Consulting Desk · AI Estate Review

The AI you already run,
named and owned.
Or listed as unowned.

The sanctioned systems. The pilots nobody closed. The tools a team bought on a card. The models quietly embedded in software you licensed years ago. Each one classified by what it touches, who owns it, and whether anyone could explain its output if a customer or a regulator asked.

You hold: the estate inventory, a risk classification per system and a keep, fix or retire call on each.

2–3
Weeks — fixed scope, fixed fee, quoted in writing first
4
Ways AI arrives — sanctioned, piloted, bought, embedded
1
Named owner per system, or it is listed as unowned
Both
Directions the count is usually wrong in

Why the count is wrong in both directions

Discovery before policy. Always that order.

Organisations write AI policy before they know what they are running. The policy then governs an imaginary estate. What we find, consistently, is that the real count is wrong in both directions — systems nobody knew were running, and systems on the register that were switched off eighteen months ago and are still being reported to a board as controlled.

So this engagement starts with discovery. Four routes in: what was formally sanctioned, what started as a pilot and was never closed, what a team procured directly on a card, and what arrived embedded inside software you licensed for another purpose. The last category is the one that surprises people, because nobody bought AI — they bought a CRM, and it now summarises customer notes with a model.

Each system is classified by what it touches (customers, regulated processes, personal data, money), who owns it, and whether anyone in the organisation could explain its output to a sceptical outsider. Then a call on each one: keep, fix, or retire.

Paper or live

This review ends on paper — a written position, correct on the day it is delivered. Sentinel is the same review delivered through Citadel, where the answer stays live instead of going stale. Review when you want the answer on paper; Sentinel when you want it to stay live.

How it runs

Every system gets a named owner, or is listed as unowned.

That is the gate. “Unowned” is a permitted answer and often the most useful line in the document — what is not permitted is a blank.

  • EngagementAdvisory Sprint — 2–3 weeks
  • MethodDiscovery before policy
  • GateEvery system has a named owner, or is listed as unowned
  • Classified byWhat it touches · who owns it · whether its output can be explained
  • Live versionSentinel — the same review, delivered through Citadel
  • Sanctioned systems, verified not assumed

    We start from your register and check it, rather than reprinting it. Entries that no longer exist come off; that alone changes most board reports.

  • Pilots nobody closed

    The proof of concept that quietly became load-bearing. These rarely have owners, almost never have monitoring, and are frequently in front of customers.

  • Bought on a card

    Team-level procurement, expensed. Found through spend, SSO grants and OAuth permission graphs rather than by asking people to declare it.

  • Embedded in what you licensed

    Models inside software you bought for another purpose. Nobody decided to run AI here, which is exactly why nobody is governing it.

  • A call on each one

    Keep, fix or retire, with the reasoning and a named owner. Plus the risk classification per system, so the list can be triaged rather than read.

The two lists that matter

What you hold, and what we will not do.

Both are in the engagement letter before you sign it. The second list is the one worth reading twice — it is where most disappointment in this market actually comes from.

What you hold at the end

  • The estate inventory — including the systems nobody knew were running
  • A risk classification per system, based on what it actually touches
  • A keep, fix or retire call on each, with the reasoning
  • A named owner per system, or an explicit “unowned” entry
  • The corrections to your existing register, both additions and removals

What we won’t do

  • Policy written before anyone knows what is running
  • Inventories built purely from self-declaration
  • Risk ratings with no statement of what the system touches
  • A register we cannot show you the discovery method for
  • Reviews that cannot name the decision they inform

When the answer needs to stay true

A paper inventory is correct on the day you sign it off.

Estates move. New tools arrive, pilots get promoted, vendors ship a model into an existing product. If the picture has to stay accurate — because a board or a regulator will ask again next quarter — then Sentinel captures the same evidence as structured data and Citadel keeps it live, with AutoDiscover running weekly.

How Citadel keeps it live

The one-day version

A Sentinel Diagnostic runs in a day across up to ten systems, and its fee is credited in full if you go further. It is the cheapest honest answer to “is this a problem here?”

Before you commit

What happens if you already have an inventory.

We already have an inventory. Is this worth doing?

We treat an existing inventory as a claim to test rather than as a finding. What is usually missing is the tools bought on a card and the models embedded in software licensed years ago. Where yours holds up, we will say so.

Do you install anything on our systems?

Not on this shape. It is interviews, documents, and read-only access where relevant. Sentinel’s pre-engagement AutoDiscover uses read-only API connections and installs no agents either.

Should we do this, or buy Sentinel?

Review when you want the answer on paper; Sentinel when you want the answer to stay live. A paper inventory is correct on the day you sign it off. If your estate is still moving, the live version is the cheaper answer.

Find out what AI is really running here.

Thirty minutes with a founder. We will tell you whether a paper review is enough, or whether the honest answer is that this needs to stay live.

Fixed fee · Quoted in writing before we start · NDA available