SPEAKER_01
Hello, hello. Have you ever given a task to Cloud Code? And you give it a feature and you be like, okay, cool. Can you build this for me? And Cloud Code starts putting it out into sub-tasks and you see it, okay, this is pretty cool. You see it running multiple sub-agents. All right, this is really cool. And you can see it ripping through all of your tasks, sub-agents being completed, and it gives you a final output, task completed. Amazing, great. But when you actually try to run it, it should be like, oh, well, it's not. Something has failed. Hey, Cloud, can you fix this little bit thing? Oh, well, let's try it again. Okay, it's fixed. Everything should be working. Oh, no. Actually, just this tiny little thing is just missing. And that's what my talk is about.
SPEAKER_01
All I want to do is play Cyberpunk on my Xbox while I have Cloud Code do some work for me. And what I realized was the problem is that I kept on telling Cloud, hey, fix this, fix that, fix this, fix that, even though if I give it a spec, if I give it some instructions, if I give it little to no instructions, every time there is something that I need to tell it. So what that means is I am the enforcement. I am the enforcement there. I have to tell Cloud on what exactly you need to do and how exactly this needs to be enforced. So the agent says it's done, but you have to check it anyway because there is nothing else that can check it for you.
SPEAKER_01
So what I wanted was something to be very deterministic. So when an agent says it's completed, have this enforcement layer deterministically check something like whether it's actually been done or not. Actually, the way I wanted it to be done because it says it is done, but is it the way that I want it? So I needed some deterministic way to do that.
SPEAKER_01
So I tried it. I built my own vector. I call it my own product called Vector V1, and it deterministically checks Cloud's output. And the way I did that is through using Cloud hooks. So that way, whenever Cloud finishes its session, it automatically, the hook calls my vector product or program, and it checks it for me. Cool. And this is how it essentially looks. So I basically give it a config file, define all of my tests over here, what I needed to be checked. And if it fails, it can actually keep on telling Cloud, hey, look, this is failing. Try again. Try again. Try again.
SPEAKER_01
So you can see one of the test outputs over here. So it's like, okay, first the test passed, first failed. Then it retries again. Then all of the things passed. Okay, cool. So what that means is it's not about whether Cloud can actually do the task. It's about trust. Can I trust Cloud to actually do everything for me? And by the way, when I say Cloud, I'm just talking in general about LLM agents in general. When I give a task to a coding agent, does it actually complete it?
SPEAKER_01
So, and that's something that I started doing was started telling this about two people and going to different events. And it was really cool. Hey, look, what about this verification feature that I built? It was so good. It was so amazing. And then I met one of the Anthropic engineers. And they just told me that we're not going to need this anymore. We'll have another agent or another model that will be so smart that you won't need enforcement. Okay? So, crisis mode. Did I just waste my time? What was the point of all of this stuff?
SPEAKER_01
But let's dig in a little bit deeper. And then, also, they released this project Glasswing that shows Project Mythos, which is supposed to be so good that it will solve everything for us. So, when I started thinking about it, okay, what is it that is actually happening? When a new model comes out, it increases in capability. But that's not necessarily the same thing as reliability. Sure, the models may become a lot more capable. But are they more reliable?
SPEAKER_01
The other thing is another argument is, oh, well, I can have the best spec. I can have the best MCP servers. I can have the best subagents. I can get all the right context to it. Amazing. We should do that. But giving good instructions is not the same thing as giving it verification. So you can give as much instructions as you want. Very good instructions, very little instructions. But you still will need to verify.
SPEAKER_01
And what I realized was that just having these small guardrails or having as many guardrails as you want, technically, you can use a smaller model, like a Haiku or even an open source model. Because it's got these guardrails on, it'll most likely be succinct and get you to the output that you want. So, in theory, what it means is that if you use a frontier model, like an Opus model, that can get you a task. Okay, cool. That will be the most expensive one. You can have Vector with a little bit of guardrails, but it gives you a little bit cheaper. But if you put on more guardrails, that means invest a little bit more time in the harness itself, so you can reduce the cost drastically. Or maybe even use async tasks as well.
SPEAKER_01
So, okay. I was feeling good. And I started talking about Vector again at two different events. And as I spoke to more and more people, there is something missing here. When I spoke to more people, what I realized was everybody's building their own stuff. Anthropic is building their own stuff. My company is building their own stuff about enforcement. Facebook is building their own stuff. Every company is building their own thing. So, if I built something that is specific to me, then I can't really share it with others because everybody has their own way of doing it. And what I enforce doesn't necessarily mean that somebody else would enforce the same thing.
SPEAKER_01
So, what that meant was, what I realized was, okay, so it's actually a pattern. So, it has to be a pattern that is applicable to everyone. So, what that means is that we can, it has to be language agnostic. It has to be something that can be shared by everybody else. And everybody can bring their own version of enforcement to it. And that's, and it should run on every level. So, it should start off with in conversation. When a conversation ends, you can have checks when, before committing. You can have checks when you're part of a multi-agent workflow. You can have checks on asynchronous operations or asynchronous agents. And as well as you can have a check that non-deterministically calls like LLM as a judge sort of thing. And it can run on any different language on any different code. As long as there's a capability to run it deterministically, we can have that.
SPEAKER_01
So, what I realized was, what we needed was essentially a contract that just says, hey, given this task, I want you to fulfill this. What is in the middle that you can, the developers themselves can define? So, this idea is really cool. And it was like, okay, so we are moving towards, we want verification always. All right, cool. So, a lot of different companies have actually started doing this as well. So, Cloud, Anthropic has recently released their new thing called Executor Advisor Pattern, where you've got one agent that actually does all the code work. And then there's an advisor that feeds in, essentially creates a feedback loop. Or in other words, verify.
SPEAKER_01
Anthropic, sorry. OpenAI built their own harness engineering. And it's the same idea. You give an agent a lot of things to do, but how do you verify it to work? You give it different tools. You give it different context. And that's essentially what a harness is for OpenAI. There are companies like Kudo that provide a very comprehensive code reviews. And again, it's the same thing. The agent has done all of its work, but do you trust it? No. So, what do we do? You do a very comprehensive PR review with all the different issues and findings and create this feedback loop.
SPEAKER_01
Something from today as well from WorkOS. So, it says enforce, don't instruct. So, it is all about running these checks deterministically. When I say checks, it's just about the verification. Another one, which is my favorite, is you still have to go slow. And the reason for that is not because the agents themselves are not able to produce code as fast as they want, but it's because the verification layer. You need to verify that everything is working or not.
SPEAKER_01
And my favorite is this one in our keynote. It's to slow the hell down. So, what is the shift that we're seeing here? Initially, what we thought was the value is in the code that we create. But it's actually now, in reality, what we're seeing here is the verification that we design. So, it's not about, can you code, but can you verify? So, TLDR is work on the harness and not on the code. So, you work on the verification system, and that produces a little bit better outputs. And that's it. Thank you. Any questions? I've got 40 seconds. Yes? Yes, it is public. Yes?
SPEAKER_01
But if you send me a message on LinkedIn, I can share that with you. Oh, there you go. Cool. Yeah. You mentioned that adding the verification layer allows you to use a smaller model. What do you say to the allegation that you're a top focus that they're coming to? I need those tokens to build a verification layer. Cool. I think that's it. or program, and it checks it for me. Cool. And this is how it essentially looks. So I basically give it a config file, define all of my tests over here, like what I needed to be checked. And if it fails, it can actually keep on telling Cloud, like, hey, look, this is failing. Try again. Try again. Try again. Sorry if it's a little bit...
SPEAKER_01
So you can see one of the test outputs over here. So it's like, okay, first the test passed, first failed. Then it retries again. Then all of the things passed. Okay, cool. So what that means is it's not about whether Cloud can actually do the task. It's about trust. Can I trust Cloud to actually do everything for me? And by the way, when I say Cloud, I'm just talking in general about LLM agents in general, is when I give a task to a coding agent, does it actually complete it?
SPEAKER_01
So, yeah. So, and that's something that... And what I started doing was started telling this about two people about and going to different events. And it was really cool. Like, hey, look, what about this verification feature that I built? It was so good. It was so amazing. And then I met one of the anthropic engineers. And they just told me that we're not going to need this anymore. Like, we'll have, like, another agent or another model that will be so smart that you won't need enforcement. Okay?
SPEAKER_01
So, crisis mode. Did I just waste my time? What did I just... Like, what was the point of all of this stuff? But let's dig in a little bit deeper. And then, also, they released this project Glasswing that shows Project Mythos, which is supposed to be so good that it will solve everything for us. So, when I started thinking about it, like, okay, what is it that is actually happening? When a new model comes out, it increases in capability. But that's not necessarily the same thing as reliability. Sure, the models may become a lot more capable. But are they more reliable? The other thing is, like, another argument is, like, oh, well, I can have the best spec.
SPEAKER_01
I can have the best MCP servers. I can have the best subagents. I can get all the right context to it. Amazing. We should do that. But giving thought instructions is not the same thing as giving it verification. So, you can give as much instructions as you want. Very good instructions, very little instructions. But you still will need to verify. And what I realized was that just... What I realized was that having these small guardrails or having as many guardrails as you want, technically, you can use a smaller model, like a Haiku or even, like, an open source models.
SPEAKER_01
Because it's got these guardrails on, it'll most likely be succinct and get you to the output that you want. So, in theory, what it means is that if you use a frontier model, like an Opus model, that can get you a task. Okay, cool. That will be the most expensive one. You can have Vector with a little bit of guardrails, but it gives you a little bit cheaper. But if you put on more guardrails, that means invest a little bit more time in the harness itself, like, you can reduce the cost drastically. Or maybe even use, like, async tasks as well. So, okay. I was feeling good. And I started talking about Vector again at two different events.
SPEAKER_01
And as I spoke to more and more people, there is something missing here. When I spoke to more people, what I realized was everybody's building their own stuff. Anthropic is building their own stuff. My company is building their own stuff about enforcement. Facebook is building their own stuff. Every company is building their own thing. So, if I built something that is specific to me, then I can't really share it with others because everybody has their own way of doing it. And what I enforce doesn't necessarily mean that somebody else would enforce the same thing. So, what that meant was, what I realized was, okay, so it's actually a pattern.
SPEAKER_01
So, it has to be a pattern that is applicable to everyone. So, what that means is that we can, it has to be language agnostic. It has to be something that can be shared by everybody else. And everybody can bring their own version of enforcement to it. And that's, and it should run on every level. So, it should start off with in conversation. When a conversation ends, you can have checks when, before committing. You can have checks when you're part of a multi-agent workflow. You can have it on checks on asynchronous operations or asynchronous agents. And as well as you can have a check that non-deterministically calls like LLM and LLM as a judge sort of a thing.
SPEAKER_01
And it can run on any, any different language on any different code. As long as there's a capability to run it deterministically, we can have that. So, what, what I realized was, what we needed was essentially a contract that just says like, hey, given this task, I want you to fulfill this. What is in the middle that you can, the developers themselves can define? So, this idea is really cool. And it was like, okay, so we are moving towards, we want verification always. All right, cool. So, a lot of different companies have actually started doing this as well. So, Cloud, Anthropic has recently released their new thing called Executed Advisor Pattern,
SPEAKER_01
where you've got one agent that actually does all the code, all the code work. And then there's an advisor that, you know, feeds in, essentially creates a feedback loop. Or in other words, verify. Anthropic, sorry. OpenAI build their own harness engineering. And it's the same idea. Like, you give an agent a lot of things to do, but how do you verify it to work? You give it different tools. You give it different context. And that's essentially what a harness is for OpenAI. There are companies like Kudo who are over here that provide a very comprehensive code reviews. And again, it's the same thing. The agent has done all of its work, but do you trust it? No.
SPEAKER_01
So, what do we do? You do a very comprehensive PR review with all the different issues and findings and create this feedback loop. Something from today as well from WorkOS. So, it says enforce, don't instruct. So, it is all about, like, running these checks deterministically. When I say checks, it's just about the verification. Another one, which is my favorite, is one of the favorites, like, you still have to go slow. And the reason for that is not because the agent themselves are not able to produce code as fast as they want, but it's because the verification layer. You need to verify that everything is working or not. And my favorite is this one in our keynote.
SPEAKER_01
It's to slow the hell down. So, what is the shift that we're seeing here? Initially, what we thought was, like, the value is in the code that we create. But it's actually now, in reality, is what we're seeing here is the verification that we design. So, it's not about, can you code, but can you verify?
SPEAKER_01
So, TLDR is work on the harness and not on the code. So, you work on the verification system, and that produces a little bit better in outputs. And that's it. Thank you.
SPEAKER_01
Any questions? I've got 40 seconds.
SPEAKER_01
Yes? Yes, it is public. Yes? Yes? Yes? Yes? Yes? Yes? Yes? But if you send me a message on LinkedIn, I can share that with you.
Oh, there you go.
Cool.
Yeah. You mentioned that adding the verification layer allows you to be a smaller model. What do you say to the allegations that you're a top focus that they're coming to? I need those tokens to build a verification layer.
Cool. I think that's it.