Geordie CTO Benji Weber: At Tens of Thousands of AI Agents, Visibility Breaks

Geordie CTO Benji Weber: At Tens of Thousands of AI Agents, Visibility Breaks

BackerLeader 43 231 390
calendar_today agoschedule3 min read

Ask Geordie co-founder and CTO Benji Weber what breaks when a company goes from a handful of AI agents to tens of thousands, and the answer isn't really about the agents. It's about the org chart. At that scale, Weber said, most companies lose track of who's actually inside their organization, let alone what every agent those people spun up is doing. Client AlphaSense reportedly runs tens of thousands of agents through Geordie's platform; biotech company Owkin, another customer, runs hundreds of agents across more than 50 petabytes of data. The failure mode at that scale isn't a dramatic breach. It's simpler: with dozens of agents, a security team can hand-configure policy for each one. At hundreds of thousands, that approach collapses, and teams need a way to group and govern agents automatically instead.

Weber came to Geordie from Snyk, the developer-first security company, and co-founded Geordie alongside colleagues from Darktrace. That mix shows up in how the platform is built: shift-left thinking borrowed from Snyk's developer-security roots, combined with an emphasis on operational visibility and control that Weber traces partly to resilience engineering, a field focused on designing systems to stay safe under failure rather than trying to prevent every individual thing that could go wrong. "The best place to prevent misuse is to set up the agent so misuse isn't possible in the first place," Weber said, describing Geordie's approach as identifying the most likely worst-case scenario for a given agent and closing it off before deployment, rather than chasing incidents after the fact.

That philosophy extends to discovery. A lot of what Geordie finds isn't malicious activity, Weber said. It's agents nobody on the security team knew existed: tools employees downloaded and installed on their own laptops, or prototype agents committed to source control without anyone flagging them. Geordie initially tried building on top of existing EDR and CSPM tools to get that visibility, and abandoned the approach. Those tools, Weber said, simply don't capture the data needed to assess an agent's exposure or operational risk, so Geordie built its own mechanisms to pull that data directly.

On detection, Weber described a mix of straightforward signature-based checks, like flagging a known npm supply chain compromise, and longer-term behavioral profiling that establishes what's normal for a given agent over time and flags deviations, including tool poisoning attacks aimed at hijacking an agent's behavior. Some of that detection runs on AI today, though Weber described the company's current use of it as targeted rather than universal, calling the technology still early and improving.

Asked what a security engineer standing up their first agent fleet should get right on day one, Weber pointed to something closer to identity governance than technical architecture: accountability and lifecycle. Someone needs to own each agent, and someone needs to decide in advance when it gets shut down rather than left running indefinitely. It's the same discipline security teams have long applied to service accounts and stale credentials, Weber said, just rarely applied yet to the agent someone spun up testing a Copilot Studio demo.

The $30 million Series A has already made itself felt, though not in a headline-grabbing way. Weber said the funding has gone primarily toward building out Geordie's engineering team, giving the company more capacity to keep pace with a threat surface that's expanding faster than most security teams can track on their own.

Weber expects the shift to keep accelerating. Geordie is just over a year old, and in his view, the next six to twelve months will push agents past what he calls the human-orientation phase, the period when a person still directly initiates most agent activity, toward a norm where agents increasingly spin up other agents on their own. For developers and architects building agent fleets now, Weber's pitch is straightforward: the same governance and control layer Geordie applies to a developer's coding agent can extend to whatever agents get built into the product itself, giving engineering teams room to move fast because the guardrails are already defined rather than improvised after something goes wrong.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

Defending Against AI Worms: Securing Multi-Agent Systems from Self-Replicating Prompts

alessandro_pignati - Apr 2

️ Agent Action Guard: Framework for Safer AI Agents

praneeth - Apr 1

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

From Prompts to Goals: The Rise of Outcome-Driven Development

Tom Smithverified - Apr 11
chevron_left
15.8k Points664 Badges
197Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

8 comments
2 comments
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!