Skip to content
Demo · Day 1

Day 1 — Kenji's Shadow

Microsoft logo

Microsoft · Incident Response Automation — SOC Playbook Deployment

Section 1 of 5 · Scene Setup

~12 min left

Scene Setup

You open your laptop at 8:30am from your home office. Your Microsoft Teams inbox has 4 messages waiting — a welcome note from Grace Liu with onboarding links, a meeting invite from Victor Reyes for a 'New PM Introduction' at 2pm, a Teams channel notification from '#soc-automation-project' (11 unread messages from the past 2 weeks), and a direct message from Alex Petrov: 'Hey. Kenji said you'd be starting today. Let me know when you want to sync on the integration status. No rush.'

The 'no rush' feels deliberate. Alex has been working without PM oversight for 2 weeks since Kenji left. He's been productive — the Teams channel shows him posting daily updates on the integration build — but the tone is independent, not collaborative. He's been running the project himself.

You spend the first 90 minutes reading Kenji's handover documentation. It's thorough: a project status document, stakeholder map, technical architecture diagram, playbook designs, and a candid 'things you should know' section. Kenji clearly cared about this project and about the team. His documentation style is warm and personal — he refers to Alex as 'the backbone of this project' and describes Sofia as 'direct and doesn't tolerate hand-waving.'

At 10am, you check the project's Azure DevOps board. The backlog is clean — Kenji organized it well. But you notice the last 2 weeks of work items (since Kenji left) are assigned to Alex and marked 'In Progress' with no PM review or approval. Alex has been self-directing based on the technical spec Kenji approved. The work looks solid from the descriptions, but you haven't validated it.

At 2pm, you join the Teams call with Victor Reyes. He's in his home office in Bellevue, a framed Microsoft Security badge on the wall behind him. He's measured and welcoming, but his first question is pointed.