Videos lMCxVorb9wM
You Didn't Ship a Bug. You Just Wrote It for a Human. - Ravi Madabhushi, Scalekit
Scene timeline
27 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 122
- whisperx 122
- chunks
- 24
- from 122 cues
- keyframes
- 18
- kept of 27 captured
- frames with text
- 18
- 257 lines read
- chapters
- 0
- from the source metadata
- keyframe bytes
- 2.4 MB
- word timings on 122 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 04:29 | 1m 25s |
stt |
done | — | 2026-08-10 04:31 | 13s |
chunk |
done | — | 2026-08-10 04:31 | 0s |
text_embed |
done | — | 2026-08-10 19:47 | 1s |
keyframe |
done | — | 2026-08-10 04:31 | 37s |
ocr |
done | — | 2026-08-10 04:32 | 10s |
frame_embed |
done | — | 2026-08-10 19:47 | 3s |
Frames, and what the machine read
-
- scalekit1.00
- You didn't ship a bug.1.00
- You just wrote it for a human.1.00
- Ravi Madabhushi1.00
- CTO, SCALEKIT0.97
-
- scalekit1.00
- A DEMO AGENT. IN PRODUCTION0.99
- Every fifteen minutes, the database strained0.99
- p990.82
- alert threshold1.00
- 0:151.00
- 0:301.00
- 0:450.99
- 1:001.00
- Latency climbed, alerts fired, then it settled, and fifteen minutes later, again.1.00
- A perfect heartbeat.1.00
-
- scalekit1.00
- last_seen = now()∥writtenfor a human0.96
- one line · updated on every tool call . the agent called it 60× a second . fixed in an afternoon0.98
-
- scalekit1.00
- WE GOT LUCKY ABOUT WHICH ASSUMPTION BROKE1.00
- That one was about speed.0.99
- The dangerous one is about authority.0.99
- A cadence bug costs you latency. You batch the write and move on.0.98
- The authority assumption breaking costs you something you can't fix with an index.1.00
-
- scalekit1.00
- ABOUT ME0.94
- I build identity layers.0.97
- First for humans. Now for agents.1.00
- Years on the human identity layer at Freshworks - millions of daily users.0.98
- Now AgentKit. Which means I see how teams wire up their agents on day one - before any of it gets scoped down.0.99
-
- scalekit1.00
- WHAT I ACTUALLY SEE1.00
- Most agents in production have more1.00
- access than anyone chose to give them.0.99
- Not carelessness - the default0.99
-
- scalekit1.00
- THE BENCHMARK1.00
- Two slots.Neither was built for this.0.98
- Your agent needs an identity →0.99
- SLOT 10.91
- SLOT 20.98
- Interactive human0.98
- Service account1.00
- Logs in. Sits at a browser. Clicks "Allow." Moves at human0.97
- A static credential. Broad, standing access. Built for0.99
- speed.1.00
- trusted backend infrastructure.1.00
- ← no human here0.98
- ← the agent lands here by default0.99
- Nobody decided the agent should have broad access. The human slot doesn't fit, so it takes the only other thing on the shelf.0.99
-
- scalekit1.00
- WHY THERE'S NO SLOT FOR AN AGENT0.99
- What authenticates has always been what acts0.99
- Every identity primitive you own carries the same quiet1.00
- assumption:1.00
- password1.00
- acts1.00
- authenticates1.00
- ONE IDENTITY1.00
- the thing that proves who it is is the same thing taking the action.1.00
- Principal and actor — welded together.0.98
- API key0.94
- authenticates1.00
- ONE IDENTITY1.00
- So old you've never had to name it.0.98
- acts1.00
- session token0.97
- authenticates1.00
- acts1.00
- ONE IDENTITY1.00
- authenticates1.00
- service account1.00
- acts1.00
-
- scalekit1.00
- WHY BROAD SCOPE WAS ALWAYS SAFE1.00
- For decades, a credential was held by a program a human wrote0.99
- That gave you two guarantees — both so reliable you never had to name them.0.98
- Authorization quietly leaned on both.1.00
- 011.00
- It acts as itself principal = actor0.99
- The thing that authenticates is the thing that acts. One1.00
- entity.1.00
- password1.00
- API Key0.95
- session1.00
- Service account1.00
- 021.00
- It stays in its lane deterministic0.99
- It only ever does what it was coded to do. It never reaches1.00
- for the parts of a broad grant it wasn't written to touch.1.00
-
- scalekit1.00
- WHAT ACTUALLY CHANGED0.99
- The agent breaks both and the dangerous half is that0.99
- it won't stay in this lane1.00
- Break 1: Principal ≠ Actor0.98
- the agent1.00
- "on behalf of"0.93
- the user1.00
- You can't even tell who acted - the agent,0.98
- the user, or the agent as the user.0.99
- actor· takes the action0.97
- principal · proves who they are0.98
- Break 2: the holder is now autonomous1.00
- The Grant1.00
- The Holder1.00
- Same broad scope as1.00
- Non-deterministic. Its own goals and latitude. It'll treat1.00
- always — unchanged0.98
- the whole granted surface as fair game.0.99
-
- scalekit1.00
- WITH NO WORD FOR THE GAP, YOU PICK ONE0.97
- So you tell one of the two lies1.00
- LIE11.00
- LIE 20.93
- “The agent is itself."0.96
- “The agent is the user.0.96
- 990.99
- Give it its own service account. Now it acts as itself, with broad access0.98
- Hand it the user's token. Scoped to one person — but you can't tell its0.99
- - no matter who it's actually serving.0.97
- actions from theirs, and it still runs at agent scale.0.99
- ← everything for everyone0.98
- ← no audit trail, agent speed0.98
- Both collapse the gap — one into the agent, one into the user. Both throw away the one thing that mattered: who acted, and for whom.0.98
-
- scalekit1.00
- Expected1.00
- tool surfaces1.00
- Maya1.00
- Jordan1.00
- Sam1.00
- M1.00
- J0.96
- S0.99
- Senior platform engineer0.99
- Junior engineer1.00
- Internal SRE1.00
- Enterprise customer1.00
- Startup customer1.00
- Your own team1.00
- Their tool surface1.00
- Their tool surface1.00
- Their tool surface1.00
- Pagerduty.admin1.00
- Github.admin.infra1.00
- Pagerduty.read1.00
- Github.read.3repos1.00
- Linear.full1.00
- notion.runbooks1.00
- Jira.full1.00
- Slack.full1.00
- Jira.project.acme1.00
- Slack.team1.00
- Monitoring.internal1.00
- Slack.internal1.00
-
- scalekit1.00
- THE REALITY1.00
- But the agent sees the same surface —0.97
- whoever it is acting for...0.99
- Maya1.00
- Jordan1.00
- Sam1.00
- M1.00
- J0.98
- S0.92
- Senior platform engineer0.98
- Junior engineer1.00
- Internal SRE1.00
- Enterprise customer1.00
- Startup customer1.00
- Your own team1.00
- Their tool surface0.99
- Their tool surface1.00
- Their tool surface1.00
- Pagerduty.admin1.00
- Github.admin.infra1.00
- Pagerduty.read0.98
- Github.read.3repos1.00
- Linear.full1.00
- notion.runbooks1.00
- Jira.full1.00
- Slack.full1.00
- Jira.project.acme1.00
- Slack.team0.96
- Monitoring.internal1.00
- Slack.internal1.00
- Jira.project.acme1.00
- Github.read.3repos1.00
- Pagerduty.admin1.00
- Github.admin.infra1.00
- Pagerduty.admin1.00
- Pagerduty.re-0.97
- Linear.full1.00
- notion.runbooks1.00
- Jira.full1.00
- Jira.delete1.00
- Linear.full1.00
- Github.admin.infra1.00
- Github.1.00
- Monitoring.internal1.00
- datadog.alerts1.00
- notion.runbooks1.00
- datadog.alerts1.00
- Jira.full1.00
- Jira.project.acm0.99
- Sentry.issues1.00
- +31 more outside their scope1.00
- +31 more outside their scope1.00
- +31 more outside their scop1.00
-
- scalekit1.00
- MAKE“ON-BEHALF OF" FIRST-CLASS0.97
- The actor bound to itsprincipal.0.99
- the agent0.99
- the user0.95
- “onbehalf of”0.97
- BOUND. SCOPED. AUDITABLE0.97
- actor· its own identity0.97
- principal1.00
- enforced every call0.99
- scoped to the user0.99
- scoped to this task1.00
- least privilege by default1.00
- OAuth restores who's acting — it doesn't make the grant narrow. A broad grant to an autonomous actor is the whole risk. That's the part AgentKit closes.0.99
-
- scalekit1.00
- WHERE THIS GOES0.97
- Identity became first-class for SaaS.0.99
- Agents are next.0.99
- ref.tools1.00
- A customer whose entire user base is coding0.99
- the actoris1.00
- agents. No humans at the front door at all.0.98
- never the principal0.99
- CURSOR1.00
- CLAUDE CODE1.00
- CODEX1.00
- Not a forecast. The leading edge of the present.0.99
Transcript
122 cues· 2,224 words· 12,243 chars
- 0:00 Hi, thank you so much for tuning in.
- 0:02 I'm Ravi.
- 0:02 I'm one of the co-founders of ScaleKit.
- 0:04 Today, I'm going to talk about how you need to think architecturally from the ground up about building your applications, APIs, your MCP servers for agents, and how the human-focused architecture doesn't scale well for agents.
- 0:20 So a while back, we were looking at our performance and latency numbers, and one thing that kind of jumped out at us was how our latency was spiking
- 0:30 every 15 minutes in a rhythmic manner.
- 0:33 Nothing harmful, but just a curious thing for us to analyze.
- 0:36 What we noticed was very interesting.
- 0:39 So in our identity and authentication infrastructure platform, we have this little timestamp that we mark for every user to say, hey, when was the user last seen or when was the user last active or last acted in our system so that
- 0:53 we can predictively say hey this user is an active user this user is not so active but one thing that we realized was the system was probably built for humans but when agents started hitting our apis in the last 12 months or so we realized that this last scene update is happening 60 times faster than what it would and that is creating unnecessary pressure in our db write system so
- 1:20 Of course, it's a harmless thing.
- 1:21 We were able to fix it very easily.
- 1:23 We would just batch the update at a second level and not at every single time we had to update it.
- 1:30 That kind of took us down a rabbit hole.
- 1:32 So the assumption that broke was how often would our system have to update this timestamp on every row?
- 1:38 And that's okay.
- 1:39 It's just about speed.
- 1:40 It's about latency, etc.
- 1:42 But what I was worried about is, hey, what if some of our assumptions that we made about authentication and authorization need to be rewired and rethought completely when it comes to agents, because we would have designed earlier for humans as actors in mind.
- 1:56 Now, just to give you a context, I worked on identity and authentication operations for the last 10 years, building an identity platform at Freshworks.
- 2:05 which is being used by millions of daily users hundreds and thousands of customers all over the world but this is predominantly human users right or at best apis but the way i think about it is apis are also accessed by machines that are written by humans that's not too bad right but what i realized is the fundamental picture has changed drastically in the last three four years or so
- 2:32 We have a unique ringside view to see how developers nowadays are building agents and how they're giving context to these agents with data from third-party applications like Salesforce or Databricks or HubSpot or Notion.
- 2:46 What we have realized is most of the agents our customers are building have
- 2:53 way too permissions and scopes than the agent's responsibility or the agent's job is.
- 3:00 Again, it's not because the developers who are building the agents are careless, but somehow this became a default pattern of giving the agents what they need access to.
- 3:12 And the existing primitives that we have don't let us
- 3:15 give extremely fine grained functions to the agents.
- 3:18 Now I'll tell you how we ended up here, right?
- 3:21 We predominantly have two slots and neither of the slots was built for agents in mind.
- 3:28 There's a human who's accessing the application, either a web application or a mobile application or their own little script that they wrote and they give it their API key so that their program can access data from the application.
- 3:39 This is all the fundamental principle here is
- 3:44 It's the same user who is authenticating and it's the same user who is acting, right?
- 3:48 And the second slot is the traditional service account scenario or M2M account scenario where you create a service account, you give it certain permissions and then say, this machine has its own identity.
- 3:59 That's where the likes of Spiff and OAuth and all of that came into picture.
- 4:03 But you would give them certain credentials and say, hey, now this machine has access to whatever data that it needs at any single point of time.
- 4:12 And this is the existing pattern, right?
- 4:15 So the fundamental philosophy that we have always maintained is whoever is authenticating is the one that is acting.
- 4:21 Every action the program or the human takes is based on fixed set of permissions that actor was granted at some time.
- 4:30 If you take traditional authentication mechanisms for humans, including password, you just say, hey, if an identity has the same password that it was set at the time of registration, if they come back,
- 4:40 And if they present the same password again, then you say, okay, this is how I validate the identity.
- 4:45 This is how I authenticate the human.
- 4:48 And every action subsequently is tied to that human identity.
- 4:51 Again, the same is the case with API key or the same is the case with web session tokens or even the same case for service account.
- 4:58 You define the permissions at the time of registration and then every single time it acts based on the registration time permissions and scopes.
- 5:09 Now this is okay all this while, because for decades, the service account and OAuth principle even is working fine, even though there are their own problems, but it is still working fine because these machines are using a program in a deterministic way by the way the human developer wrote that program.
- 5:33 So there is,
- 5:35 absolute guarantees about what the program could or the program won't do, but it is still intentional based on what the human wrote, right?
- 5:44 In this particular case, again, if it is using API keys, then the actor and the principal is the same.
- 5:51 Then there is some sort of a delegated permission for the program to act based on what consent the user has granted.
- 5:57 But the second one is the most important part, which is it's a deterministic program and it always stays in its own lane.
loading