Enterprise AI · Field Notes

The Playbook for
Deploying AI

Why unmanaged AI adoption quietly erodes cost control, security, and ROI — and what changes when core capability moves onto a sanctioned agent platform.

01 · Centralizing Intelligence

Scattered tools burn tokens.
Sanctioned agents capture value.

Each dot of light is token spend. Drag the slider: on the left, usage scatters across 50 individual tools employees have adopted, each driving its own token bill; on the right, the same work runs through 50 sanctioned agents on a governed platform — monitored, authorized, and shared by hundreds of users.

Tools in use 50
Sanctioned agents 0
SPRAWL · usage at the edge · every tool billed separately
TOOLSfragmented · shadow AI
AGENTSsanctioned · platform
Monthly token spend ▲ RISING
$30,000
cost per outcome · $2.40
Security posture
31%
Centralized intelligence
26%
Value capture · ROI
18%
02 · Vendor Independence

Rent AI from every vendor —
or own the layer between you and them.

On the left, every vendor is a control system: your AI, data, agents, workflows, and training are locked inside each one. Drag right and those assets migrate into your own control plane — the vendors shrink into swappable data sources connected by API / MCP.

Assets locked in vendors 35/35
Vendors as data sources 0/7
DEPENDENCE · AI · data · agents · workflow · training locked inside vendors
VENDOR DEPENDENCEtheir AI · their terms
VENDOR INDEPENDENCEyour platform · your terms
Cost of AI capability ▲ VENDOR PRICED
$21,000
per-seat AI add-ons · 7 vendors
Vendor lock-in risk
94%
Control & ownership
0%
Time to switch a provider
9–12 months
re-platform · migrate · retrain
03 · Converting Knowledge to AI Native

Knowledge your agents can't reach
is knowledge that can't work.

On the left, knowledge is trapped in documents, databases, people, and SaaS apps — invisible to AI. Drag right and it organizes: static knowledge runs through an embedding pipeline into a centralized vector store, live systems connect via MCP, and agents on the platform can finally act on all of it.

Knowledge trapped in silos 8/8
AI-ready sources 0/8
TRAPPED · knowledge scattered in silos · invisible to AI
0% AI NATIVEknowledge trapped · agents blind
AI NATIVE 100%vectorized + connected · agents act
Productivity lift ▼ STALLED
+0%
agents blocked by silos
Knowledge accessible to AI
4%
Automation coverage
5%
Time to find an answer
days
ask around · search 6 systems
04 · Building the Agentic Workforce

From one employee, one tool —
to one employee, a team of agents.

On the left, every employee works alone with a single AI tool — no coordination, no shared leverage. Drag right and the workforce reorganizes around a central AI platform: each employee still has their tool, but now also builds and manages three agents, all sanctioned and visible in one place.

Isolated tools 8/8
Agents deployed 0
ISOLATED · every employee alone with one tool
1:1 TOOLSisolated · uncoordinated
AGENTIC WORKFORCE1 employee : 3 agents · coordinated
Workforce output — CAPPED
×1.0
8 employees · 8 isolated tools
Coordination & visibility
10%
Work delegated to agents
0%
Agents per employee
0
isolated tools only
05 · Governance, Oversight & Compliance

Hundreds of people. Hundreds of agents.
One place to see every conversation.

On the left, a handful of users chat directly with agents — nothing is logged, nothing is checked. Drag right: the population scales into the hundreds and every conversation routes through a central governance plane running sentiment analysis, auditing, escalation checks, fraud and abuse detection, token limits, and user tracking — with a human in the loop for anything flagged.

Unmonitored conversations 97%
Checks active 0/7
UNGOVERNED · direct chatter · no logs · no oversight
UNGOVERNEDdirect · unlogged · blind
GOVERNED AT SCALErouted · checked · logged
Interactions / day ▲ UNMONITORED
1,800
visibility · none
Compliance readiness
15%
Incidents caught early
4%
Audit trail
none
who said what · unknowable
06 · From Tokens to Outcomes

Stop measuring tokens.
Start measuring FTEE.

On the left, one person with a $350/mo AI tool generates documents and code — useful, but the value drifts away untracked and ROI is a guess (~0.2 FTEE, estimated). Drag right: an agent serves 100 customers and 10 support reps, resolving tickets worth an hour of work each — outcomes land in a ledger, and the same token spend now proves 2.0 FTEE of value, $10,000+ per month.

Value attributable 0%
Tickets resolved 0
PROMPTING · tokens in · outputs drift · ROI a guess
TOKEN SPEND1 person · 1 tool · untracked
MEASURED OUTCOMES1 agent · 110 served · FTEE proven
Monthly value created ? UNMEASURED
$ ?
est. +20% productivity · unattributed
FTEE produced
0.2
Return on token spend
cannot attribute
Outcome attribution
guesswork
outputs untracked
07 · Tools + Agents

Claude Code writes the code.
raia Agents remember it for the whole team.

On the left, every Claude Code session is brilliant but ephemeral — per-developer, starting from zero, its knowledge evaporating at session end. Drag right: the raia MCP Skill connects the IDE to an Engineering Supervisor that orchestrates eight specialist agents, each backed by a vector store. Queries flow in, fresh docs flow back, knowledge compounds — and support, PMs, and execs reach the same agents through Chat, Teams, and Copilot. Hover any agent for what it knows; try the scenario player for the guided story.

Knowledge lost per session ~100%
Specialist agents online 0/8
EPHEMERAL · every session starts from zero · knowledge dies at exit
TOOLS ALONEephemeral · per-developer
TOOLS + AGENTSpersistent · shared · governed
Team knowledge retained ▼ EVAPORATES
0%
gone when the session closes
Devs on shared standards
20%
Answers reusable by team
0%
Who can ask
1 developer
inside one IDE session
08 · Beyond the Context Window

One window of context —
or an orchestra of agents.

On the left, one person uses a chat tool (Claude, ChatGPT) that fetches data over MCP one source at a time — everything must squeeze through a finite context window, and when it fills, the oldest knowledge is evicted. Drag right: an orchestrator fans work across specialist agents in parallel, each with its own vector store and MCP connections — persistent memory, every source live at once, and the whole company can ask.

Context evicted 0 chunks
Agents in parallel 0/6
CONSTRAINED · one window · serial fetches · memory evicted
TOOL + CONTEXT WINDOW1 user · serial · finite
ORCHESTRATED AGENTSmany users · parallel · persistent
Tasks in flight — SERIAL
1
one window · one task at a time
Data sources live
1/6
Memory between tasks
0%
Concurrent users
1
one seat · one conversation
09 · Anatomy of a raia Agent

From prompt-to-model —
to a fully managed RAG system.

On the left, AI is just a prompt hitting a model — raw prompt in, raw response out. Drag right and it evolves into a fully managed RAG system: prompts arrive from live chat, tools like Claude, email, API, and other agents; each one retrieves from a vector store, passes the Auditor, hits the escalation check (human in the loop when flagged), reaches out through multiple MCP servers — and only then does the LLM build the response.

Unaudited responses 100%
Skills online 1/6
PROMPT → MODEL · raw prompt in · raw response out · no control
PROMPT → MODELraw prompt · raw response
MANAGED RAG SYSTEMretrieve · govern · act
Processing steps per prompt — RAW
1
prompt → LLM · nothing else
Knowledge in reach
0%
Prompts audited
0%
Channels served
1
chat only
10 · Security — raia Command

Secrets die at ingestion —
before the vector store ever sees them.

Everything an agent knows enters through Command — and every control engages before storage. Drag right: dangerous file types bounce at the upload gate, the Security Scan destructively masks PII and secrets in the Markdown itself, AES-256 envelope encryption wraps the store, downloads require two-factor verification, and original binaries are swept on schedule. Hover any control for details and honest limitations.

Plain-text secrets in store 12
Controls active 0/6
OPEN INGESTION · anything uploads · secrets stored in plain text
OPEN INGESTIONunscanned · unencrypted
SECURED PIPELINEmasked · encrypted · verified
Secrets in plain text ▲ ACCUMULATING
12
cards · keys · SSNs in the store
Files scanned & masked
0%
Downloads 2FA-verified
0%
Original binaries
kept forever
raw files linger in storage
11 · Security — raia CX

No single perfect filter —
seven layers between attacker and data.

The agent runtime secures conversations, configuration, and connectors in depth. Drag right: the agent-status master gate, per-user rate and cost limits that fire before any tokens are spent, the probabilistic Auditor (PII · Hack · Custom), versioned guardrail packs, an isolated RAG loop reading chunks already masked by Command, and an MCP tool allow-list that holds even when an injection slips the filter — with escalation and human takeover behind it all. Hover any layer for details.

Data exfiltrations 0
Defense layers 0/7
OPEN AGENT · one door · no checks · injections walk out with data
OPEN AGENTone door · no checks
DEFENSE IN DEPTH7 layers · human in the loop
Defense layers — NONE
0
prompt → model → out
Prompts inspected in + out
0%
Tool surface exposed
100%
When an attack slips through
data walks out
nothing behind the filter
← → to change slides