A bundled copilot disappointed.
It was already paid for, it was switched on, and the work people actually do did not change. The question underneath is whether the tool was wrong or the capability was never defined.
Before anybody deploys anything, a written answer to a harder question: should you, and if so, what first.
This is the only way an engagement starts, and it is deliberately small. You are buying an outside read on your own environment: where your data goes today, what a governed AI capability would be worth, what would block it, and what it would cost to run. If the honest answer is that you do not need us, the assessment says so and you still keep it.
Almost nobody books this because they woke up wanting private AI. They book it because something specific went wrong, and the organization is now stuck between two people who both have a point. The security owner carries the risk if they say yes. The operating owner carries the cost of saying no. That standoff is what the assessment is built to break, by replacing opinion about the data path with a written map of it.
It was already paid for, it was switched on, and the work people actually do did not change. The question underneath is whether the tool was wrong or the capability was never defined.
It worked in a notebook. Then cost moved unpredictably, quality drifted, and nobody owned it. Usually the gap is not the model: it is that there was no environment to put it in.
The data flow could not be scoped, so the answer was no. The work carried on anyway, in browser tabs, with no governance at all. That is the most expensive outcome of the three.
The assessment is a working session, not a presentation. The timings below are what we typically see rather than a commitment to a date.
What prompted this, who is pushing, who is blocking, and what would count as a good outcome twelve months from now. We ask for the outcome in your words, not in ours, because the measure has to reflect what an executive here actually optimizes: delivery time for one, errors or risk or frustration for another.
Your systems of record, where the documents live, who can already see what, how identity works, what is in the cloud and what is not. Then the uncomfortable half: which AI tools your people are using today, on what data, under whose account. Shadow use is not a scandal here, it is an input.
We walk the security posture questionnaire with you: residency, encryption, identity and access, audit and logging, network, operational requirements, and what your compliance program actually needs. It is published in advance on purpose, so you can read every question before the call.
We write it up and walk you through it. It names what we would do, in what order, at what running cost, and what we would not do. Where the honest recommendation is to wait, to fix something else first, or to buy the smaller product, it says that instead.
The deliverable is useful to you even if you never speak to us again. The environment map alone answers most of what a customer's vendor questionnaire asks about your data flows.
An assessment with only one of these in the room produces a document the other two will not accept. Moving the date beats running it short-handed, and we will say so when the invitation list looks thin.
Whoever can say no and make it stick: a security lead, a privacy officer, sometimes the CFO in a smaller firm. They answer for residency, retention, identity and what is acceptable to a customer's vendor review. They are also the person the questionnaire is written for.
The person accountable for the work that would change: operations, a business unit, the founder. They define what a good outcome is and supply the baseline it is measured against. Without them the shortlist is guesswork dressed as a roadmap.
The person who will actually live with the environment: cloud accounts, identity, DNS, certificates, the existing systems it has to sit beside. They tell us what is really there, as opposed to what the architecture diagram says is there.
A data or content owner, if the first capability touches a document set, and a finance owner if the cost estimate needs to be believed by someone other than the person who commissioned it. Where your organization has outside counsel or a privacy advisor, we are glad to have them read the output; see policy advisory for how we work alongside them.
| Sometimes assumed | What this actually is | Why |
|---|---|---|
| A sales demo | ✕No | The live product is at the demo, free, and does not need an invoice attached. The assessment is time spent on your environment, not ours. |
| A free audit | ✕No | It is paid because it is real work with a real deliverable, and because free discovery is how consultancies recover the cost in the next invoice instead. |
| A security audit or penetration test | ✕No | We map data flows relevant to an AI capability. We do not test your existing systems, and we will tell you when what you need is a different specialist. |
| A commitment to deploy | ✕No | There is no follow-on obligation in either direction. The engagement path treats each step as a gate for exactly this reason. |
| A document that hedges | ✓It takes a position | A recommendation that could not have been no is not a recommendation. Ours names what we would do, in what order, and what we would refuse to do. |
The assessment is bounded in scope, not in candour: everything we find that bears on the decision goes in the document, including findings that are inconvenient for us.
Then it says so, you keep the document, and we part on good terms. That outcome is not a failure of the assessment, it is the assessment working. The two most common versions are "fix the data situation first" and "you need the gateway rather than the platform", and both save you more money than the fee.
The assessment is priced and delivered as its own piece of work: $2,500, bounded, with a deliverable you keep. Deployment is quoted separately from $2,500 and typically lands around $5,000 once the solutions pipeline is scoped, with milestone invoicing and nothing at signing. What the assessment buys you commercially is a scope that is real, so the deployment quote is not a guess.
Less than you think, and the useful preparation is human rather than documentary: agreeing internally what outcome you are chasing, and being willing to say out loud which AI tools are already in use. Assessment prep lists the artifacts worth having to hand, all of which are optional.
Yes. We also publish the questionnaire we will walk you through, the limits we do not claim past, and the fact that we hold no third-party attestation, so most of what a vendor form is trying to discover is already on this site before you ask.
Samuel Hebeisen, the founder, runs the assessment. org.tech is a small senior practice: about twenty years in software development leadership, the last three concentrated on AI implementation, with cloud solutions architect certifications at associate and professional level. There is no junior team behind a name on a proposal.
Yes, and most are. The walkthrough works over a screen share as long as the three owners are actually present. On-site is possible where the systems or the people make it worthwhile, and we will say which we think is better once we know what we are looking at.
One bounded piece of work, $2,500, with a written deliverable you keep and a recommendation that is allowed to be no.