BlueprintPage 07
07BUSINESS
Ideal Customer Profile & Market Entry
Lead with shadow-agent discovery + high-risk permission visibility, then activate enforcement.
- Priority
- P0
- Phase
- Launch
- Primary owner
- CEO / Sales
- Status
- Blueprint
Objective
The initial market should favor organizations that already have meaningful AI-agent adoption, sensitive systems, mature security teams and a reason to prove control. Start where the cost of an uncontrolled agent is materially higher than the subscription price and where integration sophistication is an advantage rather than a barrier.
What to build
- Tier 1 ICP: 2,000+ employee enterprises with active Microsoft/OpenAI/Anthropic/Google agent programs and dedicated security/IAM teams.
- Priority sectors: financial services, software/cloud, manufacturing, energy, insurance, business services and regulated enterprises.
- Trigger events: agent rollout, internal AI platform launch, MCP adoption, AI governance program, audit finding, security incident or rapid AI cost growth.
- Secondary ICP: high-growth software companies embedding agents into customer-facing products.
Implementation decisions
- Create an account scoring model using employee count, AI hiring, cloud footprint, security maturity, regulated-data exposure and agent-program signals.
- Sell the first proof of value into one controlled environment rather than asking to secure the whole company on day one.
- Target a 2-4 week discovery/governance proof before enforcing high-risk runtime policies.
- Create deployment options for SaaS control plane with customer-managed gateway/data plane where required.
Definition of done
- ICP definition is encoded in CRM and outbound targeting.
- Pilot scope can be deployed without a multi-quarter professional-services project.
- Reference architecture exists for cloud-first and high-control enterprises.
Success metrics
- Pilot-to-paid conversion
- Time to first value
- Agents discovered per pilot
- Expansion ARR after initial deployment
ENTRY WEDGE
Lead with shadow-agent discovery + high-risk permission visibility, then activate enforcement.