Forward-Deployed Engineering04

The pilot that stalled,connected, secured, scored,and in front of real users.

We take a pilot that worked in the demonstration and do the work between it and production: connectors, a security review, evaluation, monitoring, a rehearsed go-live. The criteria are written in week one and met on record.

HARDENING STAGESHardening
Duration
Eight to twelve weeks
Starts with
A pilot that exists
Week one
A gap report against the criteria
Ends with
Go-live criteria met, on record

FDE / 01Fit

Whether it is a rescue

Signs of a stalled pilot

  • It runs on a sample export, not on the system of record
  • It impressed the steering group and no one has used it since
  • Nobody can say how often it is right, because nothing scores it
  • Security has not reviewed it, so it cannot be given real access
  • The person who built it has moved on and the code has no reviewer

When it is not a rescue

  • There is no pilot yet; the Production Sprint starts from the workflow instead
  • The pilot showed the workflow is not worth automating; that is a finding, not a fault
  • The problem is a research problem no model yet solves
  • No one on your side owns the outcome
  • The pilot must stay a demonstration until a decision that has not been made yet

FDE / 02The hardening checklist

Four things a pilot lacks.

Almost every stalled pilot is missing the same four. The engagement is the work of adding them, in this order.

  1. Integration

    The pilot reads from the system of record and writes back to it, under a person's permissions, with every action attributed. The sample export is retired.

  2. Security

    A threat model, a review by your security team, secrets in your vault, egress controlled. The pilot is given real access only after the review is signed.

  3. Evaluation

    A golden set of real cases with known answers, agreed with the people who do the work, and a harness that scores every release against it. The score is the argument for going live.

  4. Monitoring

    Dashboards, alert thresholds and a person they page. A rollback that has been rehearsed before it is needed.

FDE / 03Week by week

W1 – W10

Ten weeks, drawn as a plan.

The common shape. A pilot with more systems to connect or a longer security review uses weeks eleven and twelve.

W1W2W3W4W5W6W7W8W9W10
AssessA gap report: what the pilot has, what production needs, and the go-live criteria signed
IntegrateConnectors to the system of record, write-back with attribution, the sample export retired
SecureThreat model, security review signed, secrets in your vault, egress controlled
EvaluateA golden set agreed and a harness in your pipeline; every candidate scored
MonitorDashboards, thresholds, a person paged, rollback rehearsed
Go liveReal users, real traffic, the criteria met and recorded

The go-live criteria are signed in week two. Nothing is added to them afterwards, and nothing is waived.

FDE / 04Go-live

6 ITEMS

The go-live criteria.

Written in week two, signed by the owner, and ticked one by one before real users see the system.

GO-LIVE CRITERIA6 ITEMS
  • Connected to the record

    Reads from and writes back to the system of record; the sample export no longer exists.

  • Scored on the golden set

    The release passes the agreed threshold on real cases with known answers.

  • Security review signed

    Threat model reviewed, findings closed, sign-off from your security team on file.

  • Monitoring live

    Dashboards and alert thresholds in place, with a named person they page.

  • Rollback rehearsed

    A rollback performed on the production path by your engineers before go-live, not after.

  • An owner trained

    One named person on your side who has released and rolled back the system.

FDE / 05Specified

10 FIELDS

The engagement, specified.

The terms as they stand before the first call. The pilot moves the detail; it does not move the shape.

Duration
Eight to twelve weeks, set at scoping by the systems to connect and the review to pass
Start
A scoping call, a read of the pilot's code, then the go-live criteria agreed with the owner
Engineer
One named senior engineer; a second for the integration weeks where the systems need it
Input
The pilot as it stands: its code, its prompts, its sample data, and whoever built it if they are still there
Cadence
Your standups daily; a written report weekly; a demonstration on real records at each gate
Access needed
Repository, the systems of record, real records, and your security team's time for the review
Evaluation
A golden set by week four; every candidate scored against it, as in Evaluation & Observability
Go live
Real users and real traffic, once every criterion on the sheet is ticked by your side
Handover
Runbook, decision record and a rehearsed rollback, in the last two weeks
If it slips
For reasons on our side, we stay until the criteria are met at no further fee; for access or review on yours, the clock pauses and the gap is written down

FDE / 07Questions

6 QUESTIONS

Asked about a rescue.

Do you rebuild the pilot or keep it?

We keep what holds up and replace what does not. The gap report in week one says which is which, line by line, before any code is changed. Most pilots keep their core and lose their sample data, their secrets in code and their lack of tests.

What if our pilot was built by another vendor?

That is common. We need the code, the prompts and any documentation; we do not need the vendor. Intellectual property in the pilot has to be yours for the work to proceed, and we check that at scoping.

Who writes the go-live criteria?

We draft them in week one from the gap report; the owner of the outcome on your side signs them in week two. They are the sheet on this page, with the thresholds filled in for your workflow.

How do you know it is right?

It is scored against a golden set of real cases with known answers, agreed with the people who do the work. The score is measured before every release and is the argument for going live. Nothing goes in front of users on the strength of a demonstration.

Can it be deployed inside our own perimeter?

Yes. Where the pilot must run in your cloud account, on your premises or without a network, the environment work is scoped with Regulated & Secure Deployment and runs inside the same weeks.

What happens after go-live?

Your team runs it, with the runbook and the decision record. Our engineer stays on call for an agreed period. Managed Operations exists if you would rather we keep running it.

FDE / ENDStart

Eight to twelve weeks,and the pilot is in production.

Book a scoping call and bring the pilot; you leave knowing what stands between it and real users.