Implement auditable AI governance for consequential systems
Adopt the AGEI reference independently, or engage Cognitive Insight to design and implement governed agent workflows, delegated authority controls, cryptographic evidence, and audit-ready integrations.
We do not sell generic AI-governance slide decks. We help organizations implement the technical and operating controls needed to demonstrate that consequential AI actions were authorized, policy-bound, correctly executed, and independently verifiable.
Core offers and deliverables
1. AGEI Readiness Assessment
Offer: Determine what must change for the client to move from policy documents and fragmented operational records to an auditable governance-evidence capability.
Deliverables:
- AI/agent inventory and prioritized use-case map
- Current-state governance and technical-control assessment
- Authority, access, and sensitive-data flow map
- Evidence-gap analysis: which controls they can substantiate with evidence, versus claims that rely on narrative, screenshots, or mutable records.
- Agent/tool risk classification and control tiering
- Shadow AI exposure and discovery recommendations
- Target AGEI architecture and minimum auditable path
- 90-day implementation roadmap
- Executive readout and technical working session
Scope boundary: This is an assessment and architecture engagement, not a full technology deployment. Best for organizations with active AI or agent initiatives that need a technical baseline before selecting controls, platforms, or implementation priorities.
Commercial approach: AGEI Readiness Assessments are scoped after an initial Readiness & Scoping Conversation. Typical engagements begin at $15,000 and vary based on the number of AI or agent workflows, business units, regulated data, systems, integration requirements, and assurance objectives.
2. Governed Agent Design Sprint
Offer: Design the authority and control model for one prioritized agentic workflow before it gains consequential operational access.
Deliverables:
- Agent role, purpose, and decision-boundary specification
- Tool inventory and risk classification
- Delegated-authority model
- Tool permissions, resource scopes, and action limits
- Attribute-Based Access Control (ABAC) / Role-Based Access Control (RBAC) and just-in-time elevation design
- Approval and escalation matrix
- Segregation-of-duties design for sensitive actions
- Policy-as-code requirements and rule catalog
- Revocation, session expiry, and kill-switch design
- Threat model covering indirect prompt injection, tool misuse, privilege escalation, replay, and bypass paths
- Architecture diagram and implementation backlog
Example: procurement workflow. A procurement agent may draft a purchase request autonomously, submit an approved request below a set limit, require a named approver above that threshold, and never gain direct access to payment execution.
Price: $25,000–$40,000, depending on whether the work covers one workflow, a reusable authority-control pattern, or multiple agent classes.
3. Proof-Carrying Execution Pilot
Bounded agent actions verified before execution.
Offer: Build one working, bounded implementation that proves the AGEI pattern in the client’s own stack.
Deliverables:
- One governed agent workflow operating in a controlled environment, which may include a narrowly scoped production deployment where appropriate.
- Agent identity, session, and delegation model
- Policy gate with approve, deny, escalate, and inspect outcomes
- Action-bound, short-lived, signed proof-bundle design
- Tool gateway or adapter that verifies proof before execution
- Parameter validation, target-resource binding, and replay prevention
- Request, decision, approval, and execution-outcome receipts
- Evidence graph, verification workflow, and sample audit pack
- Test suite for denied actions, expired proofs, altered parameters, replay attempts, and revoked authority
- Runbook, threat model, architecture documentation, and handoff workshop
No high-risk invocation succeeds without
- • Explicit delegated authority
- • A current policy decision
- • A scoped, unexpired proof bundle
- • Execution through the enforced gateway
- • Signed evidence of the outcome
Pilot creates
- • A governed workflow
- • A signed proof bundle
- • A tool-enforcement gateway
- • Decision and execution receipts
- • A verification flow and audit pack
Price: $50,000–$85,000 for one bounded workflow and one or two integration targets.
4. Enterprise Evidence Integration
Offer: Turn the pilot pattern into a reusable organizational capability.
Deliverables:
- AGEI reference-schema mapping to existing systems
- IAM, SSO, service-identity, and delegated-credential integration
- SIEM and security-event forwarding
- GRC, ticketing, and approval-workflow integration
- Model registry, evaluation, and lifecycle-evidence integration
- Policy and gate-management workflow
- Key-management, signing, rotation, revocation, and verification design
- Audit-pack templates and evidence-retention procedures
- Multi-workflow onboarding playbook
- Control-owner operating model and RACI
- Conformance-test suite and implementation scorecard
- Executive roadmap for scale-out
Commercial structure: Typically phased, beginning with the highest-risk workflows and control integrations.
Starting range: $90,000–$175,000+, depending on systems, workflows, and assurance requirements.
5. Fractional AI Governance & Assurance
Offer: Ongoing technical governance leadership for organizations that have AI initiatives but do not need or cannot yet hire a full-time governance architect. This engagement provides technical governance leadership and implementation oversight; it does not replace the client’s legal counsel, compliance accountability, security ownership, or executive decision authority.
Monthly deliverables:
- Monthly governance-control review
- Review of new AI use cases, agents, tools, and integrations
- Policy and delegated-authority design support
- Evidence-pack and audit-readiness review
- Shadow AI trend and remediation review
- Risk register and control-status updates
- Executive or board-ready briefing
- Implementation office hours for engineering, security, privacy, and legal teams
- Quarterly maturity assessment and roadmap refresh
Commercial terms: Limited number of stakeholders/workstreams, with major engineering implementation scoped separately.
Price: Starting at $8,000 per month (three-month minimum). For high-stakes or multi-team environments, target $12,000–$15,000/month.
Specialist modules
Specialist modules are designed as add-ons to the core engagements above.
| Module | Typical deliverables | Starting range |
|---|---|---|
| Shadow AI Discovery | Discovery design, tool registry, risk classification, remediation playbook | $20,000–$35,000 |
| Provenance & Transparency | Release controls, provenance architecture, verification workflow, disclosure process | $20,000–$40,000 |
| Privacy Evidence Mapping | AI-processing map, RoPA-support model, DPIA linkage, retention/redaction design | $25,000–$45,000 |
| Audit Pack & Evidence Verification | Receipt-verification design, audit-pack templates, incident-reconstruction workflow | $20,000–$35,000 |
| Executive AI Governance Workshop | Half-day or full-day working session, decision log, priority roadmap | $5,000–$10,000 |
Intellectual Property Boundary
The AGEI open reference architecture, schemas, and community artifacts remain available for independent adoption under their published license. Open availability of the reference architecture does not grant a warranty, certification, managed-service commitment, or deployment authorization. Client engagements produce organization-specific architecture, configuration, control mappings, implementation artifacts, and training tailored to the client’s environment, subject to the applicable statement of work.
Start with one consequential workflow
The fastest way to establish auditable AI governance is to identify one agent or AI workflow with meaningful authority, define its decision boundaries, and make its actions verifiable.
What to bring
Bring one AI, model, agent, or automated workflow you consider consequential. We will discuss its authority, connected tools, data, decision boundaries, current controls, evidence gaps, and the outcome you need.
This conversation is an initial discovery and scoping discussion. It is not legal advice, a compliance certification, or a completed technical assessment.
Meet directly with James Greenwood to discuss your AI or agent workflows, current governance environment, technical constraints, and evidence needs. If there is a fit, Cognitive Insight will recommend an engagement path, scope, timeline, and pricing.