How the work actually gets done

Four phases, two-week cycles, one accountable lead, and a human gate before anything reaches production - on a four-week sprint and a two-year build alike.

2-weekdelivery cycles
Human gatesat every stage
US · UK · EUoverlap hours
Your repo,your cloud, your IP
The engagement spine
Same on every programme
AlignWeeks 0–4

Decide what's worth building - and prove it can be governed.

Gate · business case signed
ProveWeeks 4–12

Ship one real thing into your real environment.

Gate · production-readiness review
BuildMonth 3+

Scale what worked, without losing the discipline that got it live.

Gate · your named release approver
RunOngoing

Keep it healthy in production - and hand it over well.

Gate · handover, runbooks, exit plan
A personapprovesbefore each hand-off
Why the model matters

Most AI programmes don't fail in the model. They fail in the operating model.

The technology is rarely the reason a programme stalls. It stalls because nobody owned the outcome, because the demo couldn't survive a security review, or because the invoice arrived before the working software did. Here's what we changed, and why.

What usually happens
How we run it
A pilot with no route to production

The proof-of-concept impresses, then dies waiting for an owner, a budget line and a security review nobody scoped.

Production readiness is scoped in Phase 1

Before a line of code, we agree the target architecture, the risk classification and the evidence pack your security and compliance reviewers will ask for. The route to production is part of the business case, not a surprise after it.

A team you meet once and never again

Senior people win the work; unnamed juniors deliver it. The architect from the pitch is on someone else's account by week three.

A named pod, and a named lead in the contract

Every person on your pod has a name, a CV and a face on the call. One engagement lead is accountable end-to-end, and changes to the named team need your sign-off - no silent substitutions.

Velocity you can't evidence

AI writes the code, the team ships fast, and then a regulator, an auditor or an enterprise customer asks who approved what - and the answer is a Slack thread.

Every gate produces an artefact

Design decisions land as ADRs, reviews as approvals, security as scans and SBOMs, AI behaviour as eval runs. The audit trail is a by-product of the way we work, not a project we run afterwards.

Change requests as a business model

Scope drifts, the invoice grows, and the first honest conversation about cost happens six weeks after the budget was committed.

Fixed shapes, and a demo before every invoice

Discovery and pilots are fixed scope and fixed fee. Ongoing work runs on a rolling pod with 30-day notice. Every fortnight you see working software before you see a bill.

The operating model

Four phases. One rail. A gate you have to pass to leave each one.

Every Focaloid engagement runs the same spine, whatever the size. Pick a phase to see what happens inside it, who is in the room, what you walk away with - and what has to be true before we move on.

Phase 01 · Align

Decide what's worth building - and prove it can be governed

We start narrow and finish costed. Use cases get scored on value, effort and model risk; the winner gets a target architecture, a governance plan and a price. If the honest answer is "don't build this yet", you get that in week three instead of month nine.

4 weeks
from first call to roadmap
Fixed scope
fixed fee, no retainer
What happens
  • A 30-minute call, then a structured immersion: your systems, your data, your constraints, your commercial pressure.
  • Every candidate use case scored on the same three axes - business value, delivery effort, model risk.
  • An honest build-vs-buy call on each one, including the ones we'd tell you not to build.
  • Target architecture and data readiness mapped against what you already run.
  • Governance designed in: risk class, oversight model, evidence the review will demand.
Who's in the room
FEngagement lead Ours
FSolution architect Ours
FAI / domain specialist Ours
YExecutive sponsor Yours
YProduct & data owners Yours
YSecurity / risk reviewer Yours
What you walk away with
  • A prioritised, scored use-case portfolio
  • A build-vs-buy recommendation per use case
  • Target AI architecture and data-readiness gaps
  • A governance & compliance plan mapped to EU AI Act / NIST AI RMF
  • A sequenced 6–12 month roadmap, costed
  • The first build, fully scoped and priced
The gate out of AlignYour sponsor signs the business case and the scope of the first build. Nothing moves into Prove without a named owner, a budget line and an agreed definition of success.
The AI Strategy Sprint
Phase 02 · Prove

Ship one real thing into your real environment

Not a sandbox demo - a working slice running in your cloud, against your data, behind your auth, with the evaluation harness and audit trail already attached. This is where we find out what production will actually cost, before you commit to the programme.

6–8 weeks
typical first increment
Your environment
your repo, your cloud
What happens
  • A pod stands up in your repo, your cloud, your ticketing system - day one, not month two.
  • Two-week cycles, each ending in working software you can use, not a status deck.
  • An evaluation harness for anything AI-driven: golden sets, regression prompts, red-team cases, accuracy and cost per transaction.
  • Security in the pipeline from the first commit - SAST, dependency and IaC scanning, SBOM.
  • A live decision log and risk register you can read at any time.
Who's in the room
FEngagement lead Ours
FSolution architect Ours
F2–4 engineers Ours
FDesigner & QA Ours
YProduct owner Yours
YPlatform / security contact Yours
What you walk away with
  • A working increment in production or pre-production
  • Measured accuracy, latency and cost per transaction
  • An eval suite that keeps working after we leave
  • A model-risk note and evidence pack for your reviewers
  • A validated estimate for the full build - grounded in real velocity, not a spreadsheet guess
The gate out of ProveA production-readiness review: eval thresholds met, security scans clean, cost per transaction understood, rollback tested, and an owner named for the thing once it's live. Any one of those failing stops the phase - including if the honest call is to stop entirely.
What we build
Phase 03 · Build

Scale what worked, without losing the discipline that got it live

The pod grows, the cadence doesn't change. AI does the heavy lifting across the lifecycle - requirements, design, code, tests, review, pipelines - and a person owns the decision at every stage. Speed comes from removing the waiting, not from removing the checking.

2-week cycles
demo every sprint
5–8 per pod
scales to multi-pod
What happens
  • The AI-augmented SDLC runs across every stage - the AI proposes, your team disposes.
  • Every pull request gets a human reviewer. AI-drafted code is reviewed like any other code, never merged on trust.
  • DevSecOps checks run inside the flow - scanning, SBOM, IaC policy - so security never becomes a late blocker.
  • Architecture decisions are recorded as ADRs your team can argue with later.
  • Throughput, change-failure rate and lead time tracked openly - including when they're bad.
Who's in the room
FDelivery lead Ours
FArchitect + engineers Ours
FQA automation Ours
FDevSecOps / SRE Ours
YProduct owner Yours
YNamed release approver Yours
What you walk away with
  • Releases on a predictable cadence, not a heroic one
  • Delivery metrics you can take to a board - throughput, lead time, change-failure rate
  • An evidence trail per release: approvals, scans, eval runs
  • Automated regression that grows with the product
  • Documentation and ADRs written as the work happens
The gate at every releaseYour named approver signs the release. Behind that signature sit six earlier gates - ready, design, code review, security, AI evaluation, release - each with a person and an artefact attached.
The AI-augmented SDLC
Phase 04 · Run

Keep it healthy in production - and hand it over well

Most AI projects don't fail in the lab; they fail in operations. Models drift, costs creep, prompts rot, and the person who understood it leaves. Run is the phase that keeps the value you paid for - and it's built so your own team can take it over whenever you want.

SLA-backed
agreed response targets
Exit plan
written from day one
What happens
  • MLOps and LLMOps monitoring: drift, quality regression, latency, spend per feature.
  • Evals run on a schedule and on every model or prompt change - nothing swaps silently.
  • Incident process with agreed severities, response targets and a blameless post-mortem.
  • A standing optimisation loop on cost - model routing, caching, right-sizing.
  • Quarterly business review: what the thing was supposed to move, and whether it moved it.
Who's in the room
FRun lead Ours
FMLOps / LLMOps Ours
FSRE on-call Ours
YService owner Yours
YExecutive sponsor Quarterly
What you walk away with
  • A system that stays accurate and affordable after launch
  • Runbooks and architecture docs your engineers can act on
  • Knowledge transfer sessions, recorded
  • Ongoing compliance evidence as regulations move
  • A clean handover whenever you want one - no lock-in, no ransom
The gate out of RunHandover is a deliverable, not a favour: runbooks, architecture decisions, eval suites, credentials and a shadowing period, so your team can own it the day you decide to.
ML / LLM Ops
Not every engagement starts at Align.
Already have a build-ready spec? Start at Prove. Already in production? Start at Run.
Who you actually get

A pod, not a resource pool

Focaloid delivery runs in small, cross-functional pods that stay with your product. Every role below is a named person you meet before the contract is signed - and the same people are in the room when something goes wrong.

Engagement lead
One throat to choke

Named in the contract. Owns scope, budget, escalation and the honest conversation when a date is at risk. Your sponsor's single point of contact for the whole programme.

Solution architect
Owns the shape

Sets the technical direction, writes the ADRs and co-signs design reviews with your architect. The architect in the pitch is the architect on the pod.

AI & ML engineers
Models, agents, evals

Retrieval, agent design, model selection and the evaluation harness that proves the thing behaves - plus the LLMOps to keep it behaving.

Product engineers
Full-stack build

Build in your repo, in your patterns, to your standards. Thirteen years of product engineering is the reason the AI work survives contact with production.

The unit of delivery

One pod. Five to eight people. Your product, end to end.

A pod owns a slice of outcome, not a queue of tickets - design through deployment, with the governance roles inside the team rather than in a separate compliance function that shows up at the end.

OursEngagement lead · architect · engineers · designer · QA · DevSecOps · governance
YoursExecutive sponsor · product owner (~4 hrs/week) · named release approver
Scales by adding pods, not by adding layers - multi-pod programmes get a delivery lead and a shared architecture forum, and the cadence stays identical.
Product designer
Flows & interfaces

Designs the journeys - including the ones where a human has to review, correct or override what the AI proposed. Oversight only works if it's usable.

QA & test automation
Regression from sprint 1

Automated regression built alongside the feature, plus adversarial testing of AI behaviour. AI drafts the tests; a human decides what "passing" means.

DevSecOps & SRE
Pipelines & posture

CI/CD, infrastructure as code, scanning, SBOM, observability and cost control - security native to delivery instead of a gate that blocks it at the end.

Governance & model risk
Evidence, not paperwork

Risk classification, oversight design and the evidence pack for EU AI Act, NIST AI RMF and your customers' security reviews - produced as the work happens.

No unnamed resourcesEvery person on the pod has a name, a CV and a face on the call - before you sign, not after.
No silent substitutionsChanges to the named pod need your sign-off, with a handover overlap - not an email on a Friday.
Your tools, your stackWe work inside your repo, your board and your chat. No client portal, no dependency on ours.
The rhythm

A fortnight you can set your calendar by

The cadence is deliberately boring, because predictability is what buys trust. Same ceremonies, same days, same overlap hours - from the first sprint to the last.

Inside one two-week cycle

Ten working days, four fixed touchpoints, and a demo of working software before the sprint closes.

Sprint · 10 working days
D1Mon
D2Tue
D3Wed
D4Thu
D5Fri
D6Mon
D7Tue
D8Wed
D9Thu
D10Fri
Daily stand-up · 15 minutes, in your overlap windowEvery day
Sprint planningD1
Design & architecture reviewD3
Mid-sprint demoD6
Review, retro & releaseD10
Security scans, evals & human code review, continuously in the pipelineAlways on
Steering with your sponsorMonthly
Rhythm
Demo & planning
Quality & design
Release
Governance
In your tools
JiraAzure DevOpsGitHubGitLabSlackMicrosoft TeamsConfluenceFigma

The hours we actually share

Delivery runs from our engineering hub with leads in your region. Every client gets a guaranteed live overlap window - the hours where decisions get made, not just handed off.

Times shown in UTC
Focaloid deliveryEngineering hub
Core + extended shift
United KingdomLondon
Full working day
EuropeCET · Amsterdam, Frankfurt
Full working day
US EastNew York, Boston
Morning overlap, every day
US WestBay Area, Seattle
Early window + in-region lead
Our core hours
Extended shift
Your hours
Live overlap
Stand-ups, reviews and demos are always scheduled inside the overlap - never posted as a recording. Exact windows are agreed at kick-off and adjusted for daylight saving.
The gates

Where the speed stops and a person decides

AI drafts. People decide. Six gates stand between an idea and your production environment, and each one has a name attached, a signature and an artefact that survives the meeting.

Why this matters commercially

Governed delivery isn't a tax on speed - it's what stops a launch stalling in your customer's security review or a regulator's questionnaire. The evidence your reviewers ask for is produced as we work, so the answer to "show me who approved this" takes minutes, not weeks.

01 · Definition of ready

Nothing enters a sprint without acceptance criteria, a risk classification and a named owner on your side.

Signed · your product owner
Artefact · scoped story
02 · Design & architecture review

Technical direction agreed before the build, with the trade-offs written down rather than remembered.

Signed · architects, both sides
Artefact · ADR
03 · Human code review

Every pull request is reviewed by a person. AI-drafted code is held to exactly the same bar as hand-written code - no exceptions, no "the AI wrote it".

Signed · reviewing engineer
Artefact · PR approval
04 · Security & supply chain

SAST, dependency and IaC scanning plus an SBOM on every build, inside the pipeline rather than as a pre-launch scramble.

Signed · DevSecOps
Artefact · scan report + SBOM
05 · AI evaluation gate

For anything model-driven: golden-set accuracy, regression prompts, red-team cases, latency and cost per transaction - with thresholds agreed in advance.

Signed · AI lead + your risk owner
Artefact · eval run + model-risk note
06 · Release approval

Your named approver releases to production, with the rollback path tested and the evidence from gates 1–5 attached to the record.

Signed · your release approver
Artefact · audit-trail entry
What you see

Transparency isn't a status call

You get the same view of the work that we do - live, not curated into a Friday PDF. If a sprint is going badly, you'll know on the Tuesday.

Every dayA 15-minute stand-up in your overlap window, plus a board you can open at any hour - no permission required.
Every fortnightA demo of working software, a one-page written summary, and the decisions we need from you clearly listed.
Every monthSteering with your sponsor: spend against plan, delivery metrics, open risks, and anything we got wrong.
Every quarterA business review against the case we agreed in Align - did the number move? - and a re-plan if it didn't.
focaloid · delivery view
Live
Sprint burndownSprint 14
Throughput+ trend
Gate logthis release
Design review- ADR-114Mon
Code review- 12 PRsTue–Thu
Security scan- 0 highThu
Eval gate- runningnow
Spend vs planthis quarter
Committed68%
Scope delivered71%
Illustrative viewBuilt from your own toolsNo client portal to log into
Ways to engage

Four commercial shapes - pick the one that matches your risk

You shouldn't have to commit to a programme to find out whether we're any good. Most clients start small and fixed, then move to a rolling pod once the first thing is live.

Start here · lowest risk

AI Strategy Sprint

4 weeks · fixed scope · fixed fee

A focused engagement that ends with a costed, sequenced, governed roadmap and a fully scoped first build - not an open-ended retainer and not a deck.

Best for“We know AI matters. We don't know where it pays off, or what it costs.”
What's fixedScope, fee and end date. You know the number before you start.
How it endsArtefacts you own, usable whether or not we build the next phase.
See the sprint
Maps to Phase 01 · Align
Prove it works

Fixed-scope build

6–14 weeks · fixed fee · defined acceptance

A bounded piece of product delivered against agreed acceptance criteria: a copilot, a data platform slice, a modernisation, a first agentic workflow - live in your environment.

Best forA defined outcome with a clear spec, or a pilot that has to earn the programme.
What's fixedScope, price and acceptance. Delivery risk sits with us.
How it endsAcceptance sign-off, handover pack, and an honest estimate for what's next.
What we build
Maps to Phase 02 · Prove
Keep shipping

Dedicated pod

Monthly · rolling · 30-day notice

A named cross-functional pod that stays with your product: 5–8 people, one accountable lead, delivering on a fortnightly cadence for as long as it's earning its keep.

Best forContinuous product development, or extending a team that's short on AI and platform depth.
What's fixedThe team, the rate and the cadence. Priorities stay yours to change every sprint.
How it ends30 days' notice after the initial term, with handover included - not charged as a project.
See the pod shape
Maps to Phase 03 · Build
Keep it healthy

Managed run

Monthly · SLA-backed · scales down

We operate what's live: monitoring, drift and quality regression, incident response, cost optimisation, and the compliance evidence that has to keep flowing after launch.

Best forAI features and platforms already in production that nobody has the bandwidth to own properly.
What's fixedResponse targets and monthly cost. Scale the cover up or down by quarter.
How it endsYour team takes it back with runbooks, recorded knowledge transfer and a shadowing period.
ML / LLM Ops
Maps to Phase 04 · Run
Where we'll share the risk

On engagements with a metric we can both measure - cycle time, straight-through processing, cost per case, review turnaround - we'll put a share of the fee against it. We won't do it on outcomes we don't control, and we'll say so up front rather than write a clause we intend to argue about later.

Talk commercials
How we start

From first call to working software in about 30 days

No six-week procurement theatre before anyone writes anything. Here's the actual path most engagements take - including the parts that depend on you.

Day 0
A 30-minute call

Your problem, your constraints, your deadline. We'll tell you on that call whether we're the right partner - including when the answer is no.

Outcome · a shared read on the problem
Day 3
A shaped brief and an indicative shape

We write back what we heard, the approach we'd take, the engagement model that fits and an indicative cost range. One page, in plain English.

Outcome · brief + indicative range
Day 7
The security and procurement pack

ISO/IEC 27001 certification, our data-handling and sub-processor position, DPA, insurance, MSA and SOW templates - sent before you ask, so your reviewers start early.

Outcome · your reviewers unblocked
Day 10
Named team, signed scope

You meet the exact people who'll do the work and sign a scope that says what “done” means. IP assignment and confidentiality are settled here, not later.

Outcome · SOW signed, pod named
Day 12
Kick-off and environment access

Accounts, repos, boards and data access set up; the pod joins your stand-up; the first sprint is planned with your product owner in the room.

Outcome · sprint 1 planned
Day 30
Working software in your environment

By the end of the first month you're reviewing something real - deployed, testable, with the gate log and evidence trail already running behind it.

Outcome · first increment demoed
What we put in writing

Six commitments that survive the contract

Every partner says they're transparent and accountable. These are the specific, checkable versions of that - the ones we're happy to have written into a statement of work.

You own the IP, from the first commit

Code lands in your repository, in your cloud, under your account - not ours. Assignment is settled in the SOW, not negotiated at handover.

ISO/IEC 27001 controls, on your data

Certified information security management, a signed DPA, GDPR-aligned handling, named sub-processors, and regional data-residency options for UK and EU work.

One accountable lead, named in the contract

A single person owns delivery, escalation and the uncomfortable conversations. If they change, you approve the replacement.

Working software every fortnight

A demo of something running, every two weeks, from the first sprint. If we can't show working software, that's the conversation - not a status update.

Costs you can see coming

Fixed shapes where fixed is possible, spend against plan reported monthly, and a flag the moment an estimate moves - before the work is done, not after.

An exit plan written on day one

Runbooks, architecture decisions, eval suites and a shadowing period are part of the engagement. Leaving well is a deliverable, never a commercial lever.

13+ years

Of shipping software into production environments where compliance, uptime and auditability were baseline requirements - the reason this model exists.

Since 2013 · 200+ clients
~97%

Infrastructure cost reduction on a platform migration we delivered - the kind of outcome that only shows up when engineering discipline survives the whole programme.

Client engagement · see case studies
150+

Engineers, AI specialists, designers and consultants across four regions - enough bench to scale a programme, small enough that you know who's on yours.

US · UK · Europe · Singapore
Common questions

The questions procurement and engineering actually ask

How do you price work?

Discovery and pilots are fixed scope and fixed fee, so you know the number before you start. Ongoing delivery runs as a monthly pod at an agreed blended rate, with 30 days' notice after the initial term. Managed run is a monthly fee against agreed response targets. Where there's a metric we both control, we'll put a share of the fee at risk against it.

Who owns the code and the IP?

You do - from the first commit. Work is done in your repository and your cloud account wherever possible, and IP assignment is written into the statement of work rather than left to handover. Anything we bring that is pre-existing (accelerators, internal libraries) is declared up front, with the licence terms stated in the SOW.

How do you handle our security review?

We send the pack before you ask for it: ISO/IEC 27001 certification, our data-handling position, sub-processor list, DPA, insurance and standard MSA/SOW terms. For regulated work we'll also map the engagement to your control framework and the AI-specific requirements you're facing - EU AI Act obligations, NIST AI RMF alignment, or your own customers' due-diligence questionnaires.

How do you work alongside our existing team or other vendors?

We join your ceremonies, your board and your repository rather than running a parallel process. In mixed-team programmes we'll agree explicit ownership boundaries - who owns which service, who reviews whose pull requests, who signs which gate - because ambiguity, not capability, is what usually breaks multi-vendor delivery.

What happens if the pilot doesn't work?

You get the evidence and the honest recommendation, including “don't build this”. The evaluation thresholds are agreed before we start precisely so the answer is a measurement rather than an argument. We'd rather lose the next phase than ship something you'll have to unpick after an audit.

Do you use AI to write our code - and how do we know it's safe?

Yes, across the lifecycle, and it's a large part of why delivery is fast. It's also why every gate exists: AI-drafted code, tests and documents are reviewed by a named person and held to exactly the same bar as anything hand-written, then put through the same scanning, SBOM and evaluation checks. “The AI wrote it” is never an answer.

What if we want to bring it in-house?

Then we help you do it. Handover is scoped from day one: runbooks, architecture decision records, eval suites, recorded knowledge-transfer sessions and a shadowing period while your team takes over. There is no proprietary runtime you have to keep paying us for.

Start with the smallest thing that proves it

Thirty minutes to test the fit, four weeks to a costed plan, thirty days to working software. Bring the problem - we'll bring the model.

ISO/IEC 27001 certified · Databricks, Snowflake and Claude Partner Network member · US · UK · Europe · Singapore

Keep going

The rest of the company

Where we came from and what it's like inside - the parts of Focaloid that sit behind the delivery model.