First scrum cadence planning β aligning strategic decisions, team, and execution backlog
Sprint 1 Planning β 60 minutes. First formal scrum cadence session.
| Time | Topic | Owner | Goal |
|---|---|---|---|
| 0β8 min | Cadence & Ceremonies | Joana | Confirm scrum structure, ceremonies, artifacts |
| 8β15 min | Team & Hiring | Joana / Victor | Current team, Value First hires, role shifts |
| 15β25 min | Portfolio Overview | Joana | Agent status, priority shift, Kush decisions |
| 25β35 min | Deep Dive Sessions | Tony / Joana | Quarterly design sessions plan, first deep dive scope |
| 35β52 min | Sprint 1 Planning | All | Select backlog items, assign, define sprint goal |
| 52β60 min | Open Decisions | All | Blockers, needs-human items, next steps |
Three-layer cadence: 2-week sprints, monthly portfolio, quarterly deep dives
Execution cadence. Ship code, build agents, deliver results.
| Planning | Monday, Day 1 |
| Standups | Mon/Wed/Fri (team only) |
| Review + Retro | Friday, Day 10 |
| Tony attends | Planning + Review only |
Show results to executives. Video evidence + working links.
| First meeting | ~Late July (Jul 27) |
| Attendees | Tony, Charlie + Ron |
| Format | Show, don't tell (see below) |
| Note | Separate from quarterly deep dive |
In-person design sessions. Strategic alignment + release planning.
| Duration | ~5-7 days |
| Q3 location | TBD (Houston?) |
| With | Team + Ron + key engineers |
| Output | Quarter release plan |
| Artifact | Cadence | Description | Status |
|---|---|---|---|
| Sprint Backlog | Updated daily | Items committed for current sprint, status, blockers | Define |
| Burndown | Real-time | Story points or items remaining vs time | Define |
| Sprint Review Deck | End of sprint | Video evidence + working links of shipped work | Define |
| Definition of Ready | Standing | Criteria for items entering sprint (see below) | Defined |
| Definition of Done | Standing | Criteria for items being complete (see below) | Defined |
We're moving at 5Γ traditional speed. Words can't keep up. Ron didn't understand net new revenue agents until the third time Tony explained it β and Ron is the sharpest person in the room. If Ron needs three reps to absorb a verbal summary, everyone else needs more.
The old way (what we stop doing):
The new way (what every portfolio item needs):
| Month | Location | Notes |
|---|---|---|
| July | Houston | Ron in Houston Jul 27 β anchor event |
| August | San Francisco | Krishna's base |
| September | Austin | Tony's base |
| October | Los Angeles | Charlie's base |
β οΈ Tony proposal β Joana to map against quarterly deep dive schedule to avoid over-travel.
Current team, role evolution, and Value First hiring plan
| Person | Current Role | Evolving To | Sprint Role |
|---|---|---|---|
| Tony | Strategic leadership | Product Owner (biweekly) | Sprint planning + review only |
| Joana | Program delivery | Net new revenue agent design | Scrum lead + agent designer |
| Victor | Technical delivery | Net new revenue agent design | Technical lead + agent designer |
| Charlie | Chief Architect / Agent Runtime | Platform + architecture decisions | Technical advisor |
| Warren | Engineering & Ops AI | Scrum master + execution engine | Artifact delivery, sprint tracking |
| Dukane | Delivery support | QA manager (#warren-review) | Output quality review |
| Role | Count | Region | Focus | Status |
|---|---|---|---|---|
| AI PMO / Soft Skills | 2-3 | LatAm (preferred) | Requirements gathering, stakeholder mgmt, verification | Interviewing |
| Engineer | 1-2 | Eastern Europe or LatAm | MLflow, Kindo agent configuration, integrations | Planning |
Process: Invoice β Charlie β Ron. Charlie vets technical candidates. LatAm for soft-skills (live meetings), Eastern Europe for code (Charlie's preference).
| Team | Status | Expected Back | Impact |
|---|---|---|---|
| Agent Runtime (Madison) | PTO | Early July | Multi-agent, agent features blocked |
| Agent Runtime (Sean) | PTO | Week of Jul 7 | Reduced velocity past 2 weeks |
| Core Kindo (Brian Van) | PTO | Mid-July | Core platform changes blocked |
| Charlie (Agent Runtime lead) | Active | β | Shipped memory prototype solo |
Sprint 1 implication: Focus on soft-skills deliverables (requirements, agent design, research) that don't need Kindo eng. Engineering-dependent items slot into Sprint 2+ when team is back.
Agent portfolio with June 24 priority shift β SOC for AI is the new #1
| ID | Agent | Status | Revenue Class | Blocker |
|---|---|---|---|---|
| A.1 | Threat Monitoring | PROD | Contracted | β |
| A.2 | Threat Intel | PROD | Contracted | β |
| A.3 | Threat Hunt | PROD | Contracted | β |
| A.4 | Detection Engineering | PROD | Contracted | β |
| A.5 | CTEM | BUILT | Contracted | Deployment pending |
| A.6 | Vitals Dashboard | βΈοΈ DEPRIORITIZED | Alliance | Kush shifted to SOC for AI |
| A.7 | Quality Audit Agent | REQS | Alliance | Design sprint needed |
| A.8 | Cloud Security Agent | PLANNED | Alliance | β |
| A.9 | IR Agent | PLANNED | Alliance | β |
| A.10 | IoT/OT Monitor | βΈοΈ DEPRIORITIZED | Alliance | Kush shifted to SOC for AI |
| A.11 | Custom Client Agents | REQS | Alliance | Shadow & document method |
| A.12 | Identity Agent β IdaaS | PLANNED | Alliance | Tim Corder engagement |
| A.13 | GRC Agent β GRC aaS | PLANNED | Alliance | Nathan Ellis engagement |
| NEW | SOC for AI | π΄ #1 PRIORITY | Alliance | Research + integration mapping |
"Shadow IT for AI" β discover which AI tools, agents, LLMs, copilots, MCP servers run across endpoints, SaaS, cloud; then govern, policy-enforce, remediate. Now #1 priority (Kush deprioritized A6 + A10). Distinct from A.1 (Threat Monitoring) β A.1 is Deloitte's existing SOC agent; SOC for AI coexists with / complements it.
π Layer A β Shadow AI Discovery
Which AI, by whom, how much, what risk. Via CASB/SSE + IdP + DLP + SIEM the client already owns.
π» Layer B β Endpoint / EDR Telemetry
Orchestrate EDR/SIEM agents already on the machine (CrowdStrike-style). No new agent installs β Deloitte was explicit.
Mechanism: API-level orchestration of existing monitoring agents; build domain-specialized agents inside Kindo. No core architecture change. ~80% soft-skills / ~20% engineering.
Validated Market Timing:
Source: SOC for AI β Scope & Research doc (Jun 25). Tenant-safe = research-grade, needs Charlie's sign-off. Registry status needs Victor/Charlie confirmation (Q1).
Already in Kindo β can start immediately (confirm registry):
| Platform | SOC-for-AI Capability | In Kindo? | Tenant-safe? |
|---|---|---|---|
| CrowdStrike Falcon | Shadow AI Discovery β AI apps, agents, LLM runtimes, MCP servers | β CONFIRM | β οΈ Per-tenant (cloud control plane β see Q2) |
| Splunk / Datadog | SIEM + observability for AI activity | β CONFIRM | β Yes |
| Grafana / Sumo Logic / Google SecOps | Dashboarding, log analytics, security ops | β CONFIRM | β Yes |
Gaps β likely need new integrations:
| Platform | Capability | Tenant | Priority |
|---|---|---|---|
| MS Defender for Endpoint | Shadow-AI discovery (Agent 365 β GA May, preview Jun 2026) | β Azure-native | P1 β biggest gap |
| MS Intune | AI agent policy enforcement on devices | β Azure-native | P1 |
| MS Purview | DLP / data classification for AI | β Azure-native | P2 |
| Nightfall / Netskope / Cyberhaven / Okta | GenAI DLP, CASB, data lineage, OAuth-consent discovery | β οΈ Validate | P3 |
Quarterly in-person sessions β strategic alignment + release planning with Deloitte
These items were categorized under "design sessions" in Tony's meeting notes. More than half of what Deloitte raised maps to these sessions.
| # | Topic | Description | Owner |
|---|---|---|---|
| 1 | Net New Revenue Agents | Design + deploy agents that generate alliance revenue (Tier 2/3 packages) | Tony / Joana |
| 2 | Threat Remediation | Extend A.1-A.5 into automated remediation workflows | Charlie / Victor |
| 3 | Deloitte Roadmap (Azure/GCP) | Cloud platform alignment and multi-cloud strategy | Charlie |
| 4 | Institutional Knowledge / Memory | Skills, memory, compound learning flywheel. β οΈ Don't equip Deloitte to build what we want to build (Charlie) | Charlie |
| 5 | AI Cyber Guard / Tower | Control plane co-development | Charlie |
| 6 | Lifecycle Hooks | Generic lifecycle hooks β Kush says yes but NOT most important. Ship fast MVP, don't over-engineer. Deployment speed > stickiness features. | Charlie |
| 7 | Workflow Acceleration | Accelerate deployment cycle (time-to-value for new Kindo customers) | Victor / Joana |
| 8 | SOC for AI | Shadow IT discovery, AI governance, integration mapping | Joana / Victor |
An item can enter the sprint when ALL of these are true:
| # | Criteria | Why |
|---|---|---|
| 1 | Clear outcome defined β what does "done" look like in business terms, not technical terms? | Victor's point: business value, not technical value |
| 2 | Owner assigned β single person accountable | No orphan items |
| 3 | Dependencies identified β blocked/unblocked explicitly tagged | Victor's framework: shoot where we're unblocked |
| 4 | Effort estimated β days, not points. Be honest. | Tony needs to know what to expect without asking |
| 5 | Classified soft-skill vs code β which work type? Determines who can execute. | ~80% soft-skills moves without Brian's team |
| 6 | Passes tenant filter (if integration) β tenant-scoped? data stays in tenant? SOC 2 II / BAA / DLP? | Tony's note #1: "Deloitte only" |
| 7 | Fits the sprint β total committed work β€ team capacity | Don't overcommit then under-deliver |
| 8 | Acceptance criteria written β how will we verify it's done? | "Show don't tell" starts here |
An item is done when ALL of these are true:
| # | Criteria | Evidence Required |
|---|---|---|
| 1 | Acceptance criteria met β every criterion checked off with proof | Screenshots, video, or live URL |
| 2 | Business done, not just technical done β stakeholder can see and use it | Working link or deployed artifact |
| 3 | Evidence attached β "show don't tell" proof in the same message as the completion claim | Video walkthrough, screen recording, API response |
| 4 | Integrations pass tenant + compliance check | Tenant filter results documented |
| 5 | No open blockers or regressions | Verification report |
| 6 | Reviewed β at least one other team member has seen the output | Reviewer name + β /β οΈ/β |
| 7 | Documented so Warren can report status | Warren updates programmatically |
| 8 | Owner confirmed done | Explicit sign-off |
Target: TBD (separate from monthly portfolio meeting). 5-7 day in-person session. Team + Ron + key engineers. Output: Q3 release plan, SOC for AI architecture, net new revenue agent designs.
Target: October. Location TBD. Review Q3 results, plan Q4 releases, expand to service lines beyond D&RaaS (Identity aaS, GRC aaS).
First sprint: focus on soft-skills deliverables while engineering is on PTO
Validate scope β design AI Discovery Agent β build v1 in Kindo
This is ~80% soft-skills work β agent configuration, not code. Warren accelerates: research (done), design docs, agent config specs, Kindo setup. Goal isn't just a design β it's a working agent in Kindo by sprint end. Human effort = scope confirmation (Joana's 5 Qs) + validation + review. Warren does the build grunt work.
| Item | Type | Owner | Effort | Dependencies / Risks |
|---|---|---|---|---|
| SOC for AI β Scope Confirmation Get answers to Joana's 5 questions from Charlie & Victor: registry check, CrowdStrike tenant isolation, Microsoft path, first deliverable sizing, control plane alignment |
P0 | Joana | 1d | β οΈ Depends: Charlie & Victor input β οΈ Risk: Questions sent Jun 25, still awaiting answers. If not answered before Monday, sprint planning has no confirmed scope. |
| SOC for AI β AI Discovery Agent: Design + Build v1 in Kindo Design + configure in Kindo: CrowdStrike Falcon (if tenant-safe) + MS Defender; AI app/agent inventory; dashboard; tenant-scoped data. Warren produces agent config spec + builds draft in Kindo. Human effort = review + validate. Per Joana's Β§4. |
P1 | Warren + Victor | 2d human / 6d Warren | β οΈ Depends: scope confirmation β οΈ Risk: CrowdStrike cloud control plane may not pass tenant filter (Q2). If Layer B blocked, pivot to Layer A only β smaller but still a working agent by Jul 10. |
| Outcome Package β Skill Conversion Reverse-engineer Tony's Warren process into reusable OpenClaw skill (Charlie directive) |
P3 | Victor + Warren | 2d | β οΈ Unknown state Victor said "I think I already did that" β needs confirmation. If done, just verify. If not, real work. |
Show-don't-tell: every criterion needs evidence, not a status update.
Items that produce a built artifact (agent, integration, code in Kindo) β ranked by strategic priority
Parallel track β program management work that needs an owner and date but doesn't produce a product artifact. Not sprint-rankable. Joana's track.
| Item | Owner | Target Date | Notes |
|---|---|---|---|
| Scaling Story for Ron / Forge Point | Tony + Joana | Monday Jun 29 | Capture while Tony is present β he goes biweekly after. 3-5Γ revenue growth narrative for Forge Point VC. |
| Monthly Portfolio Prep (July) | Joana | Ahead of Jul 27 Houston | Video evidence + working links for shipped functionality. |
| Value First Hiring | Joana / Victor | Ongoing | Interviews in progress. Invoice β Charlie β Ron. |
| Deep Dive Prep / Calendar + Budget | Tony / Joana | TBD | Map quarterly deep dives against monthly portfolio, avoid over-travel. |
| Warren Scrum Artifacts Setup | Joana + Warren + Victor | Sprint 1 | Configure Warren for sprint backlog, burndown, status delivery. β οΈ Verify accuracy before Tony relies on it. |
Items requiring team input during Monday's planning
These 5 questions were sent to Charlie & Victor β answers gate the Monday backlog. Source: SOC for AI β Scope & Research doc.