Rory Blundell Podcast Transcript
Rory Blundell joins host Brian Thomas on The Digital Executive Podcast.
Brian Thomas: Welcome to The Digital Executive. Today’s guest is Rory Blundell. Rory Blundell is the Chief Executive Officer of Gravitee, one of Europe’s fastest growing companies and a leader in agentic API and event management. He joined in March 2020 as the Chief Revenue Officer, becoming CEO in September 2020.
Under his leadership, Gravitee has grown from four people and a half a million dollars in revenue to over 180 employees and more than 40 million in revenue, earning recognition as a Gartner leader in API management. The platform delivers consistent security, discoverability, and observability across APIs, event streams, and AI agents, serving organizations across Europe and North America, including Blue Yonder, Walmart, and Ernst & Young.
Well, good afternoon, Rory. Welcome to the show.
Rory Blundell: Thank you for having me, Brian.
Brian Thomas: Absolutely, my friend. I appreciate it, and I know you took the time to traverse time zones and calendars to get here today. You’re hailing out of London, England, and I know you do quite a bit of travel to the US as well, so I appreciate your time today.
And Rory, jumping into your first question here, you joined Gravitee as Chief Revenue Officer in March of 2020 and became CEO just six months later, then scaled the company from four people and a half million dollars in revenue to over 180 employees and more than 40 million in revenue. What was it like taking the top job in the middle of a pandemic at such an early-stage company, and what conviction did you have about Gravitee’s mission that made you bet on it?
Rory Blundell: Yeah, great question. I had, just taking the second point first, the conviction that I had was I– So I got to know Gravitee by installing and using the software myself in actual fact, and I was just amazed at the capability this platform had. And I felt that the world at that time, back in twenty-twenty, twenty-twenty one, was going through a, a, a shift, probably not as seismic now looking back at it in retrospect as the AI world that we’re in at the moment, but it was still going through a significant change of people starting to adopt real-time event-based architectures.
And what I saw with the company was the ability to pioneer an entirely new space of API and event stream management. So everything that we had done for the last fifteen or twenty years with APIs, I thought, hang on a sec, you could do this with event streams as well. And, to cut a long story short, this is– we’re trying to do the same thing again with agents as well in the agentic world.
But that was really what sort of made me think, “Hey, I’m gonna go and take a fifty percent pay cut. I’m gonna go and join this company in the middle of a pandemic,” and, all the crazy decisions, frankly, in retrospect, when I look at it, that I made it was because I had this fervent belief that we could achieve a lot more and that the foundations of the business were exceptionally strong.
Brian Thomas: That’s awesome. Love the story. And again, that’s usually the first question here on the podcast is kind of that backstory and you were from the get-go early on, you were early user of the software, impressed by the capability, but the ability to pioneer event streaming with, with the platform really inspired you and your belief in the company, where it was going, even though it was during the pandemic and, the next day-to-day, just nobody knew what was gonna go on with the, the global economy.
So I appreciate the backstory. Thank you. Rory, you’ve argued that governance frameworks built for the API economy are fundamentally insufficient for the agentic era, that traditional API management platforms are essentially blind to the unique behaviors and risks of AI agents. What specifically breaks down when you point legacy API governance at autonomous agents?
Rory Blundell: Well, I think, I think there’s a number of things associated with this that are, that are challenging really for when you look at a technology. The first thing is that agents operate at a fundamentally different speed than we would’ve had with APIs and things of that nature. And so it’s less, I guess it’s less that the foundations of an API gateway and things of that nature aren’t necessarily…
They’re just not built and architected to be able to utilize those sorts of technologies. So if you’ve got MCP, for example, a fundamentally different protocol that one would use to be able to mediate agents communicating with tools, for example. Now, behind that tool might be an API fundamentally, but where, where APIs themselves are maybe not best placed, and API gateway’s the result of that, is that some of these subtle changes, the speed, the types of authentication, the granularity of authorization, authentication, all these sort of things, because the whole world, not just APIs and API management and API gateways, the whole world was architected around the human being the central point of focus.
And there is a seismic, subtle but seismic shift that has changed, that no longer is it the human that’s necessarily the sole center of gravity, excuse the pun. It’s the, it’s also now the agent, and that is a truly, truly differentiated thing that we’ve never really had to contend with, I would say, at any point that I can think of, certainly from a technological perspective in the past.
So it’s less specifically that it’s just, oh, these things, APIs, et cetera, are bad, et cetera, or they’re, they’re a thing of the past. That, that’s not the case. They’re still very, very widely used and still required, but it’s just that the mechanisms and the speed and the authentication, the authorization, all of these sorts of things, the paradigms are fundamentally shifted in the new agentic world versus the, the versus the human world.
Brian Thomas: Absolutely. We’re just seeing a major shift across the world in just about every vertical. And APIs is obviously at the forefront of that, in my opinion as a, a, a prior developer. But- agents are operating much faster, m- faster than we’ve ever seen, and we can’t just rely on legacy APIs for this new agentic world that we’re moving into.
And I appreciate you breaking that apart for us and I like the pun there as well. Humans aren’t the, no longer the center of gravity, right? Yeah. That’s awesome. Thank you. Rory, you’ve said that we’re, we’re giving AI arms and legs. Would it be reckless not to give it a central nervous system too?
Positioning Gamma as the control layer that makes the agentic future safe to deploy, unpack that metaphor for us. What does that central nervous system actually consist of technically, and why is a unified control plane better than bolting governance onto each tool?
Rory Blundell: Yeah, it’s a great, it’s a great question. What’s the best way to describe this? So let, let’s imagine, for example, in the old world, let’s say you’ve got a door. You’ve got a door into your office, and your door has a keypad next to it, and you’ve got your key card, and you swipe your key card on the keypad. Now, historically, what you had to do is the keypad might have been tools like, I don’t know, Okta, Ping, things like this, and the, the, the door might have been your API gateway.
Now, what you had to do was you had to stitch those two things together, and it’s very, it’s challenging in a, in the modern world when things are operating with non-human identities and stuff like that to actually, to have to do all this stitching together when you need to start looking at technologies like fine-grained authorization.
You need to really be able to… Th- things like OAuth 2, where you have more coarse-grained permissions and all that sort of stuff, don’t really work when you’ve got humans and agents that act on behalf of the humans, which is quite a common thing that we’re seeing these days. They call the on behalf of flow.
Those two things alone add a layer of complexity that just talks to the fact that really this concept of having the keypad and the door separate, actually what Gravitee is bringing and our agent management or Gamma, as you called it, framework enable… It gives you one platform where, in a single place, the first in the world that we’ve seen, that you’ve got the keypad and the door in a single platform now.
So what that ultimately means, let me be fundamentally clear about it. I think that businesses have a governance crisis at this particular point in time. All the companies that we sp- speak to have this governance crisis. The first thing is it’s a combination of three things that we see, and it’s usually it’s a, it’s multiple of these three things.
But the first is they might not even have an enforcement layer. So let me make this point to you, Brian. As a very, very seasoned and experienced IT executive yourself- If you were to go back 10 years and somebody said to you, “Hey, Brian, I want to access one of your backend services directly. I don’t really wanna have to go through a gateway.
I don’t really wanna have to go through any intermediary layer,” I would hazard a guess that your reaction would be to jump out of your skin and say, “Absolutely not.” Now, in the modern world, people are doing effectively that with their agents, so they are not having that intermediary le- intermediary layer.
And that to me is a, is something that’s a massive, massive mistake. You need to have that layer in place because that’s where you add the governance. That’s where you add the controls. That’s where you add things like the cost controls, for example, if you want people not to use so many tokens, if you want to be able to route between different models, if you want to be able to control which particular MCP service a particular agent should be able to use, and governing that using things like fine-grained authorization.
So that’s the first problem. The second problem is the, is the who. So as I said, in the past, you used to have these keypads, the equivalent, a digital keypad next to your door, and that would be a Ping or an Okta or something like that. And that was fine when you had coarse-grained coarse-grained and human-based identities.
But when you’re working with agents that are acting on behalf of humans that should have a subset of their capabilities and a subset of their permissions, where do you, where do you store that? Where do you– Because it shouldn’t be subsumed into the end application, and that’s one of the challenges that people have had in the past, and they’re starting to ex- really have much bigger issues now when you go into the agentic world.
And the third part is that those two things, even if you can address those two things, what agents and AI needs more than anything a lot of the time is context. It needs information to be… Like, information is almost like the air of a fire. Like, it needs this fuel to be able to get going. And my belief is that those three things, when you look at Gravitee and the Gamma platform, what we bring in a single place is a, is a way to be able to address all of these sorts of things.
So with capabilities that we’ve introduced, like our new Daylight product, where you can force at the daemon level traffic through the gateway, so that rather than people saying, “Oh, I’m just gonna go around the gateway,” or an agent going around the gateway, it goes through the gateway, and therefore you have your AI controls, your MCP controls.
You have all your enforcement layer. And on top of that, because it’s in the gateway, you can then use things like fine-grained authorization and very, very fine-grained controls to, to manage the permissioning and the scopes and all those sorts of things of your agents, both for your agentic and your human identities, for APIs, for event streams, and for the agents themselves.
And the last thing is, within Gravitee, you now have the ability to connect to third-party repositories, whether it be vector databases and all these sorts of things, or whether it be actually storing it yourself in Gravitee. So you can address all those three core things. That, I do believe, is the fundamental answer to the governance crisis people face today.
Brian Thomas: Thank you. Lot to unpack there, but I appreciate it. I loved your your metaphor, your, your API metaphor, the door and the key card, right? And the keypad. You talked about the complexity around it, security agents now working on behalf of humans. But your platform Gamma is really integrating that keypad and door together into a single platform.
Right. And you talked about governance and security. May not have an appropriate security layer. You talked through that, validating who has access, and then that context that it needs in order to seamlessly make this secure. So I appreciate that. And the last question of the day, Rory, you’ve predicted that before long, the same LLMs running in enterprise software will be running the machines on factory floors and in warehouses, with robotics not far behind.
As you look five years out, maybe less, what does a fully governed agentic enterprise actually look like, and what has to be true technically, organizationally, and in terms of standards for organizations to scale AI agents with confidence rather than caution?
Rory Blundell: That’s a great question. It, it’s a complex one, and what I fundamentally think the answer to this is that this is something I’ve been grappling with.
I’ve spent a lot of time recently unpacking a lot of the legislation that people are– that legislatures both in the Europe- in the European Union, but also in the US, different states are introducing AI legislation. So I’ve been looking a lot at this, and fundamentally what I’ve concluded is that in order for people to have the confidence to be able to utilize and leverage AI to the right– to the, to, to its fullest, fullest extent and to make the greatest economic gains that it could be, I do think you have to solve that governance crisis that I spoke about in the last, in the last point.
But there’s one additional point that I didn’t necessarily talk about that I do think you need to be able to address, that I don’t think I’ve seen a good implementation of yet, which is this concept, a term that’s probably bandied around that I’m sure you’ve heard it a number of times, Brian, which is human in the loop.
It’s a very interesting concept, and when you look at the technical implementations at the moment, my view is what you really need is you need to, first of all, implement all of your AI ecosystem, and your AI infrastructure must go through a central point of governance and control. I think that is the starting point.
I really strongly believe it must go through a central governance control point because unless you have that, you will have no mechanism to be able to control what happens. Now, if you were to ask the average person on the street and say, “Okay, that’s my starting point.” What people are– and you look at a lot of the legislation, and you– when you sp– I’ve spoken to people and interviewed them about this.
I think what people want is a mechanism and a way for agents and humans to work in harmony. If you look at a lot of the reporting about this subject at the moment, what you find is it’s almost a zero-sum game. When one loses, the other one wins, and all that sort of stuff. And in actual fact, what you need in order to– what I think people want, which is this type of human in the loop type of interaction You need to have that central point of governance control first.
Once you’ve got that, what we’ve introduced, for example, with Gamma, is you can now bring your own model. So in the gateway, what we’re now doing is classifying the stuff that comes through the gateway such that you can say, well, at this particular point in time, now you need a human to go and take the action, and you can then have a very temporary entry into the fine-grained authorization rule set or policy structure that basically says the next action that’s taken must come from the human in the loop.
Now, the reason why this is important is it’s very easy for organizations to generally have a set of yes/no rules, permit/deny rules for a, a finite set of very risky things. But what happens when it’s not about a very, very risky thing, when you want a human to be able to guide an overall process to say, well, this is the sort of thing I want the agent to be doing.
No, it really needs to get my approval for this, da, da, da, da. You can’t really do it, and this is where I think that having the central point of governance control where you can do things like bringing your own model, you can then make classification decisions about should you do human in the loop, should you not?
Do you have a portal to enable humans to be able to interact with it? Things of that nature. That, from my perspective, is what is critically important, to be able to enable humans and agents to work in harmony, and that is what I spend so much time thinking about.
Brian Thomas: That’s awesome. Thank you. And I’ll just highlight a few things here. I definitely agree with you. There’s a lot of AI legislation that is really starting to be at the forefront of every conversation now seen at local and national level of governments as everybody wants to solve this governance issue, right? I want to just highlight that human in the loop you talked about.
At the core of this, you talked about this AI development, the AI infrastructure must go through a centralized governance control, and at the end of the day, people want a framework that allows agents and humans to work in harmony. I thought that was pretty interesting for sure, and, and I see it in my everyday work life as well.
So thank you. Rory, it was such a pleasure having you on today, and I look forward to speaking with you real soon.
Rory Blundell: Thank you, Brian. It was a pleasure speaking with you. Have a lovely day.
Brian Thomas: Bye for now.
Rory Blundell Podcast Transcript. Listen to the audio on the guest’s Podcast Page.











