Kindo × Deloitte
Thursday Deep Dive
Session Prep

Three Topics, One Direction

Topic 1

Agent Telemetry & SOC for AI

Alpha

Agent Telemetry

Trace export, LLM judges, eval config, span detail, error diagnostics. Validated against Anthropic in Sprint 2.

Research Complete

Platform Compatibility

5 platforms mapped — Anthropic, Azure AI Foundry, Copilot, ServiceNow, Bedrock.

Implemented

Three-Pillar Framework

Your input from Jul 10 session. Platform integrations, LLM gateway, network monitoring.

Five Governance Objectives

1. Unauthorized Agents
Pillar 1 discovery — not started yet Sprint 3
2. Unauthorized Connections
Pillars 1 + 3 + MCP Gateway — not started yet Sprint 3
3. Behavioral Drift
LLM Judges — alpha working, SOC behavioral criteria needed to configure Alpha
4. Guardrail Changes
Config visibility + change tracking Roadmap
5. Cross-Tenant
Org-isolated workspaces, per-org trace storage Alpha

Sprint 3 — Recommended Direction

Recommendation

Pillar 1 Discovery First — Azure AI Foundry

Alpha proved against Anthropic. Azure has the fullest admin API across the five platforms.

Deliverable: Azure discovery integration + LLM Judges configured with SOC behavioral criteria.

Recommended

Azure AI Foundry

Full admin API. Microsoft stack. Enterprise AI footprint.

Alternative

Anthropic Console

Proven in Sprint 2. Fast-start if Azure access takes time.

Not Recommended

Defer Discovery

Objectives 1 & 2 stay open another sprint.

Three-Pillar Architecture

1

Platform Integrations

Admin APIs into Anthropic, Azure, Copilot, ServiceNow, Bedrock. The discovery layer.

2

LLM Gateway

Kindo as inference proxy. Real-time governance. Kush endorsed Jul 16.

3

Network Monitoring

Shadow AI beyond managed platforms. Endpoint-level detection.

Topic 2

Observability

Today

Gaps

  • No central log collection
  • Hourly log retention on bastion host (stopgap)
  • No token cost attribution
  • No native failure alerting
Next Release

Foundation

  • Clickhouse-backed telemetry storage
  • OTel-based ingestion pipeline
  • Foundation for SOC for AI eval layer
  • Engineering timeline pending coordination

Sprint 3 Priorities

Recommended sequencing

1. Token cost attribution — No EBITDA visibility without this. Swimlane cost comparison blocked.

2. Failure alerting — Native email / Jira / webhooks.

3. Central logging — Clickhouse replaces bastion stopgap.

Topic 3

Swimlane Transition

Sprint 3
Playbook inventory + cost model + one proof-point migration.
Nov 2026
Go/no-go decision — proof point validated, cost model complete.
Dec 2026
Contract renewal notice deadline.
Jan 2027
Full migration (if go decision).
Feb 2027
Swimlane contract expires.

Discovery Findings

Scope

80% of MXDR customers on Swimlane. Alert injection, normalization, playbook execution, Jira integration. Well beyond triage handoff.

Kindo's Approach

Agents orchestrate deterministic code in sandbox. Tokens stay out of context window.

Sprint 3 — Recommended Direction

Recommendation — Size Together First

1. Playbook inventory — All Swimlane playbooks mapped by complexity and migration effort.

2. Cost model — Three inputs needed: bench headcount, billed hours per engagement, Swimlane license cost.

3. Proof point — One playbook migrated end-to-end before the November decision.

Confirm to Start Sprint 3

What We Need From This Session

SOC for AI

  • Azure AI Foundry as Sprint 3 discovery target
  • SOC behavioral criteria for LLM Judge configuration

Observability

  • Priority sequencing: cost attribution → alerting → logging
  • Engineering roadmap coordination

Swimlane

  • Cost structure inputs for the model
  • Playbook access for inventory
  • Proof-point playbook selection
Sprint 2 Review

Full delivery details at sprint2-review.pages.dev