Strategic Briefing v3 — August 2026 · Backlog-Anchored

SOC for AI

How Kindo becomes the independent governance control plane for enterprise AI — re-anchored to Kindo's live engineering backlog.

Every enterprise is deploying AI agents. Most have no idea what those agents are doing.

AI agents are making tool calls, accessing sensitive data, executing code, and interacting with production systems — with minimal oversight. Traditional security tools were not built for autonomous AI workloads.

Palo Alto Networks launched Prisma AIRS. CrowdStrike has Falcon AI Protection. Google SecOps is adding AI detection. Microsoft has Security Copilot. Each vendor is racing to own "AI security."

But every one of these products has the same structural limitation: they only govern what passes through their own ecosystem.

"Prioritize Guardian Agent solutions independent of AI agent platforms to ensure cross-cloud governance, full enterprise information governance, and avoid vendor lock-in."— Gartner, Market Guide for Guardian Agents, February 2026 (G00836388)

Gartner projects this market at $3B+ annually by 2030, with Guardian Agents eliminating ~50% of incumbent risk/security systems in 70%+ of organizations by 2029.

The unit of competition is architectural layer, not feature parity.

Palo Alto Networks' Prisma AIRS = runtime security product. Inline network/API intercept. Infrastructure-layer security applied to AI traffic.

Kindo = governance control plane. The platform AI workloads run through — not a filter traffic passes by.

The Reframe

Kindo and runtime security vendors are not competitors. They are different layers. The demo is not "Kindo does what Prisma AIRS does." It is "Kindo governs your entire AI landscape including your Prisma AIRS deployment." The two differentiators that genuinely hold as architectural differences: cross-vendor independence and custom-built to requirements.

What Kindo delivers — honest status from the live backlog.

🔑

Pillar 1: Inference Governance

Route all AI inference through Kindo. Policies, model blocking, Data Loss Prevention (Presidio), RBAC, complete audit trail.

● Live — General Availability
🔧

Pillar 2: Tool Access Governance

Federated Model Context Protocol gateway. Per-integration/per-action access controls. One connection point, full audit trail.

● Live — General Availability
📊

Pillar 3: Telemetry

Export path: SHIPPED behind flag (ENG-10891, merged to main). Google SecOps = validate config, not build.
Native storage + dashboard: DESIGN STAGE (ENG-11460). This is the real work.
Inbound ingest: DESIGN STAGE (ENG-11461).

◐ Export Shipped (behind flag) · Dashboard Not Started ENG-10891 (Done) · ENG-11460 (Backlog) · ALI-39 (Urgent)
🛡️

Pillar 4: Policy Enforcement

Core hook engine: IN REVIEW (ENG-11023, M0 contract + pipeline).
Policy-judge layer: PROJECT EXISTS (Guardian Model, owner: Nick).
Admin guardrails: OWNED (AI Guardrails spec, owner: Josh).

◐ Core Engine In Review · Attachment Points Not Built ENG-11023 (In Review) · Guardian Model (Nick) · AI Guardrails (Josh)

Turbo Mode — Dependency at Risk

Compiled artifacts for accelerating policy hooks. PR #12155 is OPEN and CONFLICTING — not on main. LLM-only hooks are the base case for October. Turbo acceleration is a bonus if the PR lands.

⚠ At Risk — PR Conflicting ENG-11252 (In Review) · PR #12155 (conflicting/dirty)

Kindo governs across vendors — not alongside them.

KINDO — Independent Guardian Agent Platform

Inference Governance (LIVE) Tool Gateway (LIVE) Telemetry Export (SHIPPED) Policy Hooks (IN REVIEW) Behavioral Analysis (PLANNED) Cross-Vendor Independence Custom-Built to Requirements
orchestrates ↓ (Google SecOps via existing BYO OTLP sink today · others = roadmap)
Table Stakes — exist at both layers
Prompt Injection Defense · Data Loss Prevention · Audit Logging · OpenTelemetry · Model Access Control
Palo Alto Networks

Prisma AIRS · Network/API Intercept · AI Runtime Security

CrowdStrike

Falcon AI Protection · Endpoint · Shadow AI · Threat Intel

Google SecOps

SIEM · Investigation · Threat Detection · OpenTelemetry

Microsoft

Security Copilot · Defender · Sentinel · Entra · Purview

What's real, what's planned, what's at risk.

CapabilityPrisma AIRSCrowdStrikeGoogle SecOpsMicrosoftKindo
AI Inference GovernanceNoNoNoNoLive
Federated Tool GovernanceNoNoNoNoLive
Cross-Vendor IndependenceNoNoPartialNoYes
Custom-Built to RequirementsNoNoNoNoYes
Agent-as-Judge EnforcementNoNoNoPartialPlanned
Session-Level Behavioral AnalysisNo*NoNoNoPlanned
Turbo-Accelerated EnforcementNoNoNoNoAt Risk
Prompt Injection DefenseYesYesNoYesPlanned
Network Traffic InspectionYesYesNoNoNo
Endpoint ProtectionNoYesNoYesNo

*Prisma AIRS has "Agentic Threat Protection" (identity impersonation, memory manipulation, tool misuse) at the network layer — closer to behavioral analysis than a simple "No" implies. Kindo's planned hook model provides deeper session look-back with agent reasoning. Gap is narrower than it appears.
Sources: Prisma AIRS datasheet (primary). CrowdStrike, Google SecOps, Microsoft from web research — verify against vendor datasheets.

The client narrative.

"You have Palo Alto Networks protecting your network traffic. You have CrowdStrike on your endpoints. You have Google SecOps in your SOC. None of them can see across each other. That's what Cyber Digital Analyst does — it's the independent governance layer that orchestrates all of them. Gartner calls this a Guardian Agent."

The Demo Flow

1

Registry

"Here are your AI agents. Here are the high-risk ones. Click one."

Requires: extend Command Center Maturity project with risk scoring
2

Telemetry

"Here's what this agent has been doing. This data also flows to your Google SecOps."

Demo-able today: ENG-10891 export path exists (GA the flag + validate SecOps config)
3

Prevention

"No agent accesses PII without authorization. Hook caught it. Blocked. Logged."

Requires: ENG-11023 hook engine + Guardian Model — October target
4

Behavioral Analysis

"This agent's behavior is anomalous. AI judge reviewed the session."

Requires: ALI-39 co-design + hooks — October stretch target

October 2026 — Credible-Hard, Not Credible-Easy

GA-ing the export flag = the easy 20%. Native storage + dashboard + shipping hook attachment points from existing specs = the genuinely hard 80%.

Phase 1 — August
GA telemetry export (flip ORG_TELEMETRY_SINKS). Validate Google SecOps as BYO OTLP destination. Hook engine M0 lands.
ENG-10891 → flag flip · ENG-11023 (In Review)
Phase 2 — September
2 hook attachment points ship (before-inference, before-tool-call). Deterministic + LLM-judge modes. Wire to Guardian Model. Extend Command Center with risk scoring.
Lifecycle Hooks project · Guardian Model project · Command Center Maturity
Phase 3 — Sep/Oct
Native telemetry storage design → build. Basic dashboard on ClickStack. End-to-end demo. Stakeholder preview.
ENG-11460 (design) · Net-new frontend

What October Does NOT Include (Q1 2027)

Inbound telemetry collector (ENG-11461). Full 4 hook attachment points. Cross-session behavioral scoring. Auto-remediation. Palo Alto / CrowdStrike integrations. Shadow AI discovery. Turbo-accelerated hooks (unless PR #12155 lands).

What Kindo will not do — and why that's a strength.

Kindo will not run software on endpoints. Will not inspect network traffic. Will not guarantee detection of unsanctioned AI. These are deliberate architectural boundaries — Kindo orchestrates the tools that DO those things.

Strongest posture: "Only hand out Kindo API keys for AI use."

Horizon Risk: Local Models

"AI models are getting smaller and smaller. At some point, there's gonna be local models proliferating on machines. You won't have the opportunity to just turn off the API keys." — Charlie, Aug 7. No vendor has an answer to fully-local shadow AI.

Engineering Capacity

"I don't know who can build pillars three and four at Kindo. No one. I literally had to do pillars one and two against Ryan." — Charlie, Aug 10. Charlie is going on vacation. The PRD builds on existing initiatives with named owners (Josh, Nick) rather than requiring new architecture.

What could go wrong.

RiskLikelihoodImpactMitigation
Charlie unavailable + no one else can architect pillars 3-4HighCriticalBuild from existing specs with named owners (Josh, Nick). Scope to minimum.
Turbo mode PR stays conflictingMediumMediumLLM-only hooks = base case. Turbo = bonus.
Stakeholders continue feature-parity comparisonHighHighFollow-up meeting must reframe positioning before product demo.
Deloitte agent-run reliability issues (ALI-41, ENG-10478, ENG-9375, ALI-36)HighMediumPrioritize reliability tickets. Governance pitch on unreliable platform undercuts itself.
Dashboard design not started (ENG-11460)MediumHighScope to extending Command Center, not new surface.
Cyber Digital Analyst scope undefinedHighMediumResolve before engineering scopes October.

Adopt this positioning. Scope October to the minimum demo-able surface.

Positioning: Independent Guardian Agent platform. What Kindo actually is — not a marketing reframe.

The two rows that win: Cross-vendor independence + custom-built to requirements. Genuine architectural differences no vendor can replicate.

October scope: GA telemetry export + 2 hook attachment points + extend Command Center with risk scoring + validated Google SecOps config. Credible-hard.

Base case: LLM-only hooks (no turbo). Full vision (4 hooks + behavioral + turbo + inbound ingest) = Q1 2027.

"No vendor can credibly sell independence from itself. That's why the governance layer must be independent. That's Kindo."