Guardrails Are Just Suggestions: Securing AI Agents with Okta’s Kevin Akermanis

The business wants AI now. The people who have to secure it are being told to move faster while their budgets shrink. Kevin Akermanis, Solutions Architect at Okta and a 15-year Salesforce veteran, sits down with James MacDonald to unpack what really happens when enterprises rush AI into production: security funding flatlining, breaches becoming the cost of doing business, and a collapsed architecture that pushes security down to the data layer.

They dig into why AI agents are a new class of non-human identity that can roam anywhere, why guardrails are only suggestions for something non-deterministic, and the scoped, time-limited, valet-key approach that actually contains the risk.

They also tackle the harder people problem: if juniors get automated out, who backfills the seniors, and why knowing what good looks like still beats anything you can vibe-code. Practical, sceptical, no hype.

Building Tech Teams is produced by DayOne.

Listen to the episode

Transcript

Auto-transcribed with AI.

Kevin [0:00]: The business says we need to AI and we need to do it now. Your technology teams are kind of going, okay, but how? Sometimes it’s good, sometimes it’s bad that I can work on multiple things at once, which I guess depends on the state of my spicy brain.

James [0:16]: It’s going to be a very real challenge for a lot of people. I know I’ve faced that myself. So many ideas, I can achieve so much more now, but where am I putting my time?

Kevin [0:23]: Where am I putting my time?

James [0:24]: Which then I’ve tried to use AI to question me on that as well. So it’s an ongoing work in progress.

Kevin [0:29]: Okta as a company, look, we’re a digital identity security company, we actually found that the funding for security teams has either flatlined or starts to decrease.

James [0:39]: Wow.

Kevin [0:39]: Which is really scary. You shouldn’t be feeding a lot of your corporate information, a lot of your customer information into the public LLMs at all. It’s just not, just not a good idea.

James [0:51]: Welcome to another episode of Building Tech Teams, Building Tech Teams in the Age of AI. And on today’s episode, we have Kevin Akkermanis. He’s an architect at Okta. Previously to that, also spent 15 years in Salesforce, so really understands enterprise-level technology, what’s happening with enterprise-level clients, and how are they using different technologies. And I think it’d be really good to get his perspective on not only what he’s seen working inside an enterprise-level technology company in Australia, but also what are the clients doing that he’s working with, how are they using technology, how are the teams changing, how is AI influencing everything. So welcome, Kevin.

Kevin [1:28]: Thanks, James. Happy to be here.

James [1:30]: Current role, Okta. Give us a little bit of an understanding about what are you doing day in, day out? What does a week look like for you in your current role?

Kevin [1:38]: Yeah, look, it, every week is a bit different, right? But I guess holistically, I look after a lot of our customers across the Asia Pacific region from a pre-sales perspective. So I don’t maybe own any accounts directly, but I’ll work across all of our account teams just to understand holistically what’s happening across our customer base., but also within the industry and then also tie that into what’s happening globally, both from an Okta perspective, but also from an industry perspective as well.

James [2:09]: Those of our audience that don’t know Okta, give us a little bit of an understanding of what is Okta? What’s your point of difference there? I know you’re working specifically with Auth0.

Kevin [2:18]: Auth0 is a product line I work with, but Okta as a company, look, we’re a digital identity security company. A lot of people probably use us and don’t really know. A lot of the times if you want to minimize what Auth0 does, it’s that login box. So behind that, that’s the foundation of your identity. That’s the foundation of security. At a wider scale, Okta, for people who work for larger companies, you probably use this every day when you just log into something as opposed to logging into all your things individually with different passwords, which we all know we use the same password. This is much more for single sign-on at a workplace organizational level as well.

James [2:53]: Mate, let’s dive straight into the AI part. Obviously with AI, there’s a lot of conversation at the moment about AI usage, individuals using AI, you know, to varying degrees, but higher and higher at the moment. Companies using it at lesser degrees, especially at enterprise level, because there are some challenges around that. I think the biggest challenge that I’m seeing, that I’m seeing in having conversations with the market, is that security part. How do companies protect IP? How do companies protect individuals within their organization going in sharing their company IP with an Anthropic, with an OpenAI. How do you seeing your space changing? I imagine your company only becomes more and more valuable, more and more important to companies going forward.

Kevin [3:37]: Yeah, well, I think everybody wants to get into AI, right? Oh, there’s a huge business push to sort of do it, right? Like, and that’s where I think that unbalance comes between We need AI because it’s a competitive differentiator. If we don’t do it, then our competitors will do it and outpace us and on and on and on. But then there’s also that security and trust perspective saying, well, we know we need it to have information to be able for it to be useful, but where does that go and what can we do with that? And I think there’s that real push between the two. So I don’t know if anybody has really properly, you know, done it right because everything continually changes. Right? It’s always and always changing. But I think where a lot of companies are starting with is, especially with larger companies, a lot of you will use Microsoft or you’ll use Google. So you’ll use kind of that workplace thing that’s already there because it’s a walled garden, right? It has access to your documents, has access to your emails. And there’s that, at least the agreement with Microsoft or Google, whoever, that it sort of stays inside there. So I think that’s where I see a lot of companies, at least starting. Is it the greatest experience? No, because at that enterprise level or at that company level, your Copilot or Gemini inside there isn’t quite the same as your Frontier models, right? They’re a little bit more stripped back. The companies are, they need to be a lot more traceable. They need to understand what it’s being trained with. So they’re very much, I find, a very stripped back version of it. So that then creates a strange, again, tension again, where how come this is so awesome for my home life, but then I come to work and it really sucks, right? And that’s where you potentially have that leak now of people going, well, I use Claude at home, so I can access it at work. I’ll just use it there as well. And I think that becomes a real danger point for sure, because you shouldn’t be feeding a lot of your corporate information, a lot of your customer information into the public LLMs at all. It’s just not. Just not a good idea.

James [5:39]: Yeah, I think we are going to see a point within the next X months, years potentially, of a bunch of company IP being publicly available because it’s been fed into, you know, yeah, these big models. And there was already being use cases that have come out and, and that’s happened. But I think there’ll be some bigger ramifications on the, on the back, backside of this. Obviously there’s data privacy issues. Yes, companies have legal liability around the protection of data and some of this data, whether it not even be at a company level, but individuals within their company sharing data.

Kevin [6:13]: Yes.

James [6:13]: I think we’re going to see some big issues with this coming forward.

Kevin [6:16]: Definitely. I, I, I sometimes wonder how much of it will ultimately be really visible out on the internet. ‘Cause obviously when you feed it to the LLM, it doesn’t necessarily store it potentially in a readable format or something else like that, but you’re still training the model. Yes, you don’t really know how it’s going to present that later on. So yeah, it definitely does present a risk that is just, I think, really unknown in a way, right?

James [6:41]: Yeah.

Kevin [6:42]: Exactly how is it going to show up? I don’t know, but it’s out there, right? Yep. So yeah.

James [6:46]: Yeah, and then you’ve got to worry about it, obviously, the big models themselves have individuals working for those companies and then the security ramifications they have internally and what a bad seed or two might be able to do with some of that information.

Kevin [6:59]: That’s right. Yeah, yeah, that’s right.

James [7:01]: So what are you seeing at an enterprise level at the moment? Where are the biggest challenges that you’re seeing in either the, this, the shape of team sizes, how teams are being affected by AI? From a security lens, how’s this all playing out? Are we seeing companies have a greater emphasis on hiring security professionals? Uh, are we not at that stage yet?

Kevin [7:22]: Starting at your last question, The reason I kind of grinned there was, funnily enough, at a customer security council we ran a little while ago, we actually found that the funding for security and the security teams has either flatlined or started to decrease.

James [7:38]: Wow.

Kevin [7:39]: Which is really scary and ironic in a way, but I think it kind of shows that that’s because all the funds are being redirected into AI projects. Money’s just coming from anywhere and everywhere to fund anything that has the word AI in front of it. So when there isn’t that understanding of how security and identity is potentially the foundation of that, and we can talk about why I have that opinion later on, but if there’s not that real understanding, then you can see why funding is getting pulled from it.

James [8:09]: I agree. And sometimes it’s just the loudest thing.

Kevin [8:12]: Shiniest thing that kind of goes, right? The business says we need to AI, right? And there’s that, like I talked about that contention before with the business says we need to AI, and we need to do it now. And, you know, your technology teams are kind of going, okay, but how? How can we do it safely? And you want it now. And, and again, with so many things changing, it, it just becomes a huge, a huge risk.

James [8:36]: And with a lot of the media out there as well, everything’s about moving so quickly, moving fast, taking advantage of this, not missing the boat.

Kevin [8:43]: Yeah.

James [8:44]: And then technology teams and technology professionals I’ve spoken to, it’s a real frustration, is they’re being seen as holding the company back. You’re putting limiters on the company. You’re not moving fast.

Kevin [8:54]: You’re not moving fast enough. But when something goes wrong, when there’s a leak, when there’s a breach, it is all your fault.

James [8:59]: Correct. So I feel like there’s the— it’s a really challenging situation at the moment because there is a very real need for speed at the moment.

Kevin [9:06]: Yes.

James [9:07]: But there’s an infrastructure, a data, and a security play, the way I sort of look at it. Yeah. And without those three set up correctly, throwing AI Essentially it is another tool at the end of the day. We’ve had plenty of good tools come before. It is maybe the most powerful tool that we’ve experienced, definitely in my lifetime, from the internet probably. That’s like, that’s our next big play that’s going to fundamentally change businesses, change the way we operate. But without that underlying infrastructure, the data in the right accessible way, and then also the security lens, we can’t, we’re just throwing another tool at a problem.

Kevin [9:43]: Yeah, and look, it’s a novel problem and it’s really interesting, it’s very engaging. So I can kind of see why, and you can get something that feels like a result, a positive result, really quick and on volume. So I think there’s the novelty aspect and then the, well, in a way, the world of social media of how we have now want immediate gratification. Now it feeds that as well, right? So I can kind of see how it’s this self-perpetuating engine to kind of get that, quick results now, fast, and at all costs, right? But no, you’re right. I think without that underlying level of security or thought right there, and I think what it’s really come down to is when you kind of think of the way that software architectures were before, right? You had the traditional three-tier, right? You had your experience layer, you had your business layer, and you had your data layer, right? And you could layer it in that way where there’s protection between each of them, right? And then it was also deterministic of how things flowed up and down and through across those levels. And you could put the right protections between each of those. In many ways that’s all been collapsed, right? Where now your experience level and your logic layer, which is now essentially your, your foundation models and those LLMs, it’s been collapsed into one. So you’ve now lost that two layers of security you could put inside there and filtering, and it now forces a lot of that security to be down at the data layer, which it hasn’t really existed at before at that level, at that level of granularity as well. I think that’s the thing here is there’s always stats. There’s been more data generated in the last year than the last 10 years altogether. There’s all these stats that kind of come out. And to be able to have security at that data level, at that granularity, at the rate of change that it kind of changes as well, makes it a really hard problem to solve.

James [11:27]: I agree.

Kevin [11:27]: Yeah.

James [11:28]: Come back to the Security Council meeting that you went to and the cost of the funding coming down. Do you think it will trend back towards a, okay, we’re sort of getting a better understanding, we are now going to have to invest more into security?

Kevin [11:43]: Well, so the other thing that came out of that that was a little bit shocking as well was breaches are becoming very common, right? And now in some realms, it’s the cost of doing business, which is really scary as well. It’s the, well, we’re not gonna fund for more of it, we’ll just put more inside the kitty so that when we get and something goes wrong, we can pay the fine, which is again not really the right way that you want things to be going. But in a way, like, with breaches being so plentiful, there is almost a certain level of apathy out there for it.

James [12:17]: And it’s becoming more and more difficult to be secure. I think if you have a look at everything that’s going on at the moment, you know, you have a look at a really small level, you have a look at OpenClaw, and you, you have a look at what one individual can do, you put that, that sort of technology in the hand of people with bad intentions, and you’ve got, you’ve got, you know, hitting the different pain points of the different, you know, data points, different APIs, like a thousand, thousand millions, like you just more and more attacks.

Kevin [12:46]: Yeah.

James [12:46]: And you’re having a look at people building technology, building software who don’t have the same level of depth of experience that something that has happened in the past. And yet you’ve got a two-sided problem.

Kevin [12:58]: Yeah, that’s right. That’s right. Well, and, and you’re just talking about there about looking at existing attack vectors.

James [13:03]: Yeah.

Kevin [13:03]: Right. You haven’t, we haven’t even touched about the completely new attack surfaces that Agentic interfaces or whatever that experience is now opens up as well completely.

James [13:13]: So it does seem like it, it, it is a, now it’s becoming more acceptable for breaches just because there’s an understanding of it’s happening more frequently and that, yeah. Threats are becoming smarter. There’s more people that can do a lot more with a lot less when you have the right technologies. That as much as it can make people more efficient, companies more effective, and that can also on a bad side, like the new technologies out there put in the wrong hands can actually make them more powerful as well, right?

Kevin [13:42]: That’s right. Well, that’s the whole thing even just about Claude, or sorry, not Claude, but Anthropic pulling back Mythos, right? And their Project Glasswing of how it was so effective at unpacking vulnerabilities in every single operating system, including OpenBSD, which is built on security. And these things are vulnerabilities that were introduced 27 years ago that nobody’s really been able to find. And it does it really, really efficiently. So that’s sort of looking at attacks via existing vulnerabilities and existing surfaces. I think something we haven’t even unpacked is having agentic layers on top or either MCP servers or whatever that is sort of on top, these are whole new attack surfaces that we haven’t even had to think about yet. Something simplistic like, I think it was McDonald’s went and introduced a bot to do their job applications. It makes sense because they get millions and millions of applications every week around the globe. Through prompt engineering, somebody was able to exfiltrate everybody’s, all the applicants’ information through prompt engineering. So again, there’s an attack vector that this new technology has brought in that nobody’s even sort of thought about before.

James [14:58]: How do you see that changing, evolving in the companies you’re working with or in general? And then as a secondary, how’s it gonna affect the space that you play in?

Kevin [15:08]: Well, I think companies are now kind of realizing that they need to potentially slow down with bringing anything AI to market and into production, right? I think there’s that, again, the business drive to, we have to AI, and they hold internal hackathons, and hackathons are one thing, right? They’re great sort of things that you’ve put together in a couple of days, but should that be pushed into production? No. It was great for that one use case that you had, But then that’s hard because the business says, “Good, that looks great. I want that one.” And now you as a technology team saying, “Well, hold on for a sec.” And we’d already talked about earlier where you’re seen as that person who’s pumping the brakes and you don’t want to be seen as that blocker, right? So I can understand that push and pull that you have to sort of balance as a technology team. So I think as, I don’t know, I’m not too sure whether it’s gonna be taken more seriously ’cause that one part of, People becoming apathetic to breaches is one thing, which isn’t great, but then there’s whole new ways that are being breached and other attacks. Where are they going to balance out? I think it’s really hard to understand. But I think what I’m seeing, at least as I’m talking to customers more, is as people get more educated, they’re understanding a little bit more about, okay, well, we know it needs data. We shouldn’t just feed it everything., right? I think there’s that general growing understanding of we need to make sure that the agent can only access what it needs to do in the scope of time of the person it is talking to at that point in time, right? So I think there’s more understanding of saying we do need to scope things a lot tighter for a lot shorter amount of time.

James [16:48]: Yeah, the right guardrails in place, the right environment. Do you see that being the role of a security architect? Do you see that being the security engineering side? Do you think there’s a newly created roles that are kind of coming in more specifically security slash AI, AI bent?

Kevin [17:07]: I think in the short term you’ll see people come up into that space because like I said, it is a whole other way of thinking, right? We’ve collapsed the layers that were traditionally there. And what does that sort of mean to collapse our security down to the data level and what’s available there and which protocols will support that or not, right? Because so many of the, protocols that have come out, like MCP, it didn’t have an official auth part of it until like March this year. That wasn’t even part of the, the standard, which kind of blows your mind. So that’s when I think a lot of times a lot of the MCP servers you had in the early days, you would hardcode your password somewhere in a file.

James [17:47]: Yep.

Kevin [17:48]: Awesome. Versus now it being put into a proper auth flow where it’s a limited time scope token for you, but at a limited scope. So I can’t do everything, but I’m only giving you permissions to do certain things for for a certain amount of time, right? So over time, I think it will become part of regular ways of thinking, but in the short term, I think there’s probably a need to have somebody who looks at it and sees it quite differently.

James [18:14]: Yeah, I think it’s those new skill sets. And we often, I’m talking to companies all the time about the changing nature of roles. And a lot of these roles are brand new, but the same way a really good software engineer using the right tools becomes an even better software engineer. I think having that background, that strong security background, understanding infrastructure, understanding security protocols, understanding guardrails, understanding the role before just throwing AI on top puts you in a significantly better position to then say, look at it through that same lens, but it’s a new piece of technology. What are our different challenges? How do I need to evolve as an individual?

Kevin [18:50]: Yes. Yeah. Knowing what good looks like helps before using AI, right? Because if you don’t know what good looks like, whatever it spits out looks great. And then you open up the hood and everything is—

James [19:00]: which I think is the, the perfect case of software engineering, right? Like, I can vibe code something at the moment. Yeah, me looking under the hood, how much bloat’s in there? How’s it going to perform at scale? How would it perform if 5,000 users hit it? Yeah, how secure is it? I don’t know that. It could look pretty good on the front end. Yeah, yeah, but once you start opening the hood, that’s where the real differentiator— I think that’s where the traditional technology roles, technology experience, still having that, that know-how still puts you in good stead for the roles of the future.

Kevin [19:31]: I totally agree. I think, I think being somebody who’s kind of come in into computer science late ’90s, early 2000s, and having the different foundational elements kind of built, yeah, you have that sort of— you’re grounded in that. I sort of wonder though, with unfortunately when you sort of see the way companies are hiring now where they are pushing off all the entry-level positions into AI things, at one point are we going to have a huge skill deficit, right? I think it’s very short-term thinking as to what can we replace, how can we save money? But then I think you’re gonna have a longer-term problem with who’s gonna backfill, you know, me when I retire.

James [20:14]: Senior people for the near short-term, I think are in a really good spot because you just make senior people with, better tooling, even more effective. Mid-level people need to heavily, heavily lean into the tools to accelerate their careers. I think the juniors, I’m seeing two things at the moment. Some people, no need for juniors at all. I’ve got other people that are leaning into tooling and skipping two or three phases and instead of coming in as a junior engineer straight outta university, maybe got some good understanding of fundamentals, but using the right tooling, really leaning into that, Instead of the first year, year and a half of your employment, you’re not really providing a great deal of value. The company’s providing you more value than you’re providing them.

Kevin [20:56]: Yes.

James [20:56]: They’re actually more productive.

Kevin [20:58]: Yes.

James [20:59]: They’re even better. Yes. If they’ve got a senior team member around that they can learn from.

Kevin [21:03]: Yes.

James [21:04]: And I think that’s where this push back into the office, or at least more of a hybrid environment, is only going to accelerate things more and more because as well as remote works, I think the ability for junior in any profession, juniors to come in, work around other team members, people that are more senior than you, what you can pick up, what you can just bounce off other people and learn from them.

Kevin [21:28]: Yeah.

James [21:28]: Accelerates your learning. So juniors that come in leaning into the tools, surround themselves with people that are senior that really know their stuff.

Kevin [21:35]: Yeah.

James [21:36]: Can really accelerate their careers. Yeah. Yeah.

Kevin [21:38]: And I think that’s where If people can start using AI to not focus on the output and focus on efficiency and all the stuff like that, but if you can use AI to accelerate your learning and gaining of knowledge, not just to get the answer. I was literally having this conversation with my 13-year-old, the difference between getting the answer and the result versus building knowledge, right? And it’s a very different, it’s a subtle shift of how you use it, right? And it came to be for him as simple as, asking it a question and giving you one answer, saying, well, ask it the question, but then tell me 3 other ways that it could be solved as well.

James [22:15]: Well, how did that come to that?

Kevin [22:16]: Or how did you come to that? Like looking at the reasoning tree that it kind of gives you. And he was quite annoyed. He’s like, why do I have to do that? It just seems so much more. But then, you know, he kind of came around with, well, that one way didn’t work. And if it just gave me the one way, I had no, I’d just ask it again. Well, that didn’t work. Tell me another way versus if I gave me the options in the explanation, if one didn’t work, I probably understood a little bit more why it didn’t because of the other options that were there. And then he could make the next choice of how to proceed. So again, output result versus gaining knowledge. And I think that’s exactly what you’re talking about with using the juniors to then elevate them and to accelerate them gaining that knowledge, I think, faster.

James [22:56]: I agree. And again, AI is a tool or piece of technology. It’s the same thing with, do I need to learn maths because I’ve got a calculator either on my wrist, on my watch, or on my phone? Do I need to understand maths? I don’t do any handwriting anymore because everything I do comes out and think, oh, my computer or my phone. Do I need to learn handwriting? The same conversation with my children as well around that. And I think the other conversation, the changing nature of university or education is only gonna continue to change. An education, a university degree designed 3 years ago for computer science probably needs to evolve pretty quickly.

Kevin [23:34]: Yeah.

James [23:34]: Understanding the core fundamentals is still important.

Kevin [23:37]: Yeah.

James [23:38]: But for a lot of people I’ve spoken to in university, one of the key parts of university is learning how to learn.

Kevin [23:43]: Learning how to learn. Yes.

James [23:45]: And the danger—

Kevin [23:46]: Yes.

James [23:47]: —5, 10 years from now is if people don’t need formal education, they don’t need school, they start to lessen the importance of schooling, that learning how to learn or learning how to problem solve. Yes. Are two of the big challenges I think that next generation are not gonna have. Yes, I agree.

Kevin [24:04]: It’s funny, whenever people ask me or when my kids have asked me about, oh, university and what was the biggest thing you took away from it? And that’s what I’ll say. It’s actually not so much the courses. It was, well, A, learning how to take care of myself. That was the first thing. But then the learning how to learn, right? It was unstructured and I needed to figure that out for myself. And how do I take things in the most effective way for me? But you’re right, with that kind of gone, and if people are just getting the immediacy of answers without having to do the work to get there, I do have worries about that, about what does that mean for future generations and how broad is their knowledge? Like, what’s the depth of their knowledge? Is it gonna kind of be there so when there’s situations that arise that something they haven’t seen before, are they going to be able to have the confidence, but then also the depth of knowledge to kind of figure it out?

James [24:57]: I think that also leans into the, the needing to actually ask why. Yes. Why is it going this way? Because there are biases, there’s hallucinations. Yeah, everything’s not perfect with AI. No.

Kevin [25:10]: So everything’s right, but everything isn’t perfect with people either.

James [25:14]: Correct. Right. And that, that’s— it comes up in recruitment all the, all the time, right? Can you use AI as part of a recruitment process? Oh, there’s internal built-in bias. Yes, there’s also internal built-in bias within human beings. Yes. And whether you like it or not, everyone’s got their bias, right? Yeah. I think, and I’m working through this at the moment because I think there’s potentially a way that you can have less bias using AI than just humans, but the humans will have to stay in the loop somewhere. So yes, the recruitment game is, uh, continuing to change and it’s evolving. Um, so I think it affects all jobs, right?

Kevin [25:43]: Yeah, yeah, no, definitely, definitely.

James [25:45]: Your technology careers work with two big enterprise technology companies. Enterprise technology, enterprise SaaS at the moment in particular has, uh, the SaaS apocalypse is in the media, the death of SaaS, micro SaaS is going to break, you know, big SaaS companies down. SaaS valuations have been hammered. There is a bit of resurgence. How do you see the changing nature of, like, you’ve worked within these big organizations, do you see they’re only going to get smaller and smaller and achieve more with less? Do you think How do you say the company’s evolving?

Kevin [26:17]: One thing you sort of said about the valuations, just to not directly answer your question, but something about the valuations that was interesting where I think partially because of AI coming out and it being token-based, which is very much consumption-based, very much changes and has forced a lot of the SaaS market to no longer be licenses and seats. It has kind of now forced it to be consumption-based. In a way, right? I know that there’s a lot of companies are making that switch, Salesforce being one of them. While that’s great for the market wanting that, I think the other part of the market that doesn’t like it is the stock market, right? Before, you could project revenue based on the number of seats you had. How do you project revenue now when it’s consumption-based? You really can’t. And while the customers are asking for it, the stock market doesn’t like that. Level of uncertainty. I think that’s part of the reason for that stock market devaluation kind of going, because it is a level of discomfort that now the market needs to wear. But I think that’s going to kind of be the way it’s going forward. Now, your other question as to like, what does it look like now internally for teams and for how enterprises are sort of building teams? I think right now we’re in a state where there’s the Well, we can just do more with less. And I think that’s evident with a lot of the mass layoffs that are happening. I wonder whether that’s going to come back around, because you do need people at some point. And there’s that— I forgot who did that— the curve of adoption, where I think we’re still on the upward curve. We haven’t quite reached the peak. Then we come into the trough of disillusionment. I don’t think we’re quite there yet. But you still do need people who know what good looks like. It does put out a lot of bloat. You do sort of see where it’s not always creating the most secure code, right? You look at all the recent breaches. You had Lovable, you had— Vercel was this, right? Vercel, you know, a little while ago, you know, was a security breach, but you even had at AWS where its agent decided, I’m just gonna rebuild a production environment, right? So I think it’ll kind of come back around, I would hope, into saying, well, actually we do need more people kind of involved. Who know what good look like to see if that sort of comes back around to maybe bolster teams back up. I hope though that it will then be moved towards a working alongside with, right? To even what we’re saying about how do we accelerate the building of knowledge of juniors, right? How can we then use it as a plus one as opposed to a instead? But you still need people that are highly skilled, know what good looks like and have that experience, I think in order to have something that is, that is robust, that is secure, that is scalable. I think to just think that you can just vibe code something that’s going to reach that scale is just not. Right now with the current state of the stuff it produces, I don’t think that’s just a possibility right now. Maybe it’ll change in 6 months, who knows?

James [29:17]: Things are changing pretty quickly. Yep. You mentioned know what good looks like. I think the other phrase I’m hearing around is taste. Having a taste of what good looks like, what’s going to work. Is that a learned skill? Is it innate? Is it something that people can learn over time? If you’re younger and a junior, haven’t been around to see what good looks like, how do you view that?

Kevin [29:43]: How do you do that on your own? I guess that’s the thing, right? Like, if you’re on your own, how do you know? You don’t know what you don’t know. That’s where maybe as a junior kind of coming in, probably trying to find mentors, people who are more experienced about that, of understanding what does good look like, right? Because you don’t know what you don’t know. I definitely probably look at some of the stuff I wrote years ago that I thought was amazing. I look at it now and I just, so much shame. So what I kind of did. Is it innate? I think it’s, some of it I think can be innate. I think for myself, even though I work in technology, I actually didn’t come from a technology background originally. I was going to go to university for bio sci. I wanted to do prosthetics, which is a cool mix of technology and helping people, but I kind of fell into computer science, right? I always had computers around. They’re always really easy for me to kind of work with and understand. But coming from a more human background, I was actually gonna go to school for photography as well. So coming from a creative background, I think the innate part for me is I think I’ve always paid attention to the aesthetics of software design, the aesthetics of your architecture, the aesthetics even of the code that you would write, right? And for me, that aesthetics would, come out into how it flowed, how it looked, how it wrote, to the point where people actually recognized my code without my name being on it. I had people like, “Hey, this is yours, isn’t it?” They could tell by the way it was written. So I think to a certain part of it, there is that innate level of understanding and feeling what it does look like from an aesthetic point of view. That doesn’t necessarily translate into secure, but again, there can be that sort of felt sense of it. And yes, it can be learned as well, but How do you, I guess you could learn it using AI to learn it in a way is one way of doing it, but I still think that having more experienced mentors to talk to, to understand, to explore ideas with is probably a more human way to go.

James [31:54]: We mentioned this a couple of times, being around seniors, being around mentors. I think that is the best fast track for juniors who, or even middle level, people that are looking for their next organisation, you’re like, next opportunity, where do I want to go? And one of the things you should probably be prioritising rather than it just being salary or working conditions should be my ability to grow here. Who can I learn from? Is that something that either you’ve experienced in your career or you’ve seen that it’s happened strongly with people you’ve worked with?

Kevin [32:25]: Yeah, well, look, I think it’s only later on in my career that I’ve started to look at What’s the culture of the place? What are the people like? Is it open? Are there people here who I think I can learn from? I think that’s something I wish I did earlier on in my career is to not be on the back foot in the saying of just being, oh, grateful. Oh my gosh, I have a job. That’s great. But look at it as a two-way type exchange of I have skills that are valuable to them and they have an organization, a culture that’s going to be valuable for me. So what’s that back and forth that we kind of do and look at. So asking those questions, are there, do they have a culture that’s open where they encourage people to connect up and down and across? Because that’s how you’re going to learn. Not maybe even, yeah, I said the across there, not just inside your own stream, but how can you go horizontal across to really understand how does that part of the business work? Because even as a software developer, if you understand how finance works, if you understand how procurement works, if you understand how these different department works, it’s going to make you a better, a better technical developer if that’s what you can do, because you actually understand the people who you’re actually building for.

James [33:34]: You stayed at Salesforce for 15 years. Yes. They obviously did something well from a cultural perspective, learning perspective. I think the changing nature of technology, well, has a big flow-on effect to the changing nature of teams. What does Salesforce do well that other companies that are looking to continue to grow in the age of AI where people are forced to move quicker, higher productivity, better output, quicker output, any key learnings from a company that do culture, that do performance as well as Salesforce? Any key things that you’d share?

Kevin [34:09]: I think my early days there, the culture was quite strong and felt authentic through and through across your teams, across geos, across departments, which was quite good. I think something that they did quite well was everything was on a dashboard, right? Which sounds really creepy at first, and it was a little uncomfortable at first, but you can’t change what you can’t measure, right? So I think that is something that they did quite well at that point. You know, the specific thing that I was kind of thinking about that instance was more as a pre-sales engineer, we had to do time tracking, activity tracking, like in our calendar, very granular, which customer, what kind of activity, how long you’re spending. And that was never done from a top-down, why are you doing that? Why are you doing that? It wasn’t done from that. It was much more aggregated to say, what, where are we spending our time? What are we doing? And does that make the most sense for where we want to go? Right? And at that point, it informed decisions around, Well, if we want to be having these higher-level vision-setting conversations with customers, then why are we spending 75% of our time building stuff? If we’re building stuff, we’re not talking to people. Right? So I think that was a really good way to kind of do that behavioral change/culture shift by being able to measure and to really sort of understand how— what are people doing now and what do we need to kind of change about the behaviors to go to where we want to go?

James [35:42]: You mentioned understanding, talking with customers there. Obviously in pre-sales and pre-sales architecture, which is, you know, what you’ve done for the best part of your career, the understanding of the problem, the under— that communication. Everyone can build technology now. Most people can build technology now pretty quickly. Building technology for technology’s sake is only going to become more and more rife. I think about the App Store. The App Store’s got hundreds of thousands, millions of apps there. Probably some of them cleanly written code, beautifully written code. No one uses the app. It’s not a problem, it’s not a game, it’s not something that people want to use. I think we’re only going to see more and more of that with vibecoded websites, whatever else it might be. Understanding the core problem, which is your career, how have you seen that role change and evolve over time, the important levels of it? I will get into the AI and whether that’s affected it, but I’m just like, how have you seen your role or the importance of your role change and evolve over time?

Kevin [36:46]: Initially it was very technical focused, really, really technical, you know, very much from protocols to supported SDKs to all these sort of things, supported APIs is really, really technical focused. I think it’s changed much more to be, talking at the business level. What is the business goal? What is the business outcome? What is the value? And then coming up with a sort of more of a holistic solution, I guess, in a way. But then be also to be able to communicate the value of that solution that goes directly back to the customer’s business goals and what they want to kind of drive towards. Now, the part that you had to be able to do from a technology standpoint is you needed the technological understanding to sort of saying, is this even possible?

James [37:34]: Otherwise your engineers hate you. Otherwise you’re just making stuff up. Yeah, and you’d say yes to everything, go back to the engineering team and they’re like, “We can’t build that.” You can’t do that, right? “We definitely can’t do it in that timeframe.” Right?

Kevin [37:43]: So I think that’s where the job has changed dramatically, right? I think customers are expecting to see proper ROI and you do need to have it tied to business initiatives, right? And if you can’t do that, then you’re either just going to become a transactional vendor with them, And which means you’re going to be knocked out by somebody who comes in cheaper. And now if you look at the potentially the upsurge of stuff coming in, because anybody can build it now, I think that becomes a real risk. But yeah, you do need that fundamental understanding of the technology layer to understand what it does well, where you can bend it, what you just shouldn’t touch it with, and then translate that back into business value. So that’s been a very, very large shift I’ve seen.

James [38:28]: So it’s really understanding of that business problem or the bottlenecks. Yeah. Rather than the technology, just throwing a tool at it for tool’s sake.

Kevin [38:37]: Yeah, definitely. I think some of the best presentations or demonstrations that I’ve done, I’ve actually never mentioned product, right? It’s just being all about the business, their speak, their, their language, everything inside them. And you show through the demonstration, you throw, show through it how seamlessly and frictionless you can actually make that come through.

James [38:57]: You mentioned presentation there. I’m going to dig into the AI part a little bit here. Is your role evolving to the part or the point where instead of just talking about hypothetically or something that may be able to be built, you being able to build a proof of concept, you being able to— rather than it being a presentation or even going as far as like a Figma design or something like that, you being able whip together something on, this is how I could see it work. Doesn’t need to be fully functional in the backend, but at least gives somebody a look and feel for the business problems you can solve. Are we at that point yet in a pre-sales environment?

Kevin [39:33]: Well, look, with the majority of my experience being at Salesforce and sort of SaaS and the force.com platform, the majority of the stuff that I would build at Salesforce was real. Yeah. Right? Because the way that the platform was kind of done, it was, you’re able to kind of do that. And I think in the SaaS world, you can do that, right? You should, sorry, you should be able to do that. Some SaaS vendors can’t because of the way that they sort of spin things up and the cost to them, things like that. So there’s also the variances there. What it’s allowing me to do now though, I’m finding, is to tailor it a lot more to the customer. It’s really in their look and feel. You know, you can just kind of get that last polish part of it that maybe before I needed to pass off to a UI/UX design team who were a shared resource, and maybe you could get them, maybe you couldn’t, right? And did it really matter that much? No, not really. So, um, it allows it, I think, to be a lot more hyper-personalized. Yeah, I agree.

James [40:38]: I think like the background research, customization, personalization, that’s where AI is really influencing the game at the moment.

Kevin [40:44]: And also even to have almost back and forth conversations with customers and then not be conversations, but like, hey, I just kind of slammed this together. This kind of shows the way this sort of flows through. Here’s just some of the bits and pieces. Don’t use this in production, but that’s kind of what we were talking about yesterday, right? And then you can pass that over to them. They’re like, oh yeah, that’s cool. That’s great. As opposed to before, that would’ve been a lot of work during a proof of concept to figure that out. Does it really work for what we’re looking for in this particular use case because it’s Tuesday and Mercury is in retrograde? You can actually kind of put something together like that to show in that specific one, yes, it works for that.

James [41:24]: Nice. You spent less time at Okta than you have long, long period of time at Salesforce. Any big differences in the way teams operate there, uh, the cultures operating, your roles changed? At Octoverse, your significant time at Salesforce?

Kevin [41:41]: Well, look, Okta’s considerably smaller than Salesforce, right? I think Okta’s somewhere around 8,000, whereas Salesforce is sitting at what, 70,000? I think how AI is impacting the way that things flow, I’m finding it easier to get up to speed across either accounts or different teams or different opportunities a lot faster. Because of artificial intelligence, right? As opposed to having to sit down and read copious notes about the engagement over the last 6 weeks or watch, you know, videos of the last 3 phone calls or whatever, or sort of video chats, things like that. Throw it into NotebookLM, ask it a couple of probing questions, test a couple of hypotheses inside there, and then I can come back to the account team and ask them some quite deep questions right away where I just, you know, is this, this is the context as I understand it. Is that right? Yeah, it is. And I can do that in an hour versus that would’ve been me watching 4 hour-long videos and then reading documents. And then, so it, it’s the amount of time it takes for me to get up to speed is, is greatly, greatly reduced again to, to build that knowledge. Yep. Right. Is greatly reduced.

James [42:55]: And then from the flow on, so obviously the research element, the backgrounding element gives you better context going in. That’s changed the nature of that role. From the customer engagement side, ongoing from there, the designing of the solutions, is that still something that just comes first principles that you’ve, you’ve worked in this game for a long period of time, understanding the product, understanding the customer, or is AI having a significant effect on that as well?

Kevin [43:21]: I haven’t seen it come to a large impact of how we design solutions. I think at the end of the day, it’s still somebody understands the business. You understand your key stakeholders and what motivates them, or the other stakeholders in the room, and what do they need to look, feel, and see to feel comfortable. So I’m not seeing— AI solve that from a solutioning perspective. It’s helping me bring my things to fruition faster. Yep. But as for designing it as a solution, that’s not what I’m sort of seeing. Maybe as alternatives, that’s where it’s actually been quite handy where you have a solution in mind and you can, I’ve used it to sort of saying, hey, this is what I’m sort of thinking. And then now go back to your NotebookLM and looking at the other sort of complexities that were sort of in there, or the highly regulated industry, or the mishmash of other technology. I’m thinking about this. Can you tell me 5 areas where it works well and maybe suggest 3 where it’s not going to? So I think to have quicker litmus tests, it’s been quite good to do solution design. But again, I’m not typically asking the systems to tell me how to solve this. It’s, this is my hypothesis, tell me what tell me what I might be missing.

James [44:42]: And again, I think that comes down to that— the knowledge that you’ve got, the experience you’ve got. AI is a great tool and it’s a great sounding board, but you’re giving it your hypothesis, you’re giving it the context, knowing how to— well, prompting is changing. Prompting was so important 6 to 12 months ago.

Kevin [44:59]: It’s really not so much anymore, is it?

James [44:59]: It’s changed, right? Yeah. So the prompting side’s changed, but the context that you give it is becoming more and more important. Yes. And being able to give your hypothesis, give it the context, the background, your background, company background, and then have it as a sounding board there is becoming more and more important. Yes. Without your background, without that hypothesis that you came up with, you don’t have that there as a sounding board to challenge you or to, yes, you’re on the right path.

Kevin [45:27]: Yeah. And that kind of goes circular back to the, what we were saying before about where does that experience come from? From? Where do the newer generations gain that if they’re not being let in or the roles aren’t sort of there? I do wonder that. I don’t know. I don’t think I have an answer for that or can really sort of see how we backfill that.

James [45:48]: So we talked a bit about your time inside enterprise organizations. You also spend equal, if not more time inside your client organizations and working with them. You’re also playing out at security level It used to be just security for individuals, employees of a company. Now companies are evolving the way they build their teams. It’s a mix of teams and agents. Yes. How does that then play out with where you’re— the space that you’re playing in? Is this a place where we’re now looking, or companies are looking at agents like employees? Are companies advanced enough? Some of them are, I imagine, where we’re starting to look at what roles, guardrails do we give each agent? What sort of QAing, security can we do around each agent? Is that where companies are at at the moment? Is this an evolving landscape? Are companies way behind?

Kevin [46:39]: So there’s, I think initially when people were creating things, and now we’re talking about stuff that’s much more pure agentic, right? So much more autonomous, they can do what they want. Historically, I think a lot of people would view it as just another system. Another system to be integrated. And that fed the thing of sort of saying, well, and it needs information to be useful because this AI needs information. And that’s where they just view it as a computer system and give it access to everything. And that’s where things like the McDonald’s breaches would come into play. The learnings from that are now that, well, agents are technically, they’re not a computer system because they’re non-deterministic. They can wander everywhere and they fall into that classification of NHI, non-human identities. Which isn’t a new thing, right? We’ve had non-human identities for a while, but such as like, you know, service accounts or, you know, machine-to-machine integrations, right? Difference now, I think, with agentic non-human identities is they’re non-deterministic and they can kind of potentially roam anywhere they want. So that’s, that’s the difference between them. Before, you knew this was a point-to-point connection. You knew what it had access to and you knew when it would be firing versus agentic. I don’t know where it’s gonna go. It could go anywhere at any certain point in time. And if I haven’t put the right scopes on it, it could ask, I don’t even know what it’s gonna ask for. Right? So that’s where that, that wildcard comes in. So there’s definitely a different rising classification of, of agentic identities and they are themselves having their own identity. Now the weird thing about it as well is we need to know who the agent is. And what can it do, what can I have access to? But there’s a blend inside there where you now need to know who is it acting on behalf of. So there’s a concept already in identity of impersonation. So logging in as somebody else is quite common inside the customer service space where they come to assist you and like, okay, I’m gonna log on, I’m gonna access your account on your behalf. So that impersonation thing will say, I see it as you, as James, However, I can see that I’m acting as Kevin, the support agent, right? So that model kind of already exists. But again, now the part that makes it different from the agent standpoint is that, that non-deterministic aspect of it where it can kind of go anywhere at any point in time and access whatever it wants on your behalf. So that changes that yet again, where we now need to ensure the age— we know who the agents are. Who they’re acting on behalf of, but for the context. That’s the difference. What are you doing it for? And since agents are non-deterministic, guardrails are okay, but they’re just suggestions, right? They’re not hard and fast. They’re just suggestions for what it should do. It can still decide to do something else on its own. Actually, I have a side story where Claude did that to me. You need to make sure the permissions you’re giving to it on your behalf are scoped just for the context of what you’ve given it to do for that very small amount of time. So I think that’s the differences that we’re seeing now is smaller scope, time limited, and that’s it. Versus before, they were probably a lot more wider open because you knew the deterministic nature of where they’re going to be going.

James [50:04]: Is this something you work with companies on architecting these solutions?

Kevin [50:09]: I imagine— Well, understanding that as an interaction point of we’re now putting in impersonation, we’re now putting on scoping and also time-bound. So that’s something that’s quite new and different.

James [50:21]: I think that’s a really interesting space, especially when it comes to the changing nature of technology teams. I think technology teams, you will be a human being, an employee supported by multiple agents. Each of your agents, you should have some form of knowledge about what they’re doing. Yes. What they’re accessing, what data they’re sharing. Yeah. Like you would, or like most companies can if they’ve got a decent security infrastructure in place. Yeah. To say, hey, okay, where is data? Who’s accessing what? What are people doing with their employees? I think that same level of knowledge, QA, security guardrails around agents the same way you would an employee, is something where more mature environments, I think, are looking at it. But I’m also seeing a lot, especially in the SMB space, it’s just build agent, get agent to do whatever, who knows, and get it out fast.

Kevin [51:16]: Yeah, so I think that’s something that a lot of the, the software industry is trying to figure out, is how do we, as opposed to making people have to build all those things on their own, How can we kind of wrap that up more so that it’s token vaulting? So like you never give an agent a token because you’ve just given it the key. So how do I give it the valet key for a certain amount of time so it can never really do anything else with it? How do you know the actions that it’s going to take or which actions it took for that scope that you gave it? So all this traceability needs to be there as well. And right now I’m kind of seeing that as sort of of disparate features all over the place that it’s up to the developer to put into place, which if they don’t know about it, they’re not going to do because I got to get this out by Tuesday.

James [52:04]: Also, it comes back to the importance of software engineers, proper software engineers or experienced software engineers. I can vibe code a website. Me going in and actually understanding the nuances there and being able to then go to the point where I’m putting the right, the right technologies in place, the right frameworks security in place. I don’t have that know-how, and that’s where the quality engineer, the experience comes in and will remain very important. Yeah, this foreseeable future, I think, in building software or quality software, definitely enterprise-level software.

Kevin [52:35]: Definitely. Yeah, look, I think enterprise-level software is a whole other ball of wax, right, for how can you build that. And that’s where you, again, using your AI teams, quite different, as you know, for, for that level of seriousness and scaling, right? I think that’s almost where you and I first started talking about this, where you’d posted something on LinkedIn about teams and I sort of just sent a screenshot of, this is my team of agents, very, very specifically scoped agents to minimize their context window saying, you’re a security specialist, you’re a DevOps specialist, you take care of just this module. Again, to have that real specificity Which has brought us, it’s definitely brought up the level of my code to make sure that yes, it is secure. Yes, it’s following these sort of rules. No, you’re not reintroducing the same regressions over and over again. So again, that’s a bit of a, I know it’s not people teams, but again, shaping AI teams in that level of specificity, which honestly I’m modeling it after how I would build my own tech team.

James [53:39]: That seems I have called the podcast Building Tech Teams. Yeah. It’s not necessarily building human teams. Human tech teams, that’s right. I think there are cases. There’s definitely going to be one-person businesses that, you know, the big thing out there is can a one-person business be a billion-dollar business? And it’s the race to do that. Two Brothers, you know, whether it was true or not. I think it’s a really interesting space where the technology teams will evolve to it is a mix of human and agent. Yeah. And agents need to be looked at like humans in some aspects. When it comes to security, comes to access, comes to data, comes to where can and can’t they play. And also just having that visibility to what are they doing. Yeah. And this is the evolving nature of teams. And some people are there now, some people yet to be there in having a look at agents in the same way you would look at as an employee, even down to the quality. Yes. What is the quality output? The same way you would, you take an employee through a weekly review. Yeah. Having QA go over your agents, what is the quality of this output? Do we need to, you know, change aspects of it to get that higher quality or more accurate outputs?

Kevin [54:48]: We have that, the concept of the agent as judge, right? Yeah. Of sort of cycling sort of through that. But then again, where does the human kind of come in? Because, you know, the agent is only gonna know with the scope that you’ve given it and who told it what good looks like, right?

James [55:03]: So same thing. Yeah. For smaller companies or SMBs or growing companies that haven’t got to the point where they’re looking at products like OCA or Auth0 yet, what’s the journey? What’s the journey from going like, hey, I’m introducing AI into my organization, build a couple of agents that are doing some things, but I’ve understood, I’ve listened to Kevin and I’m like, oh, we’re in trouble here. We need to have some visibility. We need to make sure we’re reducing our vulnerabilities around what an agent can and can’t do. Where to start?

Kevin [55:35]: Where do I start? Yeah, well, I would say don’t start with having an external-facing agent. Do not start there, right? Because you’re just opening up the floodgates, opening up the doors. Looking internally first at what are the mundane tasks, what are the things that just kind of get in your way from doing what you really want to do from your business to really accelerate it. But then you also need to gradate that against a, what data does that need to do that? How risky is that data? How sensitive is that data, right? So I think you’re going to find that blend between the two. You know, you don’t want to take something that is, you know, really mundane, but you need to feed all your customer information. Don’t start with that, right? What are the things you can do? Second thing is then, you know, looking at the, the existing sort of integrations that are done within your Office 365 slash Google Workspace type thing. Start with that because those guardrails are fairly well defined and it’s a fairly walled garden. So looking at from that particular point at first, you know, all those admin tasks that are just really getting in the way where if you give it a little bit of access that you sort of pay attention to, you know, don’t give it read/write to everything. Don’t give it full delete access, right? So just sort of look at that. At least start with read. Have it give you summaries of the day. Tell you maybe what have I forgotten? You know, things like that. I think those things that kind of help be your extended brain, but also take care of the minutia of your daily running of business. Yep.

James [57:04]: What about when companies are more advanced than that? We are starting to play with customer data. We want something that’s publicly accessible. Is that a call-up big organizations? Is it going looking for a product like OAuth? Is it a, where am I at? What do I do? What’s my next stages from that perspective? I think there’s gonna be a lot of companies advance very quickly from where started with one agent, we’ve seen the value there. We’re now up to 20, 30, 50. I wanna start, I’ve seen what it can do with automating internal tasks. And take it to the next level.

Kevin [57:37]: Yeah, yeah, yeah. What I’m actually seeing in the Australian market, just kind of a side tangent, because you talked about agents and we’ve been talking about agents a lot. What I’m sort of seeing more is not as much focus on agents. That’s, I’m finding that’s a very North American message about the whole agentic type thing. What I’m actually finding a lot more on the Australian side is they much more care about MCP. Reason being is they want to connect their business not to their own agent, they want to connect them to the foundation models. People aren’t gonna come to my website and use my agent. They’re gonna probably go to Claude and saying, what’s the best, you know, red hot shoes for running sub-2-hour marathons? That’s what they’re gonna do first. They’re not gonna come to my website to do that. So I’m seeing a lot more customers ask for that. How can we do MCP? So I think that one is a little bit more, it can be a little bit more walled, right? You can sort of be a little bit more, uh, intelligent with, well, it’s just my product information, so it’s probably easier to kind of get that out there. It’s a little bit safer to sort of do that, right? Um, without going full crazy into saying full customer information, full corporate information out there. So that is almost a slightly easier entry point into doing that. Where do they start? Look, that’s a tough one because MCP is continually changing as well. It’s still an emerging standard. A lot of the software vendors will have some sort of base MCP offering that you can start with, you know, and then the question for you is how does it tie as easy as possible into your existing stack, right? So, you know, at some points it’s not great to have vendor lock-in. If you’re on Google, you keep on building on Google. That’s not always the greatest, but maybe that’s the lowest barrier to adoption. And probably don’t be afraid to throw stuff away. Yeah, right. Experiment. That’s the great thing about AI. You can experiment really quick. You haven’t spent months building it, you spent weeks, days building it. So that emotional attachment to your code hopefully isn’t as strong and you’re like, well, that was a new experiment, kind of served the purpose, but not quite right, and then throw it out.

James [59:40]: I agree. You mentioned the word vendor there. I think the other aspect which comes into it are the internal teams, hiring of teams, changing nature of teams. We mentioned agents as a plus to internal employees. I think vendors can be seen as an extension of your team. Companies that are in that situation, right, want to continue to do a little bit more, a little bit more. I don’t have a big internal technology team. I’m not a SaaS company, not a pure technology company. We’re tech-enabled, let’s call it. Easiest path— is it to upskill people internally? Is it to hire somebody externally to come in to be your Agentic orchestration expert? Is it bring a vendor in and work with a vendor first and they will potentially upskill your people as you go. I think they’re the 3 things I’m seeing at the moment. It’s probably one of the most interesting questions I’m being asked, and I think it is horses for course. But I’d be really keen to understand your opinion if you’re not a pure SaaS tech company who obviously has to invest significantly in your own talent.

Kevin [60:44]: Hmm, that’s an interesting one. I just— as you’re saying that, it’s sort of you’re talking about calling the vendors in. And as part of my time at Salesforce, so I was pre-sales for a good chunk, but then I took an internal role where I was CTO of an internal department. And then I was on the buying side after being on the selling side for a while. So that was a really, really interesting perspective shift. I kind of knew the games and it kind of gave me that internal perspective. And by engaging vendors, which is ironic ’cause I’m sitting on the vendor side, The job is to sell you stuff. Correct. Right? It’s not really their job to educate you. It’s their job to educate you enough so that you like their product, right? And I know that sounds really, really cynical, but—

James [61:29]: And the best vendors, I would go one step further and just say to get the most out of the product as well.

Kevin [61:35]: That’s the other thing. The best vendors. So this is what I was going to say. At my time as CTO in the internal Salesforce department, when I would have internal teams saying, oh, we need something to do this, or can it do this? I’m going to go and build something on my own. I’m like, no, no, no, hold on. We’re their customer. Call their customer success team, call their whatever team that is, that adoption team, make them do it. That’s what they’re there for. They want us to use more of the product. It behooves them that we use more and more and more. So I guess maybe partially to answer your question, If you have existing relationships with your vendors, leverage them. You know, sweat the asset. You’re paying for it. You’re potentially getting support, premier support, success managers, whatever they’re going to be called. Ask them. Get them to sort of help you sort of do that. Hey, can it do this? I’m looking to do that. You know, what will motivate, motivate them even more is, oh look, you can’t do it right now with what you have, but then If you buy this part, then it’ll do it, which is, you know, but that’s a motivator for them, right? We’re all human beings. Something needs to motivate them. But if you’re an existing customer, you can use that as the motivator to get them to show you, to help you understand, to get, be part of that education journey. So that’s one way to kind of doing it. I don’t know if I’d take that if you were a greenfield account, like as in you don’t have a relationship with at all, because then that’s a pure sales motion. Yep. Right? So again, different contexts versus if you’re an existing customer versus net new customer. I think from the other sort of two scenarios you talked about is bringing in either external consultants or growing your team internally. That’s probably much more a decision based on cash flow and your own desire to grow a team or not. Right? And I think that’s probably what’s gonna drive that more than what’s going to be the best place to start.

James [63:30]: Yeah, you know what I mean? I think it’s going to just be a really interesting question going forward for a lot of companies in general, but technology teams on where do you lean on external specialists, where do you lean on upskilling of internal staff, where do you hire new specialists into your teams, where— what do those roles look like? I just think the changing nature of a technology team in general is going to be ever evolving.

Kevin [63:54]: Well, not only that, but then what’s the depth of the pool of people to pull from to even hire? Correct. Right. How many people can say I have 5 years of AI experience?

James [64:02]: I’ve seen some of those job ads. Yeah, very real challenge. You, from an individual personal level, you mentioned you’ve got a bunch of agents with some tight, uh, guardrails around them. How are you using AI in day-to-day life?

Kevin [64:15]: I think on my, on my personal life, for a lot of reconciliation of data and finances to sort of, you know, take understanding spending trends. Again, it’s dollars and cents and where am I spending it? And I’m feeling fairly comfortable that that’s totally fine for it to sort of do bucketing. And I know, and I know there’s lots of other software programs that kind of do that, but this is a level, different level of granularity I’m looking at. So I’ll use it for, for doing things like that. Sometimes I’ll use it to read the kids’ school newsletters because they don’t always come out at the same time and what’s kind of happening, what events do I need I need to know about and what needs to be put in my calendar. I can use them for that as well. Just doing my own sort of personal side projects as well. And that’s kind of where I’ve really built out much more teams of agents to build novel ideas using technology that I don’t know really much about, but I want to do a feasibility study. Like, is this even remotely possible? And so I’ll use them there to kind of get to a, to potentially fail fast, right? And also educate myself a little bit more about technology stacks that maybe I know not a lot about.

James [65:15]: Yeah. Nice. How have you seen it change the nature of your day-to-day job?

Kevin [65:18]: Sometimes it’s good, sometimes it’s bad that I can work on multiple things at once, which I guess depends on the state of my spicy brain, whether that’s a good thing or a bad thing. Some days where it’s firing, I can be, I can have, you know, 3 VS Code terminals kind of going, each working on different things and it feels great. Other days it just becomes a really bad, noisy, I don’t, feel like I’ve gotten anything done because there’s just too much going on. So it’s a bit of a balancing act as to where should I wield this? And maybe not just for the task and the chore, but even based on my own sort of internal state and capacity.

James [65:53]: It’s going to be a very real challenge, not for yourself, for a lot of people. I know I’ve faced that myself where I’m like, so many ideas, I can achieve so much more now, but where am I putting my time? Where am I putting my time? And then is it too much time? And finding those balances. So yes. Of which then I’ve tried to use AI to question me on that as well. So it’s a, it’s an ongoing work in progress.

Kevin [66:13]: Yes, but AI will start forming its own, its own biases on you and what it thinks you should be doing, because it’s, it’s as you’ve interacted with it more in other areas, it does form its own opinion of it thinks what you should be doing, which is really, really kind of creepy.

James [66:25]: Oh yeah, definitely an evolving process. Yeah. And it’s been good to get your opinion on, uh, the changing nature of, you know, technology teams and roles and how things are going to evolve. So I appreciate your time.

Kevin [66:35]: Oh, thanks, thanks for inviting me, and it’s actually been a really, really enjoyable chat.

James [66:41]: Thanks for listening to this episode of Building Tech Teams. If you’re currently building your technology team, having some challenges, or interested in what’s happening in the market, feel free to hit me up on LinkedIn, forward slash James McDonald AU, or look at my company website ntp-talent.com.au, where we’re helping companies up the East Coast of Australia find and help recruit the best technology talent into their teams. This episode was produced by Day One. Look forward to seeing you on the next episode.