Sprint 2 delivered telemetry, platform research, and architecture. The deck is at sprint2-review.pages.dev. Thursday isn't about reviewing — it's about deciding what Sprint 3 builds.
Kishore's five governance objectives (Jul 7) are written from the lens of shadow AI at large in an enterprise. But the Sprint 2 deck answered with Kindo-native capabilities — telemetry, judges, config panels. That's a mismatch.
"Unauthorized" means AI activity outside Kindo. Kindo telemetry can't see what isn't flowing through Kindo. The correct sequence: discover shadow AI → sanction it → then telemetry governs. Answering "how do you detect unauthorized AI?" with "Agent Telemetry" is a contradiction — telemetry only sees the fishbowl.
Kindo's architecture already covers both directions — shadow AI discovery (Pillar 1: platform integrations, Pillar 3: network monitoring) and sanctioned AI governance (telemetry, judges, MCP gateway). The question is how Deloitte wants to scope Sprint 3.
Enterprises buy shadow AI governance — the CTO who doesn't know how many developers are using Copilot directly, how much is going to Anthropic API without policy. Proving that sanctioned AI within Kindo is compliant is table stakes, not the pitch. Deloitte will sell and win off governing shadow AI, not demonstrating native Kindo compliance.
Not open-ended questions. Options with tradeoffs. The goal: exit Thursday with enough clarity to scope Sprint 3 by Monday.
Suggested framing for Deloitte: "We can govern what flows through Kindo today, or we can start discovering what doesn't flow through Kindo yet. Which unlocks more value for your customers faster?"
Suggested framing: "Kindo can be the eyes or the brain. The platform research shows we can probe 5 platforms today. The question is whether Kindo reports findings or acts on them."
Suggested framing: "We've researched all five. For Sprint 3, we propose going deep on one. Azure is where your customers live. Anthropic is where we can validate the pattern fastest. Your call on sequencing."
Two paths. Both are viable. The difference is where Kindo's value shows up first. We arrive Thursday with both mapped — Deloitte chooses, Sprint 3 starts Monday.
Outcome: Kindo provably governs all sanctioned AI. Strong foundation, but doesn't address the shadow AI commercial story yet.
Outcome: Kindo demonstrates end-to-end shadow AI governance. The story Deloitte takes to enterprise customers.
From the Jul 21 program session (Nathan, Zun, Matthew). These are active blockers for their day-to-day — addressing any of them in Sprint 3 builds trust and velocity.
No central log collection in Kindo today. Nathan built a makeshift hourly log retention on bastion host as stopgap. Token cost attribution is critical. Failure alerting needed — email, Jira tickets, webhooks. Not dependent on separate products (Loki, PagerDuty).
Retry loops are the main choke point. MCP tool-calling fails initially, Kindo retries with different approaches until success. Previously hardcoded API calls were faster. Zun sanitizing internal docs for Charlie's review.
Deloitte wants to replace Swimlane. Heavy production usage across all SOC workflows. Go/no-go: December 2026. Migration complete: mid-January 2027. Contract ends: February 2027.
Swimlane is free (existing license). LLM = cost per run. Deloitte won't accept "costs will decrease." Charlie's position: Kindo is agent-first — won't add native deterministic flow control. The direction is agents orchestrating deterministic code in sandbox without tokens entering the LLM context window.
Turbo Mode (Charlie's demo) addresses this directly: agent compiles historical runs into deterministic Python. Zero token cost. If execution fails, LLM retakes control. Demo exists (eng11252, <1s execution).
How to use Thursday: Don't lead with Turbo Mode. If Deloitte raises the Swimlane concern, surface it as a response. More powerful as an answer than as an agenda item. "The sprint review shows we listen. Turbo Mode shows we anticipate."
Send, don't present. Sprint 2 Review deck goes to Krishna before Thursday. Reserve ~10 minutes at the start for recap/Q&A, then move into deep dives. Krishna asked for 2 deep dives maximum — respect that constraint.
Updated with Alpha language, shadow AI framing, rewritten Objectives 1 & 2.
"I need to share something before we send." Charlie reviews the updated deck before it goes to Krishna.
Charlie asked: "Can I confirm this group will hear from Brandon what's coming for observability before our Sprint 2 Review meeting?"
Suggested handling: Position Clickhouse as the telemetry storage engine (structured traces, not raw data lake). Kush's constraint was about not replicating SIEM/Splunk behavior. OTel traces stored in Clickhouse for eval scoring is a different category. Let Brandon introduce it in the context of the observability roadmap — not as a T&C talking point.
Suggested handling: Don't propose this Thursday. If it comes up: "We have a direction and a working demo. We should schedule a separate technical session with Zun and Charlie to walk through it." Keep the co-design session focused on SOC for AI scope, not Swimlane architecture.