Trace export, LLM judges, eval config, span detail, error diagnostics. Validated against Anthropic in Sprint 2.
5 platforms mapped — Anthropic, Azure AI Foundry, Copilot, ServiceNow, Bedrock.
Your input from Jul 10 session. Platform integrations, LLM gateway, network monitoring.
Alpha proved against Anthropic. Azure has the fullest admin API across the five platforms.
Deliverable: Azure discovery integration + LLM Judges configured with SOC behavioral criteria.
Full admin API. Microsoft stack. Enterprise AI footprint.
Proven in Sprint 2. Fast-start if Azure access takes time.
Objectives 1 & 2 stay open another sprint.
Admin APIs into Anthropic, Azure, Copilot, ServiceNow, Bedrock. The discovery layer.
Kindo as inference proxy. Real-time governance. Kush endorsed Jul 16.
Shadow AI beyond managed platforms. Endpoint-level detection.
1. Token cost attribution — No EBITDA visibility without this. Swimlane cost comparison blocked.
2. Failure alerting — Native email / Jira / webhooks.
3. Central logging — Clickhouse replaces bastion stopgap.
80% of MXDR customers on Swimlane. Alert injection, normalization, playbook execution, Jira integration. Well beyond triage handoff.
Agents orchestrate deterministic code in sandbox. Tokens stay out of context window.
1. Playbook inventory — All Swimlane playbooks mapped by complexity and migration effort.
2. Cost model — Three inputs needed: bench headcount, billed hours per engagement, Swimlane license cost.
3. Proof point — One playbook migrated end-to-end before the November decision.
Full delivery details at sprint2-review.pages.dev