<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Pier-Luc Charbonneau</title><description>Where technology meets judgment</description><link>https://charbonneau.io/</link><language>en-ca</language><item><title>Your Auditor Called. Purple AI Already Has the Answers.</title><link>https://charbonneau.io/articles/your-auditor-called-purple-ai-already-has-the-answers/</link><guid isPermaLink="true">https://charbonneau.io/articles/your-auditor-called-purple-ai-already-has-the-answers/</guid><description>Last Tuesday, Anthropic announced Claude Mythos Preview... and the cybersecurity world lost its mind.</description><pubDate>Sat, 11 Apr 2026 20:18:47 GMT</pubDate><content:encoded>&lt;h6&gt;&lt;em&gt;How SentinelOne customers are using Claude Code and the Purple AI MCP to respond to security audits in minutes instead of weeks.&lt;/em&gt;&lt;/h6&gt;
&lt;p&gt;Last Tuesday, Anthropic announced Claude Mythos Preview... and the cybersecurity world lost its mind.&lt;/p&gt;
&lt;p&gt;The model, which Anthropic is deliberately withholding from public release, can find and exploit zero-day vulnerabilities in every major operating system and every major web browser. Decades-old bugs. Autonomous exploit chains. A 27-year-old vulnerability in OpenBSD. The announcement triggered emergency meetings between Fed Chair Powell, Treasury Secretary Bessent, and the CEOs of America&apos;s largest banks.&lt;/p&gt;
&lt;p&gt;My phone started ringing.&lt;/p&gt;
&lt;p&gt;Customers wanted to know: &lt;em&gt;What can SentinelOne do about this? How do we prove our security posture to auditors who are going to be asking harder questions? How do we respond faster?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The answer surprised some of them because it was already in their hands.&lt;/p&gt;
&lt;h2&gt;SentinelOne already has an AI security assistant&lt;/h2&gt;
&lt;p&gt;While the world was reacting to Mythos, SentinelOne customers have been quietly using &lt;strong&gt;Purple AI&lt;/strong&gt; for years: our AI-powered security analyst built directly into the Singularity Platform. Purple AI understands natural language, queries your live security environment, and provides sourced, documentation-backed answers about your security posture.&lt;/p&gt;
&lt;p&gt;And now, with the release of the &lt;strong&gt;&lt;a href=&quot;https://github.com/Sentinel-One/purple-mcp&quot;&gt;Purple AI MCP Server&lt;/a&gt;&lt;/strong&gt; (open source on GitHub), that same intelligence is available anywhere you can run an MCP client — including &lt;strong&gt;Claude Code&lt;/strong&gt; and &lt;strong&gt;Claude Cowork&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;This means you can now sit in your terminal, ask questions about your SentinelOne environment in plain English, and get auditor-ready answers backed by live evidence from your own console. No browser tab-switching. No manual data exports. No spreadsheet hell.&lt;/p&gt;
&lt;h2&gt;What Is the Purple AI MCP?&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://github.com/Sentinel-One/purple-mcp&quot;&gt;Purple AI MCP Server&lt;/a&gt; is an open-source Model Context Protocol (MCP) server that connects any MCP-compatible AI client to your SentinelOne Singularity Platform.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it exposes:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Purple AI&lt;/strong&gt; — ask natural language questions about your security capabilities&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Alerts&lt;/strong&gt; — search, filter, and investigate alerts with full audit trail history&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities&lt;/strong&gt; — query your vulnerability posture with EPSS, KEV, and severity breakdowns&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Misconfigurations&lt;/strong&gt; — review cloud and infrastructure security findings&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Asset Inventory&lt;/strong&gt; — prove endpoint coverage across your managed estate&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PowerQuery&lt;/strong&gt; — run threat hunting queries against the Singularity Data Lake&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;What it can&apos;t do:&lt;/strong&gt; The MCP is &lt;strong&gt;read-only&lt;/strong&gt;. It cannot modify alerts, deploy agents, change policies, or take any response actions. It reads data from your console — nothing more. This is a research and evidence-gathering tool, not an operational one.&lt;/p&gt;
&lt;h2&gt;Getting Started: Installation in 3 Steps&lt;/h2&gt;
&lt;h3&gt;Step 1: Install Claude Code&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;brew install claude
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Step 2: Connect the Purple AI MCP&lt;/h3&gt;
&lt;p&gt;You&apos;ll need a &lt;strong&gt;Service User token&lt;/strong&gt; from your SentinelOne console. Create one in &lt;strong&gt;Policy &amp;amp; Settings → User Management → Service Users&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Then run this command in your terminal (replace with your token and console URL — no trailing slash):&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;claude mcp add purple-mcp \
  --scope user \
  --env PURPLEMCP_CONSOLE_TOKEN=YOURTOKEN \
  --env PURPLEMCP_CONSOLE_BASE_URL=https://usea1-purple.sentinelone.net \
  -- uvx --from git+https://github.com/Sentinel-One/purple-mcp.git purple-mcp --mode stdio
&lt;/code&gt;&lt;/pre&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; You&apos;ll need &lt;code&gt;uv&lt;/code&gt; installed. If you don&apos;t have it: &lt;code&gt;curl -LsSf https://astral.sh/uv/install.sh | sh&lt;/code&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Step 3: Install the Security Audit Skill&lt;/h3&gt;
&lt;p&gt;The skill is a SKILL.md file that teaches Claude Code how to structure your audit responses using a PARA framework — automatically organizing your research, evidence, and documentation references into a reusable knowledge base.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;mkdir -p ~/.claude/skills/s1-audit-assistant
cp SKILL.md ~/.claude/skills/s1-audit-assistant/SKILL.md
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;That&apos;s it. Launch Claude Code with &lt;code&gt;claude&lt;/code&gt; and you&apos;re ready to go.&lt;/p&gt;
&lt;h2&gt;How Customers Are Using It&lt;/h2&gt;
&lt;h3&gt;Scenario: SOC 2 Type II Audit&lt;/h3&gt;
&lt;p&gt;Your auditor asks: &lt;em&gt;&quot;Describe how the organization identifies and manages technical vulnerabilities.&quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Instead of spending hours pulling screenshots from the console and writing responses in Word, you type:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Start audit for acme-soc2. Framework is SOC 2 Type II. 
Answer control CC7.1: vulnerability identification and management.






&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Claude Code does the following — automatically:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Scaffolds a PARA directory structure&lt;/strong&gt; on disk — Projects, Areas, Resources, Archive — so every answer, every piece of evidence, and every documentation link is organized and reusable&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Queries Purple AI&lt;/strong&gt; to explain how SentinelOne satisfies CC7.1, pulling official documentation links&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pulls live evidence&lt;/strong&gt; from your environment — total critical vulnerabilities, actively exploited CVEs, CISA KEV catalog coverage, remediation lifecycle proof&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Writes an auditor-ready response&lt;/strong&gt; to a markdown file with the control requirement quoted, a clear coverage statement, capability description, live evidence with timestamps, and documentation references&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Updates a tracker&lt;/strong&gt; so you can see which controls are done, which have gaps, and which are pending&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The response includes a &lt;strong&gt;Gaps &amp;amp; Compensating Controls&lt;/strong&gt; section — because SentinelOne covers endpoint security, not your entire security program. The skill is honest about scope boundaries: SentinelOne doesn&apos;t cover physical security, network firewalls, identity providers, or backup solutions. Auditors respect that honesty.&lt;/p&gt;
&lt;h3&gt;Scenario: Drop Files, Get Answers&lt;/h3&gt;
&lt;p&gt;Got a 40-page audit questionnaire as a PDF? Drop it in the inbox folder:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;s1-audit/0-inbox/soc2-questionnaire.pdf






&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then tell Claude Code to process it:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Process inbox






&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The skill uses &lt;strong&gt;Microsoft MarkItDown&lt;/strong&gt; to read the PDF, parses every control question, classifies them by domain, and populates the tracker — ready for you to start answering. If you&apos;ve also dropped additional datasheets or previous audit findings in the inbox, those get extracted and routed too.&lt;/p&gt;
&lt;h3&gt;Scenario: Proving Detection Coverage&lt;/h3&gt;
&lt;p&gt;Your auditor wants evidence that your security monitoring is effective. Claude Code can pull this directly from your environment:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Total alert volume over the past 90 days, broken down by severity&lt;/li&gt;
&lt;li&gt;A specific CRITICAL alert showing the full investigation lifecycle — detection, assignment, resolution&lt;/li&gt;
&lt;li&gt;Analyst notes and audit trail for that alert&lt;/li&gt;
&lt;li&gt;Threat hunting queries executed against the Data Lake&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Every piece of evidence includes a &lt;strong&gt;timestamp&lt;/strong&gt; (auditors care when evidence was collected) and &lt;strong&gt;reproduction steps&lt;/strong&gt; (the exact MCP tool calls so the evidence can be refreshed right before fieldwork).&lt;/p&gt;
&lt;h2&gt;The PARA Structure: Knowledge That Compounds&lt;/h2&gt;
&lt;p&gt;The most powerful aspect of this skill isn&apos;t any single audit response — it&apos;s the fact that your knowledge &lt;strong&gt;compounds across audits&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The PARA (Projects, Areas, Resources, Archive) structure separates project-specific work (this year&apos;s SOC 2 audit) from reusable knowledge (how SentinelOne handles vulnerability management). When you answer a question about ransomware detection for your SOC 2 audit, that knowledge also gets written to a canonical Area file. Next year — or next month when your ISO 27001 auditor asks the same thing — Claude Code finds the existing knowledge and uses it as a starting point, only querying Purple AI for updates.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;s1-audit/
├── 0-inbox/                    ← Drop files here
├── 1-projects/acme-soc2/       ← This year&apos;s audit
├── 2-areas/                    ← Reusable knowledge (compounds over time)
├── 3-resources/                ← Documentation links, framework mappings
└── 4-archive/                  ← Last year&apos;s completed audit
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After a few audits, you have a comprehensive, source-linked knowledge base of exactly how your SentinelOne deployment maps to every major compliance framework — built from your own environment data, not generic marketing material.&lt;/p&gt;
&lt;h2&gt;What This Means Post-Mythos&lt;/h2&gt;
&lt;p&gt;The Mythos announcement doesn&apos;t change what SentinelOne does — it validates why it matters.&lt;/p&gt;
&lt;p&gt;Auditors are going to ask harder questions. Regulators are going to demand more evidence. Boards are going to want more frequent proof of security posture. The traditional approach of manually gathering screenshots, copying data into spreadsheets, and writing responses in Word documents doesn&apos;t scale to meet that demand.&lt;/p&gt;
&lt;p&gt;With the Purple AI MCP and Claude Code, you can produce auditor-ready evidence directly from your live security environment, structured and documented in a format that survives audit scrutiny. And because the PARA structure preserves and compounds your knowledge, each audit gets faster than the last.&lt;/p&gt;
&lt;p&gt;The question isn&apos;t whether AI-powered vulnerability discovery is coming. Mythos made it clear that it&apos;s already here. The question is whether your security evidence can keep pace with the questions that follow.&lt;/p&gt;
&lt;p&gt;If you&apos;re a SentinelOne customer, it already can.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong&gt;Resources:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/Sentinel-One/purple-mcp&quot;&gt;Purple AI MCP Server — GitHub&lt;/a&gt; (open source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.sentinelone.com/platform/purple/&quot;&gt;Purple AI — SentinelOne&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.claude.com/en/docs/claude-code/overview&quot;&gt;Claude Code — Anthropic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://modelcontextprotocol.io/&quot;&gt;Model Context Protocol — Anthropic&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;The Security Audit Skill (SKILL.md) referenced in this post is available here: https://github.com/plcharbonneau/SKILLS/blob/main/s1-audit-assistant&lt;/em&gt;&lt;/p&gt;
</content:encoded><dc:creator>Pier-Luc Charbonneau</dc:creator><category>AI</category><category>SentinelOne</category></item><item><title>Sales Engineers: how to use claude code to build presentation that matters</title><link>https://charbonneau.io/articles/sales-engineers-how-to-use-claude-code-to-build-presentation-that-matters/</link><guid isPermaLink="true">https://charbonneau.io/articles/sales-engineers-how-to-use-claude-code-to-build-presentation-that-matters/</guid><description>Cybersecurity sales engineers must adapt to AI tools like ChatGPT to enhance presentation effectiveness. Traditional methods often produce generic content that…</description><pubDate>Tue, 31 Mar 2026 21:53:09 GMT</pubDate><content:encoded>&lt;p&gt;If you have spent any time in cybersecurity sales engineering, you have witnessed this: a smart SE opens ChatGPT and types “create a 12-slide presentation on zero trust architecture,” only to receive a response that sounds polished, yet will bore a technical audience inside three minutes.&lt;/p&gt;
&lt;p&gt;The problem is not that AI struggles with writing, but rather the misconception that generating a deck is equivalent to designing one.&lt;/p&gt;
&lt;p&gt;If you have ever engaged in vibe coding (developing functionality by articulating intentions and allowing an AI agent to execute the implementation across multiple files), then the underlying concept will seem intuitive. You are likely to face resistance from senior SEs with similar arguments. They will say everything needs to be designed and written by hand. They are not wrong. In the same way that software coders resisted using it but are now embracing it, SEs will have to adapt and start embracing new AI tools. In fact, employing AI can help you create more effective presentations in less time.&lt;/p&gt;
&lt;h2&gt;Why the “Generate a Deck” using chatGPT Approach Fails&lt;/h2&gt;
&lt;p&gt;Requesting a language model to create a comprehensive presentation on a specific topic is equivalent to asking it to determine your argument, select your evidence, structure your argument, tailor your message to your audience, establish your product positioning, and polish your writing, all in one go. Even the most skilled human would struggle to juggle all these tasks simultaneously. As a result, the model’s output often lacks substance, uniqueness, and impact.&lt;/p&gt;
&lt;p&gt;Neuroscience provides an explanation for why this approach falls short with the audience and why this matters even more if a deck is built using chatGPT. Paul D. MacLean, a neuroscientist, proposed a hierarchical model of the brain with three distinct levels. In my own words and applied to our topic, the reptilian brain explains why polished-but-generic decks die in the room. Your deck was written by a neocortex (Neomammalian) and it speaks to the neocortex (complex arguments, nuanced positioning, detailed evidence). The audience’s primitive reptilian brain, which I like to think of as the ‘crocrodile brain’, receives the message first and decides whether the neocortex should spend energy processing it. The crocodile brain has three possible reactions: ignoring it, labelling it as dangerous, or sending it up to the higher thinking areas for more in-depth analysis. A deck full of abstractions, category overviews, and smooth transitions triggers the first response. The croc brain says “nothing new here, nothing threatening, nothing I want”. The audience starts thinking about what they will be having for dinner or about their next meeting. That deck that starts telling the CSO why cybersecurity is important and why he should care about securing his data with an EDR? Forgotten… The deck needs to trigger desire and tension within the first few minutes, or the higher brain never gets the message. To trigger desire and tension, a deck needs some novelty. Novelty and surprise is the fastest way to get the neocortex to process and remember your pitch.&lt;/p&gt;
&lt;p&gt;At its core, ChatGPT functions by predicting the most probable next word. This means it is fundamentally wired to generate the safest, most generic presentation possible. It is the exact opposite of what we actually need.&lt;/p&gt;
&lt;h2&gt;The Three-Layer Architecture&lt;/h2&gt;
&lt;p&gt;My system has three layers, and each one does what it is actually good at.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;Obsidian&lt;/strong&gt; is the project memory. It stores the brief, the research, the claims, the slide cards, the reviews, and the rehearsal materials as structured markdown files with YAML frontmatter. Properties give every note a type and status. Backlinks and graph view show you which claims connect to which evidence. Canvas gives you a visual argument map. Nothing lives only in chat.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;Claude Code&lt;/strong&gt; is the automation layer. It reads and writes files in the Obsidian vault, runs multiple agents in parallel, and manages the workflow across stages. This is where the multi-agent architecture earns its keep: you are not having a conversation with one model, you are dispatching specialized workers to handle different jobs simultaneously.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;The&lt;/strong&gt; &lt;strong&gt;human&lt;/strong&gt; is the editor-in-chief. You own the editorial line, thesis, the positioning, the final cuts, and every “should we say this?” judgment. The agents propose. You decide.&lt;/p&gt;
&lt;p&gt;This separation matters. When one tool tries to do everything: research, structure, draft, review, remember, and build. It does all of them at about 60%. When each layer handles what it is built for, the compound result is significantly better. Getting to 80% or 90% is what allows you to win the deal and gain the “trusted advisor” status.&lt;/p&gt;
&lt;h2&gt;The Operating Philosophy&lt;/h2&gt;
&lt;p&gt;Position → Discover → Prove → Control&lt;/p&gt;
&lt;p&gt;This workflow runs on a simple sequence: position the problem correctly, discover what this audience actually needs to believe, prove it with enough specificity to change their mind, and control the frame so the proof actually lands.&lt;/p&gt;
&lt;p&gt;If you speak with a psychologist, they will tell you that the frame is the location, the context, emotional undertones, and presentation of the facts. The same principle applies whether you are trying to convince someone water is not dangerous and they won’t drown or whether you are trying to pitch that deploying an EDR won’t cause all their laptops to suddenly become slow.&lt;/p&gt;
&lt;p&gt;This is where most weak technical presentations fail. They start proving before they have positioned the conversation. They pitch before they understand the audience. They dump information without managing attention. The result is a deck that sounds competent, covers the right territory, and still does not move the room.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;Position&lt;/strong&gt; comes first. Before you build slides, you need to decide what kind of story you are telling, what market frame you are operating in, and why this conversation matters now. That decision shapes everything downstream: which competitors matter, which strengths are relevant, and which proof points will actually register. Get the frame wrong and even strong material feels generic. Get it right and the audience understands the stakes almost immediately.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;Discovery&lt;/strong&gt; comes next. Not generic discovery. Audience discovery. What does this room already believe? Where are they skeptical? What would a CISO need to hear that an architect would not? What would a practitioner reject on sight? Until you know the audience’s current mental model, you are mostly guessing at what counts as proof.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;Prove&lt;/strong&gt; it. This is where most decks need more discipline. Every section should earn its place by changing a belief, resolving a tension, or making a risk feel concrete. A slide that cannot answer “what does this prove?” is usually just taking up space and wasting time. The goal of a presentation is not to cover a topic. The goal is to move the audience from one conclusion (I don’t need this product) to another.&lt;/p&gt;
&lt;p&gt;• &lt;strong&gt;Control&lt;/strong&gt; is what makes the rest of it work. You can have the right thesis and the right evidence and still lose the room if the pacing goes flat, the tension disappears, or the talk slips into vendor-safe abstraction. Attention has to be managed. Energy has to be managed. Frame has to be managed. The audience needs a reason to care before they are willing to process the details.&lt;/p&gt;
&lt;p&gt;The workflow is where those ideas stop being theory and start becoming a build process.&lt;/p&gt;
&lt;h2&gt;How Claude Code’s Multi-Agent System Works (and Why It Matters Here)&lt;/h2&gt;
&lt;p&gt;If you have used Claude Code for software engineering, you know it can spawn subagents: specialized workers that handle focused tasks and report back to the main session. The same capability transforms presentation work.&lt;/p&gt;
&lt;p&gt;Claude Code gives you three agent types that map cleanly onto presentation workflow:&lt;/p&gt;
&lt;p&gt;• Explore agents are fast, read-only workers optimized for scanning files and finding information. Use them to survey your research folder, locate specific evidence, or audit the state of your project.&lt;/p&gt;
&lt;p&gt;• Plan agents gather context and draft implementation strategies. Use them to analyze your brief and propose argument structures, or to map the gap between your audience’s current beliefs and where you need them to land.&lt;/p&gt;
&lt;p&gt;• General-purpose agents handle complex multi-step tasks with full tool access. Use them for drafting slide batches, running hostile reviews, or normalizing messy source material into structured notes.&lt;/p&gt;
&lt;p&gt;The key architectural move is parallel execution. You can spawn multiple agents simultaneously to work on independent tasks. While one agent is drafting slides 4–6, another can be running a skeptic review on slides 1–3, and a third can be auditing your claims folder for unsupported assertions. The main session aggregates the results, and you decide what to keep.&lt;/p&gt;
&lt;p&gt;This is the vibe coding analogy made concrete. In software, you describe the intent (“add authentication to this endpoint”) and the agent handles the implementation across files. In presentation work, you describe the intent (“draft the core argument batch with evidence from the research folder, no product positioning yet”) and the agent handles the structured labor. You stay the editor. The agents are your team.&lt;/p&gt;
&lt;p&gt;Good vibe coders will tell you what those of us who have worked building cloud architecture &amp;amp; CI/CD pipelines have discovered. Build your frame first (unit test) and iterate. Without it, the AI has no way to know if what it is building is AI slop or good content.&lt;/p&gt;
&lt;h2&gt;The Project Folder: Your Presentation as a Repository&lt;/h2&gt;
&lt;p&gt;Every presentation gets its own folder in your Obsidian vault. Treat it like a codebase.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;talks/
  cloud-runtime-security/
    00-brief.md
    01-thesis.md
    02-audience-delta.md
    03-not-this-talk.md
    04-product-bridge.md
    story.canvas
    sources/
      gartner-cloud-security-2025.md
      field-observations-runtime-gap.md
      ...
    claims/
      claim-01-visibility-gap.md
      claim-02-agentic-identity.md
      ...
    slides/
      slide-01.md
      slide-02.md
      ...
    reviews/
      skeptic-practitioner.md
      anti-pitch-detector.md
      clarity-editor.md
      synthesis.md
    rehearsal/
      opening-options.md
      qa-bank.md
      rehearsal-script.md
      cut-to-20.md
    export/
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Every file has YAML frontmatter with a type and status property. This is not useless: it is what makes the agents effective and able to fit what they need in their context window. When you tell Claude Code to “find all claims with status: proposed that lack linked evidence,” it can actually do that without reading every single file because the metadata is structured and machine-readable.&lt;/p&gt;
&lt;p&gt;The obsidian vault is the single source of truth. Not the chat. Not your memory. The files.&lt;/p&gt;
&lt;h2&gt;The Nine Gates: A Staged Workflow with Agent Orchestration&lt;/h2&gt;
&lt;p&gt;The workflow forces your presentation through nine gates. Each gate has a clear deliverable, and the model cannot skip ahead. This is the discipline that prevents the “polished but generic” failure mode.&lt;/p&gt;
&lt;p&gt;Here is how the gates work, and where multi-agent orchestration makes each one faster without sacrificing quality.&lt;/p&gt;
&lt;h2&gt;What Happens When You Skip the Gates&lt;/h2&gt;
&lt;p&gt;Here is a pattern that repeats across SE teams. Someone has a conference talk due in ten days. They open a chat, paste their topic, and ask for a deck. The model produces twelve slides that cover the right territory: attack surface evolution, identity gaps in agent workflows, detection challenges. The slides read well. The SE rehearses twice and walks on stage.&lt;/p&gt;
&lt;p&gt;The talk lands at about a six out of ten. The audience nods but does not engage. The Q&amp;amp;A is thin. The post-talk conversations are polite rather than substantive. When the SE reviews the recording later, they notice the problem: the deck explains a category instead of advancing an argument. It sounds like three different analyst reports merged into one narrative. There is no moment where the audience’s assumptions get challenged. There is no “I never thought about it that way.”&lt;/p&gt;
&lt;p&gt;That is the cost of skipping the gates. The deck was fluent and… forgettable&lt;/p&gt;
&lt;h2&gt;Gate 1: The Brief (Positioning Baseline)&lt;/h2&gt;
&lt;p&gt;Nothing happens until 00-brief.md exists and you have approved it. The brief locks your audience, setting, desired outcome, thesis, current audience beliefs, target beliefs, product-positioning rules, banned tropes, and failure modes.&lt;/p&gt;
&lt;p&gt;The brief must include a deliberate market frame selection — which category does this talk position your product within? The frame determines your competitive set, which features matter, and which proof points are relevant. A runtime security product framed as “next-gen endpoint protection” competes against CrowdStrike. The same product framed as “cloud workload defense” competes against Wiz. Different frame, different competitors, different arguments. The brief is where you make that choice consciously instead of letting the model default to whatever frame sounds most natural.&lt;/p&gt;
&lt;p&gt;The brief should also answer the “why now?” question using three market forces: what economic shift, social behavior change, or technology inflection makes this talk urgent right now rather than interesting-in-general? “Cloud runtime security” is a topic. “Agentic AI workloads are creating runtime identity problems that did not exist eighteen months ago, and the attacker tooling has already adapted” is a why-now frame built on technology and threat-landscape forces. If your brief cannot answer “why now?” with specific forces, the talk will feel informational rather than urgent… and urgency is what gets past the crocrodile brain.&lt;/p&gt;
&lt;h2&gt;Gate 2: Source Normalization&lt;/h2&gt;
&lt;p&gt;Every piece of external input — analyst reports, competitor docs, customer notes, field observations, conference themes — becomes a structured source note in sources/. Each note gets frontmatter properties: type: source, source_kind, confidence, relevance, and supports (linking to claims).&lt;/p&gt;
&lt;h2&gt;Gate 3: Thesis Memo&lt;/h2&gt;
&lt;p&gt;Before any outline, produce two notes: 01-thesis.md (the sharpest version of your argument) and 03-not-this-talk.md (what the talk explicitly is not).&lt;/p&gt;
&lt;p&gt;That second note is the anti-drift mechanism. For a cybersecurity talk, 03-not-this-talk.md might reject: “AI is changing everything” framing, model benchmarks as the core story, threat hype without governance, and product demo disguised as thought leadership.&lt;/p&gt;
&lt;h2&gt;Gate 4: Audience Delta (Discovery Integration)&lt;/h2&gt;
&lt;p&gt;Create 02-audience-delta.md with the audience’s default mental model, your target mental model, expected objections, and the specific belief shifts required.&lt;/p&gt;
&lt;p&gt;This is where the discovery framework transforms the gate from a guessing exercise into a structured analysis. Map the audience by role: the CISO in the room cares about risk quantification and board-level language, the architect cares about integration complexity and operational overhead, the practitioner cares about daily workflow and alert fatigue. Each role has different objections, and those objections fall into four categories — clarification (they need more info), objection (they disagree), stall (they are not ready), and test (they are probing your credibility). Your audience delta should anticipate all four types, because your talk needs to handle them structurally, not just in Q&amp;amp;A.&lt;/p&gt;
&lt;h2&gt;Gate 5: Argument Map&lt;/h2&gt;
&lt;p&gt;Only now do you create story.canvas — the visual story map. Use Canvas with constrained node types: thesis, claim, evidence, example, objection, slide candidate, and product bridge. Canvas stores its data as .canvas JSON files, which means the argument map is machine-readable.&lt;/p&gt;
&lt;h2&gt;Gate 6: Slide Cards (Proof Structure)&lt;/h2&gt;
&lt;p&gt;Before writing any polished copy, create one note per slide in slides/. Each slide note must declare its purpose, proof, memory hook, visual concept, and product role. It must also specify what to cut if time is short.&lt;/p&gt;
&lt;p&gt;This is the key anti-slop move. The model cannot hide weak thinking behind fluent prose because every slide has to declare its job before it gets to write anything.&lt;/p&gt;
&lt;p&gt;This is also where Cohan’s Great Demo! structure pays off. Each slide card should follow a proof logic: what claim does this slide make, what evidence supports it, and what should the audience believe differently after seeing it? Cohan’s sequence — opening context, capability demonstration, key message synthesis — maps directly to how you order your slide cards. The opening batch establishes context and makes the problem personal (Dunford’s market frame in action). The middle batch proves your claims with specifics. The closing batch synthesizes what was proven and bridges to action. Every slide card that cannot answer “what does this prove?” is a candidate for cutting.&lt;/p&gt;
&lt;p&gt;Cohan’s “key situation” concept is especially powerful here: instead of showing a generic capability, bridge it to a scenario the audience recognizes from their own work. A slide that says “our agent detects privilege escalation” is a feature. A slide that says “here is what happens when a compromised service account requests admin credentials at 2 AM and your on-call engineer has six minutes to respond” is a proof event.&lt;/p&gt;
&lt;p&gt;Each slide card should also pass Klaff’s hot cognition test: does this slide create desire, tension, or both? Desire is “I want that outcome.” Tension is “I need to know what happens next.” Slides that create neither — data summaries, category definitions, landscape overviews — activate cold, analytical processing and lose the room. The fix is not to remove analytical content but to sequence it so it always follows a hot-cognition moment. The audience’s croc brain says “I need to understand this” only after you have made them want something or worry about something. In your slide card template, add a field: cognition_type: hot | cold | bridge. No more than two cold slides in a row, and never open or close a batch with one.&lt;/p&gt;
&lt;h2&gt;Gate 7: Batch Drafting&lt;/h2&gt;
&lt;p&gt;Draft only 2–4 slides at a time. Never the whole deck at once.&lt;/p&gt;
&lt;p&gt;Batch sequence: framing first, then core argument, then technical proof, then action/close. After each batch, you choose: approve, revise, cut, or replace.&lt;/p&gt;
&lt;p&gt;This is also where Klaff’s push/pull pacing becomes structural. A deck that only pushes (here is why this matters, here is what you should do, here is why we are the answer) creates a one-directional energy that the audience’s croc brain reads as “someone is selling me something.” Push/pull alternates: you advance a strong claim (push), then introduce a complication, an honest limitation, or a question that creates uncertainty (pull). The pull creates tension — the audience leans in because they need to know how it resolves. Klaff calls this the intrigue frame. In practice, this means your core argument batch should not be four slides of escalating proof. It should be: claim → complication → deeper proof that resolves the complication → next claim. Each tension loop resets the audience’s attention clock.&lt;/p&gt;
&lt;h2&gt;Gate 8: Hostile Review&lt;/h2&gt;
&lt;p&gt;Before finalization, run three mandatory review passes:&lt;/p&gt;
&lt;p&gt;• reviews/skeptic-practitioner.md — “Where does this sound generic, weak, or under-evidenced?”&lt;/p&gt;
&lt;p&gt;• reviews/conference-reviewer.md — “What is genuinely distinct versus standard vendor content?”&lt;/p&gt;
&lt;p&gt;• reviews/anti-pitch-review.md — “Where does the deck start sounding commercial instead of educational?”&lt;/p&gt;
&lt;p&gt;At minimum, these three review passes are mandatory. Experienced SEs will probably add more passes with competitive analysis.&lt;/p&gt;
&lt;h2&gt;Gate 9: Rehearsal and Compression&lt;/h2&gt;
&lt;p&gt;Only after the deck is structurally approved do you generate rehearsal materials: opening options, closing, Q&amp;amp;A prep, and compressed variants (cut-to-30, cut-to-20).&lt;/p&gt;
&lt;p&gt;Eradicating neediness is the single most important delivery concept most SEs never practice. The audience’s croc brain is exquisitely tuned to detect neediness — the subtle signals that you want their approval, their deal, their positive evaluation. When the croc brain detects neediness, it categorizes you as low-status, and low-status information gets filtered out. The formula is: want nothing, focus on doing excellent work, and be willing to withdraw.&lt;/p&gt;
&lt;p&gt;In practice, this means your rehearsal should explicitly practice the moments where you are most tempted to seek validation: the product bridge, the closing ask, the Q&amp;amp;A and replace approval-seeking language with confident, take-it-or-leave-it framing. “We think you might find this useful” is needy. “This is what it does. Here is who it is for. You know whether that is you” is not.&lt;/p&gt;
&lt;p&gt;Situational status matters here too. You are not trying to dominate the room, that is a different kind of failure. You are establishing local star power: for the next 25 minutes, on this specific topic, you are the most informed person in the room. Your rehearsal should practice owning that status without arrogance.&lt;/p&gt;
&lt;p&gt;The rehearsal agents can help: have one generate the three most status-challenging questions an audience member could ask (the “analyst frame” that tries to drag you into granular data defense) and practice redirecting to your frame instead of getting pulled into theirs.&lt;/p&gt;
&lt;p&gt;The rehearsal gate is where many SEs skip corners because the argument feels “done.” It is not done until you know your opening cold, you can handle the three hardest questions without fumbling, you have a plan for what to cut when the moderator tells you that you have five fewer minutes than expected, and your delivery posture is confident without being needy.&lt;/p&gt;
&lt;h2&gt;What a Real Session Looks Like&lt;/h2&gt;
&lt;p&gt;Here is a concrete example of how this plays out in practice.&lt;/p&gt;
&lt;p&gt;You are building a 25-minute conference talk on cloud runtime security for an audience of security architects and engineering leads. You have a vault with your brief, 12 source notes, and 6 approved claims. Now that you have laid the groundwork we can get AI to help us build the rest.&lt;/p&gt;
&lt;p&gt;You open Claude Code in the project folder and say:&lt;/p&gt;
&lt;p&gt;Read the brief, audience delta, and all claim files. Then do three things in parallel:&lt;/p&gt;
&lt;p&gt;1. Propose a 10-slide sequence based on the approved claims&lt;/p&gt;
&lt;p&gt;2. Run an Explore agent to find which source notes are not linked to any claim&lt;/p&gt;
&lt;p&gt;3. Check if any claims lack supporting evidence&lt;/p&gt;
&lt;p&gt;Claude Code spawns three agents. Within a couple of minutes you have: a proposed slide sequence, a list of orphaned sources you might be under-using, and a list of claims that need stronger evidence before they earn a slide.&lt;/p&gt;
&lt;p&gt;You approve the sequence with two changes, then say:&lt;/p&gt;
&lt;p&gt;Draft slides 1–3 (framing batch). Keep the thesis from 01-thesis.md intact. No product positioning. Use evidence from the linked source notes only.&lt;/p&gt;
&lt;p&gt;While that agent drafts, you could also ask:&lt;/p&gt;
&lt;p&gt;In parallel, review slides 7–10 from the last session against the skeptic-practitioner persona. Flag anything that sounds like vendor messaging.&lt;/p&gt;
&lt;p&gt;Two agents, working simultaneously. One creating, one reviewing. You are the editor-in-chief, reading the outputs and making the calls.&lt;/p&gt;
&lt;h2&gt;The Takeaway&lt;/h2&gt;
&lt;p&gt;The SE teams that will build the best presentations with AI are not the ones who generate the fastest. They are the ones who treat presentations like engineering projects: structured inputs, staged gates, parallel workers, human judgment at every decision point, and a project folder that remembers everything the chat window forgets. This is where our technical background shines.&lt;/p&gt;
&lt;p&gt;The operating philosophy is simple: Position → Discover → Prove → Control. The nine gates enforce the sequence. The custom agents provide the cognitive diversity that a single perspective cannot.&lt;/p&gt;
&lt;p&gt;The model is not your ghostwriter. It is your research team, your structural editor, your hostile reviewer, your competitive analyst, your frame-control auditor, and your compression engine.&lt;/p&gt;
&lt;p&gt;Use it that way, and your talks will be sharper than anything you could build alone or anything the model could generate on its own. This is the way.&lt;/p&gt;
</content:encoded><dc:creator>Pier-Luc Charbonneau</dc:creator><category>Sales Engineering</category></item><item><title>Do You Have a Shadow AI Problem? Here&apos;s How to Find Out in 30 Minutes.</title><link>https://charbonneau.io/articles/do-you-have-a-shadow-ai-problem-heres-how-to-find-out-in-30-minutes/</link><guid isPermaLink="true">https://charbonneau.io/articles/do-you-have-a-shadow-ai-problem-heres-how-to-find-out-in-30-minutes/</guid><description>Discover the Shadow AI challenge: ensure your employees&apos; AI usage stays secure and compliant with our practical dashboard guide.</description><pubDate>Sat, 14 Mar 2026 21:19:52 GMT</pubDate><content:encoded>&lt;p&gt;Your employees are using AI. The question isn&apos;t &lt;em&gt;if&lt;/em&gt;. It&apos;s &lt;em&gt;how much&lt;/em&gt;, &lt;em&gt;which tools&lt;/em&gt;, and &lt;em&gt;what data are they sharing?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Research shows that roughly &lt;strong&gt;1.6% of all AI prompts contain sensitive enterprise data&lt;/strong&gt;: credentials, PII, internal strategy, proprietary code. In a 1,000-person organization, that can translate to over &lt;strong&gt;160 potential data exposures every single day&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;And here&apos;s the part that keeps CISOs up at night: most security teams have &lt;strong&gt;zero visibility&lt;/strong&gt; into which AI tools their workforce is actually using.&lt;/p&gt;
&lt;p&gt;This is the &lt;strong&gt;Shadow AI&lt;/strong&gt; problem.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;What Is Shadow AI?&lt;/h3&gt;
&lt;p&gt;Shadow AI is any AI tool used by employees outside official IT oversight. Think of it as the next evolution of Shadow IT, but with significantly higher stakes.&lt;/p&gt;
&lt;p&gt;An employee pastes a customer contract into ChatGPT for summarization. A developer feeds proprietary source code into Cursor or Copilot. Someone in finance runs a P&amp;amp;L through Claude for analysis. None of these interactions are logged, monitored, or governed by your security stack.&lt;/p&gt;
&lt;p&gt;Every one of them is a potential data leak.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;A Simple Way to Measure Your Exposure&lt;/h3&gt;
&lt;p&gt;If you&apos;re a SentinelOne customer running the &lt;strong&gt;Singularity Platform&lt;/strong&gt; with AI SIEM, you can build a &lt;strong&gt;Shadow AI Discovery Dashboard&lt;/strong&gt; in about 30 minutes using telemetry your EDR agents are already collecting. No additional agents, no new integrations, no extra licensing.&lt;/p&gt;
&lt;p&gt;The dashboard leverages two data sources that SentinelOne agents natively collect:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;URL events&lt;/strong&gt; to track which AI websites employees are visiting&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Process Creation events&lt;/strong&gt; to identify AI desktop applications being launched&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Here&apos;s how to build it.&lt;/p&gt;
&lt;h3&gt;Step 1: Create the Dashboard&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;In the &lt;strong&gt;Singularity Operations Center&lt;/strong&gt;, navigate to &lt;strong&gt;Dashboards &amp;gt; Custom Dashboards&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;New Dashboard&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Name it something like &lt;strong&gt;AI Usage Monitoring&lt;/strong&gt; and click &lt;strong&gt;Create&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Step 2: Add Six Panels&lt;/h3&gt;
&lt;p&gt;For each panel below, click the &lt;strong&gt;+&lt;/strong&gt; button on your dashboard, select &lt;strong&gt;Pie/Donut Chart&lt;/strong&gt;, and paste the corresponding query. Set each panel to &lt;strong&gt;Pie&lt;/strong&gt; style, &lt;strong&gt;10 max slices&lt;/strong&gt;, and &lt;strong&gt;Percentage&lt;/strong&gt; labels.&lt;/p&gt;
&lt;h3&gt;Panel 1: AI Desktop Apps (All OS)&lt;/h3&gt;
&lt;p&gt;See which AI desktop applications are being launched across your entire fleet.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;| filter( event.type == &quot;Process Creation&quot; AND tgt.process.name in:anycase( &quot;ChatGPT.exe&quot;, &quot;Claude.exe&quot;, &quot;Perplexity.exe&quot;, &quot;Copilot.exe&quot;, &quot;ms-copilot.exe&quot;, &quot;Cursor.exe&quot;, &quot;Windsurf.exe&quot;, &quot;LM Studio.exe&quot;, &quot;Jan.exe&quot;, &quot;ollama.exe&quot;, &quot;anythingllm.exe&quot;, &quot;flowise.exe&quot;, &quot;tabby.exe&quot;, &quot;brave.exe&quot;, &quot;notion.exe&quot;, &quot;obsidian.exe&quot;, &quot;vscode.exe&quot; ) )
| group ProcessCount = count() by tgt.process.name
| sort - ProcessCount
| limit 1000 
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Panel 2: AI Desktop Apps (Windows)&lt;/h3&gt;
&lt;p&gt;Break down AI app usage specifically on Windows endpoints.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;| filter( event.type == &quot;Process Creation&quot; AND endpoint.os == &quot;windows&quot; AND tgt.process.name in:anycase( &quot;ChatGPT.exe&quot;, &quot;Claude.exe&quot;, &quot;Perplexity.exe&quot;, &quot;Copilot.exe&quot;, &quot;ms-copilot.exe&quot;, &quot;Cursor.exe&quot;, &quot;Windsurf.exe&quot;, &quot;LM Studio.exe&quot;, &quot;Jan.exe&quot;, &quot;ollama.exe&quot;, &quot;anythingllm.exe&quot;, &quot;flowise.exe&quot;, &quot;tabby.exe&quot;, &quot;brave.exe&quot;, &quot;notion.exe&quot;, &quot;obsidian.exe&quot;, &quot;vscode.exe&quot; ) )
| group ProcessCount = count() by tgt.process.name
| sort - ProcessCount
| limit 1000 
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Panel 3: AI Desktop Apps (macOS)&lt;/h3&gt;
&lt;p&gt;Same view for macOS. Note that macOS process names don&apos;t include the .exe extension.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;| filter( event.type == &quot;Process Creation&quot; AND endpoint.os == &quot;osx&quot; AND tgt.process.name in:anycase( &quot;ChatGPT&quot;, &quot;Claude&quot;, &quot;Perplexity&quot;, &quot;Copilot&quot;, &quot;Cursor&quot;, &quot;Windsurf&quot;, &quot;LM Studio&quot;, &quot;Jan&quot;, &quot;ollama&quot;, &quot;anythingllm&quot;, &quot;flowise&quot;, &quot;tabby&quot;, &quot;brave&quot;, &quot;notion&quot;, &quot;obsidian&quot;, &quot;vscode&quot; ) )
| group ProcessCount = count() by tgt.process.name
| sort - ProcessCount
| limit 1000 
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Panel 4: Top AI Users&lt;/h3&gt;
&lt;p&gt;Identify which users are generating the most AI web traffic. This is often the most eye-opening panel.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;| filter( event.category == &quot;url&quot; AND url.address contains:anycase( &quot;chatgpt.com&quot;, &quot;openai.com&quot;, &quot;claude.ai&quot;, &quot;anthropic.com&quot;, &quot;ai.google&quot;, &quot;grok.com&quot;, &quot;gemini.google&quot;, &quot;midjourney.com&quot;, &quot;copilot.microsoft&quot;, &quot;perplexity.ai&quot; ) )
| group URLCount = count() by src.process.user
| sort - URLCount
| limit 10 
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Panel 5: Which Browsers Are Accessing AI Sites&lt;/h3&gt;
&lt;p&gt;Understand the browser landscape driving AI usage.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;| filter( event.category == &quot;url&quot; AND url.address contains:anycase( &quot;chatgpt.com&quot;, &quot;openai.com&quot;, &quot;claude.ai&quot;, &quot;anthropic.com&quot;, &quot;ai.google&quot;, &quot;grok.com&quot;, &quot;gemini.google&quot;, &quot;midjourney.com&quot;, &quot;copilot.microsoft&quot;, &quot;perplexity.ai&quot; ) )
| group URLCount = count() by src.process.name
| sort - URLCount
| limit 10 
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Panel 6: Top AI Sites by Volume&lt;/h3&gt;
&lt;p&gt;See the most-visited AI services across your organization.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;| filter( event.category == &quot;url&quot; AND url.address contains:anycase( &quot;chatgpt.com&quot;, &quot;openai.com&quot;, &quot;claude.ai&quot;, &quot;anthropic.com&quot;, &quot;ai.google&quot;, &quot;grok.com&quot;, &quot;gemini.google&quot;, &quot;midjourney.com&quot;, &quot;copilot.microsoft&quot;, &quot;perplexity.ai&quot; ) )
| group URLCount = count() by url.address
| sort - URLCount
| limit 1000 
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Step 3: Read the Results&lt;/h3&gt;
&lt;p&gt;Set the time range to &lt;strong&gt;24 hours&lt;/strong&gt; and let the data tell the story.&lt;/p&gt;
&lt;p&gt;If you see pie chart slices populating, congratulations: you&apos;ve just confirmed that AI is actively being used in your environment. Now ask yourself:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Are these &lt;strong&gt;sanctioned&lt;/strong&gt; tools?&lt;/li&gt;
&lt;li&gt;Do you have &lt;strong&gt;policies&lt;/strong&gt; governing their use?&lt;/li&gt;
&lt;li&gt;Is &lt;strong&gt;sensitive data&lt;/strong&gt; being shared in those interactions?&lt;/li&gt;
&lt;li&gt;Would you know if an employee pasted a &lt;strong&gt;customer database schema&lt;/strong&gt; into one of these tools today?&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h3&gt;What This Dashboard Can (and Can&apos;t) Tell You&lt;/h3&gt;
&lt;p&gt;This dashboard gives you &lt;strong&gt;visibility&lt;/strong&gt;: who is using AI, which tools, how often, and from which endpoints. That alone is a massive step forward for most organizations.&lt;/p&gt;
&lt;p&gt;But it &lt;strong&gt;can&apos;t&lt;/strong&gt; tell you:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;What data&lt;/strong&gt; is being shared in those AI interactions&lt;/li&gt;
&lt;li&gt;Whether prompts contain &lt;strong&gt;PII, credentials, or proprietary code&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Whether employees are using &lt;strong&gt;unapproved AI tools&lt;/strong&gt; beyond the ones listed here (there are thousands)&lt;/li&gt;
&lt;li&gt;Whether your custom AI applications are vulnerable to &lt;strong&gt;prompt injection&lt;/strong&gt; or &lt;strong&gt;jailbreak attacks&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That&apos;s where a deeper assessment comes in.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;The Next Step: A Prompt Security Assessment&lt;/h3&gt;
&lt;p&gt;If your dashboard reveals AI usage (and it almost certainly will), the natural follow-up question is: &lt;strong&gt;&quot;How do I secure this without blocking productivity?&quot;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Prompt Security from SentinelOne&lt;/strong&gt; is purpose-built to answer that question. It deploys in minutes via a lightweight browser extension and gives you:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Real-time shadow AI discovery&lt;/strong&gt; across 15,000+ AI sites and tools&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Context-aware DLP&lt;/strong&gt; that automatically redacts sensitive data from prompts before they reach external models&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Policy-based controls&lt;/strong&gt; that let you enforce safe AI usage without blocking the tools entirely&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prompt injection and jailbreak prevention&lt;/strong&gt; for your custom AI applications&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Full audit logging capabilities&lt;/strong&gt; for every AI interaction when compliance requires it&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;One customer discovered &lt;strong&gt;over 60 shadow AI tools within the first day&lt;/strong&gt; of running a Prompt Security assessment. That&apos;s 60 tools their existing security stack had no visibility into.&lt;/p&gt;
&lt;p&gt;If you&apos;re seeing AI activity on your dashboard and you want to understand what&apos;s actually happening inside those interactions, &lt;strong&gt;reach out to your SentinelOne team or partner to schedule a Prompt Security Assessment&lt;/strong&gt;. It&apos;s the fastest way to go from &quot;we have a shadow AI problem&quot; to &quot;we have a shadow AI &lt;em&gt;solution&lt;/em&gt;.&quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;The Bottom Line&lt;/h3&gt;
&lt;p&gt;AI adoption isn&apos;t slowing down. Your employees aren&apos;t going to stop using ChatGPT, Claude, or Copilot because you asked them nicely. The organizations that win are the ones that give their workforce &lt;strong&gt;guardrails&lt;/strong&gt;, not &lt;strong&gt;roadblocks&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Start with visibility. Build this dashboard. See what you find. And when you&apos;re ready to take the next step, let&apos;s talk about what Prompt Security can do for your organization.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The data is already there. The question is whether you&apos;re looking at it.&lt;/strong&gt;&lt;/p&gt;
</content:encoded><dc:creator>Pier-Luc Charbonneau</dc:creator><category>SentinelOne</category></item><item><title>We Blurred Our Backgrounds. Now We’re Blurring Our Thinking.</title><link>https://charbonneau.io/articles/blurred-background/</link><guid isPermaLink="true">https://charbonneau.io/articles/blurred-background/</guid><description>During the pandemic, when everything shifted to virtual meetings, we began to blur our backgrounds and activate the ‘touch up my appearance’ feature. We also…</description><pubDate>Mon, 02 Mar 2026 23:47:44 GMT</pubDate><content:encoded>&lt;p&gt;To begin, we focused on enhancing our image.&lt;/p&gt;
&lt;p&gt;During the pandemic, when everything shifted to virtual meetings, we began to blur our backgrounds and activate the ‘touch up my appearance’ feature. We also muted any background noise. We traded the vulnerability of noisy open-floor physical presence for the safety of a controlled, perfectly lit window. Professional presentation matters, and nobody owes their coworkers a view of their chaos. But we got a taste for something beyond pragmatism: the comfort of a smoothed-out version of ourselves.&lt;/p&gt;
&lt;p&gt;That was just the beginning.&lt;/p&gt;
&lt;p&gt;Now, with AI writing assistants embedded in every enterprise workflow, we’ve extended the same instinct to how we think. Everyone sends perfectly formatted emails, perfectly structured proposals, perfectly polished briefs. The effort of organizing one’s own ideas (the part that makes an idea unique and personal) has been delegated to a model trained on the output of others.&lt;/p&gt;
&lt;p&gt;I have coined a term for this: ‘freeze-dried competence’. It’s structurally sound, grammatically impeccable, and has about as much nutritional value as astronaut food. It offers maximum shelf life and minimum vitality.&lt;/p&gt;
&lt;p&gt;Here’s a test I’ve been running informally. When I receive a business email, I try to guess whether it was AI-assisted. Six months ago this was easy (the tells were obvious). Now it’s harder. Not because the AI has gotten better at mimicking human writing, but because human writing is converging toward AI writing. People are internalizing the patterns. The model isn’t just writing for us: it’s teaching us to write like it.&lt;/p&gt;
&lt;p&gt;The productivity gains are real and I’m not dismissing them. But the productivity argument has a blind spot: it assumes the only function of writing is to transmit information. That the struggle of finding the right words, of sitting with the discomfort of not quite knowing what you think until you’ve tried to say it is “waste” to be eliminated.&lt;/p&gt;
&lt;p&gt;It isn’t waste. It’s the process through which original thought actually happens. Thinking and expression aren’t separable. The sentence you restructured three times, the paragraph you deleted because writing it revealed you didn’t actually believe it: those aren’t cosmetic edits to a pre-formed thought. They’re the thought forming. Skip the struggle and you don’t get the same thought faster. You get a shallower one.&lt;/p&gt;
&lt;p&gt;When an entire organization runs communication through the same models trained on the same data, expression undergoes a massive regression to the mean. Large language models generate the statistically most likely output given the input. That’s not a flaw; it’s the mechanism. Every use pulls expression toward the center of the training distribution. The cracks in communication (the awkward phrasing, the unexpected tangent, the word choice that makes you pause) are exactly the signals that a specific human mind was at work. We’re engineering them out.&lt;/p&gt;
&lt;p&gt;The philosopher J.F. Martel draws a useful distinction between art and artifice. Art opens what he calls a “rift” in consensus reality: it discloses something unpredictable. Artifice closes the rift by engineering a predetermined response. Propaganda is artifice. A Hollywood blockbuster calibrated to hit every emotional beat on schedule is artifice. And an AI-polished email, optimized for the expected professional response, is artifice too.&lt;/p&gt;
&lt;p&gt;Martel’s deeper point is structural. When you collapse the boundary between genuine exploration and instrumental output, the instrumental logic always wins, because it’s measurable and exploration is not. In enterprise terms: the productivity gains show up on dashboards. The slow flattening of an organization’s capacity to surprise itself does not.&lt;/p&gt;
&lt;p&gt;Long-term innovation has never come from doing the expected thing faster. It comes from the deviations. The misread brief that sends a project somewhere better than the original plan. The junior employee who proposes something naive that contains a kernel of genuine insight. The disorganized hallway conversation that connects two unrelated problems. None of these moments are efficient. None would survive optimization. They exist because of friction, not despite it.&lt;/p&gt;
&lt;p&gt;I don’t dispute the usefulness of AI tools; I use them myself. Rejecting them would be similar to rejecting email in 1998. What I am arguing is that there’s a category of friction that isn’t waste, and that organizations need to learn the difference between the efficiency that accelerates execution and the efficiency that flattens thinking.&lt;/p&gt;
&lt;p&gt;AI can help eliminate wasteful friction such as data formatting, information retrieval, and first-draft templating. However, it is important to protect productive friction, such as ideation without AI assistance and writing that forces people to think through their own positions. Spaces where exploration is the goal rather than output should also be preserved.&lt;/p&gt;
&lt;p&gt;We must say, with a straight face, that “we’re going to be deliberately less efficient here because the efficiency is costing us something we can’t measure but can’t afford to lose.” Hard sell in a quarterly earnings culture. But the right one.&lt;/p&gt;
&lt;p&gt;I often find myself wondering: if the flaws and imperfections in communication are indicators of creative thought, then what are we constructing when we meticulously eliminate them all?&lt;/p&gt;
</content:encoded><dc:creator>Pier-Luc Charbonneau</dc:creator><category>Sales Engineering</category></item></channel></rss>