# Audience personas

Five personas, from the boardroom to the build team. The same core idea lands
differently with each - the discipline is rewriting the frame, not the
salutation. A CEO and a chief engineer should be able to compare their emails
from the same campaign and recognise the same firm, but not the same email.

Common ground across all five: they are senior, time-poor, and fluent at
detecting marketing. All of them respond to specificity and a genuine point of
view. None of them respond to enthusiasm.

---

## CEO

**Who they are.** Accountable for the whole institution. Reads email on a phone
between meetings; gives an unknown sender one line, a known one perhaps four.
Technology reaches them only as strategy, risk, or money.

**What they care about.** Board accountability, regulatory exposure, customer
trust as a franchise asset, cost of getting a strategic call wrong or late.
They think in comparisons with peers: what are the other majors doing, what
will APRA expect, what would the AFR write.

**What convinces.** A consequence stated plainly, early. A question their board
will ask them before they have an answer. Evidence that the sender advises
people like them. Brevity as a mark of respect.

**What loses them.** Product features, architecture, acronyms without immediate
translation, anything that reads like it was sent to ten thousand people.

**Register.** Peer-to-peer, almost terse. 80-150 words. Standards and
regulations by consequence, not by number ("APRA's new operational risk
standard" over a bare "CPS 230" - or give the number once, with its meaning).
CTA: a conversation - a briefing, a call, fifteen minutes. Never a webinar.

**Subject lines that fit:** "Who answers when an AI agent moves money?" /
"The identity question in your next board pack"

---

## CIO

**Who they are.** Owns the technology estate and its budget. Judged on delivery,
resilience, and cost. Permanently managing a queue of vendors who all claim to
simplify things.

**What they care about.** Whether a capability decision now saves or creates
work later. Consolidation over addition. Regulatory deadlines as delivery
dates. What their architects will say when asked "can we actually do this".

**What convinces.** A delivery-shaped argument: sequence, dependency, effort.
Honest acknowledgment of migration cost. Evidence from comparable institutions.
A view on build-versus-buy that isn't self-serving - or admits where it is.

**What loses them.** Vision without a path. "Digital transformation" framing.
Pretending integration is free.

**Register.** Businesslike, concrete. 120-200 words. Standards named plainly
with a clause on what they mean for the estate. CTA: a briefing, an assessment,
a paper with substance.

**Subject lines that fit:** "CDR compliance is becoming an architecture
decision" / "Before you renew the IAM contract"

---

## CISO

**Who they are.** Carries the risk the CEO reads about. Answers to the board
risk committee and, in Australia, increasingly directly to APRA. Professionally
sceptical - security marketing has trained them to discount claims by default.

**What they care about.** Threat reality versus vendor theatre. Control
evidence they can put in front of an auditor. CPS 234, CPS 230, the Privacy Act
reforms, incident reporting obligations. Being told about a gap before the
regulator or the attacker finds it.

**What convinces.** Precision about the actual failure mode. Regulation cited
by clause and consequence. A sender who clearly understands assurance, not just
security. Acknowledgment of what's hard.

**What loses them.** Fear-mongering, breach-porn statistics without relevance,
"military-grade" anything, being sold to during an incident news cycle.

**Register.** Sober, precise, slightly formal. 120-200 words. CTA: a workshop,
a readiness review, a technical note - things that produce evidence.

**Subject lines that fit:** "CPS 230 and the third-party identity gap" /
"What your board will ask about agent credentials"

---

## Chief / enterprise architect

**Who they are.** The institution's long-memory. Has seen three IAM programmes
and remembers why the second one failed. Reads standards documents for
pleasure, or at least without complaint. Often the real decision-maker behind
a CIO's signature.

**What they care about.** Interoperability, standards trajectory (FAPI 2.0,
OpenID Federation, verifiable credentials, BIAN service landscapes), pattern
reuse, avoiding bespoke anything. Whether a vendor's "open" is actually open.
The ten-year consequence of a two-year decision.

**What convinces.** Technical depth worn lightly - name the spec, the version,
the working group if it matters. A genuinely useful distinction they can reuse
in their own diagrams. Respect: assume they know the basics, skip the primer.

**What loses them.** Marketing abstraction of things they understand precisely.
Getting a standard's name or status wrong - one error and the sender is
discounted permanently.

**Register.** Collegial, precise, allowed to be denser. 150-250 words. CTA:
a webinar, a working session, a reference architecture, the spec itself.

**Subject lines that fit:** "FAPI 2.0 changes the CDR conversation" /
"Where agent identity fits in the BIAN landscape"

---

## Chief engineer

**Who they are.** Owns making it actually work: the platform teams, the
integration surface, the on-call roster. The person who inherits every
optimistic architecture decision.

**What they care about.** Implementation effort measured honestly. Developer
experience, SDK and API quality, operational behaviour under failure. What
breaks during migration. Documentation that exists.

**What convinces.** Concrete implementation detail - an endpoint, a flow, a
before/after. Honest "this part is annoying". Working examples over
whitepapers. A sender who has clearly built the thing, not just diagrammed it.

**What loses them.** Vision statements, business-value framing, anything a
build team would call hand-waving.

**Register.** Direct, informal end of professional, technical. 150-250 words.
CTA: a demo, a sandbox, a repo, a hands-on session.

**Subject lines that fit:** "Token exchange without the bespoke middleware" /
"What CIBA actually looks like in production"
