Cadence
Kindo × Deloitte Program
Sprint 3: Aug 5 - Aug 18 Updated Aug 4
SPRINT 3 KICKOFF AUG 5·TURBO MODE ALPHA IN AUGUST·TEAMS FEDERATION UNBLOCKED·SOAR EVALUATION ACTIVE·SWIMLANE DECISION: NOV DEADLINE·SOC FOR AI EXPANDING·PORTFOLIO REVIEW AUG 10·SPRINT 3 KICKOFF AUG 5·TURBO MODE ALPHA IN AUGUST·TEAMS FEDERATION UNBLOCKED·SOAR EVALUATION ACTIVE·SWIMLANE DECISION: NOV DEADLINE·SOC FOR AI EXPANDING·PORTFOLIO REVIEW AUG 10·
Kindo × Deloitte · Sprint 3

Sprint 3 Tracker.

Live sprint tracker - Sprint 3 kickoff August 5

Current SprintWk 32
Cycle 2 weeks
Committed TBD items
Day 1 of 10
Confidence High
Revenue Architecture →
01 · Sprint Progress

Sprint 3 Progress.

Day 1 of 10 - August 5 → August 18, 2026 - Sprint 3 Kickoff · View Sprint 2 Review →

Sprint 3 Status

Sprint 2 complete. Sprint 3 kicks off Aug 5. SOAR evaluation + Turbo Mode alpha + SOC for AI expansion.

Day 1
of 10 (Wed Aug 5)
3
Sprint 2: Delivered
Aug 18
Sprint End
Sprint 2 Recap: Sprint 2 complete. 3 items delivered (Agent Telemetry prototype, Platform Compatibility Matrix, Gateway Architecture). 2 in progress. 4 items awaiting co-design. Jul 30 design session held — SOAR replacement moved from hypothetical to active evaluation. View Sprint 2 details →
Sprint 3 Goals:
  • Turbo Mode SaaS alpha access for Deloitte - Charlie committed August timeline
  • SOAR/Swimlane replacement evaluation - Zun to share JSON workflows, Charlie to build against them
  • Teams federation completion - Deloitte side unblocked (Adelina confirmed Aug 4), T&C/Kindo side pending
  • SOC for AI + Telemetry convergence - Krishna: "I can see us taking this to clients"
  • Case management scoping - historical record search for ticket correlation (Zun requirement)
  • Multi-tenancy design - separating clients in shared tenant
  • QA/Account Manager hiring - Value First hires positioned as technical QA bridging Deloitte↔Kindo engineering
Delivered (Sprint 2)
Shipped Last Sprint
  • Agent Telemetry — Working prototype: trace export, LLM judges, eval configuration, span detail, error diagnostics
  • Platform Compatibility Matrix — 5 platforms (Anthropic, Azure, Copilot, ServiceNow, Bedrock), license gates mapped
  • Gateway Architecture (Pillar 2) — 3 open standards documented. Kush endorsed gateway approach
In Progress
Sprint 3 Active
  • Turbo Mode Alpha — SaaS alpha access for Deloitte, Charlie committed August timeline
  • SOAR Evaluation — Swimlane replacement, Zun sharing JSON workflows for Charlie to build against
  • Teams Federation — Deloitte side unblocked (Adelina, Aug 4), T&C/Kindo integration pending
For Aug 10 Portfolio
Krishna + Kush Review
  • SOC for AI + Telemetry demo — to Krishna/Kush. "I can see us taking this to clients"
  • SOAR EBITDA presentation — SaaS fee + manual playbook + triage labor vectors
  • Turbo Mode preview — alpha capability walkthrough
Sprint 2 Review: Full interactive review with demo, objectives mapping, architecture details, and platform research at sprint2-review.pages.dev
Upcoming
Key Dates
DateEventDetails
Aug 4 (Mon) Program Session Turbo Mode deep dive with Zun, Matthew, Adelina, Nathan. Swimlane requirements reviewed. Teams federation unblocked.
Aug 5 (Wed) Sprint 3 Kickoff Sprint planning with Joana.
Aug 10 (Mon) Portfolio Meeting with Krishna + Kush SOC for AI + Telemetry, SOAR/Swimlane EBITDA case, Turbo Mode preview.
Aug (mid) Turbo Mode SaaS Alpha Access Deloitte team (Zun, Matthew, Adelina) gets SaaS alpha access to evaluate Turbo Mode as Swimlane replacement. POV testing with MXDR test range + Graph API email ingestion.
Aug 18 (Mon) Sprint 3 End + Review Show-don't-tell evidence.
Sep (target) Turbo Mode Self-Managed (SMK) Release Self-managed/deployed version with Turbo Mode for Deloitte's on-prem environment. Tony confirmed September target. Enables testing against Jira behind firewall + full Swimlane workflow migration.
Aug 31 (Mon) Charlie vacation starts Returns Sep 23.
Nov (end) Swimlane Decision Deadline 90-day notice before Feb renewal. Deloitte must decide by ~Nov.
Context
Pillar 1 Deep Dive (Complete)
Charlie's framework (confirmed by Kush/Krishna Jul 10): (1) Platform integrations, (2) LLM gateway/choke point, (3) Network/endpoint monitoring for shadow AI. Deep dive completed in Sprint 2.
SOAR/Swimlane Replacement
Detection + triage automation only (not response-side). Swimlane renewal deadline Nov. Three EBITDA vectors: SaaS fee replacement, manual playbook labor, manual triage labor. Turbo Mode handles 5 of 10 requirements.
Teams Federation
Deloitte side exclusion added (Adelina, Aug 4). Pending T&C/Kindo integration. Slack confirmed dead.
Co-Develop Trajectory
May 7 · Co-sell Jun 22 · Co-design Jul 10 · Co-develop ✅ Jul 30 · SOAR evaluation
02 · Cadence

Cadence & Ceremonies.

Four-layer cadence: 2-week sprints, monthly co-design, monthly portfolio, quarterly deep dives

Four Layers

Sprint. Co-Design. Portfolio. Deep dive.

01 · Sprint
2-Week Cycle

Execution cadence. Ship code, build agents, deliver results.

PlanningMonday (every 2 weeks)
StandupsMon/Wed/Fri (team only)
Review + RetroFriday (every 2 weeks)
Tony attendsPlanning + Review only
02 · Portfolio
Monthly Review

Show results to executives. Video evidence + working links.

First meetingAug 10 (confirmed)
AttendeesTony, Krishna, Adelina, Nathan, Charlie, Joana + Kush
FormatShow, don't tell (see below)
NotePortfolio/Design layer — monthly cadence
03 · Deep Dive
Quarterly Sessions

In-person design sessions. Strategic alignment + release planning.

Duration~5-7 days
Q3 locationHouston, TX
WithTeam + Ron + key engineers
OutputQuarter release plan
04 · Co-Design
Monthly with Deloitte

Joint design sessions with Deloitte team. Quick status + 2-3 deep dives per session.

CadenceMonthly (schedule 1-2 ahead)
FormatQuick status items + 2-3 deep dives
T&CTony, Charlie, Joana, Victor
DeloitteKush, Krishna, Nathan, Zun/Adelina
First sessionJul 10 ✅ (90 min, virtual)
Next~August (TBD, waiting on Kush's agenda)
Operating Model (Jul 30)
Three-Layer Meeting Structure

Confirmed in the Jul 30 cadence email. Meetings organized in three layers by scope and attendees:

Tactical (weekly)

Delivery teams — Joana, Nathan, Zun, Matthew, Brandon/Marcos. Standup stays weekly (<5 tickets/week volume).

Program (biweekly)

Joana, Charlie, Nathan, Adelina, Zun/Matthew.

Portfolio/Design (monthly)

Tony, Krishna, Adelina, Nathan, Charlie, Joana. Next: Aug 10.

Artifacts
Scrum Artifacts - Warren Delivers
Tony expects Warren to programmatically deliver real-time sprint artifacts. No asking for status - artifacts should be self-service.
ArtifactCadenceDescriptionStatus
Sprint Backlog Updated daily Items committed for current sprint, status, blockers Sprint 2
Burndown Real-time Story points or items remaining vs time Sprint 2
Sprint Review Deck End of sprint Video evidence + working links of shipped work Sprint 2
Definition of Ready Standing Criteria for items entering sprint (see below) Defined
Definition of Done Standing Criteria for items being complete (see below) Defined
Principle
"Show Don't Tell" - What Tony Means

We're moving at 5× traditional speed. Words can't keep up. Ron didn't understand net new revenue agents until the third time Tony explained it - and Ron is the sharpest person in the room. If Ron needs three reps to absorb a verbal summary, everyone else needs more.

The old way (what we stop doing):

  • Verbal status updates: "A.5 is code complete, waiting on merge"
  • Slides with bullet points about progress
  • Written summaries explaining what happened
  • "Technical done" without "business done" evidence

The new way (what every portfolio item needs):

  • Video walkthrough - screen recording of the feature working in production (30-90 sec)
  • Live URL - clickable link where the stakeholder can see it themselves, right now
  • Before/after screenshots - visual proof of what changed
  • Metrics - measurable impact (e.g., "21min per alert → 5min")
Tony's original architecture: Akira AI PMO confirms requirements via video → team builds → confirms results via video. Both ends are visual. If you can't show it working on screen, it's not done enough to present. This applies to everyone - Krishna, Kush, Ron, Forge Point.
Rotation
Proposed Location Rotation (Monthly Portfolio)
MonthLocationNotes
AugustHoustonRescheduling to Aug 6 (tentative)
AugustSan FranciscoKrishna's base
SeptemberAustinTony's base
OctoberLos AngelesCharlie's base

Deep dives aligned with monthly portfolio locations to avoid over-travel (Q3 → Houston, Q4 → Los Angeles).

03 · Team

Team & Hiring.

Current team, Deloitte counterparts, and Value First hiring plan

Current Roster

Six roles. One mission.

Name
Tony
Current Role
Strategic leadership
Evolving To
Product Owner (biweekly)
Sprint Role
Sprint planning + review only
Name
Joana
Current Role
Program delivery
Evolving To
Net new revenue agent design
Sprint Role
Scrum lead + agent designer
Name
Victor
Current Role
Technical delivery
Evolving To
Net new revenue agent design
Sprint Role
Technical lead + agent designer
Name
Charlie
Current Role
Chief Architect / Agent Runtime
Evolving To
Platform + architecture decisions
Sprint Role
Technical advisor
Name
Warren
Current Role
Engineering & Ops AI
Evolving To
Autonomous Delivery Partner
Sprint Role
Delivery method engine, scrum artifacts
Name
Dukane
Current Role
Delivery support
Evolving To
QA manager (#warren-review)
Sprint Role
Output quality review
Deloitte Counterparts

Eight contacts. Joint delivery.

Name
Kush
Role
Strategic leadership, SOC practice lead
Focus
Priority setting, strategic direction, partnership vision
Key Quote
"You guys are phenomenal... the velocity and focus you bring"
Name
Krishna
Role
Delivery/operations lead
Focus
Team goals, resource allocation, tiered SOC model, Teams integration
Sprint 2
Navigating Deloitte IT for Teams company-to-company collaboration
Name
Zun
Role
Technical architect, production go/no-go
Focus
Representing Adelina (maternity leave). Triage agent optimization (15→10 min)
Sprint 2
Providing generalized prompts for Charlie to work on latency
Name
Nathan
Role
Infrastructure & integration specialist
Focus
Joined Feb 2026. Flagged logging gaps & agent failure logs
Sprint 2
Logging/observability improvements
Name
Kishor
Role
SOC for AI development lead (senior)
Focus
Tasked by Krishna for SOC for AI development
Sprint 2
Development work on SOC for AI
Name
Adelina
Role
Operations lead
Focus
Returned from leave. Teams federation (Deloitte side unblocked Aug 4), Bedrock quota, program cadence
Status
Active ✅
Name
Matthew Lew
Role
Technical operations engineer
Focus
MXDR test range, Swimlane workflows, Turbo Mode evaluation
Sprint 3
Turbo Mode deep dive, Swimlane JSON workflow mapping
Name
Rahul
Role
Monitoring operations leader
Focus
L2/L3 teams - digital twin pilot target
Sprint 2
L2/L3 analyst workflows for digital twin
Role Shift: Joana & Victor moving from program delivery (100 installs, training) → net new revenue agent design. Hires will backfill the program delivery gap.
Hiring
Hiring Plan - Value First / Omberto
RoleCountRegionFocusStatus
AI PMO / Soft Skills 1-2 LatAm (preferred) Requirements gathering, stakeholder mgmt, verification Interviewing
Engineer 1-2 Eastern Europe or LatAm MLflow, Kindo agent configuration, integrations Planning

Process: Invoice → Charlie → Ron. Charlie vets technical candidates. LatAm for soft-skills (live meetings), Eastern Europe for code (Charlie's preference).

Jul 8 discussion: Finding resources with AI expertise + complex environment + T&C speed is extremely difficult (Shanzo example - impressed by Kindo's AI use). Charlie's suggestion: hire for training capacity, not existing expertise. Training requires investment but broadens the candidate pool.

Availability
Engineering Availability
TeamStatusExpected BackImpact
Agent Runtime (Madison) Returned ✅ Returned Back and active. Multi-agent, agent features unblocking.
Agent Runtime (Sean) Returned ✅ Returned week of Jul 7 Returned. Ramped back up.
Core Kindo (Brian Van) PTO Mid-July (expected) Core platform changes blocked - expected back during Sprint 2
Charlie (Agent Runtime lead) Active - Shipping memory, system prompts, trace export. High velocity.

Sprint 2 implication: Madison and Sean returned ✅. Brian Van expected mid-July. More code work possible this sprint. Engineering-dependent items now feasible.

04 · Portfolio

Portfolio Status.

Agent portfolio - SOC for AI POC delivered, expanding across three pillars

Post-POC

POC delivered. Expanding across three pillars.

Jul 10 Outcome: POC well received. Kush: "you guys are phenomenal." All 5 governance objectives confirmed. Krishna proposed tiered model: Basic (detect + respond post-action) → Standard → Elite (preventative blocking). CrowdStrike analogy - menu of discovery options, not one-size-fits-all.
Status Map
Agent Status Map
IDAgentStatusRevenue ClassBlocker
A.1Threat Monitoring PROD Contracted-
A.2Threat Intel PROD Contracted-
A.3Threat Hunt PROD Contracted-
A.4Detection Engineering PROD Contracted-
A.5CTEM BUILT ContractedDeployment pending
A.6Vitals Dashboard DEPRIORITIZED AllianceKush shifted to SOC for AI
A.7Quality Audit Agent CO-DESIGN AllianceDigital twin approach - L2/L3 first use case
A.8Cloud Security Agent PLANNED Alliance-
A.9IR Agent PLANNED Alliance-
A.10IoT/OT Monitor DEPRIORITIZED AllianceKush shifted to SOC for AI
A.11Custom Client Agents REQS AllianceShadow & document method
A.12Identity Agent → IdaaS PLANNED AllianceTim Corder engagement
A.13GRC Agent → GRC aaS PLANNED AllianceNathan Ellis engagement
NEWSOC for AI EXPANDING AllianceKrishna: “I can see us taking this to clients”
NEWSOAR/Swimlane Replacement (Turbo Mode) EVALUATING AllianceAlpha in Aug. Nov decision deadline.
SOC for AI
Three-Pillar Discovery Framework

Charlie's framework (confirmed by Kush/Krishna Jul 10). Three pillars of AI SOC discovery. Sprint 2 focus: Pillar 1 deep dive (Anthropic + Azure Foundry). Pillars 2 & 3 moved to research - Pillar 2 gated on positioning decision, Pillar 3 requires Deloitte SME guidance.

Pillar 1 - Platform Integrations

Reach into Anthropic, Azure Foundry, Copilot, ServiceNow etc. API-level interrogation of AI platforms to audit agent usage, models, and configuration.

Pillar 2 - LLM Gateway / Choke Point

Kindo as inference proxy (2 lines of code to redirect). LLM is the firewall. Agents inside vs outside org walls. Kush's philosophy: the choke point IS the governance layer.

Pillar 3 - Network/Endpoint Monitoring

Sweep for shadow AI (long tail). Network and endpoint-level discovery of unauthorized AI usage beyond managed platforms.

Krishna's tiered model: Basic (detect + respond post-action) → Standard → Elite/Advanced (preventative blocking). First version: "less intrusive" - detection and response post-action.

Jul 10 Confirmed
5 Objectives - All Confirmed by Deloitte

All 5 governance objectives confirmed at Jul 10 co-design session. Kush, Krishna, Nathan asked detailed technical questions.

#Deloitte ObjectivePOC StatusJul 10 Status
1Unauthorized agent deploymentCovered✅ Confirmed
2Unauthorized tool/data connectionsCovered✅ Confirmed
3Agent action drift vs SOPsGap✅ Confirmed - biggest eng need
4Guardrail/policy changesPartial✅ Confirmed
5Multi-tenant data breachPartial✅ Confirmed

Strategic Position (Jul 10)

Kush/Krishna confirmed alignment with co-develop model. Tiered model (Basic/Standard/Elite) - CrowdStrike analogy. Menu of discovery options. Post-discovery actions platform-dependent, policy-driven (remediate, notify, or block). Need platform compatibility matrix.

Strategic Framing (Jul 10)
Kindo's Three-Standard Strategy

Charlie's follow-up email to Deloitte team (Jul 10) - Kindo reaches governance outcomes on three existing open standards, no proprietary protocol adoption required.

Standard 1 - Inference APIs (Live Today)

Chat Completions, Responses, Messages, Models. 2 lines of config to route Claude Code / Copilot / agents through Kindo. Demo →

Standard 2 - Tools / Federated MCP Gateway (Live Today)

Single governed endpoint for tool/integration access. Federated MCP gateway provides real-time control over agent tool use.

Standard 3 - Telemetry / OpenTelemetry (Landing Now)

OTLP-based. Two directions: (a) customers route Kindo agent traces to their own backend (per-org isolated), (b) Kindo ingests OTel from third-party agents/apps (Claude Desktop, etc.). Foundation for LLM-as-judge, evals, self-improvement.

Tier Mapping via Open Standards

Elite Gateway position (inference + MCP) = real-time preventative control
Basic Telemetry / discovery only = after-the-fact detect-and-respond
💡 Open standards = low adoption cost → gateway position is cheap and reversible (answers "customers worry about choke point")
Revenue
Revenue Classification
$5.5M
Contracted (A.1-A.5)
$1-2M+
Alliance Net New (A.6-A.13)
$5-12M+
Upside (2-3× Expansion)
05 · Deep Dives

Deep Dive Design Sessions.

Quarterly in-person sessions + monthly co-design with Deloitte

Quarterly + Monthly

In-person quarterly. Virtual monthly. Co-design.

Origin: Tony proposed quarterly deep dives 6 months ago - modeled after what he and Ron did independently in December (7 days of uninterrupted deep thinking). Deloitte "wholeheartedly agreed" at the June 22 meeting. Monthly co-design sessions added Jul 10 (Krishna's suggestion).
Topics
Deep Dive Topics (from Deloitte meetings)

These items were categorized under "design sessions" in Tony's meeting notes. Updated with Jul 10 co-design outcomes.

#TopicDescriptionOwner
1 Net New Revenue Agents Design + deploy agents that generate alliance revenue (Tier 2/3 packages) Tony / Joana
2 Threat Remediation Extend A.1-A.5 into automated remediation workflows Charlie / Victor
3 Deloitte Roadmap (Azure/GCP) Cloud platform alignment and multi-cloud strategy Charlie
4 Institutional Knowledge / Memory Skills, memory, compound learning flywheel. Don't equip Deloitte to build what we want to build (Charlie) Charlie
5 AI Cyber Guard / Tower Control plane co-development. Evan building on AWS: unify policy, enforcement, observability, guardrails Charlie
6 Lifecycle Hooks Generic lifecycle hooks - Kush says yes but NOT most important. Ship fast MVP, don't over-engineer. Charlie
7 Workflow Acceleration Accelerate deployment cycle (time-to-value for new Kindo customers) Victor / Joana
8 SOC for AI Three-pillar discovery, AI governance, platform compatibility matrix Joana / Victor
9 Agent Discovery Choke Points LLM gateway as firewall. Agent telemetry open standard. Kush's philosophy from Jul 10. Charlie / Kush
10 AI Cyber Guard Convergence Evan's AWS-based AI Cyber Guard (4 problem statements: unify policy, enforcement, observability, guardrails). Open standard for agent telemetry. Charlie / Evan
Calendar
Design Session Calendar

Kush Design Session - Friday, July 10 ✅ Completed

90 min, virtual. SOC for AI POC demo. Three-pillar framework confirmed. Digital twin pivoted to L2/L3 analysts. Tiered SOC model (Basic/Standard/Elite). Co-design cadence open (biweekly vs monthly TBD - needs Tony input). Teams integration Step 0 initiated. Triage agent 15→10 min, sub-agent split considered.

Outcomes: Three pillars confirmed · Digital twin → L2/L3 · Tiered SOC model · Co-design cadence open (biweekly vs monthly TBD) · Teams integration Step 0 · No data lake (Kush) · Platform compatibility matrix needed · Evan's AI Cyber Guard noted · On-prem "very close" (Krishna)

Co-Design Session #2 — July 30 ✅ Completed

90 min, virtual. SOAR/Swimlane replacement moved from hypothetical to active evaluation. Charlie demoed Turbo Mode — Krishna and Adelina responded positively. Swimlane decision deadline confirmed: end of November (90-day notice before Feb renewal). Teams federation confirmed over Slack. Weekly standup stays weekly. Three-layer meeting cadence established (Tactical/Program/Portfolio).

Outcomes: Turbo Mode alpha committed (August) · Swimlane Nov deadline · Teams > Slack ("hell no" from Deloitte) · SOAR scope = detection + triage only (not response-side) · Krishna: "We don't have to do it the exact same way" (80-90% coverage) · Case management = historical record search · Adelina back + engaged · Three EBITDA vectors identified (SaaS fees, playbook labor, triage labor)

SOC for AI Session — TBD (Before or After Aug 10 Portfolio)

Decision needed: Schedule dedicated SOC for AI deep dive with Deloitte before or after the Aug 10 portfolio meeting. From Jul 30 session — Krishna expressed excitement about SOC for AI + Telemetry convergence: "I can see us taking this to clients." Session should cover: SOC for AI expansion across three pillars, telemetry/observability integration with new Kindo infrastructure, and agent health monitoring (Adelina's ask).

Prep needed: SOC for AI + Telemetry demo (working prototype exists) · Platform compatibility matrix update · Agent health monitoring proposal (Adelina's request) · Heterogeneous AI governance story (not just Kindo-native) · Positioning: Kindo as agentic gateway to monitor all AI

Q3 2026 - First In-Person Deep Dive

Houston, TX. 5-7 day in-person session. Team + Ron + key engineers. Output: Q3 release plan, SOC for AI architecture, net new revenue agent designs.

Q4 2026 - Second Deep Dive

Los Angeles, CA - aligned with October monthly portfolio (Charlie's base). Review Q3 results, plan Q4 releases, expand to service lines beyond D&RaaS (Identity aaS, GRC aaS).

06 · Sprint 1

Sprint 1 - June 29 → July 10.

Day 10/10 - Demo Day. Nine items delivered. SOC for AI POC built and tested - first run scored 3.8/10 with real findings. Cross-platform AI orchestration demonstrated. Co-develop story ready for Kush.

✅ Sprint 1 Complete

9 items delivered. SOC for AI POC built and demoed. Jul 10 co-design session held with Kush, Krishna, Nathan, Zun. All 5 governance objectives confirmed. Three-pillar discovery framework established. Digital twin pivoted to L2/L3 analysts. Co-design cadence open - Joana suggested biweekly (sprint-aligned), Krishna suggested monthly. Left open Jul 10. Needs Tony input. Next session ~2 weeks (Jul 25).

Sprint Goal

POC built. IK shipping. Demo day.

Sprint Goal
Deliver SOC for AI POC → Demo Cross-Platform AI Orchestration → Tell Co-Develop Story

Jul 8 pivot: Charlie directed POC to demonstrate Kindo orchestrating across external AI platforms (Anthropic, OpenAI, Copilot), not just Kindo-internal governance. POC has two components: (1) Kindo-native agent governance monitoring, (2) cross-platform AI interrogation. Additionally, Charlie is shipping memory, agent-editable system prompts, and trace export - the foundational capabilities for institutional knowledge. Friday demo tells the co-develop story: SME digital twin → institutional knowledge → Kindo platform features.

Backlog
Proposed Sprint 1 Backlog
ItemTypeOwnerEffortDependencies / Risks
SOC for AI - Cross-Platform POC
Build POC on Kindo SaaS demonstrating two capabilities: (1) Kindo-native governance agent (drift detection, policy monitoring), (2) Cross-platform AI interrogation - Kindo agent connects to Anthropic/OpenAI/Copilot to check agent usage, models, and configuration. Charlie's direction: prove Kindo can orchestrate SOC for AI across heterogeneous AI environments. Agent export/import available via Yash's portability feature.
P0 Victor + Warren 2d Built ✅
Triggered Agent on Kindo SaaS. First run: governance report covering all 5 objectives, scored 3.8/10 🔴. Real findings. Enterprise access resolved (Hannah). Demo ready.
SOC for AI - Audit Surface Map
Map Kindo's current audit logs, telemetry, RBAC, DLP, MCP policies against Deloitte's 5 governance objectives. Deliver before Friday requirements call.
P0 Warren + Victor 1d Done ✅
SOC for AI - Requirements Questionnaire → Krishna
Generate SOC for AI questionnaire (same format as A.6). Send to Krishna who routes to right person.
P0 Tony + Joana + Warren 0.5d Done + Sent
SOC for AI - Detection Rule Library
Define detection rules mapping each of Deloitte's 5 objectives to specific Kindo audit events and API endpoints.
P1 Warren + Victor 2d Carries to Sprint 2
Refining post Jul 10 feedback.
Sprint 1 Meta-Risk: Eng team returning. Sprint 1 focused on soft-skills + POC build. Engineering-dependent items (drift detection, tenant monitoring) slot into Sprint 2. But if eng comes back mid-sprint and unblocks code work, do NOT mid-sprint pivot. Finish what we committed to. New engineering items go into Sprint 2 backlog.
Delivery Method Alignment: Every Sprint 1 item must map to the Deterministic Outcome Package - (1) Named Owner, (2) Transcript/Intake Artifact, (3) Standing Rules, (4) Cron-Sustained Refresh, (5) Recipient's Narrative. Evidence Base 85% pattern applies: named human owner + same-day delivery + output in recipient's language.
Exit Criteria
Sprint 1 Exit Criteria

Show-don't-tell: every criterion needs evidence, not a status update.

  • Audit Surface Map delivered before Friday call → deliverable: capability matrix (5 objectives × Kindo audit surface)
  • Detection rule templates drafted → deliverable: rule definitions + API endpoint mappings
  • Friday requirements call completed with Krishna's team → deliverable: refined scope + Sprint 2 plan
  • Warren delivering sprint status automatically → deliverable: live sprint dashboard URL
Out of Scope
Sprint 1 - NOT In Scope
  • Code shipping to Kindo platform (eng on PTO) - Sprint 2 when team returns
  • Core platform changes (Brian's team required) - blocked, not our call
  • A.6 Vitals Dashboard (deprioritized by Kush) - parked
  • Scaling Story for Ron (important but not SOC for AI) - separate workstream, not sprint backlog
  • A.7 Quality Audit design sprint (depends on Krishna scheduling) - backlog, not Sprint 1
  • Hiring decisions (interviews in progress) - parallel track
Definition of Ready
DoR - Entry Criteria

An item can enter the sprint when ALL of these are true:

#CriteriaWhy
1Clear outcome defined - what does "done" look like in business terms, not technical terms?Victor's point: business value, not technical value
2Owner assigned - single person accountableNo orphan items
3Dependencies identified - blocked/unblocked explicitly taggedVictor's framework: shoot where we're unblocked
4Effort estimated - days, not points. Be honest.Tony needs to know what to expect without asking
5Classified soft-skill vs code - which work type? Determines who can execute.~80% soft-skills moves without Brian's team
6Passes tenant filter (if integration) - tenant-scoped? data stays in tenant? SOC 2 II / BAA / DLP?Tony's note #1: "Deloitte only"
7Fits the sprint - total committed work ≤ team capacityDon't overcommit then under-deliver
8Acceptance criteria written - how will we verify it's done?"Show don't tell" starts here
Definition of Done
DoD - Completion Criteria

An item is done when ALL of these are true:

#CriteriaEvidence Required
1Acceptance criteria met - every criterion checked off with proofScreenshots, video, or live URL
2Business done, not just technical done - stakeholder can see and use itWorking link or deployed artifact
3Evidence attached - "show don't tell" proof in the same message as the completion claimVideo walkthrough, screen recording, API response
4Integrations pass tenant + compliance checkTenant filter results documented
5No open blockers or regressionsVerification report
6Reviewed - at least one other team member has seen the outputReviewer name + feedback
7Documented so Warren can report statusWarren updates programmatically
8Owner confirmed doneExplicit sign-off
Hard rule: "Code complete" ≠ done. "Waiting on merge" ≠ done. "I verified" without the actual evidence ≠ done. If you can't show it on screen, it's not done.
07 · Sprint 2 ✓

Sprint 2 - July 13 → July 25.

Sprint 2 complete. Agent telemetry prototype, platform matrix, and gateway architecture delivered. Discovery menu and OTel proposal in progress. Co-design items staged for Jul 30.

✅ Sprint 2 Complete

3 items delivered (Agent Telemetry prototype, Platform Compatibility Matrix, Gateway Architecture). 2 in progress. 4 awaiting co-design. Jul 30 design session held — SOAR/Swimlane replacement moved from hypothetical to active evaluation, Turbo Mode alpha committed for August, Teams federation decision confirmed. See Sprint 3 →

Sprint 2 Outcome

Built what we could advance autonomously. Jul 30: build together.

Sprint Goal
What Deloitte Gets at Sprint 2 End (Jul 25)

A working demo where Kindo discovers agents across Anthropic + Azure Foundry, takes a real action (notify non-compliance), and a CrowdStrike-style menu of 5–10 discovery methods Krishna can present to clients with “which approach fits your environment.” That's the show-don't-tell for the next co-design session.

Three deliverables:

  1. POC that discovers AND acts — not just “we found 286 agents” but “we found a non-compliant agent and notified the author.” Full loop on at least one platform.
  2. Discovery Menu of Options — Krishna's direct ask. The deliverable he takes to clients: “here are your 5–10 options for finding agents, here are the tradeoffs per company type.” This is the CrowdStrike analogy he kept referencing.
  3. Platform Compatibility Matrix — the evidence backing the Menu. Internal, but what gives the Menu credibility.
Critical Path
Dependency Chain — Matrix Is the Bottleneck
Platform Matrix (Victor+Charlie, 2d)
 ├──→ Discovery Menu (Joana+Charlie, 2d) — BLOCKED until Matrix done
 └──→ Pillar 1 Deep Dive (Victor+Warren, 3d) — runs parallel
           └──→ Discover→Act Loop (Victor+Warren, 1d) — BLOCKED until Pillar 1 has Foundry working

Matrix is the bottleneck.

It feeds both the Menu and validates which platforms the Act Loop can target. Victor + Charlie need to start here Day 1.

Everything else (triage optimization, A7 scoping, Copilot/ServiceNow, logging) is off the critical path — nice to have in Sprint 2 but won't make or break the co-design demo.

Two external blockers that could slip the path:

  • Foundry API access/credentials — if we don't have them, Pillar 1 shrinks to “Anthropic depth only”
  • Charlie's bandwidth — he's on Matrix, Menu (technical validation), AND runtime team items. If runtime work (triage, logging) competes, the critical path items must win
Backlog
Sprint 2 Backlog
ItemTypeOwnerEffortRisks / DependenciesStatus
SOC for AI - Pillar 1 Deep Dive (Platform Integrations + Foundry)
Deepen POC on platform integrations pillar. Add Azure Foundry interrogation alongside existing Anthropic. Demonstrate discovery + act loop on at least one platform. Pillars 2 (gateway) and 3 (network/endpoint) moved to research - Pillar 3 is greenfield requiring Deloitte SME guidance, Pillar 2 gated on positioning decision.
P0 Victor + Warren 3d Foundry API access/credentials needed. Depends on Act Loop item for full demo story. Prototype ✅
Platform Compatibility Matrix
Internal source-of-truth grid: per platform (Anthropic, Foundry, Copilot, ServiceNow, Bedrock...), what's discoverable and what actions the API supports (remediate/notify/block), and whether real-time or after-the-fact. Feeds the Discovery Menu of Options. Not a Deloitte deliverable - this is the evidence that backs the Menu.
P0 Victor + Charlie 2d Risk: Some platform APIs may have undocumented limitations. Requires hands-on probing, not just docs review. Blocker for Menu. Complete ✅
SOC for AI - Discovery Menu of Options (CrowdStrike Model)
Krishna-facing deliverable: 5-10 discovery methods for finding agents across enterprise environments (platform API, gateway/choke point, network/endpoint sweep, central registry, etc.), each with pros/cons per company type and network disposition. Modeled on CrowdStrike's '5 ways to discover endpoints' approach. Derives from the Platform Compatibility Matrix - Matrix is the input, Menu is the synthesis. Low engineering lift, high strategic value.
P0 Joana + Charlie 2d Unblocked: Platform Compatibility Matrix complete. Tier mapping in progress. Charlie availability for technical validation. In Progress
SOC for AI - Discover→Act Loop (Single Platform Demo)
Krishna asked directly: 'once you discover an agent, what can you do?' Current POC demonstrates discovery only. This item adds a real remediation action to the POC on a single platform (e.g., notify agent author of non-compliance via Anthropic API). Proves the full loop: discover → assess → act.
P0 Victor + Warren 1d LLM judges in prototype address assess step. Full act loop deferred to co-design input on platform priority. Co-Design
Triage Agent Optimization Work Session
Zun provides generalized (sanitized) prompts. Charlie + runtime team analyze latency independently. Goal: sub-10 min. Consider splitting into basic triage + advanced investigation sub-agents. Kindo runtime team scope - requires agent runtime engineering.
P1 Charlie + Runtime Team 2d Requires work session with Zun. Ready to schedule when timing works for Deloitte team. Awaiting Co-Design
A7 Quality Audit - Design & Scoping Only
Digital twin approach for weekly ticket audit - design phase only. L2/L3 analyst collaboration requires Teams integration (Step 0 + Step 1), currently blocked on Deloitte IT approval. Sprint 2 scope: define ABC grading criteria, map audit workflow, identify pilot candidates. 60% subjective scoring problem still unanswered - needs dedicated research. Full collaboration blocked on Teams.
P1 Joana + Victor 1d Depends on digital twin approach + design session with Krishna's team. Ready to co-design in Sprint 3. Awaiting Co-Design
SOC for AI - Copilot & ServiceNow Interrogation
Extend discovery to Copilot and ServiceNow platforms. Scope boundary: Pillar 1 Deep Dive covers Anthropic + Azure Foundry depth; this item covers Copilot + ServiceNow breadth. OpenAI removed from scope (not relevant to Deloitte's environment - theirs is Anthropic, Foundry, Bedrock, ServiceNow, Copilot).
P1 Victor 2d Covered in Platform Compatibility Matrix research. 5 platforms analyzed with capability mapping and license gates. In Matrix ✅
Logging/Observability Gap Analysis
Nathan/Zun flagged agent failure logs missing for troubleshooting. Context compaction being fixed in upcoming release (Mo confirmed). Assess current gaps. Kindo runtime team scope - platform-level logging requires agent runtime engineering.
P2 Charlie + Runtime Team 1d Depends: Runtime team capacity (Madison/Sean ramping). Brian Van PTO (mid-July). May slip if higher-priority runtime work (triage optimization) takes precedence. Sprint 2
Pillar 2 - Gateway/Shim Scoping & Design
Kush explicitly endorsed Kindo as gateway shim (Jul 16 email: “I would like to explore inserting Kindo as a shim to be the gateway to encore controls and gather telemetry”). Scope: architecture doc for Pillar 2 gateway positioning — inference proxy + MCP + telemetry. Deliverable for August co-design session. Gate unblocked by Kush’s endorsement.
P1 Charlie + Victor 2d Three open standards documented. Kush endorsed gateway approach. Architecture ready for collaborative refinement. Complete ✅
Agent Telemetry — Native Pillar Strategy + OTel/MLflow Architecture
Charlie’s strategic proposal (Jul 20): adopt MLflow headless + multi-tenant inside Kindo as native agent analytics — traces, LLM judges, sampling/retention/compliance. Working prototype demonstrated. Strategic fork: host telemetry natively vs. export to external tools (Galileo, Braintrust, Arize, LangFuse, Datadog). Completing the Inference + Tools + Telemetry trifecta positions Kindo to manage entire AI deployments, not just native agents. Kush aligned on both trace types. Two open Kush questions remain: (1) hook into existing customer MLflow equivalents, (2) non-Kindo agents tracing directly vs through Kindo. Resourcing gate: major surface-area expansion comparable to Sandboxes — requires minimum one dedicated engineer (effectively permanent). Charlie recommends locking execution + resourcing plan before bringing to wider engineering team.
P1 Charlie 2d Working prototype demonstrated. Trace export, LLM judges, eval configuration, span detail, error diagnostics. Strategy + resourcing decision required before wider team rollout. Prototype ✅
Telemetry Storage/Retention Architecture
Define the two levers Charlie described (retention duration + sampling fraction) as concrete, customer-facing controls. Document cost model so Deloitte can present storage as “a dial, not an open-ended liability.” Feeds into MLflow architecture doc.
P2 Charlie 1d Included in OTel/MLflow two-tier proposal. Validated in development environment. In OTel Proposal
✅ GATE SIGNAL: Kindo Positioning - Gateway/Shim Endorsed by Kush (Jul 16). Kush wrote: “I would like to explore inserting Kindo as a shim to be the gateway to encore controls and gather telemetry.” This is Deloitte’s buyer explicitly requesting the gateway approach. Tony + Charlie to confirm as official T&C position. If confirmed → Pillar 2 moves from research to active scoping this sprint. Architecture doc (not full build) is the Sprint 2 deliverable.
📊 GATE SIGNAL: Agent Telemetry — Native Pillar Proposal (Charlie, Jul 20). Charlie shared working prototype + strategic proposal: adopt MLflow headless multi-tenant as native Kindo analytics. Completes the Inference + Tools + Telemetry trifecta. Honest cost: major surface-area expansion comparable to Sandboxes. Minimum one dedicated engineer required (permanent). Charlie’s recommendation: lock strategy, governance requirements, and end-user product shape → work through execution + resourcing plan → then bring to wider engineering with plan attached. Presentation video · Slides · Raw demo
Pillars 2 & 3 - Updated Direction: Pillar 2 (LLM gateway/choke point) — Kush endorsed gateway approach Jul 16. Scoping & architecture doc added to Sprint 2. Pillar 3 (network/endpoint monitoring) remains greenfield requiring Deloitte SME guidance — research track only.
Sprint 2 Meta: Engineering team (Madison, Sean) returned ✅. Brian Van expected mid-July. More code work possible this sprint. Engineering-dependent items now feasible.
Definition of Ready
DoR - Entry Criteria

Same criteria as Sprint 1 (see Sprint 1 tab for full details):

  • Clear outcome defined (business terms)
  • Owner assigned
  • Dependencies identified
  • Effort estimated (days)
  • Classified soft-skill vs code
  • Passes tenant filter (if integration)
  • Fits the sprint
  • Acceptance criteria written
Definition of Done
DoD - Completion Criteria

Same criteria as Sprint 1 (see Sprint 1 tab for full details):

  • Acceptance criteria met with proof
  • Business done, not just technical done
  • Evidence attached (video, screenshots, URLs)
  • Integrations pass tenant + compliance check
  • No open blockers or regressions
  • Reviewed by another team member
  • Documented for Warren to report
  • Owner confirmed done
08 · Sprint 3

Sprint 3 - August 5 → August 18.

Day 1 of 10. SOAR/Swimlane replacement evaluation, Turbo Mode SaaS alpha, Teams federation completion, and the Aug 10 portfolio presentation to Krishna + Kush.

Sprint 3 Focus

Turbo Mode alpha. SOAR evaluation. Aug 10 portfolio.

Sprint Goal
What Deloitte Gets at Sprint 3 End (Aug 18)

Turbo Mode SaaS alpha access for Deloitte to evaluate as a Swimlane replacement, a Swimlane workflow import proving Turbo Mode covers the core detection + triage automation, and a portfolio-ready SOC for AI + Telemetry demo with an EBITDA case for the SOAR replacement. The Aug 10 portfolio meeting with Krishna + Kush is the show-don't-tell milestone.

Backlog
Sprint 3 Backlog
ItemTypeOwnerEffortStatus
Turbo Mode SaaS Alpha Access
Provision Turbo Mode SaaS alpha access for Deloitte to evaluate. Charlie committed August timeline. Foundation for SOAR/Swimlane replacement evaluation.
P0 Charlie 3w In Progress
Swimlane Workflow JSON Import + POV
Zun to share Swimlane JSON workflows. Charlie to import and build against them in Turbo Mode, proving coverage of the detection + triage requirements. Turbo Mode currently handles 5 of 10 requirements.
P0 Charlie + Zun 2w Waiting on Zun
SOC for AI + Telemetry Portfolio Presentation
Portfolio-ready demo for Aug 10 meeting with Krishna + Kush. SOC for AI expanding, Krishna: “I can see us taking this to clients.” Convergence with agent telemetry work.
P0 Joana + Charlie Aug 10 Planning
Teams Federation Completion
Deloitte side exclusion added (Adelina confirmed Aug 4). Complete T&C/Kindo side integration. Slack confirmed dead — Teams federation is the path.
P1 Joana + Ken Aug Unblocked
Case Management Scoping
Historical record search for ticket correlation (Zun requirement). Not just ticket management — correlation across historical case records.
P1 Charlie 1w Scoping
Multi-Tenancy Architecture
Design for separating clients within a shared tenant. Supports SOAR replacement and portfolio-wide deployment model.
P1 Charlie 1w Scoping
SOAR EBITDA Analysis for Portfolio
EBITDA case for the SOAR/Swimlane replacement across three vectors: SaaS fee replacement, manual playbook labor, manual triage labor. For Aug 10 portfolio meeting.
P1 Tony + Joana Aug 10 Planning
SOC for AI Session with Deloitte
Dedicated SOC for AI deep dive with Deloitte — from Jul 30 session, Krishna: “I can see us taking this to clients.” Decision needed: schedule before or after Aug 10 portfolio meeting. Prep: SOC for AI + Telemetry demo (prototype exists), platform compatibility matrix update, agent health monitoring proposal (Adelina’s request), heterogeneous AI governance story.
P1 Joana TBD Needs Scheduling
QA/Account Manager Role Definition
Value First hires positioned as technical QA bridging Deloitte↔Kindo engineering. Technical background required. Ongoing hiring track.
P2 Joana + Victor ongoing Hiring
Turbo Mode Visual Diagram View
Visual diagram view for Turbo Mode workflows — aids Swimlane comparison and portfolio presentation.
P2 Charlie 1w Planned
SOAR scope: Detection + triage automation only, not response-side. Krishna: “We don't have to do it the exact same way we did with Swimlane” — target 80-90% capability coverage. Swimlane decision deadline end of November (90-day notice before Feb renewal).
Definition of Ready
DoR - Entry Criteria

Same criteria as Sprint 1 (see Sprint 1 tab for full details):

  • Clear outcome defined (business terms)
  • Owner assigned
  • Dependencies identified
  • Effort estimated (days)
  • Classified soft-skill vs code
  • Passes tenant filter (if integration)
  • Fits the sprint
  • Acceptance criteria written
Definition of Done
DoD - Completion Criteria

Same criteria as Sprint 1 (see Sprint 1 tab for full details):

  • Acceptance criteria met with proof
  • Business done, not just technical done
  • Evidence attached (video, screenshots, URLs)
  • Integrations pass tenant + compliance check
  • No open blockers or regressions
  • Reviewed by another team member
  • Documented for Warren to report
  • Owner confirmed done
09 · Product Backlog

Product Backlog.

Items that produce a built artifact (agent, integration, code in Kindo) - ranked by strategic priority

Ranked by Impact

Pillar 1 deep dive first. Then digital twin. Then net new revenue.

Prioritization framework: SOC for AI three-pillar expansion is #1 (Kush mandate + Jul 10 confirmation). Then digital twin / triage optimization. Then net new revenue agents (alliance revenue). Then contracted platform work. Unblocked items before blocked items (self-unblocking bias).
P0 - Must Do Now 6 items
SOAR/Swimlane Replacement - Turbo Mode
Evaluate Turbo Mode as a Swimlane replacement. Scope: detection + triage automation only (not response-side). Zun shares Swimlane JSON workflows; Charlie imports and builds against them. Turbo Mode currently handles 5 of 10 requirements. Three EBITDA vectors: SaaS fee replacement, manual playbook labor, manual triage labor. Swimlane decision deadline end of Nov (90-day notice before Feb renewal).
Turbo Mode SOAR Sprint 3
SOC for AI - Pillar 1 Deep Dive (Platform Integrations + Foundry)
Deepen POC on platform integrations pillar. Add Azure Foundry interrogation alongside existing Anthropic. Demonstrate discovery + act loop on at least one platform. Pillars 2 (gateway) and 3 (network/endpoint) moved to research - Pillar 3 is greenfield requiring Deloitte SME guidance, Pillar 2 gated on positioning decision.
Pillar 1 SOC for AI Sprint 2
Platform Compatibility Matrix for SOC Discovery
Internal source-of-truth grid: per platform, what's discoverable and what actions the API supports (remediate/notify/block), real-time or after-the-fact. Feeds the Discovery Menu of Options. Not a Deloitte deliverable - the evidence that backs the Menu.
Matrix SOC for AI Sprint 2
SOC for AI - Cross-Platform POC
Build on Kindo SaaS: (1) Kindo-native governance agent for drift detection and policy monitoring, (2) Cross-platform AI interrogation - Kindo agent connects to Anthropic/OpenAI/Copilot to audit agent usage, model versions, and unauthorized models.
POC Cross-Platform Delivered ✅ - Expanding
Sprint 1: Victor built Triggered Agent on Kindo SaaS. First run: full governance report, 3.8/10 score, real findings. Sprint 2: extending to Copilot + ServiceNow platforms.
SOC for AI - Discovery Menu of Options (CrowdStrike Model)
Krishna-facing deliverable: 5-10 discovery methods with pros/cons per company type and network disposition. Derives from the Platform Compatibility Matrix (Matrix = input, Menu = synthesis). CrowdStrike '5 ways to discover endpoints' model.
Product SOC for AI Sprint 2
SOC for AI - Discover→Act Loop (Single Platform Demo)
Krishna asked directly: 'once you discover an agent, what can you do?' Current POC demonstrates discovery only. This item adds a real remediation action on a single platform (e.g., notify agent author of non-compliance via Anthropic API). Proves the full loop: discover → assess → act.
Act Loop SOC for AI Sprint 2
P1 - High Priority 8 items
Digital Twin L2/L3 Analyst Pilot
Krishna's redirect from Zun clone → L2/L3 analyst clones. Use cases: consistent triage quality, detection rule tuning (Splunk/Google SecOps/Palo Alto XSIAM). Prerequisite: Teams integration (Step 0 + Step 1).
Digital Twin L2/L3 Sprint 2
Teams Integration - Company-to-Company Collaboration
Step 0 complete: Charlie provided tenant ID + setup instructions to Krishna (Jul 10 meeting). Now blocked on Deloitte corporate IT approval for company-to-company Teams collaboration. Step 1: Pilot with L2 channel. Prerequisite for digital twin bot. Not in sprint - ball is with Deloitte.
Teams Integration Sprint 2
Triage Agent Sub-Agent Architecture
Zun reduced 15 min → 10 min. Considering splitting into basic triage + advanced investigation sub-agents. Work session with Charlie needed. Zun to provide generalized (non-client-specific) prompts.
Triage Optimization Sprint 2
A.7 Quality Audit Agent - Digital Twin Approach
Krishna redirected to digital twin approach. A7 = weekly ticket audit, ABC grading, 60% subjective / 40% written criteria. Digital twin handles subjective portion. First use case: L2 analysts via active Teams collaboration.
Agent Design Digital Twin Sprint 2
SOC for AI - Detection Rule Library
Refine detection rules post Jul 10 feedback. Update mappings based on three-pillar framework and tiered model. Target: deliverable for Krishna's SIEM team.
Detection Rules API Mapping Sprint 2
A.11 Custom Client Agents - Shadow & Document
Option 2: Warren ingests SOPs + ride-along with analysts. Capture institutional knowledge for custom agent patterns. Start with HP deployment patterns.
IK Capture Victor Depends: analyst access
A.5 CTEM - Production Deployment
CTEM is built, needs deployment. Eng team returning - should be first code ship.
Deployment Eng returning
Institutional Knowledge - Kindo Platform Capabilities
Charlie shipping 3 foundational IK features on Kindo: (1) Memory system (OpenClaw long memory, alpha Jul 8), (2) Agent-editable system prompts (Jul 8-9), (3) Agent run trace export to MLflow (self-serve). Next step: make trace data readable back by agents.
Platform Charlie Shipping
P2 - Medium Priority 7 items
SOC for AI - Pillars 2 & 3 - Research & Direction
Pillar 2 (LLM gateway/choke point): Kindo as inference proxy. Gated on positioning decision (platform vs backbone). Charlie's Jul 10 email positions gateway as 'cheap and reversible.' Pillar 3 (network/endpoint monitoring): Greenfield requiring Deloitte SME guidance. Both are research tracks, not committed builds.
Research SOC for AI Gated: Positioning Decision
MS Defender for Endpoint Integration (SOC for AI)
New integration needed. Shadow AI discovery via "Agent 365" (May 2026). Critical for enterprise customers. Tenant-scoped.
Integration Engineering Eng returning
AI Cyber Guard Convergence Research
Evan building AI Cyber Guard on AWS: 4 problem statements - unify policy, enforcement, observability, guardrails. Open standard for agent telemetry. Research convergence with Kindo's SOC for AI direction.
Research Evan AWS
Agent Telemetry Open Standard Research
Kush mentioned open standard for agent telemetry. Agents inside vs outside org walls. Research existing standards and Kindo's position.
Research Standards
Logging/Observability Gap Analysis
Nathan/Zun flagged agent failure logs missing for troubleshooting. Context compaction being fixed in upcoming release (Mo confirmed). Kindo runtime team scope.
Observability Charlie + Runtime Team Sprint 2
OpenTelemetry Integration + MLflow Observability Platform
Kindo ingests OTel from third-party agents/apps (Claude Desktop, etc.) for unified observability. Charlie proposed MLflow as observability engine (Jul 16). Kush aligned on both trace types flowing through Kindo. Two tiers: (1) export OTel to customer's platform, (2) Kindo-native MLflow with multi-tenant isolation. Kush's open questions: existing MLflow integration patterns + direct-to-MLflow vs through-Kindo tradeoffs. Charlie has working prototypes; internal alpha underway.
Owner: Charlie · Kush actively engaged (Jul 16 email) · Prototypes exist
Telemetry OpenTelemetry MLflow Kush Engaged - Sprint 2 Design
A.8 Cloud Security Agent - Requirements
Kush's Deloitte roadmap includes Azure/GCP alignment. Design cloud security agent leveraging cloud-native tools.
Agent Design Depends: Deep Dive
P3 - Future / Deep Dive Topics 8 items
A.9 IR Agent - Requirements
Incident Response automation agent. Extends threat monitoring (A.1) into response workflows.
Agent DesignDepends: Deep Dive
MS Purview Integration (SOC for AI - DLP)
Data loss prevention + data classification for AI usage. No Kindo integration today.
IntegrationP3
A.12 Identity Agent → IdaaS (Tim Corder)
Service line expansion into Identity aaS. Requires engagement with Tim Corder + Ravi.
Service Line ExpansionPhase 4
A.13 GRC Agent → GRC aaS (Nathan Ellis)
Service line expansion into GRC aaS. Requires engagement with Nathan Ellis.
Service Line ExpansionPhase 4
Lifecycle Hooks MVP
Kush: short answer is yes, but NOT most important. Ship fast MVP - don't over-engineer. Focus: deployment speed, not stickiness.
PlatformKush deprioritized
IK / Memory Design Session (Kush request)
Kush asked for a session on institutional knowledge, skills, memory. Charlie: protect IP - share "what" not "how."
Deep DiveIP sensitivity
SaaS Discovery Integrations (Nightfall, Netskope, Okta)
CASB/SaaS-level AI discovery tools. No Kindo integrations today. Lower priority than endpoint-level discovery.
IntegrationP3
Deloitte Integration Framework - Legal + Technical
Deloitte wants private integrations without Kindo involvement. Need legal agreement on integration sharing + licensing/enforcement mechanism.
Strategic Legal Risk
Parked 2 items
A.6 Vitals Dashboard
Deprioritized by Kush (June 22). SOC for AI takes its slot. May resurface in future sprints.
Deprioritized
A.10 IoT/OT Monitor
Deprioritized by Kush (June 22).
Deprioritized
Program Track

Program / Strategic Track.

Parallel track - program management work that needs an owner and date but doesn't produce a product artifact. Not sprint-rankable. Joana's track.

Why this is separate: These items are essential program work - investor narratives, portfolio prep, hiring, travel planning - but they don't produce a built artifact in Kindo. They run on their own timelines with their own owners, parallel to the sprint. Mixing them into P0-P3 product lanes creates false prioritization conflicts.
ItemOwnerTarget DateNotes
Deloitte Training Cohort 2 Launch Joana Jul 10 ✅ Launched. LMS technical review ✅ complete. Domain fix ✅ complete.
Scaling Story for Ron / Forge Point Tony + Joana During Sprint 2 Capture while Tony is present. 3-5× revenue growth narrative for Forge Point VC.
Monthly Portfolio Prep (July) Joana Ahead of portfolio review Video evidence + working links for shipped functionality.
Value First Hiring Joana / Victor Ongoing Interviews in progress. Invoice → Charlie → Ron.
QA/Account Manager Hiring Joana / Victor Ongoing Value First hires positioned as technical QA bridging Deloitte↔Kindo engineering. Technical background required.
Teams Integration Instructions → Krishna Charlie Sprint 2 Week 1 Email tenant ID + setup instructions for company-to-company Teams collaboration.
Co-Design Session Scheduling Joana Sprint 2 Schedule next co-design session. Cadence open - Joana suggested biweekly (sprint-aligned), Krishna suggested monthly. Left open Jul 10. Needs Tony input. Next session ~Jul 25.
Action Items from Jul 10 Session Joana Sprint 2 Week 1 Circulate action items list to all attendees.
10 · Decisions

Open Decisions & Needs-Human.

Items requiring team input - updated July 13

Attention Required

Three pillars confirmed. Digital twin pivoted.

Jul 30 + Jul 31 Sessions
Key Decisions - Jul 30 Design Session + Jul 31 Alignment

Design Session #2 with Krishna (Jul 30) and strategic alignment (Jul 31). SOAR/Swimlane replacement moved to active evaluation.

Turbo Mode alpha access in August Charlie committed to provisioning Turbo Mode SaaS alpha access for Deloitte to evaluate as a Swimlane replacement. August timeline.
SOAR scope: detection + triage automation only Not response-side. Krishna: “We don't have to do it the exact same way we did with Swimlane” — target 80-90% capability coverage. Turbo Mode currently handles 5 of 10 requirements. Three EBITDA vectors: SaaS fee replacement, manual playbook labor, manual triage labor.
Swimlane decision deadline: end of November 90-day notice required before the February renewal. Deloitte must decide on the Turbo Mode replacement by ~Nov.
Teams federation > Slack Slack confirmed dead (“hell no” from Deloitte). Krishna + Adelina pursuing Teams company-to-company federation. Deloitte side unblocked (Adelina, Aug 4). T&C/Kindo integration pending.
Case management = historical record search for correlation Zun requirement: not just ticket management — historical record search across cases for ticket correlation.
Weekly standup stays weekly Ticket volume (<5/week) doesn't justify more frequent cadence. Tactical layer stays weekly.
QA/Account Manager hiring strategy Value First hires positioned as technical QA bridging Deloitte↔Kindo engineering. Technical background required.
SOC for AI expanding Krishna: “I can see us taking this to clients.” SOC for AI + Telemetry convergence to be presented at the Aug 10 portfolio meeting.
Jul 10 Co-Design Session
Key Decisions - Jul 10 Co-Design Session

90-min session with Kush, Krishna, Nathan, Zun. First formal co-design work session.

Three-pillar discovery framework confirmed Charlie's framework confirmed by Kush/Krishna: (1) Platform integrations - reach into Anthropic, Azure Foundry, Copilot, ServiceNow, (2) LLM gateway/choke point - Kindo as inference proxy, (3) Network/endpoint monitoring - sweep for shadow AI (long tail).
Digital twin → L2/L3 analyst clones Krishna redirected from Zun clone → operational L2/L3 analyst clones. Use cases: consistent triage quality, detection rule tuning across Splunk/Google SecOps/Palo Alto XSIAM. Better scale and impact than individual SME clones.
Tiered SOC model confirmed (Basic → Standard → Elite) Krishna's CrowdStrike analogy: menu of discovery options, not one-size-fits-all. Basic = detect + respond post-action. Standard = richer monitoring. Elite/Advanced = preventative blocking. First version should be "less intrusive."
Co-design sessions: cadence open Joana suggested biweekly (sprint-aligned), Krishna suggested monthly - left open Jul 10. Needs Tony input. Next session scheduled in ~2 weeks to align with Sprint 2 end (Jul 25). Format: quick status items + 2-3 deep dives per session. Same attendees: Tony, Charlie, Joana, Victor + Kush, Krishna, Nathan, Zun/Adelina.
Teams integration: Step 0 before digital twin bot Get Deloitte corporate IT approval for company-to-company Teams collaboration. Charlie to provide tenant ID / setup instructions. Krishna to navigate red tape. Prerequisite for digital twin bot deployment.
No data lake - stay edge/API approach Kush directive: don't build a data lake. Stay edge/API approach. Kindo debating internally but no plan underway.
Triage agent splitting into basic triage + advanced investigation sub-agents Zun reduced 15 min → 10 min. Considering sub-agent split for further optimization. Work session with Charlie needed. Zun to provide generalized prompts.
AIGP protocol assessed - not adopted github.com/owner-spec/aigp-protocol - newly drafted, proprietary (patent/copyright), requires agent adoption. Kindo reaches same governance outcomes on existing open standards (inference APIs, MCP, OpenTelemetry) without new integration work. Not precluded from supporting later, but current state has long adoption runway.
Charlie's follow-up email shared with Deloitte team (Jul 10 evening) Strategy email covering three-standard approach (inference, tools, telemetry) + AIGP assessment + Claude Code demo link. Separate follow-ups planned for SOC for AI sprint 2 and "menu of options" for discovery.
Logging gaps - agent failure logs needed for troubleshooting Nathan/Zun flagged agent failure logs missing. Context compaction being fixed in upcoming release (Mo confirmed). Sprint 2 gap analysis planned.
Anti-AIGP position shared with Deloitte (Charlie's Jul 10 email) AIGP assessed as newly drafted, proprietary (patent/copyright), requires new agent adoption. Kindo reaches same outcomes on existing open standards. Sent in writing to Deloitte team. STATUS: Confirm as team-wide position (not just Charlie's individual view). Decision owner: Tony + Charlie.
GitHub repository exposure - Deloitte references Charlie flagged to Deloitte team that a commit removing personal/Deloitte references doesn't remove them from git history. Normal commit leaves content visible in repo history. Deloitte would need history rewrite + force push. Flagged as courtesy - sensitive relationship item. No sprint work required.
Action Items
Action Items - Jul 30 / Jul 31 / Aug 4
ActionOwnerStatus
Share Swimlane JSON workflows to Charlie (ASAP) Zun + Adelina Waiting
Schedule Turbo Mode deep-dive with Adelina + Zun for SOAR capability mapping Charlie Sprint 3
Set up shared ticketing system, get Deloitte's preferred tool Joana Sprint 3
Ensure Brandon and/or Marcos attend weekly standups Joana Ongoing
Retrospective on 05.10 release failure → send findings to Nathan Joana Mid-late next week
Confirm what's in 2026-07 release (context window compaction, observability, LiteLLM timeout fix) Joana In Progress
Explore AWS Bedrock quota increase for rate limiting Adelina Sprint 3
Continue Teams federation setup (Deloitte side done, T&C side pending) Krishna / Adelina Unblocked
Reproduce latency issue in isolated prototype environment Zun In Progress
Designate Deloitte attendees for weekly who can cover all open tickets Krishna In Progress
Previous
Decisions from Jul 8 Prep Session

Full team (Tony, Charlie, Victor, Joana) prep for Jul 10 design work session with Deloitte.

POC scope expanded: Cross-platform AI orchestration Charlie's direction: Don't just demo Kindo-internal governance. Set up external AI platforms (Claude, Copilot) and have Kindo agent interrogate them - proving Kindo orchestrates SOC for AI across heterogeneous AI environments. Victor to build both components on Kindo SaaS.
Strategic position: Build value ON Kindo, not as dumb pipe Keshav's email interpreted as wanting Kindo as infrastructure/dumb pipe. Team position: SOC for AI capability must be built within Kindo, not on a Deloitte-exclusive layer on top.
Co-develop story locked for Friday Tony's arc: co-sell (May 7) → co-design (Jun 22) → co-develop (Jul 10). Story delivered successfully. Kush/Krishna confirmed alignment.
Integration strategy - stall on Friday, probe for intel Deloitte wants private integrations without Kindo involvement. Friday answer: Brian on PTO. Still unresolved - needs legal framework + licensing enforcement.
11 · Evidence Base

Evidence Base.

110+ days of empirical data (Mar 9 - Jul 10, 2026) - what worked, what failed, what was killed

110+ Days of Data

What works. What fails. What was killed.

Sprint 1 Complete: 9 items delivered. SOC for AI POC built, demoed, and confirmed by Deloitte. Co-design session held Jul 10. Three-pillar framework established. All 5 governance objectives confirmed. Evidence of velocity: Kush - "you guys are phenomenal... the velocity and focus you bring."
Why this matters for Sprint 2: Sprint 2 builds on validated Sprint 1 outcomes. Every item operates on the validated methods (85% pattern), carrying none of the killed ones. Full audit: warren-evolution-audit.pages.dev
85%
Kindo Dashboards (best)
40%
Pipeline Execution (worst)
7
Systems Killed (Jun 17)
Grades
Initiative Grades - Measured, Not Claimed
InitiativeGradeKey Evidence
Kindo × Deloitte Dashboards 85% 2 production dashboards, daily cron, 240 deploys. Owner (Joana) + same-day loop + cron refresh
Strategic Dashboards 80% Same-day delivery pattern. Revenue Map for Ron dinner = built same day Tony directed
Kindo LMS 75% T1-T4 deployed (T1/T2 Joana-confirmed). P1/P3/P4 visual re-times done. Cohort 2 launched Jul 10.
Tony CoS Dashboard 55% 136 deploys, CI/CD working. But: DM capture unverified, Phase 2 never started
Autonomous Pipeline 40% Architecture complete (43 routes). But: 0 agents dispatched for 42+ days. Pipeline became meta-work
What Works
The 85% Pattern
  • Named human owner driving the loop (Joana, Tony)
  • Same-day delivery - directive → artifact in hours, not days
  • Output in recipient's language, not internal jargon
  • Cron-sustained refresh - keeps it alive after delivery
  • Synchronous sessions > async (4h live = weeks of async)
What Fails
The 40% Pattern
  • Autonomous pipeline without human driving = meta-work
  • AI judging AI = shared fault amplification (40-48% pass rate)
  • Process docs as probabilistic input = unreliable
  • Complexity accumulation without outcome measurement
  • Demo site proliferation - 8+ sites, most never viewed
Timeline
The Arc - March → May → June

March-April: Build

Pipeline architecture, 67 routes, Sprint 0, first dashboards. Every problem solved by adding.

May: Peak Complexity

6 new Pages in 3 weeks. 5 AI eval crons. 4 daily dossiers. Maximum complexity = diminishing returns.

June: Subtract

7 systems killed. 0% dossier engagement. Silence First. Human-only review. Higher signal than anything added.

Market Signal
Capability Resonance - What Customers Actually React To
#CapabilityWho ReactedWhen
1Thinking model / decision OSIgor: "Jarvis not Siri"May 15
2Knowledge extractionSteve Ward: "floored"May 25
3AIPMO / autonomous PMValent: SOW signed ($5K)Apr-Jun
4Dependency mappingNFL corpus proof pointApr
5Sprint planning / estimationHector: "that's money"Jun
Guard Rail for Sprint 2: If the number of systems, crons, or processes starts climbing without outcome improvement, subtract before adding. The March→May arc proved complexity accumulation is the default - it has to be actively resisted. Max 1-5 individual changes at a time (Tony, Jun 19).
12 · Delivery Method

Delivery Method.

Warren = Autonomous Delivery Partner - the product is the method, Warren is the engine

The Product

The method is the product. Warren is the engine.

Key insight (Tony + Victor, Jun 26): "The product isn't Warren. The product is this delivery method - with Warren as the engine that makes it run at the speed and quality level that a human team can't match." Warren transforms non-technical creative direction into shipped products. Not autonomous SDLC - Autonomous Delivery Partner.
Framework
Deterministic Outcome Package - 5 Components

Every load-bearing milestone (85% of outcomes) used these 5 components. Each Sprint 2 item should map to this template.

01
Named Owner

A human driving the loop

A human on the customer side driving the loop (the "Tony" equivalent). Sprint 2 check: Who is the owner for each item?

02
Intake Artifact

Customer's own words

Customer's own words, not our interpretation. Sprint 2 check: Do we have source material in their language?

03
Standing Rules

Deterministic, written

Deterministic rules, written - never probabilistic process docs. Sprint 2 check: Are the rules codified or still in people's heads?

04
Cron Refresh

Keep it alive after delivery

Keeps the output alive after initial delivery. Sprint 2 check: Will this need automated updates or is it one-shot?

05
Narrative

Recipient's framework

Output framed in the customer's framework, not VtKl's internal language. Sprint 2 check: Are we using Krishna's/Kush's words or ours?

Operating Pair
The Operating Pair - Appears in 5/8 Load-Bearing Milestones

01 - Owner + Same-Day Loop

The mechanism. Without a named owner driving the loop, nothing ships. Present in: Kindo dashboards, CDO thesis, Execution Plan + Revenue Map, Strategic Portfolio Design, Great Subtraction.

11 - Narrative (Recipient's Framework)

The communication layer. Without narrative framing, output ships but doesn't land. Ron needed visual revenue framing. Igor needed "Jarvis" framing. Krishna needed triage language.

Validation
Validated at Three Altitudes

E

Executive

Revenue Map for Ron dinner (May 21-23). Visual, revenue-framed.

S

Strategic

Sprint plan + GANTT + questionnaire (Jun 8-9). Full planning cycle in one thread.

O

Operational

Daily dashboard refresh via cron. 240 deploys. Deloitte logs in daily.

Evolution
Role Evolution - Self-Organized, Not Designed

Each person migrated UP in altitude over 110 days. Sprint 2 should respect these altitudes.

PersonStarted AsEvolved ToSprint 2 Altitude
TonyOperator (every function)Teacher → SubtractorStrategic direction only. Biweekly.
VictorOps SupportChief Operating IntelligenceTactical execution + Warren calibration
JoanaProgram DeliveryDelivery AuthorityScrum lead + agent design
CharlieBuilderPlatform ArchitectArchitecture decisions only
WarrenEngineering ToolAutonomous Delivery PartnerExecution engine - absorbs operations
Strategic Warning
IP Protection (Charlie, Jun 24)

"I don't want to do design partnership work where we equip them to build stuff that we want to build." Deloitte can execute faster than T&C on skills/memory if they know the HOW. Share the WHAT, never the HOW. This applies to all IK/memory sessions with Kush.

Blue Ocean (Victor, Jun 26): Agile, Scrum, SAFe - all made for humans, not AI. What T&C is building is the AI agility cycle. Greenfield. Nobody is talking about this yet. Tony isn't just talking - he has implemented and proved the value. The quarterly deep dives = "AI Big Room Planning" - release planning with AI in the room collapsing strategy-to-artifact gap to zero.

Daily Progress Log

Channel activity and progress updates - most recent first

📅 August 4, 2026 (Monday) - Program Session

  • Turbo Mode deep dive with Zun, Matthew, Adelina, Nathan. Reviewed Swimlane requirements against Turbo Mode capabilities — currently covers 5 of 10 requirements.
  • Teams federation unblocked on the Deloitte side. Adelina confirmed the Deloitte-side exclusion added Aug 4. T&C/Kindo integration still pending.
  • Swimlane requirements deepened — Zun to share JSON workflows for Charlie to import and build against in Turbo Mode.
  • Matthew Lew engaged as Deloitte technical operations engineer (MXDR test range, Swimlane workflows, Turbo Mode evaluation).

📅 July 31, 2026 (Friday) - Strategic Alignment

  • SOC for AI + Telemetry strategic positioning — convergence of SOC for AI and agent telemetry work into a portfolio-ready story for the Aug 10 meeting.
  • SOAR EBITDA vectors defined: SaaS fee replacement, manual playbook labor, manual triage labor.
  • QA/Account Manager hiring strategy — Value First hires positioned as technical QA bridging Deloitte↔Kindo engineering. Technical background required.
  • Charlie vacation Aug 31 – Sep 23 noted for planning.

📅 July 30, 2026 (Wednesday) - Design Session #2 with Krishna

  • SOAR/Swimlane evaluation activated — moved from hypothetical to active evaluation. Scope: detection + triage automation only (not response-side). Krishna: “We don't have to do it the exact same way we did with Swimlane” — target 80-90% coverage.
  • Turbo Mode alpha committed — Charlie to provision SaaS alpha access for Deloitte in August. Zun to share Swimlane JSON workflows for Charlie to build against.
  • Teams federation decision — Slack confirmed dead (“hell no”). Krishna + Adelina pursuing Teams company-to-company federation.
  • Swimlane decision deadline: end of November (90-day notice before Feb renewal).
  • Case management scoped as historical record search for ticket correlation (Zun requirement).
  • Cadence structure confirmed: three layers — Tactical (weekly), Program (biweekly), Portfolio/Design (monthly, next Aug 10). Weekly standup stays weekly (<5 tickets/week).

📅 July 16, 2026 (Wednesday) - Kush Email Exchange + Sprint 2 Scope Expansion

  • Kush endorsed gateway/shim approach (email Jul 16): “I would like to explore inserting Kindo as a shim to be the gateway to encore controls and gather telemetry.” Pillar 2 positioning gate signal — Deloitte buyer explicitly requesting the gateway model.
  • Charlie proposed MLflow as observability engine (email Jul 16). Two tiers: (1) export OTel to customer platform, (2) Kindo-native MLflow with multi-tenant isolation. Two trace scopes: Kindo-only vs external ingestion. Charlie has working prototypes; internal alpha underway.
  • Kush aligned on both trace types flowing through Kindo. Open questions: (1) how Kindo hooks into existing customer MLflow equivalents, (2) non-Kindo agents tracing directly to MLflow vs through Kindo — pros/cons.
  • Tony scoped 3 new items into Sprint 2: (1) Pillar 2 gateway/shim scoping & architecture doc, (2) OTel/MLflow architecture design doc, (3) storage/retention architecture. Committed items: 8 → 11.
  • GitHub repo history: Kush said “let’s talk about this next time we talk” — added to August co-design agenda.
  • Pillar 2 gate updated: ⛔ blocked → ✅ signal (Kush endorsement). Tony + Charlie to confirm as official position.

📅 July 13, 2026 (Monday) - Sprint 2 Kickoff

  • Sprint 2 planning. Three-pillar SOC framework re-scoped to Pillar 1 deep dive. Digital twin pivoted to L2/L3 analysts.
  • Sprint 2 backlog: 10 items committed after Joana's planning review. Added Discovery Menu of Options (P0, Krishna ask) and Discover→Act Loop (P0). Re-scoped Three-Pillar to Pillar 1 Deep Dive (Anthropic + Foundry). Pillars 2 & 3 moved to research. A7 scoped to design-only (blocked on Teams). Detection Rule Library cut (not a Jul 10 ask). Cross-Platform Extension re-scoped to Copilot & ServiceNow (OpenAI dropped).
  • Positioning gate added: Pillar 2 blocked on Kindo platform-vs-backbone decision (Tony + Charlie).
  • Co-design cadence reopened: Joana suggested biweekly, Krishna suggested monthly - needs Tony input. Next session ~Jul 25.
  • Teams integration: Step 0 complete (Charlie provided tenant ID Jul 10). Blocked on Deloitte IT approval - removed from sprint committed.

📅 July 10, 2026 (Friday) - Sprint 1 End + Co-Design Session

  • Sprint 1 complete. 9 items delivered.
  • 90-min co-design session with Kush, Krishna, Nathan, Zun. First formal design work session.
  • POC demo well-received. Kush: "you guys are phenomenal... the velocity and focus you bring."
  • All 5 governance objectives confirmed by Deloitte team.
  • Three-pillar discovery framework established (Charlie): platform integrations, LLM gateway, network/endpoint monitoring.
  • Krishna proposed tiered model: Basic (detect post-action) → Standard → Elite (preventative). CrowdStrike analogy: menu of discovery options.
  • Digital twin redirected from Zun → L2/L3 analysts (Krishna). Better use case: consistent triage quality, detection rule tuning.
  • A7 Quality Audit: weekly ticket audit, ABC grading, 60% subjective / 40% written. Digital twin could handle subjective portion.
  • Teams integration: Step 0 = Deloitte IT approval for cross-company Teams channel. Krishna to navigate. Charlie to provide setup instructions.
  • Triage agent: Zun reduced 15→10 min. Considering sub-agent split (basic triage + advanced investigation).
  • Zun to provide generalized prompts for Charlie to work on latency independently.
  • Kush mentioned Evan building AI Cyber Guard on AWS (4 problem statements: unify policy, enforcement, observability, guardrails). Open standard for agent telemetry.
  • No data lake (Kush). Stay edge/API approach.
  • Co-design cadence open: Joana suggested biweekly (sprint-aligned), Krishna suggested monthly - left open Jul 10. Needs Tony input. Next session ~Jul 25.
  • On-prem deployments: Krishna says "very close" to contracts. Custom agent dev 3-6 months post-deployment.
  • Deloitte Training Cohort 2 launched.
  • MCP Unified issue with ServiceNow - already fixed (Nathan, database modification needed).
  • Charlie sent follow-up email to Deloitte team (7:39 PM) with Kindo three-standard strategy: inference APIs (live), federated MCP gateway (live), OpenTelemetry (landing). Includes AIGP protocol assessment and Claude Code demo link. Separate follow-ups planned for SOC for AI sprint 2 and "menu of options" for discovery.

📅 July 9, 2026 (Wednesday)

  • SOC for AI POC built ✅ (Victor): Governance Monitor deployed as Triggered Agent on Kindo SaaS. Agent ID: 9ff54d70-924e-46c5-81b5-758bd96411cc. Direct webhook trigger. Two steps: (1) API Action → Anthropic /v1/models endpoint, (2) Claude Sonnet 4.6 governance analysis.
  • First run results: Full governance report covering all 5 Deloitte objectives. Score: 3.8/10 🔴. Real findings: unnamed agents with full permissions, 45 active sensitive integrations, ungoverned Anthropic models, test models in production catalog.
  • Victor enterprise access resolved: Hannah granted enterprise/API access on Kindo. Victor created Kindo API key, added Anthropic API key to Kindo secret vault.
  • Cross-platform validation: POC compares Kindo agent catalog vs Anthropic API model list, flags governance gaps between platforms.
  • Demo video recorded by Victor. Needs narration + publish. Kokoro TTS rejected (too robotic) - alternative TTS being evaluated.

📅 July 8, 2026 (Tuesday)

  • Full team prep call for Friday design session: Tony, Charlie, Victor, Joana aligned on POC scope, co-develop story, and integration strategy for Jul 10 Kush meeting.
  • POC scope expanded (Charlie): Don't just demo Kindo-internal governance - add cross-platform AI interrogation. Kindo agent to connect to Anthropic/OpenAI/Copilot and check agent usage, models, configuration. Proves Kindo orchestrates SOC for AI across heterogeneous environment.
  • Strategic position locked: Keshav's email interpreted as wanting Kindo as dumb pipe. Team position: build value ON Kindo. Deloitte handles shadow AI, Kindo owns known AI governance. Assume Keshav is misinformed vs Kush/Krishna co-develop agreement.
  • Co-develop story ready for Friday: Tony's arc: co-sell → co-design → co-develop. Digital twin of SME → institutional knowledge → Kindo APIs. Charlie prefers external agent (Warren) managing Kindo via APIs over master agent inside Kindo.
  • Charlie shipping IK primitives: Memory system (alpha today), agent-editable system prompts (today/tomorrow), trace export to MLflow (self-serve). One more change needed: agents reading trace data. Open Shell in alpha internal this week/next. Skills not started.
  • Agent portability available: Yash shipped export/import feature. POC built on SaaS can be given to Deloitte for their instances.
  • Integration concerns flagged: Deloitte wants private integrations without Kindo involvement. No integrations shared yet. Risk: Kindo becomes dumb component. Friday stall: Brian on PTO. Need legal framework + licensing enforcement.
  • Victor access resolved: Hannah granted enterprise/API access on Kindo. Victor created API key, added Anthropic key to secret vault. POC built same day.
  • Hiring challenge discussed: Finding people with AI expertise + complex environment experience + T&C speed is extremely difficult. Charlie's suggestion: hire for training not existing expertise.
  • Agenda items deferred: Deep dive topics 4 & 5 - Charlie open to discuss but nothing to pitch. Topic 3 (integrations): stall with Brian PTO. Workflow acceleration: killed. Agent marketplace: tabled (too big).

📅 July 7, 2026 (Monday)

  • SOC for AI scope reframe (MAJOR): Deloitte replied to our questionnaire - they don't need shadow AI discovery (their detection engineering team handles that). Instead they want Kindo platform governance: monitoring known AI agents on Kindo. 5 new objectives defined.
  • Kindo capability assessment completed: Mapped existing Kindo audit/telemetry/RBAC/DLP capabilities against all 5 objectives. Result: ~60% covered out of the box.
  • 3-track delivery plan defined: Track 1: Audit Surface Map. Track 2: SOC Detection Rules/Use Cases. Track 3: Drift Detection + Tenant Monitoring.
  • IK Approach page built: New page at /ik-approach for Institutional Knowledge positioning
  • Internal site 451 fix: Cloudflare blocked /cadence/ path. Moved content to /meeting-cadence/.

📅 July 3, 2026 (Thursday)

🔵 #deloitte-agents-design

  • Dashboard daily auto-refresh process set up - runs at 8 AM PT, pulls from 3 Slack channels
  • Full editorial restyle applied to all dashboard sections (dark statement bands, feature rows, editorial typography)

🟢 #client-kindo-deloitte

  • Charlie (tech SME) reviewed all 4 Technical-track LMS videos - APPROVED, no critical issues
  • Magic link UX feedback: domain mismatch across email sender, Supabase auth URL, and landing page
  • Victor initiated plan to fix domain consistency - exploring new domain or Kindo subdomain delegation
  • Victor assigned to implement Charlie's LMS feedback items

🟡 #client-kindo-training

  • No new activity

📅 July 2, 2026 (Wednesday)

  • Dashboard updated with sprint progress since Monday (Jun 29)
  • Questionnaire → Krishna marked as ✅ SENT (Jul 1), awaiting responses
  • LMS blockers removed - now pending Charlie's technical review only
  • Victor asked about building the SOC for AI Discovery Agent - Warren confirmed design + code skeleton ready
  • First cut of SOC for AI Discovery Agent files delivered: SOP, Skill file, Step config in agents/soc-for-ai-discovery/
  • Internal repo/domain (kindo-deloitte-internal) fully operational - all nav links fixed

📅 July 1, 2026 (Tuesday)

  • Victor requested internal/Deloitte deployment separation after link was accidentally shared externally
  • Internal repo t-and-c/kindo-deloitte-internal created, deployed to kindo-deloitte-internal.pages.dev
  • Allowlist isolation model implemented: Deloitte-facing repo contains ONLY explicitly named files
  • Root page set to sprint planning (Victor's request)
  • SOC for AI questionnaire sent to Krishna
Agenda 2026

Planning Agenda.

August 2026 → January 2027 — team availability, holidays, and meeting cadence across the critical stretch

Critical Stretch

September is the pressure point. Charlie OOO + Tony travel + double holiday.

Legend
Maternity Leave Charlie OOO Tony Travel / Kush OOO Holidays BR 🇧🇷 Holidays US 🇺🇸 Co-design Portfolio
Solid = Confirmed Dashed = Tentative / TBD
⚠️ September — High-Risk Month: Charlie out Aug 31 – Sep 23 (wedding Ecuador Sep 11). Tony travel overlapping (SA ~Sep 2–12 + Tokyo ~2 wks). Sep 7 = double holiday (Independência 🇧🇷 + Labor Day 🇺🇸). Plan for significantly reduced T&C capacity all month.
Jul Aug Sep ⚠️ Oct Nov Dec
Maternity
Leave
Joana — ~Nov 1 → end of Dec 2026 (~2 months) · Tentative Due date: Nov 1. Backfill: new Coordinator hire covers delivery during leave.
Kush
OOO
Jul 21–25 · Confirmed
Out next week
Charlie
OOO
Aug 31 →
Aug 31 – Sep 23 · Confirmed
💍 Sep 11 — Wedding (Ecuador)
Tony
Travel
South America ~Sep 2–12 (10 days)
Tokyo ~2 wks (after Sep 12, being rescheduled)
Tentative — dates pending
Holidays
🇧🇷 Brazil
🇧🇷🇺🇸 Sep 7 (Mon) — Independência + Labor Day
🇧🇷🇺🇸 Oct 12 (Mon) — Aparecida + Columbus Day
Nov 2 (Mon) — Finados
Nov 15 (Sun) — Proc. da República
Nov 20 (Fri) — Consciência Negra
🇧🇷🇺🇸 Dec 25 (Fri) — Natal + Christmas
Holidays
🇺🇸 US
↑ Sep 7 shared ↑ Oct 12 shared
Nov 11 (Wed) — Veterans Day
Nov 26 (Thu) — Thanksgiving
↑ Dec 25 shared
Co-design
Jul 30 (Thu) 2:30–4 PM CT · Confirmed ✅
Aug 27 (Thu) · Tentative
Last session before Charlie OOO
Oct 22 (Thu) · Tentative
Nov 19 (Thu) · Tentative
Portfolio
Aug 10 (Mon) · Confirmed
Krishna + Kush. SOC for AI + SOAR EBITDA.
Sep 24 (Thu) · Tentative
Just after Charlie returns; may run remote
Oct 8 (Thu) · Tentative
Nov 5 (Thu) · Tentative
Dec 3 (Thu) · Tentative
Single session for Dec (holidays)
Meeting cadence: Biweekly alternating Co-design ↔ Portfolio from Jul 30. Dates above are tentative — to be confirmed as the cadence establishes.

Last updated: July 20, 2026 · 10:30 AM PT

Roadmap vs. Net New Revenue

Classification Rubric.

Decision framework for classifying SOAR capabilities as standard Kindo product roadmap (covered under existing contract) or net new revenue (Deloitte-specific development, separately chargeable).

The failure mode to avoid: At the July 30 Design Session, Tony told Krishna that Kindo has been developing SOC for AI as part of its roadmap. Turbo Mode would impact items 1–5. If Turbo Mode is positioned as net new revenue, the remaining “standard roadmap” is items 6, 7, and 9 — which does not constitute a credible SOC for AI roadmap. Deloitte will ask what is actually on the standard roadmap, and the net new revenue position collapses as opportunistic.
The resolution (Charlie, August 3): The Kindo SOC for AI roadmap independent of Turbo Mode is the platform layer — public API support, configuration of external AI, MCP support for Anthropic / OpenAI / other vendors, and traceability and tracking of agents through those APIs. Plus Sprint 1 and Sprint 2 deliverables and Matthew’s ongoing development work.
Sprint 1 & 2 deliverables — evidence of pre-existing roadmap work:
  • Sprint 1 (9 items shipped): SOC for AI POC built and demoed. All 5 governance objectives confirmed by Deloitte. Three-pillar discovery framework established.
  • Sprint 2 (11 items committed): Agent Telemetry prototype delivered. Platform Compatibility Matrix (5 platforms, license gates mapped). Gateway Architecture (3 open standards, Kush endorsed).
  • Three-Standard Strategy (Charlie’s Jul 10 email): Inference APIs (live), Federated MCP Gateway (live), OpenTelemetry (landing now).
Decision Criteria — Four Tests, Applied in Order
Test Question Verdict Reasoning
B — Pre-Existence Was this in Kindo’s roadmap before Deloitte asked? ADOPT Strongest test. If Kindo was already building it, it’s roadmap. No formal SOC for AI roadmap doc exists — Sprint 1/2 deliverables are the evidence.
C — Generalizability Would a mid-market SOC customer want this? ADOPT — PRIMARY Tony’s position: general capability = roadmap. Deloitte-specific implementation = net new. MFN-safe.
D — Operational Specificity Does this encode Deloitte’s MSSP model specifically? TIEBREAKER Per-client tenancy, 80% of clients on Swimlane, email-based intake, cross-playbook communication — these are MSSP-specific.
A — Provenance Did Deloitte request it, or did Kindo propose it? CONTEXT ONLY All 10 originate from Deloitte (Zun’s April 2026 doc). But provenance alone can’t classify — Deloitte asking for multi-tenancy doesn’t make it net new if Kindo already has it.
Two-Axis Matrix — All Ten Items
Readiness (from Aug 4 page, unchanged) × Commercial Classification (new)
# Capability Readiness Commercial Source
1 Alert Intake & Scale TURBO MODE ROADMAP + NET NEW General: non-LLM ingestion is generalizable. Net new: Deloitte’s email-based intake patterns across 80% of clients.
2 Data Normalization TURBO MODE ROADMAP + NET NEW General: schema mapping is generalizable. Net new: Deloitte-specific source-to-schema mappings.
3 Noise Reduction TURBO MODE ⚠ CONTINGENT Depends on #7 (Case Management). Dedup needs prior incidents to query.
4 Incident Correlation TURBO MODE ⚠ CONTINGENT Depends on #7. Correlation needs an incident object to group against.
5 Workflow Control TURBO MODE ROADMAP + NET NEW General: deterministic flow is generalizable. Net new: migrating ~150 workflows. ⚠ Conflicting signals: Charlie (Jul 21, no native flow) vs Greg (Jul 27, hybrid is roadmap). See D1.
6 Response Actions UNDER CONSIDERATION ROADMAP if generalized / NET NEW if specific No implementation to classify yet. Depends on design approach.
7 Case Management STRATEGIC DISCUSSION ⬜ UNCLASSIFIED Load-bearing. Items 3, 4, 9 depend on this. No Kindo strategy exists. See D2.
8 Multi-Tenancy STRATEGIC DISCUSSION ROADMAP Pre-existing (Test B). Charlie: “Kindo is literally designed for multi-tenancy.”
9 Reporting & Metrics SCOPING ⚠ CONTINGENT Depends on #7. Also needs Deloitte to define “SOC reporting standards.”
10 Secure / Edge Deployment NOT PRIORITIZED ROADMAP Generalizable enterprise need (Test C). Any regulated customer needs this.
Summary: Roadmap: 3 clear (5 general, 8, 10). Net new component: 3 clear (1 config, 2 schema, 5 migration). Contingent on #7: 3 items (3, 4, 9). Unclassified: 1 (7). Decision-dependent: 1 (6).
Dependency-Inherited Classification

Item 7 (Case Management) is the keystone. Classifying it effectively classifies four items (3, 4, 7, 9). Turbo Mode’s claimed coverage of items 3 and 4 is contingent on #7 being resolved — a clean “Turbo Mode covers 1–5” position does not survive this dependency.

#7 Case Management — persistent incident lifecycle
  ↳ #3 Noise Reduction — dedup needs prior incidents
  ↳ #4 Incident Correlation — needs incident object
  ↳ #9 Reporting — needs records to query

If #7 = Roadmap: Strongest position. All four inherit roadmap for general capabilities. If #7 = Net New: Viable but exposed — Deloitte may question why case management isn’t on a SOC platform’s roadmap. If #7 = Unresolved: Four of ten remain unclassified. Current state.

Unclassified Scope — Not in the Ten Items
Surfaced after July 29. On the critical path. Strong net new revenue candidates.
Item Classification Reasoning
Migration Tooling NET NEW — STRONG ~150 Swimlane workflows. Deloitte-specific by definition (Test D). No mid-market customer has this migration need.
MCP Coverage REQUIRES MAPPING Split: MCP for widely-used platforms = roadmap. MCP for Deloitte-specific/niche tools = net new. Can’t classify until gap is mapped.
Low-Code Requirement REQUIRES SCOPING Potential 11th item. Generalizable (Test C → roadmap candidate), but may conflict with Kindo’s agentic-first direction. See D3.
Boundary Case Protocol
What happens when something built for Deloitte is absorbed into the product roadmap after the fact.

1. Classify at scope time — before development begins, not after. Classification does not change retroactively.

2. Disclose absorption — if net new is later absorbed into product, Deloitte is notified and pricing impact addressed.

3. Joint decision authority — Kindo product + T&C program management classify. Unilateral reclassification not permitted.

4. Audit trail — every classification recorded with date, decision-maker, and reasoning.

Per-Customer Categorization Guardrail (MFN)

Meta MFN constraint (Ron, August 3). Tony’s reframing: this is a “categorization” question, not a “naming” question.

General capabilities are roadmap for all customers. If deterministic workflow control is roadmap, it’s roadmap for Meta, Deloitte, and everyone.

Customer-specific work is net new for that customer. Migrating 150 Swimlane workflows is Deloitte-specific. Doesn’t trigger MFN.

Split at the implementation layer, not the capability layer. “Deterministic workflow control” = roadmap. “Migration of Deloitte’s 150 Swimlane workflows” = net new. Same capability, different commercial classification. MFN-safe.

Open Decision Register
Items requiring a human decision. Recommendations provided, decisions not made here.
D1. Is deterministic workflow control on the Kindo product roadmap?
Option A: Yes — aligns with Greg’s Jul 27 position. Turbo Mode is roadmap. Items 1–5 have a credible foundation.
Option B: No — aligns with Charlie’s Jul 21 position. Turbo Mode is Deloitte-driven. Items 1–5 lose their foundation.
Consequence: These positions were stated to Deloitte one week apart. They conflict. Must resolve before Aug 4.
REC: Resolve before Aug 4. If unresolved, do not present Turbo Mode’s commercial classification.
D2. How does Kindo address Case Management (item 7)?
Option A: Build general incident lifecycle into platform (roadmap). Strongest — 4 items inherit roadmap.
Option B: Build for Deloitte (net new). Viable but exposed — 4 items become net new.
Option C: Integrate with external systems (Jira etc.). Lowest-commitment path. Integration layer = roadmap, Deloitte config = net new.
REC: Option C initially. Escalate to A if Deloitte rejects external integration.
D3. Is low-code / visual workflow building on the Kindo product roadmap?
Option A: Yes — part of Turbo Mode direction. Roadmap.
Option B: No — agentic-first. Low-code is a Deloitte accommodation. Net new / 11th item.
REC: Defer until Adelina formally confirms. If confirmed, general capability = roadmap, Deloitte templates = net new.
D4. What is the Turbo Mode commercial classification?
Option A: Roadmap — consistent with Tony’s Jul 30 framing and Charlie’s Aug 3 answer. Deloitte migration/config = net new.
Option B: Net new — collapses SOC for AI roadmap claim. Contradicts Tony’s Jul 30 statement.
REC: Option A. Requires resolution of D1 first.
D5. Who owns the classification decision?
Option A: Kindo product classifies, T&C reviews/approves, Deloitte has visibility.
Option B: Joint with Deloitte. More transparent but gives Deloitte influence over what they pay for.
REC: Option A with written disclosure. Classify internally, share transparently.
Findings — evidence gaps:
  • No formal Kindo SOC for AI product roadmap document. Sprint 1/2 deliverables are evidence of work, not a pre-existing roadmap artifact.
  • Turbo Mode origin unverified — who requested it, under what framing, whether it originated as Deloitte-specific or general product development.
  • Kindo–Deloitte contract scope language not reviewed. Essential for binding classification.
  • Meta MFN clause specifics not reviewed. Guardrail rules based on Ron’s Aug 3 framing and standard MFN principles.
  • Matthew’s development work in SOC for AI area not documented. Charlie cited it as part of roadmap position.
  • Krishna’s May 7 statement on replacing Swimlane then Jira — referenced but not verified from primary source.

Last updated: August 3, 2026 · 12:00 PM PT