Founding engineer, DevRev25+ years in systemsContext connected, authority constrainedSan Jose, California

The YesPress Profile / Engineering

Shlomi Vaknin Builds Powerful AI by Taking Away the Keys

After 25 years spent making complex systems work, DevRev founding engineer Shlomi Vaknin has arrived at an unfashionable rule for the AI age: the cleverest agent may be the one with the fewest permissions.

The official portrait is not an office portrait. Shlomi Vaknin stands outdoors at night, wrapped against the cold, beside a telescope almost as tall as he is. The picture is grainy, monochrome and considerably more revealing than a row of framed patents would have been. On his DevRev profile, the accompanying biography is only eight words long: “My story is that of endless curiosity.” The telescope supplies the footnote.

Curiosity is an appealing trait in an engineer, but an expensive one if nobody remembers to install guardrails. Vaknin has spent more than 25 years working where software stops being a thought experiment and begins touching state, infrastructure, permissions and people. His career has taken him from defense software to language technology, big data, cloud clusters and enterprise AI. The durable question underneath all that movement is less fashionable than the tools: what, precisely, is this system allowed to change?

At DevRev Labs, where he is a senior architect and an early founding engineer, that question has become his argument for the AI-agent era. Models may converse, infer and help. Sensitive authority should live elsewhere, behind a boundary the model cannot sweet-talk. The useful agent, in Vaknin’s telling, can understand a request without possessing the master key.

25+years across software and systems architecture
2021joined DevRev as an early founding engineer
94listed degree grade, completed cum laude

A career spent asking where the state lives

Vaknin began as a software developer in 2001 with the IDF’s J6 and Cyber Defense Directorate. Four years later he moved to Tadiran Electronic Systems, where he stayed until 2012. He then became a system architect, and later a senior system architect, at Ginger Software. By 2014 he was a big-data software architect at Intel. In 2018 he joined Nutanix’s CTO office, first as a member of technical staff and then as a staff engineer.

The résumé looks like a steady climb up the abstraction stack. The artifacts left along the way make it more human. His public GitHub gists include a shell script for installing Linux performance tools on EC2 machines, another for building the tools when the right package was unavailable, a Clojure character-set experiment, and a Blender setup for video editing. They are small, practical contraptions. Each begins with an itch and ends with working machinery.

He studied while much of that career was in motion. From 2006 to 2015, Vaknin completed a BSc at The Open University of Israel, graduating cum laude with a grade listed as 94. He also completed courses in massive datasets and functional programming in Scala. His LinkedIn profile lists Clojure at native or bilingual proficiency, a joke the platform may not know it is making. Programming languages rarely ask for passports.

At Nutanix, the work acquired the formal language of invention. Patents bearing his name cover the bringing-up of computing clusters on public-cloud infrastructure and the configuration of virtualization system images across heterogeneous environments. One design begins with an expressed intent, compares it with the system’s actual state, and dispatches operations until the two agree. It is cloud engineering, but it is also a philosophy: wishes are not state, and fluent declarations do not remove the need for verification.

The recurring technical idea

Desired state must survive contact with actual state.

Vaknin’s infrastructure patents turn high-level intent into constrained, observable operations across cloud environments. His later AI work applies a related discipline to agents.

The hippocampus in the machine

DevRev brought the problem higher up the stack. The scattered objects were no longer only machines and subnets; they were tickets, accounts, product parts, customer complaints, releases and revenue. Conventional enterprise software stores those objects in separate tools. An AI layer can search each cupboard, but it still has to guess how the contents relate.

Vaknin’s metaphor for the alternative is biological. A knowledge graph, he writes, can act as the hippocampus an enterprise AI is missing. It does not merely keep facts. It maps the relationships among them. A complaint can be connected to a product issue, the issue to an engineer, the customer to a renewal, and the renewal to its business value. The agent no longer assembles a plausible story from fragments. It works inside a connected model.

“My story is that of endless curiosity.”Shlomi Vaknin, DevRev profile

That focus is visible in DevRev patent filings that name Vaknin among their inventors. They deal with product-lifecycle information, links between support and work items, and hierarchical product parameters. The vocabulary has changed since the Nutanix years, yet the structure feels familiar. There is an intended model, a messy operating world, and a need to reconcile the two without losing the links that explain what happened.

DevRev event graphic featuring Dheeraj Pandey, Ahmed Bashir and Shlomi Vaknin
Three views of the same problem: Dheeraj Pandey, Ahmed Bashir and Shlomi Vaknin led a 2024 DevRev session in Palo Alto on AI, technology and the next shape of software. Vaknin was then billed as a solutions engineer.

In 2024, he joined DevRev chief executive Dheeraj Pandey and engineering leader Ahmed Bashir for a Palo Alto session with visiting European executives and investors. The theme was the future of AI and SaaS. The event graphic called Vaknin a solutions engineer. His current title, senior architect, is a better clue to the scale at which he now speaks: not one feature, but the conditions under which a whole class of features can be trusted.

Helpful above the line, powerful below it

Vaknin’s sharpest statement of that trust model arrived in 2026 in an essay titled “Powerless by design.” His subject was a dangerous pattern in AI support: a conversational agent given direct authority over identity systems. If the agent can both interpret a plea and rewrite a recovery address, language itself begins to function as authorization. A sufficiently convincing conversation can become a credential.

His answer is deliberately uneventful. Split the system. The conversational layer may work out what a user wants, collect context, explain applicable policy, create a work item and report its status. It holds no identity-provider credentials. Verification and authorization occur below that line in a deterministic workflow. Only after those checks pass does a service account perform the action.

The separation is more than a security flourish. It distinguishes authentication from authorization. Proving who a requester is does not prove that the requester may perform a given action. Vaknin’s design checks both, using policy that the model cannot edit. Verification travels through a channel separate from the chat. Uncertainty closes the gate. Completed actions create immutable records.

“There is no sentence that grants a permission the system was never given.”Shlomi Vaknin, “Powerless by design”

There is a useful modesty here. Much of the AI industry treats intelligence as an all-purpose solvent: make the model better and the hard edges will soften. Vaknin declines the wager. Model behavior is probabilistic even when it is very good. Architecture can supply a different kind of promise. If the model has no route to the sensitive system, clever phrasing cannot invent one.

This does not reduce the agent to decoration. It can still offer a better experience than a static form. It can explain why approval is needed, help a person choose the right path and keep the request legible. It simply cannot approve itself. Charm remains in the lobby; the keys stay downstairs.

The argument also completes the circle back to Vaknin’s work on memory. An enterprise agent needs rich context to be useful and narrow authority to be safe. Those qualities are complements. The knowledge graph lets the system understand which customer, product, entitlement and workflow are connected. The permission boundary determines which connections may become actions.

The engineer beside the telescope

Vaknin’s career has passed through organizations of very different kinds, from military communications and enterprise language software to chip-scale big data, cloud infrastructure and a venture-backed AI company. He has been a developer, a system architect, a CTO-office engineer, a solutions engineer and a founding builder. Titles changed more quickly than the underlying preoccupations.

The evidence is in the nouns that recur: state, intent, boundaries, permissions, integrations, context. They are not glamorous nouns, which may explain their usefulness. They describe the connective tissue that determines whether a system merely demonstrates intelligence or behaves responsibly in the untidy world.

His latest public work continues in that direction. DevRev announced him for a live session on moving IT self-service from answering questions to resolving work. The distinction is consequential. Answers live in language. Resolutions change state. The moment software crosses from one to the other, Vaknin wants an architecture that knows exactly where the authority came from.

Perhaps that is why the telescope portrait works. A telescope is an instrument for extending sight, but it does so through alignment, calibration and a firmly mounted base. Curiosity points it toward the unknown. Structure keeps the view from becoming a blur. Vaknin’s contribution to the AI conversation is much the same: look farther, connect more, and never confuse a wider field of view with permission to move the stars.