In short
Enterprise AI should move beyond incremental efficiency gains toward rebuilding workflows from first principles, using governance, context/traceability, and agentic orchestration across the full SDLC (DevSecOps), not just code generation.
Key claims
“Faster pre-AI workflows” hit a productivity ceiling; outsized gains come from nonlinear, role-specific outcomes (e.g., innovation velocity, security/pipeline automation, support metrics). Adoption must be hub-and-spoke (central governance + embedded AI transformation owners). Skills (human-invoked, reusable workflows) scale AI usage; agents (event-triggered/autonomous) run more independently. Token “maxing” can gamify usage but doesn’t ensure ROI; measure against business KPIs.
Notable examples
GitLab’s internal “account research” skill that compiles consistent customer briefs from internal/external sources; AI-generated code reviews and auto-remediation for security/pipeline failures; using a knowledge graph (GitLab Orbit) to improve accuracy with less token spend.
Guests
Manu Narayan, CIO at GitLab (GitLab’s first CIO; leads internal-facing tech, internal AI strategy, and data infrastructure). Host: Matt Paige (Talking AI Podcast).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOIntroduction to Productivity Gains
0:00 to 0:17
Learn about the focus on outsized gains in enterprise efficiency.
“We're not, you know, really interested in just like the nominal gains or incremental efficiency gains that somebody can get.”
Understanding GitLab's Role
0:45 to 1:46
Discover GitLab's function and its significance in DevSecOps.
“Because a faster version of a pre-AI workflow is still a pre-AI workflow.”
Manu Narayan's CIO Perspective
1:46 to 2:39
Insights from Manu Narayan on the challenges and opportunities as GitLab's first CIO.
“We're really the place where software is created.”
AI Adoption Challenges
2:39 to 3:54
Explore the disparity in AI adoption across organizations and strategies for improvement.
“Like they've always had the product functions, CTO, engineering, CPO, all those things.”
Hub and Spoke Model for AI
3:54 to 4:51
Manu discusses the hub and spoke model for effective AI integration in organizations.
“Like, I think you can't just do it from top down.”
Cross-Domain Collaboration
6:45 to 7:54
Discussion on how teams are leveraging AI for cross-domain collaboration.
“Like an easy example is a copywriter and a designer, right?”
The Concept of Skills vs. Agents
7:54 to 9:56
Explore the definitions and distinctions between skills and agents in AI.
“Yeah, I think one of the things that we're really focused on is we think about the transformation.”
Building Internal Skill Libraries
9:56 to 14:00
Learn about GitLab's initiative to create an internal skill library for AI.
“know, like everybody thinks skills are a cloud thing, but really it's an AI thing.”
Automating Account Research for B2B SaaS
14:00 to 15:20
Learn how automation improves account research efficiency in B2B SaaS.
“You know, as we think about skills, I think one of the ones I like to reference is really what we've built around account research.”
The Controversy of Token Maxing
15:20 to 16:50
Explore the pros and cons of token maxing in AI spend management.
“you know, research, but also reduce just a ton of manual effort.”
Show all 24 chapters
Measuring AI Adoption Success
16:50 to 19:20
Discover how to evaluate the success of AI adoption in enterprises.
“It's really easy to gamify and there's a direct cost associated at the end, which makes it really difficult as you start to think about that being the means of driving your productivity.”
Optimizing AI Model Selection
19:20 to 23:00
Understand the challenges and strategies for optimizing AI model selection.
“You can really 5x, 10x the productivity of development teams.”
Evolving Human in the Loop Dynamics
23:00 to 28:01
Examine how the role of humans in the AI development loop is changing.
“There's like this model photo that exists.”
Evolving Governance in AI Integration
28:01 to 28:56
Understanding the need for human involvement in AI-driven processes and the importance of governance.
“And now we take that for granted where we clearly have deeply integrated systems that are currently using deterministic based integrations.”
Understanding Feedback Loops in AI
28:57 to 29:40
Exploring the concept of feedback loops and their significance in AI and agent interactions.
“It's one of the biggest things when we're talking to folks and clients is the governance side of it.”
The Role of Autonomous Agents in Development
29:41 to 31:15
How autonomous agents are changing software development and team dynamics.
“It's tough to keep up with everything that's happening, but how we see loops both on our product side, as well as some of our developers are using it is really around a change in how you interact with AI.”
Context and Traceability in AI Operations
31:16 to 33:21
The critical importance of context and traceability in AI-driven workflows and their impact on outcomes.
“You're really looking at how a team of agents is working and operating and you're helping orchestrate them.”
Managing AI-Generated Code and Governance
33:22 to 37:20
Discussing the challenges and strategies in managing AI-generated code and maintaining high standards.
“First, it's from a team I was talking to last night, and then I'll use from a GitLab product perspective.”
The Future of SaaS and Agent Integration
37:21 to 39:45
Analyzing the implications of SaaS proliferation and the interaction between multiple AI agents.
“And I'd be curious to get your take on this too.”
Addressing Shadow AI in Organizations
39:46 to 42:00
Strategies for managing shadow AI and fostering a supportive environment for approved tools.
“I'm not sure if MCP is the be all end all protocol for what we ultimately all need to do.”
Balancing Freedom and Governance in AI
42:00 to 43:36
Learn how to balance individual freedom and governance in AI deployments.
“platform that aligns with our governance strategy.”
Superpowers and First Moves in the AI Era
43:36 to 45:51
Discover essential superpowers and first steps for executives in AI.
“And that was one of the first things I did was really align with my peers on the executive team that we're not looking for incremental gains.”
The Importance of Agility and Speed in AI
45:51 to 46:56
Understand why agility and speed are critical in the AI landscape.
“What doesn't work is the traditional way of RFPs and POCs and all that stuff that like enterprise technology teams have traditionally done.”
Concluding Thoughts with Matt
46:56 to 47:29
Hear Matt's insights on connecting through LinkedIn and GitLab resources.
“Matt, it was great having you on Talking AI.”
Transcript
Automatic transcript. May contain errors.0:00We're not, you know, really interested in just like the nominal gains or incremental efficiency gains that somebody can get. Those are important. We want to capture those. We want to enable our team members to have access to all these great tools. But we really want to see where can we find outsized gains or nonlinear benefits.
0:16Matt Paige:Welcome to the Talking AI Podcast, where we talk AI with both experts in the field and early adopters. I'm your host, Matt Paige, and we're here to demystify AI for you so you can get some value from it. Let's talk some AI. Most enterprises rolling out AI right now are quietly optimizing for the wrong thing. Speed, volume, lines of code shift. But Manu Narayan, CIO at GitLab, argues that efficiency gains alone are about to drive companies straight into a productivity ceiling they can't engineer their way out of. Because a faster version of a pre-AI workflow is still a pre-AI workflow. And the real unlock isn't speeding up what you already do.
0:57Matt Paige:It's rebuilding it from first principles. And in this episode, Manu makes the case for why we need to move beyond incremental AI adoption and what the operating model for enterprise AI actually has to look like. But Manu, welcome to Talking AI. Yeah, thanks so much for having me. I'm happy to be here. I'm excited to have this conversation. And let's just first level set for our audience on what GitLab is and what you do. probably most of our audience has heard about it, but I think it's good just to level set in terms of what you all do. And you have customers like Nvidia, Lockheed, Barclays, these massive companies.
1:33Matt Paige:And GitLab describes itself as an intelligent orchestration platform for DevSecOps. And we may want to hit what that term is for our audience as well. But give us some context, just like we would when we're chatting with AI to set us up. Sure. I think we think about what GitLab is. We're really the place where software is created. So if you think about that dev, sec ops that we talk about, it's really around developers, security, operations, the full SDLC, the full lifecycle. So much focus in AI today is around code production, how you write and generate more code. GitLab's about that. We're also about everything that comes afterwards as well.
2:08And it's really exciting time to be able to provide orchestration and infrastructure for these agentic workloads beyond just coding, but including things like security, operations, CICD, et cetera. My role at GitLab is really everything that's internal facing. So not only how we use our own platform, but how do we help our team members who support customers, build the software, sell the software, provide support to other team members, become more efficient leveraging AI.
2:38Matt Paige:And I think what was super interesting in me doing my research, you're actually GitLab's first CIO. Like they've always had the product functions, CTO, engineering, CPO, all those things. But like you said, you were brought in to kind of lead this enterprise technology, internal AI strategy, data infrastructure. And I think this is on one side, the most undervalued thing in the enterprise right now. and the biggest pain point that every organization is facing. Because I think everybody at this point is leveraging AI. They've adopted AI, but it's almost like it's in these siloed pockets. Like this team's doing amazing work.
3:16Matt Paige:This person's doing the work of a hundred people, but it's not, the context isn't like going across the org. Like, I'm curious, like, how are you approaching this? and we're going to get deeper into this as we go, but like from a top line, how are you thinking about this strategically within GitLab? Yeah, I think it's a question that all of us in these roles are facing, not only by being GitLab's first CIO, but just broadly speaking, CIOs in general, it's how do you take the wins and successes that are happening across the organization, but really expand that out into more meaningful ways. and I like to talk about at times you have this idea of the AI haves and the have-nots right you have people who have embraced the technology understand how it works have incorporated it into their workflows and then you have the people that haven't and that's not by their own fault it's really a mix of their enablement that it's new technology you have to work with in different ways and my job is really around how do we capture that in a way that can expand and scale broadly I think y 'all are just from, I was looking at a recent article where you were talking, kind of taking this hub and spoke model.
4:29Matt Paige:I think it's smart. Like, I think you can't just do it from top down. You can't just do it from bottoms up. You get value from both. I don't know. I think it will be contextually relevant for a lot of folks going through this. Like, how are you thinking about that hub and spoke model and kind of the value you're getting from that to get this adoption throughout the organization? Yeah, I think it's, you said it best, it can't be just tops down. It can't be just bottoms up. I'm a believer of the saying all politics is local. I think the best way to drive meaningful transformation is more localized to the personas and roles that ultimately need transformation.
5:06And that's where this hub and spoke model, and really in some ways it's a hub spoke hub. And I'll talk about what that means in a minute. Okay, cool. The model that ultimately is around having a centralized team that can drive governance, that can drive the technology choices, help with enablement, really more detailed technical builds. But having a embedded person within each of the departments, we call them an AI transformation owner, and in some of our larger ones, there's going to be more than one, that really understand the workflows, the processes, the people at a much more detailed level that can help be that bridge between kind of functional and technical.
5:43Their role is also to then create a center of excellence within their division around champions and people that can ultimately help with those bottoms up ideas. But then that AI transformation owner is really there to help determine what has the best scale, what can really have the biggest impact organizationally, where we want to invest deeper build resources to make something that's scalable.
6:03Matt Paige:Quick break in the pod. I keep hearing the same pattern with companies I talk to. Quad's helping employees move faster, but in many companies, the business itself hasn't changed. the value is still trapped in isolated chats and experiments. And that execution gap is why forward-deployed engineers have become one of AI's most talked about deployment models. They embed with your team instead of advising from the outside. It's also why the FDE model is now central to every client engagement we lead at Hatchworks AI. As an official Anthropic partner, we embed Anthropic-certified FDEs to identify high-value business problems, build and deploy the solution, and put governance and security around it, then transfer the capability back to your team.
6:36Matt Paige:If your cloud rollout is still mostly individual usage, check out how Hatchworks AI FDEs work at hatchworks.com slash claw dash FDE. You can also find it in the show notes. Now back to the show. Yeah. I'm curious your take here too, because I've seen this interesting phenomenon within my teams and whatnot is people used to have their specific domain and they were the expert in that domain, but there's this bleeding that's going on in a good way, I guess I would say, where you can cover different areas in your domain and tertiary domains. Like an easy example is a copywriter and a designer, right?
7:15Matt Paige:And the copywriter can actually design things that takes something further for the designer. And on the flip side, the designer could generate compelling copy. Another example, when we do our strategy engagements, the teams have started to leverage AI for a lot of the stakeholder interviews, like that first round, because you can go much wider than you ever could before. And then you have AI synthesizing that. And then our sales team was like, or no, sorry, our talent team was like, oh, that's interesting. Maybe we could do that too. So there's this interesting cross-pollination. Any thoughts on that or any stories where you've seen something similar in GitLab?
7:54Yeah, I think one of the things that we're really focused on is we think about the transformation. Clearly, there's this big technology portion to it. there's a process portion and then there's this people portion, right? And some of what we're seeing and what we're driving towards is, I'm going to use the term full stack and I don't necessarily mean that from a software developer's point of view, right? But having people operate more in this full stack manner, meaning end-to-end ownership across whether it's a certain process, a certain thing where maybe you used to have four or five people that all did this, a sliver of it, really expanding that scope of role and capability.
8:27And I think AI gives us an opportunity. We use an example from my own team. If we think about internal development for something, a platform like Salesforce or CRMs, it's not uncommon to see a lot of different domain expertise within that. You have a BSA, maybe you have a product owner, you have an admin, a developer, QA, right? So all of a sudden you have six, seven different roles that are touching different parts of this lifecycle. and while those functions are all still incredibly important and critical what we find is that you can actually stretch individuals across more of them and so it can shorten the cycle of getting development done it increases that end-to-end accountability removing some of the internal handoffs that often can slow things down yeah and also gives people an opportunity to break out of the kind of existing roles they've been in and explore other areas that's one aspect of it you hit on something else, which was really interesting, which is how does this then become more cross domain as you start to think about the people team learning from the AI, from the IT group and learning from others.
9:28And I think we see that really coming about a lot as you think about things like if you're leveraging cloud and you're creating skills that help with internal research, the specific things that you're researching may be different, but the approaches that you take can oftentimes be really similar. And so we find that we have a lot of skill sharing, project sharing happening between groups where they can really share that ideation and learn from one another on how they scale out what they're doing.
9:53Matt Paige:Yeah. Okay. Rabbit hole time skills, which, you know, like everybody thinks skills are a cloud thing, but really it's an AI thing. You can do it in codex or any, whatever platform you want. But I've been going super deep in this and we're doing it org wide, but like you start to go down this rabbit hole of like, oh, I could use this skill for this. But then you start to think, oh, well, I could actually have this skill invoke this other skill and you can start nesting and chaining these things together. And then it starts to almost feel like you're architecting this system and it has its own governance in a sense.
10:26Matt Paige:I'm curious, like, how do you think about skills and then maybe follow up? How do you differentiate a skill from an agent? I think it's like an interesting topic I've heard as of late. I think maybe start with that last one first, if you don't mind. I think it's a good question because there aren't definitions for these things really, right? What is an agent and how's that difference from some of the other things that we do, you leveraging it? I tend to personally draw a distinction between what's human invoked versus autonomous. And when I think about true agentic workloads, I'm thinking about things that are maybe triggered by events that run autonomously, polling and monitoring for things versus oftentimes skills are a bit more human and person invoked.
11:09It gets a little blurry if you think about things like co-work and other things that can then execute agents on skills on a schedule. But I think that to me is one of the big differentiators is a skill often is a skill that's enhancing what a human does. An agent's something that while you may have a human in the loop as part of the process, ultimately is running a bit autonomously. As we think about skills internally, I think that's one of the key ways that we actually scale out what we're trying to achieve. If we take that example we talked about where there's the haves and the have-nots of AI usage, people that have figured out how to use AI really well for their job, whether they're using skills or not, they're ultimately creating usually a set of reusable prompts.
11:49Maybe they're using MCP and other things to pull in data and context, even take actions. And the skill helps codify that, which is really important. But moreover, it actually lets us scale that out really easily to other people in similar roles. And so I think that to us is the real power of the skill is that it's a way that you can enable without needing to fully teach around all the fundamentals and then get a consistent way of executing against certain tasks.
12:16Matt Paige:Yeah. And it's think about onboarding a new employee and instead of handing them this like SOP, they're never going to read. Like they can start leveraging these skills real time. It's just so powerful. My favorite one is still I've automated my email with a skill. So it just does it for me and it drafts it up. And I just say, yep, looks good. I have a skill that runs every morning and it's like my daily to do skill. Right. And it'll look back at conversations, emails, my prior to do list. And then just give me that brief of everything I need to know for the day. And it's incredible. Right. These are things that seem on one hand, really simple.
12:49But as you start to stack two, three, five, 10 of these use cases together, it really changes the way you work. Yeah.
12:55Matt Paige:And it's funny. I have one of those two. I call it my like AI daily. It's like a chief of staff almost. And my running joke is one time I ran it and I was traveling and we had drinks the night before the event or whatnot and had a conflict with a training thing we were running in our company. It said drinks win, get somebody to cover the training. I'm like, that's AGI right there. That's the true test. It knew exactly what you needed. Exactly. Especially after the flight and all that. Any other skills that have been interesting, either personal or work related? Yeah, you know, so one of the things we're doing with skills, you know, broadly speaking, I'll talk about kind of a broader program and I'll talk about a few specific ones.
13:35But, you know, as I talk about how skills are the way that we really see our ability to scale out AI usage, you know, we're creating our own internal skill library. We're allowing anybody to kind of write, submit skills to GitLab repo. and then we'll have a review process by which those get promoted then into like the official repo which ultimately then get into um you know clod and then distributed to people by persona and so this is both a great way that we are enabling kind of that ground up adoption but also scaling it out in a really kind of systematic and easy way to manage and so i think like that kind of infrastructure is one of the things that's just really critical as we think about a low touch way to apply a level of governance to, you know, what ultimately is a really impactful process.
14:21You know, as we think about skills, I think one of the ones I like to reference is really what we've built around account research. And so this is something that, you know, if you're a B2B SaaS company, like your sellers do a ton of this, your, you know, customer success managers, AEs, basically every field facing role, whether it's before a call, whether it's, you know, for a prospect, but you end up doing like a ton of research across internal data sources, external sources, maybe like support tickets, just all of that stuff to really get your brief together, you know, and that's the kind of work that is easy to get interrupted, you know, so you always end up losing your flow state if you're doing it manually.
14:58And it's work that's also like really critical. So you walk into those conversations kind of fully briefed. And so we have a automated, you know, not an automated, we have a skill that essentially will go through, you know, all of the internal systems, some external research, research sources, and then create a consistent brief on a customer. And I think that that's one of the things that really drives us like level of consistency around how our field can operationalize like, you know, research, but also reduce just a ton of manual effort.
15:25Matt Paige:Yeah. And spoiler alert, I do the same thing with this podcast. I had to research you and found this actually just published, I think today or yesterday, AI accountability report, which I want to chat about in a little bit. But yeah, it's just sorry for the rabbit hole, but I think it's worth it. And it's top of mind for a lot of folks right now. But I want to shift to this. So the popular term right now, and it's getting a little bit of backlash is token maxing. But I'm curious, what is your take on token maxing? So I see on one side, it's in the sense that you're enabling and giving freedom, go experiment.
15:59Matt Paige:But then you also hear these horror stories of budget being blown in a few months, the Uber CTO. And then there's the Axios article, which I still don't know if this is true, but it was an undisclosed AI consultant or somebody. It's like$500 million in a month. 500 in a month. And they didn't know. I'm like, okay, this, A, that has to be a massive company. And how do you miss that bet coming through? I feel like that's good problems to have, right? When you can miss that over the course of a month. Exactly. Exactly. Totally different type of scale. Yeah. Look, I think token maxing, it's interesting because there's two parts to it.
16:34The idea of gamification to drive adoption, I think can actually be like really beneficial. And on one hand, you could say token maxing is a way to gamify AI usage. I personally don't ascribe to it. We haven't really ascribed to it at GitLab in part because it also encourages not necessarily the right behavior. It's really easy to gamify and there's a direct cost associated at the end, which makes it really difficult as you start to think about that being the means of driving your productivity.
17:01Matt Paige:So you're CFO's best friend, right? Your CFO really likes it. Yeah, exactly. We're joined at the hip on this. I think that the idea of token maxing on one hand is, especially early on in this AI journey, wasn't a bad idea, right? It's our people using the thing. But realistically, especially given the costs involved in usage billing models, we ultimately want to make sure we're also driving ROI. And we want to understand use cases. We understand all of those things. And so as we think about our internal usage, we do try to go back to business KPIs. We try to use those as the measures of what we're driving.
17:33Even as we think about software development, right? We're not thinking just about things like lines of code. We're thinking about innovation velocity. We're thinking about release cadences. We're really thinking about how does delivery to the end customer change, as opposed to one or two of these metrics that may seem interesting on the surface, but actually don't translate necessarily to business value.
17:52Matt Paige:So are there any metrics you are looking at? I mean, obviously token maxing, just looking at usage is an easy one. But are there some internally that you are looking at or how do you measure adoption success or whatever that success metric may be? Yeah, look, I think it's both evolved over time. And I'll talk a bit about that at GitLab. And then it also is really role and function specific. Yeah. And so if we think back even to six months ago, which in the AI era seems like an eon ago, we were looking more to set raw usage stats, right? What are people using? We have five, six main enterprise-wide AI platforms.
18:30What's utilization look like? And all the things you do on traditional platforms, looking at weekly active versus daily active users and all those things. And we still do that. I think it's an important measure. And we certainly do look at tokens and costs more from a cost control perspective than we do from a maximized productivity perspective. And then if I take a step back and I say, what's our focus now today? And we're still early slash mid through this journey, but it's really by role and persona, how are we driving a transformation? And I think that the key is we're not really interested in just the nominal gains or incremental efficiency gains that somebody can get.
19:09Those are important. We want to capture those. We want to enable our team members to have access to all these great tools, but we really want to see where can we find outsized gains or nonlinear benefits. Some examples of that are, as you think about agentic software development, right? You can really 5x, 10x the productivity of development teams. How do we measure that both through the innovation cycle, like the timeline of delivery of new features? How do you look at that in terms of the overall SDLC, not just things like lines of codes or MRs, but also code review timelines, like pipeline failures and automation and all of the things that is security scanning, like all of the things that we can leverage our platform for.
19:48And then in other organizations, in like customer support, we're really looking tied to those business metrics, a significant change in time to first response, time to resolution, the number of turns a ticket takes. All these things that become really role and persona specific are really the measures that we're targeting. But with the goal ultimately of saying, how do we find nonlinear and step function change?
20:09Matt Paige:Yeah. I love that tie to like just whatever business metrics or outcomes are importance of the business. Like it doesn't have to be some new fangled thing. Is it driving the outcomes you want as a business is really critical. And I think it sounds a little quaint, right? But it's actually, it is really, I think that's, it's that simple. Exactly. And that like my mind always goes in these, and I don't know if this has been the case for you, but like now that I have just been so deep into leveraging AI for everything I do, like I always get these ideas of, oh, I could use it this way. It would be interesting to actually have AI.
20:46Matt Paige:You almost kind of give it the goal of, hey, I want to measure my productivity with AI. And could it almost do its own assessment on how you're leveraging AI relative to the model you're using? And there's all kinds of things that are emerging. I think Claude has their advisor strategy where it uses Sonnet most of the time. And if it needs help or it hits a hard problem, it goes to Opus. but I wonder if AI could almost kind of create that that nuanced rubric for us and do some kind of scoring relative to like again I am truly a believer if you have sufficient context you can do almost anything with AI context and tools and whatnot but yeah I don't know any thoughts on that like it's in the advisor strategy are y 'all starting to play around with kind of the optimizing between models in a sense?
21:39Yeah, I think I'll answer that probably two ways. So the first is, short answer is no. And what I'd say with that is, is we think about usage of things like whether it's our own product, do agent platform or cloud code. We really do leave a lot of that into the end user's hands. As we think about agents that we're creating, deploying, that is where we do a fair amount of optimization on model selection. And we have a few different agent platforms that we leverage. and I think that is where we see these repeatable runs, things that do tend to suck in a ton of context where that model choice becomes really impactful.
22:14And we do a fair amount of curation. That's part of this, if you call it a paved path to production, we'll let anyone pretty much create an agent that can run within their context, their sandbox. But the minute they want to share it out to others, they want it to run in an enterprise context, then we'll have a review of the agent. We'll do a level of optimization on it before we publish it. And I think that kind of gets the best of both worlds where we're still managing that flexibility that our team members ultimately have, but putting a level of control in place. Look, I see a future where we will do some model-specific spend caps internally.
22:45I think that's almost unavoidable. On the idea of automated model selection, we've been talking a lot about that internally. At some level, it's a harder problem than it sounds like it should be. But that's something that I think, again, I see as a future iteration for us, but not something we're doing today.
Read the full transcript
23:00Matt Paige:It is funny. There's like this model photo that exists. It's Hey, maybe I should go down to sonnet, but what if I miss out on something using Opus? I like, I never do it. You hit the limit and you're like, okay, let me sit around here for a minute or this morning. I don't know if you got hit, but Claude was just down for a few minutes and it's like, okay. What is like the end of the world? Right? Exactly. Exactly. But you hit on something you hit on GitLab, the agent platform. I'd love to like hear more about, and obviously this is on the product side. I'm assuming you being on the internal side and focusing there, you're probably leveraging GitLab to build GitLab and things like that internally.
23:37Matt Paige:But how do you think about that and preface it with, it's this unique moment where anybody can now build things with AI. And I've built probably over 100 different applications and things. There's probably like three that are actually out there in the market. And I think that's with a lot of people, right? And it's that kind of last mile, but like, talk to me, like you've had this GitLab duo and how you think about agentic orchestration and whatnot across the SDLC. Yeah. I'll talk about it in two ways. I think one, how we leverage it internally, but also why I think it matters more broadly for the industry.
24:16Certainly we see there are a lot more builders out there, right? And that's an incredible thing to see. The barrier when it comes to creating an application is on one hand down incredibly small. But as we think about all the other challenges of how you utilize something, and it's again, things like security, like how and where do you host it and build it? And just like all of those more complex challenges. I think that's how we leverage dual agent platform internally is it's our ability to really give team members that opportunity to build that scale, but still by enforcing the level of governance in control that we need to, both as a public institution, as well as one that has a lot of regulated customers.
24:54And I think that is a distinction that is easy to forget about as we talk more broadly about the advances in AI and AI for coding. There's a lot that happens client side today, whether using Codex or Cloud or even open source models. And you can do so much as sitting on your local computer, right? But I like to think about this distinction between local versus repo side. And when you think about what's happening repo side or what's happening server side, that's ultimately where you can put in assurance and governance and guardrails and the things that make you really comfortable about what's being developed.
25:29And I think that's the balance that we find with dual agent platform is we say develop software in whatever mode and approach you want, but ensure that you have the right level of governance on that repo side. But leveraging AI agents to make that as increasingly low lift as possible. And we think about code reviews as a really common use case. We have AI-generated code reviews. You can do auto-remediation for security vulnerabilities that are found. You can do as a pipeline is running to actually push the code out. If that has a failure, we can use AI for auto-remediation on those pipelines. And so we find we can really compress the after-code part of the software lifecycle really heavily using the Duo Agent platform.
26:10But that's something you can't natively or easily do if you're just running AI locally.
26:16Matt Paige:Yeah. Yeah. It's interesting. There's this nuance to, I've noticed the concept of human in the loop, which I feel like was talked about a lot over the past couple of years. And like, you have to have the human in the loop, but like what AI was capable of doing, the humans physically can't keep up. It'd be in the loop. So it's almost as the bottleneck continues to shift. To your point, we're leveraging AI in areas where we maybe used to have human in the loop, but there's still human in the loop, but it's at different levels of abstraction maybe i don't know any thoughts on that nuance and how you think about human in the loop and then because i feel like the models are getting so good that like you can't really leverage in this kind of check and balance mechanism that you're mentioning yeah i think you kind of hit the nail on the head where the nature of the human in the loop is evolving right and so it's i think if we went back even just a year ago the human in the loop was this hard gate that you had to pass where maybe they were even reviewing every line of code that was AI generated, right?
27:19And that's clearly not where we are today. As you think about agentic software development, you have teams that are creating so much code that there's no way a human could review every line that's being created, right? And so I think that's where increasingly we see people talking now about looping and loops and what does that mean? And it's agents working with other agents that have been an oversight agent, right? But there's still ultimately a person there that's overseeing that orchestration, overseeing the outputs, applying their own taste and judgment to what's being developed ultimately.
27:51And there will be this increasing abstraction of where the person gets involved. And I think that's just going to be the nature of the pace of development, the amount of code being generated. But I think that's also where it's really important that if you're in an organization, you understand what are those key points where you want to have a person involved and maybe you go look the code reviews we just want to read an ai output of code reviews but that's fine but actually the security scans we're always going to want a person to review right i think that's very much an organizational decision that it's going to become part of that evolving view around risk factors versus productivity but it'll take us a bit to catch up there it took us with traditional integrations and automations as a similar view 15 years ago where it's oh you can't automate things directly and you need to have a human reviewing every transaction, approving it.
28:38And now we take that for granted where we clearly have deeply integrated systems that are currently using deterministic based integrations. The next iteration of that will be how do we drive assurance and governance across non-deterministic ones using AI. And I think you'll have governance type platforms like GitLab for software development that help drive that.
28:57Matt Paige:Yeah. It's one of the biggest things when we're talking to folks and clients is the governance side of it. It's just becoming the hot topic right now. But like the one book I'm like recommending most to people is called thinking in systems. And I think your ability to understand how systems work is just super important because it's understanding at that level of abstraction or first principles in terms of systems and feedback loops. You mentioned loops earlier and self-reinforcing and balancing loops. And the example everybody uses is like the thermostat where it's always keeping things back in check and whatnot.
29:33Matt Paige:But you mentioned the term loops and this is like the new hot thing with agents and whatnot and the concept of a loop is not a new concept but it is the thing that a lot of people are talking about can you go a bit deeper in terms of maybe what loops are and how to think about those from an ai and agentic standpoint yeah i think look i'll be honest like i personally am early on loop still i think it's something that as the just AI landscape evolves, right? It's tough to keep up with everything that's happening, but how we see loops both on our product side, as well as some of our developers are using it is really around a change in how you interact with AI.
30:17And I think this is part of that evolution we've seen where again, maybe a year and a half ago, it was just like chat prompts and code completion. And then you have a gentic coding where you're like, no, you're giving a bit more of a complete prompt and getting full code blocks back. But that evolution now is really to have a bit of a more slightly autonomous way of developing your software, but by having a discrete set of agents that are working on discrete sets of problems that reinforce one another. Right. And then the person is there that can still inspect outputs that can give corrective actions that can provide additional inputs into that.
30:53But ultimately, you have a set of individual agents that are working in their own loops. They're taking information from the other agents and ultimately self-correcting. And this is so interesting because in many ways, it's a different way of thinking about how you achieve your job now. It's not just about me, the person sitting and writing code and ultimately pushing an application. Or if I'm a sales rep, it's not about me looking at a single account, doing the research and saying outbound email, right? You're really looking at how a team of agents is working and operating and you're helping orchestrate them.
31:27And so it's a bit of the role of almost like a manager of agents as opposed to the doer of a task. And I think that's a bit of the evolution that we see really happening in the workforce.
31:35Matt Paige:Yeah, no, it's super interesting. And I think too, it's even when you're leveraging, whether you're working in chat, GBT and kind of the reasoning side, cloud code, code code, you can see a lot of the times that reasoning with itself, it's like, oh, I can't do this. Let me go do that. Oh, I researched that. That's super interesting. So you can almost witness this reinforcing loop in a sense where it's gathering context, doing the thing before it gives you the. Yeah. It'll be like, oh no, I can't use that tool. Let me try a different tool. Let me try this thing. Yeah. It's funny kind of watching there.
32:06Matt Paige:It's like a train of thought, which is super interesting. I mentioned earlier the AI accountability reports that just got published today or yesterday. And, you know, by the time this goes live, it will already be out there. But it was like feverishly giving that claw to go research it. But you surveyed 1500 DevSecOps professionals. And I don't know if you've actually seen the output yet because it is so current. but it argued that context and traceability are the new differentiators and that speed is basically getting commoditized. How do you think about that concept of context and traceability and why it is so important right now?
32:47Yeah, you and I spoke about it a bit earlier as well, right? If you have enough of the right context, AI can do a bit of anything. And I think that's been the case for a while and it's certainly still true today, but it's almost more true because as you think about the capabilities of the different frontier LLMs has increased and improved so dramatically, the ability to access context itself has not. And so I think that as you look at how do you bring the right level of context to a task, whether it's through automated means, a human introducing that context, it's increasingly important. And I'll use an example.
33:22First, it's from a team I was talking to last night, and then I'll use from a GitLab product perspective. But if you take a customer support workload, right? So we have a support engineer and GitLab is a fairly technical product. We have very technical support engineering team members. But on one hand, people say AI is definitely like customer support to solve a problem, right? But the problem is context still really matters. And how do you actually bring to bear all of the experience that an individual has when it comes to different deployment types, different operating systems, different versions of things, the problems that they've seen in the past.
33:59Very rarely is all of that documented because that's part of what a human brings to bear. And as we think about AI and customer support, for example, it's where there's rich context, we're going to leverage AI. But then there's areas where there isn't rich context that's documented and we're going to leverage the power of the person. As you think about in a software development workflow, the same thing's actually really true. So on one hand, you can have a code base, right? and the AI is great at working through a code base. But what about the failures when you tried to push that code? What about the last security scan?
34:30What about the last comments from your manager on the code review? And all of those things stitched together actually create this more relevant and rich context that can ultimately make your agentic operations a lot better. And we see as people are leveraging, for example, our own knowledge graph, GitLab Orbit, that you can consume less tokens, get more accurate output, and oftentimes quicker output because of the ability to have this really rich knowledge graph of context, as opposed to piecemealing together pieces of that.
34:59Matt Paige:Yeah, it's interesting. On my own personal side, I've been playing around with Andres Carpathi's LLM wiki that he created. And I don't know if you qualify that as a knowledge graph or it's not really RAG either, but it's just interesting. I feel like it's close enough though, right on a personal basis. Yeah, conceptually, right? But it's really cool how it does make these connections between the things based on whatever whatever I'm doing and whatnot. The other, there's two, two other stats on the report. I'm just curious to get your take on. So there's one that the headline is AI coding is paying off and 60 % of DevSecOps professionals, it's easy to say DevSecOps, say the ROI from AI coding is exceeding expectations, right?
35:42Matt Paige:And then right after that, it was interesting. It said, but 73 % of DevSecOps professionals are concerned about the long-term maintainability of AI generating the code. So on one side, they're like, oh, this is exceeding expectations, but we're also concerned about maintaining it. Do you think the concern is maintaining it from a quality standpoint or just maintaining it from, I don't know what the heck this thing is doing in a sense? Yeah, I think it speaks a little bit to the fear of just what's not known, right? And so it's a bit of, there's so much code being generated. our velocities increased and the traditional ways that we've managed that can't hold up just again like what we were speaking about earlier and so i think a lot of that is just fear of hey like we actually don't necessarily know what will come next and afterwards but i think that's a lot of why the governance side is really critical how can you enforce organization coding standards how can you ensure that code is getting reviewed and scanned and all those things because all that ultimately really helps drive down that fear of the unknown in the future.
36:50And it also helps speed up everything that comes after the development of code. One of the other things that we see increasingly is that while coding is a lot faster, that the bottlenecks actually moved. And I think in the report, it talks about how 85 % of people say that AI has moved the bottleneck from writing code to now reviewing and validating, right? And so I think like all of those things go hand in hand, that if you don't have a good strategy to manage that influx of code after it's written, that's a bit of where that fear of what happens next comes from.
37:22Matt Paige:Yeah, that's interesting. And I'd be curious to get your take on this too. I was thinking through this the other day, and this may not apply as much to GitLab, but there's that whole narrative around the SaaS apocalypse. And part of me is it's just completely overblown and there will be incumbents that don't make it through and new startups disrupt them, just a tale as old as time. But it's interesting. It's every tool and platform has like their own agents. But then from a user perspective, it's where I really want to use 30 different agents. And it's like this bring your own agent concept where, hey, I just want to like connect to your thing and let my agent or quad go do its work with my context for my other stuff.
38:03Matt Paige:But then I started thinking through it. But there is value in whatever tool or SaaS product you're using and it having an agent, but its core function isn't necessarily interacting with the user, but the user's agents. So we can get the most value out of the platform. I don't know, like, just curious, thinking on that, maybe from a broader landscape and agents and all the things going on. Yeah, look, I for one also do believe that the SaaSpocalypse is probably overstated. The nature of SaaS and how we use it is going to shift and change. But I think what doesn't is the need for key systems of record, the need for systems that apply governance and compliance and SOX controls and just all of those things that come with it.
38:45And look, like even from embarking on some of our own internal journeys, it's like really easy to get to that proof of concept that's 80%, 90 % of the way there. It has bells and whistles and features that people love. But that remaining 20%, as you start to layer in like role-based access control, as you start to think about things like versioning, as you start to think about how do you maintain immutable versus non-immutable records, like the things that are actually like really deep problems, those end up being this really long tail on internal development then. I don't think that AI-driven software development is going to fundamentally shift and change that, especially when we think about the types of workflows and workloads that run on top of some of our key SaaS offerings.
39:28I think your note around the agent sprawl and proliferation is super real. And every agent also then wants context to every other system of record and application, right? So you start to think about all of the kind of challenges around data sovereignty, data governance. It's a very real challenging problem. For us internally, our strategy has been to focus on a few, a handful of a few platforms where we really build out agents, where we allow our data to reside, but then leverage things like native MCP connectors or custom built MCP connectors to our SaaS applications so we can bring in that rich context.
40:04I think we'll see that evolve. I'm not sure if MCP is the be all end all protocol for what we ultimately all need to do. You're coming mad around, hey, are we going to have like agents talking to agents? And that actually is like really interesting. I think something that we'll probably see a bit more of like agent-to-agent communication protocols emerging. But I don't think that MCP itself is going to be where we all land in a few years.
40:25Matt Paige:Yeah, no, that's a good point. I think you hit the nail on the head. It's cool that you can go vibe code your CRM, but by the way, you have to maintain it, govern it, add features to it. And is that actually differentiating to what you're doing as a business or could you spend your time better elsewhere? And it's just, it's trade-offs. back to like first principles in a sense, right? But I'd be remiss if I didn't ask about shadow AI to a CIO, like shadow IT is like this concept that a lot of people know and are familiar with and maybe are culprits of, but how do you think about this concept of shadow AI and people using their own AI that maybe is not sanctioned or approved?
41:06It's just like with shadow IT, it's a problem that exists and it happens. you have both awareness on it and you're constantly combating it. I think a few things that maybe jump to mind, how we tackle shadow AI isn't really any different than how we've tackled shadow IT in the past, right? And it's a mix of education, policy, a level of controls that exist with a network and endpoint layer, as well as then, and I think the most critical, is having a really happy path to production for people, right? The official means of getting something approved, of being able to do a POC, of being able to deploy a vibe-coded app, those can't be more painful than going on your own.
41:48And so a lot of it's this deep interaction we have with our team member base to ensure that we're joined with them, we're in the journey with them, and we're here to support them. And if they have needs, ideas, maybe we'll try to steer it towards a different approach or platform that aligns with our governance strategy. But ultimately, to really have that happy path to production. I think we've struck a good balance internally around giving a fair amount of freedom in those individual sandboxes I talked about earlier, but then having some governance and control as we think about broader access to data and enterprise-wide deployments.
42:22And that's helped stem that. But look, I would say the biggest challenge is probably the Vibe-coded apps and how we manage that. But luckily, we're able to do so on our platform and drive a fair amount of governance through that.
42:35Matt Paige:Yeah, no, I think you hit it. It can't be more painful than doing it on your own. It's like the perfect barometer. Okay. Let's do a bit of a lightning round. I'm going to ask a few questions to wrap us up, but okay. So what superpowers do you think are most important for individuals to have right now in this new era?
42:56Matt Paige:Gosh. Or quality superpowers. Yeah. Look, I think intellectual curiosity has always been something I've said, and I'll say it even more with AI, your ability to access information to become a pseudo expert on things is unparalleled to any time in history before. And so if you have curiosity and a little bit of intellectual horsepower, you can pretty much do anything now. Yeah. Okay. So for the senior listening who suspects they're stuck optimizing old workflows instead of rebuilding them, thinking from first principles, what's the first move that they should make. If somebody's early on in this journey, what do you feel is the first move that they should do?
43:35I think it's going to sound a little trite, but it's executive team alignment around the scope of the change you want to make. And that was one of the first things I did was really align with my peers on the executive team that we're not looking for incremental gains. We're looking for a wholesale transformation. And that's ended up being a really tight partnership with our chief people officer in his organization as we think about things like the evolving nature of roles and AI literacy and enablement and all those things. But like that top level alignment on what are we even trying to do and driving that scope of change, I think is the most critical.
44:11Matt Paige:What's one AI capability you wish vendors would stop overselling? Or what do you think is overhyped right now? Yeah, look, I still think a lot of AI vendors are simply selling essential, essentially wrappers on a model. And so it's like, we're going to give access to the data in this SaaS app to some frontier model. And they're trying to upcharge you a lot for that. I think there's nominal value in that. We really have moved beyond just data-based type use cases with AI. And we really need to have true Agenta capabilities to get work done. What's the single best dollar of AI spend you made in this past year?
44:48I normally would say GitLab, but I don't have to pay for GitLab. I think one of the ones that's given us the best bang for a buck is a platform called Glean. It's essentially an internal enterprise search platform. And I think it both is an agent platform for us, but also knowledge platform. And Pretty University is one of the ones we get the highest pieces of feedback around. Yeah, we're actually partners of Glean.
45:10Matt Paige:It's that whole intelligence layer concept is just very top of mind. Yeah, it's kind of like you're talking about Carpathy's Knowledge LLM. This is the enterprise Knowledge LLM, right? Exactly, exactly. All right, last one for you. The advice, what advice would you give to your pre-AI self or maybe before you joined GitLab? What would you have told your younger self then that you know now? Yeah, I feel like the AI era is like living in dog years, right? But I think, and I've done an okay job with this, but I think I just remind myself, we need to be nimble. We need to be agile. We need to move quickly.
45:41And it's okay to pivot. And if I think about the nine, 10 months I've been at GitLab, we've probably had three different iterations of our AI program. And I think that's perfectly okay. What doesn't work is the traditional way of RFPs and POCs and all that stuff that like enterprise technology teams have traditionally done. We really need to have a more agile approach and be okay that you're going to make a call and maybe next year it's not going to be the right call anymore.
46:07Matt Paige:Yeah, it is interesting. The cost of pivoting, I feel like has gone down a lot, right? Because you can do that more. And I struggle with this at times too. I'm like, oh, we can't make that pivot again or change this, but it is easier to do it. So there's that balance between you're constantly optimizing toward whatever metric you want and then creating confusion. But there is value in it. I do agree with you there. And I think it's like in this current time period, speed is probably the more important metric than some of the traditional ones we've optimized for. And so I think when we get bogged down and again, traditional ways of thinking about problem solving, that ultimately hurts us more than licking your wounds if you've made a wrong call, but actually moving more quickly.
46:55Totally.
46:56Matt Paige:Matt, it was great having you on Talking AI. I really enjoyed the conversation. Where can folks find you, learn more about GitLab? Yeah. First off, Matt, thanks for having me. It's been a great conversation. I'd say I'm like pretty active on LinkedIn, do a lot of posts and invite people to connect with me. happy to always do coffee chats and connect. And then our GitLab blog is great to both learn about agentic orchestration and how we see the future of software developments. And really would love for people to check that out as well. Yeah, there definitely is some good stuff on there. All right, Manu, great having you on Talking AI.
47:28Matt Paige:Yeah, thanks so much, Matt. Thanks for listening to the Talking AI Podcast. If you enjoyed the show, give us a follow or subscribe on your favorite podcast platform. And don't forget to leave us a review. We love those. For more info on Talking AI, visit TalkingAiPodcast.com. Quick break in the pod. If you're listening to this podcast, chances are you've been thinking about how to actually use AI inside your business. And that's exactly why we built the AI Opportunity Finder. It's a free tool that helps you uncover high impact, tailored AI use cases based on your business, your goals, your pain points, and your industry.
48:04Matt Paige:No fluff, no generic use cases, just real ideas that fit your business and the rank by ROI potential. It takes about three minutes to run, and it's like having your own personal AI strategist for free. If you want to try it for free, check out the link in the show notes or go to hatchworks.com backslash AI dash opportunity dash finder.
From the publisher
Most enterprises rolling out AI are quietly optimizing for the wrong thing: speed, volume, lines of code shipped. Manu Narayan, CIO of GitLab, argues that efficiency gains alone are about to drive companies straight into a productivity ceiling they can't engineer their way out of. The reason is simple and uncomfortable—a faster version of a pre-AI workflow is still a pre-AI workflow. The real unlock isn't speeding up what you already do; it's rebuilding it from first principles.
In this episode of Talking AI, Matt Paige sits down with Manu Narayan, GitLab's first-ever CIO, who owns the company's internal AI strategy, enterprise technology, and data infrastructure—in effect, putting GitLab to work inside GitLab. Manu makes the case for moving beyond incremental AI adoption toward a genuine operating model for enterprise AI.
The conversation covers GitLab's hub-and-spoke operating model and its embedded "AI transformation owners," why the team measures adoption against business KPIs instead of token counts, how "human in the loop" is evolving into an orchestration role, and why context and traceability—not raw speed—are the new differentiators in software development.
In this episode, you'll hear about:
- Why efficiency gains alone lead straight into a productivity ceiling
- The gap between AI "haves and have-nots" and how to close it
- GitLab's hub-and-spoke (really hub-spoke-hub) operating model
- What an "AI transformation owner" does inside each division
- "Full stack" people: stretching roles end-to-end across a life cycle
- The difference between a skill and an agent—and why it matters
- Building an internal skill library with governance built in
- Why token maxing is the wrong scoreboard, and what to measure instead
- How human-in-the-loop shifts to a higher level of abstraction
- What "loops" mean and the move to being a manager of agents
- Why context and traceability beat commoditized speed
- Local vs. repo-side development and where guardrails belong
- Handling shadow AI with a genuine "happy path to production"
- The first move for a CIO stuck optimizing the old workflow
Key Moments
- 00:03:11 — The AI "haves and have-nots" inside every enterprise
- 00:04:30 — The hub-and-spoke operating model and "AI transformation owners"
- 00:07:00 — "Full stack" people: stretching roles across the whole life cycle
- 00:09:06 — Skills vs. agents — human-invoked versus autonomous
- 00:12:00 — The daily to-do skill that briefs Manu every morning
- 00:12:58 — Building an internal skill library with a review-and-promote pipeline
- 00:16:13 — Why GitLab doesn't ascribe to "token maxing"
- 00:18:02 — Measuring adoption by role — beyond lines of code and MRs
- 00:24:30 — Local vs. repo side: where governance and guardrails actually live
- 00:27:39 — How "human in the loop" is evolving as agents outpace review
- 00:30:49 — What "loops" really are, and the manager-of-agents shift
- 00:33:52 — Why context and traceability are the new differentiators
- 00:37:29 — The maintainability fear and the bottleneck that moved to review
- 00:39:55 — SaaSpocalypse, agent sprawl, and the limits of MCP
- 00:42:51 — Shadow AI and the "happy path to production"
- 00:45:29 — The first move Monday morning: executive alignment on scope
- 00:47:33 — Advice to his pre-AI self: stay nimble, it's okay to pivot
Key Links
Mentioned in this episode:
AI Opportunity Finder
Feeling overwhelmed by all the AI noise out there? The AI Opportunity Finder from HatchWorks cuts through the hype and gives you a clear starting point. In less than 5 minutes, you’ll get tailored, high-impact AI use cases specific to your business—scored by ROI so you know exactly where to start. Whether you're looking to cut costs, automate tasks, or grow faster, this free tool gives you a personalized roadmap built for action. 👉 Try it now at https://hatchworks.com/ai-opportunity-finder/
