Who it fits

Enterprise / listed

300+ people · governance, PDPA and a company-wide roadmap

The questions to answer first, not what AI can do

At this size the blocker is rarely the technology. It is how far data may travel outside the organisation, who can access what, whether it can be checked afterwards, and how you go from one unit to the whole organisation with a single standard.

This is probably you if…

Business size: 300+ people / listed company

  • Every project has to clear a security review and PDPA before it starts
  • Some data must never leave the organisation
  • You need an audit trail and per-person access rights
  • You want one common standard, not every team buying its own tool

What it takes from your team

Who has to be involved

The process owner + IT/Security + Legal/DPO from the start, not as a review at the end.

Documents we prepare

Data-flow architecture, risk assessment, NDA/DPA

How it can be built

A model through a contracted API, or a model running inside the organisation (private LLM), by data tier.

What the first 30 days look like

Not a months-long project before you see anything — every step hands over something real

Step 1 / 3 · Set the data scope and access rights first

First week

01First week

Set the data scope and access rights first

Which data tiers stay in-house and which may use an external model — written down before anyone touches a system.

02Months 1–2

Pilot in one unit

Pick a job with measurable results and low risk, and take it through the security team's real review.

03Next quarter

Set the standard, then scale

Approval templates, usage rules and reporting, before the next unit comes on.

A sample of the output at this size

What your team will be looking at every day once it is set up

Audit logEvery action traceable

09:12 · agent drafted quote #4821 (using tier 2 data)

09:14 · sales manager approved — discount changed 5% → 3%

09:14 · emailed to the customer + logged in the CRM

09:20 · request for tier 3 data denied by the user's access rights

Data tiers set before any model runsSample policy
Tier 1 · publicExternal models allowed
Tier 2 · general internalAllowed under contract, never used for training
Tier 3 · sensitive / PDPARuns in-house only

The system enforces the tiers automatically, it does not rely on user discipline

Mock sample — names and numbers are made up. The real one follows your business.

How the cost is worked out

We do not set a price before we know what the work really is — but here is how we work it out, so you can estimate

  • Priced by phase: assess → pilot → scale, each phase with a defined scope and clear pass criteria
  • No lock-in — models and vendors can be swapped, the data and the workflows belong to the organisation
  • Contract details, SLA and long-term support are agreed per organisation

Want the numbers for your own business? Book a free 30-minute call and we will estimate from the work you describe.

In the same section

Want to know whether this fits your business? Book a free 30-minute call

No cost, no commitment — tell us how the work really runs and we will point out where starting pays off most

Free consultation

Book a free call 30 minutes