Techstrong TV March 16, 2026
AI’s Impact on AppSec and the Google Cloud API Leak: Steve Boone of Checkmarx joins Alan Shimel to discuss how AI-driven coding assistants are transforming the SDLC into an “agentic delivery lifecycle,” and why incidents like exposed Google Cloud API keys highlight the urgent need for better API visibility and AI-assisted vulnerability prioritization.
Neurosymbolic AI and the Future of Coding: Binny Gill, CEO of Kognitos, explains how neurosymbolic AI combines natural-language interfaces with deterministic logic—enabling enterprises to keep humans in control while AI agents execute complex workflows without hallucinations.
Agents + Apps + Chat: Richard Riley and Dion Hinchcliffe explore Microsoft’s vision for agentic business transformation, where AI agents serve as interfaces, logic layers and decision engines across enterprise workflows.
Reality Check Ep. 3 – AI in Retail: Dave Nicholson and Adam Gelnick examine how AI and digital platforms are reshaping retail—from the legacy of brick-and-mortar stores to competition with e-commerce giants like Amazon.
Cloud Discipline for On-Prem NetOps: Ahmed Abutaleb explains how Nokia designed a next-generation data center network using NetOps principles—leveraging Kubernetes-based platforms and open-source tooling to deliver cloud-like automation and consistency on-premises.
NVMe to Cloud with Hammerspace: Chad Smith of Hammerspace demonstrates how the platform unifies distributed storage across data centers and clouds—using capabilities like Data Assimilation and Tier-0 NVMe pooling to ensure AI workloads always access data where compute resources are available.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. Uh, my next guest, well, he's not a stranger to our show.
He's been on a number of times, my friend Steve Boone. He's Director of Product Marketing over at Checkmarx. Steve, welcome back.
How you been, man? I've been fantastic, Alan. Good to see you.
Thanks for having me on again. Pleasure. Uh, so Steve, you know, it certainly has been some interesting times around AppSec.
We're gonna talk about it and how it's affecting Checkmarx, but before we do that, I wanted to, for people who I haven't caught you on the show before, maybe you're not familiar with your background, give them a little bit of your history. Yeah, sure. So I've been in the DevOps cybersecurity space now for a little over ten years, focusing on everything from automation, vulnerability detection, remediation, and now at Checkmarx we're focusing on, you know, really helping organizations adopt some of the newer technologies like AI, but doing it in a meaningful and direct way, right?
How do we allow developers to use things like, you know, Copilot, but do it in a safe way, understanding that when we're generating code, right, it's no different than bringing in strangers' code, right? You wanna have eyes on that. You wanna understand if there's any issues with it.
You wanna be able to, validate it and remediate it, and ideally use it in such a way where, you know, this new code isn't coming in adding more challenges to your organization, more vulnerabilities to your existing backlog of, of stuff that you're working on. So for us, you know, we see all the shifts. We see a lot of the, challenges as well, and, our goal is to make sure that we can help organizations navigate those waters.
Absolutely. Um, Steve, you know, a-as I mentioned and as I, I guess you said, Checkmarx is, you know, they're one of the OGs in AppSec in some ways, right? For sure.
They've been around a long time. Yeah. And, we're, we're living in a very interesting time period right now, especially as it applies to AppSec, right?
The recent, releases and the amount of vulnerabilities they found, so-called vulnerabilities, right? I wrote an article the other day. You know, they, they set it loose, I think it was on Firefox or something, and it found 112 potential bugs, of which 22 were actually real vulnerabilities and only two were actually exploitable.
Yeah. But just that number, it sounds like a song from Chicago, "25 or 6 to 4," 1- 112 or 22 to 2. "25 or 6 to 4," right?
Exactly. You remember the song. You know what I'm talking about.
But it, it's changed... It's moved the cheese a little bit, right? Yeah.
It's changed the focus on not finding potential bugs, but on finding real vulnerabilities, and on real vulnerabilities, I mean ones that are reachable, exploitable, things we need to... So it, it's really, it's, it's a very different focus change. I'm not saying AppSec, as we know it, is over or anything like that, but it's- It, it- ...
changing- Yeah ... the, the mission, if you will. It, it's, it's interesting, right?
I mean, when we look at for years, right, you and I have been going and talking about things like the SDLC, right? Uh- Mm-hmm ... let's understand your software delivery life cycle, and the way that I look at this is that AppSec, it's not that AppSec is dead.
Ed- to your point, it's evolving, right? And, and so now the SDLC is largely becoming an agentic delivery life cycle, right? So as we start adopting AI, we start seeing the emergence of all these agentic agents.
We're seeing them at the development level, right, where developers are writing code and generating code. We see them at the pull request level, where there's agents that are analyzing these pull requests, trying to understand if they're, can provide more feedback, or if there is a vulnerability, could I provide remediation to it? To your point, how do I...
You know, people are always worried about reachability, exploitability. Um, so, you know, can we, at the time of a pull request, give a developer confirmation, yes, you need to care about this. This is absolutely exploitable.
It is reachable. And if we can, well, there's another opportunity to give them code that can address that, and they can make another pull request, right? So now you're starting to see these agents both at, in the IDE, at the pull request.
We're seeing them start to appear, very rapidly within the CI/CD spectrum as well, right? Agents that can help facilitate your pipelines, agents that can help remediate your pipelines, and you also start to see them at the monitoring phase as well. You know, all these applications go live.
You've got APIs, you've got runtime, all of that. You know, think about it as agents galore. And so now, not only do you have to understand how to implement these agents and scale these agents, you also need to secure these agents.
How do you make sure that they're not trained inappropriately? How do we make sure that the... 'Cause you always have this idea of AI for security and security for AI.
Mm-hmm. And we're quickly running into this area where we're seeing some... You know, like I said, we've been around for 20 years.
Been around for a long time. We've always, been very, deterministic, rule-based, if you will, in how we scan code and find vulnerabilities. You mentioned something like cloud se- cloud security, right?
That's more probabilistic anal- analysis of where we see what's probability that you're gonna have these vulnerabilities or the types of findings they have. Um, and so our goal now as we evolve, as Checkmarx move forward, is to bring both of those together. Yes, we still wanna be deterministic.
There's a lot of value in all of the rules that we've built over the last 20 years to scan code and identify known things, right? That, that's not going away. But you also wanna have that probable aspect as well, right?
You also need to be able to bring those things together, and then whatever value you can squeeze out of that, figure out a way to get it in that, into that feedback loop. And so even our feedback loops are starting to get some of that agentic feeling to it as well. Absolutely.
Absolutely. Somehow we, I, you know, I didn't mean to take us... We made a left turn.
It's all good. I hear you. Steve, what, what we were supposed to be talking about, though, today was the recent incident regarding Google Cloud API keys.
Yes. And it's not that far afield, but, you know, let me bring us back to here. Talk to us about this particular, incident and, and what became of it here.
Yeah. You know, I mean, when we look back at what happened with the, the Google Cloud situation, right? And, and the, the...
a lot of folks will say, "Oh, you know, the bigger issue is exposed keys," right? They had exposed API keys in their code. I, I would say the bigger issue isn't just an exposed key.
Um, it's that many organizations don't have a complete inventory over their APIs and credentials that are running in their environments, right? So visibility is a huge problem for, I would say, 85, 90% of organizations out there. " isn't necessarily a question that a lot of application teams can answer.
Um, so when you have credentials that are embedded in code, you know, they quietly expand, the API attack service. Um, and security teams a lot of times don't even realize it. So the real risk, at least in my opinion, starts to appear when organizations lose visibility into what those credentials can actually access once they're deployed, right?
So you can't secure APIs that you know, that you don't know exist or understand. You just... It's not a thing you can do.
Agreed. Agreed. Uh, you know, and you can't defend against what you don't see or know either, and, and that, that's always been a problem.
Um, what can we do about it? Well, I think there's, there's a couple of things, right? Um, one, you'd, you need to have that inventory, right?
So being able to scan your code and just knowing, what are my APIs, are they internal, are they external, are they secured, are they unsecured, is wildly important, right? That gives you your base understanding of, of the landscape. Now, there are several different layers of API solutions on the market.
We obviously, as a code scanning company, look at things from a code perspective. Um, there's a lot of great companies that we partner with out there as well that are more of a runtime perspective on it, right? That will analyze your network traffic, see if those APIs can be attacked, and in a lot of ways tell you that they are being attacked, and here's d- different ways that you can address that.
And, I think one of the other things is as well, though, is, is that w- I, I think organizations can do a much better job at what I'll say is secret detection, right? Very, very frequently, and I'm guilty of this as a amateur developer on my own, right? I just wanna make cool things that work for me.
I'm not out here writing the mission critical stuff that Checkmarx does. But am I-- as a hobbyist, when I'm writing code, hard coding secrets, I just, I don't care. It's running locally for me, right?
But we see this in development environments, too. So all of a sudden, you're testing something, you need to make it work, you hard code these credentials into APIs. All of a sudden, they get promoted into lower level environments and occasionally even production.
So this idea of not understanding the full attack vector of our APIs, but also knowing that bad coding practices do happen, right? That's, that's always gonna be something we're gonna deal with, expands upon it. So w- a little bit of it's going back to the basis, right?
Making sure we understand exactly what our APIs are. Um, one, making sure that we can document those APIs. Scanning regularly because as new e- APIs get introduced, sometimes we won't find about 'em until we scan the code.
Okay. Great. Now we need to make sure we go back and document them, right?
Make sure that we close that gap from a development side. And then again, regularly scanning in IE in real time for those secrets. Um, you know, once Checkmarx identifies secrets in your code, we can easily help developers remediate that, so it's not a problem going forward, right?
So those are the things I think is kinda easy blocking and tackling that organizations can do, to keep themselves safe. Fair. Fair.
Steve, we-- you just rattled off a whole bunch of really good stuff there. Where can we go on the Checkmarx site or, you know, to kinda w- so we could study this? Yeah.
So there's, there's actually a ton of locations that you can go to, right? I'll, I'll give you a couple of the ones. com because out there, you're gonna find everything that's going to address what you want in a platform, right?
Multiple different engines. Um, you've got the API scanning. You've got the code scanning.
We're doing a lot now with our DAST engines. We're actually heading to RSA here, in, in just a couple of weeks where we got- Two weeks ... really cool announcements coming out there.
Um, and if you're interested on what we're doing for developers, because we put a lot of focus in making sure that we can provide not just a great experience for developers, but a much needed necessity of, again, using all of those different coding assistants you want in a safe and secure manner. dev. dev, we've got, the Checkmarx Developer Assist.
You can get a free trial. Um, it's easy to get set up working in your local IDE. It will scan your code in real time.
It will help you with remediation of new vulnerabilities, existing vulnerabilities. It'll hap you-- help you with, package refactoring. So if we scan something and find a vulnerable package, right?
What are the steps that you need to go through to refactor that code, to adopt the new version of that package, without, you know, introducing a ton of new breaking changes, right? We're, we're here talking about APIs. Um, those change between version to version of packages.
And so Developer Assist can help, ease all of that. It'll identify new packages, tell you what's changed in the code, and it's leveraging the twenty years experience that Checkmarx has to bring that into the IDE. So, you know, a lot of people say, "Oh, well, Checkmarx, you're just a-"Asking AI for how to remediate it.
And, and that's not it, right? We're-- When we're... What we're doing is we're calling back to Checkmarx services and saying, "Hey, give us that 20 years of knowledge on how to go fix that cross-site scripting or that SQL injection," and then we pass that information back to your coding assistants to make sure that they're following the right orders and right steps to change that code securely.
dev. com will, give you everything you need to know from a platform perspective of how to make sure your enterprise is secure. Excellent.
Steve, I'll be at RSA2. I hope you'll stop by. I'll be at Broadcast Alley all...
well, Tuesday to Thursday I'm at Broadcast Alley. Monday, you know we do our annual DevSecOps. Sure.
This year it's Securing AI Native Dev. But we'll be up there, Monday. If you're around, stop up.
We have some great speakers lined up. Um- Absolutely. Important ...
but until then, I hope to see you there in person. But keep up the great work, man. It's such an exciting time.
This, it's... This stuff is... Yeah, I've never seen security move this fast.
So- It's funny. You know what? Security used to always be kind of the, the thing that was the laggard, and we, "Oh, okay, we gotta catch up," and, and now it feels like the whole market is just reinventing itself.
Crazy. Yeah. Crazy times.
All right, my friend, it's good seeing you. I'll hopefully see you in two weeks. Steve Boone, Checkmarx, here on, Techstrong TV.
We're gonna take a break. We'll be back in a moment. AI Leadership Insight Series.
I'm your host, Mike Bizzer. Today we're with Binny Gill, who's the CEO of Cognitos, and we're having a little chat about neurosymbolic AI, and I'm gonna let Binny explain exactly what that is, but generative AI is not the only game in town, shall we say. Binny, welcome to the show.
Hey, Mike, nice, to meet you, and thanks for having me. Um, neurosymbolic AI, yeah, that's basically the response to all the issues that people are having around AI hallucinating and AI doing stuff they didn't think it would do. " 'Cause it wasn't really thinking like you think.
It's not human. Uh, neurosymbolic AI, let me first explain through an analogy. Have you seen the Star Trek, series from long ago where Mr.
Spock was there in the Enterprise? Sure. Uh, he was in multiple series, but yes, I do remember the original.
Okay. So Captain Kirk is human, Mr. Spock is neurosymbolic.
All right? So highly logical, fundamentally logical thinking, but has a nice interface to humans. That is how you would define neurosymbolic.
We're trying to bring that same thing to enterprises where I want a system that is fundamentally like a computer, logical, but it has a natural language interface. English is code, natural language. I talk to it, it understands, it says, "You told me this.
" And after you say, "Yes, do it," it follows it rigorously as if it was software, as if it was code. It's going to do that, and it's not going to get biased and hallucinate, just like Mr. Spock.
Symbolic AI models have been around for a little while, so what's changing here? Is it just that they're becoming more accessible via a natural language interface? I mean, um- Yeah ...
and, and is that just being something that, you know, they kind of looked over at the generative AI playbook and said, "We could do one better"? See, with most things AI, it's about the harness, right? The power has always been there, and, you know, we are generating more and more power right now, but the harness is what's more important.
So what we have done at Cognitos is we've created a platform where we have created a separation between the planning power of AI and the execution power of AI, right? And, and through a harness that puts the human smack in the middle and says, "I'm gonna use the most advanced reasoning capabilities of AI for planning," but the planner doesn't have the ability of doing stuff. The planner is forced to write down as a document, as an SOP, like, "Here is what I'm going to do, and this is the standard process.
" And then there is this, deterministic engine that executes that step by step that isn't allowed to plan, you see? So basically planning is creativity, execution is deterministic, and we separated the two. And putting the human in the middle, almost like there is a steering wheel, human can say, "Run on autopilot," but if I want to, I can grab the steering wheel 'cause I can understand the English in the middle.
I can tell you, "Hey, here, this is wrong. " So that harness is what we have created and, providing as a platform. Does one obviate the need for the other, or am I gonna wind up using symbolic AI models alongside generative AI models that maybe are a little more probabilistic and less deterministic, but maybe they're useful for, certain applications where symbolic might be, I don't know, overkill?
Yeah. So actually we've gone one step forward further, than just having user... using a symbolic model.
So imagine like Python, have you ever thought it will hallucinate? Or Java or any programming language doesn't hallucinate because it's built on logic, right? So we have built an interpreter for natural language, and it's built on logic.
It's our own implementation that's a proprietary engine there. It's also built like a time machine, so unlike Python that is forgetful, you can't query Python, "Hey, you crashed here. " It doesn't know.
Um, we built, an engine that remembers just like humans remember, but it understands English and it's, instead of predicting the next step, it actually executes the next step. So that's the thing that we have built. And when it hits an issue, at that time, this symbolic engine says, "I need help," and it turns into a planning engine, and it becomes fully creative.
But the creative engine always has to bring in a human. It is not allowed to do things without a human approving it. So this interplay between a creative engine that is always paired with human being present and a deterministic engine that is allowed to do things by itself because it's doing something that's pre-approved, that harness is making it, much useful in business.
The ROI is there. And what we are saying is that the deterministic aspect of it is actually completely deterministic. It's not going to have any kind of bias hallucination, and the side effect is it's not even going to burn tokens, because when it runs, it doesn't run on LLM tokens, it runs on code, and it runs as fast as code does.
So it's much faster, much cheaper, and doesn't hallucinate in the execution se- phase. Uh, otherwise it's fully creative. Are there some use cases that are gonna migrate to this approach more readily than others?
I mean, you know, as you talk to customers, where are you seeing them kind of applying these types of AI models? So there are many kinds of work that humans do. Um, some work is research, some work is ad hoc.
Those are the, ones that don't migrate to this model. Then there is other kind of work which is mission critical, important enough that some manager wrote down the rules or wrote down the steps for it. And those are the ones that go into this model because, just think about it, right?
Um, when there is a large number of humans in a business, we write down... we start writing down standard operating procedures, right? Um, if it's a very large country, you write down the constitution, right?
Um, humans have figured out that you cannot tell each human and train each human individually. What scales better is you write, write down the rules and have everybody follow the rules, and you create a harness so that they follow the rules. Now, in businesses, the harness is if you don't follow the rules, then you'll get fired, okay?
And the other harness is I interview people who have the right degrees, and they know exactly how to interpret my rules, right? That's on the human side. We are saying the same thing on AI.
You're gonna write down the rules, and the harness that Cognitus provides allows, the AI, AI to follow it, to the teeth. Now, where this is important is finance and accounting, money is involved, or it's on the contracting side where you don't want to miss a single clause. Um, anything that is-- where the outcome is not the only thing that's important.
What is also important is how you did it. Did you follow the procedure? Did you follow what was pre-approved?
That's where we go in. And those are readily, transferring to this. And to your point about that, when we say something is probabilistic, it also means that it never does the same thing the same way twice, and so that's part of the challenge when using some of these generative AI models, correct?
Correct. And the, and the only way of doing that is what we are talking about, neurosymbolic. So planning, when you do, it comes up with a, with a plan that this is what I'm gonna do.
That could be, you know, if you plan with somebody 10 times, you might end up with a slightly different plan each time. But then you review a plan. The moment you reviewed the plan, you can run it a thousand times with the same input, you'll get the same output, because that part is a program.
One of the use cases where we've seen a lot of adoption of generative AI is in software development. But to your point about symbolic models and the way they operate, might those models lend themselves better to, automating a lot of the coding tasks, or at least the software engineering tasks that we have out there? I beli-- I'm a software engineer by training.
Uh, I've been coding for 30 years. Right now, I'm just trying to see how we can stop coding in any language other than natural. So what I believe is all the software coding tools that are out there are there for some time.
Um, already we are seeing that the IDEs, you know, the development environments for writing Python and oth- others are actually going away. Even my developers are stopping to look at code at all. And if you go with what Elon Musk has been saying is that y- there won't be Python.
AI will just generate machine language, assembly language. Who cares? You're not even looking at it, then why does it matter?
The last 50 years of computer science coming up with these new languages that make it easier for humans to learn it are not needed if nobody's gonna look at it. AI will just generate machine code and off you go. It'll run faster and all of those things, right?
Fundamentally, I believe, and this is also why-If you know Khosla when he was talking to us, he was interested in, you know-- The fundamental belief we have is there are a billion programmers out there who don't know that they are programmers. They program in natural language. " You say, "Okay, I know.
" You're programming me, right? Or when grandma says, "Let me write down the steps to make apple pie," she's programming another human. Everybody's a programmer.
The language of programming has to change to natural language, and all the other languages of programming will be almost like assembly. Nobody looks at it other than a very few people who are sort of the core computer science, compiler designers. Rest of the world, programming in English.
What will it take to achieve this vision? Because I think a lot of people are maybe intimidated by anything related to AI, and very few know anything about symbolic. lift is this?
" When I talk to business owners, manufacturing, logistics, retail, CXOs, and I say, "Look, AI is getting smart, and it's going to be almost like human, so therefore you don't need to upskill. If you know how to manage humans, exactly the same thing, you should manage AI. What's the difference?
You tell a human, 'Go do these 10 steps. If you have any question, ask me. Don't make your own decisions for the business.
'" Right? I said AI is exactly going to do that. The same document that you given, give a human should be the document that you give AI to execute.
That's what we say English is code. So it's no longer about creating a AI, you know, prompt or AI model or anything like that. So we're trying to make it as close to current reality for people who are not tech-savvy, but they are business savvy.
They actually design the business logic. The last 50, 70 years of what computer science has tried to do is to take business logic and bury it in software. That is going to go away.
Business logic will now rule on top, where the computer science languages, all of that, get hidden. So I think the adoption is gonna get easier, with this kind of model. A lot of times the AI agents will exceed their brief, shall we say, the ones that are built on gen AI at least, and for that matter, so do humans.
So to your point about logic, are we gonna be able to just kinda narrowly define what it is that AI agent is allowed to do, and that's part of how we kind of bring some governance or some order to the chaos? So yeah. Uh, you're talking about the safety aspects of AI doing something.
Yeah, I mean, that's precisely the whole Holy Grail, right? Um, as AI is getting smarter and smarter, the damage it could do is also getting bigger and bigger, right? Um, the way to trust AI, there, there are two ways of trusting AI, right?
One is you have the neurosymbolic model that I'm, I'm talking about, where it first tells you what it's going to do and then does what it told you it will do, right? That's, you know, deterministic execution, but it is creative, and it tells you what it's going to do. That kind of framework, that works.
In that model, it is not allowed to do something that wasn't pre-approved. Now, when it is in that rigid mindset, obviously it might hit a point where it says, "Hey, you know what? " I mean, it's stuck.
Now, because I never pre-approved that it can go and reset the password on its own, it will stop there and then reach out to a human, and with the help of a creative AI model, and try to address that issue, and that's the sort of exception handling. That exception handling happens on the side. The system then learns it as tribal knowledge, like in this world, whenever the password is expired, I have to go talk to John, who's the IT admin, and he'll give me the new password, whatever.
That's tribal knowledge, and that's also captured in our system, again, as English, and then the system proceeds from where it was stuck. We have the pattern for that, by the way. Like you, if you get stuck, you get help in natural language and continue, resume from there rather than start from the beginning.
Um, that's the pattern we have. Now, that makes it safe, so I think that's one approach I think works even today. The other approach of making AI safe is what people talk about alignment, right?
So I have an AI model that aligns with how humans think, almost like I trust my f-friend who I started the business with, for example, right? So if I'm not present, he can make the decisions. Okay.
That's alignment of thought process. With AI, I think that's extremely hard. First of all, the research needs to be done, and secondly, even if you align with human thought process, trusting somebody who's aligned with human thought process is also hard because humans don't trust each other anyway.
So, that's just a hard problem. So what do you see people doing out there today that just kinda makes you shake your head a little bit and go, "Folks, maybe we might wanna rethink that"? Well, the OpenClaw moment, right?
So, not that I'm not using OpenClaw myself, but it's about putting the guardrails around it, right? " Like, okay, I'm shaking my head. Like, you don't know the power of-See, AI is powerful, but also the damage it can do sometimes can become irreparable.
Right now, we don't know what it's capable of. If it's on your laptop, it could actually log into your bank account and do some transfers, and, you know, that'll be the end. Um, but people don't realize, right?
I mean, it's just a prompt away. Now, where will that prompt come from? Today, thankfully, AI doesn't have an agenda, right?
" 'Cause it doesn't know who to listen to. Like, am I listening to Binny? Am I listening to this guy who is talking to me?
And you can bribe these chatbots. You can say, "You know what? " And these chatbots are hungry for tokens.
Uh, I also have my own chatbot working. But again, it... But you shouldn't throw the baby out with the bathwater.
It's an amazing technology. It's a democratization of the power of AI to everybody. Now, my HR is using it, my finance is using it in a, in a very constrained way.
I have built the environment for them a separate cloud account, with this highly controlled, doesn't have access to our native internal systems, but is valuable, right? Um, marketing is using it. So there's a...
I think it's not the technology itself that has a problem. What makes me feel like, you know, people don't get it is they're using it wrong. The harness isn't there, so they need to understand you've got to use it with the proper harness.
And the other thing where I shake my head is people say, "No, I don't want to trust. " Like, there are people like that. It's like, oh, it will never come into my...
That's like people saying there are horses, yeah, some people are riding fast on horses, but I'm always gonna go on my foot, right? That's when it's like, no, you don't get it. I know you tried to jump o- get on the horse and it threw you to the ground, and you had a bad experience once.
That doesn't mean, you know, horses won't be used, right? So you just have to learn to ride it. So that's...
I mean, it's, the spectrum is quite wide. Right. All right, folks.
Well, you heard it here. There's a lot more than just one kind of AI, and you gotta fi- figure out, well, which of these is best fit for purpose? And if your purpose is that it needs to be done the same way every time, you might wanna think about symbolic.
Hey, Binny, thanks for being on the show. Thank you, Mike. All right.
ai Leadership Series. You can find this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next time. Hey everyone, it's Alan Schmel of Techstrong again. Hey, for this next session, you know, we call it Agents + Apps + Chat.
It's features Richard Riley, who's GM of the Power Platform Marketing at Microsoft, as well as our own Futurum analyst, Dion Hinchcliffe. Dion and Richard will build upon the foundational vision of Agents + Apps + Chat, creating a solution-orientated view into the heart of agentic business transformation. In this session, you're gonna learn how agents are enhancing workflows and redefining the architecture of business value today.
You're gonna hear about practical applications for agents in terms of UI, logic layer, and decision engines across business functions. Everything from finance to HR to sales, and even customer service. I think you're gonna enjoy it.
Here's Richard and Dion. Thanks, Alan. This is Dion Hinchcliffe, VP and, practice lead for our chief information officer, research group, and I'm with the Futurum Group.
I'm here with Richard. Richard, can you give us an introduction? My name's Richard Riley.
I, lead the low-code go-to-market team at Microsoft, so that covers all of our low-code portfolio, Power Apps, Power Automate, and includes Copilot Studio, our, our agent building platform. Well, it's great to have you, Richard. And what's interesting, the CIOs I talk with, they're undergoing all these changes with, with AI, and now agentic has arrived.
And they, they're under this realization that they are going to have to transform their organizations using AI agents. And so I was wondering, you know, to help them understand this, how do you define agentic business transformation that, goes, beyond just mere automation and is really ex- explains kind of why it's a new paradigm? Well, I mean, I think agents can do lots of things.
We, we tend to think of them existing on this kind of, spectrum. So you can have very simple agents on one side of the spectrum and very complex agents on the other. So to give you a bit of an example there, I would say on, on the left side, on the simple side, we kind of say agents that just do, you know, regular Q&A.
They're grounded on a few documents, and you ask them a few questions, and they can give you answers. They're super useful in certain situations. And then on the right-hand side, you've kind of got things like autonomous agents that they can work off triggers, they can run business processes, they can, they can literally work autonomously and have very complex logic, complex instructions, and run very complex business, business processes.
So... And then you've got everything in between. So we kind of think it, it, it really depends, on what the...
who's asking the question and what they're asking, the context they're asking the question in. But it's helpful to think about these as a, as a spectrum of things versus, an agent is just a, is just the same agent. We appear to be on the cusp of a massive wave of agentic solutions.
Uh, some are narrow, some are broad, and, some are open source. What makes Microsoft's approach defensible and distinctive in the flood of agent frameworks and offerings that we're seeing show up? Yeah, that's a good question.
So I'd probably start with the breadth of tooling that we've got. We kind of span from the very easy-to-use experiences that are built into M365 Copilot with Copilot Light. You can literally describe an agent that you want, you can give it some grounding content, you can tell it to go talk to, to SharePoint and a bunch of other kind of content sources.
Super easy to do, super easy to share, very valuable. We then have Copilot Studio, which kind of takes that a step further. You get access to a lot more capability, in-including things like triggers.
And then we take that an even step further when you think of, Azure AI Foundry. All of these things are kind of tied together in a, in a very integrated way. Um, so it's very easy, very easy to move from one to the other and incorporate one or the other in, in your solution.
So I'd say our, our breadth of toolset is probably number one. Uh, number two, I would probably talk about access to data. Any customer that's an M365 customer of Microsoft, has an enormous amount of kind of that tacit knowledge, that data in Microsoft Graph.
We make it very easy for you to get at that to make your agents, more intelligent. You know, it's one thing to be able to run off a, you know, rows and columns in a CRM, database or, you know, ERP or FNO kind of, service. It's something else when you can marry that with, that tacit knowledge that you've got in your enterprise to bring intelligence, much more intelligence to what the agent can do.
And then thirdly, I'd say, our kind of core strength in security, governance and compliance. You know, we, we've, we've invested heavily for a long time to help customers, secure and manage their, their enterprise data. All of that investment flows through to, to your investment on the Microsoft stack for agents.
Agents respect all of the policy, the labeling, all that kind of stuff that you've already deployed to manage your data. If you're building your agents on the Microsoft stack, that stuff just flows through. So I'd say those, these three things are probably the three primary.
Yeah, that makes a lot of sense. And so, so let's zoom in for just a moment. You know, help people understand, how do agent-powered interfaces change the way that workers interact with business systems, you know, compared to traditional user interfaces?
There is a lot going on in ind-industry with how kind of apps and agents are coming together in, in super interesting ways. Um, I think over time we'll see agents starting to adopt some of the app modalities that we expect from apps today. So think of a time when, when an agent can actually start to build an app or even just a UI, like a, a form, on the fly for it to solve a business process or to, to, to help you, you know, move forward with whatever the thing is that you're working with the agent on.
I think we're gonna start to see that show up. It's not today, but, over, over the, over the, over the course of time, I do think the app modality and the agent modality will start to mix. And ultimately, if you think about it, there's a, there's a, there's a very good reason for bringing those two things together.
The, the example that I like to use is around, you know, a, a procurement process, like every company has to buy stuff. Today at Microsoft, you know, you have to know three people, there's three different tools, a bunch of approval stuff happens. That could be s- the couple of apps you have to go use, that could be built into a series of agents and Copilot kind of marshaling the whole process.
" Copilot could know the agents that it needs to go talk to, to be able to do that. There could be a, like a, a legal agent to check the, the, the statement of work that you're trying to, trying to kind of, work through. Um, there could be a procurement agent that could go make sure you've got access to the right, and you're hiring the right vendors.
Like every step of the way, Copilot could run that whole process. You don't necessarily need to go through three different tools. If Copilot needs some data from you, it could create a form if needed, if it's not a conversational type of, thing that it's, it's asking for.
So you can see how these things start to s- really blend together when you start to think about agents working with other agents and then having something like Copilot kind of manage that interaction for you. So I'm glad you brought up talking about different agents, working across the business, and, and that's something we call orchestration. And one, challenge enterprises face is orchestrating multiple agents across different domains, finance, HR, customer service, without chaos, integration or security issues.
How does Microsoft envision enabling agent orchestration across the enterprise, and what governance mechanisms will make it all work and safe? Uh, that's a good question. So there are a couple of things that, I don't think we're particularly unique in the industry with, you know, like supporting MCP for agents to be able to use tooling and, supporting A2A for agents to talk to other agents.
That's kind of table stakes these days. The things, the thing where it starts to get interesting with Microsoft is our, our ability to use capabilities like Agent 365 to provide kind of end-to-end observability across all of the agents that you've got running, in your, in your organization. Um, to the extent that you can even give an agent, you know, an agent ID and treat it like a, like a user, things like conditional access, all that kind of stuff, just work.
And then I also think, like, once you give, organizations the ability to kind of observe and manage and govern agents, it starts to open up new kind of frontiers of where they can use agents. It allows them to think about business problems that they've had in the past that have historically been kind of unautomatable. Maybe they're too determine-- non-deterministic or, too complicated to, to do with traditional automation tools, and apply agents to those problems.
And we've seen a ton of customers kind of look at existing business pro-processes and decompose them and figure out where they can replace certain parts of them with an agent. They don't replace the whole-Process, but they start to replace parts of that process, and over time, as the technology matures, as their understanding and confidence with the technology, matures, they start to build out more, but also look at brand-new problems that they've faced for a long time that have just been very difficult to address with technology. And that's when if you kind of bring all the, all of the, all of the assets together, the things like A2A and MCP, things like Agent 365, things like the security governance and compliance capabilities that the Microsoft stack offers you, it really does let you start to look at these problems in a very different light and start to apply technology to, to things that you just previously wouldn't have tried to 'cause it was too hard.
So let's talk about really getting started with agents. You've talked about agents being on a spectrum. How should organizations assess where they are, and what kind of agents do they need?
Uh, you talk to a lot of different customers and you have a good sense of that. Can you share that with us? Yeah, totally.
And there's no single answer to this 'cause everybody's different. But I think it's important for people to start in a place they feel comfortable with. It's very easy to run into this too fast, not be super successful, and then, and then feel, you know, a little bit terrified for, for trying to scale it.
So, it's actually very similar as well to the way that people in the past, over the past six, seven, eight years have deployed low code. The deployment patterns that we see with things like Power Apps are very similar to the customers that we see deploying, you know, agents in any meaningful way. I mean, actually the comp-cu-customers that have already deployed low code at scale seem to have a very familiar pattern to follow with, with how they deploy agents.
So it really does fall into that pick a business process, maybe it's the... Maybe just pick one. Find the one that's the most inefficient, the most expensive, the most painful.
You know? It's, it's creating the most work. And then break it down to, into its com-decompose it into its component parts and start to figure out where you could apply agent technology to those component parts.
Don't try and replace the whole thing. " Now, that may be possible, but it's really difficult. So basically, figure out what that recruitment process looks like and break it down and then attack it in chunks, and then you'll learn what the product, the, the technology is capable of.
You'll learn what your, you know, your teams are capable of. And as both mature, you'll be able to expand and e-expand it within that process and expand it outside of those to other processes as well. So it really is a, it really is a journey, and, and most people will find their own way through it.
We have a ton of best practices, guidance, patterns and practices, that kind of thing, thing, and templates that we, that we can share, but, but ultimately, every customer is different and everyone's gonna look at this differently and figure out which, which is the best place to start. So when we talk about agentic business transformation, we see a lot of organizations are trying to figure out, well, how does this fit into my legacy, systems, the architecture I have today? Uh, what thoughts do you have about how do we, how do we bridge that gap between, you know, the modern agent stack and, legacy IT?
Yeah. There's a couple of things there. The first one would be find ways to integrate, like MCP is a perfect way.
The, the, the rate of adoption, for MCP has been phenomenal. So go learn about that. Go figure out like how you could stick an MCP server in front of the services that you wanna expose to, to your agents.
That's step one. And then step two is, if you already have, you know, deterministic workflows, which I'm certain everybody does, there are ways you can start to pull those in to things like Copilot Studio, keep them deterministic, but build them as agents. And that's one of the kind of the great value props of Copilot Studio is you can blend this kind of non-deterministic AI agent-driven approach to workflow with very deterministic, with things like agent flows.
So you can actually replicate what you've got in an agent, and then over time, you can start to create, you know, replace pa-parts of it so it's more agent dr-like AI agent-driven than deterministic. So there's lots of ways you can start to bring these two worlds together without kind of diving in or, or not. Agents will become the core logic and decision-making layer in businesses, business processes soon enough.
How does agents as the new logic layer, change the way that, enterprises think about their core systems? What are the implications there? Yeah.
I think, there, there's gonna be a, a meaningful change with how people interact with core line of business systems like ERP, like, like CRM. Um, traditionally today, there's a-- this is kind of a forms over data type web experience. You have to go somewhere, fill a bunch of forms in, input a bunch of data and, you know, press submit.
I think fairly soon that, that there'll be kind of an inversion of where the IP and the logic sits. It'll be less on the database and forms layer. It'll be much more on the agent layer.
And what that means for users is they're gonna get faster access to data. They're gonna get smarter answers. They're gonna be able to use multiple data sources to, to assess a cert-situation.
You know, if you're a seller, why am I sending you to the-- to our serv-cust-- you know, our customer service, solution plus your CRM to go figure out what the customer you're about to meet, whether they've got any open support tickets and they're angry at with you. Like that, that it should just be able to ask an agent to be able to do that. Um, if you're a salesperson and you've just got off the phone with a customer, maybe the call's transcribed, maybe there's a bunch of email traffic between you.
Why am I making you go repeat that, cut and paste it, make it up again, and submit it into a, into a CRM system somewhere? An agent should just be able to do that. So I think, I think there's gonna be that switch from people laboring away in, you know, web forms and web services to, to an agent proactively, in many cases, working with these systems, and helping the, the salesperson or the service person, whoever else it is, to get more done, and be way more productive.
So how are agents enabling organizations to leapfrog, traditional low-code development and go straight to intelligent orchestration? So I'll give you a few examples. The first one is, I wouldn't exactly say leapfrogging, I would say we're using agents to make that kind of low-code paradigm even stronger.
Uh, so things like the ability to use plans in Power Apps, where gone are the days where you're trying to describe an app and build an app, what you do is describe a business process, and then Power Apps plans can use, several agents. There's an architecture agent, there's a data agent, and it can actually go build a business solution for you. So...
And that business solution could be two or three apps, some workflows, a couple of agents. It'll actually do the end-to-end thinking, like if you were a business architect, what would you build versus just building an app. So that's number one.
We're, we're leveraging agents to help you build kind of better low-code, solutions. And then number two, you know, we have new capabilities in M three sixty five Copilot, like Workflow Builder and, and App Builder, where someone with absolutely zero coding experience can come and literally describe an agent or a workflow, and App Builder and Workflow Builder will go build it for you and run it. Uh, and then you can-- it, it, it can store persistent data in SharePoint.
It, you can share that with other people. Uh, you can even start to modify it. So if it's not exactly what you want the first time you kind of describe the app, you can modify and change it as much as you want conversationally.
And that really does open the door to many more people being able to kind of use this technology. These aren't gonna be apps that you end up running your business on. They can help a team or an individual achieve more, be more productive, using AI, to build apps, things like apps and, apps and workflows.
So what we're seeing as companies, plan for the role of the maker evolving, where that maker has really been that low-code developer who's been using things like Power Apps, to build point solutions in their corner of the organization. What we're seeing is that role is growing up, and it's becoming, one that, that's gonna take advantage of this, o-of these, all these intelligent agents that are, being built inside the organization. And now they can build new solutions that span departments and, and cross, silos, in terms of the business processes that they can integrate.
And so creating higher order, more strategic solutions out of that agent landscape that's, that's forming. And these are things that, that, you know, now will automate and run on their own. But is that, that we see that, that maker still has a role and in fact an even more important one.
I was wondering what you thought about that. Yeah, it's a really important point. I also think IT are gonna play a very important role in this as well.
You know, they're, they'll be the ones building the MCP servers, so they can provide access to, you know, data and, and, and logic to, to business users units that, that wanna go build their own agents. They, they'll be the ones that are building the kind of high order bit agents so that, business users can take advantage of those. So I think when, when you bring those two things together, you know, you create a, definitely create a, total is greater than the sum of the parts type math for, for customers.
So in this new world of agents where it, it's, you know, the code, the, the AI is touching your business and your data, the, the concern is around compliance and security. Uh, I was wondering if you could speak a little bit to, how does Microsoft ensure that these very powerful agents that are working with your business, are following the rules and are secure? Yeah, it comes up a lot, in conversations that I have.
The thing to remember though is, agents only have access to the data that you give them access to. They also respect all of the policy, all of the governance controls that you've got over the data. They only get access to it if they are granted access to it.
And I think that's fairly, unique to the Microsoft stack in the sense that all of the investments that you've made on things like Purview and, and managing SharePoint, that kind of stuff, that all just flows through to agents. Uh, when you go, when you go outside of the Microsoft stack, you essentially have to kind of copy-paste that data somewhere, and at that point you lose all of that governance control that you once had when it was in the kind of your M three sixty five security boundary. So it's a super important point and one where I think, we have a, we have a fairly meaningful differentiator for, for customers.
Everything just works. I think it's, it's fairly just pretty much as simple as that. And so thanks so much for, for being here, Richard.
It was, great to talk with you. Thanks, Dion. Yeah, it was a really full conversation.
I appreciate your time. So what was really interesting to me is, is seeing how far Microsoft has come so quickly with agents. As, we see this as, you know, a whole new stack that's forming inside the organization.
It was really fascinating to hear that, that, that, you're spending so much time, looking at how do I make agents work across the business. Uh, I think we've looked at a lot of, individual automation, in, in the past in low code, but I think it's that, it's understanding that Microsoft has that big picture view, and it's the breadth of the tooling. Um, it's the, the scope of, of understanding it's, you know, not just departmental.
Of course, it's departmental, but it's also how do we make this enterprise-wide, and how do we elevate the thinking so that, we're preparing those inside of our organization, to, to take advantage of the big shift that's happening going, you know, from building maybe those point low-code applications to orchestrating across the business. Um, and a lot of the pieces around making, you know, agents work together, providing that security and compliance that ensures that you can do all of this safely and not constantly sweating, am I going to go outside the security boundaries? Am I going to go against corporate policy?
It, it really is gratifying to see how far Microsoft has come in, in assembling this vision, and then offering it in, you know, it's n-n-no one can say this is mature, yet, but, you know, hearing about, how the, the stories, we see at your events about how far the customers are coming and already getting a lot of these things out there. So, that was the takeaway I had, is just, you know, getting a sense that Microsoft is really trying to make sure that they're leading this, this agentic transformation. Welcome to Reality Check.
I'm Dave Nicholson, and, this is a program where we talk to people who are making real decisions with real money, laying real reputation on the line, in the field of AI. And we like to break this down by industry vertical, horizontal. Uh, we've taken a look at the software development life cycle in financial services as an example.
Uh, also, we've taken a look at this from sort of the general counsel's perspective. You know, what are people doing on the legal side of things? And today I'm really excited because this is a category that I think a lot of us think we understand, and that is retail.
Because most of us have been in a retail establishment, and in modern times, most of us have experienced e-retailing. We've bought something online. If you haven't, you're living in a cave, obviously.
Some of us have even worked in retail in our past. Um, in fact, I sold, women's couture shoes at Neiman Marcus a very, very long time ago. So again, I have a sense that, like, I know retail, but I really don't.
Uh, we have a guest today who really, really knows retail, not only the history and what's going on now, but, but what the way forward with AI looks like. So I'd like to welcome our guest, Adam Gelnick. Welcome to the show.
Thanks for being here. Thank you so much for having me. It's really an honor to be, having this conversation with you.
No, I really appreciate it. Um, I got to know Adam, through a series of conversations that we had about AI in retail, and it was really fascinating for me to hear some of the kind of background, on, on retail, especially because Adam, this isn't just his profession, he's part of a legacy that goes back, g-generations in terms of the retail business. So I wanna start out with sort of that as the foundation, Adam.
Can you kind of tell us what retail used to be like in the good old times? And- I can tell, I can tell you it anecdotally. Uh, my entire career has been part of this flux moment.
So, I guess it'll be great to start with, I work at a company called Eglock Corporation. It was started by my grandfather. Now it's, run by my mother.
It's about 65 years old, and we are actually, you know, finishing up a transaction process that is going to join us with a larger infrastructure entity that's going to help us really compete the way we need to compete in the, the current state of the world and become more of an accessories-focused business rather than just a pure play watch business. And we're really excited about that. Um, but your, your point is really relevant, because I'm not just speaking from the watch category or the accessories category, and I think that it's important to make that distinction.
There are a lot of different ways to, understand the retail category and, you know, our category is definitely, not as exciting anymore as perhaps apparel or athleisure or, you know, Apple. And so I think that what, what I think I, I have, the ability to, to kind of shed some light on is problems that are actually, I guess agnostic to, to industry, things that, that everyone has, experienced and will continue to experience over the course of the next, you know, however long this disruption happens for. Um, but impo-- as, as in anything, in order to understand where we are, we have to understand where we came from.
So, I appreciate you bringing up the history, and I think that we can fast-forward, to where, you know, Amazon basically comes on the scene and reestablishes, you know, what the commerce world looks like. It, it took a while to, to get where it is today, obviously, but, you know, that moment over two decades ago, is really the ground zero for, a major, major shift in a decades-long process of things kind of happened and made sense in the retail category. Whether you're a wholesaler like us or you have retail shops, you, you had the ability to, forecast your, your foot traffic and forecast your, your quarters pretty accurately, whether, you know, in our case it was, you know, programs that would come, you know, four times a year, as well as replenishment and the like.
And then ultimately, you were able to build a, a business and growth profile that was pretty reliable and, you know, things that banks are, you know, comfortable with. What happened or started happening, at the outset of this e-commerce transition or disruption was the customer, or let's call it the end consumer, because as a wholesaler, we look at it in two different levels, right? You have the customer who is a retailer or somebody who sells to consumers, but ultimatelyYou also have to be mindful of who the end consumer is, otherwise, you won't be, you know, selling any product, and you'll be getting all the products back from your actual customers.
So fundamentally, as a wholesaler, we have these two levels of customers that we have to be concerned about. But the, the upshot is the same, right? You have these end consumers who are now given the opportunity to explore products that you used to be their, you know, not just primary, perhaps only resource for, and now they're seeing all of these things.
They're showrooming. They're, they're, they're given many different ways to buy it or options against buying the brands that you were selling them, so on and so forth. " Or the more, thoughtful and forward-thinking idea is recognizing how game-changing this, this movement is and trying to go where the puck's gonna be, not where the puck is.
What retail did, and this is the, I've totally been reductive about what happened in this period, but I think it gives the, the understanding that I can now tell you that most retailers, as i- is indicative by where they stand today in today's marketplace and why your, Mag 7 has no retailers other than Amazon in it, right? Your, your outcome was that, well, they tried to protect what they had, say things like, "We don't need the, the e-commerce business. " And they took a position of, I, I, I think it's a great term, optimizing decline rather than being mindful or thoughtful about how to optimize growth.
And- So let me, let me, let me just-- let me kind of, double-click on that for a second because so are, are you describing kind of the... I'm not even sure if I made the word disintermediate up. I think spell check constantly acts like I made the word up.
But what I'm hearing is a situation where you used to have a more direct... I, I, I'm using you as proxy for retail. Uh, retail, retailers and the wholesalers that they, that they're working with would have a more direct relationship with the end user consumer.
Amazon comes into the middle. So the state, the current state of the, you know, the art here is that Amazon is controlling, in this case, the customer experience. Uh, you're, you're going into their virtual showroom.
They're trying to upsell you, sell you to the left, sell you to the right, and you have far less influence, in terms of that relationship today. So is that a fair assessment of where we are? So you talk about managing decline.
Is that sort of a, "Hey, we don't get a chance to shake the customer's hand and say, 'Come on in. '" You don't have that opportunity anymore. It's very true.
It's very true, and I think that, the, the one caveat I would say to that is our wholesale business generally didn't have a shake the hand of the customer. I do believe that, you know, if, if we're gonna just take the other side for a second, the e-commerce shift in that history allowed for brands to more directly connect with c-end consumers and take the middleman out. The, the, the ultimate happening was a negative for department stores and, any sort of retailer that was selling other people's brands that didn't figure out how to think bigger about this rather than, small and protective, right?
And, you know, almost, uh... A- a-and that's where you're, you're seeing a Macy's or a Sears or a... I mean, Sears and Eddie Lampert's decision, and I, I, I hope it's okay that I'm shifting over to this right now.
Yeah, sure. But, those companies m-made that choice to optimize decline, which means they put leadership in place who, who were not merchants and were not people who could be visionary like Steve Jobs about, you know, what needs to come next. Because a, a, a positive example is Steve Jobs basically said, "I am going to make thousands of temples," and I, I'm stealing that term from Professor Scott Galloway, but thousands of temples to the brand across the United States with, you know, Ron Johnson, as the head of retail.
That was, that was mind-bogging-bogglingly stupid as it related to what Wall Street thought they should do. Yeah. But literally- At a time, at a, at a time when malls were closing down and, and being rehabilitated- They were building stores ...
as Amazon warehouses, yeah, Apple's opening up stores. Yeah, interesting. So I, I think that it's a great example of how you could have done it better, right?
How you could have... The, the whole fundamental shift is this connection with the consumer, the end consumer, like you're talking about. Wholesalers never had the ability to do that.
So we had to figure out who our customers were gonna be so that we could connect with those end consumers. So when Amazon disrupted w- the Macy's business, the Sears business, it put Toys "R" Us out of business, not because they were so bad, although we could get to that at another point, but Toys "R" Us gave over all of this stuff 'cause they said, "We don't need to manage the e-com. " And there's a case study about literally that decision being the reason they're bankrupt now.
And it, there, there are a hundred examples, the most recent one being the, the Saks and, Neiman Marcus and, and, Bergdorf being owned by a real estate guy. They chose leadership thatWere not-- They were never going to help this, this im-important industry and glamorous industry, shift for the long term and compete in a way that was, actually, going to, restore... And again, it's about experience, like anything.
Um, you go to these brands like Macy's because you trusted their merchants and the things that they bought as the things that I needed to buy. And at every level of retail, that was always the case. That trust is no longer there because they're running it as a bottom-line business.
So I guess when, when we talk about why the history is really important, it's because, okay, this industry, retail, which is super well-known and super high touch for every human on the planet, is now, okay, a, a really weary and, and downtrodden organism that is-- has no defenses to, I don't even wanna say fend off AI, 'cause it's the wrong idea. You're not trying to fight AI, but literally this industry has no ability to control its destiny or the narrative. So let me, let me ask you then, because if I'm-- if what I'm hearing is, a story of, of technological disruption in the sense that e-commerce comes along, disrupts brick-and-mortar.
Um, you know, again, let's y- w-w-we're both gonna be guilty of reducing things to simple- Sure ... simple terms. Uh, but that's okay.
Sometimes that's the height of genius is being able to- ... come up with those things. Um, that's what my wife tells me anyway.
Okay. So, um- It's fake news. It's not real.
Fake news. E-e... So e- so e-commerce comes in and disrupts brick-and-mortar, and, the, the overwhelming response from brick-and-mortar was to essentially manage the decline at some point.
com. All we need- Right ... " And it's like, no, it doesn't work that way.
So e-commerce comes in, disrupts. So you've got this weakened really kind of, I'm trying to think of the right word, just downtrodden industry that you describe as an organism. Well, now AI comes along.
So the question here is, is this a chance for revival for any part of retail? Um- Absolutely. I think that- And so if it is, so I wanna...
You know, so let's, let's talk about that. Not everyone is going to embrace it, and I have to say- Yeah ... just giving a little preview because I know that you're engaged in exactly this, figuring out how to leverage AI, right?
Right. But I think it's hysterical. I, I it's hysterical, forgive me, but it is hysterical that you're gonna be c- you're gonna be convincing people, on, on the board, et cetera, et cetera, and one of those people is your mother.
Yeah. So- So there's the added, there's the added twist there because you've gotta be- Right ... really, really clever about this.
Yeah, 'cause let me, let me tell you, the minute I try to convince her of anything is the minute I'm not convincing her of anything, right? So I have to be super smart about bringing in a whole slew of important stakeholders and influencers within the organization at, at b- at all levels, right? The high levels of the organization, the, the, the managerial levels, and I need them to understand a-and therefore I need to ar- clearly articulate all of the important things that I think are, are worth sharing so that it's not just my voice that she hears because, you know, she loves me as a son, but she's very objective as a leader.
This is a great, this is a great case study from all, from all different- Oh, for sure ... areas. So, so you've got this e-commerce landscape, and a term that you used when we were talking, earlier, was, was omni-channel.
Yes. And, and so can you kind of tell, tell us about what that sort of omni-channel concept is and how it relates to the landscape today with e-commerce and what traditional retail is up against. Okay, so it was really interesting a-as it relate a, a little bit back to the history because, you know, dot-com bubble, you put anything with a dot-com, that means you're doing great.
You find it in all the S1s and all of the quarterly reports. You know, you know it's a real important word when it literally is being re-re-replacing vernacular so that you can get Wall Street to be excited about your company. Um, that was dot-com.
That was Amazon, e-commerce, and even after the bust, it, it was still like, you know, that was the thing. At some point, and I think it really happened with, with Apple making stores and, Amazon realizing that there was going to be some sort of ceiling to their connection with the consumer if it was only a digital platform, that omni-channel became the newest buzzword. Omni-channel basically says you're connecting with your customer on multiple different platforms.
Y-uh, you know, at that point, it wasn't, social wasn't as, powerful or important yet, so it was really just on a commerce level of, okay, you're a digital, you have a dot-com, you have warehouses, you have distribution centers, and you have retail stores if you're, you know, in that business or whatever. And all of those different things interact with one another to create a more seamless experience for the consumer. That hasn't manifested in the perfect way.
It's definitely made them a stronger omni-channel player. But Wal- if you were gonna talk about the, the pinnacle, omni-channel player right now, it's gotta be Walmart. com had.
Um, and that really, leapfrogged them over the competition and brought them into a, a much more, competitive landscape on the tech front and the logistics front. But they in them- i- in and of itself wrote the book on logistics and making, you know, the most out of your distribution centers and your stores, and, you know, less, or most efficient way to ship things and freight. They re- th- they are the, the, the be-all and end-all in that, in that category.
Adam, how about Costco? What about Costco? Okay.
Costco is a great example of, a, a customer-minded company who the, the fewer stores, certain type of business, their margins are-- Their margin profile is different than a Walmart profile. It's a membership subscription model. Nobody treats their customers better.
No customer wants to shop in a store more than the Co- Costco customers. I would say that their omni-channel efforts have not compared to Walmart's because they're not... They don't need it.
They, they have people, their members are excited to come into the stores, and they don't want to change that. I don't know how that plays out in the future, but their stock price indicates that, it doesn't need to change right now. Okay.
com, but- There is ... as a- And the, it- Purely anecdotally, I just-- The reason why I ask, just the other day, while at Costco, I noticed on my membership that it shows that we've been a member for 32 years. That's amazing.
Which is, which is crazy. I'm not, I'm-- I haven't been, but as- ... as long as I could be, I have been.
Yeah. And so but, but, um... Okay, so but, but another example of...
So I mean, clearly they, they, they, th- they have an e-commerce arm, but not integrated, not the way that- Yeah ... like Walmart. Okay.
com. Uh, generally speaking, you don't have the same assortment on, on the dot com website. You don't have the idea where, you buy something in store, but you, it's not in store, they'll ship it to you.
Like, they haven't- Okay ... prioritized that omni-channel thing. You go into a, a Walmart, and if they don't have it in store, they're gonna find it either in another store or in a warehouse, and they're gonna be able to ship it to you.
And that's just one example of how the omni-channel idea is working and making use of slow-moving inventory in one location, one store in Texas that, you know, is gonna be able to support, avoiding a lost sale in New York. And in doing it, right, y- converting that sale is the s- the second most important thing. Doing it in a way that doesn't make it not profitable is the most important thing.
And Walmart has became an, is an expert in logistics and has become, over the course of this past two decades, an expert in that. Okay. So, so...
And that's crowded out a lot of small, you know, local retailers as an example, um- Sure ... through time. Pa- Wal- Walmart was the original, right?
Yeah. Wal- Walmart's the original, and then the irony of, um... I, I've had this conversation over the years.
The irony of small businesses that are in the retail space using Amazon Web Services for things- Isn't that ironic? which are actively subsidizing the retail side. Uh, so you're basically, you, you know, you're, you're, you're, you're making a deal with the devil at that point.
Right. Uh, not a, not a good thing. So here we are.
Um, there's this thing called artificial intelligence. Of course, you know that, you know, AI has been around for a while with machine learning and, and deep learning neural networks and all that. Um, but where we sit here in 2026, w- what are you, what are you thinking AI can do for you?
What are you looking into? Um, and not just, not just for your business because it has some particular- Right ... features, but broadly, within, within the kinda wholesale retail, market.
So te- tell us about the way forward with AI. Right. I'm gonna start with something I said earlier just to connect everything.
For the past two decades, we've optimized the decline, or these companies, I should say, have optimized the decline. Now, with AI and with these tools that are being developed daily, you have the opportunity to optimize growth. The question, though, is whether leadership structures can evolve fast enough to determine which tools should be deployed and how to properly use them.
And I think that when you frame the conversation in that light, y- you put a lot of the onus on your management teams and your leadership teams, and that's where it belongs because the framework is not yet set as to how this is gonna work industry to industry, company to company. I think that the answer to your question is it's t- i- it's the most important time, and it, it goes back to an earlier point you made, which is, is this a, you know, a, a revitalization moment? Is this a, a, an opportunity for the downtrodden to rise up and, you know, fi- finally move and, and, and change their stars a little bit?
And the answer is yes, for the companies that are willing to sayWe, we understand that the way we did things is not gonna be the way we're doing them in the future. And on the simplest, smallest level, I think Google has, has shown, an incredible amount of foresight and really guidance and leadership in saying, "We're going to optimize for engine optimization," you know, generative engine optimization, I should say. " And when you, when you think about the ecosystems that exist for generative AI right now, and, I'm getting a little bit on a tangent now, w-we can come back to retail in a second.
Google has figured out how to, I think, do what Microsoft did on the enterprise business level, which is... Or, or Apple did in their ecosystem with their hardware, is that we have the ecosystem for everything that is y- that you need in, in AI. They now have the Nano Banana.
They, they have... Gemini is, you know, at least if not as good, you know, better than s- you know, the ChatGPTs of the world. They're integrated into your, important email servers and, and drive, pro- They, they figured out that piece where I don't think standalone companies are going to be able to compete as well.
And Copilot's not really as good a product as these guys. But- Wait, wait. W-w-what-- Wait.
Which... W-w-what standalone companies? What do you mean by that?
Like, I th- when you think about the AI bots, right, the chatbots. Yeah. You, you, I, I...
And I, I learnt this from, from the course that we, I was fortunate to, to do with you. But it's, you, you have the Geminis, you have the ChatGPTs, you have the Clauds, and then, you know, Copilot is kind of, you know, there. Those are all pretty similar working tools, right?
Then you have other I... You know, other programs. Uh, you, you could talk more ex-explicitly about it.
But as I look at the landscape of those and seeing it from a, an organizational standpoint, and this is how I, I wanna kind of bring us back to where we were. It's like- Yeah ... okay, w- your organization works with Microsoft.
You're probably gonna end up working with Copilot, even if it's not the best tool right now. Because again, it's all embodied. It's a closed network.
You're worried about certain, you know, i-i-integrations and stuff like that. Google has that with lots of companies who use Google for a variety of different things. So that's why I think...
And then you add in all the things that they're doing, building their own chips and, the, the general know-how within AI that they've already learnt and done over the years with their search, product. I think it's become a much more- Okay. S- Um- Okay.
So you're, you're, you're, you're talking about the vertical integration that, that- Yeah ... Google has compared to, like, an OpenAI as an- Yes ... as an example.
Okay. O-okay. Just wanted to, just wanted to be clear.
Now, where does... So, it's interesting because it's an age-old story of, those who fail tend to do too much trying to avoid cannibalization. They're, they're- Yeah.
If your biggest concern is, "We don't wanna lose the business we already have," unfortunately, you lose all of the business that you would have had otherwise, and then you lose- Right ... the business that you have also. So- Right.
Defending the lead, right? I'm a- I- Yeah ... I like sports analogies, right?
So like- Yeah ... you're playing hockey, and you have a lead of one or two-nothing, and, like, if you're not continuing to try and score, you'll ultimately lose that lead, right? Yeah.
So okay. So now back to, back to retail. Um, how does this, how does this play out organizationally- So- ...
and then, kind of at the tactical level with things that maybe you're looking at that, that have caught your attention? Right. So I, I think that the, the companies that can benefit from it are the ones that, you know, get out of the mindset of, you know, we're just trying to reduce bottom line, costs or operating expenses and improve bottom line profits and change their mindset to say, "What will make us a, you know, a formidable competitor in the future?
" And the answer is in any of these AI tools, but it's not in them in piecemeal, and it's not in them in, you know, let's throw mud at a wall and see what sticks. The, the answer is actually in really holistic consideration around the problems that... or the, bottlenecks in, within your organization and then saying, "Okay, what's going to really solve those problems?
" And really to move quickly on those decisions. I think that, one of the things we really, that really stuck with me as it relates to the, the coursework that I did with you was this idea of really putting a group together of, incentively aligned people with many different inputs, with many different, skills and expertise, because this isn't gonna be solved by one visionary CEO, right? There's no way that he or she can understand all the different limitations, both on the positive and the negative side, right?
You could say, "I'm gonna use this AI tool because it's gonna make my sales team, you know, like Superman," but somehow that's gonna totally erode the logistics capacity that you did. I don't know exactly how that works, but y-you have these, these... You need all of these voices in the same room to make sure that you haveThought through all of the things.
And then you also need a really strong and visionary leader who's able to stop the conversation at the point that it needs to be stopped so that it doesn't die in, you know, deliberation at the same time. And you're speaking, you're, you're speaking from direct experience of going out- Absolutely ... and looking, and looking at, looking at the point solutions.
And, and I know that you've, that you've found, you've found some that are actually attractive. Yeah. And exciting.
I mean, there's a list of things that we were exposed to in the coursework and things that I've seen o- over the course of, my own professional work. But, th- the one that I wanted to talk about was this company called Pattern out of, Utah. Um, they are brilliant, brilliant people.
Um, you know, IQs well above mine. Um, what... I- in a sentence, I think what they've really done is, engross themselves in the world of Amazon retail specifically, but, you know, e-commerce and marketplace retail at large.
" And at each point, either they've acquired a company to improve their tech, or they built their own stuff to do it. And they've, in, in such a, effective and, clearly, explainable way, they've taken a black box of a business and, and, figured out a way to deliver, all of that AI need, at each of the different layers of either the cu- cu- customer life cycle or the, product development life cycle, and everywhere in between, wh- a- as it relates to the administrative s- work that goes into it. And they've created a way for you to scale your business, at, at less infrastructure cost.
And when, to go into each of the, the modules or the things that, it, they, they do would... You know, you have to go out there for a few hours and really understand it. But, you know, we're right now, and, let's get a little technical on the Amazon side.
We're right now an Amazon 1P vendor, a first-party vendor. They, like any wholesale business, they buy product from us, they warehouse it, and then they ship it to the end consumer. What Pattern did is they mastered Marketplace, which is the Amazon third-party business.
They take product as a wholesale customer from people like us, and they manage it from the logistics side, all using AI forecasting and, a- and, y- very, very, state-of-the-art type of, machinery and equipment to make sure that, you know, they're getting bottom, bottom, bottom dollar cost on that fulfillment, while also making sure speed and reliability is exactly where it needs to be for an Amazon business. And then they, alongside you, c- on the Amazon Marketplace platform, market and, you know, iterate and, test and do, you know, marketing campaigns and, and, you know, discount promotions, and work together with you to create that business that, you know, you were doing on 1P beforehand, but now you don't have to, you know, pay Amazon, these incredible fees to do that. They pay Amazon the third-party fee, and they've figured out how to mitigate the cost enough so that they can make money, and the wholesaler ultimately can make more money and more volume in a more healthy way.
Okay, so there was a point in time when Amazon said, "Hey, why are we, why are we giving so much money to UPS to deliver our packages? " So you're saying that AI is allowing people to do that now? It's a really interesting analogy because I, I think that the one thing I wanna share is I don't think Amazon...
Amazon obviously cares in some way about margins a- and, and profits. I have those conversations with them. They're like a- any retailer.
But they care differently. When, when they were growing, it was said that any time Amazon reported a profit, someone got fired. Why?
Because they didn't have to. Their stock price went up when they were losing money, so any dollar that was, that went to the bottom line was money they didn't spend on development, on something, whether it was Prime membership or building out- Right ... Prime Studios.
So, like, Amazon looks at profit differently and margin differently than every other company on the planet, 'cause they can, not because any other company doesn't want that same latitude and, ability to do that. I bring that up because I think their first and foremost concern when it was connected to the, the tr- decision to m- bring on trucks and planes and really steal business from UPS and FedEx was 'cause they can, and because they want as little in between them and the end consumer as possible. Because long term- Right ...
any, anyone who's on their or whose rails they have to go on is an impediment to their ultimate profit or their ultimate goals. They claim that that's customer satisfaction, but really it- it's, it's, it's a mask for the fact that it's just good business sense to, to wanna control- Sure ... your c- your destiny.
That's really important because what's really interesting about this development, so Pattern is the largest third-party seller on Amazon. They, they were at two billion in, in gross merchandise volume. They are now probably closer to three billion, if I had to guess.
This was, you know, last year. That's a really interesting thing because yes-Pattern is a, in-between business between them and their consumer and them and vendors. But if you take the same logic that we were just talking about before, how to maximize their profits but not necessarily in the most obvious way, if they feel that Pattern is doing a good enough job managing their customers, and, you know, they are, and now Amazon does not need to have a vendor manager staff to manage pain-in-the-neck vendors like myself who may or may not be doing what they're supposed to do, they lose that whatever percentages they've been try- we've been hondling over, but they get a, a basically toll road, 16% from Pattern's $3 billion.
So the more things that they can roll over to them, they have, you know, they've fired 45,000 people, of late. I believe that one of the canaries in the coal mine around that is a, an experience we had recently where the marketing group at Amazon said we're, um... It was that they broke up with us, right?
It was the not, "It's not you, it's me" line. It was us. Why was it us?
We're not big enough. We don't spend enough money through their group, so now we either need to do it on our own, or we need to find an agency to go out and do it. Well, guess what?
That's another-- That's an example of- And just to be clear, add, and just to be a- just, just for, by, by way of scale, we're not talking about hundreds of thousands of dollars in business. We're talking about- Millions. Yeah.
Millions and- Tens of millions of dollars. Yeah. Exactly.
Yeah. So- Yeah ... I, I believe the canary in the coal mine is they're gonna do this across all of their platform, where they basically say, "What do we need to be doing?
What human capital do we actually need here? " And when a company like Pattern, who deploys AI as their, their tool for, you know, benefiting everyone really, right? They, you know, they, they make it a better business for everybody, Amazon included.
And now Amazon doesn't have to employ, you know, a bunch of small business vendor, vendor managers for small businesses like, like ours. Well, they could focus on the Nikes and the Philips and, you know, that's, that's where they wanna spend their time anyway. That makes more, that's, I guess, more bang for their buck and j- worth the j- worth the squeeze in, in terms of the juice.
So, okay, so it's interesting because, you know, there's Amazon and there's Amazon Web Services obviously, and some people- Right ... some people in- conflate them, in error. " And if I'm hearing this correctly, it's really interesting because this is an example of Amazon optimizing its bus- having a third party optimize its business with AI.
It's not Amazon people. It's not an Amazon engineer, vibe coding, you know, or using Claude Cl- you know, OpenClaw to do something. This is a third party that is creating optimization that allows Amazon, sadly, you know, hey, it's the way of the world- Yeah ...
to let people go, and the net result is efficiency that's good for you, it's good for this Pattern company, and- Yeah ... it's good for Amazon. At least Amazon is judging it to be that at this point.
Um- Yeah, I think that they, you know, don't listen to what they say, listen to what they do, right? I, I- Yeah ... think that that's, that's what you're hearing here, right?
You speak to a vendor manager, and you don't get any of this i- indication. You speak to, you b- you speak to people like me, and you get y- and the interactions that I'm having and what we're seeing, you know, from our conversations with a company like Pattern, it's, it's, it's exactly that. And I, I think that the, the most important distinction there is it's not, Amazon won't view this as outsourcing optimization, even though that's what it is.
They're, they're reducing a risk. Their inventory positions are, you know, a risk by all standards, Wall Street standards, cash flow standards, their own management, metric standards. So by, by reducing, it's not just about reducing the cost of em- the employees, which, which is definitely something that they're thinking about, or re- I would say it's probably repurposing, right?
I think that they- they're not, eh, not hiring. They're just not hiring for this, these positions, and they're, you know, re- you know, reallocating those assets. Reallocation of capital, yeah.
Yeah. Investing in other things, yeah. Right?
That, and, and that's where the AWS versus the retail side comes into play, and all the other organizations or divisions that they, they have. They're, ultimately, they all run up to one company. So, you know, Andy Jassy at the top really doesn't care where the profit comes from or where the, the growth comes from, as long as the growth is what he expects it or needs it to be o- on the whole.
So he's happy to repurpose that resource allocation from, you know, vendor managers in the retail side and buy more data centers so he can, or, or, or more Nvidia chips so that he can, you know, do AWS better and make more of a, a toll road there. So I think that that's hard for, I guess it's hard for retailers to, to fully appreciate that their business is really just insignificant relative to, to the whole. So things can shift, you know, i- in a nanosecond because of, you know, decisions that, are, are beyond the scope of, you know, their day-to-day, which, m- makes all the difference in the world to companies like us and certainly the, the PNLs and, and, you know, open-to-buy, product that they, that these vendor managers have.
Back to the point about, understanding where these, um-I guess, vendor managers' heads are at or where why I, I think that pattern is not, really a threat to Amazon in any way. It- it's... They, they're propping them up.
They, they basically reduce risk, reduce cash flow obligation, and, and, and turn it into a, a toll road of a, of, of a business. And all that business is still happening on their platform, exactly what their ultimate goal is, to make sure that the Amazon customer stays on the Amazon website. One, yeah, I mean, that is it.
And so when, when we think about this, right, I, I, I'm, I'm now in consideration for moving my business from 1P to 3P. That's gonna be a, a not great thing for the vendor manager losing a brand, potentially, if it happens. Um, but, but Amazon loses nothing.
Okay, so that's a, that's an example of from, from, from your perspective, your responsibility to not only, make sure that you're doing the best for your firm, your business moving forward, but for a family legacy. No pressure. No pressure, Adam.
Um, but so that's an example, and you talked a lot about Pattern and what they do, and it's a fascinating case study in how AI finds its way into the value chain in kind of indirect ways. It's not, "We bought this AI tool. We're now running this tool.
" It's like, no, it's complex interactions. So that... Let's call that the sort of tactical space.
You mentioned something at the outset, though, about how critical it is to have more of a, a, a leadership mindset that isn't just focused on one point solution. Uh, the question I have for you is, well, what about the vendors out there who believe that, "Well, wait a minute, Adam. " How do you set your organization up to be able to be open to those things and evaluate them and then maybe integrate them over time?
What does that, what does that look like? So what does this, what does this council of elders look like? It's a really good question.
My, my turn. And I, I think the first, the, the first thing is, is a framework for that council of elders, let's call them just for purposes of our fun conversation here. Um- And they could be youngsters.
They could be youngsters too, right? It's AI. Eh.
I, I think that everybody needs the, needs... on this board would need to at least subscribe to the idea that experience leads to wisdom and wisdom leads to good decision-making. So if you wanna be on this board- Fair enough ...
that's, that's a mindset you have to have. Um, I, I think that it's important to start with the framework, which is you need to have a, a variety of different expertise and voices, you know, i- in, in the conversation. Um, and where maybe your organization doesn't have that, you need to get it from the outside.
Um, a- as an example would be, our organization is very homegrown, lots of different great people within the organization who know a lot about what we do. We definitely, on this, you would need an outside advisor who understands, you know, how a- another category works or, you know, has done things in tech that, you know, will, will bring an important level of, a- insight and expertise to the table. That's like just one example of how that could work.
But a- as important as the different voices and the, you know, the different expertise is like the, the leadership role of somebody who is wise enough to know, when the conversation needs to be, prolonged and when, you know, the, you know, conscious discourse is, is good and healthy, and when a decision needs to be made and everything needs to... and everyone needs to, subscribe ultimately, regardless of your position on what that decision is. Everyone needs to, you know, I think Jeff Bezos says it best, you know, disagree and, commit, right?
And I think, that, that mindset is going to be super important for any organization that wants to make these types of big decisions. Now, I will also say in these boards and in y- the organizational framework in general, you definitely need to have room for small mini trials, right? That aren't, you know, as big and, and, widespread.
They need to fit within the, the almost like a, a vision statement or mission statement for this disruption and this flux. And maybe, maybe something should be drafted that, you know, puts that, in a concrete form, where, where you understand that things are changing and this is, you know, we're gonna do this together, but whatever happens tomorrow, w- we know it's gonna be different than it is today. Yeah.
And that understanding, y- you create a, an opportunity to be nimble enough to activate on the smaller opportunities to test, and maybe that pushes you in a different direction, and maybe Pattern is no longer, the, the, the right path or the right, tool for, for us to be using. Um, that's where this group needs to make sure that they're, you know... It's like any good investment, right?
You, you're, you're sitting there and you're sitting on it. It's been great for so long. You still need to...
And this is where my portfolio management, you know, mindset comes in. You still need to pressure test it, right? You just because it was good five years ago doesn't mean it's gonna have the same earnings capacity down the road or the same dividend capacity that, that you, you know, you've always counted on.
So in order to not get stuck in a, you know, comfortable, complacent, position, you always need to be pressure testing that. Now, decisions like Pattern are much larger and more difficult to unwind than perhaps, you know, trying a new tool that, you know, is able to generate, videos, you know, for your marketing campaigns. Yeah.
Understanding that alsoUh, is, is helpful in your, your discussions within this, you know, council of elders where, okay, if we do wanna consider changing from pattern or from some big decision that was holistic and widespread, well, here's here, here's what that's gonna cost us, whatever that looks like, time, money. And, and your, and the council of elders has to be willing to understand that there's going to be a blank space in the agenda, a month or two from now for something that hasn't happened yet. Right.
Something doesn't exist. I love that. Yeah, we talked about that.
That was- And so, and, you know, I- I, I think that's really, really smart, almost like, on your calendar. Yeah. It, it-- we, kind of welcoming a new c- new cohort of folks in the program you referenced, at Wharton.
Uh, I ma- I made the point to let everyone know that the most exciting session we would have would be on the subject of something that has not yet happened. Yeah. And so on that note, Adam, we're gonna have to have you come back, at a future date, and what we're gonna talk about is something that hasn't happened yet that is a meaning- I'm really excited about that.
It is a... It will be a meaningful development that will change the way that you look at how AI can help you in the retail space, and we don't know what that is going to be yet, but, but, but when it happens, we'll, we'll have you come back. I wanna thank you for, for spending this time.
This has been great. We could, uh- Thank you so much for having me. We could spend hours more on this, and we will in the future.
But, thanks again, Adam, for being here. I'm looking forward to it. Thank you so much.
And for Reality Check, I'm Dave Nicholson. Stay tuned to this. It's just gonna get better and better and better.
I mean, look at this, look at this smart person that we had a chance to talk to about this subject. Uh, this is, this is really going to be exciting moving forward. Thanks for tuning in.
So as you, you know, made these decisions, you had certain things, you know, and with your view from an architecture perspective, real requirements to drive real network outcomes and performance outcomes. What are some of the things that ended up on your list of things the new network infrastructure must do? What were some of your key issues that you were addressing through your requirements gathering?
Uh, first, you know, we were getting also exposed to, public cloud, you know- Mm-hmm ... the automation there. We wanted to drive our on-prem like we do like in public cloud, you know?
Sure. Uh, make it more, more consistent, automated, and also, simpler to, to manage, you know, s-simpler to specify what you wanna do and get consistent results. Um, so we wanted on-prem to look like cloud.
Uh- Mm-hmm ... but we, we ended up with even on-prem, I think, in a bet- little bit better state than cloud because- Wow ... we had more control there.
Sure. W-we had more control there. We were able to, to control the underlying, management platform, where we couldn't do it i-i-in the cloud, really.
Um, so, um- Would you, would you call that- E-eco- Was that, was that an objective, or was that a happy side effect? We had it as an objective. We didn't achieve it with our first iteration.
Our first iteration was a few years ago with a different platform. Sure. And we, we didn't really achieve that part.
Okay. But with, with our newest platform, it gave us the, the, it, it's op, you know, being open source- Sure ... and with lots of tooling, it enabled us to put around it the, the, the, the solution that will achieve this objective.
Sure. Yeah, you, I, I know from previous conversations the ability to use more open source tooling really gave you more options and gave you more ability to customize. Yes.
A-and you... I mean, what we did, I mean, we did a lot of innovative work really, and, and we started as a s- we were a small team. We were maybe three or four engineers at the beginning.
Wow. And when we started, we really didn't know any of this modern networking techniques, but having an open source tool, you know, then you can, you can put somewhere, you know, can look on the internet really or, you know, other people would have faced what you are facing. It might n-not be, not related to networking, it might be related to something else.
Sure. But having an open source tool that people have, have, have touched this open, which is Kubernetes, we're, our tool is based on Kubernetes, and, you know, millions of people are using Kubernetes, and they've built tools that enable it to communicate with this Kubernetes cluster and do interesting things that we have used in our solution. Got it.
I don't want to, undercount, you know, the, the, the global scope of the network. You had... It wasn't just like one data center or a pair of data centers.
Talk, talk a little more about global topology and, what data center resources you had to bring all in line together. Okay. So, I mean, we've got data centers in all continent, Europe, U-US, Asia.
Uh, they're very complex data centers. They're du-dual data centers, and, got applica- you know, one is active standby of, of the other. Um, it started with a very flat, flat architecture.
You know, we've inherited a flat architecture, and we continued thinking flat, but then we made it a much more interesting, modular architecture- Mm-hmm ... you know, of the data centers where we can add remote data centers together. And we wanted, you know, a, a, this flexible architecture, but we wanted a tool that will understandThis flexibility- Sure ...
and enable us to have this modular, flexible architecture. So, that is, that is what we had in the architecture side. And when you say dual data centers, you mean dual data centers in each geographic location?
Like, you know, like within- Yes. We have... It's a, a dual geo-redundant data center.
Yeah, yeah. So, so they are, they are in the same region but, geographically apart to back up- Yeah ... each other- Yeah ...
in case of a disaster. Separate power, volcanoes- Separate, uh- ... et cetera.
Yes, yes. Yeah, yeah. Yes, yes.
Not to imply that anything- Yes, of course ... is actually in Iceland. Um, but, I know people have had routers taken out in Iceland because of lava, but anyway.
Uh, my name is, Chad Smith. I'm the Field CTO of Alliances here at Hammer Space. And today, I'm gonna give you a demonstration of Hammer Space running both on-prem and cloud, kind of a hybrid solution.
Um, I decided on doing demos instead of slides today because, a lot of you have a lot of experience in hearing about Hammer Space, talking about it, but not actually seen it in action. Mm-hmm. So I went ahead and recorded a couple demos I'd like to share with you guys today.
So today, I'm gonna present you guys with four demos. Um, they're covering, various topics such as assimilation, global file systems, Tier Zero, as well as our, our S3 interface and metadata. So let's jump into w- the first demo.
So the first demo is really all about data-in-place assimilation. We're gonna walk through the process of setting up storage assimilation, shares, storage systems, volumes and mounts. We're gonna spend a little bit of time discussing Hammer Space sh- snapshot efficiencies tied to third-party storage and APIs.
Uh, we're gonna briefly discuss, multi-protocol access via SMB to an assimilated NFS server. And then finally, we'll conclude our first demo with what it takes to set up a global file system across sites. So let's jump into it.
I'm gonna start this video, and I'm gonna pause it frequently to discuss some aspects of the solution. So out of the gate, what you're looking at right now is the Hammer Space UI. This actually runs on the AnVIL server itself.
So as long as you point your browser to the AnVIL's IP address, you're gonna get to the Hammer Space interface. This is a relatively fresh cluster, installed on an on-premise environment. And the only thing I'm gonna show you guys that I took the liberty of installing is I just attached it to Active Directory.
And the reason why I did that is 'cause we'll be using, SMB, access throughout this demo. I wanted to make sure that cross-site, SMB access is, is set up correctly. So to start the actual, data-in-place assimilation process, what I'm gonna do is I'm gonna create an empty share called Collections.
So within our UI, I'm just gonna type in the name of it. Then I'm gonna go ahead and set a snapshot schedule on this as well. The reason why I'm doing this is 'cause we're gonna talk a little bit more about snapshots later on in this demo.
Once the, share is created, I'm gonna go ahead and, and add a storage system. I'm gonna call it Images, and we're just gonna add a simple description of what it is. I'm gonna pause real fast and talk about our A- API interoperability, to third-party storage solutions.
Really the... What makes it really efficient is that a Hammer Space file can live on multiple third-party storage platforms. But when it does live on a particular platform, we wanna take advantage of its, snapshotting and clone efficiencies, for its copy-on-write.
Uh, so what we have is deep API integrations into that storage to allow us to gain that storage efficiency- Right ... regardless of where it lives. Chad, Jack Pahler with, Paradigm Technica.
So a couple questions on that. You're talking about, when you say copy-on-write and third-party storage, are you talking about... And you talked about a Hammer Space file.
First, define what you mean by Hammer Space file versus the native files. Sure. Uh.
So Hammer Space writes its files out in what's called a clone structured file system. Mm-hmm. Okay.
That file system itself is basically our structure that we understand, but the third-party storage system may not necessarily understand. Even though it may reside, let's say, on a, a PowerScale- Mm-hmm ... it is our clone structured file system on it.
Now, what we wanna do is we wanna get the efficiencies out of that third-party storage. Right. Right?
We wanna use its, sta- space efficiencies and copy-on-write. Okay. So when you're talking about the, the, the copy-on-write snapshots, clone efficiencies, you're talking about leveraging the third-party- Yes ...
storage system's native capability? That's right. Okay.
Yes. But you gotta understand, our files can live on multiple storage systems. Right.
Each one will use its third-party integration to manage these, the storage efficiencies beneath the file system itself. Right. And then when you're talking about Hammer Space files- Mm-hmm ...
that means that, if I understand you correctly, when a user is interfacing through the u- the, the-Hammer space's global namespace Yes That user can see the existing files, but if they say they're going to create a new file, right, it's going to be a Hammer space file that's then stored in some underlying storage that may be a third party. Yes. Right?
But it may... That, that new file isn't necessarily native to the or the... It wouldn't reside, let's say, on your PowerScale as a file native- Yes ...
side by side with the existing. Correct. Right?
Yes. That's correct. Yeah.
So, that's what we refer to as data place and simulation. Mm-hmm. We're not gonna move the files or modify the files until it's re- it's a modification or a creation or whatever happens.
After the initial assimilation, then we'll change the, the file structure to a Hammer space specific structure. You still go through our virtual file system to access the file- Right ... 'cause we're tracking all those changes.
Mm-hmm. You would never go back through your Isilon once you assimilate it. That's where I was going to go to next.
Yes. So, so once you start using Hammer space, you essentially lose the access to, through the native interface- Yes ... to that file.
Yes. Yes. Okay.
Uh, we do have a process called de-assimilation, which puts everything back. Gotcha. Mm.
Thank you. Mm-hmm. All right.
Let's continue with the, demonstration here. So I just shown all the various products that we support, and this particular demonstration now I'm using a Manila, NFS server. Just adding the IP address of it.
Uh, we're scanning all the available volumes on our system. To us, a volume is amount, right? So that's an interchangeable term with Hammer space.
But we do see a volume on this server called, images that resides in the mount images directory on that server. Continue the presentation here. I'm just gonna select that volume, hit next steps.
Now, it's important I'm sl- I'm selecting the assimilate button. I ha- I went through that pretty fast. Let me go ahead and pause that again.
But the assimilate, the assimilate button, allows us to use the existing storage. We're not gonna re-silver that share and use it for s- new, net new storage. We're gonna use the existing storage that resides under all the files, the directories, and we're gonna data in place assimilate that.
That's by checking a box allows you to do that. And what would happen if you didn't check that box? It would re-silver it.
It would, it would clean it out, and it would just use it as a storage bucket, in essence. And delete all the data? It would delete all the data.
Okay. Yeah. You're not assimilating, you're just using that space to put more files into it.
I see. Can I, can I jump in with that? That's, uh...
Maybe, maybe you're gonna cover it later, but- Mm-hmm ... how does it work with... By the way, Brett Walrent.
Yeah. Uh, this is also to Jack's question, I think you answered. Maybe I misunderstood it.
But is it a bit, some of these flows almost seem like one-way flows. No, they're bi-directional, for sure. Okay.
A- and what I mean is, o- one-way streets in a sense. Like, if you assimilate to Hammer space, you then need to tell everyone to stop writing directly- Yes ... over there.
Is that, am I- Yeah, yeah. And we... Because basically what, what we're gonna do is you're gonna do a one-time remapping of your data, happens once.
So you're going to your previous, PowerScale storage. Now you're basically gonna tell your, your users or you're gonna remap to a, a, another drive, and then you're gonna continue on. Uh, and that's, that's your...
That, that is your, your outage window in theory is that one-time mapping over. Everything else, as data migrates and moves between multiple systems, I mean, a lot of people use Hammer space as a migration tool, right? I'm gonna go off a NetApp, and I'm gonna go to an Isilon.
Yeah. Well, I can now do this assimilation, and everything's seamlessly moving behind the scenes, and the users don't know from one day to the next, is my data actually residing on NetApp, or is it residing on an Isilon. All happens kind of behind the scene.
So it- Once you've added that virtualization layer- Mm-hmm ... of the namespace, that all just is part of the solution. So rather than it being an extended long outage- Yes ...
for the migration, what we're essentially saying is, is you're gonna have a 30-second remap to a new drive, and then from then on, the migration's just happening transparently and- Exactly, yes. Okay. Interesting.
What about availability in those cases then? What kind of solutions do you have for that? Uh, we'll get to that.
Okay. But you're using the, durability and availability that's already existing in the Isilon- Yeah, sure ... or the, the NetApp.
Yeah, that's on the back end. Like- Yeah ... you know, the front end where you're presenting namespaces, right?
Yeah. So our, our namespace is all virtualized. Okay.
And it really depends on, the devil's in the detail. It really depends on what protocol you're using. 2, that's all built into the metadata layer that's being presented by the Anvil servers, and we have this notion called a flex file, and a flex file hands out a layout, and that's the directions to where the file's at.
And it really kind of gets into the minutia or the, the details of the solution. But any other protocol that you're using, NFSv3, SMB, CSI Driver, and S3, that goes directly to our DSX server. And then that handles any legacy, protocols, what we call legacy protocols, and then that's distributed across multiple DSXs with their own virtual IP for each one.
So that is how you maintain your high durability across legacy protocols as well. Okay. So I'm just walking through the rest of the add volumes installation wizard hereOkay.
And in a moment, we will see it show up. There it is. Now, what we're gonna do is we're gonna go back to that empty directory that we had previously created.
And now what's happening behind the scenes is this data in-place assimilation process. It's running in the background right now. It's walking the file system.
It's collecting all the metadata itself. It's not moving the data, it's just collecting the metadata. It does take a couple minutes to happen.
This is running on a couple instances in the cloud, so it's not the fastest thing. But as you can see, we're already discovering directories, right? We, we can go inside a directory, and lo and behold, you can actually now see the files, right?
So there's all my files. Uh, it's updating right now, and as you can see, just finished with 14th, 14K files it just discovered on this system, right? What we're gonna do real fast is we're going to go ahead and check it.
Can I have access to that? And the interesting thing to note too, this is an NFS server accessing through SMB. So there's your bimodal multiprotocol access out of the box, NFS server connecting via SMB, right?
And that's what we're gonna verify and check, can we have access to these files? So I'm quickly going into the directory. I'm looking at one of the directories, and there's a file.
That's a permissions issue from, an earlier lab, but now I can go into this one. Click on the file, and there it is. I can see the image.
So now I can access this assimilated storage, from an SMB share. Now, the next thing I'm gonna do- I have a question- Yes ... regarding permissions- Yeah ...
that Bell advance. Uh, so I probably have permissions defined on the file system that exists- Yeah ... on target storage.
Yes. How is, how are those permissions assimilated by Hammerspace? They are assimilated.
Okay. I guess that's the que- That, my big thing would be like- That, that, that, that's yes, the answer ... can you mess with those permissions?
Yeah. No. All, everything gets, everything gets migrated over.
You know, all your, all your, your, your file permissions gets carried over. Um, we have an RC 2307 mapping that happens, that will map SMB permissions to NFS permissions, and it just... I can't really go into too much details about it right now, but it just, rest assured that it does get migrated over.
Going forward, as I start using Hammerspace- Mm-hmm ... to manage that portion of my file system, do the permissions get written back to that storage device? So if, if someone- No ...
wanted to make an end run around- Yes ... Hammerspace to that Isilon- Yes ... would the- Well, they wouldn't even see the files because we're also laying our cone structured file system across the files.
Every file becomes a UUID- Mm ... and within that UUID becomes a payload of file that's in a chunked format. Okay.
So even if they did directly to- Yes ... to the storage device and tried to enumerate files- Yes ... they wouldn't have permission to do it.
They would have a, a very difficult time trying to m- figure it out. Okay. So really- Yes ...
at that point, the only way to get to the files is through- Yes ... the Hammerspace interface, and that's what is- Yes. Yeah ...
enforcing permissions and access control. That's correct. Yes.
Awesome. All right. Thank you.
But to be clear, that rewriting of the file into the new cone file system, that only happens when the files change. Modified or written or changed, yeah. Well, because that's data in place assimilation.
Now, you can set, you could set a, a read-only policy where you, keep your file in place, read, and then set an objective, which we haven't really talked about, but those are the rules for data movement, to put it in another location, in another volume. So our professional services team generally will make an as- a, a assimilated share read-only, and then with- on that same storage system, make a new mount where all the new data gets dropped into. I see.
Okay. So there's different ways that you can address this. It really depends on the customer's use cases and situation.
Okay. So the next thing I'm going to do r- right now is I'm going to prepare this on-prem cluster for the cloud, and this is the beginning process of setting up the global file system between two sites. The way that we do that is we use a bucket in the middle or an object storage in the middle to facilitate that transfer of the data.
So in this next demo is just me walking through, adding a s- another storage system, but this time we're gonna be connecting to, some S3 object storage in US West One in this example. This is a little bit of a laborious prod- process. I, I do apologize.
It, it does take a little bit of time. Uh, but just basically drop it in your access key and security key, will give you, you'll give you visibility to all the available buckets. And then what we'll do is we'll pick a particular bucket to use as our, as our target.
Sorry to interrupt you again. Uh-huh. Um- Go ahead.
That screen gives me the willies. Is there any other o- option besides an access key, like a role? Uh, yes, I believe there is.
Yes. Okay. Um- Access keys, no good.
Yep. Yeah, yeah. Why not?
You- I think we have, like, access tokens and stuff, I, I believe. Okay. For this demonstration, you're walking us through the user interface- Yes ...
which makes sense. Can this all be done programmatically as well? Yes.
It can. Right. Yeah, yeah.
So we have, uh... Let me pause this real fast. We have, the HSCLIAnd then we have the HSTK, which one is a command line utility, then the other one is a toolkit, a- and it can be a Python toolkit.
Uh, and then ultimately, if you're really good, we have a rest, a rest interface as well. Okay. How about a Terraform provider?
Right. Oh, we have all that. Yeah.
So we, we'll get to cloud in a second. Okay. But we support every, every, every template imaginable.
Okay. So just continuing on here. Oops, I hope I, didn't mess anything up here.
Uh, so that actually concludes our first demo. So what did we do? We assimilated some, some third-party storage, in this example, just a Linux server.
And then we, made sure that it's accessible by SMB. And then we set up, an S3 bucket that can be an archive and DR disaster recovery bucket if you wish. But we're also using it as a means to replicate between sites.
Okay. So the second demo is we're gonna go ahead and deploy in cloud, and then we're gonna finish setting up the global file system. We're gonna quickly discuss, the Hammer space deployment options.
Uh, and then we're going to, enable and finish the global file system between sites. Uh, and then we're gonna understand the behavior of a default, global file system, system, excuse me, where on, out of the box it's a pool on demand, but we want to apply objectives to proactively keep files local at each site. Okay.
So let's jump into the second demo. All right. So what I'm showing right now is I'm showing, AWS, and that is a Terraform...
not Terraform, the cloud formation tool that's built into Marketplace. Um, so of the, of the major clouds we support or we have marketplace listings, and they're generally a BYOL or a metered offering. So you really have your choice of how you wanna consume Hammer space in the cloud.
Now, I won't bore you with all the details of the fields that you have to fill out in a, in a CFT, but what I will do is I'll assume that we're familiar with that and cut directly to it running. So here we are right now. This is, this is a deployment running in AWS.
It just stood up. I just... all I'm doing is taking the IP address of the Anvil server, throwing it into our browser and logging onto the system.
See, we have the same dashboard. Uh, you can see that the site's slightly different right here. So you can see the location is now in, is in San Francisco Bay Area, while the other one was in, Ohio, for example.
Uh, so shows you it's a different cluster. And then all we're gonna do at this point is we're just gonna go configure that bucket. And it's the same bucket that we had configured in the on-premise cluster.
So you're accessing the same bucket. This is what facilitates our global file system between the two sites. Does take a little bit of time.
Does anybody have any questions while we're- I just have a- Uh-huh ... pretty, pretty basic, just a fundamental question, I suppose. Um, the, the UI, is pretty nice, of course.
Um, I suppose you have a, a, at least one API to drive this if- Yeah. Oh, yeah ... necessary?
Yeah, yeah. This is all API-driven. Um- So- I'll...
We have- If I right-click Inspect, I'll just see the- Yeah ... API calls, or do you have a spec that can be downloaded and- Yeah, we have a spec. We have, we actually have, a HSTK, API toolkit that can be downloaded.
Then of course we have the HSCLI, which is, you know, scriptable, command line language too. Oh, that's... Yeah.
Now we're getting to the whole agents using CLI sort of- Yeah ... MCP service debate. Okay.
Thank you. Yeah, yeah. There will be some announcements, I know next week about that, that very topic.
Another, another question. Sharla here. Um, you mentioned earlier, you know, what we were looking at was, I believe maybe 14,000 files.
So I was just kinda curious, what about if it's like a really large data set? Yes. Like, what's that timeline look like?
Well, it's a formula, and it really is based on the amount of resources that are in the Anvil. Uh, the Anvil that we use in this demonstration is an Amazon EC2 instance that I'm running in a lab. I think it's an M2, 2xl large, right?
So it's not a representation of what a production environment would be. Yeah. Now, our professional services team, when you're looking at a, what we call a T-shirt size large Anvil server, we understand what that ingestion cadence will be or have a, a good understanding of that is, and it's, you know, it's more like, you know, a million files per hour or something like that, w- w- whatever that, that is because that's the, our production environment.
Right. So it's gonna be far different than what I'm showing you in this demonstration. Okay.
And then what about... So, does the system like perform a full file system crawl or can you ingest metadata, you know, lazily as files are accessed? It does.
It, it... Well, it's really interesting, and that's a great point that you brought that up. Um, I didn't really go into the details of it, but if you can imagine a file system with a billion files in it, right?
And it's a live file system. As you're scanning it, you have users accessing it. " So you can go to a very specific sub-directory within your file system and it will scan on demand and assimilate that and bring it in because a user is requesting access- Yeah ...
to that specific section within a file system. So we can, we can, pr- we'll- we'll scan, the directory, you know, parent, child, and sub-directory on down, or we can do it on demand. Okay.
Yeah, y- I just thinking in my head because I deal a lot with data migration- Sure ... and so our goalpost is forever moving- ... as you're trying to get them migrated, so.
Yes, yes. Yeah, and again, a lot of people, find, the intrinsic benefit of Hammer space is just for storage migrations, right? It's an added benefit.
That's something they get for free is this ability to make this seamless. Nice. Okay.
Oh, so let you guys know what's going on here. Um, so we created the bucket at the remote site, and now I'm gonna go log into my original on-premise cluster. It is the owner of the collections share, and I'm going to give the remote site permissions to participate in a global file system.
So that's what I'm doing real fast. Log back into the on-premise cluster. I'm gonna go to the collections share.
I'm gonna go in the Edit tab, and now this time I'm going to the File Systems tab and I'm adding a participant. Let me pause this real fast and tell you what's happening in the background. When we share a bucket as a replication target, there's a reservations file that gets created.
And inside that reservations file, any participating site will add its login credentials. It will add the name of the cluster and the IP address for it to connect to. So when you have another cluster connecting, it's gonna have a list of all the participants already pre-populated.
So all you have to do is select it because it's all in that file itself. It's an encrypted file, but imagine having up to 16 sites participating at the same share at the same time. You wanna have that list pre-populated for you.
That's exactly what we're showing right now, in the GUI. So typing in the, the- the username and password of the remote cluster, testing the connection, then adding it to the global file system. So now the collections share is a global resource between sites.
It's that simple. So what we're gonna do now is we're gonna go back to the- the Anvil in the cloud, and we're gonna go look at the collections share, and we can actually see all the files available at the remote site. Just like that, they're all available.
So now you can actually see them. You can see all the metadata associated with it. Quick- Quick ...
quick, oh, sorry. No, go ahead. It may be a silly question, but I'm going to ask it anyway.
Sure. I love doing it. Um- It would be kinda cool possibly for the audience to clarify.
We keep hearing the term Anvil, like maybe- Oh, okay. S- I do apologize. So Anvil is our metadata server, and then what we have is a DSX server, a data, data services node.
Um, and at a real high level, the Anvil server, it just, is just there to, collect and maintain the metadata about the server. 2. Uh, the DSX servers has several roles and functionalities.
2 it serves on the DSX. It also is the data mover. So when you set an objective to move data, it is the engine that move, physically moves the data from one storage platform to another behind the scenes and makes it all seamless.
It also, another role that it has, is responsible for, moving files to object storage. We call that the, the cloud mover. Okay.
Its job is to take files, chunk it, encrypt it, move it up to an ob- an, an object storage, and then on the other side, bring it back down, un-encrypt it, and then we typically will apply encryption, compression on it. So it's also de- decompressing the file and making it available on the DSX as well. So those are the major roles of a DSX.
2. Uh, does that answer your question? Yes.
Thank you. Okay. Thanks.
Okay, so just to kinda catch ourselves back up to speed here, boy, I'm really running out of time. Um, I'm going to, try to connect, to SMB in a remote site. Oops, sorry.
And just gonna map to it. It's really important that we have Active Directory integration on both sites right now, so we, they understand the SIDs and the layouts between sites. Uh, if you didn't, you wouldn't-- You would instantly get permissions issues, right?
So we're gonna log in real fast. We're gonna verify that it's working. And quickly, what I'm going to do is I'm going to pause this again and talk about why it's taking a while to load this file.
Because all we did between the two sites right now is we just replicated the metadata, right? So what this file is actually doing right now is it's going across all the way to the assimilated storage. It's grabbing that file, it's moving it across the DSX, out to a bucket, back to a DSX, back to the SMB share.
It is doing this on demand because we've set no policy on how to cache the data and where to cache the data. So yes, it's gonna take a while to do because we're going across the wire each time to pull this file. Now, what we do behind the scenes is we'll cache this a-a-- on the, in the RAM on the DSX for five minutes.
If the file isn't touched or not modified after a five-minute period, we'll, we'll evict that cache, and we'll move it back. And then if you touch it again ten minutes later, you gotta go through the whole process again. But we do have this concept called ejectors, what we'll talk about later on, that removes that need to have the wait for the file to be pulled across each time.
All righty. So there's the file, and I believe that pretty much concludes the second demonstration. Okay.
So I'm gonna pause real fast, and I'm gonna start the second part of the, the demonstration now. Hello, everybody. My name is, Chad Smith.
I'm a cloud CTO at... Geez. Hey.
Chad Smith. I'm a field CTO at Hammer Space, responsible for alliances. It's been a long day already.
Um, I previously, showed two demos of Hammer Space, on-prem, assimilating some third-party storage and then, setting up a global file system to transfer files to a second site that lives in the cloud. Now we're gonna continue that conversation and add on this new concept we like to talk about, which is called Tier Zero. So let me bring my...
bring it back up here. Make sure I reshare my screen. I don't know what happened.
I do apologize. Hopefully, I can make this work. All right.
All right. And I'll put this in presentation mode. Uh, go jump to this slide.
That work? No, it did not work. I apologize, guys.
I don't know why this is... Share. All right.
Third time's a charm. All right, let me get to the next one here. Okay.
So this is where it gets exciting, right? Um, so what I like to describe Tier Zero as local performance with the utility of a file system. So we're gonna discuss Tier Zero installation dependencies on GPU nodes, how the NVMEs are mapped to the NFS mounts versus mounted shares on the client.
Uh, we're gonna set up Hammer Space storage, volumes, and this concept called volume groups and how high-availability zones, ensure data protection in this model. We're gonna review, data placement policies that affect the creation, modification of files when a durability or availability objective is applied. 2 client-side mirroring works.
Okay, so before I jump into the demo, let's talk about what it takes to prepare the, the Tier Zero nodes, or this would be your AI nodes, your GPU nodes. This would be the, the use case. There is a little bit of installation that needs to be done on these nodes, but it's not like you're, you're a kernel-level driver you have to compile for.
It is really simple stuff. Uh, it can get complicated depending on the environment, 'cause you got, you got NUMA zones, and you got all kinds of com-com-complexities on, on larger environments. But in this demo, we're just gonna, we're gonna keep it really simple.
And really when I mean simple, it's simple. Basically, you're creating a directory which is gonna be a mount point. You're gonna drop an, an NVMe in it, and then you're gonna mount that NVMe to a share.
And then you're going to then map your NV-- your Tier Zero client to that mount that we had created earlier called Collections on the Hammer Space system. So what does that look like? We're gonna tie each NVMe to a mount, and then we're going to, tie it all together by mounting my client to the Hammer Space.
And a little switcher... Oh, and then I also wanted to discuss too this notion of availability zones. So by definition, an availability zone is a fault-tolerant, is a fault domain.
And what we consider a fault domain in this use case is the instance itself and its underlying storage associated with it. By, by dictating what an AZ is, our product ensures that it's not being written to the same, the same node twice, right? Defeats the purpose of client-side mirroring if you're writing to the, the, the same drives on the same nodes, right?
So that's what an AZ, avoids. Mm-hmm. And of course, to make this all work, it's a place on.
It's another objective I'll get into a little bit, and we're gonna assign it to the collections share. It'll be much clearer in a second, trust me. All right, so another demo here.
Just like before, when we assimilated that third-party storage, we basically walked through the same process. We're gonna take a storage system, and this time the storage system is an individual GPU node. Um, and then what we're going to do is we're going to, assimilate it with, NFS other again, and we're just gonna type in its IP address.
Same step as the previous one. Uh, we have lots of scripts that can automate this. Imagine having a hundred GPU nodes.
You don't wanna do this individually, so we have ways of streamlining this process. But we just discovered two volumes on this system, and what we're gonna do is we're gonna append the name with that availability zone that I mentioned earlier, right? By just appending AZ one to it, we're telling Hammer space that this is an availability zone and these two volumes are, are in that availability zone.
I'm just changing the notification thresholds about the usable space and capacity. Um, you really don't have to worry about that too much with Tier Zero. And then I'm just gonna skip to performance test for part of this, demonstration.
I know they were not gonna get to it. So I just repeated the process for all five nodes. And then you can see that all ten volumes are available as well.
So the next thing I'm gonna do is I'm gonna create a volume group, and this volume group is gonna be all AZs and a simple description. Not so simple, actually. Let me see.
Fast-forward this thing a little bit here. All right, so I finished that. I created the volume group.
Now what I'm gonna do is I'm going to associate all volumes I've created with this volume group. What we are doing is we're creating a distribution map to map all the available volumes to this group. And then all we do to make this thing work is just assign this newly created volume group to the share itself.
So I go into the objectives. I'm gonna add an objective. We're gonna use one called a place on, and I'm going to place on this AZ and apply.
And then what's gonna happen is you're gonna see a flurry of activity. 'Cause what we're doing right now is we're moving all the data that was sitting on that assimilated storage all the way across to the, all of these, Tier Zero nodes now. So yes, go ahead.
Um, are you moving or copying or freezing and moving or? We are copying- Okay ... the, the data over.
Okay. Uh, but the concept of Hammer space, we don't ever like to use the word copies because from a physical standpoint it's a copy, but from a metadata standpoint, it's a single instance of it. We call that instantiation.
Okay. So it ever only is a single metadata copy, but it can physically live at multiple spots. Okay.
Thank you. So yes, we are copying the data over.