Service

Adoption and governance.

Licences can be bought in a week. How people use them has to be designed: who decides, what is off limits, how they learn it, and where they do it.

Two ways this
usually ends.

AI arrives from the bottom. Someone writes a good prompt, someone else builds a script, and nobody can see what already exists – so the same tool gets rebuilt in three teams at once.

Or it arrives from the top: a platform, licences for everyone, a message from the board. A quarter later a fraction of the workforce is logging in and the rest have gone back to what they did before.

The first is uncountable and uncontrolled. The second is countable and unused. Both are avoided the same way: a model that says what needs no permission and what needs a decision – and that stays when we leave.

Neither is a decision. Both are a default.

Principles

The judgement is the product.

Control proportional to risk

Not to how visible the initiative is. A personal prompt and a tool that writes to your production system are not the same object, and they should not pass through the same gate. We separate them on day one: one path with no approvals at all, where the safeguards are technical rather than procedural, and one path with a short request and a decision on a fixed date.

Ask where the time goes

“Where could AI help?” assumes knowledge people do not have, and it returns silence. “Where does your time go?” is answered in seconds, by anyone, without preparation – and every answer is a candidate. The question is the method.

The words decide adoption

Tell people a tool will save them time and many will hear that their job is the thing being saved. Adoption dies before the first login, and no amount of training brings it back. We name the benefit as better work and a wider skill, never as hours removed. What the tool does matters less than what people believe it is for.

Governance as the enabler

A process that sends every case to legal is not governance, it is a queue. Below the risk threshold, approval is automatic and the barriers are technical rather than procedural. The rigour goes where the risk actually is.

Proof before scale

One function first, then the organisation. A pilot built for a single team and a single tool cannot be extended – a pilot built as the first instance of a model can. We design the second step while delivering the first.

Built by the people who stay

The network is theirs, not ours. We put one lead in each team, most of them non-technical, and they carry the work after we leave. A model that depends on us being in the room is a model that ends when we leave it.

Two tracks instead of one queue

A process that sends every request to legal is not governance, it is a queue. A queue does not protect an organisation, it moves the work out of its sight.

We separate two categories. A private prompt, a script touching nothing shared and a helper inside one spreadsheet move without permission, with technical safeguards instead of procedural ones. Anything writing to a production system, touching personal data or becoming shared infrastructure gets a short intake and a decision by a stated date.

Drawing that line inside a particular organisation, and protecting both sides of it, is the actual substance of this work.

People, not licences

A message about saving time is heard as a plan to need fewer people, and then adoption stops before the first login, which no training reverses. We name the benefit as better work and broader skill.

In each team we name a lead, usually a non-technical one, and that person owns the area once the project closes. Training runs on that team’s real tasks, not on examples from a deck.

Training material and walkthroughs are built on labelled synthetic records. Real records never go into material that circulates around the organisation.

Environment and compliance

We work on your licences, in your tenant, on your tools. We do not stand up a parallel stack beside it, so the data stays where you already control and audit it.

We build on enterprise agreements under which the provider does not train on customer content. A tool that cannot guarantee that does not go near your data.

Risk classification and the intake path are designed to map onto regulatory requirements, the EU AI Act included, without turning the whole thing into an approval process.

Scope

What we leave behind.

The permission rule

One page: what needs none, what needs an intake, who decides and by when.

Risk classification

Tasks split by whether they touch money, personal data and production systems.

The role model

Who leads the area in each team, what they do, and how much time it actually takes.

Training on your work

Sessions run on the team’s real tasks, on synthetic data.

A library of what exists

So the third team does not rebuild what the first one already has.

The environment

Configured in your tenant, on agreements that exclude training on customer content, with technical safeguards.

Common questions

Before we begin.

We have a hundred and fifty people. Do we need a policy?
You need a written rule, which is shorter than a policy. One page saying what needs no permission, what needs an intake and who decides by when prevents more trouble than a document nobody finishes reading.
Is this training or implementation?
Both, because neither works alone. Training without a permission rule produces tools nobody can see, and a rule without training produces a document nobody opens.
Will our data be used to train models?
No. We build on enterprise agreements under which the provider does not train on customer content, and demonstrations and material run on labelled synthetic records.
Do we need a centre of excellence?
Below roughly a hundred active users, no. One person with protected time is enough, and at larger scale a network of leads inside the teams. A central unit earns its cost at a few hundred users, or when a regulator requires someone to track it continuously.

Who decides today what your people are allowed to use?

If the answer is that it depends who you ask, this is the moment. We come back within one working day.

Write to us