Riaan Kleynhans
Open the engine

Riaan Kleynhans · Target Operating Model

Nine components, held in code or marked open

The operating model a client runs after implementation, component by component. Each line is either enforced here — a route, a rule table, an append-only ledger — or printed as [ TO BE COMPLETED ]. Counts come from the code; records from this tenant’s ledgers.

Components
9
the TOM
Lines enforced
18/23
route, rule table or ledger
Lines open
5
sign in to read ledger records
1

Strategy & client outcome

Turns executive ambition into a measurable objective, one sponsor, and an explicit scope boundary.

Prevents: scope creep — new markets or volume outside the agreed bands raise change control, not goodwill.

Align · Diagnose

  • Charter and readiness

    Horizon, risk appetite and the ten-dimension readiness score with its gates, signed into the signatures ledger.

    10 dimensions · 5 gates · signatures ledger: —

    Verify
  • Included / excluded services register [ TO BE COMPLETED ]

    Channels, languages and services in or out of scope are stated by the room, not held as a register on the brief.

2

Process & workflow

The end-to-end content supply chain with its owners, its intake gate and its task routing.

Prevents: work entering production on an incomplete brief; ideation confused with waiting time.

Diagnose · Mobilize

  • Process inventory

    Use cases and processes captured through the intake dock and drawn as a verified dataflow map.

    Verify
  • Task routing

    Steps run through the plugin harness under the client’s keys; every run is a task record.

    6 plugins · tasks ledger: —

    Verify
  • SLA per step [ TO BE COMPLETED ]

    Cycle-time targets per supply-chain step are not on the record; only the whole-chain baseline is.

3

Organization, roles & RACI

Who sits in the room, who is accountable for each gate, and what each discipline must have checked off.

Prevents: generic RACIs — one accountable owner per gate, recorded before launch.

Align · Validate

  • Control owners

    Ten Govern owners over eleven domains; who signs which session is a table, not a convention.

    10 owners · 11 domains

    Verify
  • RACI by gate

    Recorded through a hash-chained ledger; the one-A-per-gate rule is enforced before append (422).

    raci ledger: —

    Verify
  • Role brain

    Per discipline: what is expected at each stage, recurring problems, objections and how to overcome them, check-offs by gate.

    4 roles

    Verify
4

Governance & decision rights

Risk tiers, the human-in-the-loop perimeter and the conditions control owners set for approval.

Prevents: autonomous publishing; a legal gate that can be talked around.

Validate · Govern

  • Default-deny access

    Roles × modules CRUD-A matrix re-derived on every request, never read from the cookie; sensitive fields redacted.

    9 roles · 10 modules

    Verify
  • Session signatures

    Every session closes with the owners’ signatures in a hash-chained ledger the microsite re-verifies.

    signatures ledger: —

    Verify
5

Technology & integration stack

The model router, the plugin harness and the connectors into the client’s systems.

Prevents: manual file hand-offs where an API trigger should run.

Model · Mobilize

  • Stack by plane

    Components and evidence per control family across the six control planes; a control is not a document.

    13 control families · 6 planes

    Verify
6

Data, security & privacy

Client keys, zero retention, default-deny access and an audit trail that cannot be edited.

Prevents: client assets or packshots reaching a public training set; access read from a cookie.

Govern

  • Audit trail

    Every decision, refusal and access is an append-only audit record with a SIEM line.

    audit ledger: —

    Verify
  • Hash-chained ledgers

    Each record links to the previous by sha256; the chain is verified on read and shown on /capabilities.

    5 chained ledgers

    Verify
  • Risk registers

    NIST AI 600-1 risks and EU AI Act high-risk areas applied per use case — not legal advice.

    12 risks · 12 high-risk areas

    Verify
  • Persisted SIEM audit [ TO BE COMPLETED ]

    The audit ledger is per tenant on the workspace; persistence to Postgres / Datadog is not wired.

7

Commercial model & economics

Price per approved asset instead of hours; contingency and volume bands inside the contract.

Prevents: token volatility and revision loops turning into change orders.

Model

  • Prioritisation

    P = V·S·A·R / (C·K) per use case, plotted value × readiness; benchmark costs are labelled, never quoted.

    Verify
  • Value ledger

    Realised, committed, forecast, capability, unmeasured — each with its evidence and risk adjustment.

    5 kinds

    Verify
8

Metrics, KPIs & baselines

Audited baselines, a signed value floor and a measured pilot against it.

Prevents: an unverified estimate standing where a baseline should — it prints [ TO BE COMPLETED ] instead.

Prove

  • Gap closure

    Each gap carries a binary closure criterion, closed only by a gap-scoped signature.

    signatures ledger: —

    Verify
  • Audit-ready evidence pack

    Twelve sections with coverage read from state; unknown sections stay unknown.

    12 sections

    Verify
  • KPI targets (< 48 h, > 85 %) [ TO BE COMPLETED ]

    The value floor is the only coded target; cycle-time and first-pass thresholds are not enforced.

9

Implementation & scale

A bounded pilot, its measurement window and the criteria that release scale.

Prevents: multi-market expansion before the pilot has proven or disproven value.

Mobilize · Prove · Scale

  • Handover

    Operating ownership signed per domain before the engagement ends.

    Verify
  • Transformation Contract

    Published as v1/contract.json with the signature chain re-verified on the microsite.

    Verify
  • Hypercare protocol [ TO BE COMPLETED ]

    No hypercare window or on-call record exists in the model.

The nine components sit on the 8-stage operating method on /method. An open line is a fact about the platform today, not a promise; it closes when code or a ledger holds it.