Approach

The GIST Framework

How we deliver data and AI work.

Every engagement runs the same way. We agree on the business decision the work will improve, build in short cycles on real data with AI doing much of the engineering under our review, deploy early, and build the controls as we go.

Why we work this way

Data and AI projects are not software projects.

GISTTHE DECISIONat the center

Standard agile assumes a known requirement and software that either works or does not. In data and AI, the requirement gets clearer as you learn the data, the output is a prediction whose quality has to be measured, and much of the engineering is done by AI that needs review like a person.

GIST keeps agile's short cycles and working software and changes the rest to fit.

The four steps

Ground. Iterate. Ship. Trust.

Every increment goes through all four, with Trust running throughout.

Ground

Agree on the decision and check the data.

We write a one-page Decision Brief: the decision the work will improve, who owns it, how we will measure it, and what it is worth. In parallel we profile the real data, draft data contracts with source owners, and list the security and compliance requirements so they shape the design.

Practices

  • A Decision Brief for every piece of work
  • Automated profiling and lineage discovery on every data source in scope
  • Data contracts agreed with source owners before we build pipelines
  • A list of security, privacy, and compliance requirements on day one

Iterate

Build in short cycles on real data.

Each fixed-length cycle delivers one thin slice that runs end to end, from source data to where the decision gets made. AI coding agents draft code, tests, and documentation; our people set direction and review every change. Each cycle ends with an Evidence Review of the working increment, its test results, and its cost.

Practices

  • One end-to-end slice per cycle: source data, transformation, and the point of use
  • AI coding agents for scaffolding, tests, documentation, and refactoring, with human review on every change
  • Automated evaluation tests from the first cycle onward
  • An Evidence Review at the end of every cycle instead of a demo

Ship

Deploy to production early and often.

We deploy from the first cycle, behind feature flags, in shadow mode, or to a small group of users, with monitoring and rollback in place. The Decision Owner sees results in their own workflow. Wider releases wait until the evaluation thresholds agreed in Ground are met.

Practices

  • Continuous delivery for pipelines, models, and prompts, gated by evaluation thresholds
  • Shadow and canary releases before full rollout
  • Monitoring for data freshness, drift, quality, and cost before launch
  • A runbook and a named on-call owner for every increment

Trust

Build the controls as you go.

Governance runs in every cycle. We write controls as code wherever we can, and every model, prompt, and agent in production has an owner, an evaluation record, a written scope, and an off switch. The Control Register stays current, so the evidence exists before anyone asks for it.

Practices

  • Access policies, quality gates, and retention rules enforced in the platform as code
  • An Evaluation Card for every model, prompt, and agent: purpose, data, metrics, known limits, owner
  • Least-privilege permissions for AI agents, the same as for people
  • A Control Register updated every cycle
Compared with standard agile

What is different.

Standard agileFeature backlogGISTDecision backlogWhyWork is organized by the business decision it improves, so we do not build pipelines and models nobody acts on.
Standard agileDefinition of doneGISTDefinition of trustedWhyAn increment is finished when it runs on real data, passes its evaluation tests, is monitored, and has an owner. Working code alone is not finished.
Standard agileSprint demoGISTEvidence ReviewWhyWe show test results and cost alongside the working software, because the output of a model has to be measured, not just shown.
Standard agileGovernance review before releaseGISTGovernance in every cycleWhyControls are built as code and checked every cycle, so there is no separate compliance gate to get through before launch.
Meetings

Five meetings, each with a purpose.

Each one produces a decision or a piece of evidence.

Framing session Start of the engagement
We meet with the Decision Owner and your governance lead to agree on the Decision Brief and the required controls.
Cycle planning Start of every cycle
We choose the slice for this cycle, confirm how it will be evaluated, and assign work to people and to AI agents.
Daily check-in Every working day, short
Blockers, code reviews waiting, and anything monitoring or the agents flagged overnight.
Evidence Review End of every cycle
We show the increment running on real data, with its test results, cost, and open risks. The Decision Owner decides whether it goes to more users.
Retrospective End of every cycle
What worked and what did not, based on delivery metrics, evaluation trends, and spend.
Roles

Who is involved.

  • Decision Owner

    Your business leader whose decision the work improves. Signs the Decision Brief and approves wider releases.

  • Delivery Lead

    Ours. Runs the cycles, owns the evaluation tests, and is accountable for every increment meeting the definition of trusted.

  • Data and AI Engineers

    Ours, often working alongside yours. Build each slice with AI agents, review every agent contribution, and own production quality.

  • Governance Partner

    Keeps the Control Register and Evaluation Cards current. Represents security, privacy, and compliance in every cycle.

Documents

What you receive.

  • Decision Brief

    One page: the decision, its owner, how success is measured, value, and risk.

  • Data Contract

    Schema, quality expectations, ownership, and change rules for each data source.

  • Evaluation Card

    Purpose, data, metrics, thresholds, known limits, and owner for every model, prompt, and agent.

  • Control Register

    The list of controls in place, how each is enforced, and the evidence it produces.

  • Runbook

    How the increment is operated, monitored, rolled back, and handed to your team.

AI agents on the team

How we control the AI that works for us.

Every AI agent we use has a named owner, a written scope, the minimum permissions it needs, and a log of everything it does. Its work gets the same code review as a person's. It cannot deploy to production, widen its own permissions, or touch data outside its contract, and if it fails an evaluation we remove it. That is how we use AI heavily and stay accountable for every result.

See how this would work for you.

Tell us the business decision you want to improve. We will draft the Decision Brief and describe the first increment.

Start a conversation