How it works
Six phases.One accountable path to handover.
For an implementation, the working system and its safeguards are designed together. Each phase has a decision, something your team provides, and a result you can review. The last phase hands the whole thing to your team.
A reviewable output at every phase.
Every implementation runs through all six phases. How long each one takes depends on the systems, data, access, security, testing, and review requirements.
- 01
Discover
What work are we changing?
Client provides
Process walkthrough, systems, stakeholders, service constraints, and current failure points.
DecarbDesk delivers
Workflow map, list of connected systems, list of responsible people, and an initial fit decision.
- 02
Assess
Where should the system stop?
Client provides
Policies, risk tolerance, approval expectations, known exceptions, and subject-matter review.
DecarbDesk delivers
Risk assessment, limits on what the system may do, who reviews it, and evidence still needed.
- 03
Design
How will the workflow behave?
Client provides
Decisions about who may access what, approval thresholds, test cases, and sign-off on requirements.
DecarbDesk delivers
Plan for connecting systems, agreed data formats, approval rules, audit records, and handling unusual cases.
- 04
Deploy
Does it work under real conditions?
Client provides
Access to a test environment, feedback during a side-by-side run, and approval before going live.
DecarbDesk delivers
Working workflow, results from agreed test cases, alerts for your reviewers, and instructions for running it.
- 05
Validate
Are behaviour and controls staying inside the agreed boundary?
Client provides
Reviewer decisions, incident context, and approval for material control changes.
DecarbDesk delivers
Test results, a check that recent changes did not make earlier cases worse, reports on unusual cases, and recommended adjustments.
How outputs are evaluated → - 06
Handover
Can the client operate and review it?
Client provides
Operators, reviewers, and administrators available for training and acceptance.
DecarbDesk delivers
Documentation, training, administrative access, and the working system itself.
Calendar
The calendar follows the work and review required.
Two workflows with similar build effort can follow different calendars. Security review, setting up access, testing requirements, reviewer availability, procurement, and training all affect when the system can be accepted.
No DecarbDesk engagement runs longer than 90 days. Work that will not fit inside that window is divided into separate engagements, each with its own deliverable and stopping point.
01Straightforward workflow
1 to 2 weeksA low-risk workflow with well-documented systems and one person accountable for the result.
Typical when
- System connections are documented and data is consistent
- Output stays inside the team that produced it
- One named approver covers the review requirement
- A wrong result does not trigger a formal reporting obligation
Usually includes
Approval steps, operating limits, reviewer alerts, and a side-by-side run before acceptance.
02Cross-team workflow
about 4 weeksSeveral systems and teams, named review authority, and records that have to hold up months later.
Typical when
- The workflow crosses multiple systems or departments
- Output leaves the originating team
- Audit records are expected by someone outside the workflow
- Exceptions follow a defined path
Usually includes
Testing with worked examples, audit records, a defined process for unusual cases, and role-based access.
03Regulated workflow
8 weeksA workflow involving regulated or personal data and formal review requirements.
Typical when
- Regulated, personal, or otherwise restricted data is in scope
- Security review is required before access is granted
- More than one reviewer role participates in the workflow
- Quality thresholds must be agreed before the workflow goes live
- Operators and reviewers need training to accept the system
Usually includes
Security review, access setup, maintained test cases with agreed quality thresholds, reviewer training, and documented review responsibilities.
04Externally reviewed workflow
up to 90 daysWork involving procurement, external review, or a staged introduction across teams.
Typical when
- A procurement process governs the engagement
- A privacy impact assessment is required
- Internal audit or a third party reviews the implementation
- Rollout is phased across teams or regions
Usually includes
Privacy impact support, evidence for external reviewers, a staged side-by-side run, and procurement documentation.
The shortest calendar the six phases run in.
A straightforward workflow can complete every phase in seven working days. Work involving regulated data, more systems, or more reviewers takes longer because each phase needs more review and evidence.
- Day 1Process mapping and system access review
- Day 2Automation rules and approval-step design
- Day 3How unusual and difficult cases will be handled
- Day 4Test connected systems and set operating limits
- Day 5Set up audit records and reviewer alerts
- Day 6Side-by-side run, with automated output compared with the manual process
- Day 7Acceptance review, operator training, and handover to your team
Handover happens at acceptance.
The workflow is ready only when its behaviour, controls, records, and operators have all been tested. From that point your team runs it.
- The approved workflow runs in the environment you own.
- Access roles, approval steps, and stop conditions have been tested.
- Agreed test cases meet the quality thresholds.
- Audit records, alerts, and procedures for unusual cases are set up and your reviewers have tested them.
- Operators and reviewers can complete their assigned tasks without us.
- You hold the system documentation and full administrative access.
Ownership and hosting
Keep the important choices under your control.
The services used to build the workflow should be replaceable. Your records, accounts, credentials, and administrative access should remain under your control.
Where data must stay inside your network, the model, data, and audit record can run there. Hosted services use accounts you own so usage and billing remain visible to you.
- Replaceable services
- Use documented services that your team can understand, extend, or replace.
- Portable records
- Keep workflow records, retained knowledge, and audit history in storage your team can search, back up, and move.
- Data location
- Run models inside your network when data cannot leave it, or through a provider account you own.
- Accounts and credentials
- Keep provider accounts, billing, usage records, and administrative access under your control.
Engagement models
Three ways to engage.
Every engagement runs under a signed statement of work that states its scope, its exclusions, its assumptions, and the acceptance criteria before it starts.
- Assessment
- A focused review of one workflow, ending with a written recommendation you keep whether or not you continue.
- Fixed-scope project
- A defined piece of work with agreed deliverables, acceptance criteria, fee, and handover.
- Monthly advisory
- Ongoing advisory support for organizations working through a sequence of decisions, with expected weekly availability agreed in advance.
Scope and ownership.
What counts as one workflow?
One operational process with a defined trigger, authorized inputs, system actions, review points, outputs, and audit record. Discovery confirms the boundary before a fee is agreed.
What changes the scope and the fee?
The same conditions that change the calendar. Security review, setting up access, multiple reviewers, agreed quality thresholds, procurement, and external review each add work before the system is allowed to act. Older systems, inconsistent data, and custom connections add build effort. We document those conditions before implementation begins.
Who pays for model or cloud usage?
You own the relevant infrastructure and provider accounts. Any external model usage is billed through your account and named in the documented technical plan.
Describe the workflow and we will tell you what shapes the scope.
Email the systems and review points involved, or use the contact page when you can describe the connections, safeguards, and approval needs.