Thursday covers agent telemetry & SOC for AI, observability, and Swimlane transition. This document lays out where we are on each, our proposed direction, and what we need from this session to move forward.
Sprint 2 advanced the SOC for AI architecture across telemetry, platform research, and discovery frameworks. The agent telemetry alpha is architected to graduate toward production — it represents the starting point for requirements finalization. Full details at sprint2-review.pages.dev.
Trace export, LLM judges, eval configuration, span detail, error diagnostics. Built natively inside Kindo. Shaped for requirements finalization — your input refines it.
Five platforms mapped — Anthropic, Azure AI Foundry, MS Copilot, ServiceNow, AWS Bedrock. Per-platform API capabilities documented for discovery and governance.
Platform integrations, LLM gateway, network monitoring. Co-designed at the Jul 10 session. Three complementary approaches to AI governance.
Each objective from the Jul 7 scope definition connects to a different part of the architecture. Objectives 1 and 2 require discovery of AI activity outside Kindo — the enterprise-wide challenge. Objectives 3–5 are addressable through the telemetry alpha.
Sprint 3 deliverable: Working discovery integration against Azure (or Anthropic as fast-start alternative). Discover → enumerate → classify → route into Kindo. Judges configured with co-defined eval criteria.
Reach into Anthropic, Azure, Copilot, ServiceNow, Bedrock via admin APIs. Enumerate agents, audit usage, inspect configs. The discovery layer.
Kindo as inference proxy. Real-time governance at the choke point. Kush endorsed Jul 16. For sanctioned workloads.
Shadow AI beyond managed platforms. Network and endpoint-level discovery. Requires detection engineering expertise to scope.
Observability has been a consistent priority from the program sessions. The upcoming Kindo platform release introduces foundational changes to the telemetry infrastructure. Here's where things stand and where we propose to go.
1. Token cost attribution — Critical for EBITDA visibility and Swimlane transition costing. Required for any cost comparison with existing tooling.
2. Failure alerting — Notifications without depending on separate products. Email, Jira ticket creation, webhooks. SOC workflows need immediate failure notification.
3. Central logging — Replace the bastion host stopgap with the Clickhouse-backed pipeline from the upcoming release.
We've been working with Zun and Matthew's team to understand the full scope of the potential Swimlane-to-Kindo transition. The scope is substantially larger than the triage handoff in production today. We'd rather size this together than guess at it.
Swimlane handles client alert injection, normalization, and all SOC workflows. Heavy daily volume — hundreds to thousands of events across clients. Email ingestion, format transforms, Jira integration. The scope goes well beyond the triage handoff currently running in Kindo.
Kindo is an agent-first platform. Rather than native deterministic flow control, the direction is agents orchestrating deterministic code in sandbox environments — without tokens entering the LLM context window. Agent as control layer, not deterministic engine. Inference costs drop with each generation.
What we propose for Sprint 3:
1. Workflow inventory — Complete mapping of Swimlane workflows, classified by complexity and migration effort.
2. Token economics model — Per-workflow cost comparison: Swimlane (zero marginal cost) vs. Kindo (inference cost per run). Including the agent-compiled deterministic execution path where applicable.
3. Proof point — One representative workflow migrated end-to-end. Validates the pattern before committing to full migration.
Token economics — inference cost as a factor in the EBITDA calculation. Did this surface in the original due diligence or later in implementation? The context shapes how we frame the cost model.
Your input from this session directly shapes Sprint 3 scope across all three topics.
Full Sprint 2 delivery details, platform compatibility matrix, architecture documentation, and current status at sprint2-review.pages.dev.