Welcome to Coruscant Technologies, home of the Digital Executive Podcast. Do you work in emerging tech, working on something innovative, maybe an entrepreneur? Apply to be a guest at www.coruscant.com forward slash brand. Welcome to the Digital Executive. Today's guest is Rory Blundell. Roy Blundell is the Chief Executive Officer of Gravity, one of Europe's fastest growing companies and a leader in agentic API and event management. He joined in March 2020 as the Chief Revenue Officer, becoming CEO in September 2020. Under his leadership, Gravity has grown from four people and a half a million dollars in revenue to over 180 employees and more than 40 million in revenue, earning recognition as a Gartner Leader in API Management. The platform delivers consistent security, discoverability, and observability across APIs, event streams, and AI agents, serving organizations across Europe and North America, including Blue Yonder, Walmart, and Ernest & Young. Well, good afternoon, Rory. Welcome to the show. Thank you for having me, Brian. Absolutely, my friend. I appreciate it. And I know you took the time to traverse time zones and calendars to get here today. You're hailing out of London, England, and I know you do quite a bit of travel to the U.S. as well, so I appreciate your time today. And Rory, jumping into your first question here, you joined Gravity as chief revenue officer in March of 2020 and became CEO just six months later, then scaled the company from four people and a half million dollars in revenue to over 180 employees and more than 40 million in revenue. What was it like taking the top job in the middle of a pandemic at such an early stage company? And what conviction did you have about Gravity's mission that made you bet on it? Yeah, great question. I had just taking the second point first, the conviction that I had was I, so I got to know Gravity by installing and using the software myself in actual fact. And I was just amazed at the capability this platform had. I felt that the world at that time, back in 2020, 2021, was going through a shift, probably not as seismic now, looking back at it in retrospect, as the AI world that we're in at the moment. But it was still going through a significant change of people starting to adopt real-time event-based architectures. And what I saw with the company was the ability to pioneer an entirely new space of API and event stream management. So everything that we had done for the last 15 or 20 years with APIs, I thought, hang on a sec, you could do this with event streams as well. And to cut a long story short, we're trying to do the same thing again with agents as well in the agentic world. But that was really what sort of made me think, hey, I'm going to go and take a 50% pay cut. I'm going to go and join this company in the middle of a pandemic and all the crazy decisions, frankly, in retrospect, when I look at it, that I made. it was because I had this fervent belief that we could achieve a lot more and that the foundations of the business were exceptionally strong. That's awesome. Love the story. And again, that's usually the first question here on the podcast is kind of that backstory. And you were from the get-go early on, you were early user of the software impressed by the capability, but the ability to pioneer event streaming with the platform really inspired you and your belief in the company, where it was going, even though it was during the pandemic and the next day to day, just nobody knew what was going to go on with the global economy. So I appreciate the backstory. Thank you. Rory, you've argued that governance frameworks built for the API economy are fundamentally insufficient for the agentic era, that traditional API management platforms are essentially blind to the unique behaviors and risks of AI agents. What specifically breaks down when you point legacy API governance at autonomous agents? Well, I think there's a number of things associated with this that are challenging really for when you look at the technology. The first thing is that agents operate at a fundamentally different speed than we would have had with APIs and things of that nature And so it less I guess it less that the foundations of an API gateway and things of that nature aren't necessarily, they're just not built and architected to be able to utilize those sorts of technologies. So if you've got MCP, for example, a fundamentally different protocol that one would use to be able to mediate agents communicating with tools, for example. Now, behind that tool might be an API fundamentally, but where APIs themselves are maybe not best placed and API gateways as a result of that is that some of these subtle changes, the speed, the types of authentication, the granularity of authorization, authentication, all these sorts of things, because the whole world, not just APIs and API management and API gateways, the whole world was architected around the human being the central point of focus. And there is a seismic, subtle, but seismic shift that has changed that no longer is it the human that's necessarily the sole center of gravity. Excuse the pun. It's also now the agent. And that is a truly, truly differentiated thing that we've never really had to contend with, I would say, any point that I can think of, certainly from a technological perspective in the past. So it's less specifically that it's just, oh, these things, APIs, et cetera, are bad, et cetera, or they're a thing of the past. That's not the case. They're still very, very widely used and still required. But it's just that the mechanisms and the speed and the authentication, the authorization, all of these sorts of things, the paradigms are fundamentally shifted in the new agentic world versus the human world. Absolutely. We're just seeing a major shift across the world in just about every vertical. And APIs is obviously at the forefront of that, in my opinion, as a prior developer. But agents are operating much faster, faster than we've ever seen. And we can't just rely on legacy APIs for this new agentic world that we're moving into. And I appreciate you breaking that apart for us. And I like the pun there as well. Humans are no longer the center of gravity, right? That's awesome. Thank you. Rory, you've said that we're giving AI arms and legs. Would it be reckless not to give it a central nervous system too? Positioning gamma as a control layer that makes the agentic future safe to deploy. Unpack that metaphor for us. What does that central nervous system actually consist of technically? And why is a unified control plane better than bolting governance onto each tool? Yeah, it's a great question. What's the best way to describe this? So let's imagine, for example, in the old world, let's say you've got a door. You've got a door into your office and your door has a keypad next to it. And you've got your keycard and you swipe your keycard on the keypad. Now, historically, what you had to do is the keypad might have been tools like, I don't know, Octa, Ping, things like this. And the door might have been your API gateway. Now, what you had to do is you had to stitch those two things together. And it's very, it's challenging in the modern world when things are operating with non-human identities and stuff like that, to actually have to do all this stitching together when you need to start looking at technologies like fine-grained authorization. You need to really be able to, things like OAuth2, where you have more coarse-grained permissions and all that sort of stuff, don't really work when you've got humans and agents that act on behalf of the humans, which is quite a common thing that we're seeing these days, they're called the on-behalf-of flow. Those two things alone add a layer of complexity that just talks to the fact that really this concept of having the keypad and the door separate, actually what gravity is bringing and our agent management or gamma, as you called it, framework, gives you one platform where in a single place, the first in the world that we've seen, that you've got the keypad and the door in a single platform now. So what that ultimately means let me be fundamentally clear about it I think that businesses have a governance crisis at this particular point in time All the companies that we speak to have this governance crisis The first thing is it a combination of three things that we see. And usually it's multiple of these three things. But the first is they might not even have an enforcement layer. So let me make this point to you, Brian, as a very, very seasoned and experienced executive yourself. If you were to go back 10 years and somebody said to you, hey, Brian, I want to access one of your backend services directly. I don't really want to have to go through a gateway. I don't really want to have to go through any intermediary layer. I would hazard a guess that your reaction would be to jump out of your skin and say, absolutely not. Now, in the modern world, people are doing effectively that with their agents. So they are not having that intermediary layer. And that to me is something that's a massive, massive mistake. You need to have that layer in place because that's where you add the governance. That's where you add the controls. That's where you add things like the cost controls, for example, if you want people not to use so many tokens, if you want to be able to root between different models, if you want to be able to control which particular MCP service a particular agent should be able to use and governing that using things like fine-grained authorization. So that's the first problem. The second problem is the who. So as I said in the past used to have these keypads, the equivalent digital keypad next to your door, and that would be a ping or an optor or something like that. And that was fine when you had coarse-grained and human-based identities. But when you're working with agents that are acting on behalf of humans that should have a subset of their capabilities and a subset of their permissions, where do you store that? Because it shouldn't be subsumed into the end application. And that's one of the challenges that people have had in the past, and they're starting to really have much bigger issues now when you go into the agentic world. And the third part is that those two things, even if you can address those two things, what agents and AI needs more than anything a lot of the time is context. It needs information. Information is almost like the air of a fire. It needs this fuel to be able to get going. And my belief is that those three things, When you look at Gravity and the Gamma platform, what we bring in a single place is a way to be able to address all of these sorts of things. So with capabilities that we've introduced, like our new Daylight product, where you can force the demon level traffic through the gateway so that rather than people saying, oh, I'm just going to go around the gateway or an agent going around the gateway, it goes through the gateway. And therefore, you have your AI controls, your MCP controls, you have all your enforcement layer. And on top of that, because it's in the gateway, you can then use things like fine-grained authorization and very, very fine-grained controls to manage the permissioning and the scopes and all those sorts of things of your agents, both for your agentic and your human identities, for APIs, for event streams, and for the agents themselves. And the last thing is, within Gravity, you now have the ability to connect to third-party repositories, whether it be vector databases and all these sorts of things, or whether it be actually storing it yourself in Gravity. So you can address all those three core things. That, I do believe, is the fundamental answer to the governance crisis people face today. Thank you. A lot to unpack there, but I appreciate it. I love your metaphor, your API metaphor, the door on the key card, right, and the keypad. You talked about the complexity around security agents now working on behalf of humans, but your platform gamma is really integrating that keypad and door together into a single platform. And you talked about governance and security may not have an appropriate security layer. You talked through that validating who has access and in that context that it needs in order to seamlessly make this secure. So I appreciate that. And the last question of the day, Rory, you've predicted that before long, the same LLMs running in enterprise software will be running the machines on factory floors and in warehouses with robotics not far behind. As you look five years out, maybe less, what does a fully governed agentic enterprise actually look like? And what has to be true technically organizationally and in terms of standards for organizations to scale AI agents with confidence rather than caution that a great question it a complex one And what I fundamentally think the answer to this is that this is something I been grappling with I spent a lot of time recently unpacking a lot of the legislation that people are, that legislatures both in the European Union, but also in the US, different states are introducing AI legislation. So I've been looking a lot at this. And fundamentally, what I've concluded is that in order for people to have the confidence to be able to utilize and leverage AI to its fullest extent and to make the greatest economic gains that it could be, I do think you have to solve that governance crisis that I spoke about in the last point. But there's one additional point that I didn't necessarily talk about that I do think you need to be able to address that I don't think I've seen a good implementation of yet, which is this concept, a term that's probably bandied around that I'm sure you've heard it a number of times, Brian, which is human in the loop. It's a very interesting concept. And when you look at the technical implementations at the moment, my view is what you really need is you need to, first of all, implement all of your AI ecosystem and your AI infrastructure must go through a central point of governance and control. I think that is the starting point. I really strongly believe it must go through a central governance control point, because unless you have that, you will have no mechanism to be able to control what happens. Now, if you were to ask the average person on the street and say, OK, that's my starting point. What people are and you look at a lot of the legislation and when I've spoken to people and interviewed them about this. I think what people want is a mechanism and a way for agents and humans to work in harmony. If you look at a lot of the reporting about this subject to the moment, what you find is it's almost a zero sum game when one loses, the other one wins and all that sort of stuff. And in actual fact, what you need in order to what I think people want, which is this type of human in the loop type of interaction. You need to have that central point of governance control first. Once you've got that, what we've introduced, for example, with Gamma is you can now bring your own model. So in the gateway, what we're now doing is classifying the stuff that comes through the gateway such that you can say, well, at this particular point in time, now you need a human to go and take the action. And you can then have a very temporary entry into the fine grained authorization rule set or policy structure that basically says the next action that's taken must come from the human in the loop. Now, the reason why this is important is it's very easy for organizations to generally have a set of yes, no rules, permit, deny rules for a finite set of very risky things. But what happens when it's not about a very, very risky thing, when you want a human to be able to guide an overall process to say, well, this is the sort of thing I want the agent to be doing. No, it really needs to get my approval for this. You can't really do it. And this is where I think that having the central point of governance control, where you can do things like bringing your own model, you can then make classification decisions about should you do human in the loop? Should you not? Do you have a portal to enable humans to be able to interact with it? Things of that nature. That, from my perspective, is what is critically important to be able to enable humans and agents to work in harmony. And that is what I spend so much time thinking about. That's awesome. Thank you. And I'll just highlight a few things here. I definitely agree with you. There's a lot of AI legislation that is really starting to be at the forefront of every conversation now. I've seen that local and national level of governments, as everybody wants to solve this governance issue, right? I want to just highlight that human loop you talked about. At the core of this, you talked about this AI development, the AI infrastructure must go through a centralized governance control. and at the end of the day, people want a framework that allows agents and humans to work in harmony. I thought that was pretty interesting for sure and I see it in my everyday work life as well. So thank you. Rory, it was such a pleasure having you on today and I look forward to speaking with you real soon. Thank you, Brian. It was a pleasure speaking with you. Have a lovely day. Bye for now. you