1
00:00:00,200 --> 00:00:03,320
All right, so at the beginning 
of April I went to New York for 

2
00:00:03,320 --> 00:00:07,400
the MCP Dev Summit, and while I 
was there I got the chance to 

3
00:00:07,400 --> 00:00:11,080
record a few podcasts with 
attendees that were at the 

4
00:00:11,080 --> 00:00:12,600
event. 
This is one of those 

5
00:00:12,600 --> 00:00:14,160
conversations. 
Hope you enjoy. 

6
00:00:14,440 --> 00:00:19,760
I think we have to look at these
agents as untrusted, maybe even 

7
00:00:19,760 --> 00:00:21,600
adversarial. 
How many people are reading this

8
00:00:21,600 --> 00:00:24,880
code or like think about, I 
think events of the last month 

9
00:00:24,880 --> 00:00:27,840
with like Anthropic in the DoD, 
Think about what we're doing. 

10
00:00:27,880 --> 00:00:32,040
We're asking citizen developers 
to deploy untrusted agents 

11
00:00:32,040 --> 00:00:34,440
behind the firewall. 
And we're frantically wiring 

12
00:00:34,440 --> 00:00:36,800
those things up to every single 
system we can find. 

13
00:00:37,480 --> 00:00:41,320
And, and every CEO is basically 
standing up and saying we must 

14
00:00:41,320 --> 00:00:42,440
do this. 
We must do it now. 

15
00:00:42,440 --> 00:00:44,800
We have to take more risk. 
We have to act like a startup. 

16
00:00:44,800 --> 00:00:48,200
I can't think of any part of our
business that isn't rapidly 

17
00:00:48,200 --> 00:00:53,480
changing where we look at it 
first and foremost as what do 

18
00:00:53,480 --> 00:00:55,440
these tools let us do? 
But they're only useful, They're

19
00:00:55,440 --> 00:00:59,440
only useful if they have the 
context of all of the, the 

20
00:00:59,440 --> 00:01:01,160
systems and the services and the
APIs. 

21
00:01:01,160 --> 00:01:03,040
And that's, that's what APIs are
at the end of the day. 

22
00:01:03,040 --> 00:01:04,959
They're the, they're the front 
door to all of that stuff. 

23
00:01:16,440 --> 00:01:19,560
Hi, I'm Alex Alkever with the 
Linux Foundation and the Agentic

24
00:01:19,600 --> 00:01:22,080
AI Foundation. 
We're here at MCP Dev Summit in 

25
00:01:22,080 --> 00:01:26,360
New York City and I'm chatting 
today with Matt Deburgolis. 

26
00:01:26,360 --> 00:01:29,040
If I said it the right way, who 
is the CEO of Apollo Graph QL? 

27
00:01:29,840 --> 00:01:32,200
And forgive me if I get anything
wrong, correct me, I have no 

28
00:01:32,200 --> 00:01:34,880
ego. 
Thank you for joining us. 

29
00:01:34,960 --> 00:01:37,880
Before we get started on this 
conversation, which is going to 

30
00:01:37,880 --> 00:01:41,760
be about API lessons for MCPI, 
believe is what we were 

31
00:01:41,760 --> 00:01:44,960
discussing and tell us a little 
bit about what a polygraph QL 

32
00:01:44,960 --> 00:01:47,400
does. 
And then how we can chat a 

33
00:01:47,400 --> 00:01:52,720
little more about how you're 
leaning into MCP, particularly 

34
00:01:52,720 --> 00:01:56,000
since you're essentially a graph
QL as a service provider and you

35
00:01:56,000 --> 00:01:58,800
know, we're generating 
everything around the API space.

36
00:01:58,800 --> 00:02:02,880
So MCP is a very interesting 
translational layer for you. 

37
00:02:03,120 --> 00:02:05,520
Yeah, sounds good. 
Thanks for thanks for doing 

38
00:02:05,520 --> 00:02:06,640
this. 
It's a great conference. 

39
00:02:07,600 --> 00:02:09,520
Thanks for coming. 
Energy is awesome. 

40
00:02:09,520 --> 00:02:12,480
It it you can't make this stuff 
up, right? 

41
00:02:12,480 --> 00:02:14,520
It it shows there. 
It's crazy, literally like 

42
00:02:14,520 --> 00:02:17,400
things are so I mean like I'm 
following all. 

43
00:02:17,400 --> 00:02:20,320
So each week I do a scrape of 
all the protocol repos and 

44
00:02:20,320 --> 00:02:23,400
you're just seeing things move 
so quickly, like, oh wait, 

45
00:02:23,400 --> 00:02:26,280
somebody signed ACLA or oh wait,
you know, they just shipped the 

46
00:02:26,280 --> 00:02:28,440
new securities back. 
It's it's, it's crazy. 

47
00:02:28,520 --> 00:02:33,880
I think what's cool about MCP is
it, it reminds me of the the 

48
00:02:33,880 --> 00:02:36,720
mash up era, right? 
It's it's, it's for builders, 

49
00:02:36,720 --> 00:02:39,640
it's for making stuff. 
And you know, we could talk 

50
00:02:39,640 --> 00:02:44,000
about agents are useful because 
they can connect to stuff. 

51
00:02:44,160 --> 00:02:47,800
So we need an answer to that. 
And MCP is a big part of it. 

52
00:02:47,800 --> 00:02:51,920
And what we've been doing it 
Apollo for the AP is of large 

53
00:02:51,920 --> 00:02:54,600
companies, especially is, is 
we're, we're basically solving 

54
00:02:54,600 --> 00:02:56,680
this problem of how do you, how 
do you take a whole bunch of 

55
00:02:56,680 --> 00:02:59,120
different systems? 
And AP is that you've got, you 

56
00:02:59,120 --> 00:03:01,800
might have thousands of them in 
a typical enterprise. 

57
00:03:01,800 --> 00:03:04,280
And how do you glue those 
together to make a great user 

58
00:03:04,280 --> 00:03:06,600
experience? 
And this got its start back when

59
00:03:06,600 --> 00:03:10,440
we're talking about building a 
mobile app or a really great 

60
00:03:10,440 --> 00:03:13,200
JavaScript app in the browser. 
But it's always been about 

61
00:03:13,200 --> 00:03:16,240
builders. 
It's always been about, I want 

62
00:03:16,240 --> 00:03:18,200
to make a cool thing. 
I want to make something my 

63
00:03:18,200 --> 00:03:22,880
customers are going to love. 
And I want to do that on top of 

64
00:03:22,880 --> 00:03:26,760
real stuff. 
And and so now we can have that 

65
00:03:26,760 --> 00:03:30,680
whole conversation again, but at
an even bigger scale because 

66
00:03:30,680 --> 00:03:35,200
we're talking about with AI 
being able to build so much more

67
00:03:35,640 --> 00:03:40,560
and not just the sort of user 
facing, you know, first class 

68
00:03:40,560 --> 00:03:43,840
mobile app, but think about all 
the things that are happening 

69
00:03:43,840 --> 00:03:46,440
inside the business now that 
we've got agents on people's 

70
00:03:46,440 --> 00:03:50,880
desks, now that we can build 
software large and small really 

71
00:03:50,880 --> 00:03:53,040
quickly. 
And the part that I'm just so 

72
00:03:53,040 --> 00:04:00,000
excited about is we know how 
much amazing stuff is out there 

73
00:04:00,080 --> 00:04:05,240
inside micro services or inside 
little pieces of SAS or inside 

74
00:04:05,240 --> 00:04:07,560
these systems that people have 
built over the years. 

75
00:04:08,000 --> 00:04:10,280
And the more of those we can 
connect together, the more of 

76
00:04:10,280 --> 00:04:11,840
those we can connect to an 
agent. 

77
00:04:11,960 --> 00:04:13,200
I think it's going to change so 
much. 

78
00:04:13,200 --> 00:04:14,760
It's going to make businesses 
faster. 

79
00:04:14,760 --> 00:04:17,200
It's going to be better customer
experiences. 

80
00:04:18,120 --> 00:04:21,399
It's real exciting. 
And so from your viewpoint too, 

81
00:04:21,399 --> 00:04:24,240
because you've spent a lot of 
time in the API world and now 

82
00:04:24,240 --> 00:04:29,440
you're essentially living in 2 
worlds, what is the transition 

83
00:04:29,440 --> 00:04:30,680
or? 
I wouldn't say transition 

84
00:04:30,680 --> 00:04:32,040
because that implies one goes 
away. 

85
00:04:32,040 --> 00:04:35,320
Ape guys don't go at all. 
No, they certainly don't. 

86
00:04:35,320 --> 00:04:36,840
No. 
And like even with like graph 

87
00:04:36,840 --> 00:04:39,480
QL, it was still like kind of 
ascending, you know. 

88
00:04:39,880 --> 00:04:42,600
And rest is still, there's a lot
more people use rest than graph,

89
00:04:42,600 --> 00:04:46,080
even though graph is arguably 
much better for AI. 

90
00:04:46,800 --> 00:04:50,680
So if you could maybe take a 
stab at like, what is this 

91
00:04:50,800 --> 00:04:55,040
translational layer look like if
it works really well for what 

92
00:04:55,040 --> 00:04:57,720
we're trying to to to build that
world you're describing? 

93
00:04:57,800 --> 00:05:00,240
Yeah, I think all these things 
are complimentary. 

94
00:05:01,200 --> 00:05:05,200
With Graphical, for example, 
it's not about getting rid of 

95
00:05:05,200 --> 00:05:08,320
REST AP is or whatever you had 
before and replacing it with 

96
00:05:08,320 --> 00:05:09,880
Graph QL. 
That's not what Graph QL is. 

97
00:05:09,880 --> 00:05:13,000
Graphical is a query language, 
so it's, it's something that you

98
00:05:13,000 --> 00:05:16,280
can layer on top of your REST AP
is and it makes them better. 

99
00:05:16,560 --> 00:05:21,240
Like graph QL introduced the 
idea of strong typing in AP is 

100
00:05:21,560 --> 00:05:23,200
it's got this idea of 
introspection. 

101
00:05:23,200 --> 00:05:28,440
So you can ask the graph, what, 
what do you have for me? 

102
00:05:28,440 --> 00:05:30,040
What are the types? 
What are the fields? 

103
00:05:30,840 --> 00:05:32,840
How do they relate? 
How are they used? 

104
00:05:32,840 --> 00:05:34,920
There's all this metadata that 
comes along with that. 

105
00:05:35,720 --> 00:05:38,880
And I think MCP very similarly, 
right? 

106
00:05:38,880 --> 00:05:42,800
Nobody's saying you're going to 
throw away your underlying AP is

107
00:05:43,440 --> 00:05:45,040
we're talking about a new way to
use them. 

108
00:05:45,040 --> 00:05:49,320
We're talking about adapting 
them for the needs of an agent. 

109
00:05:49,800 --> 00:05:54,320
But I think really the, the 
magic thing about MCP is the 

110
00:05:54,320 --> 00:05:57,080
flexibility in the free form 
part of it. 

111
00:05:58,640 --> 00:06:01,480
You know, we're, we used to 
think about AP is as these rigid

112
00:06:02,120 --> 00:06:05,200
things that got designed very 
carefully a long time ago and 

113
00:06:05,200 --> 00:06:08,320
they never change, right? 
Like, but that's not the world 

114
00:06:08,320 --> 00:06:10,520
we're in anymore. 
Systems can change every day, 

115
00:06:10,520 --> 00:06:15,120
and MCP gives us a way to to 
talk about that and to expose 

116
00:06:15,360 --> 00:06:18,560
those ideas to a system. 
Dive a little deeper on that, if

117
00:06:18,560 --> 00:06:21,080
you can tell, I mean, if you 
will, on what is 

118
00:06:21,480 --> 00:06:23,880
architecturally, what does that 
start to look like if you're 

119
00:06:23,880 --> 00:06:27,120
trying to build out something 
that takes advantage of the 

120
00:06:27,120 --> 00:06:31,040
goodness of graph QL and melds 
it to the goodness of MCP? 

121
00:06:31,160 --> 00:06:34,040
Yeah. 
So a company has been using 

122
00:06:34,040 --> 00:06:37,240
graph QL has, you know, we call 
it a super graph at Apollo. 

123
00:06:37,240 --> 00:06:44,200
They've, they've got this 
semantic catalog of not just the

124
00:06:45,600 --> 00:06:50,560
low level details of what's in 
the AP is, but the higher level 

125
00:06:51,000 --> 00:06:56,320
meaning of that stuff. 
And that's magical for AI 

126
00:06:56,480 --> 00:06:59,520
because the agent needs that 
information to make good 

127
00:06:59,520 --> 00:07:01,520
decisions. 
If if I sit down one day and I 

128
00:07:01,520 --> 00:07:04,760
say, hey, now I've got clawed 
code so I can, I can build a 

129
00:07:04,760 --> 00:07:08,360
business dashboard with that 
dashboards using the wrong 

130
00:07:08,360 --> 00:07:10,840
stuff. 
If it misinterprets the meaning 

131
00:07:10,840 --> 00:07:13,600
of what's in your AP is that's 
really bad. 

132
00:07:13,600 --> 00:07:15,680
That's, that's worse than not 
building it at all, right? 

133
00:07:15,680 --> 00:07:21,880
So what we're excited about is 
MCP gives us a way to connect 

134
00:07:21,880 --> 00:07:25,160
that graph and connect all those
business objects that that 

135
00:07:25,160 --> 00:07:31,720
people have now defined to this 
new world of interactive LLM 

136
00:07:31,720 --> 00:07:35,680
harnesses to a world of software
that's built by LO Ms. like 

137
00:07:35,680 --> 00:07:37,520
Cloud code or, or Codex or 
whatnot. 

138
00:07:39,280 --> 00:07:42,440
And think about what this means.
Like now we can sit down and we 

139
00:07:42,440 --> 00:07:43,920
can ask questions about our 
business. 

140
00:07:43,920 --> 00:07:48,920
We can say, hey, I've got, I've 
got a bunch of amazing data 

141
00:07:48,920 --> 00:07:52,480
inside this piece of SAS, the 
screen and the SAS product 

142
00:07:52,480 --> 00:07:54,840
doesn't do what I need, but I, I
don't need that anymore. 

143
00:07:54,840 --> 00:07:56,240
I can just. 
Right, the users. 

144
00:07:56,240 --> 00:07:58,080
Don't talk and the. 
Users don't want that anymore 

145
00:07:58,160 --> 00:07:59,160
either. 
They're changing, yeah. 

146
00:07:59,560 --> 00:08:02,920
Or, you know, a big problem the 
enterprise has is, is 

147
00:08:02,920 --> 00:08:04,760
essentially you've got a silo 
problem. 

148
00:08:05,440 --> 00:08:08,800
Big companies spent the last 20 
years building a whole bunch of 

149
00:08:08,800 --> 00:08:11,640
silos. 
That's what a micro service is, 

150
00:08:11,640 --> 00:08:13,040
right? 
It's it's, it goes back to the 

151
00:08:13,040 --> 00:08:14,880
Jeff Bezos memo like you're, 
you're. 

152
00:08:14,880 --> 00:08:17,480
Going to do an API for 
everything. 1 little silo and 

153
00:08:17,480 --> 00:08:18,800
you can only talk to it this 
way. 

154
00:08:19,280 --> 00:08:21,080
And that made a lot of sense 
architecturally. 

155
00:08:21,080 --> 00:08:24,400
But now we face this problem, 
which is I've got all this stuff

156
00:08:25,320 --> 00:08:30,080
and it's it's separated. 
And what what makes it valuable 

157
00:08:30,080 --> 00:08:31,840
is when I can bring it back 
together. 

158
00:08:33,360 --> 00:08:35,640
Most of the questions I want to 
ask about my business aren't 

159
00:08:35,640 --> 00:08:36,919
going to be answered out of one 
thing. 

160
00:08:36,919 --> 00:08:38,559
They're going to be answered out
of a whole bunch of them. 

161
00:08:39,360 --> 00:08:40,520
And it's the draft, and it's 
the. 

162
00:08:40,520 --> 00:08:43,200
Relationship between? 
Yeah, exactly. 

163
00:08:44,039 --> 00:08:46,640
And, and so give me a couple 
examples of how you're seeing 

164
00:08:46,640 --> 00:08:50,520
people do this in the real world
in interesting ways or 

165
00:08:50,520 --> 00:08:53,040
surprising ways. 
Or because like to your point, 

166
00:08:54,360 --> 00:08:58,160
having a, a query language that 
can supply context when you 

167
00:08:58,160 --> 00:09:00,640
start to think of things like, 
you know, additional tuning on 

168
00:09:00,640 --> 00:09:04,400
top of open source models, it, 
it can probably be semi magical 

169
00:09:04,400 --> 00:09:08,640
or just have astounding impact. 
So versus like just working off 

170
00:09:08,640 --> 00:09:11,160
of straight, you know, API 
calls. 

171
00:09:11,560 --> 00:09:17,200
Yeah, I think a big part of it 
is, is this idea that we can 

172
00:09:17,680 --> 00:09:20,760
look forward to a world where 
there are lots more builders and

173
00:09:20,760 --> 00:09:23,280
they don't all have a formal 
background in software 

174
00:09:23,280 --> 00:09:26,120
engineering. 
Like if you sit down with Claude

175
00:09:26,120 --> 00:09:30,600
code and you ask it to build on 
top of a bunch of rest AP is 

176
00:09:31,160 --> 00:09:34,400
it'll, it'll get there, it'll 
muddle its way through. 

177
00:09:34,400 --> 00:09:38,040
But I think what a lot of us 
have found is it needs some 

178
00:09:38,040 --> 00:09:40,640
guidance. 
And that guidance means the 

179
00:09:40,640 --> 00:09:45,200
person doing the work should 
have some understanding of how 

180
00:09:45,200 --> 00:09:47,680
these AP is work. 
Like what's a rest AP? 

181
00:09:47,680 --> 00:09:49,160
Oh, it's doing this thing. 
OK, I need to steer it in this 

182
00:09:49,160 --> 00:09:52,200
other direction. 
And so that really blocks the 

183
00:09:52,240 --> 00:09:55,920
the thing I want, which is I, I 
want, you know, somebody in 

184
00:09:55,920 --> 00:10:01,440
sales to be able to use Claude 
to ask sales questions, Right, 

185
00:10:01,520 --> 00:10:02,880
Right. 
Essentially like few shots, 

186
00:10:02,880 --> 00:10:07,120
single shot, no shot. 
And what we get when we've got 

187
00:10:07,120 --> 00:10:12,760
this semantics, when we've got a
clearer explanation, when we've 

188
00:10:12,760 --> 00:10:16,640
got MCP and Graph QL working 
together so that Claude's not 

189
00:10:16,640 --> 00:10:22,120
caught up in the nuance of like,
oh, I went to the SAS, I found 

190
00:10:22,120 --> 00:10:24,800
it's open API spec, but guess 
what, that's not actually 

191
00:10:24,800 --> 00:10:29,720
accurate. 
So I had to iterate 345 times 

192
00:10:29,720 --> 00:10:32,240
and it it tries to use one API, 
but it turns out that thing 

193
00:10:32,240 --> 00:10:35,280
returns the wrong pagination key
because this is just a use of 

194
00:10:35,280 --> 00:10:38,040
the API that the the product 
never really. 

195
00:10:38,040 --> 00:10:40,240
Or it's old they didn't Rev it 
or something. 

196
00:10:40,240 --> 00:10:42,880
Like that exactly. 
If we can cut. 

197
00:10:42,880 --> 00:10:47,160
Through that and it's, it's just
the crank turning roll up the 

198
00:10:47,160 --> 00:10:49,760
sleeve stuff, right. 
But if we can cut through that 

199
00:10:50,200 --> 00:10:57,440
and give the AIA more semantic 
structured entry point to all of

200
00:10:57,440 --> 00:11:00,520
those systems, then it gets 
magical. 

201
00:11:00,720 --> 00:11:03,120
Because then, then you can 
actually sit down and say, hey, 

202
00:11:04,640 --> 00:11:07,440
go over all the conversations 
that we've had, the transcripts 

203
00:11:07,440 --> 00:11:10,080
of all the conversations that 
I've got in a, in a, in a, you 

204
00:11:10,080 --> 00:11:15,400
know, SAS database and search 
for mentions of this particular 

205
00:11:15,400 --> 00:11:18,040
thing. 
Then go off and read the annual 

206
00:11:18,040 --> 00:11:21,520
reports from that company and go
figure out how that matches up 

207
00:11:21,520 --> 00:11:24,040
to like what the CE OS talking 
about in terms of their 

208
00:11:24,040 --> 00:11:27,680
priorities. 
And then I want you to go hunt 

209
00:11:27,680 --> 00:11:33,080
down, you know, maybe the 
competitors of, of that company 

210
00:11:33,080 --> 00:11:34,400
and, and what they're talking 
about. 

211
00:11:34,400 --> 00:11:40,600
And suddenly a salesperson is in
5 minutes with no special 

212
00:11:40,600 --> 00:11:45,400
technical skill, making use of 
data that we've always had, but 

213
00:11:45,400 --> 00:11:49,920
never had a way to really take 
advantage of the same way. 

214
00:11:50,520 --> 00:11:52,320
And they can do it right before 
their sales call. 

215
00:11:52,320 --> 00:11:56,760
So there's not some complicated,
you know, process where I've, 

216
00:11:56,800 --> 00:11:58,680
I've got to anticipate that I'm 
going to have this call, maybe 

217
00:11:58,680 --> 00:12:00,440
the call just got scheduled. 
They almost set it up with an 

218
00:12:00,440 --> 00:12:02,360
automated process. 
They said create a skill. 

219
00:12:02,360 --> 00:12:04,360
They run it before every ticks 
their calendar. 

220
00:12:04,400 --> 00:12:06,120
Yeah. 
And I can give you 20 examples 

221
00:12:06,120 --> 00:12:09,880
like this, like where certainly 
every part of our business is 

222
00:12:09,880 --> 00:12:12,200
changing. 
Yeah, like the way we think 

223
00:12:12,200 --> 00:12:15,160
about interviewing, how do we 
coach people on how they're 

224
00:12:15,160 --> 00:12:17,080
doing their interviews? 
How can we make those better? 

225
00:12:17,080 --> 00:12:20,880
There's a feedback cycle that we
can start doing in real time 

226
00:12:20,880 --> 00:12:23,160
that might have happened once a 
quarter before, right? 

227
00:12:23,360 --> 00:12:28,320
Or how do we do market research?
Or I mean, obviously there's a 

228
00:12:28,320 --> 00:12:30,840
whole world of how we build 
software in a different way and,

229
00:12:30,840 --> 00:12:33,520
and how we think about Rd. maps 
and, and all the things that 

230
00:12:33,520 --> 00:12:36,280
come with that. 
I can't think of any part of our

231
00:12:36,280 --> 00:12:41,080
business that isn't rapidly 
changing where we look at it 

232
00:12:41,080 --> 00:12:44,080
first and foremost as what are 
these tools? 

233
00:12:44,080 --> 00:12:45,480
Let us do? 
But they're only useful. 

234
00:12:45,480 --> 00:12:49,640
They're only useful if they have
the context of all of the, the 

235
00:12:49,640 --> 00:12:52,240
systems and the services and the
AP is, and that's, that's what 

236
00:12:52,240 --> 00:12:54,280
AP is are at the end of the day,
they're the, they're the front 

237
00:12:54,280 --> 00:12:57,800
door to all of that stuff. 
So in your view then, do we need

238
00:12:57,800 --> 00:13:03,320
to modify the way the AP is work
at all if we want to lean into 

239
00:13:03,320 --> 00:13:05,600
MCP? 
Yeah, and agentic better. 

240
00:13:05,880 --> 00:13:09,040
The big problem is the AP is 
were never designed for any of 

241
00:13:09,040 --> 00:13:11,880
what I just talked to no. 
So I I gave you the the 

242
00:13:11,880 --> 00:13:13,760
exciting. 
Version here's the AP is the 

243
00:13:13,760 --> 00:13:15,560
rest was not designed. 
For like here's the cold hard 

244
00:13:15,560 --> 00:13:18,760
reality. 
I mean the the the biggest most 

245
00:13:18,760 --> 00:13:22,320
immediate problem is a security 
problem in my view. 

246
00:13:22,720 --> 00:13:26,640
Like these AP is were built for 
trusted users. 

247
00:13:27,800 --> 00:13:30,160
And what I mean by that is like 
they were meant to be used by 

248
00:13:30,160 --> 00:13:33,840
engineers who know how to do 
engineering, who have some, you 

249
00:13:33,840 --> 00:13:36,280
know, they, they review each 
other's code. 

250
00:13:36,280 --> 00:13:40,000
There's a whole bunch of rituals
and processes that we've built 

251
00:13:40,000 --> 00:13:43,000
over the last couple decades. 
The rate limited key, etcetera, 

252
00:13:43,000 --> 00:13:44,560
etcetera. 
All that stuff and, and, and, 

253
00:13:44,560 --> 00:13:47,240
and underneath all that is human
judgement, good human judgement 

254
00:13:47,240 --> 00:13:50,880
of people I trust, right. 
So if you wipe all that away, 

255
00:13:50,880 --> 00:13:54,240
you've got a big problem. 
Because if you think about a 

256
00:13:54,240 --> 00:14:00,120
typical API, for example, it's 
probably going to mix data that 

257
00:14:00,120 --> 00:14:02,080
has very different levels of 
sensitivity. 

258
00:14:03,080 --> 00:14:07,840
Like I've got a, I've got an HR 
system in our company. 

259
00:14:08,680 --> 00:14:13,840
That HR system has a list of 
everybody and their time zone. 

260
00:14:13,840 --> 00:14:15,000
That's really useful. 
I think. 

261
00:14:15,040 --> 00:14:17,160
I think that should be at 
everybody's fingertips, right? 

262
00:14:17,240 --> 00:14:19,440
Sure. 
Who the manager is, it's also 

263
00:14:19,440 --> 00:14:22,320
got probably, I'm guessing, I'm 
not totally sure, but I think it

264
00:14:22,320 --> 00:14:24,600
has like their four O 1K 
contribution information. 

265
00:14:24,720 --> 00:14:25,720
Or their health. 
Information. 

266
00:14:25,720 --> 00:14:28,040
Probably not something right 
that people should. 

267
00:14:28,400 --> 00:14:32,440
Have exactly. 
And you know, I think just 

268
00:14:32,440 --> 00:14:35,400
across the board, whether we're 
talking about third party SAS 

269
00:14:35,400 --> 00:14:40,000
that you bought, we're talking 
about first party services that 

270
00:14:40,000 --> 00:14:42,560
you built. 
The AP is, are too coarse 

271
00:14:42,560 --> 00:14:45,600
grained. 
They commingle stuff that has a 

272
00:14:45,600 --> 00:14:50,240
very different level of, you 
know, sensitivity or importance.

273
00:14:51,760 --> 00:14:54,960
That was OK in a world where I 
had control of the other side 

274
00:14:54,960 --> 00:14:56,520
and and knew what that code was 
doing. 

275
00:14:56,520 --> 00:15:02,360
But I think we have to look at 
these agents as untrusted, maybe

276
00:15:02,360 --> 00:15:04,280
even adversarial. 
But how many people are reading 

277
00:15:04,280 --> 00:15:07,680
this code or like think about, I
think events of the last month 

278
00:15:07,680 --> 00:15:11,920
with like Anthropic and the DoD 
really tell us how little we 

279
00:15:11,920 --> 00:15:15,400
really know about what's 
happening inside some of the 

280
00:15:15,400 --> 00:15:20,000
models in the harnesses. 
And if you think about the risk 

281
00:15:20,000 --> 00:15:26,080
of data leaks and exfiltration, 
if you think about this as like 

282
00:15:26,640 --> 00:15:32,680
a savvy adversary, a competitor,
maybe an estate actor, this is 

283
00:15:32,680 --> 00:15:36,520
the biggest opportunity to crack
through. 

284
00:15:36,520 --> 00:15:37,880
I mean, think about what we're 
doing. 

285
00:15:37,960 --> 00:15:42,120
We're asking citizen developers 
to deploy untrusted agents 

286
00:15:42,120 --> 00:15:44,520
behind the firewall. 
And we're frantically wiring 

287
00:15:44,520 --> 00:15:46,880
those things up to every single 
system we can find. 

288
00:15:47,560 --> 00:15:51,400
And, and every CEO is basically 
standing up and saying we must 

289
00:15:51,400 --> 00:15:53,600
do this, we must do it now. 
We have to take more risk. 

290
00:15:53,600 --> 00:15:56,440
We have to act like a startup, 
you know, like. 

291
00:15:56,880 --> 00:15:59,680
Please compromise our AP. 
Is it's, it's a rock and a hard 

292
00:15:59,680 --> 00:16:03,280
place because I think the 
businesses that do this are 

293
00:16:03,280 --> 00:16:05,760
going to go so much faster and 
they're going to have such a 

294
00:16:05,760 --> 00:16:09,520
competitive advantage. 
But like, at what cost if you 

295
00:16:09,520 --> 00:16:11,200
get it wrong? 
Yeah, no, totally. 

296
00:16:11,200 --> 00:16:15,320
I mean, like we were, we were. 
I was in Amsterdam last week and

297
00:16:15,560 --> 00:16:19,400
chatted with, you know, some of 
the folks on the kernel, the 

298
00:16:19,400 --> 00:16:23,280
Linux kernel and they're seeing 
now essentially, you know, 0 

299
00:16:23,280 --> 00:16:29,000
days come in that are out of not
modified frontier models like 

300
00:16:29,000 --> 00:16:32,360
consumer frontier models, you 
know, with very simple prompts 

301
00:16:33,080 --> 00:16:35,560
to call them out so totally and 
like what you're saying. 

302
00:16:35,560 --> 00:16:38,040
And if you really want to be 
targeted, it's even worse. 

303
00:16:38,720 --> 00:16:42,840
So what how do you think about 
solving this? 

304
00:16:42,840 --> 00:16:47,400
Or orders like graph QL start 
because it is so faceted and can

305
00:16:47,400 --> 00:16:49,680
supply exactly so. 
I'll give you an example. 

306
00:16:49,680 --> 00:16:54,360
I, I think, I think there's no 
question that at a high level, 

307
00:16:54,440 --> 00:16:55,960
AI is going to change every part
of the stack. 

308
00:16:55,960 --> 00:16:57,520
It's going to change how we 
build software. 

309
00:16:57,520 --> 00:17:01,160
So one example of that is I 
think we have to move to call it

310
00:17:01,160 --> 00:17:05,640
a zero trust model where a a 
piece of software, an agent has 

311
00:17:05,640 --> 00:17:09,760
access to the thinnest slice of 
what it what it should. 

312
00:17:10,520 --> 00:17:14,720
And graph QL is a great 
architectural starting point for

313
00:17:14,720 --> 00:17:21,400
that because it has field by 
field semantics. 

314
00:17:22,040 --> 00:17:25,560
So a graph QL schema says here 
are the objects in your 

315
00:17:25,560 --> 00:17:27,119
business. 
Each of those objects has a set 

316
00:17:27,119 --> 00:17:29,320
of properties. 
We call them fields, right? 

317
00:17:29,720 --> 00:17:32,760
We can assign rights to those 
fields. 

318
00:17:32,760 --> 00:17:35,960
So we can say a given agent 
which has, you know, 1 

319
00:17:35,960 --> 00:17:39,440
credential, you get this field, 
this field, this field in this 

320
00:17:39,440 --> 00:17:45,920
field and that agent is going to
make that request explicit. 

321
00:17:46,720 --> 00:17:50,680
When I call a REST endpoint, I 
just say here's, here's the 

322
00:17:50,680 --> 00:17:53,680
arguments, give me back the 
result and the the API decides 

323
00:17:53,680 --> 00:17:56,600
what I'm going to get back. 
That model doesn't work for an 

324
00:17:56,600 --> 00:17:59,480
agent because the API, the micro
service, doesn't know what the 

325
00:17:59,480 --> 00:18:01,280
agents trying to do. 
It doesn't know what it is and 

326
00:18:01,280 --> 00:18:03,680
it doesn't. 
It doesn't sound in a position 

327
00:18:03,680 --> 00:18:05,640
to enforce. 
Policy agents composing if the 

328
00:18:05,640 --> 00:18:07,920
agents composing the other four 
or five things or yeah. 

329
00:18:08,440 --> 00:18:09,840
And, and this stuff goes pretty 
deep. 

330
00:18:09,840 --> 00:18:12,640
You know, we work with financial
companies that I think one 

331
00:18:12,640 --> 00:18:19,080
example is support agents only 
have access to a customer's 

332
00:18:19,960 --> 00:18:22,680
billing records if there's an 
open support ticket. 

333
00:18:23,800 --> 00:18:25,680
So those are two totally 
separate systems that if you 

334
00:18:25,680 --> 00:18:27,800
haven't joined together, but 
like that's a law, that's, 

335
00:18:27,960 --> 00:18:30,640
that's not some desired policy. 
That's actually a legal 

336
00:18:30,640 --> 00:18:34,640
requirements placed on a lot of 
financial companies as part of a

337
00:18:34,640 --> 00:18:38,560
consumer protection stance. 
So the client has to be able to 

338
00:18:38,560 --> 00:18:44,240
specify what it's trying to do. 
And I think Graph QL gives us a 

339
00:18:44,240 --> 00:18:45,960
template for how to go about 
doing that, right? 

340
00:18:45,960 --> 00:18:48,640
Because in Graph QL, you write a
query and the query is explicit,

341
00:18:48,880 --> 00:18:52,360
says I want, I want XYZ and W 
out of the graph and I want them

342
00:18:52,360 --> 00:18:54,600
in this order. 
And now we're in a position to 

343
00:18:54,600 --> 00:18:58,080
say, Yep, that's fine. 
Or like, if you want that piece 

344
00:18:58,080 --> 00:19:01,600
of personal information, we're 
going to block that request 

345
00:19:02,080 --> 00:19:05,600
until we do an approval process 
that goes through, you know, 

346
00:19:05,600 --> 00:19:08,680
somebody who owns the relevant 
system and can dole out that 

347
00:19:08,680 --> 00:19:11,560
access. 
So essentially almost as a 

348
00:19:11,960 --> 00:19:14,360
either as a Shim or if they're 
just using that as sort of a 

349
00:19:14,360 --> 00:19:19,720
native in a primitive construct 
of their API, it allows them to 

350
00:19:20,160 --> 00:19:24,360
assign much more a granularity 
to access attributes, anything 

351
00:19:24,360 --> 00:19:26,840
that they want to share. 
So a question on top of that, 

352
00:19:26,840 --> 00:19:29,680
because this is actually an 
interesting real world problem 

353
00:19:29,680 --> 00:19:32,880
that I saw, I think IBM wrote 
about it or somebody, but there 

354
00:19:32,880 --> 00:19:36,200
was an instance where you 
essentially had two bots last 

355
00:19:36,200 --> 00:19:40,040
agents inside of a company. 
You know, 1 was tasked with 

356
00:19:40,040 --> 00:19:43,760
customer, you know, customer 
maximizing customer 

357
00:19:43,760 --> 00:19:45,960
satisfaction. 
The other was you may have heard

358
00:19:45,960 --> 00:19:49,600
the story was tasked with, you 
know, whether to give people 

359
00:19:49,600 --> 00:19:52,120
refunds or not. 
And and like the reward 

360
00:19:52,120 --> 00:19:54,600
structure was, you know, 
customer satisfaction was the 

361
00:19:54,600 --> 00:19:56,840
biggest reward. 
So it actually started handing 

362
00:19:56,840 --> 00:19:58,960
out refunds Willy nilly 
automatically. 

363
00:19:59,560 --> 00:20:02,560
So like this is agent to agent. 
So when we start to have these. 

364
00:20:02,760 --> 00:20:05,560
Kinds of dynamics? 
How do? 

365
00:20:05,600 --> 00:20:10,840
How do you think about writing 
or at the API level starting to 

366
00:20:11,200 --> 00:20:13,280
put better strictures or 
controls around this? 

367
00:20:13,640 --> 00:20:16,400
I think the rabbit hole goes 
pretty deep here, right? 

368
00:20:16,400 --> 00:20:19,160
Like you can start at the 
surface level, which is should 

369
00:20:19,160 --> 00:20:21,640
an agent be able to give a 
refund autonomously? 

370
00:20:22,160 --> 00:20:24,920
Maybe not today, right? 
Maybe tomorrow, maybe maybe 

371
00:20:24,920 --> 00:20:27,080
below 50 bucks, right? 
Like, right. 

372
00:20:27,280 --> 00:20:30,760
But you're getting at this much 
deeper, much more interesting 

373
00:20:30,880 --> 00:20:32,800
question, I think, which is 
like, what's it really going to 

374
00:20:32,800 --> 00:20:37,080
look like to have an autonomous 
agent that's doing the work that

375
00:20:37,840 --> 00:20:39,520
a group of people would have 
done in the past? 

376
00:20:40,120 --> 00:20:43,680
And how do we, you know, not 
just think about it in terms of 

377
00:20:43,680 --> 00:20:46,480
the sort of the basics of 
security, but like maybe a 

378
00:20:46,480 --> 00:20:49,160
quality metric that comes with 
that? 

379
00:20:50,040 --> 00:20:52,960
Are we making a good business 
decision and how do we measure 

380
00:20:52,960 --> 00:20:55,440
that and how do we know? 
I think the interesting thing 

381
00:20:55,440 --> 00:20:59,360
is, have we really had a good 
way to do that in the in the pre

382
00:20:59,360 --> 00:21:01,120
AI world? 
Oh, no, absolutely. 

383
00:21:01,120 --> 00:21:02,240
This is a new question. 
A new. 

384
00:21:02,360 --> 00:21:03,280
Concept. 
Yeah. 

385
00:21:04,360 --> 00:21:07,280
So I think there's going to be a
lot of innovation here. 

386
00:21:07,440 --> 00:21:12,720
And I mean, it's interesting, 
like maybe a faster turn around 

387
00:21:12,720 --> 00:21:17,200
time on that decision is worth 
it if you're offering maybe more

388
00:21:17,200 --> 00:21:18,680
refunds than you really needed 
to. 

389
00:21:19,280 --> 00:21:21,400
Maybe it's not. 
Maybe that trade off changes 

390
00:21:21,400 --> 00:21:25,760
over time. 
And I think we're going to find 

391
00:21:25,760 --> 00:21:31,840
a lot of energy around exploring
the space of business decision 

392
00:21:31,840 --> 00:21:34,840
making with more and more 
autonomy, because I, I think at 

393
00:21:34,840 --> 00:21:37,040
the end of the day, it's the 
clock speed of the business that

394
00:21:37,040 --> 00:21:41,680
really determines that company's
prospects. 

395
00:21:41,680 --> 00:21:43,800
I mean, it's a, it's a very 
rapidly changing world. 

396
00:21:43,800 --> 00:21:48,760
And if you know, fast beats 
right, I think in a lot of in a 

397
00:21:48,760 --> 00:21:51,640
lot of moments today and that's 
an example of it. 

398
00:21:51,880 --> 00:21:54,000
Yeah, I completely agree. 
Because I think that that's like

399
00:21:54,000 --> 00:21:57,640
an instance where user 
expectations either in the 

400
00:21:57,640 --> 00:22:00,520
enterprise Oregon consumer, they
want everything faster all the 

401
00:22:00,520 --> 00:22:03,400
time, you know, and they're and,
and, and it really tends to 

402
00:22:03,400 --> 00:22:06,200
drive process in that direction.
And sort of the flip side of 

403
00:22:06,200 --> 00:22:08,640
that which I'm actually 
interested in your thoughts on 

404
00:22:08,640 --> 00:22:11,080
which I think builds on top of 
this on on the one hand, you 

405
00:22:11,080 --> 00:22:14,400
have security, on the other 
hand, you have trust, you know, 

406
00:22:14,400 --> 00:22:18,840
in A2 package and trust will 
enable speed if you do it right.

407
00:22:19,680 --> 00:22:22,960
So what are, how are you seeing 
people think or how do you think

408
00:22:22,960 --> 00:22:28,520
about, you know, creating trust 
systems within these complex 

409
00:22:28,520 --> 00:22:30,000
autonomous interactions? 
Yeah, and. 

410
00:22:30,000 --> 00:22:33,080
Can I add a third because I 
think about a stool, There's 

411
00:22:33,080 --> 00:22:37,960
also there's experience or 
friction because because I I 

412
00:22:37,960 --> 00:22:41,320
think a great security footprint
isn't going to be worth anything

413
00:22:41,320 --> 00:22:42,400
if you have everybody. 
Works right? 

414
00:22:42,400 --> 00:22:44,360
Everybody's mad about it. 
Yeah, yeah. 

415
00:22:44,360 --> 00:22:49,760
And and, and they will. 
So I think of it as a it's, it's

416
00:22:49,760 --> 00:22:53,240
really a, an experience problem 
at the end of the day. 

417
00:22:53,280 --> 00:22:58,920
Like if we only solve an access 
control problem, it's putting up

418
00:22:58,920 --> 00:23:02,520
a bunch of stop signs. 
But if we can look at it as, 

419
00:23:03,440 --> 00:23:09,560
hey, there is a wealth of 
incredibly valuable data that 

420
00:23:09,560 --> 00:23:12,680
you now you can have access to 
and you don't have to ask 

421
00:23:13,080 --> 00:23:15,800
because all that is taken care 
of behind the scenes for you, 

422
00:23:16,120 --> 00:23:18,320
right? 
And a lot of stuff doesn't 

423
00:23:18,320 --> 00:23:22,120
require a ton of scrutiny. 
You probably want to know what's

424
00:23:22,120 --> 00:23:23,800
happening. 
You probably want an audit log 

425
00:23:23,800 --> 00:23:25,880
of all your agents and what 
they're up to. 

426
00:23:26,720 --> 00:23:30,720
But if we can empower people to 
take that first step, that 

427
00:23:30,720 --> 00:23:33,400
builds a lot of momentum, I 
think for what comes second and 

428
00:23:33,400 --> 00:23:35,480
third and 4th, because I think 
everybody had that experience 

429
00:23:35,480 --> 00:23:38,040
with AI, right? 
Like you kind of read about it, 

430
00:23:38,040 --> 00:23:41,200
but it's when you have your 
first touch with Oh my gosh, 

431
00:23:41,200 --> 00:23:42,920
that really went as well as I 
thought. 

432
00:23:42,920 --> 00:23:46,920
Or you see a hackathon where 
somebody, you know, build 

433
00:23:46,920 --> 00:23:49,320
something and you're like, wait,
you built that and you did it in

434
00:23:49,320 --> 00:23:51,960
a day, right? 
Kind of forces you to rethink 

435
00:23:51,960 --> 00:23:53,120
your assumptions about. 
A lot. 

436
00:23:53,120 --> 00:23:56,080
I built a custom MD scraper that
basically pulls from YouTube 

437
00:23:56,080 --> 00:23:57,760
linked. 
I mean like anything I wanted to

438
00:23:57,760 --> 00:24:00,240
do the half hour vibe coding on 
on clock code. 

439
00:24:00,480 --> 00:24:02,200
They brought it locally, but 
still, you know, yeah. 

440
00:24:03,200 --> 00:24:05,120
So I just keep coming back to I,
I think there's a really 

441
00:24:05,120 --> 00:24:09,400
positive opportunity here for 
companies to get really better 

442
00:24:09,400 --> 00:24:12,040
at what they do. 
I mean, I've, I've loved the 

443
00:24:12,040 --> 00:24:14,800
technology, I've, I've been into
infrastructure for a long time. 

444
00:24:14,800 --> 00:24:19,640
But I think what really drives 
me for a lot of this is I, I 

445
00:24:19,640 --> 00:24:24,200
want to, I'm an end user. 
I want to see better products, I

446
00:24:24,200 --> 00:24:26,280
want to see better customer 
experiences. 

447
00:24:26,960 --> 00:24:28,680
I want that stuff to really be 
great. 

448
00:24:29,000 --> 00:24:34,960
And the AI thing goes way beyond
helping companies write that 

449
00:24:34,960 --> 00:24:37,040
software faster that I use 
everyday. 

450
00:24:37,040 --> 00:24:40,040
It's going to make the company a
more customer centric company 

451
00:24:40,800 --> 00:24:43,000
and it's going to show up in all
kinds of different places, I 

452
00:24:43,000 --> 00:24:48,800
think. 
And so it's it's, it is a 

453
00:24:48,800 --> 00:24:52,640
security and a trust problem. 
But I think it's also more and 

454
00:24:52,640 --> 00:24:56,600
more, the way I think about it 
at least is you get there by 

455
00:24:56,600 --> 00:25:01,000
meeting people where they are 
and showing them a, an exciting 

456
00:25:01,000 --> 00:25:02,520
path. 
Because I think everybody wants 

457
00:25:02,520 --> 00:25:06,120
to be a builder at some level, 
you know, like it's fun. 

458
00:25:06,640 --> 00:25:10,480
So, so related to that, although
much deeper down in the weeds, 

459
00:25:10,960 --> 00:25:15,720
if you had a wish list of 
changes to the MCP spec or to 

460
00:25:15,720 --> 00:25:19,280
the Graph QL spec to further 
this vision, what would be the 

461
00:25:19,280 --> 00:25:21,760
things that you would you would 
sort of say you think could 

462
00:25:21,760 --> 00:25:23,840
really help things along and if 
I'm getting you into how? 

463
00:25:23,880 --> 00:25:25,880
Much time do we? 
Have if I'm getting, I mean, if 

464
00:25:25,880 --> 00:25:27,480
I'm getting into political 
trouble, then. 

465
00:25:27,480 --> 00:25:30,080
You know, No, no, no. 
I mean, I've, I've talked about 

466
00:25:30,080 --> 00:25:32,480
the graph QL piece in, in a lot 
of places. 

467
00:25:33,280 --> 00:25:36,520
Well, I think the more context 
you can give the model, the more

468
00:25:36,520 --> 00:25:40,720
capable they get. 
So a lot of this stuff in, in 

469
00:25:40,720 --> 00:25:45,680
both MCP and graph QL I think 
goes to the idea of providing 

470
00:25:45,680 --> 00:25:50,520
more structured context. 
There's an opportunity to, I 

471
00:25:50,520 --> 00:25:56,520
think provide a richer amount of
like, if you think about what 

472
00:25:56,520 --> 00:25:58,920
this means, how does a human 
think about what something means

473
00:25:58,920 --> 00:26:01,480
while they think about how's it 
being used elsewhere, They think

474
00:26:01,480 --> 00:26:04,200
about access patterns. 
They think about, I mean, all 

475
00:26:04,200 --> 00:26:07,840
that human judgement. 
We don't, it's not always at the

476
00:26:07,840 --> 00:26:10,760
front of our mind, but it's 
what's driving our our decisions

477
00:26:10,760 --> 00:26:12,280
as developers. 
So we've got to get all that to 

478
00:26:12,280 --> 00:26:14,440
the models and there's a whole 
bunch of stuff you can do there.

479
00:26:14,760 --> 00:26:21,800
I think another piece is just if
we think about adapting the AP 

480
00:26:21,800 --> 00:26:23,800
is that we have which aren't 
going anywhere as you said to 

481
00:26:23,800 --> 00:26:27,600
what we're trying to do in 
practice, an agent in many cases

482
00:26:27,600 --> 00:26:30,120
is going to want to fetch a 
bunch of data out of a system 

483
00:26:30,120 --> 00:26:33,200
and the only way to do that is 
going to be to repeatedly call 

484
00:26:33,200 --> 00:26:36,080
something to paginate across a 
whole bunch of stuff. 

485
00:26:36,080 --> 00:26:39,440
Well that that's really not 
there's a lot of problems with 

486
00:26:39,440 --> 00:26:40,840
that access pattern. 
Sure. 

487
00:26:40,840 --> 00:26:45,440
So I think there are 
capabilities we can think about.

488
00:26:46,080 --> 00:26:49,560
Sequel's probably a good model 
for some of this stuff where the

489
00:26:50,600 --> 00:26:54,320
AP is get more sophisticated. 
We can move beyond sort of a 

490
00:26:54,320 --> 00:26:59,320
basic request response model and
start talking about things like 

491
00:26:59,360 --> 00:27:02,760
aggregation and sorting and 
filtering and the kinds of 

492
00:27:02,760 --> 00:27:05,880
things that an agent can quickly
express. 

493
00:27:06,480 --> 00:27:08,840
They can be pushed further down 
the stack because the closer we 

494
00:27:08,840 --> 00:27:12,720
can get those actions down to 
the core systems, the more 

495
00:27:12,720 --> 00:27:13,880
efficient all that's going to 
get. 

496
00:27:14,040 --> 00:27:17,120
So like essentially the task or 
the whatever the you know the 

497
00:27:17,120 --> 00:27:20,920
goal, the work becomes expressed
in a more complex query 

498
00:27:20,920 --> 00:27:24,400
structure that further down it 
can avoid some of the some of 

499
00:27:24,400 --> 00:27:26,640
the pitfalls of traditional API 
behaviors because. 

500
00:27:26,920 --> 00:27:28,960
I mean, as an example of like, 
the higher we can go up in the 

501
00:27:28,960 --> 00:27:31,440
abstraction chain, the more 
capable it's going to become. 

502
00:27:31,560 --> 00:27:36,240
And and you know, I, I think 
that applies to APIs just as 

503
00:27:36,240 --> 00:27:39,080
well. 
And at a high level, I think the

504
00:27:39,080 --> 00:27:42,640
question is just like, and do 
agents want a different kind of 

505
00:27:42,640 --> 00:27:45,840
set of access patterns like most
AP is were built either for 

506
00:27:45,840 --> 00:27:50,080
screens or they were built for 
least common denominator, you 

507
00:27:50,080 --> 00:27:53,200
know, service to service 
communication like a very domain

508
00:27:53,200 --> 00:27:57,160
oriented, you need object 25 
here you go, right. 

509
00:27:57,760 --> 00:28:01,560
So I just think what we're going
to find is that agents want 

510
00:28:02,360 --> 00:28:05,120
other things than that. 
They're going to want to crawl 

511
00:28:05,120 --> 00:28:06,440
over that data in a different 
way. 

512
00:28:06,440 --> 00:28:08,880
We can anticipate some of that. 
I think some of it will still 

513
00:28:08,880 --> 00:28:12,000
learn as we go, but I think 
there's going to be a lot of 

514
00:28:12,000 --> 00:28:16,960
value in adding that kind of 
higher level semantics to these 

515
00:28:16,960 --> 00:28:19,440
things. 
There's a lot more though. 

516
00:28:19,440 --> 00:28:22,160
I mean, we could talk about real
time and streaming and push. 

517
00:28:22,160 --> 00:28:24,080
That was a topic from this 
morning, right? 

518
00:28:24,080 --> 00:28:27,040
Like AII think fundamentally is 
kind of a real time thing. 

519
00:28:27,560 --> 00:28:29,560
It's certainly accelerating the 
way we interact with our 

520
00:28:29,560 --> 00:28:30,640
technology. 
Yeah. 

521
00:28:30,640 --> 00:28:33,440
And and I think both MCP and 
Graph QL have some, you know, 

522
00:28:34,520 --> 00:28:37,520
room for improvement on that 
front because again, it wasn't 

523
00:28:37,640 --> 00:28:41,120
maybe at the heart of what the 
original workloads most needed. 

524
00:28:41,640 --> 00:28:43,760
There's hints of it, but but 
there's a lot more that we can 

525
00:28:43,760 --> 00:28:47,600
build there. 
I'm very interested sort of as 

526
00:28:47,680 --> 00:28:49,920
because you live in at the 
intersection of two very 

527
00:28:49,920 --> 00:28:52,920
interesting worlds. 
I mean, because in graph QL, I 

528
00:28:52,920 --> 00:28:55,360
mean, you don't see a lot of 
people here that are very active

529
00:28:55,360 --> 00:28:57,120
in the API spec community as 
well. 

530
00:28:57,520 --> 00:29:00,560
I mean some, but it's, you know,
not, not you, you sit squarely 

531
00:29:00,560 --> 00:29:04,200
in the middle and it's a so you 
mean you have a very different 

532
00:29:04,200 --> 00:29:07,280
and sort of not different, but a
nuanced view of this or, you 

533
00:29:07,280 --> 00:29:08,600
know, an understanding of both 
sides. 

534
00:29:08,600 --> 00:29:11,200
It's really different. 
Yeah, it's it's, I feel like 

535
00:29:11,200 --> 00:29:16,200
we've made contact with business
world now and there's no 

536
00:29:16,200 --> 00:29:18,120
surprises there at the technical
level. 

537
00:29:18,440 --> 00:29:20,920
But there's a lot here, here. 
I'll leave you with this. 

538
00:29:21,080 --> 00:29:26,440
I've learned over the work we've
done that AP is, if you think 

539
00:29:26,440 --> 00:29:29,520
about it, are a handshake, their
contract. 

540
00:29:29,640 --> 00:29:33,560
And in a company, especially a 
mature company, especially one 

541
00:29:33,560 --> 00:29:37,040
where you've got thousands of 
these, this is really a people 

542
00:29:37,040 --> 00:29:39,440
problem. 
At its heart, this is all about 

543
00:29:40,200 --> 00:29:43,720
a multi stakeholder alignment 
and negotiation. 

544
00:29:44,240 --> 00:29:50,000
I think AI can offer a lot of 
benefit to navigating those 

545
00:29:50,000 --> 00:29:53,120
conversations and navigating the
kinds of changes that you're 

546
00:29:53,120 --> 00:29:55,160
going to want to make. 
But I think it's also important 

547
00:29:55,200 --> 00:29:57,120
to remember that like none of 
that's going to go away. 

548
00:29:57,120 --> 00:30:01,000
I think we're, we're always 
going to have people accountable

549
00:30:01,000 --> 00:30:05,360
for the quality of these systems
and the correctness and the 

550
00:30:05,360 --> 00:30:08,160
reliability and so on. 
And I think we're going to have 

551
00:30:08,160 --> 00:30:10,080
people accountable for the 
quality and correctness and 

552
00:30:10,080 --> 00:30:13,600
reliability of the agentic 
workloads that they build. 

553
00:30:14,480 --> 00:30:17,960
And if we recognize that upfront
and if we approach this not just

554
00:30:17,960 --> 00:30:20,720
from the point of view of like 
what's the transport look like 

555
00:30:20,720 --> 00:30:23,960
and how can we like add these 
semantics here to this protocol,

556
00:30:23,960 --> 00:30:26,920
but we also look at it from the 
point of view of how is the 

557
00:30:26,920 --> 00:30:28,880
organization at scale going to 
change? 

558
00:30:28,880 --> 00:30:31,160
I know that sounds really 
abstract, but I've I've just 

559
00:30:31,160 --> 00:30:35,480
found over and over and over 
again, people are are in a 

560
00:30:35,480 --> 00:30:38,200
position to help drive these 
things. 

561
00:30:38,200 --> 00:30:46,120
But it's really about because 
the API is is has two sides or 

562
00:30:46,120 --> 00:30:48,480
because you might have 1000 
consumers of your API. 

563
00:30:48,760 --> 00:30:51,720
It really is about an 
organizational transformation, 

564
00:30:52,280 --> 00:30:54,040
which is exciting. 
That's a really good point to 

565
00:30:54,040 --> 00:30:57,080
end on. 
I mean essentially change NCP 

566
00:30:57,280 --> 00:30:59,880
and plus API equals change 
management because you've 

567
00:30:59,880 --> 00:31:01,440
democratized access to all of 
these. 

568
00:31:01,440 --> 00:31:03,480
Things at the speed of. 
AI, for better or for worse. 

569
00:31:03,560 --> 00:31:06,640
Yeah, exactly. 
Yeah, it's for better but but 

570
00:31:06,640 --> 00:31:09,400
it, but it's not going to come 
without challenges. 

571
00:31:09,400 --> 00:31:12,440
And I'm just, I'm really eager 
to see that through because I, I

572
00:31:12,440 --> 00:31:15,280
think there's a, an exciting 
world on the other side of I. 

573
00:31:15,600 --> 00:31:18,000
Think somebody said recently 
Yolo responsibly or something 

574
00:31:18,000 --> 00:31:21,000
like that which but. 
I like that, yeah. 

575
00:31:21,120 --> 00:31:23,480
Yeah, well, you're enabling 
parts of that. 

576
00:31:23,560 --> 00:31:25,440
Yeah, yeah. 
Thank you very much, Matt for 

577
00:31:25,440 --> 00:31:26,840
taking the time. 
I appreciate it. 

578
00:31:27,000 --> 00:31:29,760
Likewise, hopefully get to talk 
to you in another conference. 

579
00:31:29,880 --> 00:31:30,320
Sounds good.
