AI Team — everything in flight
Every workstream the AI team has open, laid out by the function it serves. Within each lane: not yet started, actively being worked, finished. Diamonds mark the items that move the needle for that function — if a lane's priorities all land, that function is measurably better off. Everything here is written as an observation and an opportunity; none of it is intended as attribution.
4 August 2026
Day 60 of 90
How this works
- Leadership set the deliverables. The six below, in priority order, with the key results they’ll be judged on. You can’t change those here — they’re maintained on the direction board.
- You tell us which work delivers them. Hit +1 on anything in the lanes that you think matters. No limit, and you can change your mind.
- If it’s missing, add it. Use + add an item and say which deliverable it serves — or say it serves none of them. That last answer is the most useful one we get.
Everything you do is attributed to your name and visible to the team. Leadership reads which deliverables are drawing support, and what people are asking for that sits outside the plan.
Synced from last week’s meetings — 27 July to 3 August. Anything added in that
sweep is tagged New. Cards link out to Jira, GitHub and Confluence where the detail lives.
Quarterly deliverables
signed off by leadership · maintained on the direction board
Hit +1 on whatever you think we should be working on. Counts are shared — hovering one shows who picked it. Missing something? + add an item puts it on the board. Your own picks and additions save instantly and survive a refresh; other people's arrive on sync, so hit refresh if the tally looks behind.
Support & CSP48 items · 14 priority
The 8/12 decision is the fork in the road. Everything else in this lane is either evidence for that call or work that matters whichever way it goes.
Ideas19
Decouple internal analysis from the reply gateNew
Raised by Shane Storm at the end of July: the internal analysis comment and the customer-reply gate are coupled, so one cannot be produced without arming the other. The coupling has been traced in code; no ticket exists for it yet, which is the first step.
Agentic engine still routes to a departed leadNew
The legacy engine was corrected, the agentic one was not, so it can still assign to someone who has left. Unassigned since 7/28 and quiet rather than urgent — which is exactly the kind of item that stays open.
Rotate the committed GCP keySev-0
Surfaced in the June audit and still open. Currently tracked in GitHub only, which makes it easy to lose sight of.
Scope RAG retrieval by accountSev-0
Cross-customer leakage. A sweep of MD, MOR, SFD, AS and ATLAS shows no ticket covering it yet, so filing one is the first step.
Non-prod environment
Blocked twice — the Key Vault our IaC references doesn't exist, and the AAD app registration needs an identity admin.
MR3 Resiliency
26 story points, unassigned.
Template-only outbound + send gate
Constrains customer-facing output to templated first-touch info capture, with an unconditional backstop.
Content-capture ADR + Vapi voice seam
This is the telephony ADR. Scoped 7/13, still unwritten. Deciders are Travis, Elisson and Angel.
Off-hours blackout reads UTC
The last civil-date UTC read left in the source. Sibling bugs are closed; this one isn't.
CSP GitHub approver provisioningNew
Three or four CSP approvers need GitHub access. Nothing reaches prod without a CSP signature.
Groom the backlog for CSP self-serveNew
The aim is for any CSP lead to influence triage priority without booking a meeting, prioritised by customer impact and breadth rather than story points.
Refresh the Salesforce sandboxNew
Last refreshed 6/21, which predates the host change, so validations assert on queue keys rather than names in the meantime.
Lag + degradation alertingNew
With named approvers. Next roadmap step after the full-journey sandbox test.
Shadow-mode POVNew
Route live traffic through Fin for an apples-to-apples read. Threshold is set: it has to replace 30–40% of CSP volume, pushing for 60%.
Commercial + technical diligenceNew
Contract Fin directly rather than through Salesforce — that deal closes 1/31/27 and we'd inherit assumed 3× price bloat. Also: what Apex 1.0 actually is, reference customers, and whether it can auto-close AS cases in-platform.
Onboarding pilot config
Madeleine's process knowledge as the config source. Starts 8/12.
Silent-failure SLO
Heartbeat plus "eligible case, no response in N minutes." From the June audit; untracked.
Vapi consolidation review
Sharper now: a spend of only a few hundred a year, routes to humans with no context into any other system and no resolution capability. The Vapi front door is itself cited as a driver for replacing Morpheus.
Claude as CSP first-line responderNew
Building on the Claude Tags rollout: repo access plus full project context, so Claude answers in the feedback channel and raises draft PRs with a human before merge.
Doing11
Origin-filter guardNew
Epic GH 286. The blindness alarm went up as PR 290 on 8/5 and is waiting on review; the nightly drift check and a one-page summary for stakeholders are the two pieces left, and the epic closes with them. Related and now understood: the case-origin dropdown looked like it had a ghost value because “Email: CSP” was deactivated back in July 2025 — the list is frozen by agreement until the permanent guard lands.
Release gating + CI enforcement
Wire the regression gate to block merges, add secret and PII scanning, and put CSP dual approval on the release. The regression protection is written and sound — it simply isn't enforcing yet, so the remaining work is wiring rather than authorship.
Full-journey sandbox integration tier
Case → route → render → send, asserted end to end. The interim FullSB validation path landed 8/4 and the first nightly run against it came back green at 01:16 on 8/5, so the Friday CSP path is covered. What remains is the Service Cloud tier itself — worth confirming whether MD-152 is the same slice as the closed GH 260 or a separate one, since the two records read differently.
Behavioral test corpus
Mining the CSP feedback channel into redacted replay fixtures. First tranche merged — 17 tests, 13 spec-locked.
Observability epic — remaining spans
Prod image rebuild is done. Still open: masked content attributes on customer-email spans, tracing the fail-open QC gate, and the seven decision-outcome attributes that unlock automation rate and cost-per-outcome.
AM-forwarded email breaks routing
Salesforce assigns the TrustedTech account when an employee files on a customer’s behalf, which also mis-flags it as US-based. The code is written and GH 285 has been ready to go since 8/4 — it is held on three yes/no questions that need Travis: whether the fix corrects silently for accounts we own or gates on a human, and whether Salesforce gets a new field to mark “internal on behalf of external”. This one is ours to unblock rather than anyone else’s.
Triage ignores workload and complexityNew
Experienced agents receive the same volume as new hires, and status transitions like Customer Replied or On Hold don't update automatically.
Work the telephony RCA findings throughNew
The RCA gave us 67 findings; turning that into sequenced, owned work is the next step. Several need an owner, the voice estate has thinner test coverage than Morpheus core, and the document currently lives in Slack rather than anywhere durable.
Voice RCA remediation
67 findings, 10 critical. Since 3/16, when inbound moved to an assistant that had no extraction schema attached, the structured fields have been filling with defaults instead of captured values — the feed read 3 case creations since April where Vapi recorded 143. Worth stressing: cases were created correctly throughout, so this is a reporting gap rather than a service failure. Remediation is sequenced and awaiting a go.
Replace Morpheus with Fin.ai8/12
Worth being clear on the framing: this is removal and replacement rather than two tools coexisting. Go/no-go to Todd and Julian on 8/12. Costs corrected to a low six-figure annual run rate at ~12,500 cases a month with 3× assumed inside three years, noting a headcount cost only offsets if the role is removed rather than redeployed. Migration floor is firm — every existing routing rule, automation and integration carries over, configured as IaC not ClickOps.
Account Services queue crisisNew
270 open cases, with arrivals outpacing closures. Distribution is uneven — 34 tickets in one place against 2 in another — some cases are sitting untouched, close-count targets are pulling behaviour in unhelpful directions, and tickets are landing on the wrong accounts. Madeleine and Junon own it; we're advising.
Done18
Origin-guard spec and intake telemetryNew
Three PRs merged on 8/4 — the nightly workflow moved onto a new flow tier, the origin-guard spec landed, and intake telemetry went in behind it so the guard has something to read.
Case-origin picklist traced to sourceNew
Worked through with Neil Blackman, Angel Moreno and Robert Craven on 8/3. The value had been deactivated a year earlier, which is why nothing in our code explained the behaviour — a good example of a Salesforce-side change surfacing as an application bug.
Code-grounded audit
Eight parallel agents across the codebase. Surfaced three Sev-0s and graded observability, data isolation, secrets, LLM security, IaC and data governance.
EU AI Act Article 50 disclosure
Fail-closed renderer that refuses to emit any customer body without the footer; signature moved to a non-human persona. Landed ahead of the 2 August enforcement date.
Deterministic if/then routing
No free-form LLM responses reach customers.
Outbound-email fail-closed guard
Never emails real case contacts from dev or test; fails closed if unset, bypass-proof across both engines. Plus a fail-loud stage preflight.
Redaction hardening
Salesforce IDs were reaching Langfuse on 5,000 of 5,000 cases. Now zero.
Delivery model reset
Agentic-first, trunk-based on main, GitHub as source of truth, branching ADR and release playbook.
CI as a real gate
Pytest promoted to a blocking required check; the hollow test check that passed on collection failures is fixed.
Nightly autonomous CINew
First unattended overnight run against the Salesforce sandbox passed 7/31, with five PRs shipped — gate on every change, realistic routing cases, safety whitelist locked by tests, sandbox and prod signals separated. Every CSP-reported bug now becomes a permanent nightly test.
Observability foundation
OTEL plus Langfuse across five workstreams, 2,500+ traces, customer-content masking verified on live data, and the prod image rebuilt so it stops no-opping.
Timezone / OOO bug class eliminated
Fixed in both engines with frozen-clock regression tests at the write gate.
Immutable-digest prod pinning
Retired the shared :latest tag that let a dev deploy silently arm a prod restart.
Replay harness + promotion-gate ADRs
Fixture-driven corpus replay, plus a coverage ratchet in CI.
Non-prod sandbox plumbing
Email-to-Case seeder, whitelist refresh, and sandbox-org selection unified across four conventions — two of which were hardcoded to prod. All four tickets closed 8/3 with their PRs attached, along with the CI promotion-gate replay and coverage ratchet.
Release cadence lockedNew
Release-based development shipping Tuesday or Wednesday, never Friday, with auto-generated notes naming who signed off. The Friday feedback call became a mandatory go/no-go approval meeting.
Monday CSP alignment callNew
7:00 AM PST recurring, timed to catch the UK team before they drop. Leadership summary posts to CSP Slack straight after. Intake is moving to Jira Service Management.
Voice RCA + n8n platform audit
67 findings on the voice estate; 37 n8n workflows inventoried and 11 unauthenticated public paths found, one of which attempts to bulk-modify cases.
Sales & Revenue33 items · 10 priority
The end state is a seller who walks into every call already equipped — a daily note on what to focus on, a calendar booked for them, the QBR deck built, the meeting brief waiting from Gong. Every item here should put more in the rep's hands so they ask the right questions and push the products that line up with the incentives, the Microsoft funding and the services we can actually deliver. Anything that only produces a dashboard gets cut.
Ideas21
Retier on revenue and white spaceNew
Tier 1 currently spans a fifteen-fold range of monthly revenue, which is too wide a band to act on — the same label covers very different accounts. The proposed structure is Flagship, Strategic, Growth, Emerging and a T6 held by onboarding and renewal rather than a dedicated AM, set on revenue and growth potential together and re-tiered as accounts move rather than once a year. Jose and Parker own it; a few data inputs are still needed before it can roll out.
Notes field at account, contact and opportunityNew
Asked for as an open scratch pad that can actually be surfaced on a board. Gong’s own right-pane note cannot be pulled through, so a dedicated field is what makes the context visible where the work happens.
692 calls showing as unrecordedNew
Most likely call-no-answer dispositions rather than the Gong recorder being ejected, but worth confirming before any metric rests on call volume — the difference decides whether the number is a data artefact or a coverage gap.
Duplicate contacts inflate multi-threadingNew
The same person under two email addresses counts twice, so an account can clear a three-contact bar on one relationship. Merging is manual and only about three people can do it, so the threshold needs to allow for this rather than assume clean data.
Health score: Salesforce now, Gong laterNew
Phase 1 uses the Salesforce score even though everyone acknowledges it is polluted — Angel is rebuilding it and the latest iteration reads considerably healthier. The open question is whether Gong can derive a dependable score faster than Salesforce can be repaired; agreed to revisit rather than fork now.
Platform-enforced data hygieneNew
Data hygiene in Salesforce is limiting what the Gong, AppDirect and Partner Center integrations can do. The durable fix is letting the integrations enforce the rules so the platform holds the line, rather than relying on manual discipline — which is also what lets sellers stay out of these tools and sell.
Daily focus note per repNew
One note every morning saying what to work today and why, ranked. The /am and /bd pilots are two halves of this — the single daily artefact doesn't exist yet.
Auto-booked calendarsNew
Rather than telling a rep who to call, put it on their calendar. This is the step that turns a ranked list into actual coverage.
Gong meeting briefsNew
A brief waiting before every call — who's in the room, what's live, what's expiring, which incentives and funding apply.
Named at-risk renewalsNew
Three stand out. The largest, a top-tier account renewing 10/1, has no next call booked yet. A mid-tier one, an order of magnitude smaller, rests on a single contact. A third shows zero MRR against an open renewal, which is either a data issue or real. Owner: Parker.
Weekly AE/AM alert cadenceNew
Parker and Jose are defining what goes out each week of the month and what action it should prompt. This is the last open piece of the KPI work in the Doing column — deferred to a Parker and Jose session and not yet closed out.
Accounts by industry verticalNew
Asked for on an investor call; needed to match portfolio companies to real pipeline.
Salesforce Slack bot vs Claude MCPNew
The native bot is signed but not yet rolled out, and it inherits user permissions at no token cost. Worth mapping which skills retire and which should call the bot for Salesforce data.
Provision Claude for the Salesforce teamNew
Tickets via Ops with Andy approving, on the standard per-user spend default. Separately, the connector-broadcast checkbox is still off pending a review of the announcement text.
Backfill support for Parker and JoseNew
Kevin's departure leaves both of them carrying more, and also removes the co-builder of /qbr. Worth agreeing together what we absorb, what we automate, and what can reasonably wait.
Parker's monthly operating rhythmNew
The loop he runs each month: close the month, work out what to focus on, focus and track it, then start again. Every stage is manual today, which makes it one of the highest-leverage things we could hand him.
Salesforce data dictionary crawler
Method now defined: metadata-scoped read-only key, Claude drafts field descriptions with confidence scores, CSV review, then writeback on a monthly schedule.
Gong → Salesforce auto-note flow
Blocked differently than we thought — the sync is switched off over Salesforce storage cost. Storage was just cleaned up, so re-enabling is the real next step.
Gong AI Data ExtractorNew
Pull competitors, decision makers, close dates and discounts straight out of conversations so reps stop hand-filling fields.
Pre-call customer briefs in invitesNew
Guardrail against over-automation. Real case: an AM didn't know a contact's role mid-call. Goal is "AMs approve, not compose."
Quote agent
Chargebee + Partner Center + promos → three options. Prototype exists; blocked by quoting instability upstream.
Doing9
War Room dashboard — Phase 1 in GongNew
Scoped with Jose, Parker, Jamie and Martin on 5 Aug, and deliberately narrow: three buckets now, everything else later. Communications — inbound and outbound calls, emails and meetings, personalised outreach only, with marketing blasts filtered out rather than counted as engagement (they can sit in their own sub-bucket to watch for correlation, but they are not AM activity). Renewals — upcoming count by month, close date against actual close date so an early or late close can be traced back to whether anyone reached out, closed-lost dispositions, and contact coverage. Customer engagement — QBRs, defence calls and renewal QBRs by count, ChiliPiper meeting types, reciprocity over a 21-day window, opportunities created, and multi-threading against a bar of three or more active contacts. Health score stays on Salesforce for this phase and data hygiene is Phase 2 — both by agreement rather than by omission. Building in Gong for Friday’s review; the ChiliPiper meeting-type list from Jose and Jamie is the one input still outstanding.
AM/AE KPIs with Jose and ParkerNew
The previous volume targets — 40 calls, 15 meetings and 8 opportunities a week — were producing dials that met the number without meeting anyone, and data entered in a Thursday batch, so they were stood down. On the AM side there were no defined success criteria at all. The replacement set proposed off the Gong work measures coverage rather than activity: accounts touched in the last 90 days, multi-threading depth, meeting cadence against calendar coverage, and a blended priority score on renewal proximity, health signal, revenue tier and white space — feeding three play types, Protect, Grow and Maintain. Parker and Travis are aligned on the method. The measurement side of this is now the War Room dashboard above; what is still open is the weekly alert structure, which sits with Jose.
Gong Engage — buy vs build
A six-figure annual licence against building a Teams + Gong + Salesforce bridge. Gated on Carolyn's list of which features need additional purchase, plus ROI stories.
Recurring Salesforce team engagementNew
Now a standing monthly sync plus a bi-weekly release CAB. The real problem to solve: the Salesforce team has no visibility into how tools that reach Salesforce are built or used, so we're mapping where Slack and Box should integrate versus where an MCP server is the right seam.
Data-model work
With Robert Craven and Neil Blackman. Accounts → industry classification in draft.
/am account-health pulse
Live Salesforce data across two AMs, roughly 190 and 175 accounts. Still an explicit dry run.
/bd prospecting pipeline
Five reps, ranked daily list each. Blocked on ICP definition and lead-scoring criteria from Jamie and Edwin.
/qbr QBR generator
Salesforce, Gong, Chargebee and Partner Center into a branded deck with speaking notes and a white-space lens. Now without its co-builder following Kevin's departure.
Retire account health, move to Gong
A retirement rather than a rebuild. Accounts that churned were still showing a 100% relationship metric, so the measure isn't telling us what we need and stakeholders have understandably stopped leaning on it. Gong derives relationship health from observed behaviour instead — conversation frequency, sentiment, engagement, ticket volume, whitespace — so the cleaner move is to stand the account-health work down rather than keep tuning it.
Done3
Sales × Claude session
Held 6/18 with a three-tier prompt pack and a reusable Salesforce prompt encoding verified org facts, so people stop querying the wrong revenue field.
Gong data verified
49,848 activities over 30 days at 95.6% CRM association — the number the revenue boards now rest on.
Gong renewal-risk board liveNew
An eight-figure renewal book across 1,800 deals, with automated Monday digests to subscribers. Built through browser automation with no prior Gong knowledge.
Engineering & Platform30 items · 16 priority
The opportunities here are a shared SDLC, consistent CI/CD, a standard prod / non-prod split, and bringing infosec in at design time rather than review time. Morpheus shows the pattern works — extending it across teams is the open work. DORA also isn’t derivable yet, which makes improvement hard to evidence either way. Three standing bets are worth managing deliberately: we are almost entirely on one model, our Trusted Advisor story leans on a single vendor, and our APIs are still shaped for human developers rather than agents.
Ideas20
File the ask from the board, then track the ticket on the cardNew
Right now a blocker on this board is a sentence; the actual request lives somewhere else, or nowhere. The shape that fixes it: a card knows which team owns it, drafts the request with the context already on the card, files it into that team’s queue on confirmation rather than automatically, stores the issue key so it can never file twice, and then shows live status on the card instead of a claim about it. Filing works from here today — the Atlassian connector is already how the board reads and writes. Two things found while checking: vendor reviews have a home nobody was using — there is a Vendor Management project, so the two assessments can be tracked properly rather than as an email; and the Operations Service desk takes a General request, which is how the Claude admin ticket was raised, so it is the working front door. Deliberately not automatic: filing into another team’s queue without a human pressing the button is how a transparency board turns into a spam source, and these are the teams whose help we need.
Gate the exec board on group membership, not on a linkNew
Today the leadership board is protected by the fact that few people have the link, which is a convention rather than a control. Once sign-on is real, an Entra group claim in the token can enforce it properly — leadership edits direction, everyone else reads it. That is worth doing at the same time as sign-on rather than after, because retrofitting authorisation onto something people already use is the harder version of the job.
Put the database under company ownershipNew
The project currently sits under an individual account with one administrator. For something the organisation is meant to depend on, that is a single point of failure and the first thing a security review will reasonably ask about. Moving it to a company-owned organisation with more than one admin is small work now and awkward work later.
Look properly at the Atlas front endNew
Flagged on 5 Aug: much of Atlas is being built on a React front end, and how that gets secured has not had a serious look yet. Worth doing before it is load-bearing rather than after, and it pairs with the open question about what Atlas is for.
Approve once, then self-serveNew
Suggested on the 5 Aug sync as the way out of a recurring pattern: app registrations, permissions and provisioning all queue behind one team, and when that team is underwater on something else — a CrowdStrike rollout, for instance — every dependent key result slips with it. Rather than treating that as a people problem, build the thing once so security approves the pattern a single time and the request is then a button press that stays inside what was blessed. Six of the items on the blocked list are shaped exactly like this.
Full n8n auditNew
The first pass inventoried 37 workflows and read five closely. A complete audit would cover the parts that matter for durability: what only lives in someone's head, what's documented, what's reproducible, and what would happen if the person who built it were unavailable. The estate is doing real work and deserves the same standard as the rest of the platform.
vbox pins Trusted Advisor to one vendorNew
If vbox powers Trusted Advisor, a good part of what we present as ours is shaped by their roadmap. It's the same shape of consideration as being single-model, and it spans two lanes — engineering owns the integration surface, sales owns the promise made to the customer. The opportunity is to decide deliberately what we own versus what we resell while it's still early.
DORA metrics can't be measuredNew
Neither the classic four nor the updated set. There's no work-management integration between Jira and Confluence to derive them from, so lead time, change failure rate and recovery time aren't computable today. Standing this up also gives us a natural reason to agree what Jira is for — release management, sprints, story points, documentation, release notes — since it currently carries all of those without one being the agreed source of truth.
Multi-model harnesses + routingNew
We are primarily on Claude, which concentrates our exposure whether it shows up as a price move, an outage or a capability gap. The mitigation belongs at the harness: frameworks our teams use should support multiple models behind a router that picks the right model for the job. Forge already works this way — the opportunity is to make that the norm.
Agentic-first by defaultNew
API design has historically optimised for a human developer reading docs, which was the right call at the time. The default worth adopting now is different: everything we build or touch is designed so an agent can respond, infer and compose against it — discoverable, self-describing, safe to call without a person in the loop.
Atlas isn't agentic-firstNew
From what we can see of the API design, it isn't oriented that way yet. Atlas is being built now as the central data layer, so raising it today is far cheaper than retrofitting later — and it makes a good first test case for the default above.
TTT Azure Marketplace appNew
One TTT app as the single point of contact a customer has with us, with every third party routed through it. We keep the branding, we control the partnership relationships, and the customer's tenant stays clean instead of collecting one vendor app at a time.
Telemetry routing decisionNew
CrowdStrike vs Langfuse vs both, with Cisco Umbrella also in the frame. We own several tools that each partly solve observability; this blocks the pipeline design.
No defined SDLC across engineeringNew
There isn't a documented or enforced standard yet, CI/CD exists in patches, and non-prod versus prod isn't consistent across teams. Most of the capability is already in the building — it hasn't had a dedicated owner. Morpheus is a worked example of what it looks like when it does.
Claude as a PR toolNew
Claude Tags already puts the conversation in the right channels; this is the next step. Work out how Claude raising pull requests gets used and governed — who reviews, what it's allowed to touch, how it's paced.
Codex at the GitHub org levelNew
Applying Codex at the org level isn't working yet. Worth diagnosing before anyone builds a workflow that depends on it.
Canary routing + auto-rollbackNew
Longer-term release roadmap once gating lands.
Self-healing pipelinesNew
Observability detects the error, opens the PR, merges it. The engineer never sees the incident.
Warehouse + agentic memory layerNew
Loose conversations with Eric Ramos about the framework he wants to build as a data warehouse. If it lands, an agentic memory layer sits on top of it — which is a far better foundation than each skill carrying its own context.
Local vs frontier model R&DNew
Baseline what actually has to run against a frontier model in the cloud versus what runs locally, and price the offset. This is the lever that makes the ROI model move.
Doing7
Move the board onto Vercel and SupabaseNew
The artifact was the right way to find out what this should be; it is not the right way to run it for the organisation. Three hard limits, none of which are fixable in place: the artifact sandbox forbids all outbound network calls, so no real backend can be reached from it; identity is asserted by the client rather than proven, so a vote is attributed on trust; and it needs Cowork installed, which is why two leaders could not open it at all. A hosted front end on a real database fixes all three at once and turns the link into an ordinary web address that works on a phone. Already built and verified: the database is an append-only event log where update and delete are granted to nobody, tested by attempting both as the browser’s own role and having them refused, so a concurrent write cannot destroy anything and full revision history comes for free. What is left is the front end, single sign-on, a domain, and two vendor reviews — and most of that needs teams other than this one.
Vendor assessments for the board’s own stackNew
Moving this off a Confluence page and onto a proper front end and database means two more vendors through security review, on top of three already sent over. The assessment request for the database is drafted and names its own weak point rather than waiting to be asked. Worth being conscious of the queue we are adding to: the same team owns the app registration, the egress allowlist and the CrowdStrike work, so each new review competes with unblocking work already in flight.
CrowdStrike AIDR + Data ProtectionNew
Collector types cover browser, app, MCP and Claude Code, and fail-open is confirmed. Pricing and the Shield demo, then either an AIDR POV or a two-week Data Protection trial. Pre-work: validate the collector appends to rather than overwrites existing lifecycle hooks.
Risk register + trust centreNew
Working with security on how a live risk register feeding a trust centre gives leadership real visibility into business-impacting risk, instead of a spreadsheet nobody opens.
Policy-as-code so infosec is earlyNew
Open Policy Agent as the decision point, so infosec has a voice at design time rather than being handed a finished system to bless.
Observability vendor review with infosecNew
SigNoz and Langfuse assessed against ISO/IEC 27001:2022 and ISO/IEC 42001:2023 and sent to Jared and the infosec team — the point is to surface any objection to the platforms we've chosen before we build on them, not after.
Connector permission architectureNew
Read-only by default, OAuth so Claude inherits the user's permissions, per-team scoped connectors, Entra group gating. Driven by the incident where a connector with an expired key found a valid one and created bogus accounts.
Done3
Six skills built
/qbr, /am, /bd, /so-audit, /pe and /ar — all in pilot or in use.
Claude Tags rolled outNew
Live across multiple channels, so anyone can ask Claude directly about how a skill works or how Morpheus behaves and get an answer in the channel rather than filing a ticket or finding the right person. It also puts the feedback loop in the right place: the same conversation can become a pull request, which is the groundwork for Claude responding to that feedback with a change rather than an explanation.
Claude Enterprise governance
SSO, skills repo in GitHub, Entra-scoped distribution, read-only Salesforce / Gong / Chargebee connectors, and a least-privilege Salesforce AI user.
Private Equity14 items · 4 priority
PE is 60–70% of net-new revenue. One flagship sponsor relationship is the reference account that decides whether the FinOps story is real or a deck.
Ideas7
Cost-avoidance dataset + GP Stakes deck
GP Stakes deck is ready at a seven-figure cost-avoidance number and Monday's meeting happened. The full eight-figure portfolio-wide number slips to later in August after travel.
Primary FinOps vendor: commercial agreements
Referral and enterprise/CSP resale. TTT legal reviewing; meeting mid-to-late August.
RI/SP reset risk in onboardingNew
Three-year reservations can lose momentum during CSP migration. Making this a defined onboarding step means it's handled by design rather than discovered in flight.
FinOps maturity score per portcoNew
Timo's 13-control self-assessment — roughly 15 of ~300 done. Aggregating it across the whole portfolio is what our spend visibility uniquely enables. 45-minute deep dive next monthly call.
Due-diligence engine on F³New
Pre-close AI-maturity and cost diligence built on the F³ connector framework. A second PE firm has already asked for maturity assessment in pre-close. Same framework extends to standing portfolio operations at our flagship sponsor.
Second-pillar MCP cost-analysis POC
5–10 accounts via anonymized billing exports, no app install.
Growth-equity sponsor / Milo
~60 SaaS portcos surfacing into Microsoft Agent 365 — the natural continuation of the concept work already delivered for Chad.
Doing5
/so-audit pricing audit
19,863 line items extracted, 16,922 priced. A confirmed monthly overbilling figure, quantified and agreed with finance, across 1,921 lines — recurring and still uncorrected. Signature traceability is 22.2% — the DocuSign-to-account link is empty org-wide.
Primary FinOps vendor: marketplace rollout
Bridge built and approved by Andy's team; our part is the portfolio and FinOps work around it. Awaiting Microsoft certification, with broad rollout targeted ~9/1.
First portco pilot
The first portfolio company through the process, at a mid-six-figure monthly cloud spend. Reservations reset and reapplied; ~1 month of billing validation to confirm no customer impact.
A second FinOps pillar
Covers the ~10% the primary vendor can't. Open question: can commitments be bought through our enterprise app rather than per tenant?
Investor partnership — acquire or adoptNew
An investment firm with two paths on the table: acquire a portfolio company, or run TTT's own teams through the firm's Forward Deploy OS, with MCP-server sharing as the partnership model. Two or three deep dives, then face to face.
Done2
Concept work for ChadNew
IaC and research delivered for Chad covering the concepts the sponsor asked about — how AWS-native agents can be resold inside the Azure ecosystem. Gave the PE motion a concrete answer rather than a directional one.
QBR tooling for PENew
Delivered for the PE group and powered by the Claude Design system, so the decks come out on-brand without anyone rebuilding a template. PE consumes these outputs exclusively.
Finance & AR9 items · 4 priority
AppDirect is roughly sixteen months out. Everything in this lane is load-bearing for far longer than anyone planned for, and the ROI model is what makes AI spend defensible.
Ideas6
OTEL cost attribution for ClaudeNew
Claude spend isn't attributed to anything today. Tagging by repo, product, project, cost centre, team and environment lets us say which projects the money is buying.
Payer-mapping validation
62 June mappings corroborated against the Chargebee legend. A Validated column on one master table lets the skill read only confirmed rows.
MCP connectors for the AR skill
Atlassian, Drive, Chargebee — requested, pending an org owner.
Citibank → NetSuite feedNew
Call held 7/30. Cleaner source than remittance data, which truncates at ~500 characters and chops company names mid-string.
ROI validation + finance sign-offNew
Cost-offset data from Allison is still to come, and the route to CFO sign-off on the return statement isn't settled — it may go via Head of Finance.
Sell the ROI / FinOps model outwardNew
If the nine-layer token-economics model works on our own P&L, it becomes a service we sell to portfolio companies rather than an internal spreadsheet.
Doing2
Nine-layer AI ROI modelNew
Extending the existing FinOps model to TrustedTech itself so cost per AI action and AI-attributed revenue are measured, not asserted, against the 3:1 bar.
/ar cash application
Live skill reading an editable Confluence rules page; dry-run only today. Worth naming plainly: AppDirect is a ~16-month runway, so this is a long stopgap, not a quarter.
Done1
Finance onboarded to the AR skillNew
Confluence and channel access granted; Claude is live answering payer-ID and bank-ID questions. Team feedback edits the live skill with Travis approving — no ticket path needed.
Microsoft & Partner6 items · 2 priority
The constraint here is data access rather than ideas. A read-only Partner Center request has been open since mid-June, and most of this lane depends on it landing.
Ideas4
Margin-intelligence crawler
Designed, not yet built. Audience is ops and finance rather than sellers. FY26 incentive changes were the largest shift in five years and were spotted manually — a good argument for automating the watch.
Infosec pre-approval for vboxNew
Brief infosec now on the three Partner Center data points so it isn't the thing blocking ship.
Partner Center compliance skill
Quote → signed SO → Partner Center order → invoice matching. Driver: orders can currently be placed ahead of a signed sales order, which this would catch.
vbox integrationsNew
vbox eligibility signals into Gong so AMs get Monday marching orders with context; plus auto-onboarding every subscription instead of clicking each one.
Doing2
Partner Center API access
Read-only ticket open since mid-June, still blocked. Confirm whether the data already flows into Fabric before building anything parallel.
VIAcode / vboxNew
Bi-weekly sessions crawling vbox APIs and MCP endpoints. Their Partner Center integration recalculates eligibility nightly across funded engagements, promotions and propensity — e.g. 1,000 E5 seats surfacing a five-figure deployment accelerator. Not live yet. See the concentration risk in Engineering & Platform — if this powers Trusted Advisor, the dependency is strategic, not just technical.
Operations, PMO & Enablement17 items · 6 priority
Two org-wide opportunities sit here: the PMO is effectively one FTE, and there isn’t a shared answer yet on which platform owns what. Both quietly add cost to every other lane.
Ideas11
Extend the board past the AI teamNew
Discussed 5 Aug: pilot the format with one team, learn what changes, then the exec view everyone sees carries every function rather than just this one. That makes it a work-management surface rather than a status page, and the deconfliction it implies — this deliverable needs four teams and three have no bandwidth, so it cannot land this quarter — is properly a PMO function. See the PMO card: Megan is the obvious person to grow into it, and ProServe already has PMs. The honest constraint is that doing this well normally needs Jira Advanced Roadmaps plus everyone actually using Jira properly, which is why we are approximating it here.
Understand what Atlas is forNew
Where it overlaps with what we already run and with what's coming — AppDirect, and the retirement of Chargebee and Sales Hub. Getting this clear early avoids two data layers growing in parallel.
Sales Hub trust problemNew
Feedback from PE and sales — the non-technical teams — is that results are inconsistent enough that confidence in the output has dropped. That's already limiting what the quote agent can do, so it's worth treating as a business signal rather than a tooling gripe.
Scale the PMONew
Effectively one FTE covering the whole organisation, while ProServe holds its own PMO assets. The opening is to standardise on those and grow a single PMO serving every functional unit rather than duplicating the function. Discussed further on 5 Aug: the role that matters most is deconfliction — reading across every team’s commitments and saying when a date is not achievable because three of four dependent teams have no capacity.
Expand the strategy dashboardNew
The format landed well; it currently reads as Morpheus-only. Adding Partner Center, PE and the rest of the portfolio would make it the whole picture.
Granola → Slack approval flowNew
Draft summary pushed to Slack for yes/no/edit between meetings, replacing manual cut-and-paste. Summaries only, never transcripts.
Day 60 review
That's today — the page is still to be written.
SOW scope-creep detection agent
Happy-path process maps as AI contextNew
Madeleine maps onboarding, annotates the breakpoints, then we either hand it to Claude or score it against Fin and Gong.
Atlas as the partner-center data layerNew
Andy's team is building an event-driven central data layer. This may be the right answer to the internal data-marketplace ask — see the To Do card on understanding Atlas first.
Customer + ProServe hackathonNew
Manuela's idea. Run it with customers alongside the professional services team — doubles as pipeline and as ProServe enablement.
Doing4
Pick a note taker, then give the policy teethNew
Raised by Todd on 5 Aug. Six tools are in use across the company — Granola, Fathom, Fireflies, Chili Piper, Copilot and Gong — and the “we should pick one” conversation has happened before without landing. The concern is people reaching for their own tooling on customer calls, which is a consent and data-handling question rather than a preference one. Shape agreed: a short approved list of about three rather than an open field, segmented by role, because the answer differs by audience — customer-facing and compliance work points at Copilot since that is what we sell, while the tool of record for sales is already Gong. Things to decide with it: whether a bot may appear in the meeting at all, whether a tool works across Teams, Zoom and Meet, and whether it clears legal and security — some will simply fail that and drop out. California is a two-party consent state and the UK adds another layer, so recording a customer without disclosure is a real exposure. Sequence: agree the list, fold it into the AI policy legal is already drafting, amend the employee acceptable-use terms so it has teeth, then IT can enforce it through CrowdStrike. Worth saying plainly: this may well rule out the tool we are using today.
Get the 2026–2027 goals formally setNew
The exec board works only if the organisation goals above the deliverables are real. Todd agreed on 5 Aug that they need setting; the conversation with Julian is early the following Monday, and the 2027 horizon is due to come up in the strategy sessions, so part of this may sensibly wait for those. The three currently on the board are a starting proposal, not a decision. Also agreed as the operating rule: once a quarter’s deliverables are set, changing them should take an act of Congress — stable priorities, clear success criteria, cross-functional alignment and leadership sponsorship, in Todd’s words.
Hyper-V enabled across the fleetNew
Cowork needs the full Windows Hyper-V stack installed and on, which is not the default on our builds. Two leaders could not open a shared board on 8/4 until IT turned it on by hand, machine by machine. The ask into IT is whether it can go out through Intune so nobody else discovers it the same way. Owner: Shaddy Haddad with Jared’s team.
Shared artifact links read as phishingNew
Both recipients of the first shared board assumed the claude:// link was a phishing test — which is the security training working as intended. Worth a line in the rollout note so the link is expected rather than reported.
Done2
Phase 1 closeout + Phase 2 charter
Scored honestly: two delivered, one in progress, one behind, one rolled back, two stranded. Six Phase 2 capabilities defined.
F³ enablement model
Plus seven per-function AI enablement guides — leadership, finance, marketing, operations, support/CSP and professional services.
Marketing & Brand8 items · 3 priority
Marketing has become a genuine build partner rather than a reviewer at the end. The design system came out of their assets and is theirs to run, and the enablement content now ships on their monthly cadence. The open question in this lane is identity: customers already meet several differently named AI personas, and deciding which one is ours — and who owns its voice — is a brand decision, not an engineering one.
Ideas4
One outward AI identityNew
Six voice assistants are live across five names. One is still reading a stock template greeting that thanks the caller for contacting a company that isn’t us, and another is half-reskinned between two spellings of our own name. None of that was a decision — it is what accumulates when personas are created per project. The opportunity is a single identity a customer meets on the phone, in email and in chat, with marketing owning the voice.
Marketing’s email infrastructure in viewNew
Account Engagement is the one marketing system Claude cannot see: there is no connector in the registry, and both the Salesforce login host and the Pardot API are refused at our proxy. The near-term pattern is an export dropped into a connected folder, which is how the existing marketing skills already work. A small MCP server on the marketing side is the durable answer, and a separate piece of work.
Ride the monthly toolkit cadenceNew
The Sales Craft Toolkit already launches in the first week of every month, with a defined build-and-tag process behind it. Publishing AI enablement through that cadence gets reach and a review step we would otherwise have to invent.
Consistent AI disclosure across channelsNew
The Article 50 footer ships fail-closed on email, and that part is solid. What a customer hears on a call, or reads in chat, is not yet held to the same standard — so the disclosure is compliant in one channel and informal in the others.
Doing2
Name and own the outward AI identityNew
Several names were worked through internally and Tara is the one that ended up in production, on the support line since October. What is still in flight is the decision to make that the organisation’s identity rather than one assistant’s name, and to hand its voice and brand to marketing the way the design system was handed over.
How to build your own custom AI assistantNew
Matt Bauman wrote it and it is good. Held deliberately for the next monthly toolkit launch so it can be polished and rolled out properly rather than dropped in. The open question is control: how people are expected to use it, and who keeps it current as the product moves.
Done2
Design system built, marketing owns itNew
Answered Julian’s June point about deck quality. Built in Claude Design from marketing’s own assets, with their art direction on fonts, logo placement and voice, and it is now the org default whenever anyone builds a deck or an asset — PE consumes its outputs exclusively. Marketing holds the master going forward, so brand changes don’t queue behind engineering.
Extending the design systemNew
Folded in the templates Justin’s team had already built, on top of the system that is now the default.
Incident Response & Product Maturity17 items · 5 priority
We have run good post-incident reviews; we have not defined incident response. The voice estate reported fabricated data for five months before anyone noticed, which is a detection gap rather than a bad decision. The opportunity is a maturity model where nothing reaches customers without a defined response path, built agentic-first: the agent detects, triages and drafts the analysis, and a human decides.
Ideas13
Maturity model with response as a gateNew
No product or skill reaches customers without a named owner, a severity scale, a detection signal and a rehearsed rollback. Today that bar exists in one place and by habit rather than definition, so each new thing we ship inherits nothing.
Severity taxonomy and response targetsNew
Agree what Sev-0 to Sev-3 mean for AI systems, and the time-to-detect and time-to-respond we hold ourselves to. Without a shared scale, “critical” means whatever the person writing the message felt at the time.
Agentic-first incident responseNew
The agent notices the anomaly, opens the incident, assembles the timeline from traces and logs, drafts the analysis and proposes the fix as a pull request. A human decides and approves. Same principle as agentic-first APIs, applied to operations.
Silent-failure detection as the defaultNew
The voice estate filled fields with defaults for five months and the feed looked healthy throughout. Every AI system needs a heartbeat and an “expected work not happening” alarm, because the dangerous failure is the one that still returns a plausible answer.
On-call and escalation per productNew
Who is called, on what path, out of hours. Morpheus has an engineer who answers; the skills fleet, voice and n8n have no defined route.
Blameless review as standing practiceNew
A template and a cadence, so the analysis lands somewhere durable rather than in a Slack thread. Two good reviews already exist to build the pattern from.
Customer disclosure pathNew
When an AI system gets something wrong in front of a customer, who says what and how fast. Sits alongside the Article 50 work and the UK auto-decision rules rather than separate from them.
Incident register feeding risk and trustNew
Incidents roll up into the risk register and the trust centre, so leadership sees business-impacting risk from evidence rather than anecdote.
Cover the n8n estateNew
37 workflows doing real work with no defined owner or response path, and 11 unauthenticated public paths found in the audit.
Cover the voice estateNew
Vapi answers customers directly. It currently has the thinnest coverage and the worst detection record of anything we run.
Cover the skills fleetNew
/qbr, /am, /bd, /ar, /so-audit and /pe all read live customer data. A wrong answer there reaches a seller or a customer with no gate behind it.
Rehearsed rollback per productNew
A rollback that has never been run is a hypothesis. Morpheus proved the value of immutable digests the hard way; the rest of the estate hasn’t been tested.
Degradation signalling to CSP and AMsNew
When a system is degraded, the people fielding customers should know before the customer tells them.
Doing2
Define incident response for MorpheusNew
The practice largely exists — fail-closed guards, frozen-clock tests, a real RCA — but it isn’t written down as a response process with severities, detection signals and owners. This is where the pattern gets proven before it’s asked of anything else.
Observability as the detection layerNew
Langfuse and OTEL give us traces; turning those into alarms is what makes a response possible. Blocked behind the same telemetry routing decision as CrowdStrike versus Langfuse.
Done2
Two post-incident reviews deliveredNew
The voice RCA (67 findings, 10 critical) and the n8n platform audit (37 workflows, 11 unauthenticated paths). Both found real problems and both were written blamelessly — the raw material for a defined process.
Fail-closed guards on Morpheus
Outbound email, stage preflight and the disclosure footer all fail closed rather than open. The clearest existing example of designing for the failure case.
Two open items worth attention. The GCP key rotation and RAG account scoping both came out of the June audit and are still unstarted. Both are ready for a decision rather than more analysis; the RAG one still needs a ticket raised.
Ownership worth confirming. Angel has moved onto health scores and is stepping back from the CSP feedback channels — and since account health is now being retired, that assignment is worth revisiting together. If Morpheus is replaced, ownership moves to Will's team working directly with Fin.
The foundational opportunity. A shared SDLC, consistent CI/CD and a standard non-prod/prod split would lift every team. Morpheus is where we've shown what that looks like in practice, so extending it is an invitation to build on something that already works.
Success metric changed. Morpheus is now measured on tickets closed before reaching a human, not routing accuracy — with the caveat that sentiment and case type belong in any such metric, because some customers want a person.
Sourcing. Jira (MD, MOR, SFD, ATLAS), Confluence spaces AS / AR / PES / TTT, GitHub Trusted-Tech-Team/Morpheus and TrustedTech-AI/tt-claude-plugins, Slack, and meeting notes through 3 August 2026. Items marked New came from the 7/27–8/3 meetings. The Morpheus engineering package on Confluence was last updated 7/13 and understates current progress on gating and sandbox CI.