Kindo × Deloitte
SOC for AI · Deep Dive Session
Sprint 3 · Co-Design

Proposed Direction for Sprint 3

Based on Sprint 2 research and the five governance objectives, we're proposing a focused path for Sprint 3. This document lays out our recommendations — we'd like to refine them together in this session.

01 · Sprint 2 Summary

Where We Are

Sprint 2 advanced the SOC for AI architecture across three areas. The agent telemetry alpha is architected to graduate toward production — it represents the starting point for requirements finalization. Full details at sprint2-review.pages.dev.

Alpha

Agent Telemetry

Trace export, LLM judges, eval configuration, span detail, error diagnostics. Built natively inside Kindo. Shaped for requirements finalization — your input refines it.

Research Complete

Platform Compatibility

Five platforms mapped — Anthropic, Azure AI Foundry, MS Copilot, ServiceNow, AWS Bedrock. Per-platform API capabilities documented for discovery and governance.

Architecture Defined

Three-Pillar Framework

Platform integrations, LLM gateway, network monitoring. Co-designed at the Jul 10 session. Three complementary approaches to AI governance across the enterprise.

The Five Governance Objectives — How They Map

1. Unauthorized Agent Deployment
Pillar 1 platform discovery probes external platforms to find AI activity outside Kindo. Once discovered and routed through Kindo, telemetry provides ongoing governance. Pillar 1 + Telemetry
2. Unauthorized Tool/Data Connections
Pillars 1 + 3 surface unauthorized connections via API probing and network-level detection. For sanctioned workloads, MCP Gateway enforces real-time tool access policies. Pillars 1 + 3 + Gateway
3. Agent Behavioral Drift
LLM Judges score every agent run against standard operating procedures. Alpha ready — criteria to be co-defined. Alpha
4. Guardrail/Policy Changes
Configuration visibility per agent. Change tracking and audit trail scope to be defined. Roadmap
5. Cross-Tenant Contamination
Organization-isolated workspaces with per-org trace storage. Demonstrated in alpha. Alpha
02 · Architecture

Three-Pillar Discovery Framework

Co-designed at the Jul 10 session. Each pillar addresses a different part of the AI governance challenge. Our Sprint 3 proposal focuses on Pillar 1 first — the fastest path to enterprise-wide visibility.

1

Platform Integrations

Reach into Anthropic, Azure, Copilot, ServiceNow, Bedrock via admin APIs. Enumerate agents, audit usage, inspect configurations. The discovery layer.

2

LLM Gateway

Kindo as inference proxy. Real-time governance at the choke point. Kush endorsed this approach Jul 16. For sanctioned workloads.

3

Network Monitoring

Sweep for shadow AI beyond managed platforms. Network and endpoint-level discovery. Requires specialized detection engineering expertise.

03 · Proposed Direction

What We Recommend for Sprint 3

Based on the Sprint 2 research, the five objectives, and the Jul 10 session direction, we're proposing five focused areas for Sprint 3. Each recommendation includes our rationale — we'd like to refine these together.

Proposal 1

Lead With Shadow AI Discovery

Recommended: Pillar 1 first
Objectives 1 and 2 are fundamentally about AI activity happening outside Kindo — agents and connections that aren't known or sanctioned. Governing sanctioned AI within Kindo is foundational, but the enterprise challenge is visibility into what's happening across platforms. We propose Sprint 3 focuses on building a working Pillar 1 integration that discovers, enumerates, and classifies AI activity on external platforms — then routes it into Kindo for governance.

Sprint 3 deliverable: Working discovery integration against one external platform. Discover → enumerate → classify → route into Kindo. Agent telemetry alpha maintained and refined in parallel.

Refine together: Does this sequencing align with how you see the SOC for AI rollout? Should sanctioned AI governance come first instead?
Proposal 2

Start With Azure AI Foundry

Recommended: Highest customer relevance
The platform matrix shows five viable platforms. Azure AI Foundry has the strongest API surface for discovery (full ARM API, Azure Monitor for audit, RBAC + Policy enforcement) and is the most relevant for enterprise customers. We propose validating the Pillar 1 discovery pattern on Azure first, then expanding to other platforms. Anthropic is a faster alternative if Azure access isn't immediately available.

What we need: Azure subscription access with AI Foundry resources to build and validate against. We can work with a sandbox environment.

Refine together: Is Azure the right starting point for your customer base? Should we validate on Anthropic first (faster) then bring Azure in Sprint 4?
Proposal 3

Co-Define Eval Criteria for LLM Judges

Recommended: Unlocks Objective 3
The LLM Judges alpha can score agent runs against any criteria defined in natural language. The capability works — what's needed is your SOC expertise to define which standard operating procedures and behavioral rules the judges should evaluate against. This is where your domain knowledge directly shapes the product. We propose a working session to define the initial set of eval criteria for your SOC workflows.

Sprint 3 deliverable: Judges configured with Deloitte-defined SOC behavioral criteria. Production-ready eval pipeline scoring every agent run.

Refine together: Which SOC workflows should we start with? What does "drift" look like in your operations?
Proposal 4

Kindo as Orchestration Layer

Recommended: Strongest commercial position
When shadow AI activity is discovered, the governance loop needs an orchestrator. Kindo is positioned to play that role — not just discovering and reporting, but classifying, routing, and enforcing policy through MCP Gateway. This is a stronger position than being a data source for existing SIEM/SOAR tooling, and it's where Kindo's architecture has a natural advantage.

Sprint 3 deliverable: Discovery-to-governance workflow demonstrated end-to-end. Kindo discovers on external platform → classifies → routes into Kindo → telemetry + judges govern.

Refine together: Does this fit your existing SOC workflows? Should Kindo integrate with your current tooling instead of replacing parts of the loop?
Proposal 5

Discovery Tier Model: Basic → Standard → Elite

Recommended: Aligns with CrowdStrike analogy
Inspired by Krishna's CrowdStrike analogy from the Jul 10 session — a menu of options, not one-size-fits-all. We propose three tiers mapped to different governance maturity levels: Basic (detect & respond post-action), Standard (monitor & alert live with LLM judges), Elite (preventative blocking at the gateway). This gives your customers a clear adoption path.

Sprint 3 deliverable: Tier model validated with your team. Per-tier capabilities defined and mapped to platform requirements.

Refine together: Does this tier mapping fit how your customers think about governance? Should the tiers be structured differently?
04 · Today's Session

Two Deep Dives

The Sprint 2 Review covers the full delivery. These deep dives go into the two areas where collaborative refinement has the most impact on Sprint 3.

Deep Dive 1

Agent Telemetry Alpha — Requirements Refinement

Walk through the alpha together. The shape is here — this session defines the requirements that graduate it toward production.

  • Trace export and span detail — what the data looks like
  • LLM Judges — how behavioral criteria are defined and scored
  • Define the initial SOC eval criteria together
  • Sampling, retention, and cost trade-offs at your scale
  • Alerting and failure notification requirements
Deep Dive 2

Discovery Architecture — Refining the Sprint 3 Path

Walk through our proposed direction for Pillar 1 discovery. Validate the approach and refine platform priority, scope, and sequencing.

  • Three-pillar framework — validate Pillar 1 as Sprint 3 focus
  • Platform matrix — refine Azure as starting point
  • Shadow AI discovery scope — how deep, how fast
  • Kindo's role in the governance loop
  • Discovery tier model — validate Basic / Standard / Elite
05 · Next Steps

What We Need to Start Sprint 3

Your input from this session shapes Sprint 3 scope. A few items are needed to begin specific workstreams.

Eval Criteria

Which behavioral rules and SOC standard operating procedures should the LLM judges evaluate against? This directly shapes the telemetry alpha toward production.

Platform Access

Azure subscription with AI Foundry resources to validate the Pillar 1 discovery integration. Sandbox environment is sufficient to start.

Teams Coordination

Digital twin and L2/L3 workflow discovery require Teams integration with Deloitte IT. Ready to coordinate in Sprint 3.

Sprint 2 Review

Full Sprint 2 details, platform compatibility matrix, architecture documentation, and current status at sprint2-review.pages.dev.