When you need it
Your developers already use GitHub Copilot, Claude Code or Cursor, often with broad cloud credentials and no shared rules. Nobody can say what the agents may touch, where their answers come from or who approved a change.
What sets the quote
- Sized by the repositories, teams and agent tools in scope.
- One week: up to 5 repositories, 2 teams and 2 agent tools.
- Two weeks: up to 15 repositories, 5 teams and 4 agent tools, including infrastructure repositories that deploy to production.
- Larger scopes are quoted after the call.
What changes
- Every repository in scope has a written working agreement that tells agents what they may and may not do.
- Agents draw on your documentation and repository conventions through MCP servers you have approved.
- Agents work with read-only cloud identities, and every production change needs a named person's consent.
- AI-written code passes the same scans, policy checks and reviews as any other change.
What you get
- AI usage policy for engineering, written for your tools and risk level
- Working agreements for each repository in scope, as agent instruction files such as AGENTS.md or CLAUDE.md
- Grounding setup with approved MCP servers and documentation sources on an allow-list
- Read-only cloud identities for agents, with short-lived credentials and rules for handling secrets
- Review gates: a plan before the build, secret and policy scans before push, a reviewer agent before go-live and human consent for every production change
- Repository templates, so every new repository starts governed
- A 90-minute training session for your engineers
We work this way every day: coding agents in production repositories under written working agreements, grounded through MCP servers and repository conventions, with read-only cloud identities, human consent before every production change and reviewer agents before go-live. If you do not yet know which AI tools your teams use, start with the AI risk quick scan.
Not included
- Licences for the agent tools
- Building new MCP servers or custom agents (quoted separately)
- Rebuilding your CI/CD pipelines (quoted separately as keyless pipelines and secrets cleanup)
- Legal review of the tools' terms and data processing agreements
What we need from you
- An admin who can change the organisation settings of the agent tools in scope.
- Write access to the repositories in scope; every change arrives as a pull request for your review.
- A platform engineer who can create the agents' read-only cloud roles from Terraform we provide.
- One lead engineer per team for two 60-minute workshops, and two or three pilot repositories.
How it works
Free 30-minute call to count the repositories, teams and agent tools, then a written fixed quote.
Inventory of the agents, credentials and MCP servers already in use.
Policy and working agreements drafted with your lead engineers, then piloted on two or three repositories.
Rollout to the remaining repositories, then templates, training and handover.
At a glance
- Duration
- 1–2 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
AI risk quick scan
In 1–2 weeks, a read-only review of the AI tools, model keys, agents and data flows in your organisation, with the risks ranked and a 30/60/90-day plan to fix them.
AI model access and release gates
Give your applications one controlled route to AI models with a keyless fallback, keep model calls in EU regions and hold generative features back until evaluation and data-protection sign-off.
AI platform landing zone
A governed place in your cloud for AI agents and AI-enabled apps, built as code in four to six weeks: inherited guardrails, approved models and regions only, and a keyless identity for every agent.