Skip to workshop content

Enterprise AI: From Experiments to Governed Value

01 / 24

ENTERPRISE AI WORKSHOP

Enterprise AI: From Experiments to Governed Value

01/24
Agentic systems, controls, architecture, and a practical path to measurable adoption
FOR LEADERS • ARCHITECTS • OPERATORS • RISK TEAMS
Presented by Emile du Toit • BrainIT Consulting
AI
Your Team

PERSPECTIVE

Perspective and experience

02/24
Enterprise architecture experience combined with current, hands-on AI product delivery.
30+
YEARS IN TECHNOLOGY,
ARCHITECTURE & PRODUCT DELIVERY
Former GTE and Verizon systems architect and technical manager
ANTHROPIC CERTIFIED DEVELOPER
1
PLATFORM
Architect of Verizon’s least-cost-routing platform
MIGRATION
Led its zero-downtime platform modernization
3
FOUNDER
BrainIT Consulting
4
BUILDER
Creates agentic applications and automation systems

OUTCOMES

What this workshop should enable

03/24
A shared language for moving from opportunity to governed operation.
1
FRAME
Where AI is useful—and where it is not
2
DISTINGUISH
Copilots, automation, and agents
ARCHITECT
A controlled enterprise pattern
4
GOVERN
Risk tiers, approvals, and accountability
5
EVALUATE
Quality, safety, and business outcomes
6
PRIORITIZE
Use cases by value and readiness
7
PILOT
A bounded production-shaped experiment
8
SCALE
Operating model, change, and ownership

FOUNDATIONS

An LLM predicts language—not truth

04/24
Enterprise reliability comes from the surrounding system, not the model alone.
LLM
A probabilistic component that can interpret, generate, classify, summarize, and reason over language-shaped work.
FLUENT ≠ VERIFIED
STRONG FIT
Synthesis across documents
Drafting and transformation
Classification and extraction
Interactive explanation
SYSTEM MUST ADD
Authoritative data access
Identity and permissions
Deterministic controls
Evaluation and audit evidence

OPERATING PATTERNS

Copilot, workflow automation, or agent?

05/24
Choose the least autonomous pattern that can deliver the outcome.
COPILOT
Suggests or drafts
Human drives every step
Low autonomy
High interaction
Easy review
WORKFLOW AUTOMATION
Executes predefined logic
Known path; exceptions escalate
Deterministic path
Repeatable volume
Clear rules
AI AGENT
Plans and adapts
Selects approved actions from feedback
Variable path
Tool use
Explicit stop conditions

AGENTIC SYSTEMS

The agentic loop—with control points

06/24
Goal → Plan → Act → Observe → Evaluate → Continue, Escalate, or Stop
1
GOAL
Outcome + owner
2
PLAN
Steps + policy
3
ACT
Approved tool
4
OBSERVE
Result + evidence
5
EVALUATE
Quality + risk
DECIDE
Continue / escalate
POLICY
What is permitted?
EVIDENCE
What proves success?
APPROVAL
Who decides at consequence points?

ARCHITECTURE

A practical enterprise reference architecture

07/24
Keep models replaceable; keep controls, evidence, and authoritative data under enterprise ownership.
CHANNELS
Employee apps • customer portals • APIs
ORCHESTRATION
Prompting • workflow • agent state • routing
CONTROL PLANE
Identity • policy • approvals • budgets • secrets
MODEL & TOOL GATEWAY
Models • retrieval • enterprise APIs • automation
SYSTEMS OF RECORD
ERP • CRM • content • data platforms • logs
Cross-cutting evidence: telemetry • evaluation results • lineage • audit trail

USE-CASE PORTFOLIO

Enterprise value appears across functions

08/24
Prioritize workflows with repeated language work, reviewable outputs, and accessible evidence.
1
CUSTOMER OPERATIONS
Case summaries • response drafts • next-best actions
2
SALES & SERVICE
Account research • proposal analysis • call preparation
3
IT OPERATIONS
Incident triage • runbook assistance • change review
4
SOFTWARE DELIVERY
Code review • test design • documentation • migration support
5
KNOWLEDGE WORK
Search • synthesis • policy Q&A • document comparison
6
CORPORATE FUNCTIONS
Finance narratives • procurement review • HR knowledge

PORTFOLIO DECISIONS

Prioritize by value, risk, and readiness

09/24
A compelling demo is not the same as a deployable use case.
USE-CASE SCORECARD
1
BUSINESS VALUE
Frequency • time • quality • revenue
2
RISK
Consequence • reversibility • sensitivity
3
DATA READINESS
Access • quality • permission • lineage
4
PROCESS READINESS
Owner • stable steps • exception path
5
ADOPTION READINESS
Users • incentives • training • support
PORTFOLIO POSITION
VALUE →
READINESS →
START
SHAPE
LEARN
DEFER

DATA • SECURITY • PRIVACY

Data boundaries are architectural requirements

10/24
Define what may enter, what may leave, and what may be retained before connecting a model.
PUBLIC
Approved public information
Lowest sensitivity
INTERNAL
Business information not for public release
Controlled access
CONFIDENTIAL
Customer, financial, strategic, or regulated data
Explicit safeguards
RESTRICTED
Secrets, credentials, high-impact or prohibited data
Block or isolate
BOUNDARY QUESTIONS
Which data classes are allowed?
Where is content processed and retained?
Can providers train on or reuse data?
How are prompts, outputs, and tool calls logged?
How are deletion, residency, and legal holds handled?
What is the incident and vendor-exit path?

IDENTITY & ACCESS

Agents need identities, permissions, and budgets

11/24
Treat an agent as a non-human actor—not as an all-access employee.
1
NAMED IDENTITY
Every runtime and tool call is attributable
2
LEAST PRIVILEGE
Only the minimum data and actions required
3
SCOPED CREDENTIALS
Short-lived, purpose-bound, revocable secrets
4
SEPARATION OF DUTIES
High-consequence steps require independent approval
5
TRANSACTION LIMITS
Rate, spend, volume, and time boundaries
6
EMERGENCY STOP
Fast disablement with preserved evidence
PERMISSION = identity + approved resource + allowed action + limits + evidence

AI GOVERNANCE

Governance should scale with consequence

12/24
Apply stronger evidence and approval requirements as impact and autonomy increase.
TIER 1
Assistive
Drafts, summaries, internal search
EVIDENCE
User review
ACCOUNTABLE
Business owner
TIER 2
Operational
Workflow recommendations and bounded tool use
EVIDENCE
Control testing
ACCOUNTABLE
Product + risk owner
TIER 3
High impact
Material customer, employee, financial, or regulated outcomes
EVIDENCE
Independent approval
ACCOUNTABLE
Executive risk authority

EVALUATION

Evaluate the system, not just the model

13/24
Quality must be measured against real tasks, policies, and business outcomes.
1
TASK QUALITY
Correctness • completeness • relevance
2
GROUNDING
Traceability to approved sources
3
TOOL BEHAVIOR
Correct action • parameters • sequencing
4
SAFETY & POLICY
Refusal • escalation • prohibited actions
5
ROBUSTNESS
Edge cases • ambiguity • degraded dependencies
6
BUSINESS OUTCOME
Cycle time • rework • adoption • impact
Baseline before launch • evaluate changes before release • sample production continuously

OPERATIONS & AUDITABILITY

If you cannot reconstruct it, you cannot govern it

14/24
Observability connects technical events to business decisions and accountable owners.
ONE DECISION TRAIL
1
User or system request
2
Context and source versions
3
Model and configuration
4
Tool calls and returned evidence
5
Policy checks and approvals
6
Final output and downstream result
RELIABILITY
Latency and failure rate
Dependency health
Fallback behavior
RISK
Policy violations
Approval bypass attempts
Sensitive-data events
VALUE
Usage and completion
Time and rework
Outcome movement
CHANGE
Prompt / model / tool versions
Evaluation deltas
Release owner

DELIVERY STRATEGY

Buy, build, or extend?

15/24
Decide by strategic differentiation, integration depth, control needs, and operating capacity.
BUY
Commodity capability
Fastest path when workflow and controls fit
Vendor assurance
Configuration
Exit plan
EXTEND
Enterprise platform + custom workflow
Useful middle ground for integration and governance
Owned orchestration
Enterprise connectors
Shared controls
BUILD
Differentiating process or product
Justified when advantage and control outweigh lifecycle cost
Product ownership
Evaluation discipline
24×7 operations

PILOT DESIGN

Design a production-shaped pilot

16/24
A pilot should test the riskiest assumptions without pretending to be production.
1
OUTCOME
One measurable business result
2
OWNER
Named process and risk owners
3
BOUNDARY
Limited users, data, and actions
4
BASELINE
Current cost, quality, and cycle time
5
EVIDENCE
Test set, logs, reviews, incidents
6
EXIT
Scale, revise, stop, or retire
TIME-BOXED • REVERSIBLE • REVIEWABLE

OPERATING MODEL

Scale with a federated operating model

17/24
Centralize reusable guardrails; keep outcomes and adoption close to the business.
ENABLEMENT CORE
Reference architecture
Security and policy patterns
Shared evaluation platform
Vendor and model standards
Reusable connectors
Training and community
1
BUSINESS PRODUCT TEAM
Owns outcome, process, adoption, and backlog
2
RISK & ASSURANCE
Sets thresholds; reviews evidence and exceptions
3
PLATFORM & OPERATIONS
Runs shared services, telemetry, reliability, and support
4
DATA & KNOWLEDGE
Owns authoritative sources, access, quality, and lineage

CHANGE & WORKFORCE

Adoption is workflow redesign—not tool rollout

18/24
People need clarity about what changes, what remains human, and how success will be judged.
WITHOUT CHANGE DESIGN
Unclear ownership
Shadow experimentation
Inconsistent review
No shared evidence
WITH CHANGE DESIGN
Named process owner
Approved working pattern
Role-specific review
Visible outcome metrics
TRAIN
role + scenario + escalation
SUPPORT
feedback + incident + improvement

VALUE & ECONOMICS

Build the business case from a measured baseline

19/24
Separate productivity claims from realized enterprise value.
Δ TIME
Cycle time per case
Δ QUALITY
Errors, rework, consistency
Δ CAPACITY
Throughput and backlog
Δ OUTCOME
Revenue, cost, risk, service
TOTAL COST
Licensing and model usage
Integration and data work
Evaluation and assurance
Operations, support, and change
REALIZED VALUE
Usage × task frequency
Measured improvement vs baseline
Adoption and exception rates
Risk-adjusted outcome over time

CONTROLLED DEMONSTRATION

Use Hermes as a controlled enterprise sandbox

20/24
A practical way to demonstrate the complete agentic loop with explicit tool and file boundaries.
H
HERMES
1
ISOLATE
Dedicated working folder
2
DISCOVER
List available tools first
3
CONSTRAIN
Copies or synthetic data
4
APPROVE
No external action by default
5
VERIFY
Read outputs back
6
RETAIN
Prompt, files, and evidence
“Before acting, list your available tools and confirm the boundaries.”

ENTERPRISE EXERCISE

Practical prompt: vendor proposal review

21/24
Turn source documents into a traceable comparison without inventing missing information.
“Act as a procurement analysis assistant. Compare the vendor proposals I provide using only those documents and the evaluation criteria I provide.”
ANALYZE • CITE • ESCALATE
Do not select a vendor or contact anyone.
1
Extract commercial terms
2
Map requirements to evidence
3
Identify assumptions and exclusions
4
Flag conflicting claims
5
Score only defined criteria
6
Cite source pages or sections
7
List unanswered questions
8
Prepare decision brief for review
proposal_matrix.xlsx • open_questions.md • decision_brief.md

ENTERPRISE EXERCISE

Practical prompt: incident analysis package

22/24
Use evidence to prepare an accountable review—without changing production systems.
“Act as an incident-analysis assistant. Use only the timeline, logs, tickets, and change records I provide.”
Do not execute commands, change tickets, or assign blame.
EVIDENCE • UNCERTAINTY • ACTION
1
Build timestamped timeline
2
Separate facts from hypotheses
3
Identify missing evidence
4
Map contributing conditions
5
Draft impact statement
6
Propose corrective actions
7
Assign owners only if provided
8
Create review package and verify
incident_timeline.csv • analysis.md • corrective_actions.md

NEXT STEPS

A practical 90-day enterprise path

23/24
Move from alignment to evidence to a controlled scale decision.
0–30
ALIGN
Name sponsor and owners
Select 2–3 use cases
Define risk tier and baseline
Agree architecture and data boundary
31–60
PILOT
Build one bounded workflow
Create evaluation set
Run with limited users
Capture incidents and feedback
61–90
DECIDE
Compare against baseline
Review controls and operating cost
Plan scale, revise, or stop
Publish reusable patterns

E

Questions and discussion

24/24
Emile du Toit
If you would like an independent view of an AI use case, architecture, governance approach, or pilot design, you are welcome to reach out.
Bring the business outcome, workflow, and constraints. The first step is deciding whether AI is justified—and what evidence would make that decision defensible.
CONTACT
EMAIL
dutoit.emile@gmail.com
PHONE
+1 (972) 900-6286
CONSULTING
brainitconsulting.com
PORTFOLIO
brainitconsulting.com
RESOURCES
brainitconsulting.com