...
Itential Platform Pricing Explore flexible plans and options for your team
Itential logo
Video

Stop Shadow AI Before It Owns Your Network

AI agents are getting smarter fast, but intelligence alone doesn’t earn access to live network infrastructure. John Capobianco joined TFiR to cover how Itential helps enterprises bring agents into network operations with governance, controlled tool access, and auditability built in from the start.

Speakers:

Headshot of Swapnil Bhartiya, host at TFiR

Swapnil Bhartiya

Host & CEO, TFiR

John Capobianco

Head of AI & DevRel, Itential

A Governed Path From AI Experimentation to Network Operations

AI agents can already gather infrastructure context, interpret tickets, reconcile sources of truth, test the network, and help operators understand what is happening. The challenge for enterprise network teams is connecting that reasoning to real systems while maintaining control over what an agent can access and what actions it can take.

John Capobianco joined Swapnil Bhartiya on TFiR to break down why onboarding an agents is the same as onboarding a new member of the network team. You wouldn’t give someone full change access on day one. You start with lower-risk work like documentation, testing, compliance reporting, ticket triage, and information gathering. In one customer study discussed, 64% of network operator activity was read-only, creating a substantial opportunity to introduce agents and prove their value before expanding their authority.

As autonomy increases, the surrounding architecture matters even more. John walks through the approach behind Itential FlowAI, where the tools available to an agent are explicitly scoped at build time, access is governed through role-based controls, MCP connections are centralized, and reasoning steps and tool calls are captured in an audit trail.

That same model can help enterprises address shadow AI. Instead of agents, API keys, models, and infrastructure tools spreading independently across teams, organizations can create a shared environment in Itential Gateway for controlling what agents are built, which tools they can use, which models they run on, and how their activity is reviewed.

  • 💡 Governance has to grow with agent autonomy.
    As agents move from gathering information to taking action on real infrastructure, enterprises need a clear path for increasing access without increasing the blast radius. That means tighter control over tools, permissions, approvals, and what happens at runtime.

What You’ll Learn

  • Why Trust Is the Gating Factor for AI in Network Operations
    AI capability is moving quickly, but access to production infrastructure raises a different set of questions around permissions, oversight, auditability, and operational risk.
  • Why Read-Only Work Is a Practical Starting Point for Agents
    See how teams can use agents for troubleshooting, documentation, compliance, ticket triage, and source-of-truth reconciliation before introducing higher-risk write operations.
  • How Build-Time Governance Constrains Agent Behavior
    Learn why defining an agent’s approved tools and authority before execution helps limit its operational scope and gives teams more control over how reasoning connects to infrastructure.
  • How Enterprises Can Keep Shadow AI From Becoming Agent Sprawl
    John explains how centralized tool access, source and version control, RBAC, MCP governance, and model flexibility can keep individual experiments from turning into another generation of unmanaged automation.
  • Where Network Teams Are Putting Agents to Work Today
    Explore practical use cases already resonating with enterprises, including ServiceNow ticket triage, root-cause research, network testing, source-of-truth reconciliation, and port turn-up and turn-down operations.
+

Swapnil Bhartiya • 00:00

As we all know, AI agents are moving very fast. But when it comes to enterprise infrastructure, speed means nothing without trust. The real blocker is not building a smart agent. It is giving them safe access to real systems without losing control. And when it comes to agents and controls, these things are like oil and water. They’re hard to mix. That is exactly what FlowAI is built to solve.

Swapnil Bhartiya • 00:30

And today we have with us John Capobianco, head of AI and developer relations at Itential to unpack How enterprises can bring AI agents into network operations with governance built in from a start so you don’t lose their capabilities or their trust and get full advantage of AI. John, it’s good to have you on the show.

John Capobianco • 00:53

So, Swapnil, thank you so much for the introduction. And you’re right, we are entering a very exciting time. I would argue a time of opportunity and a time, I think, a Cambrian period. I think that I don’t want to get too technical too quick, but things like the Model Context Protocol is maturing on two years. OpenClaw is maturing onto almost a year. Things have moved very fast in the Agentic space and from individual contributors all the way to large enterprises. So, I want to thank you for having me here today.

John Capobianco • 01:27

And I think it’s an important discussion. And, you know, I like to think of agents almost as a brand new member of your team. Now, my team was network operations, and architects, and designers, and security people, and everyone who would make up the team that would manage a network infrastructure. Imagine a new member of the team comes along. My very 1st task is not going to be a right activity of complexity on some critical piece of infrastructure. I think the same roadmap can be followed with these agents in that they can be given read-only access. They can be given day one, day two tasks as if they were a junior or a new member of the team.

John Capobianco • 02:10

You know what, let’s document the network. Let’s test the network. Let’s do some compliance reporting. Let’s make sure that our, you know, if we have a source of truth offline, that it’s accurate and up to date and reflects the reality of the network. Let’s maybe intercept tickets and try to triage them and add some summary, some analysis without making changes. So the agents have to earn our trust, much like a new member of the team kind of earns the trust. Over time, we can introduce those change-right activities where the agent takes on more risk and takes on more autonomy.

John Capobianco • 02:47

You know, a study was done recently by one of our customers, and they found that 64% of their operators are doing read-only activities. 64% of a network engineer’s job, more or less, is doing read-only information gathering. They’re trying to troubleshoot a problem. They’re trying to plan for a change. They’re simply gathering information out of the infrastructure. So why not hand that task off to an agent that you’re in control of and let the agent take care of? 60% of your job, you know, and actually summarize that data and give you root cause analysis.

John Capobianco • 03:27

I think we can take huge leaps forward, Swapnil.

Swapnil Bhartiya • 03:30

Can you quickly tell our audience a bit about Initial?

John Capobianco • 03:34

Itential is the Agentec platform for enterprise operations. We make it easy to build and execute agents as well as deterministic workflows such as Ansible playbooks or Python scripts or Terraform jobs.

Swapnil Bhartiya • 03:46

What exactly is FlowAI and how does it help enterprises move from deterministic workflows to AI agents in network operations?

John Capobianco • 03:55

Our FlowAI platform has two different interfaces. You can interface through a skill from Anthropic and do this through spec-driven development, where you describe in natural language the agent you’d like to build and the outcomes you want to achieve. And there’s a traditional GUI builder system that lets you input the persona of your agent, the outcomes of the agent. And what’s neat is at build time, we get to select the tools. So it’s very safe, it’s very full of guardrails, there’s role-based access control, there’s OAuth 2 through our MCPs. So we’re really excited about the FlowAI platform.

Swapnil Bhartiya • 04:29

When we look at network operations, what roles do AI agents play or what kind of problems they create? So, talk a bit about AI workflows, the challenges, and the opportunities they create in network operations.

John Capobianco • 04:43

So, the challenge is like introducing a new human onto your team, right? We have to make sure that they’re following standards and methods of procedures and that they’re following, you know, specifically change requirements. And I see agents very similar, where you’re going to incorporate them through read-only, safe, human-in-the-loop activities. You know, almost 65% of what a network engineer does is read-only activities. So, we see a nice safe onboarding experience for our customers to start incorporating agents immediately with huge value, but very, very low risk. Over time, we start to increase the risk and start maybe introducing write operations. But some of the challenges are that organizations need to have their own AI governance board and own AI strategy, approved LLMs, data governance, quality of data.

John Capobianco • 05:33

There’s a lot of things that go into making a quality agent that are outside of our control. But we work with our customers to make sure they’re binding the right tools, their binding determinism, and have a really clean pathway to success.

Swapnil Bhartiya • 05:45

How is network operation different? when it comes to AI and network especially, what is the real bottleneck? Is it AI’s capability? Is it cost and token consumption? Or is it more about trust? And how does FlowAI address the safety and security concerns that keep agents stuck in sandboxes And chatbox because they cannot be trusted enough to actually take actions.

John Capobianco • 06:13

I think it does boil down to trust. It really does come down to trust. So we feel that we have a track record and we can earn that trust through, again, a roadmap through read-only activities, human in the loop, human on the loop, and then ultimately human in the lead. We want humans to lead these agents. And we have things like role-based access control, things like AAA and audit and audit trails. So we can show you when and what the LLM reasoned, as well as the tool and the tool payload that it called. You’re in full control as a customer over the model you use and the provider you use.

John Capobianco • 06:50

And it’s also governed through things like OAuth 2, if you’re talking about our model context protocol server, with bearer tokens and fine-grained access control. I know none of this sounds very sexy to the operator, but it sounds appealing to the leader of the enterprise. These are the things people care about. They’re not going to just turn any agent loose that someone has made from an open source project on their network. Network is critical. Network touches everything. Maybe that’s why it’s a little, I don’t want to say slower, but more, it’s a little more hesitant, a little more prudent.

John Capobianco • 07:25

Networks take a little while to adopt. We’ve seen the lack of adoption of basic network automation for the last 10 years. But I think this is different. I don’t think enterprises are going to wait 10 years to adopt AI for network infrastructure. The only advice I can give network operators and network leaders is talk to your peers in the software department that you work in. They have gone through this. They have gone through the pain of getting approved models and getting approved tools and getting access to these tools in a safe, confined way.

John Capobianco • 07:58

So bridge that gap. It’s just like the network automation story. You talk to the developers about Python and how to learn Python and apply it to networks. Now we’re doing the same thing, except ask those developers. The pitfalls, the gotchas, what they’ve learned, how to use models, how to distribute tokens and access to AI. So I think that there’s parallels here that we can learn from.

Swapnil Bhartiya • 08:23

Can you talk about the architectural difference between build-only platform and initials approach of building the reasoning layer and execution layer together under the same governance model?

John Capobianco • 08:36

So it actually lets us centralize and allows for a lot of reuse and a lot of multi-tiered projects. Meaning, you can bring, let’s say, the PyATS MCP server onto the gateway. And now that server is able to host tools that are spawned asynchronously in separate sessions from various agents. So imagine that, right? Or let’s just take, e.g. , the Netbox MCP server for a source of truth, or Nautobot, or OpsMill, they all have MCP servers now. You could bring those tools onto our platform and attach them deterministically to agents at build time and say, listen, I want to use PyATS to get the state of my network, maybe IP addresses or interfaces, and I want to put them into my source of truth. That could be an agent.

John Capobianco • 09:27

You and I could have built that and run it and have results in Netbox before the end of this conversation.

Swapnil Bhartiya • 09:34

We are living in a phase where there are many geopolitical crises, regulations, governance, and of course, the whole FUD around AI. At the same time, there are movements towards sovereign AI. Now, as I said, the network is at the very center of all this movement. What role does FlowAI play in better governance for regulated industries, compliance-heavy industries?

John Capobianco • 09:59

Well, I think it plays a big space in, you know, let’s say combating shadow AI, where AI is sort of distributed and people are using their own tokens and their own keys or different models that haven’t been approved. We provide that platform and that ease of platform. So people have a nice GUI experience they can log into. They can use ChatGPT or Claude Code, excuse me, to chat with our platform through our MCP server or other mechanisms like our skill. It plays a critical role because we don’t want just rogue agents. Imagine the sprawl of automation scripts for the past 10 years, distributed scripts, my script, your script, last versions of script, no version control, no source control. So think of our platform as that sort of GitHub for your agents.

John Capobianco • 10:47

There’s version control, there’s source control. The other thing is, is that The model itself, we have a bring your own model approach and bring your own provider approach. So, for those air-gapped environments, for those environments that maybe are a little bit concerned about the political overreach and models being maybe withdrawn or accessed to certain models, or they don’t maybe trust the cloud hyperscalers to handle their network information, you can bring your own OLAMA server, LM Studio server, Microsoft local server, Foundry server, and host your own local model in your own data center on your premises. And our agents are more than happy to make the API calls and use those models. So, right, we want to be Switzerland here and let people bring their own tools, bring their own models, bring their own providers. So that way they can start building agents and start seeing the benefits of artificial intelligence in production.

Swapnil Bhartiya • 11:49

Let’s go back to FlowAI and its three core pieces: FlowAgent. Flow agent builder and flow MCP gateway. Can you talk about how they work together for infrastructure teams that are managing role-based agents?

John Capobianco • 12:05

Right. So the builder is going to be the seamless building process that anyone can follow. Anyone can dump their domain-specific knowledge into this builder experience, either through the skill and cloud code or through our GUI. The gateway for MCP is going to allow you to bring your own MCP server. And MCP servers aren’t necessarily just public-facing. A lot of enterprises internally starting to make a lot of MCP servers available. So imagine bringing your in-house tools into a platform that then can be bound to the agent.

John Capobianco • 12:38

And then we have that execution runtime environment where everything is secure and extremely limited access where the actual agents are executing. In terms of audit and compliance, like I said, there is an audit trail that shows you every Decision or reasoning step that the agent may have made, as well as the tools that they called. It has the token count and the execution runtime in terms of how long it took to run. So, in terms of compliance over time, right, these agents are being you can audit these agents, you can hand over exactly what happened. Maybe if there was, you know, if you wanted to see how it solved the problem, how it came to the conclusion of a certain problem needed to be resolved, all of that information is available to the operators.

Swapnil Bhartiya • 13:25

If I’m not wrong, you folks maintain the position that governance has to be built in at build time, not later at runtime. What does that mean in practice? And where do humans in loop checkpoints fit in?

John Capobianco • 13:42

So, what we mean by that is sometimes, so MC, the LLM is going to reason and try to pick the best tool. But if it has access to too many tools or the wrong tools, there’s more of an opportunity for it to I don’t want to say hallucinate, but for it to pick the wrong tool or or be confused about the the selection of tools. Or use a tool that has nothing to do with its tasks, right? So at runtime, some solutions with agents just let the agent reason and decide what tools to use. We have a different philosophy over the governance of this and the guardrails: that at build time, when you build the agent, that is when you get to pick what exact tools from MCPs or existing workflows or emails or Slack or whatever you want for your communication stack. It’s all at build time. So when the agent executes, it will never call the wrong tool.

John Capobianco • 14:43

And if you want to be very careful and do just read-only activities, you provide it read-only tools. When you earn trust and want to add a write-capable tool, that’s when you can do so, right? So there’s a lot of governance in the actual building of the agents. We have a lot of faith that they will do what they’re supposed to do when they run, but we can limit the blast radius, we can limit the exposure to our networks if at build time we actually select the right tools.

Swapnil Bhartiya • 15:08

For those enterprise leaders who are looking at agentic operations right now. What advice do you have? What is the best place to start with how creating new operational risk and be ready for the future since things are moving so fast?

John Capobianco • 15:27

So, I would recommend that, you know, 1st establish an AI governance board, right? That’s the 1st thing I would recommend to leaders if you do not have one. The other thing is, I would strongly recommend you give your team access to local open source free models that are private and local and let them start experimenting in labs, experimenting with virtual labs. Stay away from production. There’s a long way to go. There’s a lot to learn. But through virtual labs and physical labs and access to private open source models, I would look for certain MCPs.

John Capobianco • 16:00

I would try to integrate them into your co-pilot or your cloud code, right? So it’s more about accepting some of the risk and looking at the right tools and seeing how they can be applied and learning the lessons from your colleagues in the software development department.

Swapnil Bhartiya • 16:17

As FlowAI reaches general availability, What kind of real-world use cases or deployment patterns are you seeing that resonate most with enterprise teams today?

John Capobianco • 16:28

Right, so I did mention a few of them. We have customers doing a lot of ticket triage, which seems to be very popular. So a ticket come in through ServiceNow and through the MCP, the agent can read the ticket, and then through other MCPs, it can gather information and come to a much like a triage, like an early assessment before it goes to a human operator. So now that human operator maybe is saving hours of work doing the research into what the problem’s root cause is, and the ticket just tells you, we believe this is the root cause of the issue, right? We could be wrong, but here’s our evidence, here’s what we think, here’s what the information we gathered. Other things like testing, documentation are very popular. Sources of truth reconciliation to make sure that your offline records match the reality of your network.

John Capobianco • 17:16

And then even things like port turnup. Some of our customers are very large and have a lot of interfaces that have to be turned up or turned down over 24 hours. That’s a perfect opportunity, a low-hanging fruit, low-risk opportunity for an agent to step in and handle those port turn-ups and turn downs.

Swapnil Bhartiya • 17:33

John, thank you so much for joining us and sharing these insights on what it takes to make AI agents operationally safe for real enterprise infrastructure. Thank you so much for tandre and I look forward to chatting with you again.

John Capobianco • 17:46

Thank you for having me. I really appreciate it.

Keep Learning

The Latest in Agentic Operations & Infrastructure

Ready to transform infrastructure with agentic AI?