001Engagement / 001
From fragmented platforms to one governed operating layer.
A capital-program management firm growing faster than the systems it started on. Ellis Shaw framed the target operating model, built the connected environment across the business, and now holds the ongoing transformation capability.
The situation
Nothing was broken. Everything was disconnected.
The firm was winning work faster than it could absorb it. That is a good problem, and it produces a specific and recognizable pattern: each function had solved its own problem competently and independently, and none of those solutions knew about each other.
Project controls, document management, CRM, finance, HR, and procurement each held a partial and slightly different version of the same reality. The gaps between them were bridged by people: capable, senior people spending a meaningful share of their week moving data from one system to another and reconciling the differences. The monthly executive package was an artifact of that labor rather than a product of the systems.
Underneath it sat an identity and access position that had grown organically. Onboarding a person onto a program meant a sequence of separate requests across separate queues; offboarding depended on someone remembering. As client security requirements tightened, that became a commercial problem rather than an IT one.
What we found
The operating model and the systems had quietly diverged.
We spent the first weeks in structured interviews from the executive floor to the field, alongside a full inventory of systems, integrations, licenses, and data flows. The finding was not a technology finding. The business had evolved how it actually operates, and the systems still reflected an earlier version of the company.
That divergence explained nearly every symptom on the list. The reporting was slow because the definitions were contested. The definitions were contested because no system owned them. The manual handoffs existed because there was no shared record to hand off to. And the AI conversation the leadership team was being asked about had nowhere to attach, because there was no governed data or permission model for it to sit on.
So the sequence wrote itself: foundations first, connection second, intelligence last, with adoption running the whole way through rather than waiting at the end.
What we did
Eight moves, in dependency order.
Each increment delivered something usable on its own, so the business was never holding a half-finished platform waiting on a distant go-live.
- 01
Established identity as the foundation
Before anything could be connected, the question of who someone is had to have one answer. We consolidated the directory, brought every business system behind single sign-on with enforced MFA, and modeled roles against how the firm actually assigns people to programs, including the contractor and vendor staff who make up a large share of the workforce. Joiner, mover, and leaver flows were automated against HR as the system of record.
- 02
Defined one project record
Each platform had its own idea of what a project was, with its own numbering and its own phase names. We defined a canonical project, phase, and cost-code structure, reconciled the historical data to it, and made every downstream system reference it rather than reinvent it. This is the least visible work in the engagement and the reason everything afterward was possible.
- 03
Connected pursuit through to cost
CRM, finance, HR, and procurement were joined to the project record in dependency order, so that winning work raised the questions that follow it: who staffs this, what is committed, what does it do to margin. Manual re-entry between pursuit, award, staffing, and cost was replaced with instrumented handoffs that fail loudly rather than silently.
- 04
Rebuilt onboarding as a single flow
Bringing a new person onto a program had been a sequence of parallel requests across HR, IT, security, and the project team, each with its own queue. We rebuilt it as one flow triggered from the HR record: accounts, access, devices, project assignment, and compliance items provisioned together and revoked together.
- 05
Modernized the cloud and infrastructure position
The environment had accumulated the way growing firms' environments do. We established a governed cloud landing zone, moved workloads onto it, put infrastructure under version control, and set up the deployment, monitoring, and backup posture that a firm holding client program data needs to be able to demonstrate on request.
- 06
Built the software the platforms did not cover
Several load-bearing spreadsheets were replaced with purpose-built applications on the governed data layer, and integration services were written where no vendor connector existed. All of it shipped with tests, CI/CD, monitoring, runbooks, and documentation, on the assumption that someone else will eventually own it.
- 07
Governed the numbers, then reported them
We built a metric catalogue with a written definition and a named owner for each measure, computed each one exactly once in a semantic layer, and only then built the executive views on top: portfolio health, cost-to-complete, utilization against pipeline, and risk movement. The point was not more reporting. It was ending the argument about whose number was right.
- 08
Applied AI where it had been shown to earn its place
With the record governed and permissions real, AI became viable rather than theatrical. We introduced document intelligence over the project record, retrieval scoped to what each user is permitted to see, and drafting assistance for the highest-volume repetitive writing. Each one was instrumented with an evaluation set so that quality is measured rather than assumed, and each one leaves human judgment in place where a wrong answer is expensive.
Governed foundations are not the boring part of an AI strategy. They are the AI strategy.
What changed
The business stopped reconciling and started deciding.
The clearest signal of the change is not in any dashboard. It is that a set of recurring meetings whose purpose was to agree on what the numbers were no longer need to exist in that form.
One version of a project
Executives, controllers, and field teams reference the same project record. Reconciliation between systems is no longer a job someone has.
Access that matches reality
People have what they need on day one and lose it on their last day. The firm can answer a client security questionnaire from evidence rather than from memory.
Reporting that is produced, not assembled
The executive package is generated from the governed layer instead of being reconstructed by hand from exports each month.
Growth without proportional overhead
Adding programs and people no longer requires adding the same volume of manual coordination behind them.
AI in the workflow, under governance
Applied intelligence sits inside the tools people already use, scoped by the same permissions as the underlying data, with evaluation running continuously.
A system someone else can run
Documentation, runbooks, monitoring, and named internal owners exist for every component. The firm is not dependent on us to keep operating.
Where it stands
In production, and still moving.
The environment is live and operated by the firm’s own people. Ellis Shaw continues as the retained transformation office, holding technology leadership, architecture, platform stewardship, applied-AI delivery, and vendor management on a monthly basis, with a roadmap reset each quarter against where the business is actually going.
That arrangement is explicitly designed to end. When the firm is ready to carry the capability internally, the documentation, runbooks, and ownership model needed to do that already exist, because they were built as part of the work rather than promised at the end of it.
If any of this sounds like your firm, the first conversation is free.
Book a working session