Aegis / Pinnacle Insurance - Detect Roadmap Review
Aegis will log Detect feature requests and schedule Comply v2 demo after roadmap review
Sandra Keating raised two Detect feature requests: per-entity-type alert thresholds with custom baselines, and in-product pipeline health status after the March outage. Rachel Torres acknowledged the outage, described the implemented fix, and will log both feature requests. Rachel also shared roadmap items including expanded SIEM integrations and a threat intelligence correlation layer, with follow-up on FS-ISAC feed support. Sandra expressed interest in a Comply v2 demo for the upcoming SOC 2 renewal, and Rachel will coordinate that with Marcus. The call ended with a recap of follow-ups Rachel will send by end of week.
How the call went
Customer sentiment was mostly neutral and professional, with frustration around alert fatigue and the March outage offset by appreciation for Rachel's honesty and responsiveness.
Opening
0Close
011 scored turns of 74. Hover a point for the model's reason, or read the transcript.
How the conversation ran?Talk share is measured from speech time in the captured portion of the transcript.
- Questions we asked
- 9
- Questions they asked
- 5
- Turns
- 74
- Longest silence
- 2s
Who was on the call
AegisCloud
Customer
- Sandra Keating?Matched on an initial rather than a full name, so attribution is weaker.
What happened12
The moments the model picked out, grouped by kind. Each opens onto the turns behind it.
Issue raised2?A problem was brought up on the call.
Sandra identifies the primary Detect gap: alert thresholds are one-size-fits-all and need to vary by entity type, causing noise on low-risk systems and under-alerting on high-value systems.
Sandra requests in-product pipeline health visibility after discovering the outage only because alert volume dropped to zero.
Commitment3?Someone committed to doing something.
Rachel says entity grouping is scoped but not GA, targeted for Q3, and she will connect Sandra with the product team so they have context.
Rachel commits to logging a formal feature request for in-product pipeline health status with proactive degradation alerts.
Comply v2's on-demand SOC 2 reporting aligns with Sandra's renewal pain; Rachel will set up a demo with Sandra and Marcus.
Decision1?A decision was reached.
Sandra and Rachel align on the need for entity groups with custom behavioral baseline models mapped to the customer's org hierarchy.
Risk1?A risk to the account, project, or system was surfaced.
Sandra raises the March outage, citing six hours without threat visibility and regulatory implications.
Recap4?A summary of what was agreed.
Rachel acknowledges the outage as a significant failure and describes the implemented fix: redundant processing nodes and a circuit breaker pattern live since mid-March.
Rachel announces Q2 expanded SIEM integrations, including a native connector for LogVault, which Sandra welcomes as reducing manual scripting.
Rachel announces a threat intelligence correlation layer; Sandra asks about feeds and specifically requests FS-ISAC.
Rachel recaps action items: two feature requests, feed list, LogVault timeline, and Comply demo; Sandra confirms.
Praise1?The customer said something positive.
Sandra appreciates Rachel actually listening, noting calls sometimes go into a black hole.
What was promised6
| Commitment | Owner | Due | Action type | ||
|---|---|---|---|---|---|
| Log formal feature request for entity grouping with custom behavioral baselines. | Rachel TorresAegisCloud | No date given | project tracking?Create, break down, or update tickets, epics, sprint boards, milestone plans, or roadmaps, including managing project trackers and task lists. | ||
| Log formal feature request for in-product pipeline health status with proactive degradation alerts. | Rachel TorresAegisCloud | No date given | project tracking?Create, break down, or update tickets, epics, sprint boards, milestone plans, or roadmaps, including managing project trackers and task lists. | ||
| Send confirmed list of threat intel feeds for correlation layer, including whether FS-ISAC is included. | Rachel TorresAegisCloud | 17 Apr 2026said “end of week” | send artefact?Deliver or transmit a prepared document, report, email, or update to a recipient by sharing, emailing, circulating, or handing it over. | ||
| Send details on LogVault native connector timeline. | Rachel TorresAegisCloud | 17 Apr 2026said “end of week” | send artefact?Deliver or transmit a prepared document, report, email, or update to a recipient by sharing, emailing, circulating, or handing it over. | ||
| Set up Comply v2 demo with Sandra and Marcus, aiming for week of April 20. | Rachel TorresAegisCloud | 20 Apr 2026said “within the next two weeks” | schedule session?Arrange, coordinate, or block time for a meeting, call, demo, working session, or walkthrough, including inviting participants and confirming attendance. | ||
| Keep Sandra updated on traction of feature requests with the product team. | Rachel TorresAegisCloud | No date given | notify or loop in?Inform, flag, copy, connect, or give a heads-up to a person or team for awareness, including internal alerts and handoffs that are not formal escalations. |
Left unanswered3
Which threat intel feeds will the correlation layer include?
AegisCloudSecurityWill FS-ISAC be included in the threat intel feed integration?
AegisCloudSecurityWill in-product pipeline health status with proactive degradation alerts be built?
AegisCloudMonitoring
Themes and issues5
What the call was about, and the specific issue recorded under each theme.
| Theme | As the model phrased it?The wording the model used before mapping it to the shared taxonomy. | Issue | |
|---|---|---|---|
| Monitoring?Calls about system monitoring, alerting, and visibility tools and practices. | alerting | entity type alert thresholds | |
| Reliability?Calls about overall system reliability, availability, resilience, capacity, and performance, excluding specific outages or incident response. | reliability | pipeline health visibility | |
| Integration?Calls about integrating systems via APIs, pipelines, and other connectivity work. | integrations | siem connector expansion | |
| Security?Calls about security threats, vulnerabilities, certificates, and threat intelligence. | threat intelligence | external feed correlation | |
| Compliance?Calls about regulatory, audit, and security compliance obligations, reporting, and readiness. | compliance | audit evidence reporting |
Numbers stated on this call2
Values are shown exactly as they were spoken.
| Claim | As spoken | Metric | Stated by | |
|---|---|---|---|---|
| Duration of March Detect outage | “six hours” | outage duration | Sandra Keating | |
| Alert volume during March outage | “zero” | event count | Sandra Keating |
Coaching4
How the AegisCloud side handled the call.
Strengths (4)
Rachel asked clarifying questions to understand the entity-type use case before responding.
Rachel took responsibility for the March outage without deflecting and explained the remediation.
Rachel recapped all commitments clearly and confirmed them with Sandra.
Rachel committed to keep Sandra updated even if product traction is slow.
Improvement notes (0)
Nothing recorded.
How far to trust this call
Every fact above was extracted from the captured portion of the transcript only.
13 min captured of 48 min stated. Anything said in the remaining 35 min is absent from this page.
0 turns flagged low-confidence.
- Clocks unaligned(warning)
2 participant(s) speak before joining — transcript and events are on different clocks. Do NOT derive absolute timestamps by joining these two sources.
- Partial transcript(warning)
transcript covers 23.8% of a 47.9min meeting; 35.3min after the final turn is unaccounted for
The model's own note: Transcript is partial; call may have continued past the recorded span.
Extracted 2 Aug 2026 by deepseek-v4-flash · extractor v1.0.0 · schema v1.1.0 · extended thinking on · 22,376 tokens