esya
Selected work

Selected work.

We transform businesses with AI workflows for filing rehearsal, governed ledger posting, correspondence review, live audio, and delivery assurance. Ten fields, the same ten, in the same order, appear on every engagement we publish. Read one card and you have read the format. Read the set and the differences arrive on the eye rather than having to be reconstructed out of seven pages of prose, including the differences that do us no favours.

The register.

The interesting question at this end of the market is not speed in isolation. It is what an implementation or operating arrangement is permitted to do at all, what it must ask before doing, and what evidence it leaves behind. So field five is four bands: what it does alone, what it asks about first, what it refuses outright, and the ceiling it will not cross. Every band is a property of the implementation or operating arrangement rather than a claim about it, which means you can check it before you check anything else on the card.

A fixed format refuses to flatter any single member of the set. An engagement with a ruled Evidence field sits beside one without, in the same shape, and the difference is visible in one pass. Fields with nothing behind them are ruled rather than removed: a missing row is invisible, and a reader cannot audit what they cannot see.

Compliance · Scenario planning

Rehearse the filing before it is filed

What it does
Reproduces a public filing journey end to end, with every figure, deadline and account state editable, so a finance team can be walked through the journey they will face.
The control
Rehearsal. Nothing in it touches a live filing.
Failure
Meeting an overdue payment, a rejected return or a liability that does not reconcile for the first time on a real return.
Unit of work
A journey walked through, rather than a return learned on.
Authority
  • Acts alone Renders any account state on demand, including states a live account cannot be put into.
  • Asks first Nothing, because it has no live counterparty to ask.
  • Refuses Any route to a live filing endpoint. It holds no live credentials and there is nothing for it to hold them against.
  • Never exceeds Its own environment. Every account in it is fictional and stays that way.
Named systems
Two-factor sign-in · business account · payroll · indirect tax · corporate tax
Claims
That an administrator meets an overdue payment, a rejected return and an unreconciled liability before a real one arrives. The first cohort reached independent filing in five weeks rather than eleven. At scenario inputs of 120 administrators a year, six weeks of 20 supervised hours a week and $85 an hour, a separate enterprise sensitivity model values released supervision at $1.224 million a year.
Non-claims
Any avoided penalty. An error that did not occur has no cost to measure, and a figure built on one would not survive a buyer checking it.
Evidence held
Across the first nine administrators trained in it, amendments in their first quarter fell from 2.4 each to 0.6.
Status
In production

Read the case

Finance operations · Controlled automation

A ledger that refuses to double-post

What it does
Submits batches of journal entries into an accounting ledger, having first read what is already in it.
The control
It refuses any transaction matching one already posted, or another in the same run, on date, amount, counterparty, direction and account. Refusal is the default state and overriding it is an explicit, deliberate act.
Failure
A debt or credit posted twice, a bank reconciliation that will not tie, and three weeks spent finding out why.
Unit of work
A batch checked, rather than a posting typed. Fifty transactions per write.
Authority
  • Acts alone Reads the existing ledger, groups postings into batches of fifty, and records an exit status that tells a clean run from a partial one.
  • Asks first Every commit. An operator confirms before a single posting is written.
  • Refuses Any posting that matches on all five fields. One difference is enough for it to be written.
  • Never exceeds A write budget. The run stops at the budget rather than at the end of the batch, so the worst case is bounded before it starts.
Named systems
Xero · batch write API · double-entry ledger
Claims
Measured: about 1,800 duplicate journal entries a year became none, with 1,740 refused before commit in year one, and year-end clean-up fell from three weeks to under a day. The operation had 18,000 subscriptions; that count is context, not a multiplier. Applying modelled $200 to $400 of debt-or-credit exposure plus $50 to $100 of resolution work to the measured 1,740 refusals gives $435,000 to $870,000 of annual value at risk.
Non-claims
That the dollar range is an audited saving. It is a sensitivity model whose debt, credit and resolution assumptions are published on the case page.
Evidence held
The ledger history, refusal log and year-end reconciliation: about 1,800 duplicates a year became none, with 1,740 stopped before commit in year one.
Status
In production

Read the case

Relationship intelligence · Data ingestion

The relationships buried in a decade of correspondence

What it does
Reads years of correspondence at scale, classifies every counterparty, and aggregates each into a profile: how much passed between you, in which direction, and how long ago it went quiet.
The control
A person decides which relationships are worth reviving. Nothing reaches the CRM before that sign-off.
Failure
A CRM populated by hand only ever captures the relationships somebody already remembered.
Unit of work
A decision per relationship, rather than per message.
Authority
  • Acts alone Reads and classifies, checkpointed so an interrupted run resumes rather than restarts.
  • Asks first Every write. Not one profile reaches the CRM without a person approving it.
  • Refuses To treat a classification as a decision. Machine traffic is separated from people, and the separating is where its job stops.
  • Never exceeds Read access to the mailbox and write access to nothing until sign-off.
Named systems
Google Workspace · Microsoft 365 · two implementations, no shared runtime code
Claims
Forty thousand messages judged at three seconds each take about thirty-three hours; about four thousand pre-classified correspondents judged at two seconds each take a little over two hours. At enterprise scenario inputs of one million messages, 100,000 counterparties, 90 seconds a review and $100 an hour, a separate sensitivity model removes 900,000 review decisions and values the 22,500 released hours as a one-off $2.25 million of operating capacity.
Non-claims
That this client measured either figure. They did not, and the page it appears on says so in the same sentence.
Evidence held
Of four thousand correspondents, 2,610 classified as machine traffic and 1,390 as people or organisations. The client’s team approved 412 into the CRM, 147 of which had been quiet for more than two years.
Status
In production

Read the case

Charity foundation · Pro bono · Real-time quality assurance

The operator always outranks the AI

What it does
Listens continuously to a live mix, separates speech from music, adjusts as the room changes, and coaches whoever is at the desk in plain language on a phone or a projector.
The control
Every action it can take is safety-classified. A kill switch, a rollback and a manual override sit above all of it.
Failure
Output quality that depends on whichever volunteer is at the desk that day, going to FM, Zoom and YouTube at once.
Unit of work
Competence that travels with the system, rather than with the individual.
Authority
  • Acts alone Listens, classifies the room, and coaches. It also captures the station’s own broadcast off air and compares it against the desk output.
  • Asks first Every destructive change. The operator is asked and the operator decides.
  • Refuses To act outside its safety classification, and to continue at all once the kill switch is thrown.
  • Never exceeds The desk. It never touches the broadcast chain it is listening to.
Named systems
Soundcraft Ui24R · FM · Zoom · YouTube
Claims
Deployed across four venues in three countries, with the same safety classification, operator consent and override hierarchy at every desk.
Non-claims
A measured time saving or audio-quality uplift. The deployment footprint is confirmed; a comparable cross-venue performance series has not been supplied.
Evidence held
Four venues in three countries.
Status
In production

Read the case

Delivery governance · Assurance

Evidence that the process was followed

What it does
Holds a change to a fixed sequence of review, quality assurance, release and sign-off, and denies the merge outright if a stage is missing, has expired, or does not bind to the change it claims to cover.
The control
The denial itself. Each stage leaves a tamper-evident receipt chained to the one before it.
Failure
Where agents write production code, nobody can otherwise show that the review happened.
Unit of work
Evidence produced as a by-product of doing the work, rather than assembled afterwards for an auditor.
Authority
  • Acts alone Verifies the chain and reports what it found, on every merge attempt.
  • Asks first Nothing. It has no decision to delegate, only a fact to check.
  • Refuses The merge, when a stage is missing, has expired, or binds to a different change.
  • Never exceeds It never approves on anyone’s behalf. Refusing is the only thing it can do.
Named systems
Client has not disclosed the stack
Claims
The mechanism, which is verifiable: a merge that skipped a stage is denied by a receipt chain bound to the same commit. At scenario inputs of 10,000 changes a year, 40 minutes of evidence reconstruction per change and $150 an hour, a separate enterprise sensitivity model values released assurance capacity at approximately $1 million a year.
Non-claims
Any defect-cost multiple. The figures in circulation are old and softly sourced, and would not survive a buyer checking them.
Evidence held
Run on one production software project, with receipts emitted inside the ordinary delivery path.
Status
In production

Read the case

Proptech · Venture build

The platform and the scale-up

What it does
We joined a property-investment platform at seed as their engineering partner, chose the stack, built the product, hired the product team around it, and ran delivery through launch across Europe and South East Asia.
The control
The stack was chosen for the team the company would eventually own, not for us.
Failure
A codebase the company cannot run, which is what conventional outsourcing ships.
Unit of work
The product and the team built together, rather than one after the other.
Authority
  • Acts alone Chose the stack, set the delivery process, and ran the sprint.
  • Asks first Every hire. The founders interviewed and the founders decided.
  • Refuses To build anything the client’s own team could not run without us.
  • Never exceeds Client IP throughout, and delivery passed to the standing in-house team.
Named systems
Node.js · GraphQL · Google Cloud Platform
Claims
The intervention: stack chosen, platform built, product team hired, delivery run through launch and handed over. At ten people and a modelled $180,000 to $240,000 fully loaded annual cost per role, a separate capacity model values the standing product function at $1.8 million to $2.4 million a year.
Non-claims
Revenue or unit economics. We did not verify them, so we do not claim them.
Evidence held
Nine engineers and a product designer at handover, and six markets live across Europe and South East Asia.
Status
Handed over

Read the case

Proptech · Team built and transferred

A team built to be handed over

What it does
A network connecting estate agents, conveyancers, mortgage brokers and lenders needed engineering scale without losing its culture. We built and employed the team in India, and ran delivery alongside the in-house team.
The control
The exit is written into the arrangement. Every engineer was novated in-house as the company grew: contracts transferred, nothing renegotiated.
Failure
Speed from an agency at the cost of cohesion, or cohesion from slow direct hiring at the cost of the roadmap.
Unit of work
One team with one set of rituals, rather than two teams sharing a roadmap.
Authority
  • Acts alone Sourced and assessed against the client’s own bar, and carried the employment overhead in India.
  • Asks first Every offer. The client’s engineering lead made the call on each one.
  • Refuses To run a second team. The engineers joined the client’s rituals, standards and roadmap or they did not join.
  • Never exceeds Employment, never direction. The client ran the team as their own throughout.
Named systems
Client has not disclosed the stack
Claims
The intervention and the transfer: an India-based team found against the client’s own bar, embedded with the in-house team, and novated in-house. A separate sensitivity model converts a 90-day approximate direct-hiring input against the 31-day median across 14 roles into roughly 590 working engineer-days. At a modelled $1,500 to $2,500 per working engineer-day, it values the accelerated capacity at approximately $885,000 to $1.48 million.
Non-claims
The network’s growth and transaction figures. They belong to the client, not to us.
Evidence held
Fourteen engineers found and employed in India. All fourteen novated in-house, and twelve were still in post a year after the transfer.
Status
Handed over

Read the case

Also built for.

A collaboration-services provider, a creator-economy platform and a mobile-app studio. Cases for these engagements are shorter stories; ask us about them.