Every Enterprise Is About to Have a 100,000 Agent Problem | Oren Michaels of Barndoor AI
June 06, 2026
354
59:52

Every Enterprise Is About to Have a 100,000 Agent Problem | Oren Michaels of Barndoor AI

AI agents can now connect to every tool your employees use. The problem is that connecting them and trusting them are two completely different things, and most enterprises have figured out the first without solving the second. Oren Michaels, co-founder and CEO of Barndoor AI, joins Craig Smith to explain why that gap is the defining challenge of the agentic enterprise era. His framework is simple and sharp: agents are like enthusiastic interns. They will absolutely do something when you ask them to. Whether it's what you intended is another matter, and when an agent can act across Salesforce, Slack, email, and calendar simultaneously, the blast radius of a misunderstood instruction is far larger than anything a human intern could cause.

The conversation covers the 100,000 agent problem - the reality that each agent handling a discrete task needs its own set of rules about what it's allowed to do, and that number scales to a size no human team can govern manually - and why traditional identity management systems were never built for the failure modes AI agents create. The new threat isn't bad actors getting in; it's authorized people using allowed tools with agents that still do the wrong thing. Barn Door's governance layer sits between the agent and the tools it can access, specifying exactly what each agent is permitted to do in each context, and Venn brings that same capability to individuals who want to understand what's possible before their organizations catch up. This is one of the most practically useful conversations available about what enterprise AI governance actually looks like.

Subscribe to Eye on A.I. for weekly conversations with the people building and deploying the future of AI.

[00:00:00] [SPEAKER_01] Why you compare agents to enthusiastic interns? Why do you think 2026 is an inflection point beyond open thought? While there's a lot of enthusiasm and excitement about agents, very few corporations or enterprises are putting them into production because exactly what you said, the trust issue. These systems are probabilistic.

[00:00:24] [SPEAKER_00] I think that as humans, we're pattern matchers. And so the more we see, the more we want to do. They will absolutely give you an answer. They will absolutely do something when you tell them to.

[00:00:38] [SPEAKER_00] Oren Michaels, Co-Founder and CEO of Barndoor AI, Based in New York City. And I started Barndoor October of 2024. I was seeing that the world was talking about A.I. coming into the enterprise, but we weren't seeing much of it actually happen. And I thought that I had something to add and my team had something to add to be a

[00:01:05] [SPEAKER_00] catalyst for AI to actually be a catalyst for AI to actually be successful in the enterprise. Before Barndoor, I co-founded and ran a company called Machery. We started in 2006. We were the first API as a service company, which we built over the course of seven years and sold to Intel in 2013.

[00:01:26] [SPEAKER_00] Before that, I just had a variety of positions running companies in technology, wine, theater, and various other areas.

[00:01:37] [SPEAKER_01] Yeah. I see the posters on your wall there. You're also a Broadway producer.

[00:01:44] [SPEAKER_00] I am. I am. And these are all shows that I worked on.

[00:01:47] [SPEAKER_01] Yeah, that's wonderful. Very eclectic. So, yeah, we're going to talk about Barndoor AI and then also Venn AI. Maybe you can explain the relation between them. Sure.

[00:02:02] [SPEAKER_01] And then talk about the 100,000 agent problem. And I read an article you wrote, you explained it very clearly with, you know, I can't remember how many employees. Each employee has a certain number of agents. So you got 100,000. Yeah.

[00:02:21] [SPEAKER_00] Yep. Yeah. So we believe that agents are going to become useful in companies. And when I talk about an agent, I believe an agent is something that actually takes action on behalf of an employee or on behalf of itself. It doesn't necessarily have to be tied to an employee, but most of them usually are at this point.

[00:02:45] [SPEAKER_00] And to take action, an agent doesn't merely do what our chat interface does, which is suggest something that we as the human should go do. But it actually doesn't merely suggest it. It actually takes the action and does it.

[00:03:01] [SPEAKER_00] It interacts with the same tools, the same systems that we use in the enterprise, whether it's something like Salesforce or email or Slack or Snowflake or, you know, QuickBooks or whatever it is, whatever it is that you use in your world. And so in order for that to happen, you need two things. You need the AIs to actually be able to connect to these tools.

[00:03:27] [SPEAKER_00] And you need the humans to trust the AIs will use those tools appropriately and not do things that they shouldn't. And, you know, the connectivity is something that's actually not that hard. About a year and a half ago, a protocol called MCP came out that Anthropic brought out, and that solved a decent chunk, not all, but a decent chunk of the connectivity issue.

[00:03:53] [SPEAKER_00] But it didn't do anything about the trust because MCP is not a security protocol. It's merely a pipe. It's a way of connecting. And so it's my belief that in order to really trust an agent to act autonomously, you basically have to govern that agent to a point where you're giving the agent a task, and the only things it's allowed to do are the things related to that task.

[00:04:18] [SPEAKER_00] So that if it decides to hallucinate or go off the rails or do the things that agents do, that the guardrails in place are keeping the agent narrowly focused on that task at hand. Well, we have lots of tasks, and we're going to have lots of agents doing these tasks. And so each agent that is off doing those tasks on behalf of me as an employee is going to need a different set of guardrails and a different set of rules about what it's allowed to do to carry on that task.

[00:04:46] [SPEAKER_00] And therein lies this challenge of having lots and lots and lots of agents times lots of employees means, you know, tens, hundreds of thousands of agents in your company. And as agents come and go, because obviously we want to have the best possible agent doing the things for us, and new ones come up in the last couple of weeks, we've learned about OpenClaw. Well, nobody really knew about OpenAI two months ago.

[00:05:11] [SPEAKER_00] And yet it's incredibly powerful, and there are folks who are trying to figure out how to make it powerful and have it be something you can trust. But there are going to be lots of that. It was written by one guy, right? There's going to be lots of different AIs that come out, and you're not going to want to reconnect everything and redo all the rules every time a new interesting agent comes along.

[00:05:35] [SPEAKER_00] So we believe that what needs to happen, and this is the company that Barndor is, we believe what needs to happen is there's a governance layer that manages all of these different agents on behalf of humans or not on behalf of humans, and what the agents are allowed to do given the tools they're trying to use, the context, the data they're acting on, what specific task they're doing. And that's what we built at Barndoor. And that's a great platform for companies to go and manage that.

[00:06:03] [SPEAKER_00] But the challenge we have today is that a lot of people still don't know what to do with that because MCP is relatively new. And MCP has, while it's taken off a bit on the developer set because it's kind of a technical thing to get up and running, your average finance, HR, salesperson isn't really doing much with it yet. And so because they don't know what it can do, they don't understand the power. We do.

[00:06:32] [SPEAKER_00] All of us use it every day here at our company because we've been playing with it for a while. But people really need to understand what it can do. And so in order to make that happen more broadly, we've introduced a tool called Venn. And what Venn is is everything I just described to you but for one person.

[00:06:50] [SPEAKER_00] So the idea is that you as an individual can come to Venn.ai, sign up, get started for free, and you can use it to hook up to all those same things, email, Slack, calendar, all the different tools you use whether at your company or in your personal life. And now some companies will have security that will cause it to not allow you to use Venn on corporate systems. You might have to go get special permission to do it.

[00:07:18] [SPEAKER_00] Or you can play with it in your own life on your own personal products and learn the things that you're able to do when you hook your AI up directly to the tools that you use. And our belief is that as people start learning that, that they're going to be able to bring those learnings back to their companies, and their companies are going to be more likely to implement something like Barndor in order to allow everyone in the company to benefit from this productivity.

[00:07:47] [SPEAKER_01] Just for listeners that aren't following, MCP is Model Context Protocol, and it's basically a bit of code that allows models to talk to tools or to APIs as well, doesn't it? Yeah.

[00:08:12] [SPEAKER_01] And when you refer, you talk about how AI has been in advisor mode, and that enterprises are facing action mode where they're actually going to have AI doing things in the enterprise. I spoke to a guy at EY. Sure. I don't know if it's still called Ernst & Young, but EY.

[00:08:40] [SPEAKER_00] I think it's EY. In fact, my co-founder, my technical co-founder came from EY. That was his last job.

[00:08:45] [SPEAKER_01] Okay. Yeah. Yeah. And he was saying that while there's a lot of enthusiasm and excitement about agents, very few corporations or enterprises are putting them into production because exactly what you said, the trust issue, that these systems are probabilistic.

[00:09:09] [SPEAKER_01] And even if they do a wonderful job 90% of the time, there's going to be a small percentage of the time where they do something unintended. Sure. Yeah. Can you talk about that? Absolutely. And then why you compare agents to enthusiastic interns? I thought that was an interesting...

[00:09:31] [SPEAKER_00] No, I think... So at their heart, these models, these AIs are probabilistic systems. They basically... You give them a task or you give them a prompt, you tell them something. And with a lot of really, really complicated math, they give you what they feel is the most likely set of words or pixels or video or whatever you're asking for,

[00:09:56] [SPEAKER_00] that is to them the most likely answer to the question that you're asking. And that is different than when you program an API. When you program something that uses an API, the API has certain capabilities and certain ways of using it that are documented. And the programmer writes a program that accesses that and does a specific thing with it. And if you run that program 100 times, it's going to do the exact same thing all 100 times.

[00:10:25] [SPEAKER_00] But probabilistic things don't work that way. And so what you then have is you have these systems that basically say, gosh, I'm being asked this. What's the most likely answer? And the more context you give, the more likely the answer is going to be close to what you intend. And people are starting to learn to do that.

[00:10:47] [SPEAKER_00] But absent a lot of context and even sometimes with a lot of context, you're still going to come into cases where an instruction is interpreted not in the way it was intended. And, you know, we see that with humans as well. That's why I like to call them enthusiastic interns. They will absolutely give you an answer. They will absolutely do something when you tell them to. Whether it has what you have intended, who knows, right?

[00:11:15] [SPEAKER_00] And so the sort of the potential blast radius of this, if you have an intern, you tend to manage them with a bit of skepticism at the beginning. And you say, okay, I want you to go do these things and I'm going to keep an eye on you. And I'm going to give you, you know, start you on something that's not terribly, you know, important or if you screw it up, it's not going to be catastrophic to the company.

[00:11:43] [SPEAKER_00] And as we work together and I see that you're capable of doing these things without causing a problem, I'll let you do more. And I'll ask you to do more and I'll give you broader access and broader capabilities and broader autonomy as you prove yourself capable of doing it.

[00:12:05] [SPEAKER_00] And I think that that's actually how a lot of people, either intentionally or unintentionally, are embarking on their AI journey. So, you know, you first start using it as basically glorified search. And then it becomes, you know, it becomes something more than that when you perhaps ask it to write some code or you perhaps ask it to interpret something for you. And then you get to a thing.

[00:12:32] [SPEAKER_00] One of my colleagues yesterday said that she gets so many Slack messages. And at the end of the day, she wants to, you know, feel like she can log off and, you know, go be with her family. So the last thing she does each day is she says, look at all my unread Slack messages and tell me which five are important for me to answer before I quit for the day. And, you know, that's not, that's something you can't do unless your AI is hooked up to your Slack.

[00:13:03] [SPEAKER_00] And, but it is something incredibly useful to her.

[00:13:07] [SPEAKER_01] Yeah. And, and in the past access to these systems by software, by more deterministic software was controlled by identity and access management systems. Yes. And, you know, we've all worked with those and then there, there's higher level in the stack.

[00:13:31] [SPEAKER_01] There's some that kind of sit outside the database and check the identity of who's accessing the database and check what's being taken out of the database and they can have limits and that sort of thing. Why is that not enough for Gentic AI?

[00:13:49] [SPEAKER_00] Because identity supposes that you have a human and the human comes with their own governance. I, as Orin, know that it's stupid to delete Salesforce opportunities. I'm allowed to, but I know I shouldn't. And I know that if I do it a lot, I'm going to get fired. And so that's a level of governance beyond merely identity. And it comes with my role. It comes with my identity.

[00:14:15] [SPEAKER_00] But it also comes with my history of proving to the world that I'm not going to go do stupid stuff. And the nature and identity is generally over-provisioned intentionally because we trust people to a certain point and we don't want to have to rush back. And every single time I need to do something in Salesforce, I've got to go to the Salesforce admin and have them flip one more switch for me.

[00:14:40] [SPEAKER_00] So in general, they say, okay, this guy's been hired and he's shown himself to be reasonably trustworthy. So generally speaking, we're going to give him broad latitude and assume that he's likely to not misbehave. And you don't want to take that authority away from me as a human just because I'm now using AI. But you also recognize that I, as a human, probably am not perfect at using AI.

[00:15:10] [SPEAKER_00] And I'm probably going to give some instructions that are, you know, not necessarily definitive to my AIs. And so my AIs, the AIs I'm using need by definition to have a smaller blast radius than I do. The thing about AIs is they can cause a lot of trouble really, really quickly. And, you know, they're much faster at this than I am.

[00:15:34] [SPEAKER_00] And so it's likely that you want to dial back what these things are capable of doing, certainly at least until you have the opportunity to say, okay, I've given this AI a task. And now I'm going to look and see how it attempts to carry out that task.

[00:15:57] [SPEAKER_00] And for the things it does, the MCP calls it makes, the requests it makes, if all of those are consistent with the task I've given it, great. I'll turn those capabilities on and let it go do those things. But I probably want to try it that way first and limit how much it's allowed to do before I let it just sort of run autonomously every day and go do stuff for me. Yeah.

[00:16:22] [SPEAKER_01] Yeah. Although even, I mean, there's something called automation bias where, you know, you run a system 10 times and it does it perfectly each time and pretty soon you stop checking. Yes. But if the thing is 97% accurate, you're not going to see those 3% go by where it makes a mistake.

[00:16:51] [SPEAKER_01] So how do you control that?

[00:16:53] [SPEAKER_00] Well, you probably have another agent that checks it. Right? And I think we're going to see a lot. You know, we have that in, we've had that in IT for many, many years. I remember one company I ran was a employee benefits administration sort of online sign up for benefits thing. Very, very complicated data. And we're dealing with dozens of insurance companies and hundreds of client companies. And it was very, very complicated.

[00:17:21] [SPEAKER_00] And so every night we would run a program that basically went through and looked at everything and made sure it all made sense. Because people would make mistakes or something would get corrupted or whatever. And it just made sense to go through and just have that double check. And I think that, you know, as we look at agents being able to take action autonomously, we look at how you QA that.

[00:17:51] [SPEAKER_00] It's the same thing with software. So, you know, my software engineers write some code and the first thing that happens before that code gets committed is another engineer looks at it and blesses the pull request. Right? And in many cases, a bot comes through and does a bunch of QAs and tests on it as well.

[00:18:10] [SPEAKER_00] So, you know, I think we have always had a culture of making sure that the work that people do is checked. You've been a journalist a long time. I'm sure you've had editors. And, you know, that's it. And fact checkers and all those sorts of things. And it's something we do.

[00:18:33] [SPEAKER_01] Yeah. Yeah. Okay. So tell us more about Barndoor and then Venn. I mean, you're really targeting enterprising. You talked about how individuals can use Venn. Yeah. But you're focused on the enterprise. It's very early days. As I said, enterprises are very cautious.

[00:18:57] [SPEAKER_01] But last time we spoke, you were explaining how, I don't know if it's BarnDoor or Venn, allows you to set very narrow. Yeah.

[00:19:10] [SPEAKER_00] Yeah. And BarnDoor is the enterprise grade product that lets you really do this. So, for instance, as you start allowing people to, in a company, to hook in their corporate systems and use them with AIs, there are various things you know that you don't want to be able to happen. Some of them are company-wide.

[00:19:34] [SPEAKER_00] So, for instance, one of the companies we deal with, the first policy they created is no AI is allowed to post to a Slack channel that starts with hash EXT. Because those are the channels that include people from other companies. So, we're like, for now, let's just limit the blast radius of AI on Slack to inside the company. Right?

[00:19:57] [SPEAKER_00] No AI is allowed to post to anything that writes, whether it's email or Slack or anything like that, with anything that looks like a social security number, a phone number, an address, anything that resembles PII. So, you sort of filter that stuff out. You basically say, if it's attempting to do that, reject the attempt. So, there are some very broad rules you can create.

[00:20:24] [SPEAKER_00] But then when you start getting into the sort of the more narrow rules, if you have a specific, like I have an agent that after I do a sales call, it goes to my calendar, pulls who was on the call, goes to Zoom, gets the transcript, summarizes it, goes to Salesforce, and logs the call with the folks who were there.

[00:20:50] [SPEAKER_00] So, AIs are not, because they're not determinative, sometimes they're unable to find what they're looking for in Salesforce. So, I allow my AI to create this call log, but I don't allow that particular AI to add new contacts to Salesforce. Because what I found in the past is that sometimes it will say, oh, that person's not in Salesforce, I'm just going to add them. They actually were in Salesforce, they just didn't find them.

[00:21:17] [SPEAKER_00] And what I don't want is 20 of the same person showing up in Salesforce. So, I'd rather it not complete the task and let me know and have me help it find the person than it goes and makes a bunch of nonsense in our Salesforce instance. And that's a specific thing there. Whereas a different task I have, which would be, for instance, I attended a Wall Street Journal conference last week, and I got a list of people who were at the conference.

[00:21:45] [SPEAKER_00] I wanted to make sure all of them were in our Salesforce. And I knew most of them probably weren't. So, I was happy to have this agent go through and actually create contacts for each of them.

[00:21:57] [SPEAKER_01] Yeah. You talk about a difference between safe read actions and destructive write actions for agents. Is this an example? Absolutely. When you say, yeah. Yeah, absolutely.

[00:22:16] [SPEAKER_00] And the thing about writing is, again, I believe that for an agent to actually be an agent and be useful, it has to write. And when people talk about MCP and they talk about the connections in Claude, the terms being used for what is ultimately MCP, most out-of-the-box connections don't allow writing because they don't have the governance.

[00:22:42] [SPEAKER_00] So, if you sign up with Claude and you say, okay, connect to my calendar, it won't actually create calendar events for you. It will just tell you what's there because they don't have built-in this governance. And so, you know, MCP, you sort of touched on it earlier. What MCP is, you have an underlying API which generally can do everything.

[00:23:06] [SPEAKER_00] It has, as long as you have the access and you are allowed to use those capabilities, an API can pretty much do anything that you could do with the user interface. When you create an MCP, the person creating that MCP chooses to expose a subset of that set of capabilities to the model.

[00:23:32] [SPEAKER_00] So, you might have many, many, many, many things that can be done. Some are reads, some are writes, some are deletes, some are, you know, drops. They're fairly catastrophic things that one can do programmatically. And the person creating the MCP will rationally say, out of all those things, here is the subset I want to expose.

[00:23:52] [SPEAKER_00] So, out of the box, most of these MCPs only expose things that do reading that can't write or overwrite or do things that cause problems because there's no governance that manages that. By using BarnDoor or Venn, we provide MCPs that actually do have those capabilities because they come with the governance that allows you to turn on and off the things you don't want them to be able to do.

[00:24:18] [SPEAKER_01] Right. And how do you, is this a page of toggles? Yeah. Or are you?

[00:24:25] [SPEAKER_00] So, there's, on Venn, it is exactly that. It's a page of toggles for every single service that you're signed up for. In BarnDoor, it's a lot more capable than that because it's an enterprise product. So, you can use the toggles. You can write in a language called JSON. You can write a set of very, very specific policies around it.

[00:24:47] [SPEAKER_00] And you can also do that not just through our user interface, but you can do it through our API because we believe that there are going to be so many of these agents out there that at a certain point, humans are not going to be able to create and manage all the policies that are going to be necessary.

[00:25:02] [SPEAKER_00] So, you're going to have a series of, you know, whether they're AIs or programmatically driven systems that actually ultimately turn on and off these capabilities based on the context.

[00:25:19] [SPEAKER_01] Yeah. Is there a conversational interface given that, you know, LLMs are pretty good?

[00:25:27] [SPEAKER_00] We actually, yes, we have an MCP. So, there is an MCP to BarnDoor and so you're able to, using whatever conversational interface you prefer, you can use our MCP to do these various things. Absolutely.

[00:25:42] [SPEAKER_01] Yeah. And talk a little bit about some of the challenges with agents. I mean, what is context window exhaustion?

[00:25:53] [SPEAKER_00] Yeah. You know, that's been a big issue. And when you think about how your AIs work, the AIs are managed through these things called tokens, which are essentially what a measure of how much is coming into the model and a measure of how much is going out. And I talked about the MCP. The MCP is a, it's essentially a tool and a user manual on how to use that tool for every tool that you have exposed.

[00:26:23] [SPEAKER_00] So, a typical MCP for, let's say, Gmail might have 40 or 50 or 100 different tools, each of which comes with a very significant manual that tells that AI how to access that tool. And so, if you open one of these, every time that you say, I need to use this MCP, the first thing it does is it brings in all of those tools and all of those user manuals, which burns lots and lots of tokens, even though you're not going to use most of them.

[00:26:54] [SPEAKER_00] Let's say you then turn on two or three more MCPs. Now you have calendar, you have map, you have mail, you have Slack, you have documents. Now you've got so many tools and so many user manuals that you have already used up all the tokens your window allows before you actually do something. And that's context window exhaustion. And it's why when you, and the other challenge, by the way, is with all of these tools, it's just confusing.

[00:27:22] [SPEAKER_00] It's like walking into Home Depot and you see a sea of tools in front of you. You don't know where the hammer is. You don't even know what a hammer is or how to use it. You're like, well, I'll grab the nearest thing. And what you find in the models is you'll say something like, go to Salesforce and give me information on these three opportunities. And it will say, I will go to your Google Drive and get you information on it. Because it just, it's overwhelmed.

[00:27:48] [SPEAKER_00] And so what we've built is what we call tool IQ to the model. All the model sees is a single MCP and that's ours. And ours then abstracts all the different tools that you have hooked up. So the model says to us, hey, I'm trying to do this. And our tool router says, okay, if you're trying to do that, here is the small subset of tools you need to go do that. And here's how you use them. And the model says, thank you very much, makes the call and off it goes.

[00:28:18] [SPEAKER_00] And it's sort of like, you know, you have a task, a chore to do at home and you just get the little tray of tools you need to do it. You're not bringing all of Home Depot with you, right? And so because of that, you save a lot on tokens, but you also get better response. Because you're actually having this sort of smart layer in between that abstracts these tools and makes them more useful for the model.

[00:28:39] [SPEAKER_01] Yeah. And then you're not wasting so much of the processing power. Absolutely.

[00:28:47] [SPEAKER_00] Absolutely. Yeah.

[00:28:52] [SPEAKER_01] The, you know, we're at this inflection point. In my mind, particularly because of Open Claw.

[00:28:59] [SPEAKER_00] Absolutely. That was a huge, huge event for us. Yeah.

[00:29:04] [SPEAKER_01] Do you think, I mean, it just brought the power of agents into some segment of the public consciousness. Yes. Is, is, can Barndor or Ben run on top of Open Claw? Absolutely.

[00:29:24] [SPEAKER_00] Because Open Claw is notoriously. OpenAI by itself doesn't talk to MCP. Part of the ethos of Open Claw is it shouldn't need to. It should just write whatever program it needs and go off and do whatever it wants, right? That's sort of the ethos. However, there is a extension to Open Claw called MCP Ops or MCP Ops as some people call it, which essentially is an extension for Open Claw.

[00:29:51] [SPEAKER_00] It downloads with Open Claw and allows Open Claw to access MCPs. And so that MCP Ops thing can, of course, access any MCP, including the Venn or the Barndor Tool IQ MCP.

[00:30:05] [SPEAKER_01] Yeah. A lot of people, me, for example, have been using Open Claw through something called MyClaw AI. I don't know who owns that.

[00:30:17] [SPEAKER_00] I don't know who did it either, but it's a lovely, you know, it's the cloud for Open Claw, right? Yeah.

[00:30:24] [SPEAKER_01] And it just simplifies the, it's installed in the cloud. You just log into it rather than trying to set it up on your own IDE. Does Barndor or Venn work with MyClaw?

[00:30:39] [SPEAKER_00] I assume so because it's just a regular version of Open Claw and it should be able to run MCP Ops. So I haven't tried it personally, but I don't see why it wouldn't.

[00:30:49] [SPEAKER_01] Yeah. And so what you're saying is that, yeah, agents are great. There's tremendous promise. Enterprises are scared of them and may be experimenting at the margin. And that's largely because of a trust and control issue. And Barndor provides a layer of control that then provides trust. Is that right?

[00:31:16] [SPEAKER_00] Exactly. And I was at a conference with about 50 enterprise CIOs and CISOs last week and very large companies. And they all are on this, they're all on this journey in various levels. And it's actually interesting to see.

[00:31:33] [SPEAKER_00] There's a lot of companies, even companies that have been around 50, 100 years, that have very active and capable IT teams who are actively experimenting with and building MCPs both to SaaS services they use but also to internal systems. And there's definitely a demand for this. And it seems this is an event I go to twice a year.

[00:32:00] [SPEAKER_00] And the change between six months ago and this past conference, there's just, it's the front of everyone's mind. Absolutely.

[00:32:10] [SPEAKER_01] Yeah. You know, I was at a conference last year with a company called, it was a customer conference for a company called Boomi. Oh, sure. Yeah. Yeah. I know them well. That is integration.

[00:32:30] [SPEAKER_00] Boomi actually, I believe Boomi now owns Smashery, which is the company I founded. I think it's right. We sold it to Intel and Intel sold it to TIBCO. And I think TIBCO may have sold it to Boomi. I'm obviously not involved anymore, but I think they own it. Yeah. So I'm certainly familiar with it.

[00:32:45] [SPEAKER_01] So, you know, that is a platform that connects applications, data, devices, cloud, on-prem. Um, uh, where would Barndoor sit?

[00:33:02] [SPEAKER_00] Uh, Barndoor, so Boomi, Boomi would provide the API management layer. I see. We'd provide the API that we would sit in front of. Now, Boomi will also, and all of the API management folks are going to have some version of MCP that they do. But the kind of fine-grained access control that I was describing earlier, that's out of the realm of the traditional security and API management world.

[00:33:30] [SPEAKER_00] It's a different level of combining identity with the systems and also the fine-grained access control that really reaches to the management of each of these individual systems. Your CISO doesn't know from Salesforce. They don't know what someone should or should not be allowed to do specifically in Salesforce.

[00:33:51] [SPEAKER_00] They need a broader level of, of management for each of these various tools to be governed as they need to be governed in order for, uh, successful and safe agent deployments to happen.

[00:34:07] [SPEAKER_01] Yeah. Uh, so this level or this layer in the stock, uh, that, that Barndoor provides, uh, how, are, how stiff is the competition for you?

[00:34:25] [SPEAKER_01] And, uh, because this is absolutely needed for enterprises to, uh, to use a, uh, agents are, do you see, uh, an industry, uh, forming around this? I see.

[00:34:43] [SPEAKER_00] I see. So I see a few things forming, right? I see, uh, the way I look at the, at the landscape in our world, you have incumbent companies, whether they're API management or identity or, you know, packet security or whatever. You have various incumbent companies that certainly need to present with something that seems credible here.

[00:35:06] [SPEAKER_00] Um, but they're, by their nature, by the nature of the way incumbents operate, they're going to attempt to sort of bolt this on to the underlying infrastructure of what they have. And what we're finding in the POCs we do, and we, when we're compared to these, is that those just don't go far enough in creating the kind of, of management layer that you need. So that's one element, and I, and I think we compete very well with that.

[00:35:34] [SPEAKER_00] And the other version is you have a series of developer tools that are out there. The concept is you're building some kind of an AI application. You can have the connections and the governance you need inside your application to, to manage this. And, uh, and there are various people who are doing versions of that. And the challenge with that are twofold.

[00:35:59] [SPEAKER_00] One is no one in their right mind really trusts AI companies to govern themselves. I, I, I just, I think that at this point, uh, we realize that the incentives they have to move quickly are not necessarily consistent with the, with the incentives around governance.

[00:36:21] [SPEAKER_00] Um, but it's also that no CISO or CIO wants to have hundreds of systems in their company that are individually governed. Because every time you bring one of these things in, now you're once again setting up the connections, once again setting up the rules, once again setting up the governance. And what we've learned, um, from open claw is that new things come along all the time that we're not, that we're not expecting.

[00:36:50] [SPEAKER_00] And that, you know, from that we're going to have to, um, we're going to have to be able to try and swap things in and out quickly. And that's not something that, that we do.

[00:37:04] [SPEAKER_01] In, in the piece I wrote and the conversation we had earlier, I mean, uh, we were talking about how early days this is, uh, we're, we're right at the very beginning probably, uh, of, of agentic AI in the enterprise. Uh, probably less than 1% penetration in production of, of, uh, large enterprises.

[00:37:31] [SPEAKER_01] Uh, why do you think, uh, 2026 is, is an inflection point beyond open.

[00:37:40] [SPEAKER_00] I think, I think that as, as humans were pattern matchers. And so the more we see, the more we want to do. And when AI first came on the scene, the folks who were using it to actually do stuff were coders. Because that's the one job in the enterprise where you actually do spend your time chatting with PhDs, right? You, your code doesn't work. You go to your CTOs, probably a PhD, and say, fix my code. And they do.

[00:38:08] [SPEAKER_00] And now you have an AI that does that for you instead. Um, great. Then you had, so, so, you know, that was an initial use in, in that world. And for the rest of us, it was, you know, essentially started off being glorified search. And then it became something which becomes, has become a part of our lives. But it's still more around a conversation and suggestions of things humans do.

[00:38:36] [SPEAKER_00] Well, then the coders figured out with MCP and such that they could actually get the, these AIs to not just help them fix their code, but create new code. And that became a thing. And we've all now seen the benefits of that. And that's radically changed how software gets developed. But that still hadn't yet started to happen elsewhere in the enterprise.

[00:38:59] [SPEAKER_00] And now we're seeing knowledge workers, marketers, salespeople, HR people, attorneys. We're seeing all kinds of people starting to embrace AI to actually get work done. It's new. But the more everybody sees that, the more everybody wants that. And so it's just taken until now for people to see essentially what the potential is and actually see that potential realized.

[00:39:29] [SPEAKER_00] And once they start seeing that, they want it on their own.

[00:39:33] [SPEAKER_01] Yeah. And do you think, how quickly do you think that adoption curve or steep that adoption curve is going to be? And as a company, I mean, are you seeing a lot of uptake or do you, is enterprise?

[00:39:53] [SPEAKER_00] Are definitely our cadence is increasing, which is nice. It's good to see. And I would say the steep uptake really is moments that people see someone solving a problem that they themselves have. So, you know, I saw an article some more recently about how you can use AI to help empty your massive inbox of old emails.

[00:40:24] [SPEAKER_00] And we're seeing early users of Venn doing a lot of that, right? And so, you know, there's, when people see that as an example, they sort of go and start doing it. And so part of what we're going to be doing with Venn is watching what folks are doing. We can't see the actual data. We can't see what you bring through it.

[00:40:45] [SPEAKER_00] But we can see the patterns of use and say, oh, this is probably what folks are doing and start, you know, bringing those to the surface and giving people ideas of how they can use this technology. And, you know, if you show someone what they can do with the tool, that's way better than just saying, here's a tool, go play with it.

[00:41:05] [SPEAKER_01] Yeah. On the enterprise side, how advanced, what kinds of processes do you see that could fall to agentic AI?

[00:41:22] [SPEAKER_01] I mean, we talk about, in all of my conversations, it boils down to sort of the daily grind of the knowledge worker, you know, filling out forms, you know, cleaning up or tracking your email inbox, writing responses.

[00:41:46] [SPEAKER_01] And there is a lot of talk about, you know, the agentic enterprise where more complex processes are handled by AI. But I've never really heard what those processes are. Yeah. Yeah. So what do you see? What would be an advance?

[00:42:11] [SPEAKER_00] Yeah. I'll start with it. I was on a panel, one-on-one chat at a conference last year with someone who might be a former colleague of yours, Quentin Hardy. I don't know if you know Quentin.

[00:42:23] [SPEAKER_01] Oh, yeah. I know Quentin very well. Yeah.

[00:42:25] [SPEAKER_00] So he's a dear friend. And we were on this talk together. What Quentin said was, you want AI to take on the tasks that you have in your job that you never want your kids doing if it's their job. And, you know, so that was a good start.

[00:42:45] [SPEAKER_00] You know, it's sort of like, what is it that I hate doing that just makes it, you know, as a knowledge worker, it keeps me from doing the stuff I really want to do. And start with those things. So that's one version of it. But I think it also goes further than that.

[00:43:03] [SPEAKER_00] And that is that so much of what we're seeing in AI and agentic AI in these early days are around solving things humans are doing and making it faster and maybe a little more accurate and making it so humans don't have to do it. And sort of being a faster human, which is sort of the faster horses thing, the old adage from Henry Ford, right? And that's great.

[00:43:33] [SPEAKER_00] But what I think is much more interesting are doing the things that humans aren't and can't do because they're not in our nature to be able to.

[00:43:42] [SPEAKER_00] And so, you know, we see it is early days, but it really comes down to understanding what AI is good at and what it's not and sort of figuring out what should be done programmatically, figuring out what should be done, you know, non-deterministically by these models, bringing those tasks together and creating new workflows based on them. And it's not the workflows, you know, you look at a Zapier.

[00:44:09] [SPEAKER_00] Zapier is all about, again, automating things we as humans do. It's a lovely product. We use it all the time. But that's, again, that's faster horses.

[00:44:19] [SPEAKER_00] And we want to, and I think what we're going to see exposed in these, you know, in the uses both of Venn and Barndor are things that folks who understand how to sort of abstract a problem and maybe solve it in a different way are going to go off and try to do and succeed in doing because this technology exists. And that's a lot more important or interesting to me.

[00:44:45] [SPEAKER_01] Yeah. Yeah. I mean, and, you know, I'll edit this. So if you don't have an answer, that's fine. But can you think of a critical business process that maybe enterprises you've spoken to would like to automate with agents?

[00:45:05] [SPEAKER_00] Yeah. So we're talking to a major hotel chain right now. And they want to be bringing this capability into their guest services. So if you think about it, if you stay at a fancy hotel, yeah, that's pretty and there's nice things around. But what really makes the difference is personalization.

[00:45:27] [SPEAKER_00] And today that personalization is, oh, they have a nice thing in your room or they, you know, they, I've had hotels that found a picture of me and my wife and it was our anniversary and they put it in the room. Right. That's lovely stuff. But if you can really start personalizing and really start understanding, particularly for returning guests, how they interact with the hotel, how they interact with the systems and anticipate their needs, you can do that in a way humans can't possibly do manually.

[00:45:59] [SPEAKER_00] And so it comes down to all the things. You know, you think of what AI has been being used for, for the past, you know, five, 10 years, really, really effectively feeding us advertisements. Right. It's been really, really good at that. Well, we don't necessarily want to be fed advertisements. We want to have really amazing experiences. And as much as the ad companies say, we're giving you a great experience, they're not. Right.

[00:46:24] [SPEAKER_00] But there are so many services and goods that we buy that can be brought to us where we are in the way we want it to be, that companies that succeed in doing that and unlock the data they have and then empower agents to act on that data are going to win based on just giving us humans a better experience.

[00:46:55] [SPEAKER_01] Yeah. Yeah. You talked about HR, HR department for AI in regards to IT departments. I mean, who is going to be running agents in the interview? Is it the IT?

[00:47:13] [SPEAKER_00] It's a good question. You know, I now go to chief AI officer conferences, which weren't a thing two years ago. Right. Right. So right now it's the person that the CEO went to and said, you make AI happen. Right. And that's whoever that is. It's often a CIO or a CTO or someone in that world. It is HR sometimes. It is line of business.

[00:47:37] [SPEAKER_00] One company, it's a pal of the CEO who had retired a few years ago and was brought back to lead the AI efforts. So it can be just about anyone. I think over time it will straddle these organizations kind of in the way that the CIO does. I mean, you know, at most companies, IT has to understand and straddle different parts of the company. And it means different things to different parts of the company.

[00:48:07] [SPEAKER_00] And I think this is going, as does HR. And I think that you're going to see companies that really, really embrace this are going to have AI at the table. Because, you know, when I talk to folks who work for me or in companies I advise, we talk about the difference between a manager and an executive.

[00:48:34] [SPEAKER_00] And a manager has a department to run and their job is to make that thing run really efficiently. And their focus is largely on delivering the thing their world has to do. An executive has to have the perspective of the entire company. It's often the executive's job to make their own lives more difficult in order to make the company as a whole succeed.

[00:48:58] [SPEAKER_00] And to me, when people start understanding and managing at that level, that's when they become an executive and stop being a manager. And I think that for AI to be successful in the company, the people who are, you know, sort of empowering it and deploying it and setting the rules about it and governing it

[00:49:19] [SPEAKER_00] need to have a pretty broad understanding of what's happening in the company and need to understand where more risk can be taken in order for higher reward to happen where it can't be. And sort of, you know, it's not one size fits all across the company. That's one thing. And the other is you can't expect all the humans in your company to wake up one morning knowing how to make AI hugely successful.

[00:49:46] [SPEAKER_00] We talk about, you know, 95% of AI projects fail. It's because the project was, here, use AI. We now have it. We have a deal with OpenAI now. You can use it. And people didn't know what it was. It looked like a search box. What do you do with that, right? And so, of course, it failed.

[00:50:04] [SPEAKER_00] And so, you have to also, across the organization, really find and promote and celebrate the people who figure out how to take the business challenges a company has and apply these new tools and technology to solving them. And that's not everyone in the company.

[00:50:24] [SPEAKER_01] That's right. Yeah. I talked to BCG periodically, and their head of their North American tech practice just had an article on LinkedIn about what he calls agentic quotient, which is kind of like IQ or EQ. You've got to find people in your organization that have a high- That's a great term. I like that. Quotient. Yeah. I will steal that. To manage these things, yeah.

[00:50:54] [SPEAKER_01] Currently, there is infrastructure to govern AI agents. There is. And what does Barn Door do to improve on that infrastructure already? I mean, we've already talked about it.

[00:51:17] [SPEAKER_00] Think of how you govern humans, right? So, you govern humans. You have certain people whose job it is to let them in the building and let them do various things. You have certain people whose job it is in systems whose job it is to decide what they're allowed to access and when and monitor what they're doing. We are that for the agents, right?

[00:51:38] [SPEAKER_00] And so, there are various folks out there who are trying to manage and govern AI sort of by getting inside its head, its metaphorical head, and understanding what it's doing and governing that. And I don't think that that's very easy. I don't think that you can necessarily do that anymore. Or you can get inside my head and govern me.

[00:52:05] [SPEAKER_00] So, with a lot of this, I think the governance really needs to be, you know, understand what's going in and what's going out and govern that. That's a big part of it. That's a part that we manage, right? And then there will be other elements that will be managed in terms of, you know, adaptations of other things that we have been managing in security for a long time.

[00:52:30] [SPEAKER_00] And, you know, most decent companies that are well run have various levels and vectors of security that they deal with because they understand that you only have one security to rule the ball.

[00:52:46] [SPEAKER_00] And what's different with this new concept of AI and agents that it's kind of different than what came before is that traditionally security's main role was to keep bad people from outside the company out or keep people inside the company from doing things they're not allowed to do. And that's still really, really important.

[00:53:11] [SPEAKER_00] But there's this new thing where someone who's inside the company and is allowed to be there doing something they're allowed to do with a tool they're allowed to use and bad things still happen. And that's a different vector that has not been the realm of the IT and security folks before. And in order to manage that new concept, that's why new tools are necessary.

[00:53:39] [SPEAKER_01] Yeah. Okay. You know, I'm going to ask a couple of questions that, you know, maybe you're not prepared for. But you straddle the creative world and the sort of hardcore tech world, which are very, very different worlds. Does any of this apply to theater production at any level?

[00:54:07] [SPEAKER_00] Oh, absolutely. Absolutely. And so, you know, art and creativity have been embracing technology in various ways for a long time. You know, Frank Garius famously said that without computers, he could never have designed the buildings that he designed, right?

[00:54:24] [SPEAKER_00] And so, AI as a, you know, AI is being used today in theater, certainly in marketing and helping us find new audiences, right? It's used in helping us, you know, when you're designing things, whether you're designing sets and lighting, you know, there's a lot of specifications, a lot of data that's involved. You know, it's interesting.

[00:54:54] [SPEAKER_00] You go to a Broadway theater and at the end of every show, they load everything out. It's an empty building, essentially. When you load in a Broadway show, one of the first things that's loaded in under the stage is basically a data center.

[00:55:13] [SPEAKER_00] And you walk under a Broadway stage and you see racks and racks and racks of servers and computers because it's a very, they're controlling the lighting, they're controlling the sound, they're controlling the set, all the automations on the stage, all those videos. The technology involved is staggering. And so, managing this technology and sort of improving it and, you know, I have a good friend who's a two-time winning Tony lighting designer.

[00:55:41] [SPEAKER_00] I sat with him through tech rehearsal last year for one of his Broadway shows and his screens across all the things he's seeing, we're sort of going through what each of them was. And he's like, yeah, two years ago, none of this existed. And the technology continues to evolve, particularly on Broadway because it's so expensive. And so, you know, it's so risky, particularly doing musicals, that you have to use whatever tools are available to you in order to make these things successful.

[00:56:11] [SPEAKER_00] And you have to be able to model things and you have to be able to try things. And you have to be able to, you know, synthesize an awful lot of information that comes at you very quickly. I was involved in one show. We did an out-of-town trial. We gave everybody surveys. We looked at the reviews. I just put all that stuff in chat and had it summarize it for me, right? And that was incredibly helpful.

[00:56:39] [SPEAKER_00] And I was chatting with a director, a longtime Broadway director, about it. And he said, yeah, you came up with basically the same conclusions we did after three days in Post-its, right? And so, you know, that is a very useful way to make use of this technology in creating art.

[00:57:02] [SPEAKER_01] Yeah. And what about agentic AI?

[00:57:05] [SPEAKER_00] You know, it's early days. But I would be, it would not surprise me if there are elements of managing these services and in particular managing the safety issues, right? That there's a lot of these systems. And, you know, I see enough Broadway shows every, you know, 15 or 20 shows.

[00:57:32] [SPEAKER_00] They stop the show in the middle of the performance, get everybody off the stage because something isn't moving right, right? And managing and monitoring these systems. You know, every show before the show, they turn on every light individually and make sure it's working properly. They move everything. But, you know, all of these systems kick off data.

[00:57:54] [SPEAKER_00] And understanding and managing this data and proactively scheduling maintenance and scheduling replacements of equipment and things like that to make sure everyone stays safe and make sure the show stays consistent the way it was opening night. I definitely see that coming. Yeah.

[00:58:14] [SPEAKER_01] Yeah. And you guys are a platform company. Are you also a service company? I mean, do you consult with...

[00:58:23] [SPEAKER_00] We have people here whose job it is to come and work with our customers and bring them ideas. So back in Mashery days, we would run, we had all these companies doing APIs and many of the companies didn't really know how to spell API, let alone why they were doing them. And so we would come into those companies and essentially run hackathons.

[00:58:44] [SPEAKER_00] We would come over the weekend and get every company together with some food and some beverages and some smart people and some coders and some non-coders and say, okay, you've now got this cool new thing called API. Let's find real business solutions to go solve with it. And we have folks who do the same thing with that here as well.

[00:59:04] [SPEAKER_01] Yeah. Wow. Okay. Well, Oren, if people want to explore this, they should go to barndoor.ai.

[00:59:12] [SPEAKER_00] Barndoor.ai. Barndoor.ai. And if you want to play with your own personal aversion, that's at Venn.ai.

[00:59:17] [SPEAKER_01] And that's B-E-N-N.ai. Where did the name Barndoor come from?

[00:59:22] [SPEAKER_00] Well, you know, we have a habit in our world of closing the Barndoor after the horse is already out. We felt that maybe it was early enough in the agentic journey that I felt that for once we had the chance of having the barndoor in place before the horse got out. And so that's why I named the company then. That's good.

[00:59:45] Thank you. Thank you.