Insights

2026-07-08 · Article

TechSight 90

A 90-day path from an honestly diagnosed starting point to a governed, production AI deployment.

By Frans Vermaak, CEO and AI & Data Architect

TechSight 90

A framework tells you what "governed" means. It does not, by itself, get anything built. TechSight 90 is the delivery methodology that turns a TAG diagnosis into a working, governed deployment inside a single quarter, with no phase skipped and no gate waved through because the deadline got close.

Where It Starts: The Light Ladder Check

TechSight 90 does not open with a fresh discovery workshop or a proprietary intake form. It opens with the same Blast Radius Ladder used in TAG, Tech Sight's governance framework, run here as a fast self-check rather than a full audit. Clients who have already completed a TAG assessment skip straight to Phase 1 with their rung confirmed. Clients coming to TechSight 90 directly answer four questions in the kickoff session instead:

  1. Does the agent use the same credentials and access a human engineer would, with no separate environment? (If yes: Rung 1.)
  2. Is the execution environment sandboxed, but everything the agent reads, comments included, still treated as a trustworthy instruction? (If yes: Rung 2.)
  3. Does the agent hold its own revocable identity in the access-control system, distinct from whoever launched it? (If yes: Rung 3.)
  4. Is governance already mapped to NIST AI RMF, OWASP's Agentic AI Top 10, or ISO/IEC 42001, and audited as a standing practice? (If yes: Rung 4.)

The answer to the first question you answer "yes" to is your rung. This is a starting point, not a substitute for the full TAG assessment; a light self-check surfaces the obvious gaps in an hour, a full TAG engagement finds the ones that only show up under audit.

Which rung your organisation is honestly on determines where the 90 days begin: a Rung 1 organisation spends more of its first phase on separating credentials and defining a boundary; a Rung 2 organisation that already has a sandbox spends more of it on supply-chain and content-trust controls.

Three Phases, Ninety Days

Phase 1: Scope (Weeks 1-3). Run the light ladder check above (or confirm the rung from a prior TAG assessment). Identify the single, tightly bounded use case worth building first, using a value-versus-complexity assessment: high measurable pain, low technical complexity, a process stable and repeatable enough to show results inside weeks rather than quarters. Name the three people who will sit in the Oversight Core for this project. Leave the phase with a signed scope document and a governed test environment, not a slide deck.

Phase 2: Build (Weeks 4-9). Construct and integrate against real data in the test environment defined in Phase 1. Guardrails from TAG get implemented as code, not policy: content trust boundaries, dependency pinning, confidence thresholds, and the logging that Telemetry requires are built in from the first commit, not retrofitted before launch. The Engineer owns this phase; the Sponsor and Guardian both have standing visibility into it, not just a check-in at the end.

Phase 3: Prove (Weeks 10-13). Validate against the four Trust Tollgates below, complete user acceptance testing, and hand over to production with full Oversight Core sign-off. This phase does not compress. If a Tollgate fails, the go-live date moves, not the gate.

The Four Trust Tollgates

Seven granular checklist items are easy to lose track of and easier to rubber-stamp under deadline pressure. TechSight 90 uses four broader gates, each one a genuine go/no-go decision owned by a named person, not a checkbox:

Data: is the data this deployment touches accurate, access-controlled, and classified correctly, with consent and retention handled the way the relevant regulation actually requires (POPIA, GDPR, or sector-specific rules, not a generic privacy paragraph)?

Security: has the deployment been tested against the OWASP Agentic AI Top 10 specifically, including a check for the "trusted content" failure mode that sandboxing alone does not catch?

Accuracy: does the system perform correctly on edge cases and adversarial inputs, not just the happy path demonstrated in the sales pitch, and does it fail safely (routing to a human) rather than confidently when it doesn't know the answer?

Value: does the business case this deployment was built to prove actually hold up against real, measured numbers, not the projected numbers from the Phase 1 scope document?

All four Tollgates report to the Oversight Core. The Guardian's sign-off on Security and Data is non-negotiable; the Sponsor's sign-off on Value is equally non-negotiable. Neither role can wave the other's gate through to hit a date.

The Value Realization Index

Every TechSight 90 engagement ends with a scorecard built from measured numbers, not adoption anecdotes: hours saved per week, accuracy rate before and after deployment, cost per transaction, and payback period in months. These are the numbers a CFO actually asks for when deciding whether to fund the next deployment, and they are what makes the case for whichever use case TechSight 90 tackles next.

From One Deployment to a Standing Capability

A single TechSight 90 engagement proves the methodology works on one use case. It is not, by itself, an enterprise AI strategy. Clients who run more than one engagement typically move the Oversight Core from a per-project team to a standing function, carrying the same three roles and the same four Tollgates across every subsequent deployment, and typically graduate from the light ladder check to a full TAG assessment, which is exactly how an organisation climbs the Blast Radius Ladder deliberately instead of by accident.


Sources: NIST AI Risk Management Framework; McKinsey & Company, "A Generative AI Reset," 2024, on the gap between piloting and scaling AI; Gartner research on generative AI project abandonment and agentic AI project cancellation rates, 2025; JPMorgan and Uber governance case studies as cited in Tech Sight's Agentic Coding & Governance series; TechSight TAG, Tech Sight's companion governance framework.

Book an AI Audit

More from Insights

The Single Vendor Trap: Testing An AI Exit Before You Need One

2026-07-28

Why AI Initiatives Fail to Scale: Eighty-Four Per Cent Never Left The Pilot

2026-07-28

The End of Cheap Inference: The Repricing Risk Nobody Has Modelled

2026-07-28