Free download · reference model · no email required

Become AI-native by design—
not by accident.

Most AI programs stall at pilots. This free, five-document reference model shows owners and executives of 1–500-person organisations what to build, in what order, under which controls, and how to prove the value—without the hype.

Document 01 · target architecture

Models propose. Controlled services transact.

The architecture document answers the hardest question first: what sits between a model and a business transaction? A six-plane reference model wraps a governed execution fabric around the SaaS systems you already run—without replacing them.

the six planes

One architecture, every workflow

Experience & collaboration; workflows, agents & action control; models, context & evaluation; data, knowledge & integration—with identity, security and governance cutting across all of it. Sized for 1–20, 21–100 and 101–500-person organisations, with Google- and Microsoft-anchored reference stacks.

the safety boundary

Model output is not a transaction

Models emit typed proposals. Deterministic policy checks, authenticated approvals and an idempotent executor decide what actually reaches your ledger, your CRM, or your customers. Systems of record stay authoritative—always.

execution modes are assigned per action class—and earned

T0 · retrieve

Read permitted sources; search, classify, summarise. No writes.

T1 · draft

Produce the draft or recommendation; a person independently commits it.

T2 · act with approval

Execute the exact typed action an authorised person approved.

T3 · bounded autonomy

Exceptional: narrow, reversible, low-impact actions inside hard limits, continuously monitored.

Includes the 18 architecture decisions every adopter must record—so the model becomes your model, on the record.

Download document 01 target operating & technology architecture · markdown · 45 KB

Document 02 · phased implementation plan

Four phases. Every gate is evidence, not a date.

The plan runs up to 24 months, calibrated to readiness and risk—a small firm may reach its steady state in 6–12. Each phase must earn the next: baselines before build, evaluation before reliance, sustained evidence before autonomy.

  1. Establish control and evidence
  2. Governed augmentation
  3. Controlled execution
  4. Institutionalise & selectively automate

a portfolio, not a parade of pilots

Select, gate, and kill workflows

A weighted selection framework, a reference catalogue of 15 starter workflows with control ceilings, and kill criteria agreed before anything is built. A workflow can be retired at any gate—failed experiments stop consuming licences.

start monday morning

The first 90 days, step by step

Appoint the owners, inventory the AI already in the building, fix identity and sharing basics, baseline 10–20 task families, and ship one or two low-risk workflows through evaluation and shadow mode—then hold the first evidence gate.

With readiness assessment, resourcing and budget guardrails by company size—calendar progress never substitutes for gate evidence.

Download document 02 phased implementation plan · markdown · 39 KB

Document 03 · data, security & AI governance

Stay in control—without building a bureaucracy.

Governance exists to make useful adoption repeatable and safe. The governance document keeps control effort proportional to consequence: a policy and register set an SME can actually run, mapped to current OWASP, NIST and ISO practice.

  1. accountability is named

    Every sanctioned AI system, data source and production workflow has a business owner and an operational owner.

  2. the model never authorises itself

    Deterministic policy and transaction controls sit between model reasoning and any side effect.

  3. data is purpose-bound

    A four-level classification, permission hygiene, minimisation and retrieval controls—credentials never enter a prompt.

  4. oversight is meaningful

    Approvers have competence, context, authority, time and a practical way to intervene—no rubber stamps.

  5. threats are mapped

    Controls for prompt injection, tool misuse, data poisoning and runaway cost, aligned to the OWASP LLM and agentic Top 10.

  6. incidents improve the system

    No-blame reporting, containment authority, drills—and 2026 legal watchpoints for Australia and the EU.

Registers, intake templates and checklists included—a spreadsheet is acceptable; keeping it current is the control.

Download document 03 data, security & AI governance · markdown · 43 KB

Document 04 · benefits realisation

Capacity is not cash. Count both—once.

The benefits document is the discipline most AI programs skip: baselines before business cases, capacity and cash in separate ledgers, benefits banked only when a bill, contract, licence or planned hire actually changes—and the full cost of ownership counted, not just the licences.

separate ledgers

Time saved is not money saved

Hours released are reported as capacity and allocated once—to growth, quality, or a documented workforce route. They become cash only through evidenced conversion: reduced external spend, avoided hiring, retired software. Finance co-signs what gets banked.

a worked example

The honest 100-person P&L

A fully worked example with conservative, base and stretch cases—including a plausibly negative Year 1. Plus fifteen benefit claims a finance team should reject on sight, starting with “minutes saved × every employee”.

Published productivity effects span roughly −20% to +35% depending on task, user and process fit. The guide refuses to plant a generic number in your business case—it shows you how to earn your own.

Download document 04 benefits realisation · markdown · 26 KB

Free download · no email required

Take the whole model with you.

Plain markdown, deliberately. Version it, redline it, ground your own AI assistant on it—the model is only useful once it becomes yours. Document 00 orients the set and includes a minimum viable pattern for firms of 1–20 people.

the complete set

All five documents, one file

The full reference model in a single markdown file—easy to read, search, print, or share with your board.

Download the complete set markdown · 175 KB · ~24,500 words

Written for organisations of 1–500 people on ordinary SaaS estates. Grounded in current good practice as at August 2026—NIST AI RMF, ISO/IEC 42001, OWASP LLM & agentic Top 10, ASD guidance and the EU AI Act timeline—a reference model you adapt and own, not legal advice.