How we work

Two things govern every engagement: a set of design principles we do not compromise on, and a delivery model built so you are not dependent on us afterwards.

Bounded Autonomy, Auditable by Design

Bounded, because the limits are written down. Auditable, because every step leaves a record. A control nobody can evidence is not a control.

Four principles follow. They are not marketing; they are the reason the output can be signed.

  1. 1. Every step writes a record.

    Each automated action records what ran, when, on what input, using what version of what logic, and what it produced. Not a log file for engineers. A record a compliance officer can read and an auditor can follow.

  2. 2. Judgment stays with a person.

    The system prepares, gathers, drafts and flags. It does not decide anything that carries regulatory consequence. Where a decision matters, a named individual makes it and their approval is part of the record.

  3. 3. Nothing is a black box.

    Every output traces back to its source — the clause, the holding, the transaction, the document version. If an output cannot be explained by pointing at where it came from, it is not fit for a compliance process and we will not ship it.

  4. 4. Evidence is a by-product, not a project.

    The record exists because the work happened, not because someone assembled it later. By the time anyone asks, it is already there.

Autonomy without boundaries is a governance problem. Boundaries without evidence are an assertion. You need both, and you need them designed in from the first version rather than retrofitted when someone asks.

Map · Build · Hand over

Map — two to three weeks

We sit with the function and inventory the manual work: what is done, by whom, how often, how long it takes, what evidence it leaves, and what happens when it goes wrong. The output is a prioritised list scored on time consumed and risk carried, with a recommendation on what to automate, what to fix without automation, and what to leave alone. This is a standalone piece of work with a fixed fee. You can stop here and take the map elsewhere.

Build — four to eight weeks per workflow

We build one workflow at a time, in your environment, on tooling you provide and can maintain. Control points and human checkpoints are designed in from the first version, not added at the end. Each build ships with its control map, its documentation, and a period of parallel running against the existing manual process.

Hand over — included

Documentation, a runbook, a control description written for your senior manager, and training for the people who will operate it. We are not trying to become a dependency. Ongoing support is available and is an option, not a requirement.

On technology choices

We are not a reseller, we have no product to sell you, and we do not bring our own platform. Workflows are built on tooling your firm already licenses and already permits — in practice that usually means the Microsoft or Google estate you run, your existing workflow layer, and an AI model accessed under your own enterprise agreement, on your own terms.

That means two things. Your information security team is assessing tools they have already approved, not a new supplier. And when the engagement ends, nothing leaves with us: the workflow runs on your infrastructure, under your licences, maintained by your people.

Book a call