Skip to content
Lenny's PodcastLenny's Podcast

The GitLab way: Kindness, transparency, and short toes | David DeSanto (CPO)

David DeSanto is the chief product officer of GitLab, which is the largest remote-only company in the world. They share many of their team meetings on YouTube, and they’ve grown from being an open-source code management product competing with GitHub to a multi-product platform that covers security, compliance, continuous integration, project management, and deployment tools, many of which are infused with AI magic. In our conversation, we discuss: • How GitLab operationalizes transparency • The philosophy behind recording and sharing team meetings on YouTube • Their extensive public employee handbook • GitLab’s core value of having “short toes” • Challenges and advice for doing remote work well • Strategies for ensuring effective communication in a remote work environment • GitLab’s breadth-over-depth strategy • The company’s unique approach to AI • The value of using humor in high-stakes conversations — Brought to you by: • Orb—The flexible billing engine for modern pricing: https://www.withorb.com/lenny • Eppo—Run reliable, impactful experiments: https://www.geteppo.com/ • Paragon—Ship every SaaS integration your customers want: https://www.useparagon.com/lenny Find the transcript and references at: https://www.lennysnewsletter.com/p/the-gitlab-way Where to find David DeSanto: • X: https://twitter.com/david_desanto • LinkedIn: https://www.linkedin.com/in/ddesanto/ • Threads: https://www.threads.net/@david.the.beard Where to find Lenny: • Newsletter: https://www.lennysnewsletter.com • X: https://twitter.com/lennysan • LinkedIn: https://www.linkedin.com/in/lennyrachitsky/ In this episode, we cover: (00:00) David’s background (04:20) Maintaining an epic beard (05:29) Why GitLab publicly shares team meetings (09:49) The GitLab Handbook (11:30) GitLab’s issue tracker (14:29) How to successfully build a culture of transparency (18:11) Benefits of operating with transparency (19:55) The value of building in public (21:53) How GitLab implements their core value of kindness (25:16) What it means to have “short toes” (27:41) Other core values (32:16) Common reasons for not fitting in at GitLab (34:42) Advice for remote teams (42:04) Advice for getting into product (43:52) Advice for PMs who are struggling in a remote world (48:25) Specific tools that help with remote work (53:13) Time zones and remote work (57:18) Breadth-over-depth strategy (01:04:14) AI at GitLab (01:13:11) GitLab’s products and solutions (01:14:54) Lightning round Production and marketing by https://penname.co/. For inquiries about sponsoring the podcast, email podcast@lennyrachitsky.com. Lenny may be an investor in the companies discussed.

Lenny RachitskyhostDavid DeSantoguest
Apr 14, 20241h 21mWatch on YouTube ↗

CHAPTERS

  1. 0:00 – 0:49

    Cold open: GitLab’s radical transparency in the wild

    A quick teaser of GitLab’s most unusual practices: publishing internal meetings, maintaining an open handbook, and embracing “short toes.” Lenny and David preview how these ideas connect to community contribution and better remote collaboration.

    • Public YouTube uploads of internal team meetings
    • The GitLab Handbook as an open operating system
    • “Short toes” as a cultural mechanism for reducing conflict
    • Why transparency can invite external contributions
    • Set-up for remote-work and culture discussion
  2. 0:49 – 4:21

    Sponsor break + episode framing: what makes GitLab different

    Lenny introduces David DeSanto, GitLab’s scale, and the conversation’s main themes: transparency, kindness, remote execution, and product strategy. This section also includes sponsor messages before the interview begins.

    • David’s role as CPO and GitLab’s remote-first identity
    • GitLab’s expansion from SCM into a full DevSecOps platform
    • What they share publicly vs. what they keep private
    • Upcoming focus areas: remote work, breadth/depth strategy, AI
    • Sponsor reads before the main interview
  3. 4:21 – 5:29

    Beard interlude + why GitLab’s culture draws so much attention

    A light opening about David’s beard and online handles quickly turns into why Lenny is fascinated by GitLab’s operating model. The stage is set for a deep dive into transparency as a core differentiator.

    • Beard maintenance and David’s social handles
    • Lenny’s motivation: GitLab’s unique operating system
    • GitLab’s longevity and scale as proof it works
    • Transition into transparency practices
  4. 5:29 – 9:49

    Publishing internal meetings: how GitLab decides what goes public

    David explains the practical policy behind “GitLab Unfiltered” and what gets recorded or livestreamed. He shares boundaries (customer data, vulnerabilities, MNPI) and how this changes meeting behavior and accountability.

    • Default posture: share as much as possible
    • Hard constraints: customer data, vulnerabilities, material nonpublic info
    • Examples: product meetings vs. internal KPI deep-dives
    • “GitLab Unfiltered” as a massive public archive
    • Transparency improves meeting quality and engagement
  5. 9:49 – 11:41

    The GitLab Handbook: open-sourcing how the company runs

    The conversation shifts to the public GitLab Handbook and why it’s so comprehensive—from onboarding to finance workflows. David highlights how other companies fork and reuse it as a starting point for their own operating systems.

    • Handbook covers everything from values to AP workflows
    • Source-available: companies can fork/clone sections or the whole thing
    • Real-world reuse example: UX orgs cloning GitLab’s UX handbook
    • Handbook as leverage for teams building processes from scratch
    • Public competencies/leveling frameworks as a standout resource
  6. 11:41 – 14:29

    Issue tracker + public strategy: letting the world watch (and shape) the roadmap

    David adds two more pillars of transparency: a mostly public issue tracker and unusually detailed public direction/strategy. This creates a feedback loop where customers and community members can comment, vote, and sometimes even contribute code.

    • Most issues are public; customers can comment and influence prioritization
    • External contributors can find problems and submit fixes
    • Public product direction links to epics/issues for traceability
    • Transparency as a competitive advantage: “idea vs. execution”
    • Operational cadence: consistent monthly releases over a decade
  7. 14:29 – 18:12

    How to build transparency (without breaking trust): starting small and learning fast

    Lenny presses on what it takes to make transparency work and where it can go wrong. David emphasizes separating truly confidential info from “artificial silos,” accepting occasional mistakes, and rolling out transparency incrementally.

    • Challenge “confidential by default” habits and artificial silos
    • Occasional over-sharing happens; reinforce learning and fix quickly
    • Start internally (company-wide visibility) before going public
    • Use async readouts and recorded meetings to scale transparency
    • Find the right balance for regulated industries
  8. 18:12 – 21:54

    Why transparency pays off: async alignment, less FOMO, faster decisions (and external trust)

    David outlines the benefits that outweigh added work and risk: better async participation across time zones, improved alignment, earlier problem discovery, and more informed decisions. Going public also increases external engagement and customer trust.

    • Async consumption enables global teams to stay aligned
    • Reduced fear of missing out; higher engagement across 2,000+ people
    • Earlier detection of issues before releases or go-to-market plans
    • External loop: customer comments + community contributions
    • Transparency can build trust even in regulated industries (selectively)
  9. 21:54 – 27:41

    Kindness and “short toes”: cultural guardrails for remote, async collaboration

    Lenny digs into GitLab’s values, focusing on kindness, assuming positive intent, and giving negative feedback one-on-one. David explains “short toes” as separating critique of work from critique of people—especially important when communication is mostly written.

    • Kindness practices: assume positive intent, say thanks/sorry
    • Negative feedback should be delivered one-on-one
    • “Thanks” channel as a reinforcing mechanism
    • “Short toes” = it’s about the work, not your ego
    • Values as prerequisites for transparency at scale
  10. 27:41 – 32:13

    Operating system for execution: results, efficiency, and long-horizon planning

    David highlights additional values—results and efficiency—and how GitLab pushes responsibility to the lowest level of the org. He also explains their layered planning: mission/vision/strategy/direction, with examples like the “all-ops platform” ambition and section-stage-group structure.

    • Results-first: solve customer pain points, not internal outputs
    • Efficiency: empower teams; leaders set direction, teams decide how
    • Layered planning horizons (including multi-year strategies)
    • All-ops platform vision: single source of truth for R&D and surrounding teams
    • Org structure: sections → stages → groups mapped to the DevOps toolchain
  11. 32:13 – 43:52

    Remote work at scale: why people don’t fit + how GitLab makes it work

    David explains the most common mismatch at GitLab: remote work isn’t for everyone, especially those craving daily in-person connection. He then shares foundational remote-first advice—transparency, outcome focus, overcommunication, and periodic in-person gatherings.

    • Top reason for misfit: missing in-office connection and routine
    • Remote-first fundamentals: transparency + outcomes over hours
    • Overcommunication to close understanding gaps
    • Invest in in-person meetups to strengthen human connection
    • Remote expands hiring pool and improves life flexibility
  12. 43:52 – 48:25

    Remote PM tactics: crisp requirements, no waiting, and the handbook-first workflow

    This chapter gets highly tactical for product teams operating remotely. David covers writing clear requirements, GitLab’s “deep dive” interview exercise, and how PMs should proactively unblock engineers via issues, Slack, or quick Zoom calls.

    • Requirements must be written clearly early (async-first)
    • Deep-dive interview simulates remote PM/engineering collaboration
    • Don’t wait for weekly syncs—unblock immediately in the system of record
    • Use issues/merge requests as the collaboration hub; Slack/Zoom when needed
    • Handbook updates via merge requests: document decisions for reuse
  13. 48:25 – 57:18

    Async-by-default logistics: tools, time zones, DRIs, and recorded/optional meetings

    David outlines GitLab’s core tooling and time zone practices: GitLab issues as the single source of truth, Slack and Zoom for coordination, and an anti-email bias internally. For time zones, they prioritize asynchronous decisions, DRIs, strong notes, and inclusive meeting norms.

    • Tool stack: GitLab (dogfooding), Slack, Zoom; minimal internal email
    • Decisions move into the handbook so everyone benefits
    • Time zones: async first; key decisions wait for the DRI when needed
    • Meetings are optional, recorded, and supported by strong notes
    • Empowerment model reduces need for painful timezone-overlap meetings
  14. 57:18 – 1:04:12

    Product strategy: when breadth-over-depth wins—and when to pivot to depth

    Lenny asks about GitLab’s growth approach: building breadth across the DevSecOps lifecycle, then deliberately shifting to depth in the most differentiating areas. David shares how to decide when to go wide vs. focus, with parallels to other successful platform companies.

    • Early strategy: breadth to build a true DevSecOps platform
    • Later pivot: depth in key areas (SCM, CI/CD, security, governance, planning, AI)
    • Use breadth to find differentiation; use depth to defend and win
    • Selective “good enough” areas supported by deep anchors + integrations
    • Frameworks like Crossing the Chasm guide timing of the pivot
  15. 1:04:12 – 1:11:52

    AI at GitLab (GitLab Duo): principles, privacy, and choosing the right models

    David explains GitLab’s AI strategy: assist across the entire SDLC (not just coding), maintain transparency, prioritize privacy, and deliver measurable efficiency gains. He emphasizes a practical lesson for product leaders: match the model to the use case instead of forcing one model everywhere.

    • AI across SDLC: help PMs, QA, ops, and security—not just developers
    • Transparency: disclose models, approaches, and source-available implementation
    • Privacy: don’t train/fine-tune on customer IP; partner only where requirements are met
    • Model selection: multiple models (~16) optimized per task (summarization, vuln resolution, code completion, code generation)
    • Mix of partners (Google/Anthropic), proprietary models, and open source contributions
  16. 1:11:52 – 1:21:33

    Wrap-up + lightning round: books, products, mottos, and how to help GitLab

    David closes with a concise overview of GitLab’s end-to-end platform capabilities and where to learn more. The lightning round covers favorite books and shows, interview practices, beloved tools, leadership mottos, and ways listeners can contribute via issues and merge requests.

    • GitLab platform overview across the SDLC (planning → production feedback loop)
    • Lightning round: Crossing the Chasm, Essentialism; favorite shows/movies
    • Interview approach: STAR method + tension/conflict scenarios
    • Favorite products: Artifact (RIP), Superhuman, Arc browser
    • How listeners can help: comment/vote on public issues; contribute to handbook/code

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.