Selected work Selected work.
We transform businesses with AI workflows for filing rehearsal, governed ledger posting,
correspondence review, live audio, and delivery assurance. Ten fields, the same ten, in the
same order, appear on every engagement we publish. Read one card and you have read the format.
Read the set and the differences arrive on the eye rather than having to be reconstructed out
of seven pages of prose, including the differences that do us no favours.
The register.
The interesting question at this end of the market is not speed in isolation. It is what an
implementation or operating arrangement is permitted to do at all, what it must ask before
doing, and what evidence it leaves behind. So field five is four bands: what it does alone,
what it asks about first, what it refuses outright, and the ceiling it will not cross. Every
band is a property of the implementation or operating arrangement rather than a claim about
it, which means you can check it before you check anything else on the card.
A fixed format refuses to flatter any single member of the set. An engagement with a ruled
Evidence field sits beside one without, in the same shape, and the difference is visible in
one pass. Fields with nothing behind them are ruled rather than removed: a missing row is
invisible, and a reader cannot audit what they cannot see.
Compliance · Scenario planning
Rehearse the filing before it is filed
- What it does
-
Reproduces a public filing journey end to end, with every figure, deadline and account
state editable, so a finance team can be walked through the journey they will face.
- The control
- Rehearsal. Nothing in it touches a live filing.
- Failure
-
Meeting an overdue payment, a rejected return or a liability that does not reconcile for
the first time on a real return.
- Unit of work
- A journey walked through, rather than a return learned on.
- Authority
-
- Acts alone
Renders any account state on demand, including states a live account cannot be put into.
- Asks first
Nothing, because it has no live counterparty to ask.
- Refuses
Any route to a live filing endpoint. It holds no live credentials and there is nothing
for it to hold them against.
- Never exceeds
Its own environment. Every account in it is fictional and stays that way.
- Named systems
-
Two-factor sign-in · business account · payroll · indirect tax
· corporate tax
- Claims
-
That an administrator meets an overdue payment, a rejected return and an unreconciled
liability before a real one arrives. The first cohort reached independent filing in five
weeks rather than eleven. At scenario inputs of 120 administrators a year, six weeks of
20 supervised hours a week and $85 an hour, a separate enterprise sensitivity model
values released supervision at $1.224 million a year.
- Non-claims
-
Any avoided penalty. An error that did not occur has no cost to measure, and a figure
built on one would not survive a buyer checking it.
- Evidence held
-
Across the first nine administrators trained in it, amendments in their first quarter
fell from 2.4 each to 0.6.
- Status
- In production
Read the case →
Finance operations · Controlled automation
A ledger that refuses to double-post
- What it does
-
Submits batches of journal entries into an accounting ledger, having first read what is
already in it.
- The control
-
It refuses any transaction matching one already posted, or another in the same run, on
date, amount, counterparty, direction and account. Refusal is the default state and
overriding it is an explicit, deliberate act.
- Failure
-
A debt or credit posted twice, a bank reconciliation that will not tie, and three weeks
spent finding out why.
- Unit of work
-
A batch checked, rather than a posting typed. Fifty transactions per write.
- Authority
-
- Acts alone
Reads the existing ledger, groups postings into batches of fifty, and records an exit
status that tells a clean run from a partial one.
- Asks first
Every commit. An operator confirms before a single posting is written.
- Refuses
Any posting that matches on all five fields. One difference is enough for it to be
written.
- Never exceeds
A write budget. The run stops at the budget rather than at the end of the batch, so the
worst case is bounded before it starts.
- Named systems
-
Xero · batch write API · double-entry ledger
- Claims
-
Measured: about 1,800 duplicate journal entries a year became none, with 1,740 refused
before commit in year one, and year-end clean-up fell from three weeks to under a day.
The operation had 18,000 subscriptions; that count is context, not a multiplier.
Applying modelled $200 to $400 of debt-or-credit exposure plus $50 to $100 of resolution
work to the measured 1,740 refusals gives $435,000 to $870,000 of annual value at risk.
- Non-claims
-
That the dollar range is an audited saving. It is a sensitivity model whose debt,
credit and resolution assumptions are published on the case page.
- Evidence held
-
The ledger history, refusal log and year-end reconciliation: about 1,800 duplicates a
year became none, with 1,740 stopped before commit in year one.
- Status
- In production
Read the case →
Relationship intelligence · Data ingestion
The relationships buried in a decade of correspondence
- What it does
-
Reads years of correspondence at scale, classifies every counterparty, and aggregates
each into a profile: how much passed between you, in which direction, and how long ago
it went quiet.
- The control
-
A person decides which relationships are worth reviving. Nothing reaches the CRM before
that sign-off.
- Failure
-
A CRM populated by hand only ever captures the relationships somebody already
remembered.
- Unit of work
- A decision per relationship, rather than per message.
- Authority
-
- Acts alone
Reads and classifies, checkpointed so an interrupted run resumes rather than restarts.
- Asks first
Every write. Not one profile reaches the CRM without a person approving it.
- Refuses
To treat a classification as a decision. Machine traffic is separated from people, and
the separating is where its job stops.
- Never exceeds
Read access to the mailbox and write access to nothing until sign-off.
- Named systems
-
Google Workspace · Microsoft 365 · two implementations, no shared runtime
code
- Claims
-
Forty thousand messages judged at three seconds each take about thirty-three hours;
about four thousand pre-classified correspondents judged at two seconds each take a
little over two hours. At enterprise scenario inputs of one million messages, 100,000
counterparties, 90 seconds a review and $100 an hour, a separate sensitivity model
removes 900,000 review decisions and values the 22,500 released hours as a
one-off $2.25 million of operating capacity.
- Non-claims
-
That this client measured either figure. They did not, and the page it appears on says
so in the same sentence.
- Evidence held
-
Of four thousand correspondents, 2,610 classified as machine traffic and 1,390 as people
or organisations. The client’s team approved 412 into the CRM, 147 of which had been
quiet for more than two years.
- Status
- In production
Read the case →
Charity foundation · Pro bono · Real-time quality assurance
The operator always outranks the AI
- What it does
-
Listens continuously to a live mix, separates speech from music, adjusts as the room
changes, and coaches whoever is at the desk in plain language on a phone or a projector.
- The control
-
Every action it can take is safety-classified. A kill switch, a rollback and a manual
override sit above all of it.
- Failure
-
Output quality that depends on whichever volunteer is at the desk that day, going to FM,
Zoom and YouTube at once.
- Unit of work
-
Competence that travels with the system, rather than with the individual.
- Authority
-
- Acts alone
Listens, classifies the room, and coaches. It also captures the station’s own broadcast
off air and compares it against the desk output.
- Asks first
Every destructive change. The operator is asked and the operator decides.
- Refuses
To act outside its safety classification, and to continue at all once the kill switch is
thrown.
- Never exceeds
The desk. It never touches the broadcast chain it is listening to.
- Named systems
- Soundcraft Ui24R · FM · Zoom · YouTube
- Claims
-
Deployed across four venues in three countries, with the same safety classification,
operator consent and override hierarchy at every desk.
- Non-claims
-
A measured time saving or audio-quality uplift. The deployment footprint is confirmed;
a comparable cross-venue performance series has not been supplied.
- Evidence held
- Four venues in three countries.
- Status
- In production
Read the case →
Delivery governance · Assurance
Evidence that the process was followed
- What it does
-
Holds a change to a fixed sequence of review, quality assurance, release and sign-off,
and denies the merge outright if a stage is missing, has expired, or does not bind to
the change it claims to cover.
- The control
-
The denial itself. Each stage leaves a tamper-evident receipt chained to the one before
it.
- Failure
-
Where agents write production code, nobody can otherwise show that the review happened.
- Unit of work
-
Evidence produced as a by-product of doing the work, rather than assembled afterwards
for an auditor.
- Authority
-
- Acts alone
Verifies the chain and reports what it found, on every merge attempt.
- Asks first
Nothing. It has no decision to delegate, only a fact to check.
- Refuses
The merge, when a stage is missing, has expired, or binds to a different change.
- Never exceeds
It never approves on anyone’s behalf. Refusing is the only thing it can do.
- Named systems
- Client has not disclosed the stack
- Claims
-
The mechanism, which is verifiable: a merge that skipped a stage is denied by a receipt
chain bound to the same commit. At scenario inputs of 10,000 changes a year, 40 minutes
of evidence reconstruction per change and $150 an hour, a separate enterprise
sensitivity model values released assurance capacity at approximately $1 million a
year.
- Non-claims
-
Any defect-cost multiple. The figures in circulation are old and softly sourced, and
would not survive a buyer checking them.
- Evidence held
-
Run on one production software project, with receipts emitted inside the ordinary
delivery path.
- Status
- In production
Read the case →
Proptech · Venture build
- What it does
-
We joined a property-investment platform at seed as their engineering partner, chose the
stack, built the product, hired the product team around it, and ran delivery through
launch across Europe and South East Asia.
- The control
-
The stack was chosen for the team the company would eventually own, not for us.
- Failure
-
A codebase the company cannot run, which is what conventional outsourcing ships.
- Unit of work
-
The product and the team built together, rather than one after the other.
- Authority
-
- Acts alone
Chose the stack, set the delivery process, and ran the sprint.
- Asks first
Every hire. The founders interviewed and the founders decided.
- Refuses
To build anything the client’s own team could not run without us.
- Never exceeds
Client IP throughout, and delivery passed to the standing in-house team.
- Named systems
- Node.js · GraphQL · Google Cloud Platform
- Claims
-
The intervention: stack chosen, platform built, product team hired, delivery run through
launch and handed over. At ten people and a modelled $180,000 to $240,000 fully loaded
annual cost per role, a separate capacity model values the standing product function at
$1.8 million to $2.4 million a year.
- Non-claims
-
Revenue or unit economics. We did not verify them, so we do not claim them.
- Evidence held
-
Nine engineers and a product designer at handover, and six markets live across Europe
and South East Asia.
- Status
- Handed over
Read the case →
Proptech · Team built and transferred
A team built to be handed over
- What it does
-
A network connecting estate agents, conveyancers, mortgage brokers and lenders needed
engineering scale without losing its culture. We built and employed the team in India,
and ran delivery alongside the in-house team.
- The control
-
The exit is written into the arrangement. Every engineer was novated in-house as the
company grew: contracts transferred, nothing renegotiated.
- Failure
-
Speed from an agency at the cost of cohesion, or cohesion from slow direct hiring at the
cost of the roadmap.
- Unit of work
-
One team with one set of rituals, rather than two teams sharing a roadmap.
- Authority
-
- Acts alone
Sourced and assessed against the client’s own bar, and carried the employment overhead
in India.
- Asks first
Every offer. The client’s engineering lead made the call on each one.
- Refuses
To run a second team. The engineers joined the client’s rituals, standards and roadmap
or they did not join.
- Never exceeds
Employment, never direction. The client ran the team as their own throughout.
- Named systems
- Client has not disclosed the stack
- Claims
-
The intervention and the transfer: an India-based team found against the client’s own
bar, embedded with the in-house team, and novated in-house. A separate sensitivity model
converts a 90-day approximate direct-hiring input against the 31-day median across 14
roles into roughly 590 working engineer-days. At a modelled $1,500 to $2,500 per working
engineer-day, it values the accelerated capacity at approximately
$885,000 to $1.48 million.
- Non-claims
-
The network’s growth and transaction figures. They belong to the client, not to us.
- Evidence held
-
Fourteen engineers found and employed in India. All fourteen novated in-house, and twelve
were still in post a year after the transfer.
- Status
- Handed over
Read the case →
Also built for.
A collaboration-services provider, a creator-economy platform and a mobile-app studio.
Cases for these engagements are shorter stories; ask us about them.