Automation

The work nobody was hired to do does not need doing by anyone.

Retyping between two systems that do not talk. Completing files. The same email for the hundredth time. I map where that work sits, establish per step what a model can reliably take over, and build the automation that follows. Within the boundaries the EU AI Act sets — from the first session, not bolted on at the end.

Schedule an intro call

Where does automation start, and what does it actually return?

It starts not with technology but with an honest inventory: which work costs your people time without adding value, and how much of it can a model reliably take over? I answer that in an AI readiness session with your team — not a presentation but a working session in which we walk through processes and decide, step by step, what can be done, what is allowed, and what is better left alone. Out of it comes a prioritised list: what you switch on tomorrow, what we automate, and what only makes sense once something else has been fixed first. That same session doubles as the inventory Article 4 of the AI Act asks of you.

From process analysis to working automation

01

Process analysis

A working session with the people who do the work. We map processes, systems and data sources, establish the risk level per process and record which applications hold promise. You get a priority list with an estimate of time saved per use case — and an explicit list of what I advise against.

02

Building with the right tooling

Internal processes that cross system boundaries — handovers, approvals, data requests, reporting — are set up with whatever fits: Copilot where Microsoft is already your foundation, Claude or another model where that demonstrably works better. Usually a combination, never on the basis of a preference I happen to hold.

03

Oversight and record-keeping

On every link that touches money, customers or the law there is a human who signs off. Who that is, with what authority and with what means is recorded — together with the logging that lets you show afterwards what actually happened. Without it, this is not automation but a risk with a nice interface.

Administration

The work nobody was hired to do.

Reading invoices, retyping data between two systems that do not talk, completing files, drafting standard correspondence. Rarely complicated, always time-consuming, and precisely the work where a well-built automation pays for itself fastest.

Customer Service

First line on duty 24/7, with a human on the final link.

Routing, status updates and answers drawn from an approved knowledge base run through. The moment a reply contains a commitment or touches money, the automation prepares a draft and your colleague decides. And every visitor knows they are talking to AI — that transparency is an obligation, not a choice.

HR

Administration automated, assessment left to people.

Recruitment and selection sits in Annex III of the AI Act: high risk. So we automate the administration around it — vacancy copy, scheduling, status communication, onboarding documents — and never the assessment of candidates. Ranking, scoring or rejecting stays human work.

Sales

Pipeline hygiene on autopilot, the deal with your team.

Lead enrichment, follow-up reminders and progress reporting run independently. Quotes and pricing arrive as drafts with an account manager. Our automations never send out a commitment on their own — that is policy, not a technical limitation.

Marketing

Content at scale, with editorial control that counts.

SEO content, social scheduling and A/B reporting at speed. Every publication passes an editorial review that we record. That is not only quality policy: substantive human editing is exactly what the transparency rules ask of you.

Microsoft where it fits. Something else where that works better.

If your organisation runs on Microsoft 365, Copilot is rarely the wrong starting point: the data is already there, management is arranged and the licence is predictable. Forrester calculated a 353% ROI for the SMB segment with an average of nine hours saved per user per month — but only at organisations that introduced it deliberately. Handing out licences without instruction buys you an expensive search bar. I am certified on Microsoft 365 and Copilot and on Azure, and bring years of experience with complex Power Platform and Dynamics implementations. On that basis I advise what to switch on and what to skip. But I do not sell licences, so I have no reason to talk you into Copilot: where another model demonstrably works better or cheaper — Claude for long documents and complex reasoning, a specialised or self-hosted model where data may not leave the country — I build that instead. Usually the answer is a combination.

Domain-Driven Design

We use DDD to map processes together with your team — and to record, per process step, what an automation may decide on its own and what it may not. The solution follows the logic of your domain, within boundaries you have drawn.

Agentic Framework

The four pillars of your Agentic Solutions

Scalable AI requires more than powerful models — it demands architectural choices that grow with your organisation and with a regulatory regime that is still moving.

01
Scalable Autonomy

Autonomy follows the risk classification

Not every task demands the same freedom. We first establish the risk level of a process — prohibited, high, limited or minimal — and derive the agent's room to act from it. From advisory assistant to autonomous actor, always with a safety net and never with more permissions than the task requires.

02
Built-in Governance

Human oversight that is not a formality

Oversight only works if someone can genuinely exercise it. For every agent we record who supervises, with what authority and with what means: identity-bound permissions, mandatory approval checkpoints, kill switches and rollbacks. The supervisor must be able to detect, override and stop — otherwise oversight exists only on paper.

03
Continuous Observability

Provable, not plausible

Comprehensive logging, real-time alerts and periodic sampling of output. From offline scenario tests to online feedback loops, with logs retained for at least six months. In an audit you do not explain what probably happened — you show what did.

04
Future-proof Flexibility

Designed for shifting ground

The rules move: deadlines shift, prohibitions are added, harmonised standards arrive only gradually. Modular components, model routers and standardised interfaces let you switch model or vendor without rebuilding your architecture — or your conformity file.

Spine5
Methodology

A proven method. For every project.

Spine5 is our proprietary 5-step delivery approach that guarantees structure, transparency and quality — regardless of project size.

Phase 01 1–2 weeks

Insights

Strategy & Discovery

We start with a deep analysis of your business goals, challenges and stakeholders. We align everyone, clarify scope and define the fastest path to measurable outcomes.

We map your current stack, data sources, integrations and operational constraints. Architecture options, success metrics and delivery milestones are locked in — so implementation starts with clear priorities and minimal risk.

What's Included

  • Business requirements analysis
  • Technical architecture planning
  • AI & automation strategy
  • UX direction & user flows
  • Timeline & budget estimation

Key Benefits

  • Reduced development risks
  • Clear project scope
  • Optimised resource allocation
  • Full stakeholder alignment

Ready to start Insights?

Start the discovery
Phase 02 1–3 weeks

Details

Analysis & Modelling

We dive deep into your processes, systems and data sources. Using Domain Driven Design (DDD) we model exact requirements and translate business logic into a solid technical specification.

Every integration point, edge case and acceptance criterion is documented. The result: a detailed technical blueprint with zero surprises during the build.

What's Included

  • Domain Driven Design (DDD)
  • Process modelling & flow diagrams
  • Data architecture & integration map
  • API specifications
  • Acceptance criteria per feature

Key Benefits

  • Zero technical surprises
  • Faster development iterations
  • Lower error rate at delivery
  • Transparent documentation

Ready to start Details?

Discuss your requirements
Phase 03 Weekly sprints

Development

Building with Continuous Feedback

We build iteratively in short 1–2 week sprints. After every sprint you get tangible results and can steer directly. No waiting months for a big-bang release.

Our senior developers work with CI/CD pipelines and automated testing. A live staging environment gives you full visibility and the ability to give real-time feedback.

What's Included

  • Weekly sprint demos
  • CI/CD pipeline & automated tests
  • Live staging environment
  • Senior code reviews
  • Weekly progress reports

Key Benefits

  • Fast time-to-value
  • Fully transparent process
  • Early steering without extra cost
  • High-quality maintainable code

Ready to start Development?

See our approach
Phase 04 1–2 weeks

Testing

Quality Assurance & Validation

Quality assurance is not a phase we skip. We test functionally, technically and on user experience — together with you as the client. Nothing goes live without your approval.

We run automated regression tests, performance load tests and security scans. User Acceptance Tests (UAT) are conducted together with your team to ensure everything works exactly as intended.

What's Included

  • Automated regression tests
  • Performance & load testing
  • Security audit
  • User Acceptance Testing (UAT)
  • Browser & device compatibility

Key Benefits

  • Zero surprises after go-live
  • Proven performance
  • Secure and scalable code
  • Full client validation

Ready to start Testing?

Learn about our quality approach
Phase 05 Ongoing

Production

Go-live, Handover & Support

Go-live is the beginning, not the end. We guide the launch, ensure a smooth handover and provide post-launch support so your team can operate fully independently.

We deliver complete technical documentation, team training and a monitoring setup. We stay available for further development and optimisations as your business grows.

What's Included

  • Guided production deployment
  • Full technical documentation
  • Team training & knowledge transfer
  • Monitoring & alerting setup
  • Post-launch support

Key Benefits

  • Smooth go-live
  • Fully self-reliant team
  • Structural monitoring & insights
  • Long-term partner

Ready to start Production?

Plan your go-live
Compliance by design

The EU AI Act runs through every step of our methodology

Compliance is not a final check that can sink a project late. It is a series of decisions taken — and recorded — at the right moment in Spine5.

  1. Insights

    Risk classification before the first line of code

    We establish which risk category your application falls into and whether any prohibited practices sit in scope. If the process falls under Annex III — recruitment, credit scoring, education, critical infrastructure — you know that at the start of the engagement, not at delivery.

    • Risk classification per use case, recorded with its reasoning
    • Screening for prohibited practices such as social scoring, emotion recognition in the workplace and biometric categorisation
    • Role determination: do you become the provider or the deployer? Put your own brand on a high-risk system or change its intended purpose and you legally become the provider — with every obligation that carries
  2. Details

    Data governance and impact assessment

    In the modelling phase we record which data the agent may see and why. If the application processes personal data at likely high risk, a DPIA belongs with it. Where fundamental rights are touched, a FRIA. We plan both in rather than repair them later.

    • Data governance: origin, quality and representativeness of every source, to prevent bias
    • DPIA under Article 35 GDPR where the processing calls for one
    • FRIA where fundamental rights are affected
    • Least privilege recorded per integration: which agent may touch which system, and how far
  3. Development

    Guardrails in the code, not in the manual

    Prompt injection is no theoretical risk for agents that read emails, documents and websites. A model distinguishes poorly between your instruction and one hidden inside the text it processes. So we defend in layers, knowing full well that no watertight technical fix exists.

    • Instruction isolation: external text is source content, never an instruction that overrides earlier ones
    • Reporting behaviour in the system instruction — on a suspicious instruction the agent halts, quotes the text and asks for human confirmation
    • Output validation for unwanted patterns and leakage of sensitive data, before any user sees the result
    • Trusted sources in RAG: extra caution the moment third-party documents enter the knowledge base
  4. Testing

    Testing what the law tests

    Alongside functional testing, performance and UAT we test on the axes a conformity assessment also covers: risk management, data quality, human oversight, accuracy and cybersecurity. Injection scenarios are part of that as standard.

    • Scenario and red-team testing aimed at prompt injection and agent hijacking
    • Bias and representativeness checks on the datasets in use
    • Validation of the human-machine interface: can the supervisor understand, validate and reverse the output?
    • Technical documentation under Article 11 kept current and complete, covering architecture, logic and data governance
  5. Production

    The file runs with it

    From go-live the system records what it does. Logs, validations and KPIs together form the file with which you demonstrate a human is in the loop. We train your team in AI literacy, because only someone who understands the system and its limits can supervise it.

    • Automatic logging retained for at least six months
    • AI register and validation log as living documents, not a snapshot
    • KPI monitoring and periodic sampling of interactions
    • AI literacy training and a clear escalation path for anyone who spots an error or an injection attempt

Article references are to Regulation (EU) 2024/1689 (the EU AI Act) unless stated otherwise. Article 35 refers to Regulation (EU) 2016/679 (the GDPR). This is a plain-language summary, not legal advice.

European hosting, European rules.

Your data stays in Europe and your AI stays within the lines. We build so that you can prove compliance with the EU AI Act and the GDPR: risk classification up front, human oversight built in, logging from day one. The declaration of conformity remains your signature — we make sure the file underneath it holds up.

Which work costs your team time without returning anything?

Describe the process. I classify the risk and tell you what is allowed, what is possible — and what I would not build.

Schedule an intro call