Here's what we said we'd do. Here's what we did. And here's what we need from you to shape Sprint 3.
This is an alpha release — architected to graduate directly toward production inside the Kindo platform — demonstrating the telemetry capabilities discussed at the Jul 10 session. It represents months of research and prototyping in a final shape to drive requirements finalization. Your input refines it.
Sprint 2 responded to the five governance objectives from Kishore's Jul 7 email and the direction from the Jul 10 co-design session. Every commitment addressed.
Each objective mapped to a platform capability. Badges indicate honest status — what's built, what's research, what needs your input.
Detect when unauthorized users are deploying new agents or updating existing agents.
Platform response: Pillar 1 — Platform Discovery (research complete) + Agent Telemetry (alpha). Kindo probes Anthropic, Azure, Copilot, ServiceNow, and Bedrock admin APIs to enumerate agents deployed across the enterprise — including those outside Kindo. Unauthorized agents are discovered, flagged, and routed into Kindo for governance. Once sanctioned and flowing through Kindo, Agent Telemetry provides continuous visibility: every agent in the catalog with creator, last updated, type, and telemetry export capturing every run.
We'd welcome your input on which platforms to prioritize for discovery integration.
Detect when new integrations to unauthorized tools/sensitive data sources are added.
Platform response: Pillar 1 + Pillar 3 — Platform Discovery + Network Monitoring (research complete). Shadow AI connections — direct Anthropic API usage, Copilot integrations, unsanctioned endpoints — are discovered through platform API probing and network-level detection. Kindo orchestrates existing endpoint detection systems to surface unauthorized tool and data connections across the enterprise. For sanctioned AI flowing through Kindo, the Federated MCP Gateway enforces real-time tool access policies, and trace detail captures every tool call with arguments and data returned.
We'd welcome your guidance on defining "unauthorized" within your governance framework.
Detect when actions performed are NOT in-line with the standard operating procedures defined for the agents.
Platform response: LLM Judges (alpha) — plain-language evals that score every agent run. Once workloads flow through Kindo — whether native or rerouted from discovery — judges flag behavioral deviations run-by-run against defined standard operating procedures.
To maximize this capability, we'd like to co-define which standard operating procedures and behavioral criteria the judges should evaluate against.
Detect changes in MCP/tool policies to provision edit/delete privileges to agents when not intended.
Platform response: Configuration panel — telemetry export, sampling rate, retention, and eval configs visible per agent.
Full change tracking and audit trail for configuration modifications is on the roadmap as a next step.
In the multi-tenant environment, detect data breach/contamination when agent for one client cross-references data of another client.
Platform response: Organization-isolated workspaces — traces stored per org, cross-tenant isolation enforced at the platform level.
Per-org isolation demonstrated in alpha. Production-grade cross-tenant monitoring is a planned enhancement.
For the next session, we'd like to walk through these capabilities together and get your input on shaping what comes next.
We delivered what we could advance autonomously. What comes next, we build together.
Sprint 2 (Jul 13–25). We focused on what we could advance autonomously. Items that need collaborative input are waiting for the next co-design session — we're aligned with your pace.
Alpha release: trace export, LLM judges, eval configuration, span detail, error diagnostics. Architected to graduate toward production — deployment is a next step together.
5-platform research (Anthropic, Azure, Copilot, ServiceNow, Bedrock). Based on public API documentation. Ready for your input on platform priority.
Kush endorsed gateway approach (Jul 16). Three-standard strategy documented. Architecture ready for collaborative refinement.
Two-tier model proposed: export (current alpha) vs native pillar. Alpha validated in development. Next steps depend on collaborative input.
Krishna-facing deliverable. 5–7 discovery methods with tier mapping. Ready for collaborative refinement.
Teams integration needs Deloitte IT coordination. Ready to pick up together in Sprint 3.
Requires work session with Zun. Ready to schedule when timing works for your team.
Depends on digital twin approach + design session with Krishna's team. Ready to co-design in Sprint 3.
Developed collaboratively at the Jul 10 co-design session. Three approaches to AI governance — each platform has different strengths.
Reach into Anthropic, Azure, Copilot, ServiceNow, Bedrock via admin APIs. Enumerate agents, audit usage, inspect configs.
Kindo as inference proxy — 2 lines of config to redirect. Real-time governance at the choke point.
Sweep for shadow AI — the long tail. Network and endpoint-level discovery beyond managed platforms.
Inspired by Krishna's CrowdStrike analogy — a menu of options, not one-size-fits-all. Proposed framework for co-design validation.
Telemetry export + audit log analysis. After-the-fact detection. Low adoption cost.
Native telemetry + LLM judges scoring every run. Real-time drift detection.
Gateway position = real-time control. Block unauthorized actions before they execute.
Proposed framework, not yet validated with Deloitte.
Per-platform capabilities for discovery and governance. Based on public API documentation — the research Krishna asked for.
| Capability | Anthropic | Azure AI Foundry | MS Copilot | ServiceNow | AWS Bedrock |
|---|---|---|---|---|---|
| List models/agents | ✓ API | ✓ ARM API | ~ Graph catalog API ² | ~ Table API ³ | ✓ API |
| Usage/audit logs | ✓ Usage/Cost + Compliance APIs ¹ | ✓ Azure Monitor * | ✓ Purview | ✓ System logs | ✓ CloudTrail * |
| Content/safety filters | ✗ Not via API | ✓ Full API + Terraform | ~ DLP policies | ~ Admin config | ✓ Guardrails API |
| Disable/block access | ✓ Key + workspace revocation | ✓ RBAC + Policy | ✓ Licensing + Integrated Apps (+ Entra CA) | ✓ Role-based | ✓ IAM + SCPs |
| Enforce policies | ~ Spend/rate limits (no content policy) | ✓ Azure Policy | ✓ DLP + labels | ~ Workflows | ✓ Guardrails + SCPs |
| Alerting | ~ Spend notifications + SIEM polling | ✓ Monitor Alerts | ✓ Sentinel | ✓ Event Mgmt ⁴ | ✓ EventBridge |
| Best Kindo method | API + Gateway (P1+2) | API + Gateway (P1+2) | API + Network (P1+3) | API (P1) ⁵ | API + Gateway (P1+2) |
✓ Full API · ~ Partial · ✗ Not available
Kindo reaches governance outcomes on existing open standards — no proprietary protocol required.
Chat Completions, Responses, Messages. 2 lines of config to route any agent through Kindo.
Single governed endpoint for tool/integration access. Real-time control over agent tool use.
OTLP-based. Kindo ingests traces from any AI workload. Foundation for evals and governance.
Sprint 2 builds directly on Sprint 1 and the Jul 10 co-design session. Expand each card for full detail.
The team built a SOC for AI Governance Monitor as a triggered agent on Kindo. The agent scanned the full Kindo deployment, evaluated active integrations, and assessed change management controls. The result was a proof of concept demonstrating that AI governance monitoring could work at speed — setting the stage for the Jul 10 co-design session with Deloitte.
Presented to Kush, Krishna, Nathan, and Zun. The session defined every deliverable in Sprint 2:
Kishore's email clarified a key misunderstanding: SOC for AI is about monitoring known AI agents and platforms — not shadow AI discovery, which is handled by Deloitte's detection engineering team. He defined the five governance objectives that became the foundation of Sprint 2 and specified two implementation requirements: (1) audit logs and telemetry data from the platform, and (2) a process and data collection architecture to monitor for these risks.
Take the feedback from Jul 10 and Kishore's objectives, and respond with working demonstrations: the platform compatibility matrix that Krishna requested, the three-pillar discovery architecture defined collaboratively by Charlie and Kush, and the agent telemetry capability — built natively inside Kindo — that makes governance monitoring concrete and testable.