CEO of @speakeasydev. Building the AI Control Plane. Every agent action, governed.

San Francisco, CA
Automate everything and an agent eventually does something irreversible with nobody watching. Approve every step and you've built a very expensive human. Where to draw that line was half my conversation with George Finney and Nick Espinosa on @CISOseries' Security You Should Know. What we shipped flags the high-impact calls, rm -rf, DROP TABLE, moving money, holds those for a human, lets everything else run, and logs all of it. What's on your never-let-it-run-unattended list?
2
11
170
Private drinks with the private network. Join the @Speakeasydev and @Tailscale teams at a real life speakeasy. It's on the last day of @aiDotEngineer, we'll be chatting about privacy and security in the age of agents. Space is limited: luma.com/po85yuqq
5
15
14,835
Skills are a powerful primitive, but organizations have struggled to get a handle on them. Extending MCP to cover Skills is going to encourage more companies to manage skills as a 1st class artifact, and that's going to explode usage. With MCP there was enough friction in creating them that most employees wouldn't create their own. Not the case with skills, anyone can create a markdown file, so management has been highly dispersed. Not a single company we've worked with knew how many skills were in active use across their org (before implementing @speakeasydev ofc). That's not inherently a problem, but there's usually a lot of duplicate work being done. Once companies start bundling skills in their MCP servers they'll start spending more time curating them. Usage will go up without users even needing to be aware. Kudos to the committee for continuing to be great stewards of the protocol.
3
2
10
12,728
This is an exciting update for claw devotees who want to pitch this upwards to their IT and Security leaders. There's still a major gap though. Claws are long lived and proactive entities that will work and take action like employees. For humans you can go into @okta and authorise access to apps. How do you do this for long lived agents like openclaw? We've been cooking on an easy to use Agent Identity feature on the @speakeasydev control plane. I use the word "easy" because the Agent Identity space is filled with dozens of acronyms: Workloads, SPIFFE, WHIMSE, CXA, ID-JAG and more. We've made built on the state of the art protocols here to give users a simple workflow to register an agent (or discover it automatically) and grant it scoped and revocable permissions to various mcp servers and other tools. Every agent has its own identity and short live tokens rather than less secure shared access models like service accounts. For an IT admin though its just a few clicks or running a skill. I'm excited to see how many enterprises we can accelerate agent adoption in by solving the foundational building block of identity. A little more on how we've done that for Claude Tag. Open Claw next! 🦞speakeasy.com/blog/agent-ide…
Today we’re announcing OpenClaw Enterprise In collaboration with @RedHat , @nvidia and @OpenAI the OpenClaw Foundation is open sourcing a powerful enterprise control plane for persistent agents OpenClaw Enterprise is built to run on your own infrastructure and will always be free for an organization to use openclaw.ai/blog/openclaw-en…
12
2
11
484
SaaS as a category was always silly. It bundled systems of record like Slack or Jira with productivity apps like Miro or Canva. Agents have made this division clear... Systems of record are more important than ever, just look at MCP usage on the @speakeasydev gateway Productivity apps, not so much...
1
2
12
340
Sagar Batchu retweeted
Nvidia pushes agent containment below the model, dv01 and Cognizant put agents into finance and claims workflows, and Google tests buying from Flipkart inside Gemini. Speakeasy adds tighter identity and policy controls for MCP.
Article

Nvidia Agent Safety, dv01 MCP + Google Flipkart Checkout - Daily Agentic 9.28.26

Two of today's stories turn on whose authority an agent is really using. Mohit Gurnani and Okta's Aaron Parecki both take that question on at AGNTCon + MCPCon North America in San Jose, October 22-23.

2
3
11
567
I understand the rush for companies to adopt token-based pricing, but I can't help thinking that for most it will turn out to be a mistake in the long run for the simple reason that, 1 Claude token ≠ 1 DeepSeek token Different models use tokens in completely different ways. That doesn't matter if you build your product on a single model, but what happens when you change the underlying model? Are you going to switch all your billing? What if your product becomes multi-model? What if you allow users to BYOM? It gets complicated quickly. For most products, token-based pricing doesn't make sense because tokens are not tied to the economic value of the outcome the product is driving. I saw recently that @PostHog's self-driving feature charges $15/PR opened i.e. patches submitted. I think this is much more appropriate for the majority of AI-based products. Focus on the outcomes you are driving and price-in what it costs for you to accomplish it. The one place where token-based pricing does make sense is companies where the stream of tokens is the basis of the value. For example a model router company, or a company like @Speakeasydev where the greater % of the companies AI usage flowing through the platform, the more value the customer gets.
1
3
14
355
Sagar Batchu retweeted
Replying to @moonpay
@MoonPay distributed AI to every employee without turning security into the bottleneck. Now they run 200+ MCP servers and 60,000+ agent sessions through one control plane. Great writeup from @AgenticAIFdn:
MoonPay moves funds between fiat and digital assets for 30M+ customers and 900+ partners. When employees started connecting AI assistants to internal systems through MCP, browser-level governance stopped being enough. Their security team went to market with clear requirements: full visibility into MCP usage, coverage across Claude, Codex, Cursor, and Gemini, and the ability to block unsanctioned MCP servers at the point of use. Everything had to work in production immediately. They evaluated Speakeasy, an AAIF member, on a 30-day POC with success criteria written up front, then rolled it out company-wide in a single deployment. Today: 200+ MCP servers under governance, 60,000+ agent sessions, 5,000+ brokered MCP connections. Full writeup: bit.ly/4AAkrcy
2
1
11
212
I am going to The @AIConference in SF next week. We may or may not be bringing drinks to the booth 🍸️ See you there!
11
195
Most of the @speakeasydev has been together for multiple years now through cycles of growth and PMF iteration. Longevity >> team size.
It tells you a lot when someone has moved around a lot in their career. Also tells you a lot when there is low company turnover. A team that has been working together for 3+ years is significantly higher throughput and more resilient than a team that has just formed. A key mistake I see investors/employees make all the time is to simply ask about team size as opposed to team longevity. AUC for teams is the right metric.
1
6
501
Sagar Batchu retweeted
MoonPay moves funds between fiat and digital assets for 30M+ customers and 900+ partners. When employees started connecting AI assistants to internal systems through MCP, browser-level governance stopped being enough. Their security team went to market with clear requirements: full visibility into MCP usage, coverage across Claude, Codex, Cursor, and Gemini, and the ability to block unsanctioned MCP servers at the point of use. Everything had to work in production immediately. They evaluated Speakeasy, an AAIF member, on a 30-day POC with success criteria written up front, then rolled it out company-wide in a single deployment. Today: 200+ MCP servers under governance, 60,000+ agent sessions, 5,000+ brokered MCP connections. Full writeup: bit.ly/4AAkrcy
1
2
5
448
The cooking has not stopped
Man our engineers are COOKING
4
10
411
Have agents made it easier or harder to build software products? If I had to boil down the sentiment, I would say that MVP is easier than ever, PMF is harder than ever... There's no question that agents make it possible to go from idea to usable in a day, which was previously unheard of. The problem I'm seeing though is when it comes to PMF. Product creation is becoming infinite, but market is still finite. There's only so much buyer attention in the world. As the volume of product increases the competition for that finite market attention is becoming much higher. What are the implications? I think we'll see a correction to the spray and pray product development that is happening. Teams will need to build conviction over what is the most impactful thing they can build, build it to a high degree of polish and then really hammer their messaging with the market.
12
393
Man our engineers are COOKING
14
14
415
208,438
@ghaidar0 looking after our margins :)
1
1
1,995
Don't want Harvey's +50% --> -50% margins drop!
Man our engineers are COOKING
3
1,635
To be clear this is our costs curve not our revenue curve 😅
Man our engineers are COOKING
8
1,048
All the @speakeasydev engineers are in SF this week for our engineering onsite. Humbling to be reminded how cracked this team is.
6
4,208
More from @CISOSeries' Security You Should Know. An agent should get permissions to the only systems a task needs, then lose them the moment the task ends. We call that task-scoped credentials: minted per session, bound to the person, and dead in minutes.
1
12
260