News 4 u.

THE DAILY EDITION / America/Los_Angeles
Back to the edition

Listening room

How Stripe built internal AI around project permissions and reusable skills

Lenny's Newsletter

Stripe engineering manager Sharadh Krishnamurthy joins Claire Vo to explain Kai, an internal AI assistant built around company context, project permissions and reusable workflows. Through a dashboard demonstration, he describes how existing data infrastructure, isolated execution environments and shared skills support use beyond engineering. The practical lesson is that enterprise agents require substantial governance and infrastructure work alongside model access. Adoption and staffing figures are his account, not independently verified results; he also acknowledges infrastructure incidents and unresolved design problems.

Editorial summary · Machine transcript (full audio)

The takeaways

  • Project owners can configure models, tools and approval requirements for particular workflows, reducing repeated setup by employees.
  • Data skills steer agents toward established reports and analytics before resorting to raw catalog exploration.
  • Reusable skills turn an interactive task into a workflow others can discover, while introducing maintenance and retrieval challenges.
  • Krishnamurthy credits existing infrastructure and supporting teams for enabling a small core team to expand deployment.
  • Agent traffic exposed infrastructure weaknesses; he describes hardening systems and continuing work on agent identity.
  • The speakers favor selective approvals and relevant context, warning that excessive friction and overloaded skill libraries can undermine results.

Why build an internal assistant

Krishnamurthy says Stripe’s central problem was enabling AI across a complex organization with appropriate governance. Kai incorporates organizational context and runs within the company’s cloud security boundaries. Building internally also lets the team exercise infrastructure that can support customer-facing agents. His argument depends on Stripe’s particular needs and existing capabilities; the conversation does not establish that every enterprise should build its own assistant or provide a comparative cost analysis of commercial alternatives.

Personal context with employee controls

Kai starts with information such as an employee’s position in the organization. Connected tools can supply project context, while employees choose whether to grant access to sources such as Google Drive, Slack and private messages. Krishnamurthy says he personally switches access on and off regularly. That distinction matters: organizational awareness and access to sensitive personal work communications are described as different layers, with employees controlling how much additional context they expose.

Projects make governance part of the workflow

Projects group relevant skills and configure how an agent should operate for a team or initiative. Owners can choose default models, restrict expensive options and establish tool policies, allowing a smaller group to manage cost, latency and performance choices. Some projects can use a different backend agent while retaining shared platform features. The design treats the company as a collection of workflows with different needs, rather than requiring every employee to make every configuration decision.

Data agents depend on curated foundations

The demonstration asks Kai to find existing adoption queries and build a dashboard. Its data skill guides retrieval through established artifacts and analytics resources, falling back to the data catalog when necessary. The discussion varies slightly in its ordering of reports and analytics, but consistently favors trusted existing work before fresh query construction. Krishnamurthy argues that schemas, dataset quality tiers and established analytics help agents avoid producing plausible answers from unsuitable tables or queries.

Execution isolation and infrastructure resilience

Kai provides a separate cloud sandbox for each session, with tools to move data in, run scripts and retrieve results. Isolation does not eliminate pressure on shared infrastructure. Krishnamurthy recalls agents that nearly disrupted core systems before the team intervened and hardened them. He describes identifying agent activity and its intended use as an unfinished avenue for prioritization and load shedding. The broader implication is that agent deployment can magnify existing failure modes through unusually intensive tool use.

Iterating on useful artifacts

The dashboard example continues through a follow-up request that adds a breakdown to the existing artifact. Krishnamurthy argues that preserving and editing work reduces waste compared with regenerating it each turn, while supporting collaboration over longer sessions. He sees particular value in small dashboards and applications tailored to individual workflows: centrally maintained reporting cannot anticipate every last-mile need. The demonstration illustrates that interaction pattern, but supplies no independent measurement of accuracy or token savings.

Rollout relied on more than the core team

Krishnamurthy estimates that an initial version took roughly one and a half engineers two weeks, followed by a pilot with a few hundred users and interest from go-to-market teams. A company-wide demonstration accelerated adoption. He reports more than 10,000 weekly users and a core experience team smaller than ten people. He explicitly credits supporting teams, coding tools and existing infrastructure, making these figures a poor standalone estimate of what another company would need to invest.

Selective approvals balance protection and friction

Tool policies let a project owner require human approval for sensitive actions. An HR example illustrates the concern: an agent should not inadvertently move restricted information into a broadly accessible document. A calendar action demonstrates the approval pattern. Vo emphasizes sharing permissions appropriate to a workflow; Krishnamurthy warns that prompts on every action could encourage careless approval or workarounds. Their recommendation is to concentrate friction where the task warrants it, though the interview does not independently validate the security controls.

Skills require discovery and ongoing maintenance

Kai can package a completed session into a reusable skill, with descriptions, usage guidance and an interface for editing and sharing. Krishnamurthy describes approximately 2,000 skills, making retrieval and context selection substantial engineering problems. Telemetry and improvement suggestions help determine which skills belong in general workflows and which should remain specialized. Vo proposes retirement policies she has seen elsewhere; he does not confirm that exact process at Stripe. He also stresses that narrowly used skills can remain valuable to small teams.

An unfinished system with everyday utility

In closing, Krishnamurthy emphasizes that the team has not solved enterprise AI and expects the system to evolve quickly. His personal example is using scheduled assistance to remember commitments, a modest benefit alongside the more elaborate dashboard workflows. The conversation ends with anecdotal prompting habits, without evidence that politeness improves performance. These notes cover the substantive discussion; consult the original episode for the full conversation and demonstration.

Context & caveats

  • The supplied full transcript is machine-generated and inconsistently renders names and technical terms, including Kai. Staffing, usage and skill counts are approximate guest statements and may contain transcription errors.
  • The interview and narrated demonstration provide a first-party implementation account, not an independent security audit, productivity evaluation or verification of adoption.
Why this made the edition

The full transcript contains detailed implementation examples, governance tradeoffs, rollout experience and explicit limitations from a builder of Stripe’s internal agent. Operational and adoption claims remain first-party accounts.

Source material
News 4 u.25 stories / 2026-09-08