A mid-size SaaS product and IT services company in Chennai was building AI agents into its platform. The AI R&D team and the Product team were working towards the same goal in complete isolation — and nobody had noticed.
The company is a mid-size SaaS product and IT services firm based in Chennai, India — serving over 200 enterprise and SME clients across India, the UK, Australia, and the United States, across verticals including e-commerce, education, and enterprise operations. A team of under 100, moving at pace, with a product footprint larger than its headcount would suggest.
In early 2026, leadership made a deliberate decision to embed AI agents into their existing SaaS platform and develop a standalone AI agent capability for their client base. They had an R&D team already working with on-premises models. They had a product roadmap. What they did not have was any governance structure connecting the AI work to the product, the delivery process, or their customers' regulatory expectations — including a growing number of EU and UK-based clients with explicit AI explainability requirements.
They came to Orquestra AI with a question: "We're building AI. Are we building it right?"
The assessment was conducted using the Navigator Framework™ — Orquestra AI's governance standard for Governable Autonomy. The framework scores five capabilities on a 0–4 scale: Human Responsibility, Decision Governance, Engineering Capability, Knowledge Capability, and Assurance Capability. Each finding and recommendation maps directly to one or more of these capabilities.
Before the assessment began, the expectation was that the two primary functions — the R&D AI team and the Product/SDLC team — were working in close coordination. They were not. What the five-day assessment surfaced was a structural isolation that ran deeper than process gaps.
The R&D team was technically proficient — experimenting with agents, fine-tuning on-premises models, and building capability at pace. The Product team was managing a live multi-client SaaS roadmap. But the two teams had no shared language, no integration process, and no mechanism to evaluate whether the AI being built corresponded to the use cases the product actually served.
No finding was a surprise in isolation. What made them significant was the combination: without audit, accountability, or shared context, an organisation cannot tell whether its AI is working correctly, whether it is governable, or whether a regulator would accept its explanation of what the AI did.
No named human owned any AI decision. No approval trail existed for any agent output — autonomy with no responsible human attached.
No audit record. No EU AI Act explainability documentation despite an active UK/EU client base — no evidence existed to assess.
Each team was capable within its own domain but neither could evaluate the other's work. No escalation path, no shared vocabulary, no governance connecting the two.
AI output entering the product with no review gate, no test independence requirement, and no checkpoint enforcement before client delivery.
Both teams were operational independently on their own knowledge base. Cross-team knowledge governance was not the primary risk surface at this stage.
The engagement ran over four weeks with a clear phase structure — assessment first, recommendations second, implementation support third. The five-day assessment in Week 1 was intensive and structured around the Navigator Capability Model's five capabilities, applied across both the R&D AI team's development process and the Product/SDLC team's delivery workflow.
SDLC process review, AI development workflow mapping, audit gap identification, cross-team integration assessment, EU compliance gap review.
Findings synthesis, risk classification per AI use case, recommendations report delivered, joint workshop with both teams.
Hand-holding during policy drafting, HITL framework setup, explainability template development, reskilling plan initiated.
The assessment used the Navigator Controls Catalogue as its reference standard — specifically the Human Responsibility, Decision Governance, and Engineering Capability controls at Stage 1 and 2. Where the catalogue identifies a control gap, the engagement produces a named remediation owner and a defined fix.
Every gap identified in the assessment was a governance, process, or communication failure — not a capability failure. The teams were skilled. The problems were structural.
No record of what AI agents had been built, what decisions they made, on what data, under what constraints, or who had approved them for any use. Zero audit infrastructure across both teams.
The R&D AI team had no visibility into product use cases. The Product team had no visibility into AI capabilities. There was no integration process, no shared roadmap, and no mechanism to connect AI output to product requirements.
The company serves clients in the UK and EU where AI Act transparency obligations apply to limited-risk AI systems — including disclosure requirements, accountability documentation, and explainability for automated outputs. No such documentation existed for any AI agent in development. A live compliance liability in active client relationships.
AI agents were being developed without any defined human-in-the-loop approval points. No named person was accountable for AI outputs before they entered the product or were demonstrated to clients.
Product team lacked the AI vocabulary to evaluate what the R&D team was building. R&D team lacked the product knowledge to prioritise the right use cases. Neither team could effectively brief the other.
"The AI team was building agents the product team didn't know existed, for use cases the product team hadn't defined, with no record that any of it had happened."
The recommendations were delivered in a structured report and a one-week hand-holding session with both teams. Each recommendation addressed a specific gap and named the accountable owner for implementation.
A defined integration workflow connecting AI agent development to the product roadmap — including a shared backlog, a joint use-case review cadence, and a handoff checkpoint before any AI output enters the SDLC.
Each planned AI agent classified into a risk class — Low, Moderate, High, or Critical — using the Navigator Critical Controls Guide's five determinants. Higher-risk agents flagged for additional review before client-facing deployment.
A structured explainability template for each AI agent in the product: what it does, what data it acts on, what decisions it makes, and who is accountable for its outputs. Designed to meet EU AI Act transparency requirements for limited-risk systems.
Named human-in-the-loop approval points defined for each AI use case before production deployment. A named approver signs off that the AI output has been reviewed, meets the stated use case, and is fit for client use.
A foundational AI use policy covering acceptable use cases, prohibited uses, data handling by AI agents, audit requirements, and the process for reviewing new AI use cases before development begins.
A structured capability exchange: Product team trained on AI agent capabilities, limitations, and evaluation criteria. R&D team trained on product use cases, client requirements, and the business context their agents need to serve. Designed so each team could brief the other effectively.
At the end of the four-week engagement, the company had moved from a state of zero governance to a defined, operational governance posture — with named owners, documented policies, and an integration process both teams could use from day one.
From zero documented approvals for any AI output to full HITL coverage — every AI use case requiring named human sign-off before client-facing deployment.
From two teams operating with no shared process to a defined integration workflow, a joint review cadence, and a shared backlog connecting AI capability to product requirements.
From no explainability documentation to a structured template covering all EU and UK client-facing AI systems — aligned to AI Act transparency obligations for limited-risk systems.
All planned AI use cases risk-classified for the first time — Low, Moderate, High, or Critical — with higher-risk agents identified before any client deployment.
Defined R&D-to-Product integration workflow established for the first time.
HITL approval framework live — named sign-off required before AI reaches clients.
Explainability framework covering EU and UK client-facing AI, aligned to AI Act obligations.
Foundational AI use policy established — acceptable use, data handling, and audit requirements.
Both teams reskilled to brief each other — shared vocabulary between R&D and Product for the first time.
All active AI use cases risk-classified — high-risk agents identified before deployment.
The most significant outcome was not a document or a policy. It was visibility. For the first time, both teams could see what the other was doing — and had a structure to work together without one team erasing the other's context.
This engagement is a direct illustration of what the Navigator Capability Model was designed to find: AI development happening outside the governance structures that should contain it. The five capabilities — Human Responsibility, Decision Governance, Engineering Capability, Knowledge Capability, and Assurance Capability — are not abstract categories. In this case, three of the five scored at Stage 0 on day one of the assessment.
The framework works because it does not ask whether an organisation has good intentions about AI governance. It asks whether named humans can defend specific decisions, whether audit evidence exists for specific outputs, and whether the right checkpoints exist at the right points in the lifecycle. In this case, the answers to all three were no — and each no was fixable within the four-week engagement.
For this company, the exposure was compounded by active EU and UK client relationships where AI Act transparency obligations were not optional. The gap between what they had built and what they could account for was not a technical problem. It was a governance one — and it was solvable in four weeks because the framework gave both teams a common language and a clear set of named fixes.
That is what the Navigator Framework™ is for: not to slow AI development down, but to ensure that the humans responsible for it are actually in a position to defend it — at every gate, to any audience that asks.
Both documents below are free to download and share — no email gate.
A Navigator Assessment identifies the governance gaps in your AI development — before a regulator, auditor, client, or investor does.