How we work
Fixed scope, your code, and no surprises about your data
Most of this comes up in the first call anyway. Here it is in writing, so you can check it before we talk.
The four steps
- 01
Clarify
We map the workflow and find where AI actually saves time or money. If it doesn’t, we say so before you pay.
- 02
Prototype
In 1–2 weeks you get a working prototype on your data — not slides. You see the result and decide whether to go on.
- 03
Integrate
We wire it into your tools, hand over the code and documentation, and walk your team through running it.
- 04
Support
Two weeks of monitoring and tuning on real traffic — we fix whatever the first live days surface.
Engagement terms
What you’re agreeing to when you hire us.
- Scope
- One workflow, written down before we start — inputs, outputs, the exceptions, what’s explicitly out. No moving target.
- Price
- Fixed, agreed up front against that scope. A change to the scope is a new line item, not a surprise invoice.
- Code
- Yours. Delivered to your repository, MIT-style internal licence, no runtime lock to us. You can take it and maintain it elsewhere.
- Accounts
- Every third-party account — model API, telephony, database, hosting — is created in your name and paid by you. We work inside them; we don’t resell them.
- First project
- Deliberately small — enough to ship one thing and get a real number. If it works, we scope the next one.
Access & data
What we touch, where it goes, and what we don’t do with it.
- Access
- Least-privilege from the start. We ask for the specific scopes a workflow needs, not admin. Access is logged and revoked at handover unless you keep us on support.
- Where data lives
- In your infrastructure, or in named managed services (your Supabase, your CRM, your cloud) that you own and control. We tell you exactly what is stored where and for how long.
- Training
- Nothing you give us is used to train a model. We use API tiers with training disabled, and we don’t retain your data beyond what the workflow needs to run.
- Secrets
- API keys and credentials live in a vault or the platform’s secret store — never in code, never in a repo, never in a chat message.
- Untrusted input
- Agents that read inbound email, forms or documents are built to treat that content as data, not instructions — so a message can’t talk the agent into doing something it shouldn’t.
Safety
How the systems behave when they’re unsure or something breaks.
- Human approval
- Anything consequential — sending money, signing, deleting, mailing a client — waits for a person. The agent proposes; a human confirms.
- Escalation over guessing
- Off-script, ambiguous, or low-confidence cases are handed to a person with context. The agent doesn’t improvise on the things that matter.
- Monitoring
- Every run is logged. You get alerts when something fails, stalls, or crosses a threshold you set — before a client notices.
- Rollback
- Changes ship behind a flag where it’s possible. If a live day goes wrong, we can turn the workflow off and fall back to the manual process without data loss.
Handover
What you have at the end, and what happens if you leave.
- Documentation
- A written runbook: what it does, how to run it, how to change the script, what each failure means, who to call.
- Walkthrough
- A live session with the people who’ll own it day to day, recorded.
- Support window
- Two weeks included. After that, an optional monthly arrangement with defined response times and a fixed change-request rate — or nothing, and you run it yourself.
- Exit
- If you stop working with us, you keep the code, the accounts and the data. There is nothing to unwind.
Have a workflow in mind?
Tell us what it is. We’ll say whether AI is the right tool and what it would take.
Get in touch