In short
Deploying agent workflows in enterprise environments using “agents.md” and a platform approach (VMware Tanzu/Cloud Foundry), including MCP tool access, identity/SSO, memory services, and an AI control plane (Prediction Guard) to apply zero-trust and compensate for the lack of a single “AI kill switch.”
Guest backgrounds
Nick (podcaster and tech marketing at Broadcom Tanzu VMware; co-host of Cloud Foundry Weekly). He has enterprise/private-cloud experience and focuses on how to operationalize agents with platform engineering.
Key claims
Enterprise constraints include limited/no internet (sometimes true air gaps) and compliance (PCI/SOX/HIPAA/FIPS). Agents should be treated like deployable apps via build packs (CF push agents.md). Biggest agent-specific challenges: state/memory persistence and co-locating intelligence near apps/data to reduce latency. Control must span multiple layers (I/O safeguards, agent identity, misuse detection, goal drift). Prediction Guard provides a self-hosted AI control plane.
Notable examples
A demo security-review agent triggered by GitHub/webhooks on repo events; agents performing Jira ticket updates; MCP gateway registering/authorizing many MCP servers; monitoring/metrics for tool calls (e.g., alert if an agent makes excessive destructive calls).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOMidwest AI Summit Discussion
1:00 to 1:48
Discussion about the upcoming Midwest AI Summit and guest Nick's involvement.
“One of those being our guest is one of the speakers at the upcoming Midwest AI Summit, which is going to be amazing.”
Enterprise Environment Overview
1:48 to 2:24
Nick explains what operating in an enterprise environment entails.
“Also excited to see you all in person in Indianapolis.”
Challenges in Enterprise Settings
2:24 to 4:48
Nick discusses the challenges faced in enterprise settings, including compliance and limited internet access.
“in an enterprise environment, which seems to be really fascinating.”
Path to Production in Enterprises
4:48 to 8:00
Nick describes how to simplify the path to production for applications in enterprise environments.
“it's a wild world, but it frustrates a lot of, I think, new folks to the enterprise base.”
Comparing Apps and Agents
8:00 to 12:54
Discussion on similarities and differences between traditional applications and AI agents.
“that they can use to get apps into production.”
AI Kill Switches and Control
12:54 to 14:03
Nick addresses the complexities of AI kill switches in the context of agents and control measures.
“if you're using some of these SaaS providers, they're maybe not the most reliable in terms of what traditional enterprises expect and demand.”
Understanding AI Kill Switches
14:03 to 14:58
Explore the challenges of implementing AI kill switches in a multi-agent environment.
“But the reality is that there is no one AI kill switch.”
The Rise of Multi-Agent Systems
15:49 to 17:33
Delve into the evolution and scale of multi-agent systems in enterprise settings.
“I want to kind of build on what you've been sharing so far.”
Deploying Agents with Tenzu Build Pack
17:33 to 19:12
Learn about the Tenzu Agent Build Pack for deploying AI agents effectively.
“Yeah, so I think that the first thing that we want to focus on is that the enterprise needs to get whatever technology approved throughout their system.”
Integrating Agents and Local Models
19:12 to 21:05
Understand how to integrate AI agents with local models in cloud platforms.
“And instead of machine-readable code, we have a human-readable language, the agents MD.”
Show all 20 chapters
Security and Control in Agent Operations
21:05 to 23:21
Discover best practices for controlling and securing AI agent operations.
“And then we're starting to add in like the memory service as well to have a kind of a shared memory service.”
Understanding MCP Gateways
23:21 to 26:21
Gain insights into the role of MCP gateways in managing access to AI resources.
“And we've talked a lot on the show over various episodes about agents using MCP to get access to different apps and services and tools and stuff like that out there.”
Defining Agent Behavior with agents.md
26:21 to 28:01
Learn how to define agent behaviors and manage their states using agents.md files.
“And there were a couple of things that you mentioned in there, I think are additionally worth digging into.”
Understanding Agent Implementations
28:01 to 31:21
Explore how agents are constructed, their functionalities, and the use of memory services in AI.
“How is that like state of the agent spread across, you know, the implementation, I guess?”
Integrating AI in Enterprise
31:32 to 39:34
Discover strategies for effective integration of AI technologies in enterprise settings.
“I think I had some understanding, but you've gotten a level of detail.”
Security Considerations for AI
39:35 to 42:01
Discuss the implications of security in AI deployments and maintaining control over agents.
“I want to circle back for a moment on something you said.”
Understanding Enterprise Security Measures
42:01 to 43:22
Learn about essential security controls for enterprise systems and the importance of monitoring.
“It's like, well, guys, you could have just had some basic controls.”
AI and Social Media Reactions
43:23 to 44:48
Explore the social media reactions to AI concerns and the misconceptions around them.
“And then that stirred up a lot of conversation, let's just say.”
Prognosticating the Future of AI in Enterprises
44:49 to 47:20
Speculate on future changes in enterprises due to AI advancements and new roles.
“What should orgs be having a thought toward for the future, even if we're not there yet today?”
Closing Remarks and Show Wrap-Up
47:21 to 48:09
Reflect on the discussion and provide closing thoughts and show information.
“And they should definitely go to the Midwest Summit and hear your talk.”
Transcript
Automatic transcript. May contain errors.0:01Welcome to the Practical AI Podcast, where we break down the real-world applications of artificial intelligence and how it's shaping the way we live, work, and create. Our goal is to help make AI technology practical, productive, and accessible to everyone. Whether you're a developer, business leader, or just curious about the tech behind the buzz, you're in the right place. Be sure to connect with us on LinkedIn, X, or Blue Sky to stay up to date with episode drops, behind-the-scenes content, and AI insights. You can learn more at practicalai.fm. Now, on to the show.
0:41Welcome to another episode of the Practical AI Podcast. This is Daniel Whitenack. I am CEO at Prediction Guard, and I'm joined as always by my co-host, Chris Benson, who is a principal AI and autonomy research engineer. How are you doing, Chris? Hey, doing great today. How's it going? It's going great. And I know this is going to be a great conversation for a few different reasons today. One of those being our guest is one of the speakers at the upcoming Midwest AI Summit, which is going to be amazing. There's going to be a bunch of amazing speakers there. I'm going to do a bit of emceeing, see if I don't mess that up.
1:19Would encourage our listeners to check that out October 15th in Indianapolis. You can get 20 % off with Practical AI 20. So check that out. So amazing speaker, going to be at the Midwest AI Summit. Also a fellow podcaster, which is great. One of the hosts of Cloud Foundry Weekly. and a tech marketing whiz at Broadcom Tansu VMware. So welcome, Nick. Great to have you. Thanks for having me. Great to be on the show. Yeah. Also excited to see you all in person in Indianapolis. Yeah, it's going to be fun. We're representing the good representation of the Silicon Prairie here. I like it. So, yeah, Nick, I know you're going to be talking.
2:10One of the things I thought was cool about your talk at the Midwest AI Summit is you bring in this concept of taking agents.md and shipping that to a production environment where you run an actual agent in an enterprise environment, which seems to be really fascinating. We recently had on someone from the Agentic AI Foundation who is kind of stewarding the model context protocol and agents.md and those sorts of things. So very relevant kind of carry on from that conversation. But I'm wondering as we set that up, what exactly does it mean to be operating in an enterprise environment? So the customers that you're working with, your kind of day-to-day, what makes an enterprise environment an enterprise environment?
3:06What are some of the concerns or characteristics of that type of environment? And I know you're always experimenting. You do a lot of home lab stuff as well. So always have a whole range of experience in working in different sorts of environments. So yeah, if you could just help us understand from a general perspective, what does that mean when you say kind of enterprise? Right. So yeah, if we think of the enterprise, we think about, you know, a few things. One, let's just assume you're going to have limited or no internet access. And, you know, I've been at VMortensia for about five years. And before that, I was at one of these large enterprises for about 14 years.
3:51So when we had vendors come in, it would always be like, they would always assume that we could just go to the internet. And it was always like, well, try again, because that's not going to work here. So that's kind of always like the biggest hurdle where you're going to be regulated and or, you know, you're not going to, what you can do at home is not going to be what you can do at work, so to speak. So you're going to be highly regulated. You're going to have to deal with potential PCI or SOX compliance or HIPAA or FIPS. And I could probably go on and on about all the different compliance tiers that you'd have to deal with.
4:25So it's just a whole different ballgame where you could potentially do something that has dramatic consequences. And you have a highly controlled, highly regulated environment where even some of the customers I work with, they're like, you know, they actually have the real air gap where we're carrying in things, you know, physically into the data center because there is no internet access type of thing. So it's a wild world, but it frustrates a lot of, I think, new folks to the enterprise base. But if you've been in a while, you know how to deal with it and how to handle it type of thing. And I guess, you know, people have been dealing with these types of environments for for quite a while, right?
5:07Because there've been enterprises for quite a while. And maybe just give us a sense of like leading up to AI agents, and we'll talk about agents here in a second, but leading up to AI agents, like what were some of the ways that you could, I guess, ease, you know, put some ointment on those pains of working in that sort of environment? How would you get an application into that sort of environment or or have it be enterprise ready quote unquote and then we can shift and talk about you know what changes with with agents yeah so i mean i think so you know i currently work for vmortanzu and we run a you know a platform or a platform as a service uh you know geared for private cloud whether that be on your like on your own bare metal in your data center or you could deploy it on a private cloud in your own like VPC on a hyperscaler, that type of thing.
6:03But we think about that, you know, we want to, in the scope of an enterprise, right, you have all these regulations, controls, et cetera, you want to make that path to production kind of the least resistant and easiest path. And if you make that path to production, like all the checkboxes and everything good to go, that's going to be a highly adopted path. So the whole concept of, you know, a Tinsu platform, and it's actually based on an open source project called Cloud Foundry, which is, I think, I mean, it's, you know, predates Kubernetes and Docker. So, you know, 2011-ish is when it kind of started originally out of VMware and spun out and then became part of an open source project.
6:38So it's been around and battle tested and seen a lot of things where you have that concept of like, I just want to take my code and send it to the platform. And the platform is going to know like the best practices for, it's going to build a container for the developer. So the developer doesn't have to worry about like, you know, securing the container or anything like that, the platform would take care of that. It will handle, you know, ingress, like certs, certificates, all the, you know, load balancers, all those things just handle health monitoring, potentially even kind of like sandboxing the apps from each other.
7:09Something that, you know, maybe some of these labs may learn from, but so that the apps can't escape type of thing. And, you know, if the app needs services like a database or messaging, middleware, any type of thing, even maybe a large language model, it can, what we call bind or kind of connect to a service on the fly. And that's all kind of handled underneath the cover. So it's just a few commands like you push, bind, scale your app with just a few simple constructs. And that's how you go to production. And what we see with enterprises, once that path, like once they take this, like this is a Tansy platform, it's been certified through all these different standards, it's just kind of like an unlock for these enterprises because it's so easy and so simple to use and they don't have to, you know, they don't have to recertify everything.
7:59It's just like this framework that they can use to get apps into production. And then the biggest thing is that you want these, the enterprises or the businesses, they don't want their developers, you know, hand crafting a new platform or a new way to deploy apps for every sub team and have like 100 different snowflakes, right? They want the same repeatable pattern across the board so that they can audit it and secure it and have their developers actually spend time writing the business logic versus like fiddling with infrastructure. So that's kind of like the whole premise behind, you know, the whole platform as a surface construct and, you know, Tainsit platform.
8:32And as you can imagine, go ahead. Yeah. No, no, go ahead. Finish up and then I'll follow up. All good. Okay. As you could imagine, those principles when we're talking about apps could probably play nicely into this agent world that we're living in. So it sounds like you're drawing a lot of commonality between kind of traditional app development and all of the structure that we're all used to, that we've been doing forever. And kind of now we're into the syngentic world, and maybe people have been thinking about that in a different way. But it sounds like you've really kind of said, and correct me if I'm wrong, I'm going to throw something out there.
9:11like it's kind of the same thing in the sense of there are differences but agents and apps should sort of be treated the same way is that am I getting that correctly in terms of of how you're structuring that and that maybe people need to look at what they've been doing for years and make that work for agents in the same way is that is that fair yeah I think it's a pretty fair assessment and we're starting to see that more and more just within our customer base and you know even like if you think about like apps back in the day, like someone would write some app on their laptop and like run it on their laptop, but it's like, we can't just run it on, you know, like you got to get it off your laptop somewhere.
9:50And the same thing with agents. You're like, I got this, I've got all these agents who are on my laptop. If I shut my lid, everything stops. Like I don't really want that to happen, right? I want them to run 24 seven, you know, 365 and do all the work I give them. So yeah, I think that's kind of precisely what we're going with. So I guess then it begs the question, why are people kind of throwing out what maybe their intuition uh like in certain ways people are saying oh we have agents now we need to do something totally different which is maybe driven by some things that make an agent not an app not just a sort of simple application but also it doesn't necessarily mean you know obviously we have to throw out everything we've learned about platform engineering and and how to deploy things.
10:39So from your mindset, where does the kind of agent equals just another app, where might that fall apart or what are the kind of unique characteristics that you're dealing with on the agentic side on the deployment pathway that you might not have had to consider before or at least are considering in a new way? Well, I mean, I think some of the biggest differences, right, where like you talk about Cloud Foundry and TNC platform, it was kind of based on this premise of a 12-factor application where storage and state are a little decoupled cleanly from the actual apps. I can scale up to a thousand instances and be fine and you handle session state and things.
11:20The traditional harnesses or agents were kind of built originally just like, I've got file system access and I can just write a bunch of MD files and that's like my memory. Everything's great. Well, you start to get into a cloud world that things spin up and down and are ephemeral. you're going to want to save those MD files somewhere they're going to go off into the ether. So that's probably I think the biggest challenge when we start talking about how do we take the app deployment methodology and then push that into an agent running on a cloud platform per se. It's probably the biggest challenge.
11:54And then just kind of getting the fact that there's some valid use cases for your laptop or whatever but then also as we're starting to see more and more enterprises want agents to be on demand and usable say in a CICD pipeline or within part of their e-commerce suite or just normal applications and you want those to be kind of really close to the apps because if you have them way off even just from a pure networking perspective if you have the agent or the LLM or whatever that's 30 hops away from the microservices trying to call it, there's physics that are going to add on to all of that latency and potentially at scale even be problematic.
12:33So they kind of want to collate all the, co-locate the intelligence with the app and the data as close as possible. That's what we've seen too. That's something that I didn't expect really because some of these responses are kind of long, but it's like what we've seen with our customers at scale. Like we want to get the LLMs and the agents closer to us and our actual apps using them and the people using them as well. And not to mention, if you're using some of these SaaS providers, they're maybe not the most reliable in terms of what traditional enterprises expect and demand. So you can't just have them going offline for hours because even at my past job, the very first thing I did there was work on a warehouse inventory system.
13:11And let's just say it was for a large retailer that was a grocery retailer in the US. And I was an intern out of college and the app was older than me at the time, still older than me. And it was a bunch of C and shell scripts on Unix systems. And if that thing went down, like within five minutes, like the warehouse was backing up trucks like on the interstate. So it's like, you have to like, the scale of enterprise versus just, you know, like consumer is a completely different scale. So that's why some of all the things we're trying to make them a little bit more enterprise grade and more used to what these enterprises expect from software.
13:54Some mornings as I'm drinking my morning coffee. I listened to live news updates to figure out what's going on in the world, and it seems like recently everyone is talking about AI kill switches. But the reality is that there is no one AI kill switch. We've moved from models to agents. Those agents are connected to multiple models. They have an agent harness. They're connected to MCP servers and tools, and those agents are acting within a fleet, delegating to one another and interacting with one another. In that environment, what you don't have is a single kill switch that solves all of your problems.
14:33But that doesn't mean that you can't exert your control. You just have to exert that control across various layers of that stack through, of course, component input output safeguards, but also controls on agents tied to their agent identity, things that track tool misuse or memory poisoning or goal drift, etc. And what we're providing at PredictionGuard, the company that I lead personally, is an AI control plane that you self-host in your own infrastructure that gives you that control plane or control layer for the relevant stack that agents operate on top of. I'd encourage you to check out what we're doing at predictionguard.com slash practical AI.
15:23Go ahead and book a call with myself and the team to learn more about how you can gain control of the agents operating in your environment and exert zero trust principles in the way that you operate those agents. So check us out at predictionguard.com slash practical AI. That's predictionguard.com slash practical AI. So Nick, I would love to dive back. I want to kind of build on what you've been sharing so far. And part of that is that we're all diving into this multi-agentic world where, you know, some, you know, late last year, you know, you'd have an agent. and then for most people I think getting into multi-agents it was probably developers in the environments that the AI providers were making available and you had multiple agents working on a project but now we're really seeing with these work products and other things that have come out we're seeing agents really multiplying across many different contexts and with a lot of different utility and it's moved out of being just frontier services and we're now doing that with our hosted agents as well that we're running.
16:44And so like this multi-agentic world has just taken off in a very short amount of time. And as you're, I guess I'm asking if you can kind of paint a picture as you start scaling this out in the enterprise and what that looks like, Like, could you describe, you know, and we have analogies, as you've pointed out, with kind of the traditional software development world and the containers and all the, you know, and how you're structuring deployment and stuff. Could you talk a little bit about what that looks like, kind of paint a picture so that somebody can really get that in their head? Me, first of all, about what that multi-agent world looks like when you were doing all these right things that you need to do in the enterprise.
17:33Yeah, so I think that the first thing that we want to focus on is that the enterprise needs to get whatever technology approved throughout their system. And then we are providing a harness called the Tenzu Agent Build Pack, and that helps through that process. So our existing customers already have our customer, we're already approved so that we can help provide them those tools. And we just make that process just another app deployment on the platform. So I probably haven't covered, they said, I'll explain what a build pack is, right? So when you, when you. Yeah, I was about to, I was about to ask you that.
18:08Right. If you could kind of dive into what the specifics of each of those things does. Sure. So when I would do demos before AI and before, you know, a year or two ago or whatever, we would always take like a Java app and it was like a simple kind of like, you know, music album, we called it Spring Music or whatever. But we take that Java code to be like a jar file, like compiled Java code. And we're like, all right, now we're going to take this. We have a little simple manifest file that tells us what the name of the app is, how much resources to give it. And we just run a command called CFPush.
18:35And that would then just take that code, the jar file, and upload it to the platform. And the platform would be like, oh, it's a Java app. So I'm going to use the Java Build Pack. And the Build Pack is basically kind of a command set to make a best practice container based off that use case. So the Java Build Pack knows to do all the JVM memory calculators, do the JDK and certificates. and everything that's best practiced to run Java in a container on a cloud platform. And that would be great. And then we would attach a database and all these things and show how that scales. Now, we've taken that same concept and then said, hey, we're going to have this agent.
19:11We're going to just CF push an agent. And instead of machine-readable code, we have a human-readable language, the agents MD. So basically, you tell what the agent it's going to do, and then you just push it to the platform, and it starts up within a minute type of thing. and you can scale that up, push as many agents as you want. And I think the coolest thing that I've seen is that once we're on the platform, then we can run models on the platform. So obviously a lot of our customers are air-gapped and some of them were smart enough to buy GPUs a few years ago. So some of them have lots of GPUs that can run all these local models and have a great experience.
19:46Some are wishing that they bought GPUs and hardware as the pricing of all this hardware goes through the roof. But then they can run local models and then tie the agent to that Or if they don't have, they might have a contract with one of their cloud providers or one of their approved LLMs of choice to register that. Then that kind of gave us a simple, here's your out-of-box agent with chat experience. And then along the way, we've done a lot of things with MCP, the model context protocol. Probably you guys covered that on the show before, but it's basically a way for an app to talk to an LLM.
20:21Very high level, right? So that's become useful as well as we then give the agent tools via MCP servers. And even at Broadcom, the only way approved way to use for our developers is to deploy MCP servers on Tansy platform. So that we have a whole set of MCP servers that are approved and hosted and they're kind of secured and maintained because they're very similar to applications as well. And then we have a concept of like the MCP gateway service that kind of registers that and secures all those servers. So then we can then extend the gateway to that agent. So then the gateway, this agent now has like secure access to a runtime, you know, battle test runtime.
20:58It can talk to an LLM that's approved and get tools via gateway. And then we're starting to add in like the memory service as well to have a kind of a shared memory service. So we're kind of expanding all that out where we're seeing all those best practice app lifecycle. Go to, you know, see a push, go, here's an agent, here's all the things it wants to do. And then, you know, it can be a security review agent. And like one of the things I showed, I was at a, I think a week or two ago, I can't quite remember. I was in Las Vegas for a conference, VMware Explorer. And I had like a five-phase demo where I walked through this.
21:33Maybe I'll show a little bit of this at the Midwest Summit here. but push the agent, bind all these services but the end goal was like the boss level was like all right, now we have these agents sitting in there and I can hook them up to a repo with an event listener or a webhook and say, all right, now do issue five on my repo, do a security review on this repository and then it sends it off to the agent via webhook and like, oh, the Tenzu agent fires up, gets it, fires up from the platform it gets a request and it just immediately pulls down the repo and starts doing a security review and then publishes or pushes up to the issue that I created on GitHub and says, this is security review.
22:13So you can see how that flow would be really useful in enterprise where like maybe on every git commit, you just have all these agents spinning up on the fly that could be a security review agent, potentially like a style or code quality review agent or potentially even like a, I don't know, like maybe a design review agent, all firing up on the fly as things like call. So it's kind of like, and then they all have their, they're all in their own little sandbox and everything's proper, right? Because part of, you know, the platform for a while, it's been like this very secured container runtime where like we have, you know, they can't talk to each other unless you enable them.
22:48So they can't go to the internet. Unless that's enabled, they can't, you know, escalate. Otherwise, they only get access to what you give them. So it's kind of that benefit as well. And then obviously they're containerized. They don't have access to the, underlying host system as well. So as we've seen some of these things of uncontrolled agent swarms, I think we have some remedies here that some of these AI labs could maybe take into account and implement some best practices that's learned throughout the past two decades. The unplanned swarms, the swarms that you don't necessarily want. I actually have a two-second follow-up and that is for my benefit.
23:25And we've talked a lot on the show over various episodes about agents using MCP to get access to different apps and services and tools and stuff like that out there. We haven't really talked about what an MCP gateway is, and I was wondering if you could share that for a moment just as a detail, because that's kind of the one little new piece of architecture that we've never touched on on the show. Yeah, so if you think about an MCP gateway as a way to easily control and scale access to MCP servers, especially within, you're in a cloud, I guess, platform. So we may have like 30 or 40 MCP servers that we run, or I don't even know how many it is, right?
24:06And then those get bound, those get registered and bound to certain specific MCP gateways. So maybe there's a, you know, and the MCP gateway is something we can spit up on the fly on the platform. There are many different MCP gateways out there. There's many different AI gateways out there. Some of them are like the same, one and the same. But you basically register MCP servers to this gateway and the gateway kind of controls access, so to speak, and regulates that. So it may say you can bind to this gateway and you only get these MCP servers you only get these MCP tools within it, that type of thing.
24:40So it's a way to easily abstract all the different MCP servers that may be in an organization and kind of direct them into either a certain agent or we even have a flow where we'll take those MCP gateways that we run that front all of our MCP servers. And then you can say, hey, go give me a way to connect this to my cursor or my cloud code or my whatever. And then it just injects it in there. And then your local agent has all the tools that are approved as well for your organization. And then it's just like a simple click and then it just registers. And then depending on the MCP server, it helps the handle the auth as well.
25:14Because some of them are like, well, if I'm using the GitHub MCP server, I want to pass my end user credentials all the way through to that MCP server because I don't want it just to be like, well, here's our generic service account for the entire organization and every GitHub action is going to be seen by that one account. And you have to have the individual identity pass through. So you have the concept of SSO and sign-in as well and identity for agents or humans running their agents on their desktop. So that's kind of a quick level of view. And then a great way about that too is because it's all flowing through that gateway, we get metrics out of it.
25:49so we can see all the tool calls and all the events happening coming from the agents to the MCP servers and back and forth. So you can kind of see what's happening, especially if maybe if there's something unexpected, like, well, this one agent made 200 ,000 tool calls to delete repo. Like, oh, maybe we should alert on that. That's probably not good. So another visibility or metric to see what agents are doing and what tool calls are doing as well. So I guess hopefully that made sense because that's kind of how I understand it. Yeah, that was great. And there were a couple of things that you mentioned in there, I think are additionally worth digging into.
26:27And you kind of have this, if I'm understanding right, in part of the build pack that you're working on, part of that centers around kind of pushing an agents.md file. You mentioned like people have these MD files hanging around. You mentioned memory, you mentioned identity. I'm wondering if you could kind of help us understand, like, if I'm working on my laptop, right, and I'm using a certain agent harness, I may have an MD file that is kind of generic. And then I have files that are created by the agent that it uses that are only corresponding to my single agent. and then I have memory and then calls into other things.
Read the full transcript
27:16As you're pushing this off the laptop, and I imagine taking that off, what belongs in an agents.md file? And as you're giving that example, you may have one agent in the platform that does security reviews. When you spin that agent up, Does each instance of that, each session have a unique identity? What is the, what's unique about that session and the data that is generated by that session versus maybe the things that are always static? Like, I'm not sure if the agents.md is always static. So could you help us understand like, which are the static elements? What's developing over time? How is that like state of the agent spread across, you know, the implementation, I guess?
28:09Sure. So if you think about it, in this specific implementation, the agent's build pack is basically the boilerplate code of what you want the agent or app to do. So I'll do demos and I'll have it be like you're a pirate. One of my demos is you're a Jira, you're a senior software engineer. You're going to watch this Jira page, or I forgot the terminology here. Basically, watch this Jira queue and look for any inbound tickets. As inbound tickets come in, review them and make sure that they're of good quality. Here's all these different things that you want to do. Don't do any of this. It's more of a very simple agents MD where it's just telling this agent what it should do and how it should act.
28:55Then you can call that and ticket 500 came in. It was poorly documented. Update that Jira ticket and whatever. Then you can add fun things like talk like a pirate. So it's like, all right, matey, your ticket 500 is terrible, right? Like, go back and update it, that type of thing. So that's kind of where the static part of it is. And then the memory service we have, you can attach it, you can have potentially memory of a certain project. So we kind of envision each set of teams to have their own multiple set of agents, right? And it could be like, well, Team A's agents have the access to Team A's memory.
29:29So as they come up, they know all of this historical data of the architecture of the application, what's been done before, the roadmap, that type of thing. So as it spins up and does a security review, it can make proper decisions and proper guidance so that as you build your local agents and give them memory and they become smarter, that memory service, as you have agents spin up and down, they just immediately know what's happened before, know how to proceed. As you heard at the beginning of this episode, some amazing people like Nick, who's the guest on this episode, are joining us at the Midwest AI Summit, October 15th in Indianapolis, Indiana.
30:16Nick is going to come talk about what it looks like to deploy AI agents in real world environments. And we've got a bunch of other amazing speakers talking about how AI-enabled teams work, how to make decisions about what to say yes to and what to say no to in relation to AI, and much more. Super practical and amazing talks. Plus, there's going to be an AI engineering lounge where you can actually sit down with folks like myself. I'll be there. Get review on your AI architecture, your stack, your roadmap, etc. Towards the rollout of things like agents or other AI technology. This is a practical, amazing event that you don't want to miss.
31:03There'll be great food, great people, great networking and practical value. Do not miss this. It's October 15th in Indianapolis, Indiana, and you can use the code practicalAI20 to get 20 % off registration. So go to midwestaisummit.com and use the code practicalAI20 to get 20 % off registration. before we were going into break i think i may have cut you off uh when you were just starting to say something uh you want to dive back into that real quick um no i i think i think i covered it hopefully i answered the question again but that's no problem okay so really i really like this has been really good uh for helping me trying to conceptualize you know how all this fits together.
31:56I think I had some understanding, but you've gotten a level of detail. I want to ask you, as we are looking forward, I have several questions that are really kind of driving my thinking. You've got me thinking creatively based on what you've said. So as you look at, we've talked about MCP. There are new things coming out, things like there's the A2A, which is the agent-to-agent protocol, and organizations are starting to look at that, and they already have their MCP servers maybe, but they're trying to get the structure and kind of bring the sanity around it that you've been talking about. Then they kind of go, oh, okay, it's not so different from what we've already know.
32:43But as this is evolving very fast and you have things like these new protocols, do you have any guidance on how to start integrating this constant flow of change in, in terms of, first on the technology, and I'll hit the other half of that afterwards, but as you're trying to bring things in and make it work, and have you guys kind of thought about how to structure that? Yeah, I think it's, I mean, I guess we'll just say take baby steps from everything, right? Because especially when you talk about the enterprise scope, they can be a lot slower to adopt some of these newer technologies. so you kind of layer that on and like you don't have to necessarily adopt all of these things at once you can maybe just get a simple agent running and you know for most places you know just getting access to an LLM is still the biggest hurdle right a secured you know approved so and then potentially you know going through the AI council committee right like everything must run through the AI council and be approved if you know like most you know if you're not if you've never worked in an enterprise Most large enterprises have a council or committee for everything, right?
33:51Yeah, I do. So I know what you're talking about. It's like, well, we shall go to the committee and we shall present our idea. And we will wait six months and see what has the result been, right? So you just kind of have to work through the councils and the committees and all that fun. But once you finally get something approved, just iterate. And you're like, don't try to boil the ocean, make baby steps, you know, and get progress. And then as you'll like, and you'll learn the technologies and the next step will just kind of be obvious. It's like, well, I can make the agent better if I get some MCP servers, get them tools.
34:22All right, and then we've got to get these tools approved and then add on to that. And then, you know, and some of these guardrails help, you know, of Tainsy Platform, help enterprises bring these tools to light because it's not just, you know, all this random stuff downloaded from the internet, right? Which that can be its own danger nowadays. So having the, you know, having some guardrails in place is a good thing. if you've had you know if you have experience with some of these platforms or apps running before take that take that experience and that knowledge and kind of bring it forward and and utilize your existing people and skills I think too I think a lot a lot of times too I see in organizations like a new technology will come up and like a new team will be built and that new team will decree but there's so much other like really skilled people that could help and it's always kind of a friction too so how to try to try to get the teams to work together too and not not just have the new team doing all the new things and then the teams that have been there all the while have that, like that's always another constant flow.
35:20So try to break those silos down as well to help get people up to speed and get through that process. Having worked in multiple enterprises myself, I think that last point, I think I've seen that multiple times across different organizations. And how do you bridge that? I think part of it, you kind of have every organization has its internal politics. They all have kind of the different structures. It's really common, say, new tech, new team there. But then I think people recognize, you know, why? You know, that kind of, you'll see that and sometimes you'll see a reconciliation, but it always seems like a little bit of a struggle when that happens to try to, you know, do you have any thoughts around as As you're trying to do that, you may have a lot of big organizations have their very one business unit, maybe almost like in a different universe from another business unit sometimes.
36:22And so how do you get that kind of cross adoption where you're taking advantage of maybe both the new teams that may be there, but also some of the old structured teams and you're trying to spread the capability across the larger organization in a useful way? Do you have any guidance? You know, I imagine it can't be that different from, you know, the more traditional app dev side. But I think this is a struggle that a lot of boards are facing right now. Yeah, well, I think, yeah. So, I mean, it goes, I think, a lot both ways. So if you have the new team, right? The new team can, like, the responsibility of the new team is, like, engage every other team because they have a lot of people that can help you out and achieve your goal, right?
37:09Because the new team probably most likely has a very stressful and like, you know, like adopt AI everywhere or before it was like go cloud everywhere, right? Like those goals are like not quite easy to get going in an enterprise. So the new team needs to like, you know, they potentially run, you know, office hours, weekly office hours, reach out to their other teams, you know, maybe before, you know, like a lunch and learn if you're in the office and have people in the office, that type of thing. And just have like a forum for people to come in and learn and get started and ask questions. Like, hey, I saw this post about this new platform or this new AI thing.
37:50How do I get started? Is there any documentation or what can I do to get started? And just kind of have an open and very welcoming place to get started to bring in the folks. And then if you're on some of the, let's say, not new teams or teams that then are a while, be engaging and reach out to those teams because a lot of the new people are going to need help. They're maybe under stress. So it's just breaking that down. And then I think with this iteration, it's going to happen a lot faster. And I think people just naturally want to work together. Because I think I was at VM Explorer and I did a few talks and I started every talk with like, all right, let's get a show of hands in the room.
38:29Who has used one of these tools at work, like cursor, cloud code, whatever. And pretty much the entire room and all of them went up. And I was like, well, that's a lot more than I expected. So the adoption rate, even at the traditional platform or developer engineer or just infrastructure admin at some of these personas is well into that scope. So the entire enterprise, I think, is picking up on this really fast. And the more collaboration, I think, just will help out. So, you know, just office hours, you know, reach out, be proactive. And I guess if you're on, if don't be, be, be mindful or be open to change.
39:07I just, this is just in general, if what I've seen before, and if you're, if you're resistant, and resist the change, and, you know, that's, that's going to kind of get you labeled and kind of put off the side. But if you're, you may be, you may have your own opinions, but if you present them in a way that kind of is, let's say, maybe open minded, per se, you have a better chance at some of those key learnings that you've dealt with throughout your career to actually be applied in the new way as well. That makes sense. I'm curious. I want to circle back for a moment on something you said. As we're talking about kind of spreading across, my mind goes to security because I know in my industry, security is a pretty big deal.
39:50We do have air gap things and stuff like that. That's what we do in defense. but as you're thinking about that one of the topics that is a really common topic now is kind of going back a few weeks we covered it in depth on a previous episode the whole open AI swarms got out hugging face, that whole thing I'll refer people back if they're not familiar with it to our episode recently that covered that but that is top of mind it's not only top of mind for security, but it's top of mind for legal. It's top of mind for comms as they're thinking about what do we do if something like this were to happen in our org, whatever that org is.
40:34And can you talk a little bit about, as you've kind of brought the enterprise structure up to date to deal with agents and we're beyond just the traditional software and app world and we're We're taking some of the same lessons and reapplying them in a new context here. Can you talk a little bit about how that helps on the security side? For the folks out there that are really, you know, that's their job is to keep things from really going awry. Can you talk for a moment about keeping things in the box, if you will? Yes, for sure. And then I guess I'll put a disclaimer. These are all could be suggestions to help out with.
41:14If you really dig into some of the hugging face stuff, it's a little like scary. So I'm not to say that we're like better than all of the iLabs or anything like that. But if you look at some of the things or how that kind of got started is where they, you know, like started getting out of the sandbox, right? And then they found things that were like they could get access to or, you know, having monitoring control around what those apps or agents can do is, you know, something that's been in mind for all enterprise apps, right? So like having, you know, kind of guardrails, even like network zones are like, hey, this is a highly regulated zone.
41:48it's super locked down. Even just traditional firewall would have potentially blocked a lot of this stuff. It's kind of key. A lot of the core enterprise learning to maybe take that for the old team versus the new team. It's like, well, guys, you could have just had some basic controls. I think they even talked about their monitoring wasn't working. They weren't really monitoring it. You had all these agent swarms. Then I got to the artifactory, which then I found the weak link, and the artifactory had the internet access, and somehow they magically, you know, zero-day the Artifactory instance multiple times.
42:20So not to say that we could prevent everything, but it's just you take those, these core enterprise technologies that maybe would have helped out a little bit of just, you know, agent control, like hardened sandbox type constructs, very locked down network controls. That would have helped a little bit potentially, you know, just, you know, monitoring what's in the agent, make sure that the agents are, you know, somehow injecting tools that they're not supposed to have. I'm not sure if that was an issue or not. But, you know, when you talk about an application, the whole dependency stack is always up to grab.
42:55So you want to make sure that the dependency stack, the container, everything is in the whole OS and the whole platform is trying to patch and reliable as possible. So I think the key thing is obviously, you know, we had the whole mind-bending effect of that they somehow made this messaging board on Artifactory and then it got deleted and they recreated it. So there's that factor, which I think everybody's a little like, that goes into the whole AI is going to kill us thing that happened over the weekend, right? Versus just do some basic security, basic stuff, right? Just to clarify, that was a social media post, less people misinterpret that.
43:28Yeah, that's a question. If you're not on AI Twitter or AIX, there's a lot of posts around, you know, somebody left Anthropic and a bunch of Anthropic people started posting around that they're afraid that, you know, there's a greater than 10 % chance that AI is going to take out humanity over the weekend slash Friday. And then that stirred up a lot of conversation, let's just say. So that's what I was referring to. Yeah. Okay. I guess that's useful. I appreciate that. We like to finish off by kind of giving you kind of a free form question. And that is kind of toward the future as you are doing your job and running your podcast and talking to people and kind of building up your perspective on where things are going with this.
44:20We like to ask guests to go ahead and get crazy and prognosticate just a bit. And we don't hold you to it. But really the way we do this is when you're kind of just letting your mind wander and you're thinking about these things in the back of your mind, going to bed at night, having a glass of wine, whatever it is you do to chill out. What do you think things are going? And you can choose the timeframe that you like, but I really like to think like, what do you think is coming? What's next? What should orgs be having a thought toward for the future, even if we're not there yet today? Any thoughts on what that future looks like as we close out?
45:07Oh boy. it could be many things but I think from an enterprise perspective I think we'll see a lot of like team change role change not even just in enterprise like the whole like from the business side things are going to change a lot right because you're starting to see and I was going through old episodes of my podcast this year and just some of the old just the start of this year and there's just now I was like wow a lot has changed like can't imagine like can you like you know imagine a couple years from now how much change the rate of change is now It's accelerating. It's hard to imagine that, but I definitely think from a business perspective, we're going to see a radical change in how development and product management and everything changes.
45:51There's going to be new roles get created. Orgs are going to change, I think. I think for the good, too, because there's always a fear of job loss, but I find that I've heard this echoed across many personal experiences. I am working harder than I ever have because I have all these agents and they need stuff from me. And I'm constantly building things that I always wanted to build but just never had the time to. So I feel like we're all going to be busy and maybe we need to not get too crazy with the agents, but it's hard for me because it's fascinating. It's really enjoyable. Doing a lot of things with automation, I can only imagine what these agents are going to be like in the next six months in terms of what they can do for you.
46:35I think we'll see a lot with voice come into play, maybe even a new style of interaction with the computer as well. So that will be interesting as well. And then obviously I think, you know, did you see the posts like hugging face had little robot things on sale? Yes. Yeah. So like the little micro duck things or whatever. I did. I was like, to my wife, I was like, maybe we should get one. She's like, you have enough toys. You just stop. Yeah. Well, I may have ordered a few for the family and I'm like, those things are going to be awesome. So like, like robotics and things like, you know, I think the LLM is great and wonderful, but there's so many more possibilities where we could go that I guess like for humanity, right?
47:14As long as we prevent the Terminator scenario, it'll be great, right? absolutely great I appreciate you painting that that helps a lot yeah the rate of change is just insane now and I agree with you I think it's going to get faster and faster but great way to end the show a lot of fun I always love to hear what people say when we're asking about kind of where they think things are going thank you for coming on the show today it was a great conversation I learned so much really appreciate that And I hope people tune in to Cloud Foundry Weekly to hear you talking more about these topics. And they should definitely go to the Midwest Summit and hear your talk.
47:59I was there last year, did a talk. I won't be there this year. So I'll have to see if I can get a hold of the video of it or something. But anyway, thanks for coming on Practically I today. Thanks for having me.
48:16All right, that's our show for this week. If you haven't checked out our website, head to practicalai.fm and be sure to connect with us on LinkedIn, X, or Blue Sky. You'll see us posting insights related to the latest AI developments, and we would love for you to join the conversation. Thanks to our partner, Prediction Guard, for providing operational support for the show. Check them out at predictionguard.com. also thanks to Breakmaster Cylinder for the beats and to you for listening that's all for now but you'll hear from us again next week
From the publisher
AI agents are moving beyond laptops and prototypes and into enterprise environments where security, compliance, scalability, and reliability matter. Nick Kuhn from VMware Tanzu Platform joins Daniel and Chris to discuss what changes (and what doesn’t) when deploying agents alongside traditional applications. They explore agent build packs, MCP gateways, shared memory, identity, sandboxing, and what enterprises can learn from years of platform engineering. Nick also shares practical advice for organizations adopting agents today and looks at what the future of AI could mean for enterprise teams and software development.
Featuring:
- Nick Kuhn – LinkedIn
- Daniel Whitenack – Website, GitHub, X
- Chris Benson – Website, LinkedIn, Bluesky, GitHub, X
Sponsors:
- Midwest AI Summit: Join AI practitioners on October 15 in Indianapolis for practical sessions, hands-on discussions, and real-world AI solutions. Use code PracticalAI20 to save 20% on your registration. https://midwestaisummit.com/#tickets
- Prediction Guard: A self-hosted AI control plane for running agents in high impact environments. predictionguard.com/practicalai
Resources and Events:




