Skip to content

Model · How an engagement is structured

One person owns your outcome. The engine sits behind them.

Most firms make you choose: a senior you trust, at a rate that hurts, or a distributed team at a price that works and a distance you have to absorb. We split the role instead. The person who owns your result sits in your working hours. The team that builds and proves it does not need to.

The split

Two jobs, fused by habit. We separate them.

An engineer who owns a customer is doing two jobs at once: holding the relationship and the intent, and running the build. They are different jobs. They need different things. And they do not have to happen in the same building — or the same country — once you can show your working.

So the seat that owns your outcome sits close to you. The pod that builds and verifies sits where the cost base is. What connects them is not optimism about communication; it is a stack of evidence that means the same thing wherever it was produced.

Split the role, bridge it with proofA client-facing engineer onshore owns the relationship and the outcome; an offshore pod runs the build and the gates. The proof stack bridges them.ONSHORE / NEARSHOREClient-facing engineerIn your time zone, and insideyour trust. Owns intent, therelationship, and the outcome.CARRIESTRUST + OUTCOMEOFFSHOREBuild-and-verify podWhere the cost base lives.Runs the belt, owns the gates.Low cost becomes your price.CARRIESTHE BELT + THE PROOFTHE PROOF STACKconformance · traceabilityreconciliation · panel verdictschain of custodyEvidence travels across distance in a way reassurance never does.
One senior owns the outcome in your time zone. Evidence — not reassurance — carries the distance.

The pod

Four seats that are never left empty.

When generating code got cheap, the junior-heavy pyramid stopped making sense. The unit of delivery is now a small group that owns one outcome end to end, rather than a large team that owns a backlog. One person can hold more than one seat — with a single exception, below.

ORC
Orchestrator
Owns your outcome and the specification. This is the seat that sits in your time zone, joins your standups, and is accountable when the answer is I don't know yet.
Client-facing →
SPEC
Spec engineer
Authors the contract and holds what you actually meant, as distinct from what got written down. Runs the feasibility review before anything locks.
Front of the belt →
VER
Verifier
Owns the gates and holds the authority to stop a release — including over the objections of everyone else on this list. Never verifies work they produced.
The gate →
EXP
Experience lead
Owns the built experience and checks it against what was approved, screen by screen. The seat that catches a UI that drifted while every test stayed green.
Conformance →
The pod: four seats around one owned outcomeA small team owning one outcome end to end, rather than a large team owning a backlog. Four of the five seats must always be filled.Outcomeowned end to endOrchestratorspec + outcomeVerifierthe gatesSpec eng.the contractExperiencethe built UXAgent eng.drives agents
Four seats that cannot be empty. The verifier can stop a release.

The exception: nobody verifies what they built. Multi-role is fine and normal on a small team. One engineer building one thing and verifying a different thing is fine. The same person signing off their own work is not, and no deadline has ever been a good enough reason.

The chain of custody

The paperwork that settles the worst conversation.

Every services firm eventually has the same conversation: this is not what we asked for. It is unwinnable from a distance if the only record is memory and a thread of emails. So the record is built as the work happens, not reconstructed afterwards when it is already too late.

  1. 01

    Every change request is a document

    Versioned in the repository, with its criteria written down, its design attached, and a feasibility review signed off with your technical contact before it locks. After lock, a change is a new revision — never a verbal adjustment someone half-remembers.

  2. 02

    Every contribution is attributable

    Each role's work lands as a commit against the change it belongs to. The audit trail is not a document someone maintains; it accumulates as the residue of working in the open, which is why it costs almost nothing to produce.

  3. 03

    The trail settles the argument

    When a delivery matches the signed spec, this is not what we asked for stops being a negotiation about competence and becomes a review of an approved document — one you can hold us to from any time zone.

Your data

What may reach a model, and what may not.

An engineering practice that uses AI has a security question the old review was never built to catch. Keeping secrets out of source control is the floor. The ceiling is that a careless prompt can put your regulated data across a border and into a vendor's retention window, and no code review will ever see it happen.

So it is settled in writing before any work starts: what data may enter a model context and what is redacted or synthesised first; which endpoints and retention terms are permitted and which cross a border we may not cross; where a private or on-premise model is required instead of a public API; and, in regulated work, which named credentialed person signs the correctness gate and carries the accountability a firm and an agent cannot.

A practice that proves the code correct while leaking your data through a prompt has proved the wrong thing.

The honest edges

Where this model stops working.

A trail proves conformance, not fitness. When what we delivered matches what you signed, the record settles it. When the delivery matched the spec and still did not do what you needed, the record settles nothing — that is a different failure, it is usually more expensive, and we treat it as its own category rather than filing it under yours.

It needs you to be able to say what you want. This structure runs on intent that can be written down and locked. If you are genuinely still discovering what the product should be, a feasibility-gated lock is the wrong instrument, and we would rather scope a discovery engagement than sell you a machine that fights you.

We are describing our structure, not a track record for it. This is how our engagements are organised and what you would be handed. We are not claiming it has been run end to end, start to finish, across a full engagement and measured — because it has not, and you should discount anyone who tells you their method is finished.

FAQ

What buyers ask about the structure.

Where are your engineers actually based?
The client-facing seat sits in or near your time zone. The build-and-verify pod is distributed across regions selected for overlap with US business hours, and we cover the specific geography under NDA on the discovery call. The reason we lead with the evidence rather than the map is that the map has never been what makes distributed delivery work or fail.
Isn't this just offshore delivery with a nicer name?
Offshore delivery is the cost structure, and we don't pretend otherwise — it is why the price works. What is different is what crosses the distance. The usual arrangement asks you to trust people you cannot see; this one hands you conformance rows, a traceability matrix and a change trail instead. If the evidence isn't good enough to replace presence, the model has failed and you should hold us to that.
Who do I actually talk to?
One senior person who owns your outcome, in your working hours, for the life of the engagement. Not a rotating account manager, and not a queue. If that person changes, you're told before it happens and told why.
What happens when something conforms to the spec but still doesn't work for us?
That is a real failure mode and it is not a conformance failure — the spec was wrong, or the world changed. We treat it as its own category: it enters change control, we say plainly that the original criteria were met, and we agree what moves. What we don't do is quietly reclassify it as our defect or your fault. That distinction is written into the contract before work starts.
Does the verifier really stop releases?
Yes, and it is the one authority that does not get overruled by commercial pressure, including ours. A verifier who can be talked round under a deadline is a formality, and a formality is worse than nothing because it produces a signature that means nothing.

Ask who'd own your account.

Thirty minutes, no deck. We'll tell you which seat you'd be talking to, what the pod behind them looks like, and what lands in your inbox at each checkpoint.