Skip to main content

What the Company Runs and What It Already Owns

The inventory establishes what the company has in production before any process is scored: which Microsoft 365 services are provisioned service by service, what the scheduling, invoicing and bookkeeping systems hold, which mailboxes and file shares carry the working documents, and which spreadsheets have become databases over time.

The inventory is derived from the live systems directly, kept current on the day the work starts. Two findings come out of it consistently. One is capability already on the invoice and never opened, covering work that could start without a new purchase. The other is spreadsheets maintained in Excel and retyped elsewhere, where manual hours concentrate before any process has been scored.

Both findings shape which routes are available when the time drains are found.

Recurring Work Found, Scored and Mapped to KPIs

Recurring work is surfaced from the systems themselves: the ticket queue, mailboxes and shared calendars, business apps, and the spreadsheets that have become databases. One session with the whole office confirms frequency and effort for each item on the list and settles which five go forward.

Each process is scored on three measurements: how often it runs per month, how many minutes a run takes, and the follow-up effort behind it. Six suitability criteria score it further: regularity, input data, verifiability, consequences of an error, system access and acceptance criteria. Totals land between 6 and 30.

Each selected process is then mapped to a KPI: a baseline in hours per month, recorded with its date and whether it was measured or estimated. The same measurement taken after the change shows what moved.

Legal Position Settled Before the First Licence

The DSGVO and EU AI Act review runs inside this pass, before any model touches company data. Its subject is the estate as it currently runs: an architecture that does not exist yet cannot be assessed. A task touching personal data keeps its place and gets a review attached, not dropped on a technicality.

For a smaller company, the plan tier matters more than the seat price. Seat count compares easily; what actually separates one tier from the next is the conditions attached to company content once it goes in. An advisory track of exactly this shape was delivered between 2026-08-06 and 2026-08-11.

What lands on the table: one checklist per stakeholder role and onboarding material for the staff who will use the tools. Running the legal question first makes the phase safe to stop: no licence year to defend.

Six
suitability criteria applied to each process, scoring between 6 and 30
One session
with the whole office and management to confirm, score and settle the list
9 questions
route questions asked in order, first match winning
Exactly 5
processes selected, each with a baseline in hours per month

The Running Systems Decide What Gets Built

Count What Is Already Paid For 2 steps
01

What the Company Has in Production

The inventory is derived from the live systems themselves: which Microsoft 365 services the tenant has provisioned, what the bookkeeping and scheduling apps hold, which mailboxes and file shares carry the working documents, what sits in the ticket system, and which spreadsheets have become databases. Reading directly from what is running keeps the count accurate on the day the work starts.
02

The Capability Already on the Invoice

The pass records what is provisioned against what anyone actually opens, service by service. Mail, files, calendar, Teams and SharePoint are counted as work an agent could take over, because that is what decides which tasks have a route at all. Capability provisioned and never opened shows up here, covering work that could start without a new purchase.
Recurring Work Found and Scored 3 steps
03

Recurring Work Surfaced from the Running Systems

Recurring work is surfaced from the systems themselves: the ticket queue for requests that arrive on a schedule, mailboxes and shared calendars for tasks that follow a fixed pattern, business apps for processes that repeat on known triggers, and spreadsheets used as databases for work that is copied or retyped regularly. One session with the office then confirms frequency and effort for each item on the list and resolves any gaps before scoring begins.
04

Six Suitability Criteria Applied to Each Process

Each process carries three measurements: how often it runs per month, how many minutes a run takes, and the follow-up effort behind it. Six suitability criteria then score it: regularity, input data, verifiability, consequences of an error, system access and acceptance criteria. Totals land between 6 and 30. The scoring produces a ranked list in a common unit, and selection works from the ranked numbers.
05

A Confirmed List of Exactly Five Processes

The scored list is ranked by monthly hours against the suitability total. A session with the whole office and management settles on exactly five processes. Two or more people naming the same process is a signal: it usually marks the item most worth solving first. The five confirmed processes each carry a KPI in hours per month, ready for the baseline step.
One Route Per Task 2 steps
06

Nine Questions in Order, First Match Wins

Nine questions run in a fixed order and the first match wins. Unclear workflows get a planning step, work living in Outlook, Excel or Teams takes the Microsoft 365 route, a portal with no interface goes to browser automation, and a fixed house standard becomes a skill or an MCP connector. Running the questions in order means the route is determined by the task itself, with the logic recorded and readable.
07

A Data Sheet Per Task, Measured in Hours Per Month

Each selected process gets a data sheet naming who performs it, who accepts the result, the current hours per month with the date and source of that figure, whether it was measured or estimated, and a target in the same unit. The baseline is the KPI that makes the effect visible: the same measurement taken after the change shows what moved.
The Legal Question, First 3 steps
08

Settled Before the First Seat Is Bought

The DSGVO and EU AI Act check sits inside this same pass, run over the systems already in production. The risk tier is classified before any routing decision is made: the places personal data is processed are located, and tasks touching it are flagged for review. Running the check on what is real means the assessment covers the estate that will carry the work.
09

Where the Data Sits, Service by Service

The review produces an EU-hosted operating concept, the data privacy conditions attached to each connected service, and the practical difference between team and enterprise licensing terms, since the plan tier is what governs whether company content stays confined to the task it was handed to. The record names the physical location, the operator, the access model and the backup destination for each service in scope.
10

Actionable Handover Per Stakeholder Role

The handover is a set of artifacts anyone can act on: a checklist per stakeholder role, onboarding material for the people who will use the tools, governance recommendations naming who approves what, and the scored process list carrying one leading route and a KPI baseline in hours per month for each of the five. That is what leaves the room, and what the next phase builds from.

Frequently Asked Questions

Do we have to replace anything we already run?
No. This is a reading exercise, not a migration plan. The bookkeeping system, the file shares, the mailboxes and the ticket system are recorded as they are, and the route assigned to each task is chosen to work against those systems rather than around them. How a connector sits in front of one without touching it is shown on the automations page. If a task can only be solved by replacing a system, that is written down as exactly that and left as a separate decision.
Is our data leaving the country?
That gets answered per connected service, before anything is connected. The review produces an EU-hosted operating concept and lists the data privacy conditions attached to each service in scope, so the record holds the physical location, the operator, the access model and the backup destination for each service. EU-hosted AI options are named alongside it, making the model provider an explicit decision.
What does the discovery pass cost us in time?
The discovery reads the running systems directly and produces the initial list from what is already recorded there. One session with the whole office and management confirms frequency and effort, resolves any gaps and settles on exactly five. No classroom day, no system change and no licence in this phase. What leaves the session is a scored list with one leading route per process, a data sheet per selected process carrying its KPI baseline, the checklist set per stakeholder role, and the written DSGVO and EU AI Act position.
What if it turns out nothing is worth automating?
Then that is the result, and the pass cost is all that was spent. The suitability totals and the hours per month are on the table before any spend, so a process that scores low is simply not selected. Either way the pass ends with the same things in hand: the scored process list with one leading route per process, a data sheet per selected process carrying its baseline, the checklist set per stakeholder role, and the written DSGVO and EU AI Act position.