read-only demo

Videos lMCxVorb9wM

You Didn't Ship a Bug. You Just Wrote It for a Human. - Ravi Madabhushi, Scalekit

index_state ready data_status ok

AI Engineer· published 2026-07-19· 0:12:50· en-US· indexed 2026-08-10 19:47

Open on YouTube

Scene timeline

  1. Shot 0, 0:00 to 0:20, 1 of 1 keyframes kept
  2. Shot 1, 0:20 to 0:39, 1 of 1 keyframes kept
  3. Shot 2, 0:39 to 1:04, 1 of 1 keyframes kept
  4. Shot 3, 1:04 to 1:30, 0 of 1 keyframes kept
  5. Shot 4, 1:30 to 1:58, 1 of 1 keyframes kept
  6. Shot 5, 1:58 to 2:32, 1 of 1 keyframes kept
  7. Shot 6, 2:32 to 3:18, 1 of 1 keyframes kept
  8. Shot 7, 3:18 to 3:46, 1 of 1 keyframes kept
  9. Shot 8, 3:46 to 4:15, 0 of 1 keyframes kept
  10. Shot 9, 4:15 to 4:42, 1 of 1 keyframes kept
  11. Shot 10, 4:42 to 5:09, 0 of 1 keyframes kept
  12. Shot 11, 5:09 to 5:36, 1 of 1 keyframes kept
  13. Shot 12, 5:36 to 6:04, 0 of 1 keyframes kept
  14. Shot 13, 6:04 to 6:31, 0 of 1 keyframes kept
  15. Shot 14, 6:31 to 7:03, 1 of 1 keyframes kept
  16. Shot 15, 7:03 to 7:35, 0 of 1 keyframes kept
  17. Shot 16, 7:35 to 8:07, 1 of 1 keyframes kept
  18. Shot 17, 8:07 to 8:38, 1 of 1 keyframes kept
  19. Shot 18, 8:38 to 9:10, 1 of 1 keyframes kept
  20. Shot 19, 9:10 to 9:39, 1 of 1 keyframes kept
  21. Shot 20, 9:39 to 10:08, 0 of 1 keyframes kept
  22. Shot 21, 10:08 to 10:36, 0 of 1 keyframes kept
  23. Shot 22, 10:36 to 11:05, 0 of 1 keyframes kept
  24. Shot 23, 11:05 to 11:44, 1 of 1 keyframes kept
  25. Shot 24, 11:44 to 12:20, 1 of 1 keyframes kept
  26. Shot 25, 12:20 to 12:49, 1 of 1 keyframes kept
  27. Shot 26, 12:49 to 12:49, 1 of 1 keyframes kept

27 shot(s).

keyframes kept every frame deduplicated

What was stored

cues
122
whisperx 122
chunks
24
from 122 cues
keyframes
18
kept of 27 captured
frames with text
18
257 lines read
chapters
0
from the source metadata
keyframe bytes
2.4 MB
word timings on 122 cues

Provenance

Each pipeline stage, its state and the model that produced it
stage state model started took
fetch done 2026-08-10 04:29 1m 25s
stt done 2026-08-10 04:31 13s
chunk done 2026-08-10 04:31 0s
text_embed done 2026-08-10 19:47 1s
keyframe done 2026-08-10 04:31 37s
ocr done 2026-08-10 04:32 10s
frame_embed done 2026-08-10 19:47 3s

Frames, and what the machine read

  • 0:14 #0 done5 line(s)

    shot 0·sharpness 833.3

    1. scalekit1.00
    2. You didn't ship a bug.1.00
    3. You just wrote it for a human.1.00
    4. Ravi Madabhushi1.00
    5. CTO, SCALEKIT0.97
  • 0:37 #1 done11 line(s)

    shot 1·sharpness 826.0

    1. scalekit1.00
    2. A DEMO AGENT. IN PRODUCTION0.99
    3. Every fifteen minutes, the database strained0.99
    4. p990.82
    5. alert threshold1.00
    6. 0:151.00
    7. 0:301.00
    8. 0:450.99
    9. 1:001.00
    10. Latency climbed, alerts fired, then it settled, and fifteen minutes later, again.1.00
    11. A perfect heartbeat.1.00
  • 0:54 #2 done3 line(s)

    shot 2·sharpness 589.9

    1. scalekit1.00
    2. last_seen = now()∥writtenfor a human0.96
    3. one line · updated on every tool call . the agent called it 60× a second . fixed in an afternoon0.98
  • 1:07 #3 skipped

    shot 3·duplicate of #2

  • 1:38 #4 done6 line(s)

    shot 4·sharpness 1356.4

    1. scalekit1.00
    2. WE GOT LUCKY ABOUT WHICH ASSUMPTION BROKE1.00
    3. That one was about speed.0.99
    4. The dangerous one is about authority.0.99
    5. A cadence bug costs you latency. You batch the write and move on.0.98
    6. The authority assumption breaking costs you something you can't fix with an index.1.00
  • 2:08 #5 done6 line(s)

    shot 5·sharpness 1168.5

    1. scalekit1.00
    2. ABOUT ME0.94
    3. I build identity layers.0.97
    4. First for humans. Now for agents.1.00
    5. Years on the human identity layer at Freshworks - millions of daily users.0.98
    6. Now AgentKit. Which means I see how teams wire up their agents on day one - before any of it gets scoped down.0.99
  • 3:08 #6 done5 line(s)

    shot 6·sharpness 1051.0

    1. scalekit1.00
    2. WHAT I ACTUALLY SEE1.00
    3. Most agents in production have more1.00
    4. access than anyone chose to give them.0.99
    5. Not carelessness - the default0.99
  • 3:24 #7 done15 line(s)

    shot 7·sharpness 2011.6

    1. scalekit1.00
    2. THE BENCHMARK1.00
    3. Two slots.Neither was built for this.0.98
    4. Your agent needs an identity →0.99
    5. SLOT 10.91
    6. SLOT 20.98
    7. Interactive human0.98
    8. Service account1.00
    9. Logs in. Sits at a browser. Clicks "Allow." Moves at human0.97
    10. A static credential. Broad, standing access. Built for0.99
    11. speed.1.00
    12. trusted backend infrastructure.1.00
    13. ← no human here0.98
    14. ← the agent lands here by default0.99
    15. Nobody decided the agent should have broad access. The human slot doesn't fit, so it takes the only other thing on the shelf.0.99
  • 4:08 #8 skipped

    shot 8·duplicate of #7

  • 4:18 #9 done23 line(s)

    shot 9·sharpness 1297.6

    1. scalekit1.00
    2. WHY THERE'S NO SLOT FOR AN AGENT0.99
    3. What authenticates has always been what acts0.99
    4. Every identity primitive you own carries the same quiet1.00
    5. assumption:1.00
    6. password1.00
    7. acts1.00
    8. authenticates1.00
    9. ONE IDENTITY1.00
    10. the thing that proves who it is is the same thing taking the action.1.00
    11. Principal and actor — welded together.0.98
    12. API key0.94
    13. authenticates1.00
    14. ONE IDENTITY1.00
    15. So old you've never had to name it.0.98
    16. acts1.00
    17. session token0.97
    18. authenticates1.00
    19. acts1.00
    20. ONE IDENTITY1.00
    21. authenticates1.00
    22. service account1.00
    23. acts1.00
  • 4:50 #10 skipped

    shot 10·duplicate of #9

  • 5:30 #11 done17 line(s)

    shot 11·sharpness 2152.0

    1. scalekit1.00
    2. WHY BROAD SCOPE WAS ALWAYS SAFE1.00
    3. For decades, a credential was held by a program a human wrote0.99
    4. That gave you two guarantees — both so reliable you never had to name them.0.98
    5. Authorization quietly leaned on both.1.00
    6. 011.00
    7. It acts as itself principal = actor0.99
    8. The thing that authenticates is the thing that acts. One1.00
    9. entity.1.00
    10. password1.00
    11. API Key0.95
    12. session1.00
    13. Service account1.00
    14. 021.00
    15. It stays in its lane deterministic0.99
    16. It only ever does what it was coded to do. It never reaches1.00
    17. for the parts of a broad grant it wasn't written to touch.1.00
  • 5:47 #12 skipped

    shot 12·duplicate of #11

  • 6:23 #13 skipped

    shot 13·duplicate of #11

  • 6:44 #14 done19 line(s)

    shot 14·sharpness 1947.7

    1. scalekit1.00
    2. WHAT ACTUALLY CHANGED0.99
    3. The agent breaks both and the dangerous half is that0.99
    4. it won't stay in this lane1.00
    5. Break 1: Principal ≠ Actor0.98
    6. the agent1.00
    7. "on behalf of"0.93
    8. the user1.00
    9. You can't even tell who acted - the agent,0.98
    10. the user, or the agent as the user.0.99
    11. actor· takes the action0.97
    12. principal · proves who they are0.98
    13. Break 2: the holder is now autonomous1.00
    14. The Grant1.00
    15. The Holder1.00
    16. Same broad scope as1.00
    17. Non-deterministic. Its own goals and latitude. It'll treat1.00
    18. always — unchanged0.98
    19. the whole granted surface as fair game.0.99
  • 7:22 #15 skipped

    shot 15·duplicate of #14

  • 7:51 #16 done15 line(s)

    shot 16·sharpness 2881.7

    1. scalekit1.00
    2. WITH NO WORD FOR THE GAP, YOU PICK ONE0.97
    3. So you tell one of the two lies1.00
    4. LIE11.00
    5. LIE 20.93
    6. “The agent is itself."0.96
    7. “The agent is the user.0.96
    8. 990.99
    9. Give it its own service account. Now it acts as itself, with broad access0.98
    10. Hand it the user's token. Scoped to one person — but you can't tell its0.99
    11. - no matter who it's actually serving.0.97
    12. actions from theirs, and it still runs at agent scale.0.99
    13. ← everything for everyone0.98
    14. ← no audit trail, agent speed0.98
    15. Both collapse the gap — one into the agent, one into the user. Both throw away the one thing that mattered: who acted, and for whom.0.98
  • 8:34 #17 done30 line(s)

    shot 17·sharpness 791.9

    1. scalekit1.00
    2. Expected1.00
    3. tool surfaces1.00
    4. Maya1.00
    5. Jordan1.00
    6. Sam1.00
    7. M1.00
    8. J0.96
    9. S0.99
    10. Senior platform engineer0.99
    11. Junior engineer1.00
    12. Internal SRE1.00
    13. Enterprise customer1.00
    14. Startup customer1.00
    15. Your own team1.00
    16. Their tool surface1.00
    17. Their tool surface1.00
    18. Their tool surface1.00
    19. Pagerduty.admin1.00
    20. Github.admin.infra1.00
    21. Pagerduty.read1.00
    22. Github.read.3repos1.00
    23. Linear.full1.00
    24. notion.runbooks1.00
    25. Jira.full1.00
    26. Slack.full1.00
    27. Jira.project.acme1.00
    28. Slack.team1.00
    29. Monitoring.internal1.00
    30. Slack.internal1.00
  • 8:42 #18 done54 line(s)

    shot 18·sharpness 1801.5

    1. scalekit1.00
    2. THE REALITY1.00
    3. But the agent sees the same surface —0.97
    4. whoever it is acting for...0.99
    5. Maya1.00
    6. Jordan1.00
    7. Sam1.00
    8. M1.00
    9. J0.98
    10. S0.92
    11. Senior platform engineer0.98
    12. Junior engineer1.00
    13. Internal SRE1.00
    14. Enterprise customer1.00
    15. Startup customer1.00
    16. Your own team1.00
    17. Their tool surface0.99
    18. Their tool surface1.00
    19. Their tool surface1.00
    20. Pagerduty.admin1.00
    21. Github.admin.infra1.00
    22. Pagerduty.read0.98
    23. Github.read.3repos1.00
    24. Linear.full1.00
    25. notion.runbooks1.00
    26. Jira.full1.00
    27. Slack.full1.00
    28. Jira.project.acme1.00
    29. Slack.team0.96
    30. Monitoring.internal1.00
    31. Slack.internal1.00
    32. Jira.project.acme1.00
    33. Github.read.3repos1.00
    34. Pagerduty.admin1.00
    35. Github.admin.infra1.00
    36. Pagerduty.admin1.00
    37. Pagerduty.re-0.97
    38. Linear.full1.00
    39. notion.runbooks1.00
    40. Jira.full1.00
    41. Jira.delete1.00
    42. Linear.full1.00
    43. Github.admin.infra1.00
    44. Github.1.00
    45. Monitoring.internal1.00
    46. datadog.alerts1.00
    47. notion.runbooks1.00
    48. datadog.alerts1.00
    49. Jira.full1.00
    50. Jira.project.acm0.99
    51. Sentry.issues1.00
    52. +31 more outside their scope1.00
    53. +31 more outside their scope1.00
    54. +31 more outside their scop1.00
  • 9:22 #19 done14 line(s)

    shot 19·sharpness 1159.1

    1. scalekit1.00
    2. MAKE“ON-BEHALF OF" FIRST-CLASS0.97
    3. The actor bound to itsprincipal.0.99
    4. the agent0.99
    5. the user0.95
    6. “onbehalf of”0.97
    7. BOUND. SCOPED. AUDITABLE0.97
    8. actor· its own identity0.97
    9. principal1.00
    10. enforced every call0.99
    11. scoped to the user0.99
    12. scoped to this task1.00
    13. least privilege by default1.00
    14. OAuth restores who's acting — it doesn't make the grant narrow. A broad grant to an autonomous actor is the whole risk. That's the part AgentKit closes.0.99
  • 10:01 #20 skipped

    shot 20·duplicate of #19

  • 10:16 #21 skipped

    shot 21·duplicate of #19

  • 10:40 #22 skipped

    shot 22·duplicate of #19

  • 11:36 #23 done13 line(s)

    shot 23·sharpness 1078.0

    1. scalekit1.00
    2. WHERE THIS GOES0.97
    3. Identity became first-class for SaaS.0.99
    4. Agents are next.0.99
    5. ref.tools1.00
    6. A customer whose entire user base is coding0.99
    7. the actoris1.00
    8. agents. No humans at the front door at all.0.98
    9. never the principal0.99
    10. CURSOR1.00
    11. CLAUDE CODE1.00
    12. CODEX1.00
    13. Not a forecast. The leading edge of the present.0.99

Transcript

122 cues· 2,224 words· 12,243 chars

  1. 0:00 Hi, thank you so much for tuning in.
  2. 0:02 I'm Ravi.
  3. 0:02 I'm one of the co-founders of ScaleKit.
  4. 0:04 Today, I'm going to talk about how you need to think architecturally from the ground up about building your applications, APIs, your MCP servers for agents, and how the human-focused architecture doesn't scale well for agents.
  5. 0:20 So a while back, we were looking at our performance and latency numbers, and one thing that kind of jumped out at us was how our latency was spiking
  6. 0:30 every 15 minutes in a rhythmic manner.
  7. 0:33 Nothing harmful, but just a curious thing for us to analyze.
  8. 0:36 What we noticed was very interesting.
  9. 0:39 So in our identity and authentication infrastructure platform, we have this little timestamp that we mark for every user to say, hey, when was the user last seen or when was the user last active or last acted in our system so that
  10. 0:53 we can predictively say hey this user is an active user this user is not so active but one thing that we realized was the system was probably built for humans but when agents started hitting our apis in the last 12 months or so we realized that this last scene update is happening 60 times faster than what it would and that is creating unnecessary pressure in our db write system so
  11. 1:20 Of course, it's a harmless thing.
  12. 1:21 We were able to fix it very easily.
  13. 1:23 We would just batch the update at a second level and not at every single time we had to update it.
  14. 1:30 That kind of took us down a rabbit hole.
  15. 1:32 So the assumption that broke was how often would our system have to update this timestamp on every row?
  16. 1:38 And that's okay.
  17. 1:39 It's just about speed.
  18. 1:40 It's about latency, etc.
  19. 1:42 But what I was worried about is, hey, what if some of our assumptions that we made about authentication and authorization need to be rewired and rethought completely when it comes to agents, because we would have designed earlier for humans as actors in mind.
  20. 1:56 Now, just to give you a context, I worked on identity and authentication operations for the last 10 years, building an identity platform at Freshworks.
  21. 2:05 which is being used by millions of daily users hundreds and thousands of customers all over the world but this is predominantly human users right or at best apis but the way i think about it is apis are also accessed by machines that are written by humans that's not too bad right but what i realized is the fundamental picture has changed drastically in the last three four years or so
  22. 2:32 We have a unique ringside view to see how developers nowadays are building agents and how they're giving context to these agents with data from third-party applications like Salesforce or Databricks or HubSpot or Notion.
  23. 2:46 What we have realized is most of the agents our customers are building have
  24. 2:53 way too permissions and scopes than the agent's responsibility or the agent's job is.
  25. 3:00 Again, it's not because the developers who are building the agents are careless, but somehow this became a default pattern of giving the agents what they need access to.
  26. 3:12 And the existing primitives that we have don't let us
  27. 3:15 give extremely fine grained functions to the agents.
  28. 3:18 Now I'll tell you how we ended up here, right?
  29. 3:21 We predominantly have two slots and neither of the slots was built for agents in mind.
  30. 3:28 There's a human who's accessing the application, either a web application or a mobile application or their own little script that they wrote and they give it their API key so that their program can access data from the application.
  31. 3:39 This is all the fundamental principle here is
  32. 3:44 It's the same user who is authenticating and it's the same user who is acting, right?
  33. 3:48 And the second slot is the traditional service account scenario or M2M account scenario where you create a service account, you give it certain permissions and then say, this machine has its own identity.
  34. 3:59 That's where the likes of Spiff and OAuth and all of that came into picture.
  35. 4:03 But you would give them certain credentials and say, hey, now this machine has access to whatever data that it needs at any single point of time.
  36. 4:12 And this is the existing pattern, right?
  37. 4:15 So the fundamental philosophy that we have always maintained is whoever is authenticating is the one that is acting.
  38. 4:21 Every action the program or the human takes is based on fixed set of permissions that actor was granted at some time.
  39. 4:30 If you take traditional authentication mechanisms for humans, including password, you just say, hey, if an identity has the same password that it was set at the time of registration, if they come back,
  40. 4:40 And if they present the same password again, then you say, okay, this is how I validate the identity.
  41. 4:45 This is how I authenticate the human.
  42. 4:48 And every action subsequently is tied to that human identity.
  43. 4:51 Again, the same is the case with API key or the same is the case with web session tokens or even the same case for service account.
  44. 4:58 You define the permissions at the time of registration and then every single time it acts based on the registration time permissions and scopes.
  45. 5:09 Now this is okay all this while, because for decades, the service account and OAuth principle even is working fine, even though there are their own problems, but it is still working fine because these machines are using a program in a deterministic way by the way the human developer wrote that program.
  46. 5:33 So there is,
  47. 5:35 absolute guarantees about what the program could or the program won't do, but it is still intentional based on what the human wrote, right?
  48. 5:44 In this particular case, again, if it is using API keys, then the actor and the principal is the same.
  49. 5:51 Then there is some sort of a delegated permission for the program to act based on what consent the user has granted.
  50. 5:57 But the second one is the most important part, which is it's a deterministic program and it always stays in its own lane.

Open at this second