YouTube2Text

Fost India 2026 - Restoring Trust in AI-Native Development | apidays India 2026. — Transcript

by apidays · 6,940 words · 998 segments · language en · Watch on YouTube

Full transcript

  1. 0:07Good morning everyone.
  2. 0:09Hope you had a good conferencing day
  3. 0:13yesterday which is probably why you're
  4. 0:15here on time today. Uh but we'll get
  5. 0:18started. I think there's been a lot of
  6. 0:21discussion around uh we want to make the
  7. 0:24agents autonomous and I always joke that
  8. 0:27we've not got humans autonomous. We're
  9. 0:29trying to get agents autonomous. So
  10. 0:31that's a bit of a stretch. But I think
  11. 0:34there's been a lot of uh interesting
  12. 0:36work that's been happening in the last
  13. 0:38uh at least two years to move towards
  14. 0:40this direction. And I'm going to share
  15. 0:43some of my uh experience having worked
  16. 0:46with lots of enterprises in terms of how
  17. 0:49we are approaching this. I don't think
  18. 0:51we have an answer uh but we have a
  19. 0:53direction and that's kind of what I'm
  20. 0:55going to try and present here. Um but
  21. 0:59the first question to ask is why do we
  22. 1:01want the agents to be autonomous?
  23. 1:04What is that we are trying to achieve?
  24. 1:08Right? My hypothesis is that every
  25. 1:11organization wants to optimize the idea
  26. 1:14to cash cycle, right? And agents are a
  27. 1:18great way to accelerate that to get
  28. 1:20faster. And so that is one of the
  29. 1:23motivations at least is to optimize this
  30. 1:25to reduce the time to market to be more
  31. 1:28responsive etc etc. And this is not new.
  32. 1:31I mean as as a industry as software uh
  33. 1:35we've been doing this for many many
  34. 1:37years and there have been two kind of uh
  35. 1:41big ideas that uh we have been uh
  36. 1:43putting to use uh for many years in
  37. 1:46terms of optimizing the concept to cache
  38. 1:49uh cycle. One is modular production
  39. 1:53which is basically defining components,
  40. 1:55defining modules, having a clean
  41. 1:57interface between them and allowing them
  42. 2:00to be built parallelly so you can
  43. 2:01assemble rapidly and get it out. Right?
  44. 2:04So this is one way of uh basically
  45. 2:08reducing the time to market right and
  46. 2:11the other is uh just in time which is
  47. 2:13again very important from minimizing
  48. 2:16inventory and optimizing flow. Um so
  49. 2:20these two two two ideas have been around
  50. 2:22with us for many many years and we've
  51. 2:24been trying to do this and since this is
  52. 2:26API days conference I'm going to try and
  53. 2:29uh map this to what does this mean uh
  54. 2:32you know to APIs right so if you think
  55. 2:36of modular right I believe uh we've kind
  56. 2:39of now established that you know APIs
  57. 2:42are kind of the Lego blocks right the
  58. 2:44building blocks by which we can assemble
  59. 2:47integrate and build products rapidly,
  60. 2:50right? So we can reuse, we can uh you
  61. 2:53know basically bring things very rapidly
  62. 2:55together and go from concept to idea in
  63. 2:58a very short cycle. U
  64. 3:01however
  65. 3:03we've had several challenges along the
  66. 3:05way, right? And one of the challenges to
  67. 3:09really talk about is what's happened in
  68. 3:11the last I would say 15 years at least
  69. 3:14in the you know the desire to move from
  70. 3:16monoliths to microservices expose
  71. 3:19everything as interfaces actually it's
  72. 3:21interesting to see uh who would you give
  73. 3:25credit to in terms of uh coming up with
  74. 3:28this idea any thoughts
  75. 3:36Uncle Bob.
  76. 3:37>> Uncle Bob. No, no, no, no.
  77. 3:44>> Who actually made the case? Uh, I mean,
  78. 3:47of course, this is debatable. Uh, so I'm
  79. 3:49going to present my viewpoint, but I
  80. 3:51would say the credit should go to Jeff
  81. 3:53Bezos
  82. 3:55for really pushing with the API mandate.
  83. 3:58uh he wrote a letter uh you know across
  84. 4:01Amazon to all the development team all
  85. 4:03the engineering team saying going
  86. 4:05forward everything should be built so
  87. 4:08that it can be uh exposed as a standard
  88. 4:12interface and integrated uh it doesn't
  89. 4:14matter if you're building internal stuff
  90. 4:15or external stuff everything should have
  91. 4:18a clear service boundary and your
  92. 4:20implementation can be in whatever
  93. 4:21language you care I don't care but it
  94. 4:24should essentially be remote procedure
  95. 4:28invocation with a clear service
  96. 4:29interface, right? And so,
  97. 4:32of course, there are a lot of other
  98. 4:34folks who've also had this idea. And so,
  99. 4:37uh, we've gone through this, but one of
  100. 4:39the big challenges you will see when you
  101. 4:41move from a monolith to microser is you
  102. 4:44lose the compiler safety, right?
  103. 4:48Anyone's had this challenge?
  104. 4:52When you had a monolith, you had like a
  105. 4:54lot of feedback you could get. If you
  106. 4:56made a function call, you missed a
  107. 4:58mandatory parameter. You know, it would
  108. 5:01be a compile time error. When you do
  109. 5:03this across a network boundary, it's not
  110. 5:06easy to get this feedback. And where
  111. 5:08this becomes interesting is when you
  112. 5:10deploy agents at scale, uh the problem
  113. 5:13gets amplified, right? So the problems
  114. 5:16of things like you know not having the
  115. 5:19compiler safety now becomes a runtime
  116. 5:21issue and this is where the problems
  117. 5:24kind of start amplifying. So what do we
  118. 5:27do to to kind of uh deal with this
  119. 5:29problem? Right? Before we kind of jump
  120. 5:32into the solution, let's kind of quickly
  121. 5:34take a quick analogy to just put things
  122. 5:36into perspective. Right? Uh so anyone's
  123. 5:40been at a really good highway where you
  124. 5:43eventually end up with a single booth or
  125. 5:45a few booths and you have to pay toll
  126. 5:47before you can move and you see a
  127. 5:50massive congestion, right? So you're
  128. 5:53building these massive
  129. 5:55parallel highways so that people can you
  130. 5:58know go really fast but then you
  131. 6:00introduce these artificial uh
  132. 6:03constraints which really bottleneck
  133. 6:06people right and so uh you can draw
  134. 6:09analogy to software right everyone can
  135. 6:13draw an uh can can apply this back to
  136. 6:15your teams and software
  137. 6:23like a lot of companies I I still think
  138. 6:26have these central teams uh which are
  139. 6:28kind of the toll boots uh and they
  140. 6:31essentially block uh the path to
  141. 6:33production. Uh I'm not saying that's a
  142. 6:35bad thing. What I'm saying is
  143. 6:37essentially this becomes a bottleneck in
  144. 6:39the system. And so I think over the last
  145. 6:4220 years maybe because of agile devops
  146. 6:45and a lot of things that have happened
  147. 6:47uh people have moved to what we call a
  148. 6:49streamalign teams uh where they are
  149. 6:51self-contained teams they have all the
  150. 6:53cross functional capabilities and so if
  151. 6:56you kind of apply that to this analogy
  152. 6:59essentially what you're doing is you're
  153. 7:01basically introducing a toll booth per
  154. 7:03lane
  155. 7:05yeah
  156. 7:07and I would say this is much better than
  157. 7:09what we had before but this is not what
  158. 7:12will get us to that concept to cache in
  159. 7:15few days uh kind of a thought process
  160. 7:18that we have right so if you really want
  161. 7:21to move to that what you need to do is
  162. 7:23you need to make sure that the vehicles
  163. 7:26don't stop
  164. 7:28the flow does not get impacted right so
  165. 7:32if you if you do things which allow
  166. 7:35things to move seamlessly so in case of
  167. 7:37like a lot of countries have implement
  168. 7:39mented this where you don't have to stop
  169. 7:41at a toll booth you just keep driving
  170. 7:44right and you use RFIDs and other kinds
  171. 7:46of things which automatically you know
  172. 7:48charge right so uh what is the
  173. 7:50equivalent of that in software that we
  174. 7:53are trying to do
  175. 7:59>> uh autonomous agents feel like the
  176. 8:01second one to me
  177. 8:05at least as of today because in a lot of
  178. 8:08companies you are deploying autonomous
  179. 8:10agents. The agents are producing things
  180. 8:13at a very rapid pace and then you have
  181. 8:16someone who has to review that. That's a
  182. 8:18toll booth.
  183. 8:26>> So some people say okay we're going to
  184. 8:27in add more agents who are going to
  185. 8:30automate the toll boots, right? Uh but
  186. 8:33then I've not at least met any large
  187. 8:36enterprise that can completely trust uh
  188. 8:39nonhuman
  189. 8:41uh you know toll boots if you will uh to
  190. 8:44let things just go to production. Some
  191. 8:46have tried and then they have regretted
  192. 8:49uh we've seen all those stories. uh so I
  193. 8:51don't think we are yet at the stage
  194. 8:53where you can say that we have
  195. 8:55completely achieved a a flow in your
  196. 8:58software delivery which has basically no
  197. 9:01uh stopping no toll boots right it's
  198. 9:03just seamlessly flowing
  199. 9:06so
  200. 9:10let's quickly move forward uh so we are
  201. 9:13not the first to actually have this
  202. 9:16problem so I'll again draw another
  203. 9:18analogy from uh textile. Anyone's
  204. 9:22familiar with uh looms, right? If you
  205. 9:25live in Bangalore, probably you should
  206. 9:27be familiar with looms because this used
  207. 9:29to be a pretty massive uh silk
  208. 9:32manufacturing hub. Uh those places got
  209. 9:35taken over by software factories and you
  210. 9:37know you see the history repeats itself
  211. 9:39in some sense. So uh back in the days
  212. 9:42you would have uh hand looms where a
  213. 9:45craftsman would sit and basically handw
  214. 9:47weave cloth uh and produce really
  215. 9:50beautiful design but it was a very much
  216. 9:52a craftsman uh ship approach to building
  217. 9:55cloth right
  218. 9:58of course this had limited uh errors and
  219. 10:02it was kind of uh well controlled uh but
  220. 10:05you know you couldn't like really
  221. 10:06massroduce so during the second world
  222. 10:08war or even probably the first world
  223. 10:10about people wanted to mass-roduce cloth
  224. 10:13and this was not a solution.
  225. 10:15So we had the next wave which is the uh
  226. 10:20power looms right uh which basically
  227. 10:23meant that you could uh now mass-roduce
  228. 10:25cloth but unfortunately when power looms
  229. 10:28were originally introduced you would see
  230. 10:30something like this at every loom one
  231. 10:32person standing and watching the loom.
  232. 10:36Yeah. And so if you had a factory of 30
  233. 10:39looms, you would have like 30 people
  234. 10:41standing and watching the loom. To me,
  235. 10:43this is very similar to what we have
  236. 10:45today in software, right? We've hit the
  237. 10:47power loop moment with uh agents, but we
  238. 10:51don't fully trust the agents. And so we
  239. 10:54basically put one human at every and we
  240. 10:58call it human in the loop. Uh which is
  241. 11:00kind of uh very nice. Uh but you know
  242. 11:03essentially you're putting uh a human to
  243. 11:06kind of monitor this right but of course
  244. 11:09if you fast forward today uh you
  245. 11:12wouldn't see in any factory stuff like
  246. 11:14this. So what did what did the textile
  247. 11:17factory do to basically change this
  248. 11:19scenario
  249. 11:21right? So we could draw some inspiration
  250. 11:23from that and that's kind of the crux of
  251. 11:24my talk is basically what are the things
  252. 11:27we can draw and one company that
  253. 11:28particularly pioneered this is a company
  254. 11:31called Toyota. It's a precursor to
  255. 11:33Toyota. And what they ended up building
  256. 11:36is they ended up building these
  257. 11:38autonomous looms uh which essentially
  258. 11:42had all kinds of sensors built into the
  259. 11:45loom and that's generally now referred
  260. 11:47to as building quality in. So the loom
  261. 11:50would basically be self it's an
  262. 11:53autonomous loom. it'll run on its own
  263. 11:55and if something goes wrong it'll
  264. 11:57basically stop and ask a human to come
  265. 12:00and basically fix things right uh in
  266. 12:03fact they kind of evolved further uh I
  267. 12:06believe they have about 118 patents if
  268. 12:08I'm not wrong on just one loom and all
  269. 12:10the kinds of interesting things they
  270. 12:12have done to basically make the loom as
  271. 12:14autonomous as possible so today in most
  272. 12:17places you would go you would see a
  273. 12:19factory with 100 looms managed by one
  274. 12:21human
  275. 12:23Right. And that's to me kind of the
  276. 12:26aspiration or where you know I would
  277. 12:29personally like uh our industry to go
  278. 12:32right where you don't need uh 100 humans
  279. 12:36sitting in front of a uh agent and be
  280. 12:39becoming the toll boot to the agent
  281. 12:41right so how do we get there is is kind
  282. 12:44of the question and there are some
  283. 12:46principles we will talk about that
  284. 12:47actually help them achieve that. Uh but
  285. 12:50before that I thought it'll be
  286. 12:51interesting for those who have not been
  287. 12:52to a power loom to see a quick uh video
  288. 12:56on this thing. Okay,
  289. 13:02that's how a power loom works. You don't
  290. 13:04see a human there. And this is uh just
  291. 13:08showing you when a thread breaks because
  292. 13:10that's one of the main challenge in in a
  293. 13:12power loom is the thread snaps. uh and
  294. 13:15so they built in these kinds of systems
  295. 13:17which basically as soon as the thread
  296. 13:19breaks the liver goes and jams the
  297. 13:21machine. So it kind of stops uh the
  298. 13:24machine from continuing with an error.
  299. 13:27Right? So these are checks built into
  300. 13:30the machine not inspection not some
  301. 13:34human watching over this. Right? And so
  302. 13:36this is kind of the uh one of the
  303. 13:38innovations that uh that they did. And
  304. 13:41so this is referred to as if you look at
  305. 13:43the principle it's referred to as jidoka
  306. 13:46uh this is a Japanese term uh for
  307. 13:49basically what what the term means is
  308. 13:51automation with human touch because it's
  309. 13:54a little politically incorrect to say uh
  310. 13:57automation without human touch right u
  311. 14:01but technically uh you would see that
  312. 14:03philosophy has uh you know in everyday
  313. 14:07life things that we use so if you've
  314. 14:09ever used a washing machine and let's
  315. 14:11say the washing machine halfway through
  316. 14:13the wash cycle water stops
  317. 14:16there are sensors built into the machine
  318. 14:18that will not like just continue to wash
  319. 14:20your clothes and say oh even though
  320. 14:22water I will just wash it and give it to
  321. 14:24you right there are sensors built into
  322. 14:26it it'll stop uh another example that's
  323. 14:29very popular is in the elevators right
  324. 14:32when the door is closing there are
  325. 14:34sensors in the door if you try to if
  326. 14:36some someone is in between then the the
  327. 14:38doors will unlock right it don't
  328. 14:40continue to go through. So these are all
  329. 14:42kind of mechanisms which basically makes
  330. 14:44them autonomous right which which
  331. 14:47basically helps them achieve this. What
  332. 14:49is the equivalent of this uh in APIs?
  333. 14:59So I would say something like having a
  334. 15:02pre-commit hook, right? Before you push
  335. 15:05any change, you want to basically run a
  336. 15:08battery of tests, right? What whatever
  337. 15:10it could be linting, it could be uh
  338. 15:12contract tests, it could be backward
  339. 15:14compatibility checks, etc. And if if any
  340. 15:17of those checks fail, you want to
  341. 15:19basically stop uh the commit going out.
  342. 15:23Right? So that's kind of my example of
  343. 15:27uh how we've tried to apply this is
  344. 15:29before agents, right? This is how we've
  345. 15:31tried to take some inspiration from this
  346. 15:33principle and apply this uh in uh in our
  347. 15:36work.
  348. 15:38The next principle I want to talk about
  349. 15:39is poo yoke. Uh poker yoke is
  350. 15:43essentially mistake proofing. Uh and
  351. 15:46again we've seen a lot of examples of
  352. 15:48this. Anyone remember uh USB 2 or USBA?
  353. 15:53Uh you have to always figure out which
  354. 15:55direction because it doesn't like you
  355. 15:57can't just put it in any direction. And
  356. 15:58so when you move to USBC, uh you don't
  357. 16:02care anymore, right? You can put it,
  358. 16:03it's just you don't have to worry about
  359. 16:06the side or the direction. So it's one
  360. 16:08way of mistake proofing so people don't
  361. 16:10try to jam something. Sockets are
  362. 16:12another example. Uh so are uh you know
  363. 16:15SD cards or your SIM cards, all of them
  364. 16:17kind of have a similar uh philosophy
  365. 16:20where you design something that it is
  366. 16:22not possible for you to make a mistake,
  367. 16:25right? So it's mistake proofing. So what
  368. 16:27is an example of mistake proofing in
  369. 16:30APIs?
  370. 16:38>> Contract testing seems a little bit as a
  371. 16:41uh the previous example to me not
  372. 16:43necessarily a mistake proofing but more
  373. 16:46of a sensor that kind of tells you
  374. 16:49something's wrong. Right?
  375. 16:53So if you take this example where you
  376. 16:55say okay I have uh you know I can post
  377. 16:57an order and uh status is a is a string
  378. 17:01uh and I've written a beautiful comment
  379. 17:03that it should be one of these three
  380. 17:05things right uh but this doesn't stop
  381. 17:08someone from sending a status which is
  382. 17:11not one of those three things
  383. 17:14then you'd have to put a sensor to stop
  384. 17:17someone from doing that right but if you
  385. 17:19were to mistake proof this so that it's
  386. 17:21not possible at all. Then you would
  387. 17:23essentially define an enum and say it
  388. 17:26has to be one of these three values.
  389. 17:30Right? So that's kind of I would say an
  390. 17:32example of mistake proofing in in the
  391. 17:35context of APIs. Right? And quickly I
  392. 17:39want to touch upon the third principle
  393. 17:41which is very important because these
  394. 17:43have a dizzy chain effect and they kind
  395. 17:44of work with each other is andon. and uh
  396. 17:48the idea with andon is essentially if
  397. 17:50something goes wrong make it visible as
  398. 17:52quickly as possible so an action can be
  399. 17:55taken a corrective action can be taken
  400. 17:57an example is you you see this every day
  401. 18:00in your uh cars for example if your tire
  402. 18:02pressure is low the car can sense that
  403. 18:05and put it on the dashboard so you know
  404. 18:07about it and you don't drive halfway
  405. 18:10through and then have a flat tire right
  406. 18:13uh so these are kind of giving you
  407. 18:14feedback so that you can avoid
  408. 18:17uh you know problems later. Uh same
  409. 18:21concept uh with you know your fire
  410. 18:25sensors. uh all of these are again kind
  411. 18:28of idea to kind of give you the feedback
  412. 18:30so that you can uh you know you know now
  413. 18:33quickly moving to and in case of API
  414. 18:37what would be the example running things
  415. 18:40in CI and when they fail you get a very
  416. 18:42visual feedback saying hey you know
  417. 18:44something's wrong uh and then that kind
  418. 18:47of stops uh bad things it notifies
  419. 18:50people and so whoever pushed this commit
  420. 18:52can actually uh address this right uh so
  421. 18:56So just to quickly summarize then
  422. 18:57putting all three principles together uh
  423. 19:00the way I kind of look at it is uh you
  424. 19:03know pok is essentially mistake
  425. 19:05proofing. uh in spite of mistake
  426. 19:08proofing you may still end up with some
  427. 19:10challenges and this is where you would
  428. 19:12use DTO to kind of uh sense and stop
  429. 19:15things from going bad and then when
  430. 19:17things do slip through and show up then
  431. 19:21typically during integration or in your
  432. 19:23CI you would essentially make it visible
  433. 19:25and then any learnings that come back
  434. 19:27from it circles back and you mistake
  435. 19:30proof it right and so this is kind of a
  436. 19:32principle that we've been applying uh
  437. 19:34for a long time I would say at least at
  438. 19:36least extreme programming made some of
  439. 19:38these things uh quite popular right so
  440. 19:41uh I've given some examples in software
  441. 19:44that kind of translate to that but how
  442. 19:48does this relate to agents
  443. 19:52what can we do with these principles to
  444. 19:54make agents autonomous
  445. 20:02you already probably seen a lot of uh
  446. 20:04this kind of stuff where We're moving
  447. 20:06from VIP coding to things like
  448. 20:09specdriven development and we're trying
  449. 20:11to say okay you know if you provide a
  450. 20:13spec uh the agents will probably do a
  451. 20:16much better job than just giving them
  452. 20:18some prompts right uh and in some sense
  453. 20:22there are bunch of uh principles baked
  454. 20:25into this idea and uh if you were to
  455. 20:28kind of doubleclick on it essentially
  456. 20:31what we are saying in this new uh
  457. 20:33specdriven development paradigm
  458. 20:36Spec is the new source code,
  459. 20:40right? Spec is the new source code
  460. 20:42because that's the level of abstraction
  461. 20:44at which humans will operate and
  462. 20:47whatever code is generated as equivalent
  463. 20:49to assembly or bite code. So you don't
  464. 20:51really care about it. Uh every time you
  465. 20:53just recompile, you throw away and you
  466. 20:55start from scratch, right? uh not
  467. 20:58everyone's fully onboarded with this
  468. 21:00idea but that's kind of where uh you
  469. 21:02know like if you see the industry is
  470. 21:04going is moving towards specifications
  471. 21:07being source of truth. One other
  472. 21:10interesting idea is uh harness
  473. 21:12engineering and uh recently I think
  474. 21:14there was a interesting blog on Martin's
  475. 21:17uh Martin Fowler's site where uh they
  476. 21:20tried to kind of classify this into a
  477. 21:22little bit more uh categories. So you
  478. 21:25have guides which basically give
  479. 21:27feedback to the agent so that the first
  480. 21:31uh generation of code that the agent
  481. 21:33would do is guided based on certain
  482. 21:36things right so we've all written
  483. 21:38agents.mmd file we've written a bunch of
  484. 21:40we provide a bunch of skills uh which
  485. 21:43essentially you know act and then again
  486. 21:45uh you know you can have both uh
  487. 21:48inference-based things so any MD file
  488. 21:50and things like that you're writing is
  489. 21:52more inference based so the agent will
  490. 21:54have to infer it, derive what you're
  491. 21:56trying to say and then uh guide itself.
  492. 21:59And there are also some computational
  493. 22:01things which are not necessarily just
  494. 22:03inference based but they are something
  495. 22:05that the agent can execute as a way to
  496. 22:07get feedback and move forward. Right? So
  497. 22:10you've got the initial generation done
  498. 22:12which typically we call as the forward
  499. 22:14loop. Uh but that is not sufficient.
  500. 22:17Right? Once the agent has produced
  501. 22:19something, you do want to then use a set
  502. 22:22of sensors. And this is kind of your
  503. 22:24judokco in action, if you will, uh where
  504. 22:26you're essentially providing feedback to
  505. 22:29the agent saying, "Oh, you you produce
  506. 22:31this, but you kind of dropped, let's
  507. 22:33say, the code coverage or you didn't
  508. 22:35write tests or you you made this
  509. 22:38architectural mistake, right?" So, you
  510. 22:40kind of provide that feedback. So it
  511. 22:42goes into a self-correcting loop uh and
  512. 22:44and provides you the response finally
  513. 22:48right and again while all of this is
  514. 22:50happening human is still in the loop in
  515. 22:52some sense uh because the human is kind
  516. 22:55of watching what's happening and maybe
  517. 22:57steering not all the time sitting in
  518. 23:00front of it but maybe at some regular
  519. 23:02intervals you may want to steer that
  520. 23:04right so this is uh kind of harness
  521. 23:06engineering if you were to try and
  522. 23:08extrapolate this to like API specific
  523. 23:11specifically what are the what are the
  524. 23:14guides and sensors in case of APIs right
  525. 23:17so if I were to quickly just jump ahead
  526. 23:20uh what you will see is you know you can
  527. 23:22feed in like API best practices uh you
  528. 23:26can feed in things like API
  529. 23:27specifications you can give in examples
  530. 23:30uh you can give in agent plugins which
  531. 23:32are skills and uh MCPS packaged together
  532. 23:35uh these all can act as guides for the
  533. 23:38agent when it's producing the code it'll
  534. 23:42keep these things in mind and produce
  535. 23:44things right what are the kinds of
  536. 23:46sensors when it comes to uh APIs
  537. 23:54>> absolutely so contracts uh contract
  538. 23:56tests mock compatibility tests these are
  539. 23:59all important things like resiliency and
  540. 24:01security test becomes important llinters
  541. 24:03and other policies become important you
  542. 24:05can execute them and kind of give
  543. 24:07feedback you can look at things like API
  544. 24:10coverage
  545. 24:11uh not just code coverage but API
  546. 24:13coverage and kind of use that as a
  547. 24:15feedback again to the agents to say hey
  548. 24:17you've not covered these scenarios and
  549. 24:19things like that. So uh there's quite a
  550. 24:21lot of work happening in this space both
  551. 24:23on the guides and sensors to basically
  552. 24:25make API design lot more autonomous uh
  553. 24:28with the agents.
  554. 24:31uh but it doesn't have to stop here
  555. 24:33right this kind of can apply throughout
  556. 24:36the uh SDLC process in terms of even at
  557. 24:39further stages in the pipeline in
  558. 24:42production you can have a constantly
  559. 24:44learning running loop to basically do
  560. 24:46drift detection and so forth so that you
  561. 24:49can feed that back to the agent so they
  562. 24:50can selforrect right so it doesn't have
  563. 24:52to stop at the first uh generation of
  564. 24:55the code it can go all the way uh into
  565. 24:58your pipelines it can go all the way
  566. 25:00into production and keep the loop
  567. 25:02running, right?
  568. 25:05And I think there's a lot of promise
  569. 25:06with hardness engineering. A lot of work
  570. 25:08is happening with hardness engineering.
  571. 25:10But I would ask myself, is hardness
  572. 25:13engineering sufficient?
  573. 25:17Will that really help us achieve the v
  574. 25:20the dream of autonomous agents?
  575. 25:25And that's kind of where you start
  576. 25:27wondering about what happens to things
  577. 25:29like your architecture, overall
  578. 25:32architecture, not just an individual
  579. 25:34API, but the whole system architecture.
  580. 25:37What about things like governance? Uh,
  581. 25:39you know, would would it be able to
  582. 25:41handle all of those kinds of things? So,
  583. 25:43just kind of again like if you have
  584. 25:44guides uh that help the coding agent,
  585. 25:47you have sensors which basically are
  586. 25:49executable specifications which kind of
  587. 25:51guide the thing. So that's an important
  588. 25:53thing at a individual API level but a
  589. 25:57system is not just an individual API
  590. 25:58level right. So typically when you have
  591. 26:01some kind of an intent that you're
  592. 26:03trying to uh communicate how do you make
  593. 26:07sure that what you are thinking is being
  594. 26:11effectively communicated to an agent.
  595. 26:14Right? So there's a term that is
  596. 26:16emerging for this which is called
  597. 26:17executable intent which means that you
  598. 26:21are able to express the intent and
  599. 26:23validate the intent before you actually
  600. 26:26give it to the agent to make sure that
  601. 26:28what you're thinking is actually machine
  602. 26:31understandable agent understandable
  603. 26:33right and there are things where you can
  604. 26:35go from like plain English uh to an
  605. 26:38executable specification you can spin up
  606. 26:41a sandbox in which you can actually
  607. 26:43prototype type uh and figure out whether
  608. 26:47you know if this is your business case
  609. 26:49whether it has captured it correctly in
  610. 26:51terms of an API specification and when I
  611. 26:54mean an API specification it's not just
  612. 26:56open API specification it's things like
  613. 26:58aradozo it's things like which allow you
  614. 27:00to orchestrate an entire workflow right
  615. 27:02so it allows you to capture that
  616. 27:04simulate that whole thing so that you
  617. 27:06would be able to validate it's it's
  618. 27:09almost like Figma for API design if you
  619. 27:12will right where you can quickly
  620. 27:14uh do high fidelity prototyping and kind
  621. 27:17of execute your intent and validate
  622. 27:19whether your intent is what you need.
  623. 27:22Right? So that's one idea that we've
  624. 27:24been working on. Lots of other folks are
  625. 27:26also doing a lot of interesting work in
  626. 27:28this space. The next one is what we call
  627. 27:30as executable architecture. Uh the idea
  628. 27:33with executable architecture is that
  629. 27:36individual APIs is fine but across the
  630. 27:39several different integration patterns
  631. 27:41that I have. It could be uh restful
  632. 27:43integrations, it could be asynchronous
  633. 27:45integrations, it could be uh file-based
  634. 27:48integration, CLI based integration,
  635. 27:50several other forms of integration. How
  636. 27:52do I define all of that? Not in a
  637. 27:55document which is again inference-based
  638. 27:58but a document which is executable. a
  639. 28:02document that I can actually click a
  640. 28:04button, spin up my entire architecture,
  641. 28:08right? And then be able to kind of test
  642. 28:11itself, right? So, one of the ideas that
  643. 28:14you would see that is emerging is kind
  644. 28:16of using a combination of Arazzo
  645. 28:19specification with uh open API
  646. 28:21specification, a sync API specification,
  647. 28:24and then spinning up a mock for the
  648. 28:26entire system. So you have all the
  649. 28:28pieces that that basically spin up as a
  650. 28:31mock and then you use the same
  651. 28:33specification to then generate a test
  652. 28:35from it and so it gives you uh a set of
  653. 28:38tests that will run against the mock. We
  654. 28:40call it the closed loop uh test. And
  655. 28:43what this will do is it'll help you
  656. 28:45visualize if this is how you're
  657. 28:46envisioning your architecture to be
  658. 28:48whether it makes sense, right? You know,
  659. 28:51so before you've actually built a single
  660. 28:52line of code, before you even ask the
  661. 28:54agent to build anything, you want to
  662. 28:56kind of quickly validate your
  663. 28:58architecture itself, right? So that's
  664. 29:00again another uh I would say idea on top
  665. 29:03of harness engineering that would allow
  666. 29:05you to uh you know validate your
  667. 29:07architecture and keep this loop going
  668. 29:10right. So as as components get built
  669. 29:12they get plugged in but the overall
  670. 29:14feedback loop on your architecture to
  671. 29:17make sure that you're not drifting. You
  672. 29:19intended this to be asynchronous. It
  673. 29:21should not suddenly become synchronous.
  674. 29:23Right? Those kinds of things can be now
  675. 29:25validated at this level. Is that
  676. 29:27sufficient? Are we good with these two
  677. 29:30things? Is there anything missing?
  678. 29:35I would say there's one other important
  679. 29:36thing which is the governance thing but
  680. 29:39not the current style of governance that
  681. 29:42a lot of places we are seeing. What we
  682. 29:44want is essentially again a continuous
  683. 29:47governance which is kind of a control
  684. 29:49plane uh taking feedback and providing
  685. 29:52feedback to each of these. So just to
  686. 29:54give you a little bit more context, when
  687. 29:56I'm trying to do executable intent, uh
  688. 29:58let's say I'm going from a plain English
  689. 30:01intent to a executable specification, I
  690. 30:04don't want to reinvent things that
  691. 30:06already exist,
  692. 30:08right?
  693. 30:10How how does how does the agent know
  694. 30:12when it's going from plain English to an
  695. 30:14executable spec that this already
  696. 30:16exists?
  697. 30:19Today in a lot of organizations we don't
  698. 30:22have a single view of the uh API
  699. 30:26inventory that exists in your
  700. 30:28organization even if you have it's it's
  701. 30:30in lots of different formats which is
  702. 30:32not very friendly for an agent to
  703. 30:34understand
  704. 30:36right so imagine you had a kind of
  705. 30:39central repository of all your
  706. 30:41specification you don't need the details
  707. 30:43but mostly the metadata which an agent
  708. 30:46can understand and that can be fed into
  709. 30:48this upper cycle there executable intent
  710. 30:51cycle and so it can basically uh
  711. 30:54leverage what is already there not
  712. 30:56rebuild it so avoids duplication and
  713. 30:59stuff like that it can reuse schemas
  714. 31:01that already exists so for example if
  715. 31:03shipping address is already defined in
  716. 31:05your system you don't want to build a
  717. 31:07different uh implementation of a
  718. 31:09shipping address again right so all of
  719. 31:11those things can be leveraged back in
  720. 31:14this and also same thing applies at
  721. 31:16executable architecture level these all
  722. 31:18kind of feed into each other. So there's
  723. 31:20almost you can imagine a loop going
  724. 31:22around this whole thing, right? So you
  725. 31:25have executable intent, you have
  726. 31:26executable architecture, you have the
  727. 31:28harness in between and then you have
  728. 31:30governance which is kind of your control
  729. 31:32plane. So all put all of this together
  730. 31:34is what I think we calling as closed
  731. 31:36loop engineering. And this is
  732. 31:40I'm not sure if this is sufficient but
  733. 31:42it is uh at least something that we're
  734. 31:45all kind of building towards as we go uh
  735. 31:47to figure out if this can help avoid a
  736. 31:50lot of challenges that we are seeing to
  737. 31:52avoid kind of the toll booth right so
  738. 31:54just to again quickly summarize
  739. 31:58uh what we are saying is you want
  740. 31:59autonomous generation you want
  741. 32:01validation against executable
  742. 32:03specification you want any deviation to
  743. 32:06be detected and uh removed uh you then
  744. 32:09want the correction the sensors to auto
  745. 32:11feed in and then that leads to a
  746. 32:13continuous flow which allows you to
  747. 32:15trust the output before a human gets it.
  748. 32:18Right? So all of this happens uh before
  749. 32:21you actually look at it and so the trust
  750. 32:25in what the agents are doing would go up
  751. 32:27and hence probably you'll stop putting a
  752. 32:30human in front of an agent and slowing
  753. 32:32it down. Right? So I think that's pretty
  754. 32:35much uh what I had. I am uh
  755. 32:39I wanted to leave uh time for questions.
  756. 32:42So I think it's good time. We have 10
  757. 32:44minutes if I'm not wrong or 8 minutes
  758. 32:46for questions.
  759. 32:48Yes. Can someone please help with the
  760. 32:50mic?
  761. 33:00>> So my question is on the previous closed
  762. 33:02loop diagram that you just showed.
  763. 33:04>> Yeah. So what if we have an ability to
  764. 33:07treat that whole thing as a skill and
  765. 33:09then put it in a continuous uh
  766. 33:11self-arning
  767. 33:13mode? Would that be a good extension of
  768. 33:16improving that?
  769. 33:17>> Uh you will run out of context.
  770. 33:20If you try to stuff all of this into one
  771. 33:23skill, you will run out of context.
  772. 33:27>> That's my short answer. Got you.
  773. 33:34Yeah, uh really nice uh presentation. Uh
  774. 33:37so I had one question. You mentioned at
  775. 33:39one place u in your u kind of the
  776. 33:43structure you presented that whenever
  777. 33:45there's a mistake
  778. 33:47uh we would like the human to get
  779. 33:48involved there. Yeah. So with the uh new
  780. 33:52systems and AI becoming more and more
  781. 33:54powerful and uh all the experimentation
  782. 33:57going on will it not be an idea where we
  783. 33:59actually have some bit of intelligent
  784. 34:02autocorrection also built there and then
  785. 34:04if AI is not able to correct something
  786. 34:07then only human comes in the loop.
  787. 34:09>> Absolutely. That's that's the idea with
  788. 34:11basically that's why you're providing
  789. 34:13the sensors so it can selfcorrect
  790. 34:15itself. You don't necessarily need a
  791. 34:18human. You only need a human when the
  792. 34:21the agent is not able to figure out
  793. 34:23things. Uh but you make sure that you
  794. 34:26can provide uh both the guides and the
  795. 34:28sensors so that the agent can be
  796. 34:30autonomous to the extent. But I'll give
  797. 34:32you an example, right? What if you've
  798. 34:34given contradicting
  799. 34:36uh you know requirements in your prompt
  800. 34:40to the agent? What should it do? Should
  801. 34:44it self-correct?
  802. 34:48Yeah. Yeah, it can. It can still try to
  803. 34:50self-correct. But when it gets you into
  804. 34:52that situation, see that that trigger
  805. 34:54has to be there somewhere. Yeah. So that
  806. 34:56trigger has to be there because AI in
  807. 34:59the current form is highly likely that
  808. 35:02it will never come back to us with the
  809. 35:03LM support will never come back to us
  810. 35:05saying that okay, I'm not able to do
  811. 35:06this. Yeah,
  812. 35:07>> that's the problem I feel today is that
  813. 35:10the agent assumes right. Right? So if
  814. 35:13you gave a contradicting requirement
  815. 35:15like to make it very specific let's say
  816. 35:17in one place you've said that this
  817. 35:19particular value should be less than 10
  818. 35:22in another place you you've given that
  819. 35:24it should be more than 20 right today
  820. 35:27the agent will pick one of them and move
  821. 35:30forward right
  822. 35:31>> so you' give some guides that will tell
  823. 35:34it like hey don't do this when you're
  824. 35:36confused like basically pull the human
  825. 35:39don't so the the difference right is
  826. 35:41that Don't expect a human watching over
  827. 35:44you. But when you can't figure out
  828. 35:46stuff, pull the human, right? So that
  829. 35:49you uh you can like not make
  830. 35:52assumptions. Uh because once you start
  831. 35:54making assumptions and people figure out
  832. 35:56it's not what they wanted, then the
  833. 35:58trust factor doesn't kick in. When the
  834. 36:00trust factor doesn't kick in, then you
  835. 36:02will have one human standing in front of
  836. 36:03every agent waiting to watch. Right? So
  837. 36:06we want to get out of that loop that
  838. 36:08mentality and you want to let the agents
  839. 36:11do things and that's where you want to
  840. 36:13provide as much information you can but
  841. 36:16when you try to provide too much
  842. 36:18information again like you end up you
  843. 36:20know exceeding the context you end uh
  844. 36:24other kinds of problems uh and you may
  845. 36:26not get the results right so there's a
  846. 36:28lot of uh I would say skill involved in
  847. 36:31terms of optimizing the context that
  848. 36:33you're going to provide uh and when
  849. 36:35you're going to provide that uh but let
  850. 36:37the agent pull you when it's not able to
  851. 36:40figure out something rather than
  852. 36:41assuming and moving forward. But to your
  853. 36:44point, absolutely you'll provide the
  854. 36:45sensors, you'll provide everything so
  855. 36:47that it can self-correct, right? You
  856. 36:50don't want to be waiting and watching
  857. 36:52over it. Uh but that's not always
  858. 36:55possible like the example I gave you
  859. 36:57where you've given contradicting things,
  860. 36:59right? Or there may be other regulatory
  861. 37:01kinds of things where it's you wouldn't
  862. 37:03want it to just make
  863. 37:09Yeah. Okay.
  864. 37:10>> Um, hi. So, I really like how we are,
  865. 37:15you know, uh, putting this together for
  866. 37:17APIs because right now in my
  867. 37:19organization, we are we have something
  868. 37:22called maturity index for each of the
  869. 37:24repositories. So, this stands first I
  870. 37:27guess the guides and the sensors and
  871. 37:29everything else should be put together
  872. 37:31for APIs and then separately for UI. My
  873. 37:34question is regarding the guides uh
  874. 37:37where uh the agent plug-in uh has skills
  875. 37:41and MCP. What do you specifically mean
  876. 37:44by MCP in this place? Because whether
  877. 37:46it's a developed MCP or you are just
  878. 37:48providing the guidance to create that
  879. 37:50MCP along with the API.
  880. 37:52>> Uh so there are several different forms
  881. 37:54of MCPS that you can plug into it. Uh so
  882. 37:57anytime like basically an agent is going
  883. 38:00from a prompt to generating the code for
  884. 38:03you it'll need a set of uh inputs right
  885. 38:06so a language server for example is an
  886. 38:08MCP that you could provide to it right
  887. 38:11but you could also have an MCP sitting
  888. 38:13on your control plane that the agent can
  889. 38:16talk to to figure out like hey am I
  890. 38:18doing uh something that I should avoid
  891. 38:21right uh from uh let's say uh if you see
  892. 38:25like a an API's unstable. Should you be
  893. 38:28depending on that API?
  894. 38:30>> Okay.
  895. 38:31>> Right. You may not want to depend on an
  896. 38:32API which is unstable, which is not or
  897. 38:35deprecated. That's even better example,
  898. 38:37right? So if an API is deprecated, you
  899. 38:39would want that feedback to go in, but
  900. 38:41you can't stuff all of that in up front,
  901. 38:44right? So you would provide uh you know
  902. 38:46MCPS to kind of make those decisions.
  903. 38:49>> Okay. So we are talking about real MCPs
  904. 38:51that do the job of implementation and
  905. 38:54correcting and all that right
  906. 38:56>> MCPs for mostly providing feedback to
  907. 38:59the agent or guidance to the agent so
  908. 39:01that they can kind of selfcorrect.
  909. 39:03>> Okay. Yeah. Yeah. Understood.
  910. 39:04>> Or produce things right in the first
  911. 39:06place.
  912. 39:07>> Thank you.
  913. 39:08>> Uh so really loved the presentation nar
  914. 39:11and especially the analogies of the loom
  915. 39:12and the traffic lanes. Uh brilliantly
  916. 39:15done. uh and I was actually I worked on
  917. 39:18the Citrix API platform long back 2018
  918. 39:2019 and I just wish I could take all of
  919. 39:22this and go back in time and you know
  920. 39:23use all of this. Uh coming to the
  921. 39:25question uh to me looks like this takes
  922. 39:28care of a lot of the design aspects
  923. 39:31implementation aspects even testing
  924. 39:33where do you think uh you know runtime
  925. 39:35characteristics like scale performance
  926. 39:37fit into this whole you know framework?
  927. 39:39>> That's that's a brilliant question. So
  928. 39:41when we saying the governance piece
  929. 39:43that's also looking at so it has all the
  930. 39:46observability aspects into it and that's
  931. 39:48kind of where you want to have these uh
  932. 39:51feedback loops between them right expose
  933. 39:53an MCP on your control plane so
  934. 39:55everybody else can tap into it and you
  935. 39:58know you basically are getting feedback
  936. 40:00from uh monitoring uh from your
  937. 40:03governance uh sorry from your
  938. 40:04observability systems into this so you
  939. 40:07know what's happening in the production
  940. 40:08environment at runtime as you scale
  941. 40:11things but also what uh at least we've
  942. 40:13done in a lot of cases is built a lot of
  943. 40:16that stuff here right so when you're
  944. 40:18individually designing an API you can do
  945. 40:21a lot of resiliency testing you can do a
  946. 40:23lot of things uh for example if a
  947. 40:25downstream service is down how are you
  948. 40:27going to behave you know you have you
  949. 40:29implemented circuit breakers correctly
  950. 40:31how do you validate that uh so both as
  951. 40:33part of sensors and guides you can kind
  952. 40:36of so guide would be essentially like
  953. 40:38hey for for this kind of an API I I want
  954. 40:40you to fall back to asynchronous, right?
  955. 40:42So instead of doing 2011, do a 202 uh
  956. 40:46and then respond back with the monitor
  957. 40:48pattern, right? Like that would be like
  958. 40:50a best uh practice that you would feed
  959. 40:52into uh the the agent, right? But then
  960. 40:55you need to validate whether it did
  961. 40:57actually implement it exactly in that
  962. 40:59way or not, right? Is it's given you a
  963. 41:02monitor link, but is the monitor link
  964. 41:04actually when you hit it eventually when
  965. 41:06it completes, does it give you back a
  966. 41:08result? Right? So a lot of those kinds
  967. 41:11of things at an individual API level
  968. 41:13today we already have the capability to
  969. 41:16do that. Right? But at a scale when
  970. 41:18you're trying to look across like in my
  971. 41:20case 40,000 services then you
  972. 41:23essentially want all of that data coming
  973. 41:25into your control plane and then feeding
  974. 41:27it back into all the agents. Right? So
  975. 41:29that's kind of another example of the
  976. 41:31MCP that kicks in.
  977. 41:33>> Thank you. That helps. And if I may add
  978. 41:34a part B to the question, uh if let's
  979. 41:37say you're specifically designing and
  980. 41:38implementing APIs to be consumed by
  981. 41:40agents in that case, do you see this
  982. 41:42framework evolving? And
  983. 41:44>> absolutely. So there are a lot of like
  984. 41:46AI quality metrics, scorecards and
  985. 41:48things like that that you build into
  986. 41:49your governance uh which essentially
  987. 41:51helps you understand whether the API
  988. 41:54itself is ready uh that you want to
  989. 41:57expose to an agent or not. I think
  990. 41:59there's a lot of great work that uh I
  991. 42:01don't know Eric and Frank the folks from
  992. 42:03Gentic are doing. Uh even Kinlane is
  993. 42:06doing some very interesting work in that
  994. 42:08space. So uh there's a lot of folks who
  995. 42:10are trying to figure out uh whether like
  996. 42:13how do I score how do I guide whether my
  997. 42:16APIs are actually ready for the agents
  998. 42:18to be consumed.

About this transcript

This page contains the full transcript of Fost India 2026 - Restoring Trust in AI-Native Development | apidays India 2026. by apidays, generated from the public captions YouTube serves with the video. The transcript has 6,940 words across 998 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.