VOL_01 / 2026 — SERVICES 25 services · 3 engagement formats

The full service catalog.

Three engagement formats — Discover, Operate, Implement. Twenty-five service lines underneath, from one-week diagnostic spot-checks to multi-month implementation projects to standing monthly retainers. Every engagement is fixed-scope with named senior advisor accountability.

// 01
Engagement Formats

Three ways we engage. Pick one to start.

Every service falls into one of three formats. Most clients start with a Discover engagement, then graduate to an Operate retainer, then add Implement projects as needs surface.

[D] Discover

Fixed-scope diagnostic.

Short, contained engagement that produces a tangible deliverable — usually a report, an inventory, a heat map, or a roadmap. The wedge into the relationship.

7 services · 1–4 weeks · one-shot
[O] Operate

Standing operational layer.

Monthly retainer covering quarterly reviews, ongoing oversight, training cadence, hotline access, briefings, incident response, and policy maintenance.

7 services · annual contract · recurring
[I] Implement

Project work that moves something.

Defined-scope projects pulled from Discover findings or Operate conversations — use case rollouts, vendor work, policies, audits, evals, code review.

11 services · 1–16 weeks · project-based
// 02
The Catalog

All 25 services, organized by engagement format.

Click any service for the full playbook (where one exists), or book a call to discuss a custom scope. Color-coded tags signal personality: standard (teal), emphasis (sienna), high-stakes or technical (black).

// DISCOVER · 7 services

Find what's there. Map the surface. Prioritize what to fix first.

// OPERATE · 7 services

Standing oversight. Recurring deliverables. The relationship that compounds.

// IMPLEMENT · 11 services

Ship the thing. Audit the thing. Document the thing. Defined-scope project work, fixed price.

Implement

Pre-Launch Ship Review

Senior dev reviews AI-generated code pre-deploy. Auth, secrets, prompt-injection surface, eval coverage, cost guardrails, error handling.

3–5 days · fixed-scope
Implement

AI Use Case Rollout

Stand up a new AI capability — customer service AI, hiring AI, knowledge base, document automation, sales enablement. End-to-end.

8–16 weeks · project-based
Implement

Tooling Architecture & Marketplace

Map your risk surface to vendor categories. Recommend best-fit (with disclosed referral relationships). Implementation included.

Architecture + per-tool implementation
Implement

AI Acceptable Use Policy

Drafting + rollout collateral. Plain-language policy + employee one-pager + FAQ + manager talking points + comms template.

2–3 weeks · fixed-scope
Implement

AI Vendor Due Diligence

Per-vendor assessment with disclosed referral relationships. Standardized rubric across security, privacy, AI-specific risk, commercial.

Per-vendor engagement
Implement

AI Bias Audit

Statistical bias testing of AI outputs against protected groups. Documented methodology, mitigation recommendations, audit-ready report.

4–6 weeks · project-based
Implement

System Prompt Review

Find the prompts that will leak data, get jailbroken, or hallucinate disastrously. Hardening recommendations + ongoing-review rubric.

1 week · fixed-scope
Implement

Eval Setup

Build 20–50 test cases so model swaps don't silently break your product. Eval framework picked to fit your stack, seeded with realistic test data.

1–2 weeks · project-based
Implement

AI Cost Optimization

Model selection, caching strategy, rate limits, fallbacks. Often pays for itself in the first month — sometimes the first week.

1 week · fixed-scope
Implement

Privacy Policy & ToS Review

Make sure your AI-generated privacy policy actually matches what your app does. Specific to AI products with user data flowing through models.

1 week · fixed-scope
Implement

Trust Signal Setup

AI usage disclosure page, plain-language model card, security overview. The artifacts your enterprise prospects will ask for in due diligence.

1 week · fixed-scope
// WHEN YOU'RE READY FOR FULL COMPLIANCE

The same firm. Deeper specialization. No transition friction.

When you take EU funding, sign your first enterprise customer, or hit a regulatory threshold, you'll need formal compliance work — ISO 42001, EU AI Act conformity, SOC 2. Our sister practice GovernMy.ai handles that, with the same client team you already trust. Your operational relationship with us continues in parallel.

Visit GovernMy.ai →

Not sure where to start? Start with the conversation.

30-minute call. We listen, ask questions, and tell you which service fits. If we're not the right fit, we'll say so.