1. Source intake, parsing & safety boundary
The Engine first converts heterogeneous source material into a safe and attributable assessment pack. It does not begin by asking an AI model whether the organization is ready.
PDFOpen logicInput preparationMulti-format local parsing
Normalizes PDFs, HTML, tables, JSON, screenshots, and other artifacts before model analysis.
Local extractionPage markersTable rows
“An AI governance clause on page 14 and a platform diagram on page 27 remain separate evidence objects; they cannot become one blended impression.”DLPOpen logicSafety controlDLP & sensitive-data review
Scans the distributed source registry for secrets, identifiers, and other unsafe content before deeper analysis.
SecretsDistributed samplingRedaction
“Use the presence of unclear data-access controls as evidence; do not expose named individuals, credentials, or unnecessary entity labels.”PQOpen logicInput qualityParse quality & visual evidence
Identifies sparse pages, extraction gaps, and visually rich sources that require image-aware interpretation.
Sparse-page warningVisual sourceUsability status
“A service blueprint may prove ownership and handoffs even when its labels appear only inside a rendered diagram.”KBOpen logicClean-room ruleCustomer evidence vs. reference KB
Separates witness evidence from methodology, definitions, false-positive guards, tactics, and confidential reference material.
Source of truthReference onlyNo provenance leakage
“The KB defines what embedded AI lifecycle control looks like. It does not prove that the assessed organization has implemented it.”2. Source registry, chunking & five domain packets
The complete source pack is transformed into traceable chunks and routed into bounded A–E evidence packets before parallel audit begins.
IDOpen logicTraceability layerSource registry & provenance
Assigns stable source, page, row, image, and chunk identifiers to every evidence unit.
Source IDChunk IDManifest
“The verifier should be able to point to src-004, page 011, chunk 3—not only to a generic ‘AI Strategy’ document.”A–EOpen logicDeterministic routingDomain relevance classification
Scores each source chunk against domain-specific operating, architecture, governance, data, and service signals.
High / medium / lowRouting reasonsPre-classification
“Model-release and observability evidence routes primarily to B; service-blueprint evidence routes to E; value hypotheses and portfolio decisions route to C.”POpen logicBounded evidence packetPacket construction & weak coverage
Selects the highest-value chunks for each domain and makes thin evidence coverage visible.
Bounded packetGap signalsWeak-coverage flag
“A Domain D packet containing only a generic data strategy cannot certify semantic quality, lineage, retrieval quality, or governed AI access.”RTOpen logicExecution controlTask-fit model routing & fallback
Maps each task to a controlled primary model profile and ordered fallback chain.
Stage IDsTask fitRun trace
“A targeted rescan uses a deeper challenge profile than initial extraction because it must resolve a disputed finding rather than repeat the first pass.”3. Five parallel forensic domain audits
Each domain audits five maturity criteria and five opposing anti-patterns. Capability evidence, harmful patterns, and missing evidence remain separate throughout the assessment.
AOpen logicForensic domainAdaptive Operating Model
Tests decision rhythm, demand routing, Launch-and-Learn, shared learning, and human-AI work redesign.
Decision rightsLearning loopsWork redesignExpanded sample model
“Multiple pilots plus unclear transition to service ownership indicates activity, but may still support Pilot Purgatory rather than embedded readiness.”BOpen logicForensic domainEnterprise AI Architecture & Platform Readiness
Tests integration, lifecycle control, observability, trust and safety, and AI platform-as-product capability.
ArchitectureLifecycleSafety
“A model gateway proves shared access, but without routing policy, observability, budget controls, and service ownership it does not prove an AI platform product.”COpen logicForensic domainAI Strategy, Governance & Value Realization
Tests purpose, impact framing, embedded governance, responsible-AI control, and evidence-based investment.
ValueGovernancePortfolio
“A large AI portfolio can indicate strategic activity while simultaneously supporting AI Investment Drift if weak initiatives are not stopped or reprioritized.”DOpen logicForensic domainData Foundations, Ownership & Accessibility
Tests domain ownership, semantic context, quality and lineage, governed access, and reusable retrieval patterns.
Data productsSemantic contextRetrieval
“A RAG index may exist, but stale sources, duplicate stores, weak ownership, and unbounded context cost still indicate an access-architecture anti-pattern.”EOpen logicForensic domainBusiness Capability & Service Architecture
Tests capability anchoring, service blueprints, solution traceability, service-area ownership, and phased scaling.
Service architectureValue streamsScaling
“Automating one task may improve local speed while worsening downstream rework; the audit evaluates the end-to-end service flow, not only the AI feature.”4. Independent evidence check, anti-pattern semantics & targeted rescan
The first audit is provisional. A separate verification layer tests whether forwarded scores and quotations are genuinely supported before any metric is calculated.
VOpen logicIndependent verifierClaim and score verification
Tests each forwarded criterion against the raw packet and exact evidence location.
SupportedWeakUnsupported / missing
“The source says an AI governance forum is planned. The scanner scored embedded governance at 3. Verify as aspirational and lower the count.”ØOpen logicAbsence semanticsAnti-pattern adjudication
Separates confirmed presence, partial presence, tested absence, and unknown absence.
Confirmed presentPartially presentTested / unknown absentExpanded reliability model
“No mention of shadow AI is not tested absence. A comprehensive usage-control review showing governed access and monitored exceptions may support tested absence.”↺Open logicSecond opinionTargeted rescan
Re-examines only the highest-value weak, unsupported, or missing criteria instead of rerunning an entire domain blindly.
Disputed criteriaRescan budgetFocused feedback
“Re-open B2 and B4 because related controls exist but the evidence is ambiguous; do not regenerate all ten Domain B findings.”↓Open logicDeterministic correctionApply verified counts
Writes evidence-check outcomes, absence states, adjustment reasons, and rescan status back into Phase 1 before scoring.
Original vs. verifiedAdjustment reasonNo optimism carryover
“Scanner score 3, verifier score 1, targeted rescan still weak: Phase 2 receives 1 and retains the downgrade reason.”5. Deterministic metric firewall & confidence bracket
AI does not decide the headline readiness result. Arithmetic converts the verified audit into bounded metrics, classification, and permission for later synthesis.
ΣOpen logicMetric firewallEvidence-gated AI readiness
Calculates maturity, burden, clearance, coverage, integrity, density, and A–E domain scores from verified data.
Deterministic math0–100Traceable inputs
“Strong AI policy evidence plus weak operating proof and entrenched pilot anti-patterns cannot become a high readiness score through narrative synthesis.”E/S/AOpen logicClassificationReadiness stage
Translates the capped score and burden into an evidence-aware organizational classification.
InsufficientEmerging / StructuredAdaptive
“A readiness score of 54 with anti-pattern burden above 50 is ‘Scaling with friction,’ not a clean Structured state.”CAPOpen logicEvidence capEvidence density & readiness ceiling
Caps optimistic readiness when too few criteria have verified source coverage.
<30 BLOCK floor<60 warning capCoverage matters
“A polished AI strategy covering only ten of fifty evidence surfaces cannot justify a high enterprise readiness result.”H/M/LOpen logicSynthesis permissionConfidence bracket
Converts density, delivery integrity, and silent areas into HIGH, MEDIUM, or LOW synthesis behavior.
HIGH directiveMEDIUM cautiousLOW findings-onlyPermission model
“The material may suggest real weaknesses, but if evidence is sparse, the correct output is a validation path—not confident implementation advice.”6. Evidence summary, diagnosis & three executive lenses
The Engine first creates a fact-only assessment summary, then explains the organizational condition, and only then translates the same evidence through different decision-maker lenses.
ESOpen logicFacts-first synthesisAssessment evidence summary
Creates the non-prescriptive synopsis of classification, metrics, strengths, gaps, anti-patterns, and missing evidence.
Evidence onlyNo tactic IDsNo directives
“The report may state that evidence density is 58% and Domain B scores 7/15; it cannot turn those values into an invented productivity or ROI claim.”DOpen logicInterpretive layerAI Transformation diagnosis
Explains the primary bottleneck, root causes, deterministic domain diagnosis, and confidence without yet prescribing the roadmap.
Primary bottleneckRoot causesA–E diagnosisExpanded sample model
“AI ambition, weak service ownership, unclear data meaning, and pilot-heavy delivery may jointly indicate an absorption bottleneck—but certainty remains limited if operating evidence is thin.”TLOpen logicPersona lensAI Transformation Lead
Reads the evidence through operating-model readiness, change capacity, portfolio learning, and service-area enablement.
Operating modelLearningScale readiness
“Emphasize the missing transition from pilot learning to service-area ownership—not a generic change-management programme.”CTOOpen logicPersona lensCIO / CTO / CDAO
Reads the same diagnosis through architecture, platform, data, lifecycle, security, and operational reliability.
PlatformDataRisk control
“Describe missing release traceability and evaluation controls; do not assume a specific MLOps stack or vendor.”BOOpen logicPersona lensBusiness / Service Area Owner
Reads the evidence through customer value, service outcomes, work redesign, adoption, and accountable ownership.
Customer valueService flowAdoption
“Ask whether the pilot improves the whole service flow and first-time-right quality—not only whether one task is completed faster.”↟Open logicAdaptive routingSynthesis escalation
Routes especially complex or high-friction diagnoses to deeper synthesis using deterministic triggers or explicit deep mode.
Complexity triggersDeep modeRecorded reason
“A low-readiness estate with cross-domain anti-patterns may justify deeper causal synthesis, but LOW confidence still forbids a directive roadmap.”7. Planning decision, Ready-and-Adapt roadmap & tactic permissioning
Recommendations are created only after diagnosis and only in the form permitted by the confidence bracket. The roadmap follows Kickstart → Building the System sequencing and remains linked to verified findings.
H/M/LOpen logicRoadmap modeDirective, cautious, or findings-only
Changes the shape of Phase 3 output according to evidence permission.
HIGH roadmapMEDIUM assumptionsLOW validation plan
“When evidence is LOW, validate decision rights, service ownership, lifecycle records, and value baselines before prescribing scale.”GO?Open logicActionability gatePlanning decision
States whether the roadmap is safe to use, conditionally usable, or blocked pending stronger evidence.
GOCONDITIONAL_GONO_GO
“Safe now: validate service ownership and baseline the target flow. Unsafe now: scale agents across service areas before boundaries and evidence are proven.”4POpen logicTransformation sequencingFour Ready-and-Adapt phases
Preserves Kickstart validation before Building-the-System scaling.
0–3 months3–6 / 6–1212+ monthsExpanded roadmap model
“Do not prescribe enterprise AI operating-model redesign before one service-area vertical slice has clarified value, data, lifecycle, safety, ownership, and absorption needs.”TACOpen logicTactic permissioningVerified tactic IDs & activity grounding
Requires exact approved tactic IDs only when the locked problem pattern and prerequisites support them.
Exact TAC IDsWhen to useAcceptance criteria
“A learning-community tactic cannot be attached to generic improvement language unless the evidence shows a learning-flow or fragmented-knowledge gap.”8. Fact-check, sanitation, Quality Gate & audit trail
The complete report is treated as another artifact to verify. Unsupported claims are challenged, corrected, removed, or blocked before the final publication state is assigned.
FCOpen logicIndependent verificationSummary & roadmap fact-check
Reviews evidence-summary and diagnosis claims separately from planning decisions and roadmap actions.
Separate checksBounded retriesHigh-reasoning escalation
“The finding that lifecycle control is weak may be supported, while a promised 30% release-efficiency gain remains fabricated and must be removed.”SANOpen logicActive correctionStrategy, privacy & reference sanitation
Removes, rewrites, or quarantines unsupported claims, identifying content, and confidential reference provenance.
RemoveRewriteQuarantine
“Replace a leaked KB document name with generic methodology language; remove an unsupported named owner; keep the evidence-backed functional gap.”QGOpen logicPublication controlGO / WARN / BLOCK Quality Gate
Aggregates evidence density, traceability, verification, fact-checking, silence, coverage, and sanitation into a visible final decision.
GOWARNBLOCKFinal authority
“Evidence density 28% triggers BLOCK even when the prose is excellent. The system chooses evidence sufficiency over presentation quality.”TRACEOpen logicAssurance layerRun trace, diagnostics & effective confidence
Records the actual pipeline path and ensures later quality failures can downgrade how the report is rendered.
Model traceDiagnosticsEffective bracket
“A HIGH-bracket roadmap that later receives BLOCK is rendered as effectively LOW-confidence rather than remaining visibly directive.”Evidence Summary
Facts, metrics, strengths, gaps, anti-patterns, and missing evidence.
AI Transformation Diagnosis
Primary bottleneck, root causes, and deterministic A–E interpretation.
Persona Views
Transformation Lead, CIO / CTO / CDAO, and Service Owner lenses.
Roadmap or Findings Mode
Directive, cautious, or validation-first output according to evidence permission.
Quality Appendix
Evidence checks, sanitation, source gaps, model trace, and GO / WARN / BLOCK state.