Skip to content
Governance and policy documentation for AI tool use

Engagement 03 · Governance Setup · Five Weeks

Internal rules for how your organisation uses automated tools, written down and agreed

When staff begin using tools ahead of any policy, the organisation is exposed without knowing the shape of that exposure. This engagement produces the written rules that make the situation legible and manageable.

Back to home

What this engagement delivers

A written policy, a staff briefing, and a register template for tracking tools in use

For management

At the end of five weeks, your organisation holds a written policy that covers which tools are approved for use, what information may not be entered into external services, what review is required before outputs are used in decisions, and how tools in use are recorded for oversight purposes.

Staff will have attended a briefing session that walks through the policy in practical terms. The register template gives the organisation a way to track what tools are in active use, by whom, and for what purpose.

For technical staff

The policy document is written at a level of specificity appropriate for your organisation's size and tool mix. It distinguishes between tool categories, sets out data classification rules for external service inputs, and defines the review checkpoint for automated outputs entering consequential workflows.

The register template is a structured document your team can maintain in whatever format fits your existing record-keeping — spreadsheet, wiki, or document store. It is not a software tool that creates a new dependency.

The situation

Staff using tools ahead of policy is not unusual — but it leaves the organisation without a clear picture of its exposure

For management

Automated tools became widely accessible faster than most organisations could develop policies for them. Staff began using them because they were useful, not because there was a decision to do so. The result is that the organisation often does not know which tools are in active use, what information has been entered into them, or what decisions have been influenced by their outputs.

That is a governance gap, not a technology problem. The question is not whether to use these tools — it is whether the organisation has agreed rules for how they are used and a way to see that those rules are followed.

For technical staff

Without a data classification policy, staff cannot make an informed decision about whether a given input is appropriate for an external API. Without a tool approval process, the surface area of third-party dependencies grows without visibility. Without a decision review requirement, outputs from probabilistic systems enter workflows as if they were authoritative.

These are each tractable problems with documented solutions. The difficulty is usually not technical — it is that nobody has been given the task of writing them down and getting agreement from legal, operational, and technical stakeholders at the same time.

The approach

Legal, technical, and operational input brought together in one structured process

For management

The engagement works with the people in your organisation who need to be part of this conversation — legal, operations, and technical staff — over five weeks. The policy that comes out of it reflects how your organisation actually works, not a template written for an imagined average company.

The staff briefing session at the end is not a checkbox. It is designed to give the people who will live under the policy a chance to ask questions and understand the reasoning behind specific rules, so that the policy is applied as intended rather than worked around.

For technical staff

The engagement begins with an inventory of tools currently in use across the organisation. This is done through structured conversations with department leads, not a technical audit. The inventory informs the policy scope and ensures that the approved tool list reflects reality rather than assumption.

Policy drafts are reviewed in two rounds — first with legal and technical stakeholders for accuracy, then with operational staff for practicality. The register template is built around the tool categories identified during inventory, so it is immediately usable rather than requiring adaptation.

Working together

Five weeks, drawing on legal, technical, and operational input from your team

Weeks 1–2

Inventory and stakeholder input

We conduct structured conversations with legal, technical, and operational leads to map the tools currently in use, the data they touch, and the decisions they currently inform. This becomes the foundation for the policy scope.

Weeks 3–4

Policy drafting and review

A policy draft is produced and reviewed in two rounds. The first with legal and technical staff for accuracy; the second with operations for workability. Register template is drafted in parallel and shared for review.

Week 5

Briefing and handover

The staff briefing session is held, the finalised policy and register template are handed over, and any remaining questions from the review process are addressed. The organisation leaves the engagement with documents it can maintain independently.

Investment

¥30,000 JPY for five weeks of work

What is included

Written policy

A policy document sized for your organisation, covering approved tools, data handling restrictions, output review requirements, and record-keeping obligations. Reviewed and agreed by relevant stakeholders.

Staff briefing session

A session with relevant staff walking through the policy in practical terms, covering the reasoning behind specific rules and how they apply to day-to-day tool use.

Register template

A structured template for tracking tools in active use, by whom, and for what purpose. Built around your tool inventory and ready to populate immediately after handover.

Stakeholder coordination

Structured conversations with legal, technical, and operational staff managed as part of the engagement — your staff are not expected to coordinate the process themselves.

Practical details

Duration

Five weeks from engagement start

Investment

¥30,000 JPY (invoiced at engagement start)

Format

Structured conversations with legal, technical, and operational staff; remote or in Oita

Output ownership

All materials belong to your organisation at handover

Suitable for

Organisations where staff have begun using automated tools ahead of any formal policy

Measurement

What is measured before and after this engagement

Three figures are established at the start of the engagement through the inventory process, and confirmed again at close through the staff briefing session.

Before

Systems without documented approval

Number of automated tools or systems in active use across the organisation that have no formal record of being reviewed or approved for that use. Identified during the inventory phase.

After

Each tool in active use is recorded in the register with approval status noted

Before

Staff awareness of data handling rules

Assessed through brief questions during inventory conversations. Captures the gap between what staff understand about data handling constraints and what the organisation's legal position actually requires.

After

Confirmed via staff briefing session — questions and responses noted during session

Before

Register completeness

Whether any register of tools in use exists and how complete it is. Organisations beginning this engagement typically have no register at all, or an informal list that is not maintained.

After

A structured register template populated from inventory, with a named owner for ongoing maintenance

Our commitment

The scope is agreed before work begins, and the output is yours to use independently

This engagement produces documents, not a dependency. The policy, register template, and briefing materials all belong to your organisation and are written to be maintained internally after handover. There is no software subscription and no ongoing relationship required for the output to remain useful.

The initial conversation carries no commitment. If it becomes clear during that conversation that this engagement is not the right fit — because the policy work has already been done, or because the organisation is at an earlier stage than this engagement assumes — we will say so directly.

Before any commitment

Initial conversation

No charge, no obligation. We discuss the tools in use, who is involved in policy decisions, and whether five weeks is the right scope for your situation.

Written scope

The scoping note names which stakeholders are included, what the policy will cover, and what the deliverables look like. Agreed before any work begins.

Your ownership

Policy, register template, and briefing materials all belong to your organisation at handover. No Naze Blend Zone involvement is needed to maintain or update them.

Next steps

How to begin

Step one

Send a message

Write to info@naze-blendzone.com or use the contact form on the home page. A short description of your current situation — which tools are in use and whether any policy exists — is enough to start.

Step two

Initial conversation

We discuss the tools currently in use, the stakeholders who need to be involved, and whether this engagement scope fits what your organisation needs at this point.

Step three

Scoping note and start

A written scoping note is produced, reviewed, and agreed. The engagement begins from that point. Five weeks to the staff briefing and final handover.

Other engagements

Governance setup is one of three areas

Engagement 01

Data Preparation

Addresses duplicates, formatting inconsistencies, historical gaps, and conflicting field definitions across departments. Seven weeks. Delivers a data dictionary, cleaned dataset, and validation rules.

¥40,000 JPY

View

Engagement 02

Model Monitoring Setup

Establishing ongoing monitoring for systems already deployed — accuracy drift, distribution shifts, alert thresholds and escalation routines. Five weeks. Delivers a dashboard with defined thresholds and a performance assessment.

¥36,000 JPY

View

Governance and Policy Setup

Five weeks to internal rules your organisation has agreed and written down

If staff are using automated tools without a policy in place, this engagement addresses that directly. The initial conversation is without commitment.