Co-located, remote, and hybrid
We work on-site where the work requires it: the framing sessions, the executive working groups, the high-stakes design reviews. And remotely where the work does not. We do not have a default mode; we fit the work.
Four phases, one shape, no surprises.
§ 01 ·
Every NOETRONIQ engagement moves through the same four phases. The phases exist because the work has a shape, and the shape is what makes the engagement predictable for the client: each phase has a concrete entry criterion, a concrete deliverable, and a concrete handoff. The shape is not the technique. The technique: how we conduct the interviews, how we design the artefact, how we review the work, is the firm's practice, applied phase by phase to the problem the client brings. The shape is what the client sees, in the same way on every engagement. What follows is the shape. The artefacts at each phase are described on the [Deliverables](/services/deliverables/) page; the work of each service line on top of the shape is described on the individual service pages.
The engagement begins when the client has a problem worth engaging on and has not yet named, precisely, the question the work is supposed to answer. The work of this phase is the framing: surfacing the question, making it narrower than the brief, and getting it agreed on with the leadership who will carry the work forward.
The deliverable at the end of the phase is a short, written statement of the question (typically a single page) agreed on in a working session with the executive sponsor and the people who will own the engagement on the client side. The statement of the question is the artefact against which the rest of the engagement is evaluated; if the rest of the work does not answer the question, the question was wrong.
The handoff is to the Phase 2 lead, who uses the statement of the question to scope the evidence and design work.
The engagement enters this phase with a written statement of the question. The work of the phase is gathering the evidence the position will be built on, and turning the evidence into a design: a target architecture, a paved-road library, a threat model, a target identity architecture, an evaluation harness, or whatever the service line calls for. The design is specific, dated to the version of the system it describes, and revisable when the evidence changes.
The deliverable at the end of the phase is a design artefact, in a form the client can carry forward: a reference model, a paved-road template library, a target architecture document, a written position with the evidence traceable to source. The form depends on the service. The property is the same: the client has something they can act on.
The handoff is to the Phase 3 lead, who uses the design as the input to the build or integration work.
The engagement enters this phase with a design. The work of the phase is turning the design into something that runs in the client's environment: a working integration, a deployed paved road, an identity federation contract in production, a model in production with its evaluation harness attached, or the equivalent for the service line.
The deliverable at the end of the phase is the working system, the working artefact, or the working integration, running on the client's infrastructure, with the contract tested, the deployment documented, and the monitoring in place. The artefact exists in production before the phase closes.
The handoff is to the operating team, with the operating model documented and the first 90 days of operation scheduled.
The engagement enters this phase with a working artefact and a written operating model. The work of this phase is what makes the rest of the engagement durable: the operating habits become established, the team that has to carry the work is supported through the first cycles, and the position is revised when the evidence changes.
The deliverable at the end of the phase is a transition: the engagement ends when the client's own team is carrying the work, the operating habits are visible in the team's practice, and the firm's role has moved from operator to occasional advisor. The transition is a scheduled milestone, not an open-ended retainer.
The handoff is to the client team, with the engagement's reference materials, decision records, and operating-model documents transferred.
Three things that do not change between engagements, regardless of service line, sector, or engagement length.
We work on-site where the work requires it: the framing sessions, the executive working groups, the high-stakes design reviews. And remotely where the work does not. We do not have a default mode; we fit the work.
We work in the tooling the client already uses: shared documents, a project tracker, a video call, a wiki, an identity provider, a code repository. We do not require a separate platform, a parallel tracker, or a separate identity for the engagement team.
We do not take on work we are not the right firm for. We do not extend an engagement past the point where the client team can carry the work. We do not deliver a report where a position is owed, and we do not deliver a position where a report is owed.
§ 03 ·
Numbers from the firm's own engagements over the last several years. Every number has a basis: `engagement data` (measured from real engagements), `design heuristic` (a working target the firm uses to plan), or `target` (a posture the practice is designed to maintain).
§ 04 ·
The questions we hear most often about how the firm works, in the order they tend to come up.
Most engagements run between three and nine months, with the bulk of the work in Phases 2 and 3. Phase 1 (frame the question) is six to twelve weeks; Phase 4 (operate and sustain) is sized to the work the client team is taking on, typically one to three months beyond the build. The total horizon is set in the Phase 1 working session and revised only by mutual agreement.
Engagements are priced against the Phase 1 statement of the question. The cost depends on the service line, the engagement length, and the size of the team the work needs. A typical range for a multi-phase engagement sits in the low-to-mid six figures; the final figure is set in the scoping call after Phase 1 has produced its written statement of the question.
Every engagement has a named partner who is the sponsor, one to three practitioners who do the day-to-day work, and access to the wider firm for the parts of the work that need it (security review for an AI engagement, identity review for an architecture engagement, and so on). The named partner is the single point of contact for the client sponsor and is accountable for the engagement across all four phases.
The first 30 days are the framing phase: a working session with the executive sponsor, a series of structured conversations with the people who will own the engagement on the client side, and the production of the written statement of the question. By the end of the first 30 days, the client has a one-page artefact that scopes the rest of the engagement.
The engagement ends when the client's own team is carrying the work, the operating habits are visible in the team's practice, and the firm's role has moved from operator to occasional advisor. The transition is a scheduled milestone set in the Phase 1 statement of the question. The firm remains available for ad-hoc advisory work after the engagement ends, on terms set in the engagement letter.
§ 05 ·
Six failure modes the four-phase shape is designed to prevent. Each failure mode is one the firm has seen on engagements it has been called in to rescue, not on its own work.
The engagement's work is a function of the question it is supposed to answer. A wrong question produces work that looks thorough and is operationally useless.
Evidence without a question is documentation. It is useful to have; it is not engagement work. The work of Phase 2 is the synthesis of evidence around a question that has been agreed on with leadership.
A design that is technically correct and operationally infeasible is a design that will be revised under deadline pressure. The work of Phase 2 includes a check that the client team can carry what is being designed.
The dangerous period is the parallel run, between go-live and the decommissioning of the prior system. Until the contracts are stable and the operating team has rehearsed the new artefact under load, the build is not done.
An engagement that ends the day the artefact is delivered is an engagement that does not survive the next apriority cycle. Phase 4 is where the work becomes durable — or it does not.
An engagement whose position is fixed and cannot be revised on new evidence is a position that has stopped being a position.
§ 06 ·
Canonical public frameworks that inform the firm's practice. The firm draws on these as vocabulary; the firm's operationalisation of each is its own practice, not described here.
The Identify-Protect-Detect-Respond-Recover structure is the vocabulary used to organise the security practice's operating model.
Used as a vocabulary for capability mapping and target architecture, not as a process.
The bounded-context framing and the strategic classification of capabilities (core, supporting, generic) inform the firm's enterprise architecture work.
The four team types and three interaction modes are the operating-model vocabulary the firm uses most often.
The DORA four-key-metrics framework is the delivery-measurement model the firm's engineering practice uses.
If you are weighing a decision the firm's practice is built for, a short conversation is the right next step. The conversation is scoping, not selling; the firm will tell you whether the work is a fit before any engagement letter is on the table.
Start a conversation