AI Engineer World's Fair 2026

An AI Future Without the Lock-In — Remy Guercio, Tailscale

Read the talk

An AI Future Without the Lock-In

Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 33 secondsOpen full source frame
Opening slide: “An AI Future Without the Lock-In.”

Remy Guercio explains how separating models, data access, interfaces and execution environments can make internal AI deployments easier to change—and how Tailscale’s Aperture gateway connects those choices through identity, budgets and logs.

From a talk by Remy Guercio

At a glance

Ideas worth remembering

  • Separate models, data connectors, interfaces and execution environments so a team can change the component it needs without choosing a bespoke stack at every layer.

  • Aperture uses tailnet user and machine identity to determine access, while provider credentials and connector authentication remain at the gateway.

  • Different budgets for cheap and frontier models keep lower-cost options available while constraining expensive usage.

  • Central data authentication lowers the effort of trying another agent client; gateway logs help explain failed or unexpected attempts.

  • Pass-through identity for additional interfaces and sandbox orchestration were planned additions in the recording, extending the same approach beyond direct client connections and model routing.

Long context makes agents useful—and expensive

A coding session can grow to hundreds or thousands of messages without anyone clearing its context. In the gateway usage Remy Guercio sees at Tailscale, some sessions accumulate tens of millions of tokens while their cache remains effectively maxed out. Keeping context can help an agent continue its work, but a session that keeps growing also keeps spending. This is the practical opening problem for Guercio, who works on Tailscale’s AI gateway, Aperture.

The preceding year’s “token maxing” had a useful purpose: discovering what agents could do with million-token context windows and access to information from many places. MCP connectors, command-line tools and coding tools could find context and bring it into a model. That combination made agentic coding possible in ways a standalone chat interface could not.

Two costs now complicate that progress. Large, persistent sessions consume money, and vertically integrated toolchains tie the model to the agent and its surrounding tools. Claude Code and Codex are examples of that integration. As the assumption of an unlimited AI budget weakens, the question becomes how to keep useful capabilities while making room for less expensive tasks and different implementations.

Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 168 secondsOpen full source frame
“Problems” slide listing expense and vertically integrated toolchains.
0:122:12
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

0:12 · section reference included

Consolidating vendors can narrow the ways AI pays off

The natural response to an unexplained bill is to reduce the number of things that can generate it. Over six months of conversations with hundreds of people about AI usage, Guercio repeatedly encountered the same proposed fix: standardize everyone on one vendor, perhaps two. Finance wants an explanation; IT wants control; mandating the tool everybody already seems to use feels like a manageable answer.

That decision can preserve the expensive part of the deployment. If every use case must run through a frontier model and its entire ecosystem, work that cannot justify that cost becomes untenable. A smaller vendor list may simplify purchasing while leaving the organization with too few ways to make AI useful.

Guercio calls the next objective “ROI maxing”: prove that a workflow creates value, and retain enough choice to expand usage where the economics make sense. This is a proposed direction for internal AI deployments, rather than a demonstrated calculation of return on investment. The talk develops the architecture for making those choices; it does not quantify the resulting savings or productivity gains.

3:424:12
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

3:42 · section reference included

Separate the four choices inside an internal AI deployment

An internal AI deployment has four components worth choosing separately. This framing concerns the tools people and agents use inside an organization, rather than a new AI feature shipped to customers.

  • Models: The LLM or LLMs that perform the work.
  • Data connectors: The ways an agent gets information, including MCP, CLIs, APIs and reading files.
  • Interfaces: The place people interact with the agent, such as chat, an IDE, a phone or Slack.
  • Sandboxes and environments: The place the agent runs.
Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 403 secondsOpen full source frame
Slide listing LLMs, data connectors, interface and sandboxes/environment.

Separating these components does not require a bespoke selection at every layer. It preserves the ability to change one when a particular team needs something different. An engineering team may prefer a coding interface, while a marketing team may ask data questions entirely through Slack threads. Those teams should not have to adopt the same interaction pattern merely to share access to models and organizational data.

The useful design question is therefore whether changing an interface also forces changes to model access, connector authentication or the execution environment. A gateway offers a common point through which several of those choices can be managed, reducing the work needed to try another tool.

5:436:13
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

5:43 · section reference included

Put the gateway between agents and their endpoints

Aperture sits between agents and the endpoints they call, including LLM providers, MCP servers and APIs. That position gives it two jobs: control access and spending, and record what happens. The same infrastructure used to enforce policy can also help explain an agent’s behavior.

Consider an agent that keeps working without reaching an answer. Its logs let a user return to the attempt and ask where it went wrong. Guercio’s observation is that models which struggle to stop themselves can still be useful at analyzing their failed attempts afterward. Logging makes that retrospective investigation possible; it does not itself make the agent stop.

Many gateways centralize provider keys, then issue another set of synthetic keys to clients. Aperture uses a different source of client identity: the Tailscale connection. Tailscale is an identity-based mesh network built on WireGuard. Installing its agent on the relevant laptops, containers or GPU servers lets connections across the resulting tailnet carry information about the user or machine at the other end.

Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 605 secondsOpen full source frame
Diagram showing a login identity provider connected to several nodes.

That identity has useful distinctions. A tagged machine can represent a PR review bot, while its separate node ID identifies a particular instance of that bot. A laptop connection can identify the person using Claude Code. Groups synchronized from Entra or Okta can add organizational membership. Aperture is built with the open-source tsnet library, which lets it see this connection identity and use it when handling requests.

What stays shared when the client changes? The diagram shows several clients reaching one gateway, where connection identity informs access and budgets before requests reach models or data services. The important relationship is that provider credentials and connector setup live at the gateway, while the client supplies a request over the tailnet.

How it fits togetherDifferent clients, shared identity and endpoint configuration

Cursor, Claude Code, Codex or another agent framework.

Aperture uses tailnet identity to apply access and budget choices while centralizing provider credentials and data connector authentication.

8:138:43
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

8:13 · section reference included

Give cheap and frontier models different budgets

On the model side, an administrator places provider credentials on the gateway. Guercio describes a configuration containing providers including Anthropic, OpenAI and Vercel. The client then connects without creating a separate synthetic gateway key: Aperture recognizes the connecting user or agent and determines which providers and models it can use.

This makes a differentiated budget possible. A cheap model can have an unlimited budget while a frontier model has a very narrow one. The policy keeps a lower-cost route available for experimentation and routine work, while constraining the expensive route. It does not establish that the cheap model can complete every task; earlier in the talk, cheaper models were also associated with attempts that fail to stop.

Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 504 secondsOpen full source frame
Aperture usage dashboard with a bar chart and summary figures.

Centralizing the model layer also gives the organization a place to change providers. Provider setup and budget decisions no longer have to be reproduced independently for every agent tool. The intended benefit is room to choose a model for the work, rather than letting the first adopted tool determine every subsequent choice.

11:1311:43
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

11:13 · section reference included

Keep data authentication when you switch agent tools

Aperture also acts as an MCP gateway. It can inject authentication into standard API requests and re-expose those APIs as MCP services. This is why Guercio deliberately uses the broader term AI gateway: the managed endpoints include both models and the data services agents need.

Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 841 secondsOpen full source frame
Aperture connectors screen showing a selected connector and configuration details.

Connector setup has its own switching costs. MCP servers may follow different versions of the standard and use different authentication approaches—enough variation to turn setup into an “archeology lesson.” Aperture puts that integration work in one place. Administrators configure the permitted servers, including built-in integrations the team has checked for ease of use.

Identity then distinguishes several parallel access choices:

  • Marketing access: Google Calendar and Gmail can be available to the marketing team.
  • Engineering access: Engineering can additionally receive GitHub access.
  • Permission levels: Different parts of engineering can receive read-only or write access to GitHub.

Follow the engineering example through a tool change. An engineer using Claude Code can be recognized through their tailnet identity and receive the GitHub access assigned to their group. If that engineer tries Cursor or Codex, the new client reaches the same gateway endpoint over the tailnet. Authentication still happens at Aperture, so trying the new client does not require repeating authentication separately for every configured data service.

The observable change in this example is the agent interface; the data authentication remains centralized. Removing repeated sign-ins lowers the effort required to compare workflows. That matters because small setup frictions can prevent the experiment that would reveal a cheaper or faster way to do the work.

12:1312:44
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

12:44 · section reference included

Custom interfaces need to preserve the person behind the request

Aperture includes a chat UI—“Surprise,” as Guercio puts it—but that UI runs on APIs other developers can use too. The same services can support a Slack bot, another chat interface, a mobile app or a voice interface. Connectors are configured in Aperture rather than in its chat UI, so the interface consumes access that has already been set up.

Selected presentation frame from An AI Future Without the Lock-In — Remy Guercio, Tailscale at 908 secondsOpen full source frame
Aperture chat interface displayed in a browser window.

An intervening UI introduces a subtle identity problem. Requests can appear to come from the UI’s system account, losing the distinction between the users behind it. The gateway still sees traffic, but the identity it sees is less useful for understanding who caused it.

Pass-through authentication is the proposed fix: carry user and machine identities through the interface so the gateway retains that visibility. Guercio describes this as coming soon at the time of the recording. The ability to use Aperture’s APIs and the plan to preserve identity through additional interfaces are therefore separate parts of the story.

14:4315:14
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

14:43 · section reference included

Execution environments and logs complete the picture

Sandboxes already offer considerable choice. Different teams mean different things by a sandbox and need different properties from the environment where their agents run. That variety has produced a “let a thousand flowers bloom” phase, with many providers and active integration work.

Aperture’s planned sandbox orchestration layer would extend the gateway’s role into that fourth component. At the time of the talk, this is a future addition. The ambition is to make environments, models and connectors visible together and easier to combine—something Guercio describes as almost a universal translation layer. Centralizing that coordination is intended to preserve choices across the deployment rather than only across model providers.

The ending returns to a use case smaller than an enterprise rollout: one person running an agent in the background. The agent does something unexpected, and its owner does not know what happened. Routing its activity through a gateway provides logs to revisit the attempt and diagnose where it went wrong.

That diagnostic use is valuable even when there is no immediate provider switch to make. A gateway can support experimentation by making an attempt inspectable: what the agent did, where the workflow diverged and what might need to change next. Guercio’s closing recommendation extends beyond Aperture. Consider a gateway for the understanding it provides, as well as the choices it keeps available.

6:4316:44
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

16:44 · section reference included

Resources

Read the complete timestamped transcript
  1. 0:12

    Well, hi, folks. Uh, thanks for joining me here for the last talk on this stage, uh, of the, uh, AI Engineer World's Fair this year. So, um, yeah, thank you for joining me. My name's Remy. I am on the strategic projects team at Tailscale. Uh, and more specifically, I actually work on our AI gateway, Aperture. And today I wanna talk a little bit about, you know, what it means or, you know, what it's gonna take, uh, to have a AI future without the lock-in. I

  2. 0:42

    think a lot of the lock-in that we've seen, uh, over the last twelve months. And yeah, so if we take a look real quick at the, you know, the last twelve months, you know, I think it can really be, you know, described quite a bit by, uh, the phrase token maxing. And I, I don't mean that in the kind of, you know, negative sense that you might kind of hear outside of the, you know, kinda AI enthusiast circle. I mean that in the sort of, you know, it's been a year of trying to figure out, you know, what we can do with million token context windows,

  3. 1:12

    uh, with the ability to get context from anywhere, right? Not just, you know, MCP being everywhere, but, you know, also having coding tools, right, that are great at finding context, using the CLI, bringing that context into the model, uh, bringing it, you know, bringing it into, you know, everything that you need and, and, and going from there, right? It's, it's been pretty cool, right? I mean, we've gotten-- It's really made truly agentic coding possible, having all of this, right? So yeah, it's, I mean, it's, it's quite cool and, you know, we're gonna see, uh, not just agentic

  4. 1:42

    coding but, you know, other agentic use cases where it continue to take off, uh, as we, as we do this. So, um, you know, token maxing is cool, but right, it has, it has problems, right? Ob-- There's obvious problems, right? It's very expensive, right? It's, it's, it's an extremely expensive endeavor. Uh, you know, I think the last twelve months are, you know, have maybe been marked by, "Hey, we have, you know, unlimited AI budget." Uh, and that's changed here in the last few months, uh, in

  5. 2:12

    terms of, you know, what it, what it means to, you know, what it means to use AI. Um, it also-- I mean, you know, it's expensive, like, just generally if you're doing it, you know right. But it also, it does incentivize what I would call, like, wasted tokens by default. I mean, I, I work on an AI gateway. Uh, we use our AI gateway. I get to see all of the usage from the AI gateway. You would not believe the number of sessions that are hundreds or thousands of messages long where nobody clears the context. They just kinda keep going. I mean, it's helpful sometimes, but, you know, it's,

  6. 2:42

    it's, it's pretty surprising. You will have, you know, tens of millions of tokens of a session, uh, where it's-- the cache is basically max out, maxed out the entire time. Uh, it gets really expensive. Um, and the other thing is, right, so, you know, this has been an exciting time, right? People are doing new things, building new things, uh, but this has led to, you know, in many cases, very vertically integrated tool chains. Uh, Claude Code is obviously, you know, a big one. Codex, right? Everybody's kinda building up their, you know, for all the way from the model, you know, all the way, all the way out of the top, uh,

  7. 3:12

    you know, building their, uh, you know, building their agents, building their tool chains. So, um, right, there's a lot of problems there. And so, you know, my question, right, in terms of this is, uh, you know, how do we address these problems? In particular, how do we address the lock-in and, you know, how do we actually improve, uh, how we use AI such that, you know, we can use it for things that aren't just, you know, kind of essentially frontier task or where we're just kind of wasting, wasting money, wasting tokens, uh, you know, that sort of thing. Um, but first I wanna talk about how not

  8. 3:42

    to address the problem. Uh, and this is a super, super common thing. So, uh, over the last six months, we've been talking to-- I've literally been talking to hundreds and hundreds of folks about their AI spend, their AI usage, right? That's the kind of benefit of working on an AI gateway. Folks come to you, they're like, "I don't know what's going on. I know we're using a lot of AI. I get, you know, uh, I get an Anthropic bill every day. Uh, I get a Codex bill every day." Um, uh, so you know, I-- it's not just that, you know. I see it all the time. So you

  9. 4:12

    know, what do I do? They usually come with one kind of solution in mind, uh, and that is, "Oh, we're just gonna, like, uh, everybody seems to be using Claude Code right now, so we're just gonna, like, consolidate on a single vendor. Maybe two vendors, right? Maybe two vendors." So that's, uh, they're like, "I need to get a handle on this. How do I get a handle on this? How do I get, you know... Oh, oh, okay, yeah, I will say everybody's gonna use this, right? We're just gonna use this thing." Um, that is not, not a great idea. Uh, you know, I-- might seem obvious sitting here that it's maybe not a great idea, but you know, when you're in that

  10. 4:43

    panic zone of, "We've spent a lot of money, and we don't know how exactly," uh, and we, you know, finance is talking to you, IT is being like, "What are you doing?" Uh, um, you know, like, we said to, you know, use AI, but maybe not use that much AI. Uh, and you know, it, it's a pretty natural response to go, "Okay, I'm gonna consolidate everything down, right? Okay, well, I'm gonna, I'm gonna have a control on it. I'm gonna have, you know, I'm gonna have control on this, uh, control of this." Um, and you know, I think this is kind of peeking at what we're gonna see the next twelve months and what people are actually trying

  11. 5:13

    to do. Uh, at least at the, you know, kind of frontier is, uh, what I would like to call ROI maxing, right? We're not gonna be token maxing. We're gonna be ROI maxing. Uh, and you know, it's, it's really just a necessity, right? It's not, uh, um... And I don't mean that-- When I say ROI maxing, I don't just mean cutting costs, right? I mean actually proving some sort of value, uh, to the thing that you're doing. Uh, and not only that, but also kind of opening things up, right? So if the only thing you have is, like, two frontier models

  12. 5:43

    and their entire stacked ecosystem, that's a certain cost level where you, you-- it just makes things un- certain things untenable, right? You can't actually expand AI usage into the company if that's the only way you can use AI. Um, and so, you know, when we think about ROI maxing, we first need to kinda think about, like, what are the components- Of an internal AI deployment. I'm not talking about, like, a, "Hey, we've built this new AI feature in our app." I mean, you know, internal, internal to your organization. And so, you know, there's four things, right? There's the LLM or LLMs, right, there's that

  13. 6:13

    layer. Uh, there's sort of the data connector layer. I mean, this is MCP for a lot of people, but in reality it's, you know, CLI or APIs, or really just any way that you get data. Uh, could be reading a file, right, into your, uh, into your agentic system. Uh, there's the interface. I think people kind of forget about this sometimes, but you know it's started with the chat interface. We got 2Es. You know, we kinda got a, uh, we got, you know, IDEs with chat. We got, you know, kind of a whiplash back from 2Es into, you know, I'm gonna do it on my ... go to my phone, uh, you know, to

  14. 6:43

    oh, now the, you know, the hot thing is, you know, Claude Tag, and like, I'm gonna use, you know, I'm gonna use... We're just gonna interface with agents via Slack, right? So, uh, um, you know, it's another core component, and it is a component that you can break out. Uh, and then the last one is sandboxes/just the environment in which the agent runs, right? So those are your four kind of, uh, you know, four components really. Uh, and to be ROI maxing, uh, means to be maxing your, you know, every opportunity that you have, uh, for choice, to make a choice at one of those

  15. 7:13

    layers, right? You don't have to necessarily have a unique thing at, you know, oh, I've made my bespoke special choice at every one of those layers, but it's really important to be able to make a choice at any given layer that you need at any given time. Uh, and it might be different for different teams or different folks, right? It's, you know, it, it can be pretty different across the organization. I don't totally imagine, like, an entire engineering team just coding via, you know, Slack thread. It might be fun, but I don't totally imagine that, right? Uh, um, but, you know, the entire marketing team

  16. 7:43

    might be working entirely, uh, you know, in a Slack thread asking data questions, doing other things like that. So it's really important to, you know, to be able to, uh, kind of separate these things. And right, so I, I work at Tailscale, right? I work on an AI gateway. Uh, you know, maybe no surprise that I'm here to talk a little bit about why an AI gateway, uh, will help you do that, can help you do that. And I don't just mean necessarily using our AI gateway. I think it's nice, but, you know, just any AI gateway is the, um, you know, is important for this. Uh, so our AI gate- AI gateway is, uh, called Aperture,

  17. 8:13

    and, um, what it does, uh, is, right, it's maybe no surprise here, right? But it lets you-- It sits in between your agents and that interface of that agent, uh, and, you know, all of your endpoints, uh, as wel- both, like, LLM endpoints as... and data, you know, kind of MCP endpoints, API endpoints, anything that you have, uh, it sits in the middle and lets you both control and monitor what's happening from a-- That can be from a, like, security perspective. That can be from a cost perspective. That can be from a, which we do a lot,

  18. 8:43

    "I wanna learn about what somebody is doing or what an agent is doing" perspective. It's actually really cool when you have logs, uh, and you can tell your agent to, "Hey, uh, I... It... Maybe it ran out." It kind of just kind of, you know, oh, it, it didn't reach an answer. It just kind of spiraled out of control. Uh, maybe happens less now. Definitely used to happen quite a bit. Happens with, you know, maybe cheaper models more often too. Uh, they're usually not great at stopping themselves, uh, but they are great at analyzing where they went wrong after the fact. And so when you have

  19. 9:13

    something like an AI gateway, it's really easy to point it back at what you were doing and say, "What happened?" "Why did this not, why did this not, you know, work the way I was expecting it to?" Uh, and so, you know, if you've used an AI gateway, how many people, like, have an AI gateway, have deployed an AI gateway, use an AI? Yeah. So if you've used one before, you're probably used to, "Okay, so I've put all my keys on this gateway. Now I need to go create synthetic keys for everything that I have," right? So it's like, okay, I've traded some keys for a bunch of other keys. Uh, we get to

  20. 9:43

    do something a little special. So Aperture is built on Tailscale, and if you're not familiar with Tailscale, Tailscale is an identity-based mesh network. It's built on WireGuard. Uh, and what you get to do with Tailscale is, uh, every connection that is made over a tailnet, so it's a Tailscale network. Uh, you know, you install the tailnet agent everywhere that you need. It can be containers, laptops, GPU servers, doesn't matter. Um, you install it everywhere, and every connection that's now made over that tailnet,

  21. 10:13

    uh, comes with the identity of the machine or the user on the other side. So that can be a tag, right? So that can be like, "Hey, this is a machine ID. This is a PR review bot," right? Uh, and then it would get a separate node ID underneath. This is the instantiation of that PR review bot, right? So you can do that, or it can be the user, right? So it's just me using Claude Code on my laptop. Uh, that can come with it as well. Uh, in addition to if you're using something like Entra or Okta, uh, we can actually sync all the groups in, uh, so you can see the group that that person is associated with. So something on the

  22. 10:43

    other side is able to see all of that. We have this really cool library. It's called tsnet. It's an open source library. You can use it to build these sorts of apps. That is what we use to build Aperture. That is what is actually happening here. So it is able to see the, uh, it is able to see the identity of that user or that agent on the other side of the thing or the other side of the connection. And so, you know, again, just reminder, components of a, you know, an internal, you know, AI deployment, uh, right? So there's the LLM side of things. There's the data side of things, the interface side of things, and the

  23. 11:13

    actual sandboxes, uh, sandbox and environment in which things run, uh, side of things. So, um, when it comes to using Aperture, uh, you know, as far as LLMs go, this is pretty similar, I think, to, you know, what you might expect from other, other AI gateways. Except now, you know, here I have a, you know, a configured gateway. Uh, it's got Anthropic, OpenAI, Vercel. You know, it's got even Anthropic OAuth, uh, you know, Bedrock Codecs, everything, uh, that you can imagine. I put all those keys on that gateway, and then now

  24. 11:43

    when I wanna actually connect to that LLM provider as an agent or a user, there's no-- I don't have-- There's-- If I had this expanded, there's, there's no extra screen for create these API keys, create these identities, create this. Once I connect to the-- Once I actually connect to the gateway, it knows who I am. It knows what I am. And it's like, "Oh, you have access to these models, this provider," right? You can use GLM 5.2. Uh, you get this budget with GLM 5.2, right? You get unlimited budget with a cheap model, and you get an extremely narrow budget with

  25. 12:13

    a frontier model, right? Those sorts of things. Uh, there's no extra setting here. It's just add your, add your API key and go. So again, we've taken all the LLM layer, and we've put it into a, you know, put it into one place that you can then, you know, kind of expand out within your organization again. Doesn't matter if you're trying to switch models or providers, you can do that. Uh, the next thing is the data side of things. So, uh, in addition to, you know, being an, an LLM gateway, and this is actually why I said AI gateway at the beginning. So I know that seems kinda nebulous,

  26. 12:44

    uh, but I've actually, I very specifically chose that term because we're both an LLM gateway and an MCP gateway, and we even do auth, like, uh, injection for just standard APIs and re-expose those as MCPs too. So, uh, you know, kind of intentionally choosing the broader term here. Um, but with this, as you can see here, uh, in Aperture as an admin, you can go in and configure whatever MCP servers you want. We have kind of built in ones where we've, you know, checked them out, made sure they're easy to, easy to work with, all those sort of things. If you've ever

  27. 13:13

    deployed an MCP or used MCPs within your organization, you'll know that, uh, there's a standard, but everybody follows a different version of that standard. Uh, you know, you can tell exactly when an MCP server was built by exactly how they decided to do auth. Uh, yeah, it's a, it's a great, uh, you know, kind of archeology lesson, uh, when you go through, when you go through setting up MCP servers. But we try to make that a very simple process here, right? We've kind of gone through this. Uh, so you as an admin can say, "Hey, I've configured these. These are the ones that are allowed." You can use that

  28. 13:43

    same identity information to say, "Hey, the marketing team, you know, they get access to Google Calendar and Gmail, but the engineering team will also get access to GitHub," right? Uh, you can even say things like, "Oh, the engineering-- you know, this side of the engineering team gets access, write access to GitHub or read-only access to GitHub." You can do all, all sorts of things here. And what's really nice, and again talking about decoupling, is all of the authentication happens here. So if you have folks that wanna use Cursor or they wanna use Claude

  29. 14:13

    Code or they wanna use Codex or they wanna use some special agent framework that they're-- You know, some new hot thing that they've, you know, they've discovered or built or whatever, uh, all they have to do is hit that endpoint, and if they're on the tailnet, everything's authenticated as them or as whatever the agent or as whatever, you know, the tag device is. Uh, there's no like, "Oh, I have to go reauth into everything and then reauth into everything and then reauth into this new tool." Uh, we make the switching cost, right, of like actually trying out tools and trying different workflows and different experiences a lot, a lot easier with

  30. 14:43

    this sort of thing. It's all those little points of friction, uh, that lead to use cases where like, you know, people just don't try new use cases. They don't try to, uh, you know, "Oh, maybe I should experiment. Maybe I can make this cheaper. Maybe I can make this faster." Um, you know, next thing, talking about the interface. So, uh, with Aperture, we actually have a built-in chat UI. Surprise. Uh, you know, everybody seems to have a chat UI. We have a built-in ch- built-in chat UI. Um, however, it is built on top of APIs that you can also leverage yourself. Uh, so our whole goal

  31. 15:14

    with Aperture is to actually provide you with the same sort of, you know, tools and interfaces and-- or tools to build interfaces that we can. So whether or not you wanna build a Slack bot or you wanna build a chat UI or you wanna build, you know, some new thing that nobody's thought of, some mobile app kinda thing, you know, voice only interface, right? Uh, you can, you can do that. The whole point is you're gonna be able to do that with Aperture. We wanna support all of those din-- different individual, uh, use cases. But again, you can see it has connectors. Those are all, again, set up through Aperture itself. They're not set up in the

  32. 15:44

    chat UI. You're just getting them, uh, by way, by way of Aperture. Uh, and then the last thing-- So this is, uh, you know-- So we talked about interfaces, you know, a little bit. It's, you know, it's-- Again, it's very important, uh, that you be able to kinda use all of that. Uh, actually one other thing that's coming very soon here is, um, uh, if you've ever s-- I don't know if anybody's ever tried to set up like Open WebUI or, you know, or like Libre-- Like, or any of the-- Like, kind of like any of the like, "Oh, I'm gonna set up like a, hey, this like, you know, this interface or this interface." Uh, one big

  33. 16:14

    thing is you always lose identity information and then suddenly all of the, you know, everything's coming from the UI, right? Everything's kinda like, "Oh, everything's just coming from the system." Uh, we're actually gonna be adding a full like pass-through auth, uh, so you'll be able to actually see all of the like user identities and machine identities if for some reason they're using whatever interface that you have. Uh, you're just gonna be able to set it up so that you can pass through the auth and you still get all of the same visibility that you're kind of expecting from a, from an AI gateway as well. Um, and then, yeah, the last thing is, right, this is actually the-- I think the area

  34. 16:44

    in which, um, folks are doing pretty good. There's actually a lot of choice already. People are trying to do this. Uh, I think that's because, uh, the definition of a sandbox, I'm sure I could poll everybody here and would have a different-- everybody would have a different definition of exactly what a sandbox is, uh, or what they need from a sandbox or what they want from a sandbox. Uh, and so, you know, there's-- we're kind of in that let a thousand flowers bloom phase of, you know, there's a sandbox provider for every sort of whim and need and, you know, and want out there.

  35. 17:14

    Um, but, uh, you know, and folks are doing a pretty good job of integrating them. But again, it's a really important thing. We're actually gonna be adding kind of an orchestration layer as well for sandboxes to a gateway. Uh, again, trying to use that term AI gateway very loosely, intentionally very loosely because in order to, again, kind of make the best choices for all of the different endpoints that your, you know, environments, LLMs, data connectors, all that sort of thing, uh, you really do need, uh, to kinda have a place to sort of see them all, uh, and then a place that brings them all together such that you can then

  36. 17:44

    use any other one. So right, kind of a-- almost a universal translation layer in a way. Um, but yeah. So that's, that's mostly that. And, you know, like I said or as a reminder here, uh, is, you know, ROI maxing really is all about maximizing choice, uh, to prevent lock-in, right? So, you know, even if you don't use Aperture, I do highly recommend you start considering an AI gateway. You look at an AI gateway. It's, it's good just beyond like actual, you know, oh, you know, I don't have to, you know, uh, have three different providers

  37. 18:13

    configured or switch between them this way. You know, uh, it's good beyond that, right? It's great for just, you know, understanding what agents are doing, even if it's just you as an individual. We have so many people who are just as an individual, they have their usage behind an AI gateway just to have an idea as to what their agents are doing because, you know, if you're running, uh, very commonly, uh, is people are running something like OpenClaw with-- on Tailscale and it's on their tailnet and they-- and it's just running in the background and they're like, "Oh my goodness. It, it did something. I'm not sure what it

  38. 18:43

    did. It did something it was not supposed to do." With something like an AI gateway, you can actually go back and you can see and you can look and you can actually diagnose where it went wrong, what happened. Um, so, you know, it's, it's not just lock-in, right? It's actually just experimentation and understanding as a whole, uh, is, you know, is very important to use something, uh, like a, like an AI or LLM gateway. So, um, that's it, uh, for my talk. Just short and sweet. Uh, thank you very much for attending. I know this is the, the last talk in here of the day, so, uh, I hope everybody's had a

  39. 19:13

    really great conference. I know I love the AI Engineer World's Fair, uh, and I hope you do too. So thank you.