Services
Five things, done in the right order.
Advisory, policy, privacy, implementation and agents. Start where it hurts. Each piece stands on its own and makes the next one easier.
01 · Advisory
Advisory
Decide what AI should do here.
WHAT IT INCLUDES
- Readiness review across strategy, data, people, security, governance and workflow
- Use-case mapping ranked by hours saved and risk carried
- Build-versus-buy and vendor evaluation with a written scorecard
- Board, trustee and leadership briefings in the language your people use
- A 12-month roadmap with owners, budget ranges and decision points
Usually starts with the AI Readiness Review · 2–3 weeks
Most organizations don't have an AI problem. They have a decision problem: staff are already using AI, vendors are already pitching it, and nobody has said out loud what it is for, what it must never touch, and who decides.
Advisory work starts there. We sit with the people who do the work, learn how it runs today, and come back with a plain-language read: where AI would take real hours off the table, where it would create risk you can't afford, and what to do in what order.
A clear, written answer to “what should we do about AI?” that a non-technical board can approve.
Who's in the room
Whoever runs the work: the office manager, the training director, the fund administrator, the program lead, the owner. Not just leadership. The people who will use AI every day know where the hours go and what must never be automated, and their answers shape the roadmap more than any vendor demo.
02 · Policy & Governance
Policy & Governance
Write the rules people will actually follow.
WHAT IT INCLUDES
- AI use policy and a one-page do's-and-don'ts card
- Approval path and intake form for new AI tools and uses
- Oversight roles and a human-review rule for consequential decisions
- Policy structure aligned to NIST AI RMF 1.0 and the ISO/IEC 42001 management-system pattern
- Contract, procurement and bargaining language for AI where you need it
- Staff briefing and a 12-month review calendar
Usually starts with the AI Use Policy Sprint · 3 weeks
A policy nobody reads is a liability, not a control. We write yours for the people who will live with it: office staff, instructors, organizers, case workers, finance. Short sections, real examples, a card that fits on a desk.
Behind the plain language is structure that holds up: roles and accountability, a way to approve new tools, tiers for uses that touch a member, an employee, a patient or a dollar, and a calendar for revisiting the rules as AI and the law change.
Rules your people understand, a record you can show a regulator, a trustee or a member, and a way to keep them current.
Where the rules come from
We write policy to the structure of NIST AI RMF 1.0 and the Generative AI Profile, and to the management-system pattern in ISO/IEC 42001, so certification is reachable later if you ever want it. Anything touching workers follows the Future of Privacy Forum's Best Practices for AI in Hiring & Employment (August 2026) and is consistent with the AFL-CIO's Workers First principles: notice, human review, a right to ask questions, and training led by the people affected.
03 · Privacy & Security
Privacy & Security
Keep member, employee and client data where it belongs.
WHAT IT INCLUDES
- Data map: what you hold, where it lives, who touches it, and what law governs it
- Shadow-AI discovery across browsers, add-ins, bots and personal accounts
- Vendor and data-handling review with a written questionnaire and scorecard
- Private-versus-public AI decision for each class of data
- Threat modeling against OWASP Top 10 for LLM and Agentic Applications, mapped to MITRE ATLAS
- Incident playbook: what to do when something is uploaded that shouldn't have been
Usually starts with the Privacy & Security Review · 3–4 weeks
The most common AI incident isn't a hack. It's a spreadsheet of members pasted into a public chatbot, a PDF of course material uploaded to a free tool that trains on it, or a meeting-notes bot that quietly joined a grievance call.
We map what data you hold and who touches it, discover the AI tools already in use, review each vendor's data handling in writing, and rank fixes by risk. Where you build, we threat-model against the same lists the security community uses for AI systems and agents.
You know where your data is, what is allowed to touch it, and what to do the day something goes wrong.
What we check against
Assistants are tested against the OWASP Top 10 for LLM Applications (2026 edition); agents against the OWASP Top 10 for Agentic Applications. Threat models map to MITRE ATLAS so your security team, or your insurer, can read them. We name the laws that bind you today — Illinois, California, Texas — and the ones arriving on January 1, 2027 in Colorado and California.
04 · Implementation & Integration
Implementation & Integration
Put AI to work inside the systems you already run.
WHAT IT INCLUDES
- Private AI deployment in your environment, or hosted for you, with your data staying yours
- Connections to membership, dispatch, training/LMS, benefits, accounting, Microsoft 365 and Google Workspace
- Assistants over your own material: policies, contracts, manuals, course content
- Rollout plan, role-based training and a measurement baseline
- Documentation and hand-off so you own what runs
Usually starts with the Implementation Blueprint · 4–6 weeks
AI earns its keep when it lives where the work happens: inside the membership system, the training records, the finance workflow, the inbox. Bolted on the side, it becomes one more tab nobody opens.
We stand up private AI in your environment or ours, connect it to the systems you already run, train your people on their own work, and measure the result in hours and errors, not demos. We deliver on Parseek, our private AI platform, when it fits; we recommend something else when it doesn't.
AI your staff use every day, in the systems they already know, with a number attached to what it saves.
Private, public, or both
Not every use needs a private system. Drafting a newsletter can happen in a well-configured commercial tool; anything that names a member, a patient or an employee stays inside. We make that split explicit by class of data, then build the private side to match. Everything runs with an off switch you control.
05 · Agentic AI
Agentic AI
Build agents that do real work, with a person in the loop.
WHAT IT INCLUDES
- One workflow scoped end to end, with the autonomy level chosen with you
- Approval gates before any action that affects a person, a record or a dollar
- Logging, monitoring and a plain-language activity report
- Threat modeling against OWASP Top 10 for Agentic Applications
- Go/no-go review after the pilot, and a path to the next workflow
- Ownership: code, prompts, configuration and documentation handed to you
Usually starts with the Agent Pilot · 6–8 weeks
An assistant answers a question. An agent does a job: reads the remittance file, flags what doesn't reconcile, drafts the letter, schedules the follow-up, and stops to ask a person before anything goes out. How much it is allowed to do on its own is a choice you make, not a default you inherit.
We build agents one workflow at a time, in production, with the guardrails written into the build: what it may touch, what it must ask about, what gets logged, and who can turn it off. Everything we build is yours, documented, and portable.
A working agent in production that your team trusts because they can see what it did and stop it when they want.
The autonomy ladder
Rung one: the agent drafts and a person sends. Rung two: it acts and a person reviews the log. Rung three: it acts and escalates only exceptions. Most organizations should start on rung one with a single workflow and move up only when the log has earned it. We put the rung in writing before we build.
Next step
Not sure which one you need first?
Take the five-minute readiness check, or tell us what's happening and we'll say which piece fits — including “none yet.”
NO SALES DECK · NO OBLIGATION · ASK@SOLIDARE.AI
