1. Screening and baseline
The first meeting produces a one-page problem definition. Confirm the process owner, monthly volume, sample data, current errors and handling time. Development starts only after the baseline is accepted in writing.
2. Pilot design
Select one process, a small number of data sources, an explicit permission matrix and a bounded test set. Document exclusions, third-party costs, stop conditions and success criteria.
Automatic payment, binding agreements, bank-detail changes and critical production control remain outside the first pilot.
3. Shadow mode and controlled use
The system recommends while employees continue the official process. Classify errors, then enable only the approved narrow transaction group after critical tests pass.
Training, support hours, rollback and incident ownership are part of go-live—not optional extras.
4. Value reconciliation and expansion
Review realised value, adoption, error rates and support load together each month. Open the next process only when the current module is both safe and economically sound.
- No outcome fee without verified benefit
- No expansion after a critical security incident
- Separate written approval for added scope
- Return, deletion and access revocation on exit