org.tech / Approach / Engagement path Six stages. Approach · 02

Nothing here is released by a calendar. Every stage is released by the evidence the one before it produced.

Every step is a gate, not a date.

A gate is a question that must be answered yes, not a date that must pass. Six of them stand between a first conversation and an organization whose own people are building governed capabilities on a platform it owns. Each one names the question, and the person who answers it.

Why a gate beats a timeline.

THE RULE · 01

Plans made of dates fail quietly. The date arrives, the thing is not ready, and because the plan has momentum it moves anyway. Plans made of gates fail loudly and early, which is the cheap kind of failure. A stage that cannot answer its question is a stage that has told you something worth knowing.

This also bounds your exposure without any financial theatre. You are never committing to the whole path. You are committing to the next stage, on the evidence the previous one produced, with the option to stop holding whatever the earlier stages already delivered.

Running at every deployment
Built, first client use under way
Scoped per deliverable

A gate is a question that must be answered yes, not a date that must pass.The rule the whole path is built on

Six stages, six questions.

THE PATH · 02
  1. 01Bounded

    Strategic assessment

    A bounded review of where governed AI would create value in your organization and what is currently blocking it. We walk the security posture questionnaire with you rather than at you, so the residency, retention and control questions are answered in writing before anyone designs anything.

    You keep the deliverable whether or not you go further: a data-flow and topology picture of how a deployment would sit in your environment, a recommended posture tier with any overrides written down and reasoned, and a short list of the first capabilities worth building. What is in it.

    Gate
    Does governed AI create enough value here to be worth doing, and can this organization name the owners the work will need?
    Decides: your executive sponsor
  2. 02Your account

    Deployment into an account you own

    You hold the account, the root credentials and the billing relationship with your cloud provider. We deploy into it from a tagged release and a clean checkout, with the posture you approved committed as a typed object that drives both the infrastructure and the plan page you see inside the product. A test fails the build if those two ever disagree.

    What lands: a dashboard branded as yours, governed model access with the content policy mandatory on every call, administration for users, roles, grants and quotas, and the module runtime. Layer by layer.

    Gate
    Does the deployed state match the posture that was approved, and does your security owner accept the resolved controls together with their standing exceptions?
    Decides: your security owner, with us
  3. 03Small group

    A bounded first use

    A handful of named people, non-sensitive material, real work. General chat over the models your posture allows, with per-person quotas that fail closed, and usage visible per person from the first day. If the knowledge base is switched on, it is loaded only with documents every user of the deployment may read.

    This stage exists to produce evidence, not enthusiasm. It is also where people discover which of their questions a model answers well and which it should never have been asked. Chat and knowledge, with its limits.

    Gate
    Did a small group get answers they could act on, from material everyone in the deployment may see, inside the quotas you set?
    Decides: the operating sponsor and the first users
  4. 04Managed ops

    Wider rollout on managed operations

    Roles become identity groups with grants your administrator edits at runtime, no redeploy. Quotas go per person. The audit record starts carrying the things you will later be asked about, including an administrator reading someone's transcript, which is itself written to the record.

    Managed operations begin at the same moment: releases cut and rolled one deployment at a time, drift and diff checks before changes, acceptance scripts run against the live deployment over HTTPS afterwards, the model catalogue refreshed as the provider changes it, cost watch with budget alarms, a dated operations journal, and a direct line to the person who built it. What $500 a month covers.

    Gate
    Can your administrator run it without us in the room, and does the audit record show what you expected it to show?
    Decides: your administrator and IT owner
  5. 05Per deliverable

    Capabilities, one deliverable at a time

    The slower and more valuable work. We sit inside a process, learn its handoffs, approvals, exceptions and data sources, and productionize the highest-value parts as governed capabilities on the platform you already own. Each one is scoped, priced and accepted on its own.

    Deterministic work stays deterministic: several of the capabilities that get built this way never call a model at all. That is a design decision, not a shortfall. Where AI does not belong.

    Gate
    Is the outcome one you defined rather than one we assumed, is the part that must be exactly right deterministic, and did the last capability earn this one?
    Decides: executive sponsor and finance owner, monthly
  6. 06Pilot

    Your own people authoring modules

    The authoring kit, a scaffold that produces a working module from one command, a validator that refuses anything outside the contract and names the file and the fix, and a publish path that reaches the staging channel only. Promotion to production is a named administrator approving the exact artifact by hash. Our own automation cannot promote.

    The path is proven end to end by us acting as the client, and the first client-authored build is a pilot. The authoring kit and the promotion path.

    Gate
    Is the validator clean, and will a named administrator approve the exact artifact hash that was reviewed?
    Decides: your administrator

Two administrators approve a promotion. A deployment with a single administrator can self-approve with a written justification, recorded as exactly that. We do not call that segregation of duties, because it is not.

Evidence, not enthusiasm.

WHAT RELEASES A STAGE · 03
Bounded exposure with stage gates

Each stage is released on evidence from the one before it.

Finance owners have seen enough business cases built on assumptions to distrust the genre, and they are right to. So we do not ask for a number that models three years of value. We ask for the next stage, against evidence that already exists.

  • 01
    Deployment evidence is mechanical. The build fails if the plan page and the infrastructure disagree, and the factory refuses a tag that is not on the mainline or a tree that is not clean.
  • 02
    Post-deploy evidence is adversarial. Acceptance scripts exercise the real deployment over HTTPS and each hostile case must be refused, not merely handled.
  • 03
    Use evidence is yours. Per-person metering settled against the provider's own record of each call, and usage by person in the administration area.
acceptance · post-deploy
RUNNING
orgos accept --deployment your-org --over https
[accept] release tag on mainline, tree clean
Replayed access ticket✓ refused
Forged session cookie✓ refused
Module session at another module's host✓ refused
Corrupted upload✓ refused
Inference without the content policy✓ denied by cloud policy
Plan page vs deployed posture• reconciled
Gate 02 evidence recorded · your security owner decides
Illustrative outputexit 0
Each hostile case must be refused·Not merely handled

Four names, not four committees.

WHAT YOU BRING · 04

The most common reason an engagement stalls is not technical. It is that no single person is accountable for a decision the path needs, so the decision is taken by nobody and revisited by everybody. We ask for four names at the assessment, and an organization that cannot supply them is telling us something useful.

A

Executive sponsor.

Owns the decision to proceed at each gate and the outcome the work is aimed at. Not a steering group.

B

Security owner.

Accepts the resolved posture and its standing exceptions, and holds the veto. Involved from stage one, never presented with a finished system.

C

Content owner.

Decides what may be loaded and keeps it current. Knowledge quality is not something a supplier can own on your behalf.

D

Administrator.

Runs roles, grants, quotas and promotions inside the product. This is the person who has to be comfortable, because the system answers to them.

Who decides what, in writing

The split between what we are accountable for and what you are is set out before anything is deployed, not argued about afterwards. Shared responsibility.

Priced by stage, invoiced by milestone.

WHAT EACH STEP COSTS · 05
01
Strategic assessment
$2,500once

Bounded. You keep the deliverable whether or not you proceed to a deployment.

Gate 01
02
Deployment
$2,500from

Typically lands around $5,000 once the solutions pipeline is scoped. Milestone invoicing, nothing at signing.

Gates 02 and 03
03
Managed operations
$500per month

Cancel anytime. You lose us, not the platform, because the platform is in your account.

Gate 04 onward
The two lines without a number

Enterprise automation and forward-deployed engineering are scoped per deliverable. Longer engagements are priced in the range of one junior technical hire, without the permanent headcount. Compute is billed by your cloud provider directly to you, at their list price. We never sit between you and the compute bill, so there is nothing there for us to mark up. The whole price list and what we have seen compute actually cost.

Three refusals, stated up front.

WHAT WE WILL NOT DO · 06
01

Skip the security owner.

We will not run a deployment past the person who holds the veto and present it to them finished. It is the fastest way to a system nobody will sign for, and it wastes the one advantage this architecture has, which is that it survives being examined.

Stage oneNon-negotiable
02

Start with your most sensitive material.

The first bounded use runs on material everyone in the deployment may see. Not because the controls are weak: retrieval today carries no per-document permissions, so what you choose to load is the control, and stage three is where that choice is made deliberately.

Stage threeStated limit
03

Promise a date.

You get a sequence, the question each stage has to answer, and the person who answers it. A stage is released by the evidence the one before it produced, which is a harder commitment to make than a calendar and a much more useful one to hold a supplier to.

Every stageGates, not dates
01Can we stop after the assessment?

Yes, and some do. The assessment is bounded and the deliverable is yours: the topology and data-flow picture, the posture recommendation with its overrides, and the capability shortlist. Several of those are useful even if you deploy nothing, or deploy something else.

02What if a gate fails?

Then the stage has done its job. Usually it means one of three things: the value is thinner than it looked, an owner cannot be named, or a control the security owner needs is on a higher posture tier than the one you costed. All three are cheaper to find at that gate than two stages later. Posture tiers.

03Who actually does the work?

A founder-led practice with a small bench of contractors, working against a deployment factory rather than a blank page. That is said plainly because you should size your expectations on it: you get a principal who has built the thing, not an account manager and a rotating team. About us.

04Does managed operations include support at any hour?

Managed operations is deliberate work on your deployment: releases cut and rolled one deployment at a time, drift and difference checks before a change, acceptance runs against the live deployment afterwards, the model catalogue refreshed as the provider changes it, cost watch with budget alarms, a dated operations journal, and a direct line to the person who built the system, with no queue in front of it. We publish no response-time commitment.

05Can we bring our own engineers into this?

That is the point of stage six, and it is the stage we most want to reach. Your people author modules with the same kit we use, validated locally and re-validated server-side against the exact uploaded bytes, admitted only to what their manifest declared. Today that is in pilot.

⎯⎯ Book the strategic assessment ⎯⎯

Your private AI, inside your control ·

Stage one is bounded, costs $2,500, and ends with a document you keep whichever way the first gate goes.