How We Work | OpenKit AI Engagement Principles

How we
work.

Getting AI running takes an afternoon. Keeping it safe is the work.

Anyone can connect Claude or ChatGPT to a company login in an afternoon. The hard part is the part nobody sees: keeping it secure, maintained, and not quietly leaking your data into a tool no one signed off on.

OpenKit is a UK AI consultancy of working engineers, not advisers. These are the principles we build by, and why a careful CTO can hand us the keys.

ISO 27001 · ISO 9001 · Cyber Essentials · GDPR · Cambridge, working across the UK

Six principles, in order.

A careful AI rollout is mostly about sequence and restraint. These are the defaults we hold to on every engagement, before anyone writes a line of code.

01

Start where the risk is lowest

Big AI builds fail quietly because they start with the riskiest system. We begin with a fixed-scope audit, then configure workflows on the stack you already run.

You get a strategy roadmap that names the top opportunities, what to start in Claude today, and where a build is genuinely warranted.

Maps to: the AI audit and transformation block

RISK ↑ VALUE → Drafting Summaries Intake Bespoke build scope after audit → start here
02

One senior lead, start to finish

Handoffs are where AI projects lose their context and their nerve. The senior engineer who runs your audit is the same one who stays on as your embedded AI lead.

No account-manager layer sits between you and the person doing the work. You talk to the engineer, every week.

Maps to: the embedded AI lead

OPENKIT vs. THE HANDOFF MODEL AUDIT BUILD LEAD Same engineer, the whole way through Sold by one team, built by another, run by a third
03

Working software, not slide decks

A strategy PDF is easy to write and impossible to use. The audit ends with workflows running against your data and your team trained to drive them.

We would rather show you one working thing than describe ten. The roadmap exists to point at the next working thing.

Maps to: every engagement, by default

strategy.pdf /summarise intake → running · against your data
04

Your data stays yours

The fear is real: connect AI to company data, and a leak becomes your name on the incident report. We design the guardrails first, so nothing leaves the boundary you set.

Access stays role-based, prompts and responses are logged, and the data protection review runs against ISO 27001 from day one.

ISO 27001 · Cyber Essentials · GDPR

YOUR BOUNDARY Company data M365 · DBs · docs Role-based access partner · assoc AI workflow private · UK AUDIT LOG · prompt · response · user · timestamp no leak
05

Document everything we build

A consultancy that hides the how is selling dependence. We write down every workflow, so your team can author their own once we step back.

The audit ships with a workflow-authoring walkthrough and recorded sessions. Continuing with us should be a choice, not a trap.

Maps to: the embedded AI lead and handover

WORKFLOW workflow.md your team can author next OPENKIT YOUR TEAM
06

Build bespoke only when it earns its place

Most problems are solved by configuring tools you already pay for. A custom build is the exception, scoped only once the audit shows configuration will not reach.

When a build does earn its place, we are strong engineers and we do it well: retrieval over your own data, regulated-industry tools, internal platforms.

Maps to: bespoke builds, scoped after the audit

DECISION GATE A new need from the audit CONFIG REACH? Configure it the usual path yes Bespoke build scoped · rare no

What an engagement looks like.

Almost everyone starts with the audit. Most continue with an embedded lead. A bespoke build happens only when the audit shows it should.

01

AI audit & transformation

Two to four weeks · fixed scope

Workflows in production, team trained

See the AI audit

The usual front door. A fixed-scope engagement that opens with a discovery audit of where AI fits and ends with workflows running in production and your team trained on them.

What happens

  • Discovery workshops with leadership & the teams in scope
  • Process and data review across the functions in scope
  • Data-protection review against ISO 27001 & your sector obligations
  • A prioritised opportunity list with effort & risk for each
  • Configuration of the chosen workflows on your existing stack
  • Hands-on training calibrated per role

What you get

  • A strategy roadmap of opportunities, risks & data-protection notes
  • Configured workflows running against your data
  • A workflow-authoring walkthrough for your own team
  • Recorded training sessions
02

Embedded AI lead

Rolling monthly · same engineer

Continuous shipping, quarterly review

Talk to us

The ongoing motion. After the audit most clients keep a senior OpenKit engineer on a monthly retainer, shipping new workflows as opportunities surface and staying accountable for the estate you are building.

What happens

  • Weekly working sessions with the in-house team
  • Hands-on build of new workflows as the opportunity list evolves
  • Review of any AI work your internal staff have done
  • Vendor & tool selection for new AI features
  • Quarterly review against the original opportunity list

What you get

  • Working AI features shipping on the cadence of your business
  • A quarterly progress report against the original audit
  • Internal documentation of every workflow
03

Bespoke builds

Optional route
Scoped per project · after the audit

A working system in production

Talk to us

When you need it built. Some engagements need a system that does not exist yet: retrieval over a proprietary corpus, a regulated-industry tool with custom audit logging, an internal platform with role-based access. Less common than the audit-and-retainer route, and never the headline.

What happens

  • Scoping workshops with technical & business stakeholders
  • Architecture & security review
  • Build, test and deploy against your environment
  • Handover & operational documentation

What you get

  • A working system in production
  • Architecture documentation
  • An operational runbook

The safe way to put AI to work.

Start with the audit. We find where AI fits, configure it on the stack you already run, and keep one senior engineer accountable for it.

OpenKit is a UK AI consultancy that puts AI to work safely, starting with a fixed-scope audit and then an embedded senior AI lead on a monthly retainer. OpenKit configures workflows on the stack you already run, keeps your data inside your boundary with role-based access and audit logging, and builds bespoke software only when the audit shows configuration will not reach. OpenKit holds ISO 27001, ISO 9001, and Cyber Essentials, is GDPR compliant, and works with clients across the United Kingdom from a base in Cambridge.

Start Your AI Project

Thank you for your interest. Enter your project details below and our team will get in contact within 24 hours.

About your AI project

0 / 2,000

About you

By submitting this form, you confirm that you have read and agree to our privacy policy. We will only use your information to respond to your inquiry.