Skip to content
Capabilities

One operating question, whatever the work

These lines cover most of what we are asked for, and they are how the practice is organised rather than a boundary around it. Every engagement starts from the same question: which repeated work should stop, and what has to be true for it to stop safely?

01 · Advisory

Technology strategy and architecture

Decide what to build, what to buy and what to leave alone, before anyone spends money. The target state written down, with the order of work argued for.

Where this usually starts

An operational diagnostic across one business cycle, delivered as a written map with the friction ranked by cost.

Most technology spending in a mid-sized firm is committed one product at a time, by whoever is closest to the problem that week. The result is a stack nobody designed. We map what you run today against what the business actually needs it to do, identify where the duplication and the fragility sit, and produce a target state with a sequence: what changes first, what depends on what, and what can safely wait a year. Where the right answer is to keep a system you were told to replace, we will say so and show the working.

In scope

  • Current-state architecture map across applications, data and infrastructure
  • Target state and a sequenced roadmap with dependencies made explicit
  • Independent vendor and product evaluation, with no commission taken
  • Technology cost review, licence rationalisation and contract renewal advice
02 · Delivery

Systems integration and automation

Stop moving the same numbers between a spreadsheet, an accounting package and a messaging thread. We connect the software you already pay for, and build the interfaces it lacks.

Where this usually starts

One high-volume workflow, mapped and automated end to end, with the acceptance test agreed before the build.

Operational friction is rarely a missing system. More often it is several systems that do not speak to each other, held together by a person retyping figures between them. We map where each figure originates, where it is needed, and what breaks when the two fall out of step. Then we build the connective layer: scheduled syncs, event-driven webhooks, reconciliation jobs, and exception reports that surface the handful of records a person genuinely needs to look at. Where no product covers the workflow, we build the interface for it: a dispatch board, an approvals queue, a client status portal, deliberately plain and fast enough to use on a mid-range phone.

In scope

  • ERP and CRM synchronisation, including QuickBooks, Zoho and Odoo
  • Payment and settlement reconciliation across M-Pesa, card and bank rails
  • Automated invoicing, statements and client notifications
  • Operational dashboards, approval queues and client-facing portals
  • Exception reporting, so staff review the outliers rather than every record
03 · Data and AI

Data and applied AI

Reporting you can trust, and language models pointed at your own documents in a tenant you control. Retrieval and drafting that can be checked.

Where this usually starts

A scoped retrieval pilot over one document set, evaluated against questions your staff actually ask.

Reporting comes first: if two systems disagree about last month, no model built on top of them will help. We settle the definitions, build the reporting layer, then deploy retrieval over material the firm already owns. Staff ask a question in plain language and receive an answer with the source passage attached, so the output can be verified rather than trusted. Models run inside a tenant you control, with retention, logging and training-exclusion settled in writing before anything is indexed. Where a task is better served by a deterministic rule than by a model, we say so and write the rule.

In scope

  • Reporting layer with agreed definitions, so the numbers stop disagreeing
  • Document, invoice and delivery-note parsing into structured records
  • Internal knowledge retrieval, with every answer citing its source passage
  • Structured WhatsApp and email response drafting for sales desks
  • Tenant isolation, retention policy and training exclusion configured first
04 · Infrastructure

Cloud and infrastructure

Move off personal mailboxes and unmanaged laptops onto managed identity, with connectivity that fails over and backups that have actually been restored.

Where this usually starts

An infrastructure posture review across identity, backup, network and endpoints, delivered as a ranked remediation list you can act on without us.

We migrate firms onto Microsoft 365 or Google Workspace properly: managed identity, separated administrative accounts, retention and legal hold where the sector requires it, and a migration run so trading is not interrupted. Underneath it we deal with the parts nobody photographs, which are the parts that fail: the single fibre link with no fallback, the switch under someone’s desk, the server with one disk. Backups are configured, then tested by performing an actual restore, because a backup nobody has restored is a hypothesis rather than a control.

In scope

  • Enterprise email and domain migration with no interruption to trading
  • Managed identity, device enrolment and administrative account separation
  • Encrypted offsite backup with a documented, rehearsed restore
  • Network, failover connectivity and on-site infrastructure remediation
05 · Risk

Cybersecurity and digital trust

Most of the controls that would have prevented the incident are already in the licences you hold. We switch them on, prove they work, and write down who has access to what.

Where this usually starts

A security posture assessment against a written baseline, with findings ranked by exposure rather than by severity label.

Business email compromise is among the most damaging incidents a small firm can suffer, and it is usually preventable with controls the firm is already paying for but has never enabled. We enforce multi-factor authentication, set conditional access, remove standing administrative privilege, and review who can reach what. Then we document it, because a control nobody has written down is a control nobody can audit. For regulated clients we prepare the evidence an examiner or the ODPC will ask for, before they ask for it.

In scope

  • Multi-factor authentication and conditional access rollout
  • Access review, privilege reduction and joiner-mover-leaver process
  • Security posture assessment against a written baseline
  • Kenya Data Protection Act readiness and ODPC registration support
  • Staff awareness training on the attacks that actually reach them
06 · Managed service

Managed services and support

Someone who answers when a laptop, a printer or a link fails, and who improves one workflow every month rather than waiting to be asked.

Where this usually starts

A monthly retainer sized to seat count, with the response commitment written into the agreement.

Building a system is the short part. Keeping it working, patched and understood by the people who joined after it was built is the rest. A retainer covers the helpdesk your staff call, the monitoring that notices a failed backup before you do, the patching nobody schedules, and one agreed improvement each month so the estate gets better rather than merely surviving. The response commitment is written into the agreement rather than described on a website.

In scope

  • Remote helpdesk for staff workstations, email and network faults
  • Backup verification, patching and endpoint monitoring
  • One agreed workflow improvement per month, scoped in advance
  • Independent hardware and vendor procurement advice
  • Documentation kept current, so a new joiner is not dependent on us
Scope discipline

What we will not sell you

A short list, kept deliberately public. It is the fastest way to tell whether we are the right firm for the problem in front of you.

A system where a written procedure would do
If three people follow a rule consistently, automating it adds a dependency and removes nothing. We will say so.
An AI feature with no measurable task behind it
A model that cannot be evaluated against work someone is currently doing is a demonstration, not a deliverable.
A platform migration you did not ask for
Replatforming is expensive and disruptive. We will fix the integration before we propose replacing the system.
Licences we earn commission on
We take no vendor commission. Where a product is right, you buy it directly at the price you negotiate.
Anything not listed

The lines above are how we are organised, not what we are limited to

They cover most of what we are asked for, which is why they are the headings. Plenty of work does not announce itself as one of them, and a problem being unusual is not a reason not to ask.

Work we have taken that sits between the headings, or outside them entirely:

  • A licence audit before a renewal negotiation
  • Recovering an account nobody had the credentials for
  • Moving a business off one accounting package onto another
  • Untangling a domain and email setup left by a previous supplier
  • Specifying and buying hardware for a new office
  • Structured cabling and network layout for a fit-out
  • A one-off data clean-up before a system goes in
  • Training staff on a system somebody else installed
  • A second opinion on a quote from another firm
  • Getting a stalled project finished

If it runs on a computer or a network and it is costing you time, money or sleep, describe it and we will tell you plainly whether it is ours to take. Where it is not, we will usually know who should.

Which of these is the pressing one?

Or describe something that is not on the list. A diagnostic answers it either way, with a written output and no obligation to proceed.