Medigram Insights · September 2026

Sherri Douville on The New CISO: Trust, AI Agents, Security and Accountable Outcomes

A conversation with Exabeam's Steve Moore and Medigram CEO Sherri Douville on the changing role of the CISO, trustworthy AI and agents, evidence, behavior verification, continuous monitoring, and the operational consequences of reliability failures in healthcare.

From The New CISO, an Exabeam podcast: Episode 150, “The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools” (September 18, 2026)

The New CISO is a podcast produced and published by Exabeam. This page presents selected highlights and an edited transcript; the full episode and original transcript are available on Exabeam’s site.

Episode art for The New CISO, Episode 150: The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools, courtesy of Exabeam
exabeam.com · The New CISO
The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools
Episode 150 · Host Steve Moore with guest Sherri Douville · September 18, 2026
Listen on Exabeam →

Episode art courtesy of Exabeam.

In the conversation, Sherri Douville, CEO and Architect of Medigram and Founder & Chair of the Trustworthy Technology & Innovation Consortium (TTIC), discusses governed AI decision records, the separation between TTIC and Medigram, how AI is changing the economic value of executive judgment, the CISO’s role as a steward of trust, why agent behavior verification and continuous monitoring matter after deployment, and the downstream clinical consequences of healthcare technology outages.

Key ideas from the conversation

Governed AI decisions and evidence
In the conversation, Sherri Douville describes Medigram as building and operating Darwin, a governed AI decision platform, and explains that Darwin produces a sealed governance record at the moment of an agent action, capturing what happened, when, why, and who was involved.
TTIC and standards-to-market implementation
In the conversation, Sherri Douville describes TTIC as an independent governance body, separate by design from Medigram, created to help move standards work into adoption, implementation, and maintenance across the stakeholders required in high-reliability environments.
The changing executive value of expertise
In the conversation, Sherri Douville argues that AI is changing the scarcity value of expert analysis, increasing the importance of judgment, authority, execution, verification, organizational integration, and ownership of the outcome.
CISO as an active steward of trust
In the conversation, Sherri Douville frames CISOs as potential stewards of trust who increasingly need selective depth and active involvement, rather than functioning only as advisory or reporting layers.
Agent behavior verification and continuous monitoring
In the conversation, Sherri Douville and Steve Moore distinguish pre-production assessment from runtime telemetry, emphasizing that configuration alone does not reliably predict agent behavior after deployment.
Healthcare reliability and the human cost of outages
In the conversation, Sherri Douville connects incident response and infrastructure reliability to downstream clinical delays, accumulated work, communication problems, and patient-safety consequences.

What is a sealed governance record for an AI or agent action?

In the conversation, Sherri Douville describes Medigram as building and operating Darwin, a governed AI decision platform, and explains that Darwin produces a sealed governance record at the moment of an agent action, capturing what happened, when, why, and who was involved.

Excerpts are quoted from the edited transcript below, based on Exabeam’s published transcript.

Medigram builds and operates Darwin, a governed AI decision platform. We have an agentic fleet running in production. What Darwin does is produce a sealed governance record at the moment of every agent action.

Sherri Douville

We focus on high-reliability industries like pro sports and healthcare. They need to have a record of what happened, when it happened, why it happened, and who was involved. That’s what we provide.

Sherri Douville

It’s the defensible, auditable record that they can provide to counsel, a court, an insurer, or a credit rating agency for financial and legal purposes.

Sherri Douville

Why was TTIC created, and how is it separate from Medigram?

In the conversation, Sherri Douville describes TTIC as an independent governance body, separate by design from Medigram, created to help move standards work into adoption, implementation, and maintenance across the stakeholders required in high-reliability environments.

TTIC is an independent governance body. Medigram is the company I run, which is a commercial implementation of the governance work we do, and they are separate by design.

Sherri Douville
Discussing IEEE/UL 2933:

TTIC was stood up by myself and Mitch Parker, CISO at IU Health. IEEE is an incredible organization, and we built this standard for clinical IoT device and data interoperability. However, to get it adopted and maintained in an industry like healthcare, you need many stakeholders involved. TTIC was created to bring together CIOs, CISOs, physicians, engineers, and everyone necessary to do that work.

Sherri Douville

Learn more at the Trustworthy Technology & Innovation Consortium (TTIC).

What is IEEE/UL 2933, and how does it shape the implementation?

I co-chair the Trust and Identity Subgroup of IEEE/UL 2933, the standard for clinical IoT data and device interoperability with TIPPSS: Trust, Identity, Privacy, Protection, Safety, and Security.

Sherri Douville

We implement IEEE/UL 2933, and we were able to use Praxen.

Sherri Douville

Having a strong architecture from the IEEE standard gave us a clear remit.

Sherri Douville

How is AI changing the role and economic value of executive expertise?

In the conversation, Sherri Douville argues that AI is changing the scarcity value of expert analysis, increasing the importance of judgment, authority, execution, verification, organizational integration, and ownership of the outcome.

The scarcity structure of expertise is changing. AI is reducing the value of expert analysis but increasing the value of something more mentally athletic. That formula is: judgment, authority, execution, verification, organizational integration, and ownership of the security outcome. Can I count on you, the CISO, to make that security problem disappear? Can you reduce my exposure? Can you produce the evidence that the issue was solved without creating another coordination burden for me?

Sherri Douville

What was the genesis of that framework?

Steve Moore

This conversation with you and the last one we had. It’s a derivative of our conversations.

Sherri Douville

What does it mean for a CISO to become a steward of trust?

In the conversation, Sherri Douville frames CISOs as potential stewards of trust who increasingly need selective depth and active involvement, rather than functioning only as advisory or reporting layers.

The reason it’s important, especially in healthcare, is that everything is about trust. The best CISOs are stewards of trust. In the tech industry, trust can sometimes be off to the side, but in healthcare, it’s the core of the business. It’s nice to see that the whole world, with AI and agents, is now moving towards trust. CISOs have the opportunity to be the stewards of that trust, and that’s how they can become the rock stars of the C-suite.

Sherri Douville

The CISO needs to be more like a defensive captain than an analyst, bringing the whole defensive team to the next level. They need to be able to go onto the court, not just coach from the sideline. That worked in a certain context, but not anymore. You need to have “selective depth”—selectively go deep to understand the work, even if you aren’t doing the security AI engineer’s job. If you don’t understand it, you need to get on top of it as quickly as possible.

Sherri Douville

Why do AI and agent systems require behavior verification after deployment?

In the conversation, Sherri Douville and Steve Moore distinguish pre-production assessment from runtime telemetry, emphasizing that configuration alone does not reliably predict agent behavior after deployment.

In your writing, you noted, “Configuration has stopped predicting behavior. That single fact has changed what the job is, what it costs, and what a CISO has to do personally… In agentic environments, the systems are immature, the abstractions are unreliable, and the consequences of subtle errors are high.”

Steve Moore, quoting Sherri Douville’s writing

How do Praxen and Observra fit into pre-production assessment and runtime monitoring?

Praxen and Observra are open-source tools from Exabeam, the publisher of The New CISO.

To give some background, Praxen came from conversations at a security conference. We wanted to build something free that gives you an overview of your remit, aligns feedback to the OWASP Top 10 for LLMs, and provides a human-readable visual on how to make your code better. It helps you verify and improve your code pre-production by flagging issues like policy divergence and credential exposure. There’s also Observra, a runtime agent for observing telemetry and analyzing behavior as it’s running.

Steve Moore

There are two questions: was it a heavy lift to run, and is it a heavy lift to remediate? It’s painless, fast, and super simple to run. Remediation depends on the standard you’re trying to hit.

Sherri Douville

Steve Wilson from Exabeam is the chair of AI Security with us at TTIC.

Sherri Douville

Why does architecture-first implementation matter for agentic systems?

The aspect of architecture upfront is important. We used the six layers of the Indiana Executive Council on Cybersecurity’s AI Security System Architecture Layers framework. Praxen assesses whether those controls are in place. You need a framework to tell you where to put the controls, and you need a structure the executive team understands. Observra then addresses that sixth layer, which is continuous monitoring.

Sherri Douville

What are the downstream clinical consequences of technology outages?

In the conversation, Sherri Douville connects incident response and infrastructure reliability to downstream clinical delays, accumulated work, communication problems, and patient-safety consequences.

I want to see IEEE/UL 2933 implemented across infrastructure providers, because I believe it would lead to fewer outages. When outages happen in healthcare, it’s really hard on clinicians. They lose access to records, and this can persist for hours or days. People think it’s just a patient safety problem for that hour, but it’s actually a long tail of delays, challenges, and miscommunications for the next 14 to 20 days. It’s a huge problem for doctors and patients.

Sherri Douville

What should CISOs do differently as AI and agents move into production?

When I hire a CISO, I’ll be expecting them to take ownership. I don’t want them sending me reports that just generate another meeting. I want them to make the problem go away.

Sherri Douville

CISOs have a huge opportunity to help create more efficiency and safety. The thing they can do on Monday is to think more strategically. If they were thinking about what they knew, they should add what judgment they are bringing. If they were identifying problems, they should think about determining the action. If they were providing recommendations, they need to think about what the implementation sounds like. If they were assessing tools, they need to get into the game of using and verifying them—maybe run Praxen themselves.

Sherri Douville

Transcript

Transcript courtesy of Exabeam, from The New CISO, Episode 150, “The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools.”

Edited for accuracy and clarity from Exabeam’s published transcript. Edits are limited to Sherri Douville’s own statements.

Host: Steve Moore | Guest: Sherri Douville, CEO & Architect, Medigram; Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC)

Steve Moore: Sherri, thank you so much for being here. For the listener, this show is going to be a little bit different. We’ve got a different guest, which I hope you’ll really enjoy. We have a lot to talk about around the world of AI, open-source controls, and being a friend of the CISO. Sherri, who are you and what do you do?

Sherri Douville: Thank you so much. I’m honored to be here, Steve. I’m Sherri Douville, the CEO and architect of Medigram. I’m also the chair of the Trustworthy Technology & Innovation Consortium (TTIC). Medigram builds and operates Darwin, a governed AI decision platform. We have an agentic fleet running in production. What Darwin does is produce a sealed governance record at the moment of every agent action. I think that’s why we’re here, because I have experiences with some tools that we’re going to talk about.

Steve Moore: Just for fun, because it was in your introduction, what exactly do you mean by a “sealed governance record”?

Sherri Douville: We focus on high-reliability industries like pro sports and healthcare. They need to have a record of what happened, when it happened, why it happened, and who was involved. That’s what we provide.

Steve Moore: It’s much like a police investigation, figuring out all the elements of an event. It’s about the provability around a set of events, non-repudiation, and having a digital chain of custody to show that no changes occurred.

Sherri Douville: Exactly. It’s the defensible, auditable record that they can provide to counsel, a court, an insurer, or a credit rating agency for financial and legal purposes.

Steve Moore: When there is a problem, they can show it as evidence. It’s supremely important. That connects back into an open-source project that Exabeam is leading and that you’re involved with. Before we hit on that, you mentioned TTIC. At a very high level, what is that organization, what does it do, and why does it exist?

Sherri Douville: TTIC is an independent governance body. Medigram is the company I run, which is a commercial implementation of the governance work we do, and they are separate by design. My background spans mobile security, quant analysis, financial markets, and standards development for clinical AI governance. I co-chair the Trust and Identity Subgroup of IEEE/UL 2933, the standard for clinical IoT data and device interoperability with TIPPSS: Trust, Identity, Privacy, Protection, Safety, and Security.

TTIC was stood up by myself and Mitch Parker, CISO at IU Health. IEEE is an incredible organization, and we built this standard for clinical IoT device and data interoperability. However, to get it adopted and maintained in an industry like healthcare, you need many stakeholders involved. TTIC was created to bring together CIOs, CISOs, physicians, engineers, and everyone necessary to do that work.

Steve Moore: What has been the most difficult part of standing that up?

Sherri Douville: That is a very good question. The hardest part has probably been negotiating with other bodies in the market. The space of AI and IT in high-reliability industries is incredibly complex and political. There are a lot of turf wars. Negotiating those relationships and helping people feel comfortable that we aren’t stepping on anyone’s territory has been challenging. Establishing that clearly took a lot of effort and personal time.

Steve Moore: In our earlier conversation, you noted that you were really good at helping CISOs make security cool, integrate with the business, and sneak security into the business. I find all that fascinating. When you said those things, what do you mean and what advice do you have for the CISO interested in this universe of technology and problems?

Sherri Douville: I’ve been coached and guided by a lot of CISOs in this journey. What I’ve been helping them with is getting them onto stages they wouldn’t have gotten on in the past—in front of physician health system leadership, getting them onto healthcare podcasts, getting them published in books, and giving them a broader leadership persona.

When I say making them cool, I mean giving them more visibility and encouraging a different kind of executive presence. The reason it’s important, especially in healthcare, is that everything is about trust. The best CISOs are stewards of trust. In the tech industry, trust can sometimes be off to the side, but in healthcare, it’s the core of the business. It’s nice to see that the whole world, with AI and agents, is now moving towards trust. CISOs have the opportunity to be the stewards of that trust, and that’s how they can become the rock stars of the C-suite.

Steve Moore: AI commands all this attention, from Wall Street to Hacker News. There is a lot of distrust or at least concern, but also equal excitement about the great advancements, like in radiology or gene editing. There’s this great upside, but also a great problem source. Many organizations are even treating AI like an insider threat. Trust is in the middle. If the CISO is the vehicle of trust, where do you think they struggle most right now? What skills do they need to work on?

Sherri Douville: I’m so glad you asked. The game has radically changed, and CISOs have a great opportunity to play this new game. They spent years defending the fact that cybersecurity should even be at the executive table. Now that they have a seat with the CEO, CFO, and general counsel, they are competing for scarce enterprise resources. The problem with AI is it’s a game of “more.” But more is not better; better is better.

If the CISO can be that voice of trust and quality, they can solve issues instead of just creating more reports and coordination overhead. When I hire a CISO, I’ll be expecting them to take ownership. I don’t want them sending me reports that just generate another meeting. I want them to make the problem go away.

Steve Moore: I just sat down with a prominent CISO who is as sharp as it gets. His take on AI is that it’s like a curious seven-year-old with a gun. There’s this desire to please and a mission focus that will not sleep and can cause other problems. He’s saying that ownership is still by committee right now, and everyone’s figuring out how to manage this tactically. There are cracks in the foundation because most AI has shown up from the bottom up, not top-down.

Sherri Douville: I want to push back on that framing. My analogy is that AI is a gifted teenager. They have very specific talents and drawbacks. They can do a lot, but they consume a lot of resources and need a lot of direction and coaching. This is why all of us executives need to change our mindset to be more like player-coaches. It’s not about being cool because we don’t have to get our hands dirty anymore; it’s about being cool because we’re still fit enough to do the work.

As a country and as a company, we need to succeed with AI. Leaders should be thinking about what they are doing to help move that forward. That’s why the seven-year-old analogy didn’t work for me.

Steve Moore: You said it’s cool because we are “still fit enough to do the work,” alluding to hands-on technical work. Is that what you meant?

Sherri Douville: It can be different depending on the role. I’m not expecting a doctor or CFO to be coding, but they will be verifying AI output. I try to teach people discipline—let’s talk about constraints, errors, handoffs, and documentation. Let’s talk about how the work actually gets done. CISOs have often been allowed to be consulting advisors. For a lot of boards and CEOs, that’s not working anymore, especially with AI. They need to roll up their sleeves and get on the court.

Steve Moore: That’s a recurring theme on the show. You mentioned the CISO being a “consulting advisor,” just relaying problems or numbers. I do see that. The only pushback might be that CISOs are often asked to create those reports because they don’t own the thing they are analyzing, like innovation or AI. But your point is well made: jump in, have some discipline, and get answers.

Sherri Douville: From a CEO and board perspective, that’s important. The consulting industry is transforming rapidly because many of those artifacts can now be produced by AI. The scarcity structure of expertise is changing. AI is reducing the value of expert analysis but increasing the value of something more mentally athletic. That formula is: judgment, authority, execution, verification, organizational integration, and ownership of the security outcome. Can I count on you, the CISO, to make that security problem disappear? Can you reduce my exposure? Can you produce the evidence that the issue was solved without creating another coordination burden for me? Many security executives might not realize that if their analysis still has to be processed by management, and AI can provide that analysis, their value is diminished.

Steve Moore: Starting with judgment and authority, could you run through those again?

Sherri Douville: Judgment, authority, execution, verification, organizational integration, and ownership of the outcome—the security outcome.

Steve Moore: What was the genesis of that framework?

Sherri Douville: This conversation with you and the last one we had. It’s a derivative of our conversations.

Steve Moore: So those six points and asking yourself if you are a “coordination burden” is a key takeaway. You wrote an article about this CISO role change, using a basketball analogy. What more can you say about that?

Sherri Douville: The CISO needs to be more like a defensive captain than an analyst, bringing the whole defensive team to the next level. They need to be able to go onto the court, not just coach from the sideline. That worked in a certain context, but not anymore. You need to have “selective depth”—selectively go deep to understand the work, even if you aren’t doing the security AI engineer’s job. If you don’t understand it, you need to get on top of it as quickly as possible.

Steve Moore: I think being active is the key takeaway. In your writing, you noted, “Configuration has stopped predicting behavior. That single fact has changed what the job is, what it costs, and what a CISO has to do personally… In agentic environments, the systems are immature, the abstractions are unreliable, and the consequences of subtle errors are high.” This sets the tone for the open-source work you are doing.

Sherri Douville: To understand how I got involved with open source, you need the context of TTIC. The challenge is that all the compliance frameworks don’t do the job of risk management for AI because of its probabilistic nature. Our systems haven’t caught up, which is why these open-source tools are so valuable. Steve Wilson from Exabeam is the chair of AI Security with us at TTIC. We implement IEEE/UL 2933, and we were able to use Praxen.

Steve Moore: To give some background, Praxen came from conversations at a security conference. We wanted to build something free that gives you an overview of your remit, aligns feedback to the OWASP Top 10 for LLMs, and provides a human-readable visual on how to make your code better. It helps you verify and improve your code pre-production by flagging issues like policy divergence and credential exposure. There’s also Observra, a runtime agent for observing telemetry and analyzing behavior as it’s running.

Sherri Douville: My experience using Praxen is that it gives code-specific feedback on how to improve your score, which I didn’t know about before I used it. Having a strong architecture from the IEEE standard gave us a clear remit. We ran it three times and were able to get the highest governance score recorded on Praxen as of July 2026, with zero open findings across critical, high, and medium categories. As someone building a system where the value proposition is trust, being able to develop a capability like that internally with this easy-to-use tool is super valuable.

Steve Moore: Was this a heavy lift to implement? If someone is at zero and wants to do a code-level assessment, is it easy to utilize?

Sherri Douville: There are two questions: was it a heavy lift to run, and is it a heavy lift to remediate? It’s painless, fast, and super simple to run. Remediation depends on the standard you’re trying to hit. The aspect of architecture upfront is important. We used the six layers of the Indiana Executive Council on Cybersecurity’s AI Security System Architecture Layers framework. Praxen assesses whether those controls are in place. You need a framework to tell you where to put the controls, and you need a structure the executive team understands. Observra then addresses that sixth layer, which is continuous monitoring.

Steve Moore: The telemetry piece is different because as the world interacts with your agent, it generates enriched, human-readable logging events—the kinds of things you would want to know.

Sherri Douville: Exactly. And Praxen measures six behavioral categories based on OWASP: defined scope, knowledge base, treating every input as potentially hostile, controlling dependencies, adversarial probing, and tracking behavior after deployment. That’s the basis for the score, and it helps the industry understand what “good” looks like. Not getting behind the concept of evidence is what’s really held back technology from connecting with industries like medicine and aviation.

Steve Moore: Even with all this diligence, you can still have an ongoing issue. Configuration has stopped predicting behavior. What are your thoughts on incident response in this new world, especially in healthcare where rules are tight?

Sherri Douville: Cascading failures in agents are a real risk. We have to prepare for the worst. One way I do that is by building with a highly disciplined architecture first. But you also have to have incident response on the back end. I want to see IEEE/UL 2933 implemented across infrastructure providers, because I believe it would lead to fewer outages. When outages happen in healthcare, it’s really hard on clinicians. They lose access to records, and this can persist for hours or days. People think it’s just a patient safety problem for that hour, but it’s actually a long tail of delays, challenges, and miscommunications for the next 14 to 20 days. It’s a huge problem for doctors and patients. The human element is why it’s so important to address incident response.

Steve Moore: It’s catastrophic. You add another opportunity for good, but if not set up correctly, it could be another vehicle for erosion of trust, outage, or breach. Anything you’d like to close on?

Sherri Douville: CISOs have a huge opportunity to help create more efficiency and safety. The thing they can do on Monday is to think more strategically. If they were thinking about what they knew, they should add what judgment they are bringing. If they were identifying problems, they should think about determining the action. If they were providing recommendations, they need to think about what the implementation sounds like. If they were assessing tools, they need to get into the game of using and verifying them—maybe run Praxen themselves. I want to encourage them to think about what it means to get into this game and play at their best.

Steve Moore: Sherri, thank you so much for all your time and thoughts. And for those listening, the closing advice is to get in the game. Thank you so much.

Sherri Douville: Thank you. Thank you so much.

Listen to the full episode on Exabeam →


Host

Steve Moore, The New CISO (Exabeam)

Guest

Sherri Douville, CEO and Architect, Medigram

Organizations

Medigram and the Trustworthy Technology & Innovation Consortium (TTIC) are separate organizations. Medigram's CEO founded and chairs TTIC; TTIC maintains independent governance, standards, and decision-making boundaries.

Published September 22, 2026 · Last updated September 22, 2026