Chris Watkins

About

I'm Chris Watkins.
I build as Bingo Codes.

I spent more than twelve years operating and securing production environments — threat detection, hunting, incident response, security automation, cloud security, SIEM, SOAR, XDR, and healthcare security. I built detection logic, automated response pipelines, and helped teams make sense of what was happening inside complex systems under pressure.

Today I apply that to one problem: helping healthcare organizations securely deploy AI and autonomous systems — especially across Microsoft cloud. Copilot, agents, Entra, Purview, Azure, identity, data protection, and incident response. Same ops discipline. New surface.

The arc

From the SOC to the stack.

Security operations and securing AI systems look like different fields until you understand what good security ops actually requires. A SOC analyst who's doing the job well isn't just watching dashboards. They're defining what normal looks like, setting gates for what should trigger a response, observing what's actually happening in the system, and owning what ships out the other side. They're governing autonomous behavior in high-stakes environments.

That's exactly the job when healthcare turns on Copilot and agents inside a Microsoft tenant that already holds PHI. The threat model is different. The vocabulary is different. But the underlying discipline (define intent clearly, set guardrails deliberately, observe continuously, own every outcome) is the same.

Applying ops to the AI layer is less of a leap than it looks. Most of the instincts that make for a good security engineer make for a good AI security practitioner: skepticism about what a system claims to be doing, attention to failure modes, respect for the humans at the other end of the decisions. I'm bringing all of it.

"The discipline of security operations (defining intent, governing systems, setting gates, observing outcomes, owning what ships) is exactly the mindset healthcare AI security demands."

What I'm building

The work.

Melanin Map is the one shipped product — proof I build. Kelpie is in design: Healthcare AI Exposure Management for Microsoft. Djembe is the company, not a product. You can follow the full process on the Building in Public page.

The show

AI in Living Color

A weekly roundup of what actually matters in AI and agentic engineering, cutting through the noise, plus a monthly deep-dive series built for people starting from zero. Honest, practical, and in plain language. You can hear a sneak peek on the Podcast page.

Build in public

Raw, honest, open.

I document the real process. Not the polished retrospective. The actual work as it happens. What I tried, what broke, what I had to unlearn, what clicked. If something didn't work, I'll say so. If I don't know something yet, I'll say that too.

Part of why I build in public is to give back to the industry for free. Security got me here. A lot of people shared knowledge openly so I could learn the craft, and I want to do the same for whoever comes behind me. Everything I figure out is documented and available: the wins, the dead ends, and the real cost of building something from scratch.

If you're following along, welcome. If you're securing Microsoft AI in healthcare, or building something adjacent, I want to hear what you're working on.