'll automatically, you know, find the right flight for you and book it. Um, wait a second, right?
Do I really want my browser, you know, do I really want perplexity to decide how about, or, or even better, do I really want Google to decide which flight to buy and buy it without any approval? Or alternatively, as it says in, in there as well, there's that chaos of approvals. Or alternatively, do I really want to click the little button and say, buy me a flight, and then have it say, do I have your permission to access your calendar?
Do I have per your permission to access your email? Do I have your permission to access your, uh, frequent flyer accounts? Do I have your permission to, you know, because again, that's, that's another issue.
Um, uh, another other issue I wanna point out. I was reading the CloudFlare blog, um, last week, and they were talking about, um, you know, their, their, uh, one of their articles, uh, using, uh, MCP in code mode. Uh, their, their thesis is we've been all been using MCP wrong.
Their suggestion is that instead of calling tools, what we should do is have MCP dynamically recode the calling and the APIs on our behalf automatically, and then run it as code instead of in MCP. And the whole time I'm reading that, I'm just thinking, but what about security? So essentially we want to, we want to just tell AI every time the agents do anything, Hey, go ahead and just rewrite this yourself.
Like, just figure out how to do it. Would you? And yeah, I mean, it's, it's just, it's just a complete total nightmare.
And, and so I wanna point out what, what, um, the clever thing that NetApp announced last week, and this is not gonna solve this problem, but I liked one aspect of it. They are in their new, um, AI data engine. They are using, uh, AI tools to do data classification and to then use that to enforce access controls on data.
So instead of, um, instead of just saying like, uh, I think you can access everything on that file share, you would be able to say, you can access, you know, data related to ACME Corporation client, but no financial information. Hmm. And then that way, and, and their, their idea was, and I completely agree with this, that the only way to keep an LLM from leaking data is to never let that data into the LLM to begin with.
And, and they're, so they're using ai, but in no way that actually is exposing anything. They're just using it to create metadata, and then they're enforcing access based on the metadata that was created in a sort of a standard deterministic programmatic API type way. So there is not AI talking to ai, it's actually, you can't access this.
You can only get this subset of data. And I love that idea. Interesting.
I was also at, uh, at the Oracle last week at the, uh, a now renamed AI world, um, and similar kind of approach of not only is it the data store, but that's, you know, they have databases, massive databases, uh, business applications, E-R-P-C-R-M, et cetera. And their approach is something similar where they said, look, the data never leaves this platform and AI will access it through MCP, but that MCP will be controlled by all of our existing security and privacy policies that you already implement in those products. So That's like the same idea except for structured data, whereas, and NetApp was talking specifically about unstructured and mot multimodal data.
Yep. Makes a lot of sense. So it, it's interesting, you, we, I wanna go back to the, the, the polymorphic topic you brought up of code creating code, right?
And that's, we're already doing that. We just have it in the developer's hands when it's creating code for us, right? Um, but that's very much where, where this is heading, is that agents will be able to create agents, agents will be able to create code dynamically.
Um, and in doing, doing, so, yeah, it might be minor things, but still that's how, how things get leaked in. That's how CR credentials get lost. All kinds of issues kind of come up.
That article you were talking about on Security Boulevard, by the way, was we'll put a link to it beyond chatbots, why, uh, agent security is the industry's next major challenge. And there were like 10 items, I think there were, that came from the artificial intelligence, identity management community group that, that had a number of, of these issues that they talked about that need to be addressed. So, yeah, I'm sure it's not everything, but I thought that was a good list too Point.
The, the interesting thing about all that and sort of the polymorphic is we, we do that a little bit today in a very subtle way, which is when you think about infrastructure as code, that really is mm-hmm. Uh, another form of that where we say, here is some code that defines the desired state of our environment. Now you go figure out how to write code to talk to agents that are, or to have agents that go talk to different types of systems, whether it's servers or routers or storage devices, to get 'em configured the way you want them to, to operate.
And in that environment, we still have a very big problem of anonymity of access, right? Every, if you think about those types of environments and infrastructure as code, everything you're doing is a privileged access. You're operating as a super user or in a system administrator where you can go change any configuration.
You can, uh, delete hosts, delete servers, delete virtual machines to start 'em, start multiple instances. And with the anonymity in there, it's very hard to audit and trace back who's doing what and why something actually happened. And hey, you know, we just shut down our entire production server.
What happened? Well, this agent turned it off, but why did that agent turn it off? I don't know.
Because, you know, somebody somewhere made a typo in an IAC file. But there's no way to tie all of that back together without a lot of manual effort. And very often, because it's all anonymous access, you can't, and that's part of the problem in the MCP world as well, is agents can take on and work for multiple people simultaneously, and they can do things, uh, autonomously, right?
Where you say, Hey, I wanna buy an airline ticket. But that triggers many different actions, which could trigger many different agents to do things, as you said, access your calendar, put something on my calendar or delete a meeting off of my calendar by mistake. Right?
Hey, that meeting disappeared. I don't know why it disappeared. Who made it disappear?
Where's that, uh, log? You know, I feel like I'm reliving the, uh, dipping back here in history. The, uh, the 12 blinking clock on the VHS tech tape deck.
I can barely keep HubSpot and LinkedIn connected all the time. Have to go back and relink it. Yeah.
Um, so how are we gonna do that? That's the thing, right? And, and again, in Cloudflare's defense, I mean, they're not talking about zero authentication.
I mean, they just use conventional, um, off authentication tokens. Um, and MCP is fully, uh, able to do, you know, standard authentication tokens. But, um, like you said, I mean, that introduces a sense, a a sense of fragility and, and sort of a black box nature to it, where you're just not sure, uh, where did it get this token?
Who's it authorized as, you know, how do I control this? Um, and, you know, yeah, the, the blinking 12 o'clock problem, um, we are all gonna face that problem because it doesn't matter how smart you are when you're, I said black box now twice here. I'm gonna say it again.
Um, when you're faced with, you know, fundamentally and agent, agent to agent is a black box, you know, you're saying, you know, here's some tools that you can use. Now they do, again, to cloudflare's defense. They're running these things in a sandbox.
Um, they're using authentication tokens, but it's the step of having the agent create its own code. That gets me a little scared. Um, you know, their justification is that LLMs, um, you know, the trouble with MCP, and this is actually kind of a clever thought, the trouble with MCP is that LLMs were never trained on any dataset that contains MCP calls because MCP didn't exist when they were being trained.
Hmm. And so it doesn't understand fundamentally how to deal with special, the special MCP tool calling token and how to call tools. Even, even if it's been, um, fine tuned and to, to, to handle MCP, it's not fundamental to its training, whereas allowing it to reach, redo everything in TypeScript, it's, it has a huge experience with TypeScript, and it's able then to more effectively execute all that I agree with.
It's just, but that doesn't change the fact that we don't know what it's executing and nobody knows because it's executing in a sandboxed environment that's ephemeral and then it evaporates. It also doesn't change the fact that right now, code generation capabilities are at, at the infancy. Right.
Very, very, uh, immature stage. And so the probability that it generates code that does something wrong is relatively high today. Yeah.
Go generate some code and go execute it. And don't ask me and don't show me. Exactly.
Now, go. Exactly. And, and AI likes to generate a lot of code for you on your behalf, even if you don't want it to.
You have to be careful with it. Well, good, good stuff. I mean, we've covered a range of, you know, what about the MCP?
What about MCP, who's, it's like the weather, who's doing something about it? Oh. Or agent security.
So, uh, I have a feeling we're gonna talk about this topic a lot more. So stay tuned, we'll be back and we'll be, uh, jump to our next topic. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included that work you are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. Well, we're talking about security day. It's security day on the Textron Gang.
com talking about the, the big secrets leak, if you will. Uh, that has to do with vs code visual studio code, developer tool, IDE, uh, through extensions leaking secrets. Um, Wiz had earlier this year, uh, announced the discovery about, about how many supply chain security, supply chain leaks that were due to these extensions, not only in VS code, but also opened VSX marketplace.
And then Microsoft researchers found that publishers of more than 100 vs code extensions leaked access tokens. Hmm. That would've enabled a, a bad actor to distribute malware to more than 150,000 users.
Eh, what's a, you know, that's not bad. It's kind of a small number, isn't it? So, so it, it just shows you the, the attack or the leakage surface of data and security credentials, secrets is as far wide and as deep as as you can make it.
And now we're talking about developer tools. We're, we're talking about MCP, you know, that's now also part of the developer tool space. So what are the security folks gonna do about this?
Jack, when are you gonna fix this for us? When are we gonna fix it? No, when are you gonna fix this, Jack?
When am I gonna fix it? There you go. You are personally gonna fix it.
Well, I, you know, I'll, I'll use a very simple analogy that the IDE, the integrated development environment is effectively the web browser for developers, right? It's their main way of they interact with things and extensions in the ID inter, uh, interface are the equivalent of the extensions in a web browser. And so we sort of have the, it's the exact same problem we've had in web browsers for a while.
If you have rogue or malicious or poorly programmed extensions, they can come in and get access to your passwords, see where you're typing, yada, yada, yada, the same sort of security things. And so, uh, you know, uh, we have a couple of, in the security world, we now have a couple of, um, startups doing browser detection and response, which I wrote about recently, like square x, who has an extension that goes out and tries to, uh, protect the user of a web browser from malicious activity by, either by either websites or other extensions. And now, or maybe will go and see developer, browser developer environment, IDE security tools that are gonna have to be third party tools to come in and look at this.
Or, um, the other option is to go towards more of the Apple model where you have a, uh, walled garden and somebody Microsoft for visuals, uh, studio and, uh, goes out and vets the extensions to say that this is behaving properly or not. And that's an awful lot of work on both cases. So I don't know.
Yeah. On the square X thing, I, I, I have to say, uh, we did just have them present at Security Field Day. So if you wanna learn how, what that's all about, you can just Google Square X and Security Field Day and you'll find a video, which is a, a deep dive demo of, of exactly what they're doing.
But absolutely, um, the thing that, that gets me about this kind of in relationship to the previous discussion that we had, the, the leaking of secrets. I mean, we just talked about tokens and secrets in MCP and how that works. Um, the leaking of secrets is one of the primary things that, um, jail breakers are trying to do with AI models.
Um, basically figure out how to make it leak secrets for me. And there are many ways, and, and, and you cannot fundamentally prevent that, except by having sort of a convoluted calling process. Like I could see a situation where somebody could have an MCP tool that exists that is only a secret's vault, maybe one password should do that, and, um, and basically have the agent call a tool that it doesn't have visibility into.
And then that tool then basically just provides the token on your behalf or something like that. Because if, if it can see the secret, then it can leak. The secret.
And that's the problem with this vs code story, is that essentially people left the, the token, the secret in the code. And the thing is, um, you know, black hats are literally, I mean, they, they basically just have regular expressions searching for, you know, tokens and secrets on GitHub and VS. Code and everything constantly.
So if you do it even for a moment if you like, oh, commit that, oh man, oh, no, no, no, nope. Lemme get rid of that, you know, well, guess what? You know, you just, you know, it's gone.
You know, as soon as you say it, it's gone. It reminds me of the situation back in the day when we would set up, you know, windows servers and within literally 30 seconds, somebody was hitting, um, known vulnerabilities in Windows to try to, uh, you know, hack into those servers over the internet. So you had to like, like install, you know, windows servers, uh, disconnected because otherwise somebody would hack it before you could even apply the patch.
It's kind of the same thing here. And, and in vs code what it sounds like too, people didn't even do that. They didn't even get rid of the, the stuff quickly.
They, they just did it and didn't know that they did it. Um, at the end, you know, you're talking about, um, you're thinking about vibe coding, you're thinking about AI written code, uh, I think there's a very good chance that AI is gonna put some sloppy code out there that's gonna include tokens and secrets and that aren't properly managed Well, and, and it's not, you know, rookies doing this too. I mean, they found, you know, extensions that came from open AI and Gemini and Google, Gemini, philanthropic, you know, perplexity even as well as AWS and GitHub, et cetera.
So there, so these are, you know, are weren't just kind of rogue actors out there that who left their secrets in their extension. And there are things to do exactly like you're talking about in the development world, one of the popular open sources, one is called Vault, and that's the way it is. The secrets is stored there, and it's only because the trust relationship you set up between your code, your system, and that vault that gives you the access token yet to get that credential, that secret, um, I, I kind of faulted at, at, at the IDE level.
This should be built into the IDE, right? There are, and you can use secrets managers in VS code. Um, but that should be part of it.
It should be very easy to manage secrets already, just right in the IDE pop it right there. It already has, you know, I built the trust relationship when I installed it. This is my test environment.
This is, I hook up to my corporate environment. That should be part of how that's set up. I mean, it's, jack security is set up from the beginning, not after the car leaves the factory.
And we wanna add airbags, which is, which is why I, my column is secure by design. I really fundamentally believe we need to think about security at day one. When we talked about MCP earlier, we didn't think about the identity portion of the security of MCP.
When we look at the IDE, the IDE is something that has grown organically over 40 years. Right? You know, when I was an engineer many, many years ago, we used a text editor, right?
There was no integrated development environment. You didn't have all the tools integrated. You ran me outta screen to do, you know, you red typed your code, you exited the editor, and then you invoked the compiler and then you invoked your test environment.
Uh, so in systems that have grown organically, we haven't really thought about security at the beginning. And I think it's now time, it's clearly time to sort of take a pause and say, how do we build, how do we sort of rethink this so that we can import the security tools that we need into it? Such as, um, uh, secrets managers, you know, built into the ID environment or, and, and, and not only that, but how do we make it a standard operating procedure of how we teach programmers and engineers to develop us to think about that and to use the secrets manager rather than the hard coding it.
Yeah. But I wanna say, go ahead. Maybe The IDE could enforce that and basically refuse to allow you to put secrets Yes.
In your code To start with. I think it's something, something you brought up earlier, Mitch, was that, you know, you named, you know, the, the rogues gallery who, who of, uh, who's who of AI as part of the, the group that created extensions, that leaked code. And my question is, and something Steven brought up is, was that code that leaked the secrets written by a human or by ai?
Well, that, that's a good question. I, I, I And was it the code for all of 'em? I bet money is by by both.
Yeah. Was it written in 2025? Probably ai ai.
No. And I didn't name all didn't, I didn't name all names. I'm holding some of that.
No, no, absolutely. There was a lot more, but, alright. Well, you know, I think, so the, the, the parting thought is when we talk about software supply chain security, we're usually thinking about SBOs and package managers and things, source source images and things like that.
We have to also think about the tool chain. We're now using AI based browser tools to do development and running agents in browsers, right? So all of, all of that execution environment, either for development or production, all that has to be secured.
So It's the tool chain too. The whole part of it. That's how SolarWinds happen.
So we'll be back. We're gonna finish up on security theme. One more topic.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Well, welcome back. We're gonna shift a little bit and not just pick on AI security.
That's a little bit too easy at the moment. I think in some ways we're gonna talk about really the runtime environment for cloud native applications with AI powered security. Hmm, okay.
There's an interesting thought. Now, of course, when we talk about cloud native, we're usually talking about Kubernetes, at least as one of the technology that's pretty common to run. Um, and we also, we also look at, you know, visibility to things like, um, observability type tools, uh, things like that.
I know this is an area that you looked in to in prepara preparation for today's segment. Jack, give us kind of your rundown. Um, well, I think, you know, in one of the articles that Alan wrote, and I think he said it best, which is you can't secure what you can't see, right?
And so we really need to think about in a, in a cloud native Kubernetes environment, how do we understand what's actually happening in the running environment, not necessarily in the development or code environment. So you'll have, and as we talked about with or the first segment in MCP, you will have instances of your application either talking to other instances, um, or talking to other resources in your environment. And you may not, you probably won't have visibility into all of that because it might be either in a process, communication on the same server, or, um, going across a, a local connection that's not part of your outbound network security protocols and what you're looking at for network security.
So if you're not observing what's going on, you can't understand if something bad is happening. I think that's the crux of the problem. And so as you start having AI developed code and AI running in your environment, now, there's a whole lot more happening that you don't know about.
And so understand, trying to get a handle on that invisibility into that, I think is critical. There's an interesting thing too, and Alan's and Alan's chi take at the end of this article, he's talking, he talks about it's not humans versus machines for security. It's humans and machines working together.
And with ai, since agents and AI often mimic or do things that are essentially what a user would do, whether developer or, or an end user. So machine identity doesn't kind of cut it anymore in what we traditionally think of a machine to machine identity security mechanism. 'cause the actions it's taking is actually looks more like an end user or is frankly, it's just a digital user.
It, it's so interesting how similar this is to our discussion of MCP in that, um, you know, the, the, this whole idea that, uh, cloud native applications can and absolutely do spin up and, uh, then destroy, uh, containers that are basically, I'm gonna call 'em agents, uh, you know mm-hmm. So microservice could have, could be an agent. Absolutely could be.
And, uh, you know, that they create these agents that they run an something on them and then they destroy the container afterward. Um, it's the same challenge. Uh, and I do like the idea of, you know, kind of turning it over on its head.
It's kinda like what I was talking about with NetApp and their MCP kind of protections by doing automatic AI based data classification. The idea of using ai, not, you know, it's not like running AI applications. It's basically just throwing some AI at the problem by saying, Hey, ai, keep an eye on what's going on in this environment all the time.
Um, it's act, I I like the idea because it's just another tool, it's another quote set of eyes, even though it's not really a set of eyes, but it's another, um, opportunity to discover something going on in this environment. So, you know, by having AI watch non-AI things, I think that's one of its better uses. Um, I've been pretty excited about, uh, AI assisted firewalls.
Um, I'm pretty excited about AI data classification. I'm pretty excited about, you know, AI assisted security generally because, not, not that it's gonna solve the problems, but that it has a chance, it has a shot of detecting things that we wouldn't normally detect. Um, do you see that too?
I, I definitely do. I think the, for me, one of the differences here is when we think about, you know, AI is a very broad, encompassing term. One of the challenges when you think about an LLMA large language model, it is designed to be non-deterministic, give it the same inputs, and it gives you a different answer when we're doing analytics, which is essentially what we're talking about here, is looking at, uh, a series of data that's repetitive, the same type of data, and really looking for an anomalies, right?
That is what traditionally is called machine learning, but is designed to be very deterministic. Give it the same inputs, it will give you the same outputs. The advantage that machine learning has is that it can operate at a speed and scale that humans can't.
So it can look at a vast amount of data that humans can't deal with in our heads and can do it at very, very quickly. And that allows you to look for, um, anomalies bad behavior or strange behavior over a greater period of time. So one of the things that attackers try to do is they try to operate, um, low and slow.
Like right where ACP attacks, right? I'm sorry, a CP type type of tax. Yeah, yeah, yeah.
A CP tax where, where basically you're trying to exfiltrate data, but if you send, uh, uh, you know, a couple packets every second, rather than a couple of gigabytes every second, you might escape notice. And so they can operate over very long periods of time, 30, 60, 90 days before they're discovered. And at that, during that time, they're able to, you know, exfiltrate a lot of data.
It would be very hard for a human looking at the data, the, the telemetry that you have about what's going on in your network and find something like that. 'cause it's literally the proverbial needle in the haystack. But it is something that, uh, machine language, uh, sorry, machine learning program can do.
And I think it's a very good application of AI to look at these vast amounts of telemetry about what's going on in our environment to identify things that shouldn't be happening. Well, you know, it, it, I, I like the promise of where we're going because, you know, we, we've gone from let's do log aggregation, get a whole of logs in one place so we can find them. Let's put 'em all into one system so we can do analysis and application performance monitoring.
Let's put more sophistication to it and, and have observability so we can do more analytics on it and connect the dots across, uh, the organization applications. So the next layer, in addition to AI being part of the solution is graph technology, which is adding context to that. Um, HashiCorp announced kind of, they're claiming the moniker of the ENT infrastructure, um, adding AI capabilities into, into what we do with, uh, Terraform.
And, but what it's informed by is something called infograph, which is a graph technology that is the state of what the infrastructure looks like. You know, we were talking earlier about code, generating code. Well, and you use the infrastructures code example, and that's a perfect one.
If you're doing it in isolation, go create this. That's one thing. If you're doing that in, in the context of a larger system, well, how do I find out what that is?
How does AI find out what that is? That gives you a lot more, uh, I think validity to be able to handle the, not only the volume, but the breadth you were talking about, Jack. I think there's a lot of promise in that, in, in helping solve some of these issues.
Well, I I'm glad you brought up sort of the graph concepts because that's something that Microsoft itself, uh, is also thinking about. Um, Microsoft gave a, participated in a tech field, a exclusive event, uh, and they talked about how they're integrating, uh, graph, uh, the concept of graphs and graph database into their, um, uh, si their, their sim and their entire security ai security platform. Hmm.
And part of it is that attackers think in graphs, right? They think about, I'm, I've penetrated this particular server or a host or device endpoint or user now from there, how do I, what's the graph look like that I get to the next part and the next part to explore? Because they don't have visibility into the entire infrastructure at once.
So they sort of have to build that out and they think about it in terms of graphs. So if you can build your tools around the same way that the attacker thinks and understand the graphs of how your systems are interacting with each other, it gives you a leg up in understanding what's going on and, and trying to be one step ahead of the attackers. Steven, how much is graph technology coming up in the vendor events that you're doing with field days?
Yeah, we're hearing about it a lot more. And, um, yeah, this, this whole idea is absolutely coming up from sort of people who are i companies that are ahead of the, ahead of the, the trends instead of, uh, you know, sort of looking at things the, the old way. Um, I don't know enough about it yet, but I do know that we have seen it and heard about it from a wide variety of companies at Field Day.
And, um, yeah, I'd be really interested to see where it goes. Oh, we will have to get, uh, Neo four J or somebody like that into a field day. Yeah.
And, and love to have somebody or anybody else. By the way, if you're interested, contact Steven or anybody here. We'll, we'll set you up.
And I think that'd be a fascinating set of conversations, so. Well, good. Well, well, gentlemen, it's been, it's been fun.
You know, I feel like we were, um, we're, we're missing the, the Allen drummer and, uh, so, but we decided to do the Rush Band and just kind of fill in. So we've got the trio back together just for some new players. So good to have you here, guys.
Have a good week everybody. Thanks for watching today. Be sure in Tech Out, we talked a lot about Tech Field Day, thankfully, uh, Steven was here.
We could touch on them. Well, Jack too, 'cause you, you've done a number. com.
tv. Fantastic. So stay tuned.
So starting tomorrow, right? Wednesday, what'd you said? Wednesday, Thursday?
Yeah, it's the, yeah, Wednesday, Thursday, 22nd and 23rd. Very nice. Very nice.
Excellent. Well everyone be ready 'cause we're gonna be talking about agents and CPS and runtime security a lot, I'm sure. Alright, well be safe out there.
And, uh, please check out the rest of the program. We're out here on the Techstrong tv, uh, the great shows and interviews and conversations that are happening, things like Tech Field Day as well. We, we will talk to you soon.
Hey everyone, welcome back here to Techstrong tv. I've got a, uh, new company, first time guest to introduce you to Let me introduce you to Gabriel or Gabe Bian. Coney.
Gabe is the, uh, co-founder and CEO over at a company called Tensor Zero. Gabe, welcome to Tech Trunk tv. It's great to have you on here.
Thank you. Thanks for having me. Pleasure.
So, you know, we're gonna talk about Tensor Zero, but before we do Gabe, let's, let's talk a little bit about you, right? How, you know, you don't wake up at four in the morning and say, I wanna start a company. What, what, what kind of, you know, what path did you take to co-founding this company?
Yeah, so I started this company with my friend Viraj that I actually met back in college over a decade ago. We in the same dorm, we were both at Stanford, uh, had gotten to work together since then. I, I worked at a number of startups most recently.
This company called Ono, uh, barrage went to grad school. He was pursuing his PhD and Penn Azure was actually an extension of some of the research he was doing during his PhD. He was doing a PhD SU on reinforcement learning.
And the main topic there was like, how do you get machine learning systems to learn from experience in the real world? And as LMS were ramping up back in like 20 22, 20 23, we started asking the same question about lms. How do you get LLMs to learn from experience in the real world experience being metrics from your product and your business being human feedback, user behavior, whatever makes sense in the context of what you're building.
And we realized that the tooling that existed wasn't perfect for this, uh, feedback loops for the systems to learn from what they're doing from the consequences of their actions. So we decided to kinda redesign and rethink the stack from the ground up, and that's how Penn surgery came together. Excellent.
Now when you say reinforced learning, like, so for instance, deep seek, you know, the Chinese, uh, ai, gen AI LLM model, you know, they, they claim that they did a much better job with reinforced learning and and so was they were a lot more efficient in training their model. Is that the kind of reinforcement you're talking about here? Yes and no.
So I, I think when it comes to alums, there are different kinds of reinforcement learning, like also like different stages of the, let's say, pipeline to train a model like that. If you think about foundational labs or companies like, uh, deep seek, they start all the way for like pre-training where they're sending like massive amounts of data to those models and spending out hundreds of millions of dollars. You can billions of dollars to train them.
But once you have, uh, uh, a model that exists, anything from GP D five to deep seek, those models and so on, application companies have to take those models and tailor them for specific use cases. You can start very simply by just using prompts and prompt engineer and so on. But if you really wanna squeeze the most out of those models, there are a number of different techniques that you might want to try here.
Uh, so when we think about reinforcement learning, there are reinforcement learning techniques about like specific techniques you can apply to those models. But we're thinking also about the broader LLM engineering loop. So how do you think about like, the whole application or the whole LM system to improve from like the downstream performance?
So we do use reinforcement learning, but that could also mean other techniques. Anything from optimizing the prompts to fine tuning to dynamic context learning and many other buzzwords I can share here. Absolutely.
Now, so you got my attention right, because, you know, IIII use chat GPT as my main go-to for, for, uh, ai. And I've done a fair amount of prompt engineering with it over the months and years now, where it does a good job for me, right? com and our tech strong AI sites and, you know, a lot of material there.
So that it really, I feel like I'm starting off halfway through the thing rather than at the beginning. And I'm sure there's a lot of us out here doing that, but that's not really what 10 to, is that what 10 to Zero is doing? No.
You're, you're really, uh, training these models or better training the reinforced training for applications that are using them, not, not for people's use. EE exactly. So the end user of 10 zero is typically an LM engineer or a software engineer or maybe a product manager at a company that is building an AI product.
So in your case, you're already using in a application like Chat JPT. But for us it's typically companies that are building their own products that integrated the open AI, API or any of the other similar APIs across all sorts of domains. So we have users, anything from, you know, healthcare, back office automation, all the way to, you know, education and tutoring and, and so on, all the way to, you know, compliance in banks and the like.
But they're building software systems that leverage those LM under hub. And for that, there are a number of complexities you, you might want to do deal with where you're not manually looking at each of those conversations like you're doing. Sometimes there's quite like high risk use cases, for example, in healthcare and compliance and so on, where it's actually interacting with the real world.
So you need a lot of additional safeguards, better observability ability to plug into all the different model providers and the like. So that's where a, a tool like ten three zero can come in. Excellent.
And you're doing this through an open source called an LLM Ops platform. Talk to us about what that is Exactly. So we have this open source project also called ten three zero, which has five major components.
Uh, first is a model gateway. So this unified API that lets you integrate with every major model provider e that open source or pull source providers using the same API. So you can very quickly try the different models as you're using this inference gateway.
We're collecting very structured data about those inferences as well as like downstream metrics and human feedback and so on about what happened there. And with that, like providing both observability so you can really understand what happened there at the microscopic and microscopic level, but also curating data sets that you can use for optimization workflows, be that optimizing your prompts, optimizing the models, running reinforcement learning, and so on. And finally, uh, once you're, as you're iterating over the system, we can do evaluations of sanity checks that things are working as expected before you put that in production.
And also experimentation. Once it is in production, we can ab test different choices of models and prompts and parameters, and I like to make sure it's moving the needle in the right direction. So basically, once you have this whole stack in place and it's all open source, you're, you basically have everything you need to, you know, uh, try all the different models, see what's happening with them, iterate on the prompts and models and so on to make them better, and then send it to check and confirm they're working as expected and, and moving the needle in the right direction.
Very cool. Very cool indeed. Um, let, let's get some housekeeping out of the way.
com, not, not the number zero. Um, and then Gabe, how, how do people engage with you? How do they get started here?
So it's fully open source. So most companies will go straight to GitHub and try the project, follow the quickstar and tutorials, and a lot of companies use it without ever having spoken to us. We're also very happy to support, so we have channels on Slack and Discord and, and social media, so very happy to answer your questions and help with onboarding and so on.
We also have a number of design partners or companies that we work very closely with to, you know, take on feature requests, provide support, and the like. So this can really vary, uh, on the user here. If they just wanna try it out and not talk to anyone, they can just go to GitHub and download it.
Uh, if they want help, if they want support, very, very happy to chat it and support it on this journey. And, and what, what's the commercial model like? We're pre-revenue right now, so we're fully focused on the open source.
Oh, just fully open right now. We, you know, we're getting users delivering delight. I imagine at some point there might be a hosted version or some premium features or something like that.
Yeah, that's great. How long have you been at this? Well, I works outta your part, your co-founder's PhD in 22, 23, you said?
So it's been, Yeah, so Pretty Much we, we started the company, uh, beginning of last year, and we launched open source about a year ago, so we just turned one for the open source. Very cool. And, um, are you pre, do you pre-revenue, obviously?
What about pre fundraising? No, We, we recently raised, uh, a seed round, so we raised just over $7 million, uh, which we're very happy about. And that's A very healthy seed round.
Congratulations. Yeah. So this will support no continuing to accelerate the, the engineering and growth for the project and starting to grow the team now.
So early on, it was just me and my co-founder. Now we're six people and they go through, hopefully get to 10 or so by the end of the year. Excellent.
Excellent, excellent. You know what, it's good to see, and, and I love the open source model here, and it's good to see there's so much going on in AI and there's so many different aspects and facets of, of how we are going to do this. Here's something that I think everyone out here can wrap their head around and with a, a really sane business model, right?
Of sort of your traditional open source was delivered, delight, and then, you know, go from there. Um, so 10 to zero is the website. It's available on GitHub as well.
Is there a GitHub url? com/tenor source or something like that? com/tenor zero.
And you can find the whole project there. It's all open source. Yeah.
10 to zero. Excuse me. Well, Gabe, I wanna wish you the best of luck.
Oh, thank you. With Ted SU zero. This is, this is an interest.
You know, it's funny, I I'm in our studio here where we have three different, well, it's a sound stage, we have three different sets. So I was, I came here from the Textron gang set down the studio there, and, um, we were just talking about sort of, you know, there's a feeding frenzy right now. I'm building data centers and I'm going to use your chips and you'll use my chips and you'll put your stuff on my chips and I'll put my chips on your stuff and all of this.
But what we're looking for is the next growth phase, the next evolutionary stage where, okay, you, you've got the, the data centers and the chips in that infrastructure and, you know, you have these frontier models, but now how are we going to that next for every net for every company? And it's not just going into chat GT five or philanthropic quad four or whatever it is, it's really customizing, you know, for your needs. So this, this is that next gen.
Good for you, Matt. Congratulations. Thank you.
And I appreciate that. All right. Gabriel Bian, Coney, CEO co-founder of Ted Soze.
That's T-E-N-S-O-R-Z-E-R-O here on text Trump tv. We're gonna take a break. We'll be right back.
Hey everybody, we're back at Atlassian Europe, and we're talking to my good friend Andrew here, who's the customer, CTO for the Atlassian Williams F1 racing team. Andrew, welcome to show. Hey, Mike, thanks for having me.
How did this whole relationship between Atlassian and Williams come about? And, and, and, and why Atlassian and how did you guys like decide that Williams was the team to be? Yeah, so, um, earlier this year we signed on as our title partner and technology partner for, uh, Williams Racing.
Uh, and initially we, we were having a look at many teams and, um, it was clear that Williams had a great culture. They were, um, on the, a similar journey to, uh, to the top. Uh, we felt like we could support them in getting there.
Uh, and they really felt like teamwork and technology was gonna be the key to help them get back to the top of the grid. And when you're looking for better teamwork, who do you come to, I suppose? So what were they using before they found you guys, and what have you done as the technology partner to upgrade their environment?
Yeah, so, uh, if you look at the history of Williams racing, they haven't really invested too much in technology, uh, in terms of knowledge worker technology, uh, over the past 10 years. Uh, and so they were using a variety of, of different tools. Uh, however, if you look at the different software, the different collections from Atlassian, uh, we're leaders in, in every market that we play in.
Uh, and so we came in and we had a look at, um, how are they working? What kind of products are they using? How could we help?
Uh, and so we've started rolling out our teamwork collection there. Uh, and the re uh, Williams are really seeing a massive uplift, uh, as a result of that. Yeah.
So are they wor, are the engineers working differently now together? I mean, you know, gimme an example of what they're doing that they probably weren't doing before, or should have been doing before. Yeah, I mean, uh, a good example is what happens at the track.
Um, so a lot of people dunno that when a Formula One team turns up to a track, uh, they have a garage. When you see it on tv, it looks great. It says Atlassian everywhere, lots of shiny cupboards, two beautiful cars inside.
Um, but the reality is when a team first turns up there, it's an empty concrete box. They, they start off by painting the floors. So that's the level of work that needs to go into it.
And a lot of people don't think about what does it take to get all those things there and set it up. Uh, and one of the, one of the things that, that we're doing, we're tracking basically in a notes app, all the tasks that had to be done to set up a garage. Uh, and as a part of that, there are incidents and things that go wrong, uh, that they also need to keep track of.
So rather than using a a Notes app for that, which, uh, wasn't really giving them a lot of insights about repeat issues and, and ways they can improve, we transition them onto Jira. Uh, where now we have a repeat, uh, uh, repeatable cycle. Uh, the tasks are assigned to people when something goes wrong, they're able to, uh, log it as an incident, talk about what's happened, uh, and that way after the race, they're able to go back and see how they can improve and how do they avoid those things from happening again.
Uh, an extension of that actually is they can ask Rover at the end of the day, how was the setup today in Singapore? Uh, and Rover will give a report about what's been done, what's outstanding, uh, how many incidents happened, uh, which really helps, uh, in terms of continuous improvement, How big is the team and is it the same team that goes to every one of these cities where the race is at? Yeah, a lot of people don't really think about the size of a Formula One team, and they're surprised when I say there's about 1,100 people who work at Atlasian Williams Racing.
Uh, I don't remember the exact number of people who travel to a race, but I think it's like 80 people go to a race. Uh, and so it's not always the same 80 people who go every week to different races, but, uh, they have different teams. So for the, for example, the Garage team that I spoke about earlier, uh, they have, I believe, an A and a B team.
Uh, so they're setting up two different tracks at the same time. Yeah. So how is the team doing from your perspective?
Yeah, they're doing great. I mean, it's been six months since we, uh, started working and we're already seeing massive improvements, uh, in the way that they work. Uh, we've reduced how many meetings they're having.
Uh, we've been unlocking knowledge between the different teams, uh, at a, at the, at the race teams team, uh, predominantly using Confluence and Rvo. Uh, they're seeing great benefits from using Loom. Um, that was one way of cutting down meetings, but also recording meetings, uh, which gives you a nice summary with nice actions, uh, automated as a result of that, uh, is also paying some big dividends for them.
Um, are the engineers discovering anything or they, they didn't know before? Or are they finding duplicate efforts or anything like that? Yeah, I mean, if you look at any company they, they problems that happen, uh, in any company where you have people working on the same thing or the same thing in different ways, uh, I think it comes down to a few things.
It comes to prioritization and to, um, visibility across what people are doing in different teams. If we, if we talk about prioritization for a second, um, their, their top level goal is to improve lab time. Now, the thing about Formula One teams is they have a cost cap.
And so nearly all the people they hire are trying to contribute to reducing lab time. Uh, and so then it becomes hard to prioritize because everything is contributing to the overall goal. Uh, and so what they've been able to do using JPD is define what is value for them, uh, what does it mean to reduce lap time.
They put all of their ideas in one place with all of their data that supports that idea. They can track how much effort something will take and the impact they think it's going to have. And it becomes a really nice way for them to prioritize what's important for them to work on right now versus something that we can work on a little bit later on.
I would imagine that they're also trying to prioritize their own efforts, but a lot of the knowledge you seem to be capturing used to be, you know, what we call wet wear between somebody's ears. So have they kind of figured out that they can now maybe, um, you know, if somebody leaves the team, it's not as catastrophic an event because there's a, the tribal knowledge is captured. Yeah, absolutely.
I mean, um, as a part of the design of the car and when they, when they're doing their aerodynamics, uh, a lot of the information was captured in places where it was only accessible to one or two people or, or a very small group of people. Uh, which is problematic when, um, that's the very beginning of a process. 'cause that that information, uh, results in the design, which ends up in the wind tunnel, which eventually ends up as a part of a car.
So there are many people who need to contribute to, um, that process. And so having the very beginning of that process locked away, uh, doesn't enable the, a nice collaboration flow, uh, throughout that value stream. So now that it's being captured in Confluence, it's indexed by VO and people are able, are able to surface the right information at the right time throughout the, uh, the end-to-end process.
And the thing that's different about all this with the AI is that, as least as I understand it, it used to be somebody would stand around with like a clipboard and then capture data and then type it in somewhere that nobody else could access it. Um, now it seems like the AI agent is actually capturing all that data and then sharing it with the team. So I'm not sitting there doing a lot of data entry.
Yeah, I mean, so with, with the Atlassian platform, the, the most powerful thing is actually the teamwork graph. So people don't really have to go too, too far out of their way to put information somewhere. We try and connect all the different elements into the teamwork graph so teams can put the information where it works for them, uh, and, and it'll still be accessible through the platform and through vo.
Yeah, Because I think half the battle we've seen with any application is nobody actually wants to spend time putting the data in there, which kind of defeats the purpose. So, um, are we gonna get the value out of the software investments that we've been making all these years in ways that we never could before? I think there's a different way to think about things now.
Uh, I've been speaking to a lot of customers at this conference, uh, about standardization and why they wanna standardize the way teams work. If you think about what a why people wanna standardize is so that information is stored in a consistent way in a, in a place that people can find it and digest it easily. But teams don't want that.
Teams wanna work in a way that works for them in a way that supports them to go faster and get to their outcomes faster. The beauty of teamwork graph and robo means teams are able to work in a way that goes faster for them, maybe with minimal standardization, uh, but other people in the company can still find that information without knowing exactly where to look and in an expected format. Uh, and so now we, we kind of solve that problem around standardization and, uh, limiting the way that teams work through the use of rvo and the graph.
Are they consolidating the number of tools they have? At least I know in my job, my issue isn't necessarily that I don't have a tool. It's more like I got too many of them and I can't quite figure out how to make them all work together.
Yeah, I mean, obviously, uh, they're huge advocates of the Atlassian platform. Uh, and so it's more around enterprise architecture and what product should we use for different things. Uh, and so they are centralizing on Atlassian.
All right. Um, are they playing around with AI agents? Are they gonna build their own or what are you guys thinking?
Yeah, they've built, they've built many different Rover agents. We had a session this morning where Richard Slaughter from a WR spoke about a wind tunnel tapping agent that he built. So he had a lot of knowledge in his head, actually.
He used to be an aerodynamicist. And uh, he's captured all that information in the platform and built his own rover agent so that he can reduce the number of questions he's being asked, uh, about this particular thing. And people are going to the agent now, he's actually been tracking how many people are hitting the agent, and he counts that as a benefit to him.
'cause all those people would've come to him in the past. Yeah, You hit on an interesting point, right? 'cause there are people who are specialists and they have a lot of knowledge, but I might argue they spend half their time just answering questions from the rest of the organization rather than doing what their real day job is.
So will that change the way we think about general purpose workers versus specialists in, um, the way we might even organize our companies? I, I think about it in, um, this concept of low value collaboration and high value collaboration. So low value collaboration is something similar to what you described, where you have someone with deep expertise, people contact that person to extract information that's low value for the person who has the information, even if it's high value for the other person.
So overall, that collaboration is low value 'cause only one party gets, uh, gets benefit from it. High value collaboration is, uh, what I think is being enabled through ai, which is, um, they can go to an agent, they can get the information they need, then if they need to work together on something, both parties will get information be but get value, uh, because the person who was originally asking the the question has enough information to have an informed conversation rather than asking basic questions. Yeah.
So at the end of the day, um, am I gonna get more work done or am I just gonna have less stress in my work life per se? Uh, I think about it in terms of value, right? Like if we think about the person who is answering questions, that's low value for them.
If they're an expert in something, you want them spending as much time as they can working on whatever, whatever's their area of expertise. Uh, so I think by uh, introducing ai, we're able to free up that person's time to spend more time probably on the thing they like doing rather than answering questions. If that reduces stress or not, I don't know.
Depends on the individual. Is Williams trying to figure out, you know, how much of a productivity boost they're seeing or are they just kind of accepting the fact that everybody seems to be working more cohesively and with less toil and that's the benefit in its own right? Yeah, productivity.
Productivity is an interesting one. Uh, academics have been trying to measure productivity for decades unsuccessfully. Um, but absolutely we're looking at how can we be more efficient?
Uh, so where is their time wastage, uh, in the things that they're trying to do, and how do we reduce that? And that shows up in different ways. Like it shows up in number of meetings or effective meetings, uh, you know, how many emails are being sent, things like that, uh, where we often see efficiency traps, um, showing up.
Yeah. So you've been working with them for a while. What's the one thing that you know, kind of surprised you to discover?
Actually their culture is very similar to the Atlassian culture, where, uh, people are very supportive. Everybody who works there really loves their job. Uh, they're all happy to be there and uh, their teams who want to collaborate.
Uh, and so for me it's an absolute pleasure to be able to enable them to do what they already want to do. All right folks, you heard in here Atlassian Williams is a winning team and when they actually win the next trophy, we'll see. Hey, thanks for coming By.
Thanks a lot. All Right. Hello and welcome back to, to Atlassian Europe.
And we're having a chat here with Asha and we're having a discussion about strategy collection, which is a set of tools that Atlassian has developed for well changing the way we manage our companies and our organizations. Asha, welcome to show. Thank you.
So explain this to us a little bit. I know initially came out at the US conference, but now you've updated it a little bit and it's generally available to folks, but there's, as I understand it, three applications. But walk us through the portfolio a little bit.
Yeah, totally. Strategy collection, first off, helps leaders do strategic planning, also helps you do talent management and helps you track your strategic initiatives all the way down to your day-to-day work. We have three apps in the collection.
First is focus, it's our app that helps you do strategy planning and helps you see your strategic priorities in real time. Then we also have talent and app that we just GAed a couple of months ago that lets you do knowledge workforce planning. What I mean by that is you can always make sure the right teams are working on your most important priorities.
And we also have the Align app as a part of strategy collection where your teams of teams can plan and track work and you can make sure that work led us up to our strategic priorities. So that's the strategic collection offering that we have and we continue to add improvements to the collection as uh, time goes on, Right on the face of it. That sounds almost intuitively obvious, but what were people using beforehand?
It seems like what did they have a bunch of spreadsheets that they were just trying to manage stuff with It? Totally great questions. Guess where most companies document their strategy?
Take a guess Word document. Uh, Close Word documents and PowerPoint. Like when I ask customers, where are your strategies documented?
You know, majority of them will say that, which is like, it's in a PowerPoint, but we all know that strategies that go into PowerPoint end up becoming shelfware. I kind of always joke that they go there to die. So that's where the focus app actually comes in.
It helps you convert like a static plan into like a living, breathing strategy. So think, uh, you are a company, you have a couple of line of business units, so each of the business units can have their own strategies and then the departments under can have their own strategies. And then you have execution priorities under, so focus lets you map the entire strategic planning hierarchy in the app.
So you no longer have to worry about it being dead in a PowerPoint or a spreadsheet. It's always tracked in real time. And that's kind of important because at least in my company, the strategy kind of continuously evolves and communicating that to everybody is often difficult.
And then they have to align their department strategy. So as part of the whole effort here, some way to kinda streamline the communications of the intent of the strategy. Yeah, totally.
And also track it in real time, which I don't think like a customer of ours said this really well. Um, for example, Lloyds, let's say where they say there's not another tool where you can actually track your strategy, your goals, and your work as well as the funds think budget all in one place. It's the one collection that lets you kind of manage the entire portfolio.
Mm-hmm. And at least in my experience, we don't always know who we have working in the company and what skills they have and what expertise they have. And sometimes we go out and hire somebody else when we already have somebody who has that skills and expertise.
So as part of the exercise here, just to manage my talent better. Totally, And that's what the talent app does, right? So think about your traditional HRIS tools, which are amazing, but they give you job title org structures, all valuable information, but not realtime information and not what projects they're working on.
So none of the HRIS tools have the work and the people map to the work. So what talent does is it maps every person in there and what funds does is it actually, sorry, what focus does is it manages all of your projects or your initiatives or your strategic initiatives. Now you can see your talent mapped against the initiative that's in funds.
So that's what strategy collection lets you do. We've been talking about AI all week here. How will AI get applied to all of this and what should people kind of expect going forward?
Yeah, like you heard in our keynote, RO is also in strategy collection. So RO helps you bring insights. It also gives you like predictive recommendations and the system and strategy collection where it helps leaders basically figure out what is the next action that they need to take if they figure something is off track.
So it helps you summarize as well as give you predictive insights into what you have to do next about it. Yeah. So will I be able to, I don't know, ask VO which projects that we've funded that are not aligned to my strategy and therefore maybe I might wanna reallocate those resources to something else?
Totally. So what VO will let you do is it'll kind of say, Hey, these are the initiatives that are off track. Mm-hmm.
And it'll help you identify smart recommendations as well. So for example, it can tell you, Hey, this initiative is off track. And to bring it back on track, you may need to add senior engineering talent in US West, let's say.
Then you go into the talent app and you can filter down for the very first time on, give me all of the senior engineering talent that's in US West, and the talent app will narrow down that list for you and now you can identify what focus areas are they working on. If all of those focus areas are on track, it probably gives you an opportunity to say, I'm gonna identify some people and bring my other initiative back on track. So that's the beauty of strategy collection.
The other thing that business leaders routinely struggle with is there's dependencies between projects. And so suddenly I think that, you know, these projects are moving along, but then I discover that there's a bottleneck because this other project is way behind and nothing's gonna move forward accordingly, but I never know that until it's too late. Can I see that now?
A hundred percent. So we have a app called Jira Align, like I was saying earlier, that's the app where across your enterprise you can do work planning. So that particular app has dependencies and ask in there as well.
So you can see not just your projects, you can also identify what is the dependency that each of the projects have on each other. And then ro on top of strategy collection helps you draw insights, um, which make all of our leaders a lot more intelligent. So I kind of always look at it as Atlassian's mission is unleash the potential of every team, and I think of strategy collection as unleashing the potential of every company.
Ah. So what does it take to get started with all this? Because to your point, I do have all these PowerPoints and spreadsheets and Word documents.
How do I get from there to this strategy collection that you're talking about? Do I import all that stuff that I already have or do I gotta reenter it? Or how does that all come together?
Yeah, Totally. Um, our vision ultimately is that VU one day helps you just upload all of your PowerPoint and spreadsheets or wherever your structure is, both of like people as well as the strategic priorities that I'm talking about. And the product, you know, during the onboarding phase helps you set it up, but for now, you can also choose to kind of manually set that up.
So as we onboard customers, we actually work with them on what is the structure of their company, so what are the lines of businesses they have, what are the portfolios under each one of them? What are the biggest strategic or market projects as customers call it, that they're working on? And then we also map the work in Jira to each of those initiatives.
We then help the leaders identify their goals and they can set up goals against each of those initiatives as well. And then the product tracks that end to end. And then VO on top of it helps you give insights.
Every company that I know has owners and investors, and there's usually some sort of quarterly meeting where we all get ready for and we give these giant preparations for, and, and we, we spend an inordinate amount of time getting that together. Will that become easier? Because it sounds to me like all those documents are now living documents within your system and I can be ready for that meeting and a couple hours, A hundred percent.
I promise I didn't plan this question, uh, but totally. So what strategy collection lets you do, and we do this in Atlassian. So we run Atlassian off strategy collection, like I was saying earlier.
So every month in our monthly business review, all the leaders in the respective portfolio put in their updates on what's working well, what's not working well, how are they tracking against the portfolio's goals, and we actually run our monthly exec reviews of the product itself. So that's how we have been running Atlassian on Atlassian on strategy collection. And most definitely it gets easier because now these are not documents that are won and done and they get lost in a shelfware.
You can track progress in real time. And more importantly, I'm also excited to introduce, we have strategy events within the product. What that means is every quarter, or it could be every half, or it could be every year depending on the planning cycle for the company, every company looks back, let's say at the last quarter, which I always call as an inspect phase, and they adapt the next quarter or the next half or the next year.
So what strategy events lets you do is every portfolio or every leader or every unit leader can make proposals that kinda get tracked within the system, be it proposals for change in headcount, change in goals, change in projects, and then the leaders of the company can decide to approve or not approve. So even the quarterly planning has gotten a lot more structured and efficient with both strategy events as well as the product as a whole. Yeah, The only other activity that's similar but even less fun is a lot of organizations are public and they have to deal with auditors and all kinds of folks come through.
Is that gonna get simpler too? Because all this stuff is already organized and kind of easier to present? I would definitely argue that strategy collection is the organizational capability that you need to help yourself get organized to lower the leaks in the system, and most importantly, unleash knowledge and insight.
So you kinda know how is your company's operating model actually working? Is the company efficient, not efficient? And like our sharing with the fund's view, you can now track budget versus spend too.
And when I say spend, you can truly understand how much of your spend is in change the business versus run the business. You can double click into your spend into labor and non-labor costs, as well as double click into your labor spend so you know how much of your spend is in product versus data engineering versus let's say marketing versus sales. So it gives you insights and visibility that you have never had before.
There you go. Hey folks, you heard it here. Running companies is stressful.
There's no two ways about it, but it could be a lot less stressful if we had different software to manage the workplace and everything that goes with it, including the talent. Asha, thanks for being on the show, being A pleasure. Thank you all And we'll be back in a minute.
Your Edge Fleet, your Edge project, you need to make this successful because you're investing a lot of money in it, not just today, but tomorrow, next year, and probably five years from now. Join us on the special episode of the Tech Field Day podcast as we talk with from career. Welcome to the Tech Fields Aid podcast, where we bring together a group of IT technical experts to discuss a single idea around key concepts in the industry.
This podcast features a variety of perspectives from members of the Tech Fields aid delegate community, and is often recorded in association with one of our events. Tech Field Day is part of the Futurum group, and this podcast is also published on our sister company site Text tv. On this episode presented by Zaida, we'll be discussing the premise that without Fleet Lifecycle Management, your edge projects will fail.
Before we start the discussion, let's meet who's on the panel today. Uh, hi, I'm Guy Courier. I'm an analyst at the Futurum Group.
Um, ai, AI infrastructure edge, um, as well as, uh, some of the things that fuel, fuel, those like chip sets, containers and so forth. Those are my areas of coverage. Hey guys, I'm Sachin Eva.
I am the VP of product here at Zita, and I am responsible for driving the product strategy pricing as well as driving the portfolio around Edge AI as well as management and orchestration solutions. And of course, I'm Alistair Cook. I'm an event lead here at Tech Field Day.
And what to look at the kind of context of edge deployments and some of the things that make edge deployments quite different to how we might sort of view things. Sometimes we view, uh, edge deployments as an, an edge projects as being a, a cross between being a, a cloud platform and being, uh, like managing a fleet of laptops. And while it has elements of both of these it's own quite unique complexion, these projects to deploy, uh, intelligence and, and applications out to the edge are very different to giving a a, a group of traveling salespeople their laptops or using cloud services.
We have near infinite resources available in front of us. Um, one of the other elements on this is that that edge deployments tend to be characterized by a huge number of very small deployments. We end up with devices at every branch or attached to every oil well or to every, uh, ship that we have traveling around the world.
And that, that that's, um, lots of small deployments is very different from dealing with clouds that are, that are massive. And so things that sort of make sense in the public cloud and makes sense if you, you have a, a small number of laptops that are in the hands of skilled and experienced staff don't necessarily translate to where you're putting a whole lot of devices out in hostile locations with potentially staff who really don't care about those devices at all. And, uh, but makes things quite difficult as we scale and operations start to dominate.
What we're actually doing, uh, moves, ads, changes to the applications. These things that are out at the edge, uh, section is you are working with customers, particularly those who are adding functionality like the AI that you're focusing on. Um, what are the sort of challenges as they, they hitting with managing their fleet of locations as changes are come, come in, Right?
Uh, there's actually quite a few challenges that we are seeing, uh, especially with, uh, AI coming more and more, uh, apparent and, and, and more organized and more structured first, uh, and foremost, you know, so fleet management is about managing total cost of ownership of your devices, the lifecycle. And, uh, that includes also the, uh, not just updating the office stack, but also updating the applications that run on these devices. So the, with ai, what's going on is the, the applications are iterating faster.
They're AI models that are coming around, uh, with, with newer technology, uh, you know, interfaces, um, without even talking about gen ai, if we take the classic machine learning models, they are, uh, now starting to be fully commoditized. And so we are seeing the, uh, challenge, uh, of taking and packaging these models in a way that they're lightweight and they're easily deployable. Second, uh, the version management of these models, uh, become super important across the fleet.
Uh, you might have different versions deployed for different application types because one version sort of exists and continues to operate as it was trained, but another version might be required because, um, you know, uh, the data has changed for a particular region, for a particular site. So within the fleet there, uh, you know, there are, um, parts of the fleet that will require, uh, you know, the, the sort of, uh, model management, uh, to be different versions. Uh, so packaging will change accordingly.
Uh, uh, the, the ability to then coming back to like back to lifecycle is automation, right? So how do we easily drive, uh, uh, changes that are maybe driven by the IT team for security purposes, but the OT team, uh, does not want to apply the change right away. So there's a, a, a management, uh, for the edge when it comes to fleet management to actually hybridize this IT o OT bridge and make sure that, uh, there's a right level of approval that's built into this fleet orchestration solution as well.
I think that, um, when I think about, I mean This is really good insight, uh, Sachin, because when I think about, um, let's take the word fleet out for just a second. When you think about managing, um, edge applications to start with, there are at least three basic dimensions to this, because there's the management of the physical device and, and its physical environment. Um, there is management of, uh, the payload.
Um, and then there's, uh, a management of, uh, uh, communications. Uh, whether it's, uh, it could be a data collection device or it could be a data utilization device, um, uh, you know, a drone or something like that. A data utilization just meaning, uh, the application performing, uh, functionality of some sort in field.
But when you add AI into this, um, that creates an added level of complexity and, and variation. The variation of, I mean, you talked about machine learning. There's a certain amount that can and must happen for disconnected devices in the field.
There's data collection and training back in the core that's required. You might wanna do pre-processing for that. So, so, um, the, uh, the relationship of the ultimate application to the ai, um, is an added area of management.
And it was helpful to me for you to open up this idea of the provisioning and the payload and the application and versioning position in the lifecycle. That also all needs to be considered part of fleet management as well. And I, and I suppose, and this might be my question back to you, Sachin.
Um, I suppose that, you know, part of the game here, uh, for customers is to understand where they need to focus. Because you, you, you can't focus on six things. You, you need to focus on, on the most important elements of that, that that management part of it that comes after development when you're on day one and beyond.
Is that, is that right? And what sort of shape does that focus take? How do you advise your customers where to focus?
That's a, uh, that's a good segue, right? So back to sort of, um, let's, you know, when we talk about fleet and lifecycle, right? All these, uh, um, words that sort of interlinked, let's talk about the lifecycle and the anatomy of an AI application, right?
Let's start there, and then, then we can talk about the focus that we need customers to sort of really put energy on. So first and foremost, um, you mentioned, right, there's a, there's a training that happens. Uh, there's data that's involved, right?
All of that can happen in a centralized location where all of the centralized data lake, uh, is connecting all this info. Um, and once this training has occurred, however, there is a, a need for the customer to take this package, it in a way that it's lightweight, so it fits the edge form factor might be deploying this on a small, sort of a Nvidia Jetson based platform, which has, uh, you know, limited, uh, resources. Or we might be doing this on a high-end GPU AI server, which has, uh, you know, a lot of resources.
So, so there has a, there has to be a deterministic or there's a determination on the resource at the edge. And, and ideally, you don't want to think about it at the time of, you know, thinking of deploying this. So ideally, you want to sort of push that decision to somebody else, like, where does it go in a consistent way?
And if the resource is not available, what happens then? Uh, then if you continue on the lifecycle, right? Once you move into a deployment, then there's monitoring, which is, uh, observability.
You know, how is my application performing? How is this AI model accuracy? You know, is it up or down?
Is it data drift? Uh, to your point, right? Data collection has to occur, occur, uh, occur.
Typically, that, um, ecosystem is driven by, uh, data collection, not at the edge, but data collection all the way making data, making its way all the way back into the cloud. So there's an obvious cost to pushing data all the way back and then figuring out if the model drift occurred or not. So, uh, let's, uh, take this apart, right?
So on the deployment side, uh, the, um, identifying the target, identifying the right environment, and then packaging it to the right form factor, and then monitoring means, um, maybe collecting the data at the edge and then having, you know, something to do with retraining the model at the edge. Uh, those become sort of really sort of big drivers for driving this. So now, um, what we are starting to talk about with customers is their focus needs to be on the model itself.
I mean, they have the domain expertise on the business logic that gets attached to the model. The model is doing its bit, which is the inference part, but once the output of the inference comes in, right, they have to bring, bring some post-processing logic that helps, uh, you know, conclude to certain business decisions that happen either at the edge or happen maybe centrally. And so, let's, uh, help you, Mr.
Customer focus on solving those problems within the application and take the rest of the application challenges around packaging, deploying, fitting it to the right form factor, observing or collecting data, uh, leave it to, you know, an infrastructure provider to help you get all that info, uh, so that you can actually come back and then decide whether your model actually worked properly. Whether you are able to glean the right information to make the right business decision, whether you can automate around it deterministically, or whether you need to continue to sort of iterate and, uh, and continue to, you know, uh, what we call test, uh, and, and deploy and trade, right? So, and, and we know with ai, uh, iteration and testing, and, you know, what we call AB testing is, is the norm nowadays, right?
Because a single model doesn't fit all use cases, whether it's overfitted or unfitted. Uh, but, and so, so you know, these, um, so focus on the business logic, focus on the outputs of these models, and let us take care of the rest. I mean, it starts to get really interesting when you're thinking about variation, um, based on local conditions and, and learning and, and, and maybe some sort of, you know, automated or, or, or not fully automated iteration and versioning.
I mean, that's like the mother of all forks. I mean, uh, that's not necessarily something that, uh, that, that it's, it's the sort of thing that can give a customer pause. But it sounds like Aida's point of view here is that there are certain elements of that that are more technical than domain related.
If you're an ag or if you are in energy, um, you wanna focus on, um, you know, uh, applying your, what you call the business business, I think, business rules. But it's really about how you're operating your company, what your go-to market model is in energy, in ag, um, and, um, certainly focus AI development, data management, and all that sort of thing on that domain. And Aida's point of view is there's, there are technical elements of this that can and should be handled by provider tool software.
Yeah. Is that right? That's absolutely correct.
I think one of the things I wanted to hit on was quite a lot of what you've talked about, sachan is true for people who are doing AI deployments that are not edge deployments, that are doing this in, in their own data centers as well. A lot of that, that same process goes on for a deployment in your own data center, but that's quite different from where the actual business logic is being applied at hundreds of locations spread around the world. And that decisions need to be made locally inside each of those locations for speed and cost reasons.
Uh, and particularly one of the things we see is the intermittent connection of some of these locations. And that adds another dimension that maybe the, the model that we believe is our, our best, most accurate model is only in 90 of our a hundred locations, because 10 of them have been offline during that update, and maybe two of those were offline in the last update as well. And this is that, that perspective on fleet management and wanting to have policy-based management across it rather than having to manage every single site individually.
And I think that's really where you're talking about handing off this responsibility for the, essentially providing a, a platform and an infrastructure layer and a consistent and predictable way. I think that that difference between doing this in your own data center to doing it across lots of potentially intermittently connected low power locations is what's really different in edge deployments versus cloud or on premises. Yeah, that's a, that's a great point.
And, um, two words come to mind when, you know, we talk about these two items where you start off in this centralized mode of operations, and then you're trying to really deploy something at the edge, which has different constraints. And you may not have tested for it, you may not have thought through all the implications of it, so quantization and optimization, right? So, so we believe that, um, that is a significant effort, uh, in, especially as, as the edge, as you're aware, there are a variety and diversity of platforms out there, right?
So, and, and we know there's a constant sort of, um, uptick on the number of, uh, systems or platforms or chips we are seeing now in the market. So, you know, for example, Nvidia is pushing, uh, the Jetson infrastructure and the Jetson chip, uh, platform, and it's actually revving. Its super fast.
So, you know, within, uh, a couple of years, we've already seen, like within this year, we've already seen two versions, two variations come up. And, and the last one, the Jetson Thor was based on the Blackwell GPU, but that's not alone, right? I mean, you've got Qualcomm with, with, uh, with their NPUs, and then you've got custom chip makers, um, um, like Halo and, you know, with TPUs, and then you've got the hyperscalers bringing their own flavors of the chips that they're also building, which they might want, and also push towards the edge.
So we are seeing a plethora of all these systems. And, and so when you start thinking about quantization and optimization, you have to think about the common, common, you know, elements that exist from an infrastructure point of view to help you deploy this in a consistent way without worrying about, um, uh, you know, getting, uh, a hit on your accuracy or hit on your performance. Now, um, it is a tough problem.
It's not an easy problem, but, you know, we love to like try to like address this in a, in a way that we can address it, uh, one step at a time and, you know, ensure that we can actually move towards some level of standardization. Uh, there's a lot of open source efforts going on towards taking the work that, uh, is being done, um, for one specific chip set maker, and then bringing it as a generic, uh, you know, approach to inference, for example. And inference engines are, are sort of, you know, um, are taking on that the open source community is taking on that effort as well.
I wonder though, uh, if I, I rather feel like this is an issue that's not talked about much in edge. Um, and maybe it's because it's a non-issue, but that's diversity of, of platform, uh, meaning hardware platform, meaning edge device platform. My, my general sense from talking with customers and, and especially, uh, application managers over the years, um, because this has been going on for a long time, including AI at the edge going on for quite a long time, is that, uh, any one application actually can have several different types of edge devices.
Um, it's not just a question of architecture, it's a question of size, rugged, non rugged. Is it a, does it have a human interface? Does it not?
Is it collecting, is it, in other words, is it, is it mobile or is it fixed? You know, what kind of connectivity that single applications have? Diverse hosting environments.
And, you know, I'm sorry, but you know, I don't, I don't see K two s as really solving this. I don't see anything solving this other than, uh, a way to, I, I'm gonna use the word centralized, but I just mean sort of in a virtual sense, centralizing development, so that there is a way to develop one application, but that can have its various functionalities deployed into diverse, um, onto diverse hosts. So, so I, I just wonder if, you know, from, from the analyst perch that I sit on, if that's just me speculating or if that's actually a reality, and if so, why isn't it talked about more?
So it's the same idea that, you know, um, a lot of companies in the networking space talk about when they built the hardware abstraction layers, right? The Hal, so you're right, uh, at, at some point, you know, when the rubber meets road and you're actually trying to bring a hell that actually works on a specific platform or device, right? Uh, you've gotta make sure that it actually works, end, works end to end.
So it's the same concept for us, right? We, we will handpick a few that are most predominant in the industry and start with them. And then as, as adoption occurs across, you know, other, uh, players and emergent or existing players coming in, uh, and, and so customer driven, right?
Adoption, then, you know, we'll start to address it as part of, uh, this, uh, this notion of a hell or this notion of an abstraction interface, which, uh, starts to abstract it. What we are, what you're correct about is that, uh, we would have to pick and choose. Sometimes, you know, sometimes it's not feasible, you know, the portability is a, is, is a, is a desired sort of inconsistency of workflow is a desired end state.
But, you know, for some applications we may not never achieve that. So especially like where we, we are seeing a very diverse, uh, set of, uh, applications, but I think our, the vendors we're working with are also trying to address that. So, HMI related, like where you have touch screens, uh, the apps are gonna be very different.
There's gonna be a lot of sort of, you know, um, um, interfaces, uh, that built in are on the touchscreen and the actions, and then versus, you know, an, an industrial pc, which is not, uh, you know, looking for that interactive mode of operation. So, uh, we do, you know, it's, it comes back to the anatomy of, uh, of the application itself and what you're trying to do. Um, you know, and if you break it down into a series of microservices with accompanying models and accompanying data for managing drift, uh, we can argue, yeah, we, you know, how we then package this, uh, whether there's a UI or not UI component or not becomes an interesting conversation to your point.
Um, but yeah, I mean, the, the, the model will certainly have a dependency, and the runtime of the model will have a dependency on the type of hardware you deploy. That that is, Yeah, that's, that's the real, I mean, Alistair, you, you, you've lived that, that it's these, these reference platforms and everything. They just sound really great when you're in buy mode.
But then when you're in use mode, that's when you know, you have the company breeding down your neck and, and yeah, you setting off your beeper in the middle of the night, right? There's, there's also the element that your edge, each deployment is not gonna be a written replace everything when there is an update that you'll end up as, as you see with the diversity of hardware, even if you have multiple sites that have exactly the same requirements as the same application set, you may have one site that has hardware that's six months old, another site that has hardware that's four and a half years old, and managing that diversity, making sure that we're not pushing down a model to that old hardware that is so, uh, heavily quantized that will fit on the hardware, but no longer produces a useful result. There's absolutely some challenges around fleet management across that diversity and, and then flagging back to the hardware lifecycle as well as to the application.
And the, the infrastructure underneath the lifecycle of these things are all tied together and driven changes driven by the business need. But there's a very high change for, uh, high cost for changing the hardware at all of these Edge locations compared to trying to shoehorn whatever application we can get into the hardware that's already there. Uh, this is what leads us to four and a half year old hardware sites, because it's sitting out in a, in Alaskan mine, uh, and it's just monitoring as, as one of the, the examples I've seen is monitoring a conveyor belt to see if one of the staff has, uh, gotten onto the conveyor belt because they're maybe, hmm, not in good working condition, uh, the staff that is not the conveyor belt.
So, yeah, that, that diversity is a challenge That that is exactly right. So, uh, you know, there's a promise of, of an abstraction and a reference, uh, you know, uh, platform. But the reality is there's diversity to manage, and it becomes half process and half technology.
So, you know, so yeah, one of our customers, uh, you know, has more than 18 vendors. I, I don't think, I don't think customers are asking for this problem to be eliminated, but that's what vendors are offering. We have this magic potion that's gonna eliminate this problem.
I think customers are looking for a way to rapidly and relatively simply respond, be responsive to these scenarios and situations. A node goes out, they need to be able to do something about it, um, in a reasonable way because, you know, as they say, stuff happens. Yeah.
So, so I would argue that, uh, for ai, right? It's wild, wild west. So, you know, and so there is some level of standardization that can happen.
Uh, for example, you know, the inference engines, uh, out there like open vio, infra, you know, uh, the, uh, your, uh, tensor RT or, you know, like the new Dynamo or, um, on nx, right? So, so, so we will see some level of settling and, and our customers asking us, well, tell us upfront if you are comfortable driving on nx, then we'll align to on NX as a format for packaging. And so there is that level of conversation also happening at the same time.
So, so I, you know, while, while there is no magical cure for, for the diversity of hardware, there's definitely a, a a, a runtime that can be, uh, you know, that the format, uh, for example, could be agreed upon. It could be an agreed upon. It doesn't mean it's, uh, it's an industry-wide standard that's adopted, but, you know, adoption and sort of this goes hand in hand.
So, so I think if you can agree upon one or two or a couple versus, uh, bring a lot of flexibility into your fleet, uh, management, then, you know, then, then you can really sort of own and manage it. I think it really frees the, um, the, the, the, um, let's say the device management team too, to respond to, uh, more quickly to, uh, new opportunities, new, not just new applications. I'm thinking, you know, uh, um, you know, entering new fields, new operational zones and areas, whatever it is.
I'm, I'm losing my lingo here because I don't have that domain expertise necessarily, but it allows them to, um, to be more creative. As always, on the Tech Field Day podcast, our guests could continue to discuss and learn from one another for hours, possibly days, Frank. That's probably why we have longer events at Tech Field Day.
But I'd like to thank you all for joining us today at the Tech Field Day podcast. And before we go, where can the people watching people listening connect with you and continue this conversation? com.
Um, and, uh, as I attend events and conferences or do, um, uh, shows like this one I tend to post in LinkedIn, that's a good place. And I'm also at Blue Sky at Guy Courier, blue Sky, whatever. It's, You can find me at, uh, you know, on the, uh, zaa do com website, um, where you can reach out to the zaa team, as well as on LinkedIn.
Um, so yeah, happy to provide more, uh, more insights as needed and looking to engage. Yeah. And of course, you can find me Alistair Cook on, uh, any of the Tech Field Day and Future insights, as well as on LinkedIn.
Uh, do make sure to check out the previous visit presentations that we've seen from zaida. You'll find them all on the Tech Field Day website. If you just, uh, go to Tech Field Day slash company slash zaida, you'll find all the great presentations from.
And so, thank you for listening to this episode of the Tech Field Day podcasts, uh, showcasing Adidas Edge expertise. If you've enjoyed this discussion, subscribe on YouTube or your favorite podcast application. So don't miss a single episode.
Uh, do also remember to give us a rating, a very positive rating, and a nice review. This podcast was brought to you by zaida and Tech Field Day, the home of IT experts from across the enterprise and a part of the RUM group For upcoming events and more episodes, head to day slash podcast or view us on text on tv. Thanks for listening, and we'll see you next week.
Hey, guys, thanks with Throw, we're here with Inmar Apple Blot, who is the CEO of Token Security, and we're having a little chat about AI agents and non-human identities. 'cause well, we've been trying to manage these things before and we're not so good at it, and it might get worse before it gets better. Inmar, welcome to show.
Hello. Nice to be here. Walk us through this a little bit, but I think people can understand the idea that there are these non-human identities.
They're machines, there's software applications, there's more of them than there are humans, and now it looks like we're moving and exponentially increase them with the number of AI agents. Is that a fair assessment in what we're looking at? Oh, yeah, absolutely.
Today, by the way, we have 98% of our identity, uh, infrastructure is our non-human identities. So it's one to 50. The ratio between human and non-human now that, uh, CEOs and board members asking for, uh, security team to adopt agents and have this AI transformation, the amount of non-human identities of identity that meant automation gonna go even more.
And we, we already seeing it happening in, in a lot of our customers environment. Yeah. So it also seems to me that we're not very good at managing them as they are.
So how are we gonna manage 'em when there's gonna be exponentially more of them soon? Are we prepared? Yeah, yeah.
I think that, uh, right now, uh, uh, the piece, uh, we have a lot of solutions for human identities when it comes to non-human. Um, we, we overlook that for a while. Um, cloud and our AI really created an acceleration of the amount of identities.
So the first biggest, like, I think that the first challenge is understanding, uh, and, and gaining visibility into those identities, right? Knowing about them, knowing about the risk, and then also understand who is accountable for that. You have an AI agent who is responsible for that.
Uh, so I think those are the first few gaps that you want to tackle. And then also understand how, how to support those, those identities in scale, manage their lifecycle, and, uh, and improve their security posture. Mm-hmm.
Is the risk level gonna be higher? Because, at least as far as I understand it, a lot of these AI agents are going to be somewhat autonomous, and if somebody compromises them, they might take over an entire workflow. Yeah, yeah.
Um, the risk is, is is similar but also different when it comes to, uh, identities of, uh, of AI agents and, uh, agent ai. What we see is that one of the biggest challenges, so historically you have human identities and non-human or workload identities. So for human, you have, uh, identities that running in a very low scale and taking, uh, actions.
The permission is best based on their roles in the organization, right? Then you have workload identities that are deterministic. It's very hard to predict what they're gonna do, but they're doing it in scale all the time.
Now, AI is a bit of a combination of the two, right? It's on one hand, has the flexibility of a human, but then the scale and the robustness of, of identity. And that create a, a, a, a much bigger challenge to, to manage and to, and to manage their boundaries and secure them.
Mm-hmm. So what is your best advice to folks? 'cause I also think people are kind of, at least historically, that had one platform for managing human identities and they had other platforms for non-human or, and does all that need to converge now when we have these hybrid identities that are sitting in the middle of it?
Or are we gonna have a separate platform for the AI agents alongside the other platforms we're using for other identities? Yeah, so, um, my first advice, regardless to the type of a platform, is to really, um, gain, uh, before running into, um, creating architectures of how agents should interact with one another. You need to understand what you have, you need to look and gain visibility into all of your agents gain, uh, uh, um, traceability into their actions.
Logs collection is very important here. The other thing is try to separate between, uh, regular identities for human regular identities, for workload identities and identities for AI. Agents don't use singular identity for different actions from different workloads or operations.
We see that today, quite often, that you see a human identity that an agent is running on their behalf. That's, that's really problematic when you want to manage those in scale. So, my, my first advice, gain visibility in what you have, have, uh, improve your log retentions and collection in order to gain traceability and adaptability.
And the third part is, um, separate between the identities. So you will have a, a, a very good source of truth. I also can't help but wonder how sophisticated these attacks might get in this regard.
Um, today, cyber criminals will steal your credentials and pretend to be you, and they'll hang out for a while, and they'll even start to look like insiders. Well, won't the same thing happen with AI agents? Somebody will create a fake AI agent that may look legitimate for an extended period of time before somebody decides to actually, um, invoke its more malicious capabilities.
Yeah, yeah. That, that's a good point. Look, today, uh, most attacks are identity based attacks, right?
Hackers don't break in. They log in to also be with an, with, with agents. So I don't, I don't think that it'll, the first ways of attacks will be generating those new agents.
'cause you already have a lot of them. They'll not monitored well enough, and they're not secured. So threat actors now have like, uh, a real, um, good variety of types of identities that are mismanaged that they can, uh, uh, uh, take advantage of.
Mm-hmm. Um, are we waiting for some sort of cataclysmic event to occur before we have to get serious about this? It seems like, once again, there's an emerging technology and the cybersecurity folks are chasing after it again.
Yeah, yeah. Uh, look, uh, in, in the energized space, we see attacks happening all the time. And the market in the past couple of years started to, to, uh, um, be more aware of these challenges and, and, and have, uh, an architecture for that.
I, we are going to see it part of, uh, agents as well. But what we need to consider is that the pace of adoption is just much faster than ever before. We see Fortune 500 that five months ago didn't have any agents and now have thousands of new agents that's running in their environment, because every organization understand that this is, uh, um, um, a business enablement and, and that that could really help them succeed.
And also a competitive advantage. So we will see it, uh, um, uh, um, being adopted faster. The other thing that I want to mention is that we see a lot of times the security teams adopting agents for them to be more, uh, efficient.
So the wellness for, uh, threats and, and lifecycle management is a bit higher. I ju I don't think it'll be just from the incident perspective, that only then, uh, security teams will start, uh, uh, uh, look for that, uh, for a solution. They're already looking for that.
Mm-hmm. Um, will we need to update, or maybe they already have, are the regulations and compliance frameworks that we see. I mean, we have things like HIPAA and all kinds of stuff that's out there, but, um, I don't think we're gonna write new regs, so we just need to update the ones we have for the age of AI agents.
Yeah, I, I, I, I agree. I think that that's, that's the way to go. The are, um, I, as I ISO and different compliance, uh, uh, and regulations that are well meant for managing, uh, a AI and securing ai.
But I do think that the, um, that the regular regulations that we're following should also consider a world where organization adopting ai, 'cause it's already happening, uh, and also giving tools for the auditors to actually validate some of those, uh, compliance, which I think it's, it is part of the problem when you don't have visibility to those agents, then how do you validate that you are following some of those compliance could be a bit tough. So we need to update those, Right? So once that one thing you kinda see folks doing today that makes you just shake your head a little bit and go, folks, we might wanna be a little bit smarter than that.
Yeah. Uh, I, I, I think that, that on on one side, we see organizations that says, uh, uh, and security teams that say, you know what? I don't understand the threat.
I don't, I don't want to, I don't allow any adoption of AI agents. I actually, uh, uh, also as, as a CEO of a company, I feel that this is not the right approach. You do need to iterate fast and be, and allowing your business to move forward and support the migration and not just block them.
On the other hand, we see some teams that are, it's really the wild, wild west, and there is no any visibility into their agents. And, and, and that's the other way. So there's always a spectrum, and you want to be somewhere in the middle enable allowing your organization to move fast, but at the same time, uh, um, um, um, have some philosophy and support the phases of their adoption and add controls as you're growing, uh, uh, in your AI journey.
The, my, I think that today, the biggest issue that I see for organization is using the same identity for multiple different, uh, actions consumers. So you see both human and AI using the same identity, and that just can create a, a, a chaos, Right? And to your point, are we likely to see the rise of what we might call shadow AI agents?
And might those shadow AI agents outnumber these so-called legitimate AI agents? Is that where we're headed? Yeah, a bit similar to shadow it, right?
You had, uh, uh, uh, uh, a decade ago, one of the biggest problem is that organization just adapted a lot of shape or forms of it that weren't part of the security visibility and part of their controls. We see that also with shadow ai, where organization are leveraging some AI agents, AI mechanisms, uh, that are not part of their, um, um, framework and how they wanna manage. So I think that this visibility into those all types of ai, uh, agents is, is the first step to go.
All right. Yeah, folks you heard in here we're just beginning to understand the scope of the issue. And AI agents, if you don't have 'em in your organization already, they're coming and well, they're gonna be some of the richest targets out there.
So you might want to think about how to secure them now. 'cause if you do it later, it might be too late in Amar. Thanks being on the show.
Thanks, Mike. It was a pleasure. All right, back to you guys.
Hey, everyone. Welcome back here to our live coverage of RSA conference 2025. We are in Moscone West on what they call Broadcast Alley, and we've been doing mostly interviews of people here at the show, and we're gonna do that today.
But really, this is a special edition of our DevSecOps Show, cracking the code, which we do like every other week. Anyway, um, cracking the codes available on your favorite podcast, uh, platform, whatever that may be. Excellent.
Textron tv, YouTube's Textron TV channel. And by the time you watch this, probably our Textron TV OTT channel. So you could watch this on Apple TV or Roku or Amazon or whatever you'd like.
The important thing is to watch it on cracking the code. We explore the frontiers of DevSecOps. Um, and just yesterday we had our 10th annual DevSecOps event here at the RSA conference, and it was about ai, AppSec and app dev.
Great, great show. We have actually some of our speakers here today, were there yesterday. Um, but let me introduce you to today's panel for this episode of Cracking the Code.
I'm gonna start to my far right, this gentleman here, Aaron. Yeah. Hunsberger.
Yes. Aaron Is, um, with Check Marks, who of course is the sponsor of our Cracking the Code show, our partner in producing it. Iran, it's great to have you on in person across the table from me.
Yeah. Thank you for having me. Uh, thank you.
Uh, I run the product marketing for check marks and, uh, excited about the show. We are hearing ama hearing amazing things, uh, at, uh, RSA so far. Good.
Happy to share them with you guys. Absolutely. It's great to have you on.
I've said this before, Aaron and I go back a little while, even before check Marks and everything else, so it's great to be working with him again. Next to I on this little lady right here is a firecracker. She came to our show yesterday and lit it up at the, on the stage there.
And she was up, she was in the panel with the CIO, the CISO CSOs of Open AI and anthropic and senior Security people from Meta, but she had the most to say her name is Marran Ashkenazi Marran, welcome and thank you. Thank You everyone. It's pleasure to be here.
Thank you for having me yesterday. It was amazing panel and super interesting to get everyone's thoughts, so excellent. I happy, happy to be here From tell people a little bit about you.
Yeah. So I'm j ffr, chief Security Officer. I'm within Jfr for five and a half years.
It's amazing because we're doing our own journey into the security, and we're a DevOps company and now a DevSecOps company that providing a whole solution for the supply chain insecure with ai. Uh, everything is simple. Absolutely.
Of course, our audience is no stranger to check marks or Jfr for that matter. Well, let me introduce you to our third, third guest. Tyler, I blanked on your last name, Egypt, I apologize.
It's all right. How do you pronounce it? Egypt.
Egypt. Mm-hmm. Tyler, Egypt.
Tyler, why don't you introduce yourself? I Appreciate it. Thanks for having me here.
So, my name is Tyler Egypt. I'm our Vice President of Global Enablement at Check marks. So I work closely with, uh, enabling, uh, not only the field at check marks, but also our customers and partners bringing awareness around AppSec, uh, and the great capabilities that we have and offer.
So, very excited to talk about DevSecOps and some of the advancements we've seen and, uh, especially at this event of, uh, learning more and more about trends across the products. Absolutely. So let me kick things off.
You know, as I mentioned yesterday was our 10th annual Devs DevSecOps Connect here. I remember 10 years ago it was like having a wedding where the in-laws didn't get along, right? Yeah.
So on one side of the audience sat, the security people on one side of the audience sent to DevOps people. And I like, I could build a wall in the middle. Yeah, right?
True. You could. They just wouldn't come together.
A lot's happened in 10 years. They have come together. DevSecOps is real.
We all realize that we all want to have better code, more secure code. I've never met one developer who raised their hand and said, I don't care about the security of my code. They all care.
It's quality. They have pride in what they do. Security people, they're the old, and I'm a security person, I should say.
We used to say, no one cares about security, but us, excuse me, only we can care about security. But we realize now everyone cares about security from the highest levels of our companies on down. So we made a lot of progress, but we've also made some mistakes.
I think one of those mistakes was like we do with everything else. We, we took our security tools designed by security people and said, here, developer, good Luck. Good Luck.
Enjoy. Yeah. Well, that, that didn't work out so well.
Did it. Right? No, and and the reason is is they're not security people.
So a lot of DevSecOps companies died on the side of the road with that. Right. And it's interesting because we got two different companies here, check Marks.
You are an absec company from the day you were, I remember when Check Marks was founded. Yep. Mm-hmm.
Jfr, you weren't No, you were a developer company and, and a Artifactory. Right? Right.
But you've come, you know, parallel evolution to the same point of what do we need to make developers successful? Yeah. And so I, I'll ask all of you Yeah.
What, what is this magic formula? What's the secret sauce to enabling developers to develop more secure code? And please don't tell me it's ai.
No, it's not. Okay. It's ai.
Who wants, who wants not today. Anyway, yeah. Who wants to go first?
Tyler, we're gonna make you go first. Absolutely. So we, like you said, developers take pride in their work.
Uh, they want to deliver code on time, uh, with security in mind, but they need to be empowered to, uh, understand the risk that's involved. And they need to be guided and helped with, uh, how they address those, the risks that's created. So we found understanding that developer experience, uh, working in their existing workflows within their existing tool set, um, is extremely important.
So we're not disrupting their flow. We're giving them the right information at the right time. So they're the catalyst to change, uh, and, and improve their DevSecOps footprint at the company.
So we know they're a key part of DevSecOps and the ones that are gonna be driving the majority of the fixes. So really meeting them where they work's a common theme. We've seen, um, more codes being generated by AI and productivity's going through the roof right now.
We're seeing, but that also adds layers of complexity, uh, uncertainty. Um, so we need to really understand, again, how they're writing modern code with modern applications, what risk that presents them, and then let's empower them to, uh, address that risk with the right kind of information and guide us. So that's kind of where we've seen that collaboration come together.
And, uh, yeah, both parties need to work together to make a, you know, advancements within software delivery. So it's, it's, they're needed more on. I think that, uh, we learn from mistakes.
That's, uh, that's something that both humans and We learn more from mistakes than we do from success sometimes. And absolutely. And I think that both side understand that we depends on the other.
We cannot do that independently. Security cannot do anything without the right partners to drive it. We can bring the product, but it's a banner of, uh, uh, democratization.
Developers need to have the platforms and choose the right tools that will accelerate their day to day and not like find them, like we're, we're talking about like the shift left. So it need to be like in their IDE, something very natural, very native, not go to a different interface, try to find a CVE, try the vulnerability, try to fix it, go back to the code, go back to the malicious package, go back. It need to be very na natively, not extra work and mean to be very effective.
'cause, uh, by the end of the day, they want to like focus on releasing a product, a perfect product and innovative feature. And that's it. They don't care about security.
Yeah. But on the other hand, they do need to like implement that. They need to release secure software, right?
Because it's there, it's your code. You, you own it, you own it. So both side need to come together.
So that's, I think that that's the point. I, I agree. They, they do need to come together and they have let, let's, I don't want to give a false narrative, right?
We've made a tremendous amount of progress. If you were out there yesterday, you couldn't tell who was who, where they were sitting. They're all mixed in.
So we've made progress there. I wonder, it's funny. So you come from the security side, you come from the developer side.
When you are talking to security folks, did they say, but you're not a security company, right? And vice versa. Well, you are not a developer tools company.
You're a security company. How do you get credibility across the aisle, Aaron, around any thoughts? Of course.
Uh, so I think, uh, and you mentioned like 10, 10 years ago and now, okay. I think that today you're no longer working in silos. Okay?
So it's not your developer, you security, they all have the same objectives of releasing high quality software highly secured. And what is changing is the scale. Okay?
More pipelines, more development teams, higher, higher sized developer teams. Uh, and these guys need to trust what they're using. Okay?
So the world trust here, I think is a key word because these guys, whether it's they were the head of a security or developer or quality engineer or platform engineering leader, they need to have the trust in their tools that will get them towards their objectives. And their objective are the same. Zero fibers in production, higher security.
Because we know that these guys are dealing with, I dunno, 60, 70, 80, sometimes 90% of open source code. Most of the code that they're using is not even theirs. Okay?
So if they, maybe they don't trust the code that they're using coming from others, they should trust the tools that we are giving them with check marks, with j Fog that will get them towards, you know, uh, the finish line successfully. And another keyword is trust and continuously, right. Okay.
What you see today is not what you see tomorrow. Every, like, the minute, the minute I'm speaking with you here, Ellen, someone is working on a new malicious package. Right?
Right. So, uh, it's a moment in time if you like Maran. Any thoughts on that?
Yeah, I think that, uh, totally agree with you. It's about the speed is just, uh, something that we cannot control anymore. It's just, it's, it's there.
It's running super fast and you need to have like, automation as part of it. So that's the part of the lifecycle need to go grow and fast. Therefore, it's like different motivations.
I want the security, I want the product to be super secure, and r and d want it to be fast, and we need to collaborate to make it, to make it happen. So it's different motivation, but single target to get this done. Uh, and it's okay to have like different motivation in order to, to make it happen.
Definitely. Yeah. I wanna talk about another DevSecOps principle that I think has undergone a big change.
Yeah. com 20 14, 20 13, actually shift left. Everything was shift left.
Yes. Right. I gotta tell you the truth.
I'm of the opinion now. You gotta shift everywhere. Mm-hmm.
But what do you think about shift left as it was, let's say eight, 10 years ago versus today? I think it has been changed because we understand that it's not just the shift left, it's also shift right to the runtime shift up to the cloud. Yeah.
It's like, like Shift out to The earth, turn around and around. It's all over. That's shift everywhere.
Yeah, it is. And that's the security Yeah. Mission.
Now Every chain in the, the life cycle Agree. Right? So I think we've recognized these things and, and they've manifested themselves into tools, security tools that are easier for the developers to use.
Yes. Built into the IDE. Yes.
For your instance, I know check marks they made, I think you made an announcement here at RSAI got the, uh, yes. We embargo. Yes.
You're building, uh, into IDE. Correct. So we've had, uh, integration in the IDE on understanding risk, whether it's the custom code you wrote, your open source software infrastructure codes, that's all been available.
What we recently announced was, uh, our application security, posture management, right. View of those results. So now not only do you have this large, uh, list, hopefully that's reducing over time, but this large list of findings, but we're helping the developers prioritize on which actions to take on which items are most critical.
So that's, this goes back to balance. If you look at what we're asking modern developers to do today, their responsibilities have grown. So they need to be understanding way more, you know, whether it's new languages and frameworks, whether it's, uh, cloud native development and understanding how, uh, the application will be deployed.
That's, we're getting faster, but we're also adding more complexity as a result of it. Um, so what we introduced in the, uh, IDE is a giving them the, a very, uh, condensed and focused view so we're not overwhelming them and to what you were alluding to earlier, um, meeting them in the IDE. So it's, there's no context switching.
So as a developer, I'm doing my day-to-day activities trying to produce quality, quick quality code quickly. Um, and this allows me to address risk along that process. So it's not switching to different products or different views logging into different systems.
And we've seen as a result of this, that developer time to fix is drastically decreased. So now we're helping in, uh, not only prioritized, but the speed to fix is a new concern that we're addressing as well. Yeah.
Fair, fair. Now, Maran, I, I know, I know j Frog's history and story, right? You didn't just make a developer tool friendly for security people.
You j Frog's actually acquired several right. Security vendors, correct? I think you come from What we acquired Yeah.
Vision that became jfr Advanced Security, which I, I'll talk about it. And also Qua that became J Rog. Ml.
Ml. Yeah. And going back to the shift left, the, the reason that we're, I super like support that it's because it's about efficiency of the software development lifecycle.
When it's shift lab, when you identify the true issues that you need to focus on, that will really save the time, right? So be effective with that and understand the full lifecycle, but as, as, as soon as possible, if it's like malicious package or there is like malicious even model in LLM now. So think about the full dimensions that is, is operating in order to create a new application and try to push it as soon as possible.
So it'll be like time. It, it's time consuming. So if you can do that as fast as you can, it's a plus for everyone.
And developers want it, but it must be very focused and not like spam, uh, different tools on the ID plugin, but consider everything, prioritize that, make sure that it's, validate that it's applicable and save time. Yeah, Agreed. If I can just add on top of that, I think, uh, what Tyler and Morani was saying, it's exactly, you know, we, we are seeing today, uh, with the advancements of technology, uh, developers being overwhelmed with so much findings, okay?
They dunno where to start. Okay? There is too much noise in some cases, a lot of false positives, okay?
At the end of the day, they need to get the job done. Okay? They have a feature that they need to fix, they have a bug they need to fix, they need to manage their pipelines.
The more you reduce the noise on their end and walk within, of course the ID like serving them where, where they are, you are actually talking, going back to the trust, right? You are building the trust into the workflow of software development. And that, in my mind, can transform developers into security champions because we know developers are not security champions by definition.
Right? But if you feed them with the right amount of security training, security findings, prioritization, risk management, right? Uh, with this A SPM and the id, we actually also introduced what, uh, a very, uh, modern scoring, uh, algorithm.
So it's not just that you're prioritizing that based on, you know, the severity of any findings, but actually what matters most to the developers so they can actually get their own unique report that they need to take, take care of the most unique CV that they need to take care of and whatever. So, uh, they experience user friendly reduction of noise. These are the things that in my mind matter and allows developers to adopt more user security tools.
Yeah. And, uh, the tools. And that's the power of platform.
I think that is, you're talking about like platform engineering? Yes. That's the power of platform to unify and give a context.
So it'll be very clear, very like rec side. We're gonna jump into platform engineering in a moment, but I want to focus just on platform for a second. You know, I, I did an interview, I did a few interviews over the last couple days and this whole concept of platform came up.
I've been in security 30 plus years. One thing I've learned about the security business is small companies, little fish, they make what they call products, right? Then medium sized companies, they look at those products as features.
Mm-hmm. And they buy the little fish and they roll those products up as features into their products. And they think they have the product and we sell point products, but then the bigger fish, they say, no, we don't want products, we want platforms.
Yes. Yeah. And my platform has multiple products in it.
Not just my products. We plug in, we connect API, whatever, we connect to other products into this holistic platform. Yep.
And that's really where companies want to be. And not only vendors. Yeah.
But end user companies. Yeah. Consumers.
Yeah. Consumers. They don't want 27, 36 integrations point products.
Yes. They want a platform that handles this mission for them. And so I think it behooves all of us, you know, of course everybody wants to be the platform.
You're a platform, you're a plat, we're all a platform, right? That doesn't work either. Right?
But we want these tools to work together better. And that's, I think a, a, a key piece of it. I want to turn to platform engineering.
Sure. com about, uh, eight months ago now. org.
Very big. He's A great guy. Yeah.
200, 300,000 members there. Luca and I, and the check marks people do our platform engineering show every other week. Yeah.
And round tables and stuff. And we've spoken about this on that show, right? That if we could give the developers a platform that is both secure, tested, stable, scalable, and just say, developer, do what you like to do.
Exactly. Develop, focus on that. Look, just Develop, go code, go as fast as you could go.
That's what we need. Right? That's, and that's, I think at, at the Nugget, that's the appeal of platform engineering.
Yeah. I know how check marks is working with them. How does Jfr view that platform engineering?
That's the, that's Jfr story. It's about DevSecOps for real, right? Come from a company that did like DevOps and get into security world, but in a very natural way for the developers.
It's bring developers into the security and and really connect, be the glue that connect between them. And that's exactly the power of the, of the platform. Because you don't need to go to a different, you just got everything on a single place.
And that's trusted releases. Um, combine those two together. Yeah.
Alright. So I think within platform engineering and what we call an IDP, right? An internal developer, uh, platform portal, everyone is using the p in a different way, by the way.
Uh, so I think if you give these guys the developers, uh, a centralized portfolio, if you like, of the best of breed platform for security, for, uh, I know for cloud, for whatever they need to get the job done. Uh, that's also how you build trust. But also that's how you take, um, people look at the platform engineering as the next level or next evolution of DevOps.
Okay? It doesn't replace DevOps. It's kind of built on top of DevOps to optimize these pipelines to optimize the software development lifecycle.
But also, I've spoken with one of the, the analysts the other day also to put some safeguards on the tools that are being used, uh, and governed and controlled within the, the, you mentioned earlier, Alan, these different point solutions, right? Right. So with so many platforms, so many different tools, especially when you're dealing with enterprises, you need a governed approach to different tool chains within, uh, the organization.
And when you're dealing with, I know, 100 dev teams with thousands of pipelines, what you don't, you do want to give them, uh, the freedom of choice of tools and platforms, but you also want to control that. And platform engineering brings this governance into the software development life cycle. I think that they're not, you know, dedicated as the knowledge, the right knowledge to do.
You can accelerate that and give them that as a platform. They don't need to be security expert. They don't need to be, uh, even like, uh, legal expert or privacy experts, especially in ILLM.
But they do need to, to just consume it, consume it as a service. And that's the change I think that we are going to see. I think the service, that's the right, the right word here, Right?
The service and application, which is like, it's the higher level. It's not just the DevOps, it's just application that combine everything together. The security and the DevOps.
Agreed. Let me turn now to another topic. 'cause we are going low on time.
But look, we're here at RSA. You can't walk more than five feet without tripping over ai. There's AI agents, there's generative ai, there's that ai, there's ml, there's everything.
Both of your companies at Jfr and Checkmarx have news around AI and have put big bets, right? Uh, JJ ml, Right? You have AI agents.
Yes. I just spoke to Sandeep, the, uh, CEO about. Yeah.
How real, how big is ai? So is AI taking any jobs away here, or is AI making us better? If not, when will it, is it more talk at this point than real thoughts?
So, I, I I can start. So ai, uh, serves a specific use case, okay? And each, let's say agent serve a specific use case for the developers, for the security engineers, whatever persona is using that.
So a AI is not going to replace anyone's or take anyone's job. I think that what we're going to see eventually, and we, we need just put it on the table. We, AI or people that are using AI are going to replace people that are not using ai.
Okay? So if you are today in the software development lifecycle, doing anything like from QA to dev to security production monitoring observability, I'm coming also from a previous observability space. They are all looking at ai.
So if you're not going to start getting used to the fact that AI is kind of your copilot, your, uh, supporter in everything that you need to do, someone that uses AI will replace you. So AI is going to be driven by engineering, okay. By engineers, uh, as part of the software development life cycle.
Okay? But it's not going to replace jobs for people in my mind, that's just going to aid, uh, you know, bottlenecks or whatever challenges that these guys have and support them, uh, through their journey. So that's a, a short answer.
I think they will replace humans in a lot of, uh, manual work. People that are, that they're doing it today. It'll get into every position, not just like engineering.
It'll replace in every, like, uh, every job in a company. We're going to see, um, displacement, uh, for sure in the support, uh, chat bot, replace support, you know, humans. So think about what AI will do, uh, about related to documentation.
So many different aspects of service providers that will be totally improved and accelerate. But I said it yesterday, I do think that the human factor is still very strong. And this is like our responsibility to make sure that we're doing the right thing.
We're using it carefully, we're putting the right guardrails, we're putting the right F foundations. Yeah. Um, and it's in every several dimensions.
Like the infrastructure need to be like aligned. We have to put the right skeleton, the right model, um, due diligence, the models to make sure they won't be like data exfiltration and data poisoning. And then it's continue with AI agents, understand what are their guardrails, what is the identity and access management, if it's like something that we implemented, reduce the, the actions that they can do, especially for various critical service and critical commands and operation or with sensitive data limit that align with the regulation.
Make sure that we are aligned with the law. Um, if, if autonomous AI agent will share data between us and, and, and, and uk, what about GDPR? How can I confirm that this identity is doing what it need to be done from legislation perspective?
And that's a lot of things to do, or different dimension that we'll need to take care of them. So we are going to focus on control them, manage it, do it the right thing, take it slowly, but it'll run fast. That's what I think.
Fair? Yeah. Fair.
Tyler, what about you? Yeah, I'll just add, so it's gonna, the jury's still out. It's obviously, uh, AI's here to stay.
So that ship has sailed, but how it's being used, I think we're still waiting to see what's truly, uh, impactful and making a difference. There's a lot of noise around adding AI to certain product capabilities, but it goes back to what problem are we actually trying to solve and how is it really, uh, empowering, especially in our case, the developers and security teams to work better together and remove a lot of what they call like developer toil or those mundane tasks that, uh, can be easily replaced by something like an agent ai. So, uh, we're excited to see and uh, we, we've launched a, a concept that we're working with our customers to really fit into their needs and understand their workflows.
But it'll be, uh, I think pretty groundbreaking, exciting to see how that plays out. And then, uh, if, if I could boil down, you know, the DevSecOps movement and, and focusing on the people and the processes, uh, AI's really gonna focus on the processes and I think that's a good movement for understanding, uh, the model of DevSecOps. Everybody's kind of singing off the same sheet of music and there's alignment as far as how the processes work together and what everybody's role in that is.
So, uh, yeah, definitely exciting times and seeing how it plays out to. Fair enough. So one last question and we'll wrap up as we sit here today, really the first full day of RSAC in terms of keynotes and sessions, expo hall, are you bullish on DevSecOps?
Do you think the best is yet to come? Or do we, is there another direction we need to go in? What's your thought?
Uh, I think it's evolutionary. So it, it will build on what we are doing today. We're learning from what works and where we failed and where we can improve.
I think we're only getting faster with the new, uh, AI capabilities and really having us look internally on what is working and what isn't. Um, so I think, uh, it's exciting to see a lot of the consolidation around what's happening in our space. Um, and a lot of the great insights or context that we can derive from that.
Uh, so I do think anytime you can get people together to solve the same types of problems, it's a powerful thing. So I think, uh, I don't think there's a way around it and I think it's the right trend. It just will grow and, uh, evolve over time.
I'm going to give you the last first. Yeah, I don't think we are bullish, but I think we are reacting to the trends for sure. 'cause uh, just like cloud, it just started and everyone just start, you know, syn up and, and, and that, uh, same goes with ai.
So everyone are talking about MCP right now, right? Because it just started and then it's like a storm. Everyone are doing it.
So I do think that we're reacting to new trends and new technology and that, that makes sense. So reacting to that, just focus on doing the right thing and do and providing holistic solution to drive that. Yeah.
Love it. Alright, that's gonna wrap us up here. You've just watched another episode of cracking the Code, the DevSecOps Show.
We'll be back live with more RSA conference coverage in just a moment. If you're not watching this live, you catch it on Apple or Spotify or YouTube or something. I'm sorry you weren't here to see it live, but we're doing our best to bring it to you.
I'm Alan Shimel. We're out.