Approach

The GIST Framework

How we deliver data and AI work.

We run every engagement the same way. We agree on the business decision the work will improve. We build in short cycles on real data, with AI doing much of the engineering under our review. We deploy to production early. We build security and compliance controls as we go instead of reviewing for them at the end. We call this GIST: Ground, Iterate, Ship, Trust.

GISTTHE DECISIONat the center
Why we work this way

Data and AI projects are not software projects.

Standard agile assumes you know the requirement and the software either works or it does not. Data and AI work is different. The requirement is a business decision that gets clearer as you understand the data. The output is a prediction or a generated answer whose quality has to be measured. And much of the engineering is now done by AI, which needs the same review and permissions as a person.

GIST keeps the short cycles and working software from agile and changes the rest to fit that reality. It is how we run every engagement.

The four steps

Ground. Iterate. Ship. Trust.

Every increment goes through all four. Trust runs alongside the other three throughout. Here is what happens in each step and what the AI agents do.

Ground

Agree on the decision and check the data.

We write a one-page Decision Brief. It names the business decision the work will improve, who owns that decision, how we will measure improvement, and what it is worth. At the same time, we profile the actual data, not the documentation, and draft data contracts with the people who own each source. We also list the security, privacy, and compliance requirements up front so they shape the design.

Practices

  • A Decision Brief for every piece of work
  • Automated profiling and lineage discovery on every data source in scope
  • Data contracts agreed with source owners before we build pipelines
  • A list of security, privacy, and compliance requirements on day one

Iterate

Build in short cycles on real data.

We work in fixed-length cycles. Each cycle delivers one thin slice that runs end to end, from source data to the screen or system where the decision gets made. Our engineers work with AI coding agents that write scaffolding, tests, documentation, and first drafts. Our people set direction and review every change. We build automated evaluation tests in the first cycle and run them in every cycle after. Each cycle ends with an Evidence Review: the working increment, its test results, and its cost.

Practices

  • One end-to-end slice per cycle: source data, transformation, and the point of use
  • AI coding agents for scaffolding, tests, documentation, and refactoring, with human review on every change
  • Automated evaluation tests from the first cycle onward
  • An Evidence Review at the end of every cycle instead of a demo

Ship

Deploy to production early and often.

We deploy from the first cycle, behind feature flags, in shadow mode, or to a small group of users. We automate the release process early so that deploying is routine. Monitoring, alerting, and rollback are part of every increment. The Decision Owner sees results in their actual workflow, not in a presentation. Releases to wider audiences are gated by the evaluation thresholds agreed in Ground.

Practices

  • Continuous delivery for pipelines, models, and prompts, gated by evaluation thresholds
  • Shadow and canary releases before full rollout
  • Monitoring for data freshness, drift, quality, and cost before launch
  • A runbook and a named on-call owner for every increment

Trust

Build controls as you go, not at the end.

Governance runs in every cycle, not as a review at the end. We write controls as code and tests wherever possible. Every model, prompt, and agent in production has a named owner, an evaluation record, a written scope of what it may do, and a way to switch it off. We keep a Control Register current so that when a regulator, auditor, or customer asks how a decision was made, the evidence already exists.

Practices

  • Access policies, quality gates, and retention rules enforced in the platform as code
  • An Evaluation Card for every model, prompt, and agent: purpose, data, metrics, known limits, owner
  • Least-privilege permissions for AI agents, the same as for people
  • A Control Register updated every cycle
Compared with standard agile

What is different.

Standard agileFeature backlogGISTDecision backlogWhyWork is organized by the business decision it improves, so we do not build pipelines and models nobody acts on.
Standard agileDefinition of doneGISTDefinition of trustedWhyAn increment is finished when it runs on real data, passes its evaluation tests, is monitored, and has an owner. Working code alone is not finished.
Standard agileSprint demoGISTEvidence ReviewWhyWe show test results and cost alongside the working software, because the output of a model has to be measured, not just shown.
Standard agilePeople write and review codeGISTAI writes, people review and decideWhyAI agents do much of the engineering, with the same permissions and code review as our engineers. People keep judgment and accountability.
Standard agileGovernance review before releaseGISTGovernance in every cycleWhyControls are built as code and checked every cycle, so there is no separate compliance gate to get through before launch.
Meetings

Five meetings, each with a purpose.

Cycles are short and fixed in length. Each meeting produces a decision or a piece of evidence.

Framing session Start of the engagement
We meet with the Decision Owner and your governance lead to agree on the Decision Brief and the required controls.
Cycle planning Start of every cycle
We choose the slice for this cycle, confirm how it will be evaluated, and assign work to people and to AI agents.
Daily check-in Every working day, short
Blockers, code reviews waiting, and anything monitoring or the agents flagged overnight.
Evidence Review End of every cycle
We show the increment running on real data, with its test results, cost, and open risks. The Decision Owner decides whether it goes to more users.
Retrospective End of every cycle
What worked and what did not, based on delivery metrics, evaluation trends, and spend.
Roles

Who is involved.

  • Decision Owner

    Your business leader whose decision the work improves. Signs the Decision Brief and approves wider releases.

  • Delivery Lead

    Ours. Runs the cycles, owns the evaluation tests, and is accountable for every increment meeting the definition of trusted.

  • Data and AI Engineers

    Ours, often working alongside yours. Build each slice with AI agents, review every agent contribution, and own production quality.

  • Governance Partner

    Keeps the Control Register and Evaluation Cards current. Represents security, privacy, and compliance in every cycle.

  • AI Agents

    Software agents on our team with limited permissions and full logging. They profile, build, test, evaluate, and monitor. They cannot deploy to production or change their own permissions.

Documents

What you receive.

  • Decision Brief

    One page: the decision, its owner, how success is measured, value, and risk.

  • Data Contract

    Schema, quality expectations, ownership, and change rules for each data source.

  • Evaluation Card

    Purpose, data, metrics, thresholds, known limits, and owner for every model, prompt, and agent.

  • Control Register

    The list of controls in place, how each is enforced, and the evidence it produces.

  • Runbook

    How the increment is operated, monitored, rolled back, and handed to your team.

AI agents on the team

How we control the AI that works for us.

Every AI agent we use has a named human owner, a written scope, minimum necessary permissions, and a log of everything it does. Its work goes through the same code review as a person's. It cannot deploy to production, expand its own permissions, or access data outside its contract. If it fails an evaluation, we remove it. This is what lets us use AI heavily and still be accountable for every result.

See how this would work for you.

Tell us the business decision you want to improve. We will draft the Decision Brief and describe the first increment.

Start a conversation