Approach
Five phases, with governance running through all of them.
The sequence below is how every engagement runs, whether it concludes at a roadmap or continues through to a system in production. Phases can be entered independently, but they are not skipped.
01
Assess
Understand the work before proposing to change it.
02
Design
Specify the system, its limits, and how it will be judged.
03
Build
Engineer it against the specification, in the open.
04
Deploy
Move it into real operations without a cliff edge.
05
Govern
Keep it correct, monitored, and owned by you.
Phase 01
Assess
We spend time with the people who do the work before we say anything about technology. Assessment is where most of the value of an engagement is decided.
What happens
- Structured interviews with operators, not only with sponsors. The documented process and the actual process are usually different, and the difference matters.
- Review of the data that a system would depend on: where it lives, who owns it, how clean it is, and what its access constraints are.
- Identification of the decisions the system would influence, and what evidencing each decision requires.
- Constraint mapping: regulatory, contractual, security, and residency requirements that bound the solution space.
What you receive
A findings document stating what is worth doing, what is not, what it would cost, and what has to be true before it can start. Where the answer is that AI is not the right instrument, that is what the document says.
Phase 02
Design
The system is specified on paper — including how it can fail and how anyone would know — before a line of production code is written.
What happens
- Solution architecture: models, data flows, integrations, hosting, and where the security boundary sits.
- An evaluation plan agreed in advance — the accuracy bar, how it will be measured, and against whose judgment.
- Human oversight design: which actions require approval, who holds it, and what happens on disagreement.
- Failure mode analysis: what a wrong output costs in this context, and which controls reduce that exposure.
What you receive
A technical specification and an evaluation plan, both signed off before build. The accuracy target is a commitment made at this stage, not a number reported after the fact.
Phase 03
Build
Engineering against the specification, in short cycles, with your team able to see the work as it happens rather than at a reveal.
What happens
- Development in your repository, or in one transferred to you at completion. You own the code throughout.
- Continuous evaluation against the agreed test set, with results visible to you as they change.
- Security review of credentials, data handling, retention, and third-party exposure.
- Subject-matter experts from your side review real outputs during the build, not after it.
What you receive
Working software, source code, technical documentation, and an evaluation report measured against the target set in Design.
Phase 04
Deploy
Systems enter operations gradually and alongside the existing process, so the organization can compare rather than trust.
What happens
- Parallel running against the current process, with outputs compared on live work before anything is switched over.
- Staged rollout by team, volume, or case type, with defined criteria for widening.
- Operator training and written runbooks for the people who will live with the system.
- A documented rollback path that can be executed by your staff without us.
What you receive
A system in production, staff trained to operate it, runbooks, and comparison data from the parallel period showing how it performed against the process it replaces.
Phase 05
Govern
AI systems drift. Inputs change, models change, and the world the system was tuned against moves. Governance is the phase that never closes.
What happens
- Ongoing monitoring of accuracy, volume, cost, latency, and exception rates against the original baseline.
- Scheduled re-evaluation, and re-testing whenever an underlying model or dependency changes.
- Audit records maintained in a form that satisfies an external reviewer, not just an internal one.
- Periodic review of whether the system still earns its place, including the option to retire it.
What you receive
Monitoring in place, a review cadence, and audit records. Ongoing support is available but never required — every system is handed over so that your team, or another vendor, can operate it.
Governance & Security
The commitments we make on every engagement.
These are not options to be priced separately. They are the conditions under which we are willing to put an AI system into someone's operation.
Data Handling
Your data stays where you put it
Residency, retention, and third-party exposure are specified at design. Where a model provider is involved, what leaves your boundary is documented and agreed.
Access Control
Least privilege, inherited
Systems receive the narrowest access that lets them work, and honor the permissions of the systems they read from rather than flattening them.
Evaluation
A number agreed before build
Accuracy is measured against a human-labeled set drawn from your real work, with the target agreed in advance and reported honestly.
Human Oversight
Named accountability
Consequential actions require a person. Who that person is, and what they are approving, is defined during design rather than assumed.
Auditability
Reconstructable after the fact
Inputs, outputs, model versions, and human overrides are logged so a material decision can be explained months later.
Ownership
No lock-in by construction
You hold the source, the infrastructure, and the credentials. Continuing with us should be a choice, not a dependency.
Across the Group
The same discipline, applied to a different problem.
This phased structure will look familiar to anyone who has worked with the other Fortbridge arms. Fortbridge Solutions runs requirements, assessment, sourcing, execution, and reporting. Aegis One runs intake, threat assessment, operational design, deployment, and after-action review.
The domains differ; the insistence on assessing before acting, designing before building, and documenting throughout does not.
Engagement
Most engagements begin at Assess.
It is the cheapest phase and the one that determines whether the rest is worth doing.
Scope an Engagement