A read-only audit that instruments how work actually moves across your stack and returns a ranked, costed map of the highest-return automations. The fee credits in full against the pilot.
Before a line of anything is built, we measure. T1 Recon fuses five signals, desktop observation, system and audit logs, the entitlement graph, the document corpus and network signal, into one honest picture of how work is really permitted to flow, not how the process diagram says it should. The output is a Top-N automation map, each candidate scored against your own labour cost, error rate and cycle time, so the business case is arithmetic rather than assertion. Pega's research puts the scale of the waste in view: 1,100-plus application switches and 134 copy-pastes per person, per day. Recon finds where that tax is heaviest and what it is worth to remove. Nothing is committed and nothing is written to your systems; the audit is read-only by construction, and its fee credits in full against the pilot that follows.
One workflow, fixed price, proven against live operations. We instrument cycle-time baselines going in and measure the delta coming out, so value is demonstrated in weeks, not the multi-year programmes that fail.
The pilot takes the highest-return candidate from Recon and proves it, end to end, against real operations, not a sandbox and not a demo. Scope is deliberately narrow: a single high-volume workflow, one system boundary, a fixed price agreed before we start. We model the workflow as a state machine with evaluation gates, stand up the semantic bridge that turns intent into validated structured commands, and put consequential writes behind two-phase human confirmation from day one. Because the pre-pilot baseline was already instrumented in Recon, the result is a measured delta, cycle time, touch count, error rate, rather than a story. RAND finds more than 80% of AI projects fail and CMU's TheAgentCompany benchmark clocks unconstrained agents at roughly 30% task completion; the pilot exists to show, on your data, that a governed and deterministic system clears that bar with room to spare before you commit to building.
The platform stood up on your systems, inside your perimeter. Schema mapping across each system of record, domain-adapted models fine-tuned in-perimeter, your weights from day one.
Build takes the proven pilot and turns it into infrastructure. We deploy inside your perimeter, VPC or air-gapped, and map schemas across each system the operation cannot replace: PSS, MRO, cargo, the DMS, core banking, the EHR. Each becomes a headless backend behind one governed agent and a single workspace. Domain-adapted models are fine-tuned on your corpus inside your boundary, with PII masked before it ever reaches a prompt; the weights are yours from the first training run, never pooled and never shared. We widen coverage from the single pilot workflow to the Top-N map, wiring each new workflow into the same deterministic control plane, state machines, eval gates, two-phase confirm, halt-to-human, so scope grows without the safety envelope loosening. The result is a platform that reads across your silos and acts against them, sitting underneath the work rather than beside it.
We run and improve the platform under an evergreen annual licence, continuous in-perimeter fine-tuning, a defined SLA, and your engineers riding along so the operating knowledge transfers to your team.
Operate is the Build-Operate phase of the commercial model: an evergreen annual licence under which we keep the platform sharp while your team learns to own it. Models are re-tuned monthly inside your perimeter as the operation and its documents evolve, so accuracy tracks reality instead of drifting from it. Every consequential action stays behind human confirmation and every workflow keeps its halt-to-human boundary; we monitor eval-gate outcomes and expand coverage as new high-return workflows clear the bar. Your engineers ride along throughout, pairing on tuning runs, schema changes and incident response, so operating knowledge transfers rather than concentrating with us. A defined SLA covers availability, response and the safety envelope, and you receive the metrics that matter: throughput, straight-through rate, error and intervention rate, and the cost removed against the Recon baseline.
A priced buyout closes the arc. You take ownership of the source, the weights and the infrastructure outright, with a defined support tail to make the handover clean.
Transfer is the Build-Operate-Transfer endpoint, and it is the point of the whole model: you end up owning the platform, not renting it forever. At a price agreed in advance, ownership passes to you in full, the source code, the fine-tuned model weights, the deployment infrastructure and the operating documentation. Because everything already runs inside your perimeter on your systems, there is nothing to migrate and no captive dependency to unwind; transfer is a change of control, not a re-platforming. A defined support tail runs alongside the handover so your engineers, who have been riding along since Operate, take the controls with support beside them rather than a cliff-edge cutover. This is the difference between an agent you have to keep paying to keep, and one that becomes a durable asset on your own balance sheet.
Elapsed time from first conversation to a platform running in production is typically four to seven months, though the gates matter more than the calendar. T1 Recon runs two to four weeks and ends with a costed decision; a pilot proves one workflow against live operations in roughly six to ten weeks; and Build stands the platform up across your systems over three to five months, with early workflows live well before the last one lands. Operate then runs for as long as it earns its keep under the evergreen annual licence, and Transfer happens whenever you choose to exercise the buyout. Because each stage credits or de-risks the next, the audit fee credits against the pilot, the pilot baselines the build, you are never paying twice for the same certainty, and you can stop at any gate having already banked the value proven up to it.
The largest failures start by building first and hoping the value shows up. We invert it. T1 Recon proves the opportunity in your own labour, error and cycle-time numbers before a pilot is scoped, and the pilot proves it against live operations before anything is built at scale. Every gate is quantitative, so you are never committing on a promise.
An impressive demo and a system you can put in front of an IOC dispatcher are different things. Every workflow is a state machine with evaluation gates, the semantic bridge issues validated structured commands rather than free-form guesses, consequential writes require two-phase confirmation, and the controller halts to a human rather than improvising. We optimise for what survives contact with production, not for what looks clever on stage.
The models run inside your perimeter, VPC or air-gapped, never on a shared endpoint. PII is masked before it reaches a prompt, fine-tuning happens in-perimeter on your corpus, and your data does not leave your boundary to train anyone else's system. Sovereignty is the default configuration, not a premium add-on you have to ask for.
The commercial arc is Build-Operate-Transfer for a reason: it ends with you owning the platform outright, source, weights and infrastructure. Because it already runs on your systems, transfer is a change of control, not a migration, and there is no captive dependency to unwind. We earn the renewal by being worth keeping, not by making you impossible to leave.