// IT & data leader
We show up with the architecture and the exit plan.
Sanctioned integration surfaces only. No shadow system. The semantic layer is yours. And a transfer plan written into the first scope, rather than sold to you as a follow-on.
// The situation
Your instinct to run hard diligence is correct.
Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, and estimates only around 130 of the thousands of self-described agentic vendors are genuine.
Gartner · 2026.
The base rate supports the skepticism.
So we publish what you would otherwise have to extract, and we do it before the first call rather than during procurement.
// What we bring to your review
Named in the proposal, not discovered at implementation.
Sanctioned surfaces, named in the proposal
Guidewire Cloud API, Application Events, Integration Gateway, Cloud Data Access. Duck Creek's gateway and its MCP and A2A interfaces. ACORD AL3. If a build requires an unsanctioned surface — direct database reads, RPA, scraping — we say so in the proposal and let you decide. We verify general-availability status before architecting on anything marked early access.
The semantic layer is a deliverable you own
Not a black box we operate. Schema, transformations, tests and documentation live in your repository, run on your infrastructure, and survive our departure. We are measured on your team running it without us.
The governance package, built in
Model inventory with risk tier, data lineage including the provenance of every external source, pre-deployment bias testing and the annual re-test procedure, drift thresholds with remediation triggers, human-override specification, and the vendor-validation record.
Runbook, tests, handover
Monitoring, alerting, retraining procedure, escalation path and an owner named on your side before go-live. Exit criteria are written at kickoff, not negotiated at the end.
// Security posture
Where your data lives.
Everything we build carries role-based access and audit logging. Data stays in your tenancy, and where a step cannot run there we name it in the proposal. The subprocessor list is named and kept current. The data-handling terms are in the master agreement, and we send it before you ask.
We answer a model-governance and explainability questionnaire for anything touching a regulated decision.
The security section →// What's hard about this
Two things we tell you in week two.
Your envelope is already committed.
IT spend runs around 4.6% of direct written premium, and core modernization consumes more than half of it at large carriers. Any honest proposal scopes to what the remaining envelope actually funds — and part of Discovery is telling you what to stop doing, including when a capability is arriving in your core vendor’s release notes and you should wait for it.
If the loss data is on the legacy stack, that is the first project.
AS/400, DB2, COBOL. Getting at it comes before anything a model does with it. It is not glamorous and it is not fast. Every proposal that skips that step is scoped on the new system only, or it is wrong. So we scope it first and price it before you fund the part you actually wanted.
Read the architecture before the case study.
Everything a security review, a general counsel and a procurement committee will ask for, on one page.