← All speakers

Bio, Work & Ideas

Sam Prodger

Conference affiliation: Gravitee

On this page

Sam Prodger is a Field CTO at Gravitee on secondment from the RNLI, where his work combines data leadership with experience as a volunteer lifeboat crew member at Poole. His career spans coastal research, lifesaving data services, and enterprise AI governance, with a recurring concern: dependable information, controlled access, and systems whose behavior can be inspected when something goes wrong.

From coastal measurement to lifesaving data

Prodger earned a PhD at the University of Plymouth in 2017, investigating how sand grain size and sorting vary across beaches and over time. His research combined regional sampling with detailed observations at individual beaches, examining properties that influence sediment transport and beach shape but can be oversimplified in models.

At the RNLI, his responsibilities developed from analysis into leadership of data and applications. A 2022 presentation identifies him as Head of Data Operations and Applications; he subsequently led the charity’s data function as Head of Data.

The RNLI’s API-first modernization gives that work concrete stakes. Before a lifeboat launches, an operations manager needs to assess crew readiness, lifeboat availability, and weather and sea conditions. Legacy file transfers, batch processing, and local knowledge made relevant information harder to access and systems harder to connect. The RNLI adopted Gravitee to govern the APIs supplying these signals, including those used by its callout and messaging application. Access controls protect sensitive crew and operational information, while monitoring helps IT teams identify failures that could affect downstream operations. Launch decisions remain human judgments supported by data and training.

Prodger’s placement at Gravitee extends this relationship beyond a conventional customer engagement. After more than eight years at the RNLI in various roles, he began a twelve-month secondment on March 2, 2026, with a planned return to the RNLI in March 2027 and another person taking over his Head of Data responsibilities during the placement. It gives him exposure to API, event, and AI management strategy while bringing the perspective of an operational volunteer and technology customer into Gravitee’s roadmap.

His coastal research also continued alongside his data career. He co-authored a 2024 study of lesser weever fish habitat that used beachgoers’ sting incidents, adjusted for water-user numbers, to investigate patterns of fish abundance. The collaboration used operational records to examine environmental questions that are difficult to study through direct sampling alone.

Enforcing what agents can do

Prodger argues that governance belongs in infrastructure. Agent instructions can describe acceptable behavior, but permissions must be enforced where an agent calls a tool or accesses a system. His hotel-booking agent demonstration makes that distinction concrete: an agent can discover a destructive tool without being authorized to execute it.

His approach connects several operational concerns:

  • Identity-scoped authorization: In the demonstration, the gateway rejects a request to delete all bookings with a forbidden response while allowing the agent to cancel an individual booking. A separate scenario blocks access to synthetic guest records. The aim is to let an agent complete authorized work while enforcing limits on the actions and data available to its identity.
  • Curated MCP tools: Prodger advocates narrowing the tools exposed through the Model Context Protocol to those an agent needs. He describes a CRM server exposing 64 tools: reducing that set limits both the capabilities available for misuse and the context sent to the model. Tool selection and runtime authorization serve related purposes, but neither replaces the other.
  • Cost controls before inference: Rate limits and prompt-size checks can stop requests before they incur downstream model costs. Semantic caching addresses repeated work by serving sufficiently similar requests from stored responses. In his booking-query example, Prodger reports roughly 200 tokens with caching versus 1,000 without it; these are demonstration results rather than a general savings guarantee.

Prodger also emphasizes visibility across workflows that move between models, tools, and other agents. Exportable telemetry lets teams inspect requests, tool calls, and policy decisions through their existing monitoring systems. Model routing separates applications from a single provider, while his discussion of shadow AI on employee laptops identifies a practical limit: governance must account for traffic that otherwise bypasses the managed gateway. These concerns extend his focus on dependable data services to software agents acting on enterprise systems.

Read the topics behind these talks

1 conference talk

Key ideas

Scroll to read ↓

A hotel-booking agent makes the difference between written rules and enforced permissions concrete. Five live scenarios show where a gateway can stop destructive actions, protect guest data and prevent avoidable model calls.

  • Tool discovery and tool authorization are separate. The governed booking agent discovers the bulk-delete tool, but the gateway denies execution while allowing the individual cancellation.
    3:12 ↗
  • Rate limits and prompt-size limits avoid downstream model work only when they run before inference. The demonstrations admit three requests per minute and reject an oversized prompt before an LLM call.
    7:43 ↗
  • Semantic caching reduces repeated model calls, with configurable similarity and visible cache-hit logs. The five repeated booking queries consume about 200 tokens with caching versus about 1,000 without it.
    8:53 ↗
  • A gateway can also route models and curate MCP tool catalogs. Those controls reduce provider-specific coupling, unnecessary context and the range of operations exposed to an agent.
    14:33 ↗
  • Gateway enforcement depends on traffic coverage. Direct AI use on employee laptops motivates the edge-management capability described at the end of the talk.
    16:03 ↗

References