Kindo
Kindo × Deloitte Program
Design Session #2 · July 30, 2026

Kindo × Deloitte.

Second co-design session in the SOC for AI workstream. Platform readiness, observability, Swimlane transition, and SOC for AI — aligning on direction with engineering leadership.

First co-design session: July 10, 2026. A portfolio-level meeting with Kush will be scheduled within the next ~10 days.

Session Goals
1
Review and resolve 5 active platform issues affecting production SOC operations — context window, silent failures, rate limiting, MCP latency, and flow control
2
Align on Kindo's platform direction regarding Swimlane replacement — with the December go/no-go decision as backdrop
3
Present Sprint 2 SOC for AI deliverables and secure co-design input for Sprint 3 scope
Attendees
Tony Wong · Charlie Hulcher · Joana Dias · Victor Slompo · Krishna Marella · Kush Singh · Nathan Ellis · Zun Huang (Deloitte)
Agenda
Block A — Active Platform Issues · 25 MIN
Krishna's open issues — five platform problems affecting production SOC operations. Status reflects Kindo's current position on each item.
🚀 READY — SHIPPING 2026.07 #1 · Context Window Exhaustion — Agent Failure on Limit Hit
Agents fail when context window is exhausted. Chat compaction is GA — shipping in 2026.07, targeted for tomorrow (July 31). Observability (#2) is also being worked to get into this release.
🔧 IN PROGRESS #2 · Agent Silent Failures — No Root-Cause Visibility (Observability)
Runs fail with no diagnostic telemetry. Brandon and team are targeting the 2026.07 release — ClickHouse + HyperDX. Operators will have direct access to reliable logs without terminal commands. Traces and metrics follow once log infrastructure is validated.
🔧 IN PROGRESS #3 · Rate Limiting Under Alert Floods
Concurrent agent bursts hit model rate limits, causing run failures. Model fallback routing in internal alpha — multiple providers behind a single model with automatic failover. In development for approximately seven weeks.
⏳ BLOCKED #4 · MCP Tool-Calling & Step Latency
Triage agents running slower than target. Charlie had a working session with Zun on Jun 29 — pending sanitized internal docs and prompts from Zun so Charlie can propose optimizations.
→ BLOCK B #5 · Deterministic Flow Control & Auto-Retry
No conditional branching, loops, or auto-retry. This connects directly to the Swimlane transition discussion — covered in Block B below.
Block B — Swimlane Transition & Platform Direction · 25 MIN
Swimlane contract ends February 2027. Go/no-go decision by December 2026. Migration underway by December, completed mid-January. This block absorbs the deterministic flow control discussion from issue #5 above.
Krishna's SOAR Question
Does Kindo plan to target traditional automation (SOAR) as part of its product roadmap? This question determines whether the Swimlane transition is a platform migration or requires complementary tooling.
Zun's Capability Gap Requirements · SHARED JULY 29
1.
Alert Intake & Scale — Alert ingestion is solely agentic; no way to handle large volumes without using LLM.
2.
Data Normalization — No standard schema mapping across sources, adding cost and inconsistency.
3.
Noise Reduction — No deduplication/suppression layer; repetitive alerts drive avoidable processing cost.
4.
Incident Correlation — No native way to group related alerts into a single incident; each run is isolated.
5.
Workflow Control — No deterministic layer for actions requiring guaranteed, repeatable execution.
6.
Response Actions — No pre-built action library with structured approvals, rollback, or runaway safeguards.
7.
Case Management — No persistent incident lifecycle or system of record; reliant on external ticketing.
8.
Multi-Tenancy — Client isolation and per-client configuration limited for managed-service delivery.
9.
Reporting & Metrics — Operational, SLA, and performance dashboards fall short of SOC reporting standards.
10.
Secure / Edge Deployment — No lightweight on-prem or air-gapped option; PrivateLink or site-to-site VPN required for SaaS behind firewall.
Platform Direction — Turbo Mode Demo
Kindo's approach to high-volume deterministic workflows — Turbo Mode demo and walkthrough.
Timeline
December 2026 go/no-go · Mid-January migration complete · February contract end
Ask 1
How do Kindo and Deloitte jointly define the replacement scope? Proposed approach, named Deloitte counterpart, and date to begin.
Ask 2
What date does Deloitte need Kindo's final deliverable in order to hit the December go/no-go and mid-January migration?
SLA Discovery · 10 MIN
Information gathering — not decision-making. Understanding Deloitte's contractual SLA framework so Kindo can design platform capabilities accordingly.
Three Questions for Deloitte
1. Deloitte's standard customer SLA for this platform: uptime target, measurement window, exclusions.
2. How P1 / P2 severity is defined contractually, and the response and resolution times attached.
3. Which layer the SLA applies to: Kindo SaaS, on-prem installation, or customer-supplied inference.
Responsibility split to be worked through in a dedicated session. Severity classification to be resolved at the portfolio meeting.
Agent Telemetry & SOC for AI · 30 MIN
SOC for AI co-design — Sprint 2 review. Sprint 1 proved the concept. Sprint 2 built working prototypes inside the platform. Sprint 3 is co-design: Deloitte shapes the scope.
Sprint 2 Deliverables
Agent Telemetry — working prototype · Platform Matrix — 5 platforms researched, license gates mapped · Gateway Architecture — 3 open standards proposed, endorsed · Tier mapping and observability integration proposals in progress · Full Sprint 2 Review →
Co-Design Input Needed
Which SOPs should define evaluation criteria? · Which platform to integrate first? · Does the Basic/Standard/Elite tier model fit your service structure?
Sprint 3 Direction
Co-design session where Deloitte defines eval criteria, platform priority, and scope. Format depends on what we learn together. Output: validated requirements that engineering can build with confidence.
Carried-Over Open Items · OUTSTANDING
Items raised previously and still unresolved on the Deloitte side.
⏳ OPEN Teams Access for Analyst Observation & Co-Design Sessions
Raised at the July 22 program meeting — still open. Required for analyst observation and co-design sessions to proceed effectively.
⏳ OPEN Sanitized MCP Docs & Prompts from Zun
Pending since Charlie's June 29 working session with Zun. Needed so Charlie can propose MCP latency optimizations (issue #4).
Connecting Thread
These topics are interconnected. Platform stability (Block A) enables reliable SOC automation. Observability provides the diagnostic foundation. The Swimlane transition (Block B) shapes the platform roadmap. SOC for AI is the co-design process where we build together with Deloitte. SLA discovery sets the contractual frame for all of it.