Kindo × Deloitte
Internal · Deep Dive Session Prep
Thursday Co-Design Session

Three Decisions to Exit With

Sprint 2 delivered telemetry, platform research, and architecture. The deck is at sprint2-review.pages.dev. Thursday isn't about reviewing — it's about deciding what Sprint 3 builds.

01 · The Reframe

Shadow AI Is the Enterprise Problem. Not Sanctioned AI Compliance.

Kishore's five governance objectives (Jul 7) are written from the lens of shadow AI at large in an enterprise. But the Sprint 2 deck answered with Kindo-native capabilities — telemetry, judges, config panels. That's a mismatch.

Charlie's Insight

"Unauthorized" means AI activity outside Kindo. Kindo telemetry can't see what isn't flowing through Kindo. The correct sequence: discover shadow AI → sanction it → then telemetry governs. Answering "how do you detect unauthorized AI?" with "Agent Telemetry" is a contradiction — telemetry only sees the fishbowl.

Charlie Hulcher, Jul 27 — feedback on Sprint 2 Review

Kindo's architecture already covers both directions — shadow AI discovery (Pillar 1: platform integrations, Pillar 3: network monitoring) and sanctioned AI governance (telemetry, judges, MCP gateway). The question is how Deloitte wants to scope Sprint 3.

Why This Matters Commercially

Enterprises buy shadow AI governance — the CTO who doesn't know how many developers are using Copilot directly, how much is going to Anthropic API without policy. Proving that sanctioned AI within Kindo is compliant is table stakes, not the pitch. Deloitte will sell and win off governing shadow AI, not demonstrating native Kindo compliance.

Session Framing Note
The Sprint 2 Review deck has been updated with this reframe (Alpha language, Objectives 1 & 2 rewritten with shadow AI discovery framing). Thursday's session should reference the deck as evidence and drive toward the decisions below.
02 · Decisions

Three Decisions to Drive Toward Thursday

Not open-ended questions. Options with tradeoffs. The goal: exit Thursday with enough clarity to scope Sprint 3 by Monday.

Decision 1
Scope: How Far Into Shadow AI Does Sprint 3 Go?
The tension: Kishore (Jul 7) said "SOC for AI = monitoring known AI agents." But his own five objectives describe detecting unauthorized activity — which by definition is outside Kindo. The Sprint 2 Review shows Kindo can do both. Deloitte needs to choose what comes first.
Option A — Sanctioned AI First
Sprint 3 deepens governance of AI workloads already flowing through Kindo. Telemetry to alpha, LLM judges production-ready, OTel pipeline hardened.
Lower risk, faster delivery. Doesn't address Kishore's "unauthorized" objectives.
Option B — Shadow AI Discovery First
Sprint 3 builds a working Pillar 1 integration against at least one external platform (Azure Foundry or Anthropic). Discover → enumerate → flag → route into Kindo.
Addresses the commercial problem. Requires platform access and Deloitte SME input on triage workflows.

Suggested framing for Deloitte: "We can govern what flows through Kindo today, or we can start discovering what doesn't flow through Kindo yet. Which unlocks more value for your customers faster?"

Decision 2
Ownership: Who Runs the Discovery-to-Governance Loop?
The tension: If Sprint 3 includes shadow AI discovery, the data has to go somewhere. Does Kindo deliver raw discovery data for Deloitte's existing detection engineering to triage? Or does Kindo orchestrate the full loop — discover, classify, recommend action?
Option A — Kindo as Data Source
Kindo discovers and reports. Deloitte's SOC teams triage with existing SIEM/SOAR tooling. Kindo exports telemetry, Deloitte acts on it.
Lower Kindo scope. Fits Deloitte's existing workflows. Limits Kindo's commercial position.
Option B — Kindo Orchestrates
Kindo discovers, classifies, and orchestrates response — including integration with endpoint detection, automated sanctioning workflows, and governance enforcement via MCP Gateway.
Larger Kindo role. Stronger commercial positioning. Requires deeper integration and Deloitte buy-in on Kindo as orchestration layer.

Suggested framing: "Kindo can be the eyes or the brain. The platform research shows we can probe 5 platforms today. The question is whether Kindo reports findings or acts on them."

Decision 3
Platform Priority: Which External Platform First?
The context: The platform compatibility matrix covers Anthropic, Azure AI Foundry, MS Copilot, ServiceNow, and AWS Bedrock. Each has different API maturity for discovery. Sprint 3 can't do all five — which one demonstrates the most value for Deloitte's customers?
Azure AI Foundry
Full ARM API. Azure Monitor for audit. RBAC + Policy enforcement. Deloitte's enterprise customers are overwhelmingly Azure. Requires Azure subscription access.
Highest customer relevance. Needs Deloitte to provide sandbox access or coordinate Azure credentials.
Anthropic
Admin API documented and accessible. Workspace enumeration, usage reports, key revocation. T&C has existing API access — can demo today.
Fastest to demo. Lower customer relevance than Azure for Deloitte's portfolio. Good for validating the pattern before Azure.

Suggested framing: "We've researched all five. For Sprint 3, we propose going deep on one. Azure is where your customers live. Anthropic is where we can validate the pattern fastest. Your call on sequencing."

03 · Sprint 3 Scenarios

Pre-Mapped Sprint 3 Based on Thursday's Decisions

Two paths. Both are viable. The difference is where Kindo's value shows up first. We arrive Thursday with both mapped — Deloitte chooses, Sprint 3 starts Monday.

Path A — Deepen Sanctioned AI Governance

Lower Risk · 2-Week Sprint
  • Telemetry alpha → production-ready (OTel pipeline, Clickhouse integration)
  • LLM Judges hardened with Deloitte-defined SOC behavioral criteria
  • Eval criteria co-designed in Thursday session
  • Configuration audit trail (Objective 4) — change tracking for guardrail policies
  • Token cost attribution dashboard (Nathan's P1 priority)
  • Failure alerting via webhooks (Matthew's request)

Outcome: Kindo provably governs all sanctioned AI. Strong foundation, but doesn't address the shadow AI commercial story yet.

Path B — Shadow AI Discovery + Governance

Higher Impact · 3-Week Sprint
  • Pillar 1 integration live against one platform (Azure or Anthropic)
  • Discovery → enumerate → classify → route into Kindo workflow
  • Telemetry alpha maintained (Sprint 2 work preserved)
  • MCP Gateway positioning for sanctioned AI choke point
  • Discovery tier model validated with Deloitte (Basic/Standard/Elite)
  • Pillar 3 (network monitoring) stays research — needs Deloitte SME

Outcome: Kindo demonstrates end-to-end shadow AI governance. The story Deloitte takes to enterprise customers.

04 · Their Open Priorities

What Deloitte's Team Is Asking For Right Now

From the Jul 21 program session (Nathan, Zun, Matthew). These are active blockers for their day-to-day — addressing any of them in Sprint 3 builds trust and velocity.

Agent Observability

Nathan · P1 · Active Blocker

No central log collection in Kindo today. Nathan built a makeshift hourly log retention on bastion host as stopgap. Token cost attribution is critical. Failure alerting needed — email, Jira tickets, webhooks. Not dependent on separate products (Loki, PagerDuty).

MCP Tool-Calling Reliability

Zun · P2 · Perf Bottleneck

Retry loops are the main choke point. MCP tool-calling fails initially, Kindo retries with different approaches until success. Previously hardcoded API calls were faster. Zun sanitizing internal docs for Charlie's review.

Swimlane/SOAR Replacement

Zun + Matthew · P3 · Dec 2026 Deadline

Deloitte wants to replace Swimlane. Heavy production usage across all SOC workflows. Go/no-go: December 2026. Migration complete: mid-January 2027. Contract ends: February 2027.

Swimlane — Strategic Context

Swimlane is free (existing license). LLM = cost per run. Deloitte won't accept "costs will decrease." Charlie's position: Kindo is agent-first — won't add native deterministic flow control. The direction is agents orchestrating deterministic code in sandbox without tokens entering the LLM context window.

Turbo Mode (Charlie's demo) addresses this directly: agent compiles historical runs into deterministic Python. Zero token cost. If execution fails, LLM retakes control. Demo exists (eng11252, <1s execution).

How to use Thursday: Don't lead with Turbo Mode. If Deloitte raises the Swimlane concern, surface it as a response. More powerful as an answer than as an agenda item. "The sprint review shows we listen. Turbo Mode shows we anticipate."

05 · Session Playbook

How Thursday Should Run

Format Agreed (Jul 24 Internal Review)

Send, don't present. Sprint 2 Review deck goes to Krishna before Thursday. Reserve ~10 minutes at the start for recap/Q&A, then move into deep dives. Krishna asked for 2 deep dives maximum — respect that constraint.

Suggested Deep Dives

Deep Dive 1: Agent Telemetry Alpha

  • Live walkthrough of trace export, LLM judges, eval config
  • Co-define behavioral criteria for SOC workflows
  • Sampling & retention: coverage vs. storage cost
  • Aligns directly with Kishore's five objectives

Deep Dive 2: Shadow AI Discovery Architecture

  • Walk through the three-pillar framework with platform matrix
  • Surface the scope decision: sanctioned vs. shadow AI first
  • Platform priority: where to go deep in Sprint 3
  • Discovery tier model: Basic / Standard / Elite mapping

Session Flow (60 min)

0–10 min
Sprint 2 Recap. "You've seen the deck. Here's the one thing to know: we delivered everything we could advance autonomously. What comes next, we shape together."
10–30 min
Deep Dive 1: Telemetry Alpha. Charlie walks through the prototype. Co-define eval criteria. Exit with: which behavioral rules matter most for their SOC workflows.
30–50 min
Deep Dive 2: Discovery Architecture. Victor/Tony walk the three pillars + platform matrix. Surface the three decisions. Exit with: scope, ownership model, and platform priority for Sprint 3.
50–60 min
Sprint 3 Alignment. Based on their answers, present the matching Sprint 3 path. Confirm timeline, access needs, and next session date.

Pre-Session Checklist

Sprint 2 Review Deck

Updated with Alpha language, shadow AI framing, rewritten Objectives 1 & 2.

✓ Ready to send

Charlie Review

"I need to share something before we send." Charlie reviews the updated deck before it goes to Krishna.

⏳ Pending Charlie's sign-off

Brandon / Observability

Charlie asked: "Can I confirm this group will hear from Brandon what's coming for observability before our Sprint 2 Review meeting?"

⏳ Pending confirmation
06 · Handle With Care

Known Tensions to Navigate

Tension 1
Clickhouse ↔ "No Data Lake"
Kindo engineering is shipping Clickhouse as mandatory telemetry backend in the next release. Kush told us "don't build a data lake" (Jul 10). These aren't necessarily contradictory — Clickhouse as OTel backend ≠ a data lake for raw logs — but the framing matters.

Suggested handling: Position Clickhouse as the telemetry storage engine (structured traces, not raw data lake). Kush's constraint was about not replicating SIEM/Splunk behavior. OTel traces stored in Clickhouse for eval scoring is a different category. Let Brandon introduce it in the context of the observability roadmap — not as a T&C talking point.

Tension 2
Deterministic Flow Control
Zun and Matthew want a Swimlane replacement. Charlie's position: Kindo won't add native deterministic flow control. Agents orchestrate deterministic code in sandbox. Zun/Matthew are skeptical — "sounds theoretical."

Suggested handling: Don't propose this Thursday. If it comes up: "We have a direction and a working demo. We should schedule a separate technical session with Zun and Charlie to walk through it." Keep the co-design session focused on SOC for AI scope, not Swimlane architecture.