Sprint 2 focused on translating Deloitte's SOC for AI governance objectives into platform capabilities. This review maps each objective to what was built, what was researched, and what's next for the co-design session.
Five governance objectives defined by Kishore's team (Jul 7, 2026). Focus: monitoring risks from known AI agents/platforms — not shadow AI discovery, which is handled by Deloitte's detection engineering team.
Implementation requires two things: (1) audit logs/telemetry data from the platform and (2) process/data collection architecture to monitor for these risks.
Live walkthrough of the Agent Telemetry capabilities built into the Kindo platform. This is not a mockup — it's the actual platform running with real agent traces, LLM judges, and eval verdicts.
Demo video available — 1:07 walkthrough of Agent Telemetry in Kindo.
Presentation video → · Raw demo →
Charlie's framework, confirmed by Kush and Krishna at the Jul 10 co-design session. Three approaches to AI governance discovery — each platform has different strengths.
Krishna's CrowdStrike analogy — a menu of discovery options, not one-size-fits-all. First version: "less intrusive" detection and response post-action.
Per-platform capabilities for discovery and governance actions. Determines which tier model and which pillar applies to each platform in a customer's environment.
| Capability | Anthropic | Azure AI Foundry | Microsoft Copilot | ServiceNow | AWS Bedrock |
|---|---|---|---|---|---|
| List models/agents | ✓ API | ✓ ARM API | ~ Graph + Studio | ~ Table API | ✓ API |
| Usage/audit logs | ~ Limited | ✓ Azure Monitor | ✓ Purview | ✓ System logs | ✓ CloudTrail |
| Content/safety filters | ✗ Not via API | ✓ Full API | ~ DLP policies | ~ Admin config | ✓ Guardrails API |
| Disable/block access | ✓ Key revocation | ✓ RBAC + Policy | ✓ Entra ID | ✓ Role-based | ✓ IAM + SCPs |
| Enforce policies | ✗ No policy API | ✓ Azure Policy | ✓ DLP + labels | ~ Workflows | ✓ Guardrails + SCPs |
| Alerting/notifications | ✗ None | ✓ Monitor Alerts | ✓ Sentinel | ✓ Event Mgmt | ✓ EventBridge |
| Best Kindo method | Gateway (P2) | API + Gateway (P1+2) | API + Network (P1+3) | API + Network (P1+3) | API + Gateway (P1+2) |
✓ Full API · ~ Partial · ✗ Not available
No single discovery method works across all platforms. This is why Krishna's CrowdStrike analogy is right — customers need a menu of discovery methods, deployed based on: which platforms are in their environment, network disposition (gateway possible?), and governance maturity (Basic/Standard/Elite).
Kindo's advantage: it can operate at all three pillars simultaneously. Rich admin APIs (Azure, Bedrock) → Pillar 1. Limited admin APIs (Anthropic) → Pillar 2 gateway fills the gap. Shadow AI → Pillar 3 catches the rest.
Kindo reaches governance outcomes on three existing open standards — no proprietary protocol adoption required.
Inference + Tools + Telemetry = comprehensive AI governance. Open standards = low adoption cost. Gateway position is cheap and reversible — addresses "customers worry about choke point."
Working prototype: trace export, LLM judges, eval configuration, span detail, error diagnostics. Demo video available.
5-platform research (Anthropic, Azure, Copilot, ServiceNow, Bedrock). Per-platform discovery/action capabilities mapped to three pillars.
Kush endorsed gateway approach (Jul 16). Three-standard strategy documented. Inference + MCP + Telemetry trifecta.
Two-tier model: export out (alpha) vs native pillar. MLflow adoption proposal with working prototype. Integration patterns documented.
Krishna-facing deliverable. 5-7 discovery methods with tier mapping. Dependent on Platform Matrix (complete) — synthesis in progress.
Teams integration blocked on Deloitte IT. Krishna circling back internally. Sprint 2 goal was discovery — how to do this. Moved to Sprint 3.
Requires work session with Zun. Kush OOO Jul 21-25. Moved to Sprint 3.
Depends on digital twin approach + design session with Krishna's team. Sprint 3.
For the next co-design session (~August), we'd like to walk through these capabilities with your team and get input on: