← Back

How a private co-pilot actually gets built

There’s no mystery to it, and no magic. It’s four layers, built in order, each one auditable before the next goes on top.

We own all four. That’s unusual, and it’s the whole reason we can answer questions about data flow and accountability that other vendors have to escalate to a partner.

the stack · bottom to top
LAYER 04

Interface

Where your team meets it: a browser workspace, or embedded into the system they already have open all day. Never a tool that adds a login to someone’s morning.

LAYER 03

Approval & audit

The layer nobody else builds. Every action carries a tier (suggest, draft, or act), and every one of them lands in a signed, append-only log. This is what turns “the AI wrote it” into a defensible record.

LAYER 02

Retrieval & reasoning

Finds the right passages from your corpus, mirrors the permissions of whoever asked, and answers with citations back to the source file. If it can’t find support, it says so.

LAYER 01

Your prepared corpus

The foundation, and two thirds of the work. Documents extracted, de-duplicated, versioned, structured and mapped to your access model. This asset is yours. It outlives us and any model we use.

Layer 01, said properly

Your knowledge modelled, not just indexed

A prepared corpus is not a pile of files with search bolted on top. During preparation we model what your firm actually deals in: clients, matters, projects, policies, people, decisions, and the relationships between them. A document stops being a blob of text and becomes evidence attached to something the firm already recognises.

That is the difference between answering “what position did we take, and why” and returning nine documents that contain the phrase. It is also what makes the approval and audit layer worth having: every action is recorded against that model, so the log reads as a sequence of decisions about real things rather than a list of file accesses.

Systems that model an organisation this way have a reputation for being opaque, and some have earned it. We take the opposite position. How your firm is modelled, what the co-pilot can reach, and what it did are all yours to read, in writing, whenever you ask. Being legible is the whole product.

The twelve weeks, honestly

Including the part where it gets tedious.

  1. 01 · WEEKS 1–3

    Audit

    We map every relevant data source and its condition, interview the people who do the work, and rank candidate workflows on value against effort and risk. You get a data map, three ranked use cases, a security architecture and a fixed-price quote.

    You do: a kickoff, two or three short interviews, read access under NDA. About six hours total.

  2. 02 · WEEKS 4–6

    Prepare

    Text extraction from scanned PDFs nobody ever OCR'd. De-duplication of the same document living in four folders. Version resolution. Structure and metadata. Permission mapping against your existing access model. It is not interesting and it is not optional.

    You do: answer questions about which version is authoritative. Nobody else can answer those.

  3. 03 · WEEKS 7–11

    Build

    One workflow, done properly, rather than five done shallowly. Retrieval tuned to your corpus, output shaped to your house style, approval tiers set with you, audit logging on from day one, deployed into the environment scoped in the audit.

    You do: nominate two or three people to react to weekly builds. Real reactions, not polite ones.

  4. 04 · WEEK 12

    Prove

    We benchmark it against work your team has already completed, where the right answer is known, and we hand you the accuracy and citation figures. If they aren't good enough, we say so before anyone relies on it.

    You do: agree what "good enough" means, in advance, in writing.

  5. 05 · ONGOING

    Run

    We host, monitor and maintain it, keep the corpus current as new work lands, review accuracy quarterly, and add workflows as your team finds them. Flat monthly fee within your deployment tier. Tiers step with corpus size and workload, never per user.

    You do: tell us what people are trying to make it do. That's where workflow two comes from.

Why we start with one workflow

A co-pilot that does one job reliably gets used. A platform that does nine jobs adequately gets opened twice and abandoned; then AI is “something we tried”.

The first workflow also teaches us your corpus properly, which makes the second one considerably faster and cheaper than the first.

What we don’t do

We don’t replace your practice management system, your finance system or your document store. We read from them. Core system replacement is a different project with a different risk profile, and we’d be the wrong people for it.

We also don’t do everyday productivity AI. That’s already in your subscription and it’s fine.