Three stages. Most engagements start at the first.
The stages are sequential and independent. An assessment is a complete deliverable on its own, and so is an implementation. Most organizations find that each stage earns the next.
Assessment
Timeframe: one to two weeks. Size: focused, fixed-scope engagement.
The entry point. We audit the organization's current and planned AI usage, identify the risks and the opportunities, map existing processes to the six-layer model, and deliver a prioritized roadmap.
Scope
- Stakeholder interviews across IT, operations, compliance, and end users
- Current AI usage inventory: which tools, used by whom, for what
- Risk assessment: data exposure, compliance gaps, ungoverned usage patterns
- Process mapping for high-value AI automation candidates
- Six-layer gap analysis with prioritized recommendations
- Executive summary and detailed roadmap document
Implementation
Timeframe: four to eight weeks per engagement. Size: project-based, scoped to the roadmap the assessment produced.
Build out the governance layer. Custom guardrails for the organization's industry. Workflows for its specific processes. Domain knowledge packaged for its business context. Observability infrastructure for compliance.
Scope
- Guardrail definition and implementation: block rules, approval gates, escalation paths
- Workflow design and automation for three to five core business processes
- Domain knowledge packaging: policies, procedures, regulatory context
- Observability and audit trail infrastructure
- Memory system for institutional knowledge persistence
- Identity and role configuration for each AI agent context
- Team training on framework operation and maintenance
- Documentation and runbooks for internal operators
Managed Operations
Timeframe: ongoing. Size: monthly retainer.
AI platforms change constantly. New model releases break workflows. Regulations shift. Domain knowledge ages. Most organizations will not staff this internally for years. Managed Operations is how the governance layer stays current without adding a full-time hire.
Scope
- Monthly audit log review and compliance reporting
- Workflow optimization based on usage patterns and performance data
- Domain knowledge updates as policies and regulations change
- Model migration support when clients upgrade or switch AI providers
- Guardrail tuning based on incident reports and near-misses
- Quarterly business review with ROI analysis
What you walk away with at each stage
| Stage | Timeframe | You walk away with |
|---|---|---|
| Assessment | 1-2 weeks | A readiness report and prioritized roadmap |
| Implementation | 4-8 weeks | A deployed governance layer and trained internal team |
| Managed | Ongoing | Continuous compliance, tuning, and updates |