CHAPTER 02 · DISCOVER
We Learn Your Operation Before We Propose Anything
One day, on-site, inside the approved compliance boundary. The program office sponsor framed the stakes up front. Then we did what we always do: talk to people, watch the work, map it, and rank what we found — not just run a meeting.
WHAT WE ACTUALLY DID
We Don't Just Run a Meeting
A roadmap session is where it starts, not where discovery ends. Interviews, documentation, the tools already in use — all of it, before we propose anything.
Interviews
31 sessions / 24 stakeholders
We start with the program office sponsor, then work down through every function that touches risk — not just the people who signed off on the meeting.
Every session recorded, transcribed, and tagged inside the approved boundary.
Documentation
58 sources reviewed
Supplier quality agreements, compliance manuals, and the shadow spreadsheets people built because the real system couldn't keep up.
Indexed so the agents can reference it directly, inside the boundary.
Systems & Tools
7 systems mapped
Everything the program office already touches — no new platform to certify, no rip-and-replace.
All seven connected before we proposed anything.
Facility walkthroughs
We walked the controlled areas and watched how access actually gets requested and granted — not just how the SOP says it should.
Process mapping & improvement
Every workflow got mapped end-to-end, then we asked what should change before any of it gets automated.
Adjacent conversations
We talked to the people upstream and downstream of each workflow — program management office, security, and IT — not just the process owner.
AUTOMATION MAP
Of 180,000 hours a year spent on manual risk work, here's how much we can take off the program office's plate
Stays human — final risk decisions, supplier relationships, and every access-control ruling.
Of the 122,400 hrs, here's what each workflow contributes
P1
P2
P3
P4
TOTAL
P1
Supplier Risk Monitoring
52K hrs/yr · $3.1M
P2
Software Supply-Chain (SBOM) Review
34K hrs/yr · $2.0M
P3
Facility Access Review
21K hrs/yr · $1.3M
P4
Compliance Reporting & Audit Prep
15K hrs/yr · $0.9M
What we picked to build first
Supplier risk monitoring & alerting
Highest-leverage, lowest-risk: the public data signals already existed, the pain was universal across every program, and a visible win in 30 days would change every later conversation about what AI could touch here.
Committed on the wall. Working session scheduled within 10 days.
16 weeks to the first system live · then ongoing
Discover
Working session, on-site
Supplier risk monitoring
Wave 1
Software supply-chain review
Wave 1
Facility access adjudication
Wave 1
THE METHOD
Same Approach, Every Engagement
Most AI roadmaps fail the same way — a list of interesting projects with no way to choose which one matters. Ours turns what we actually find on the floor into a ranked, ownable plan.
Discover
What do you repeat? What frustrates you? What runs on a schedule?
→ A named list of the real, repeated work — across every department.
Map & Improve
How does this actually happen, workarounds included — and what should change before we automate it?
→ An end-to-end picture of each workflow, cleaned up first.
Rank & Commit
What ships first? Who owns it? How do we know it worked?
→ A ranked plan with a named owner and a metric on every line.
UP NEXT · BUILD