The fourth capability inside our Fractional CIO practice. We design and build the small internal apps and automations that kill your spreadsheets, approval emails and double entry — with identity, data controls and AI governance designed in, not retrofitted.
Sydney operating base · On-site across NSW · Remote across Australia
We map the manual work end to end, rank each workflow by payback, effort, data sensitivity and risk, and agree the first build. Output is a ranked backlog you keep either way.
One bounded internal app — request and approval flows, registers, intake forms, tracking and reporting — designed, built, tested and deployed into your environment.
Drafting, triage, extraction and summarisation built with human review gates, evaluation criteria, rollback and the evidence ISO 42001 expects.
Connecting the systems you already pay for — Microsoft 365, finance, CRM, ticketing — so data moves once, in one direction, with logging at each hop.
Identity and access model, data classification, least privilege, logging, retention and offboarding documented before a line of code ships.
A small monthly retainer covering changes, monitoring, dependency and security patching, and a quarterly review of whether the app still earns its place.

Purchase, leave, discount and access requests chased through inboxes with no record of who approved what, or when.
The same details re-keyed into four systems, checklists in a shared document, and no view of where anyone is up to.
A spreadsheet nobody trusts, last updated by someone who has left, quoted straight back to you in a due-diligence questionnaire.
Issues arriving by text, email and hallway conversation, triaged from memory, with no timeline you could reconstruct later.
A fortnight of scrambling every time a customer asks for policies, certificates and control evidence you already hold.
Someone senior spending two days a month copying numbers between systems to build a report that is stale on arrival.
Worked examples from Australian small businesses and not-for-profits. Each one is a bounded build — weeks, not quarters — and each one produces evidence you can hand to a client, a funder or an assessor.
One intake form for suspected phishing, lost devices and system outages. It timestamps the report, notifies the response lead, walks them through the containment steps and holds the decision log.
Outcome: A defensible timeline for OAIC notifiable data breach assessment, instead of a reconstructed email trail.
Control owners are prompted on a schedule to upload the evidence they already produce — access reviews, backup tests, training completions — against the ISO 27001 or Essential Eight control it satisfies.
Outcome: Audit and client due-diligence packs assembled in an afternoon rather than a fortnight.
A short risk-tiered questionnaire, automatic escalation when a supplier touches personal or client data, and a renewal reminder tied to the contract date.
Outcome: A supplier register that survives a CPS 234 or client third-party risk question.
Sensitive intake captured once, with consent recorded explicitly, records segregated by program, and access limited to the caseworkers actually assigned.
Outcome: Privacy Act obligations handled at the point of collection, not patched afterwards.
Milestones, spend and outcome measures against each funding agreement, with the reporting artefacts attached where they were produced.
Outcome: Acquittal reports drawn from live data instead of a month-end spreadsheet reconstruction.
Working With Children Check and police check expiry tracked with automatic reminders, and role access revoked the day a clearance lapses.
Outcome: Screening compliance you can evidence on request, without someone owning a calendar of expiry dates.
The productivity win is easy. The governance debt is what catches people eighteen months later, when a client asks who has access to that data. Every gate below exists to make sure you never have to answer that question badly.
Map the workflow as it actually runs, not as the process document claims. Agree the measurable outcome: hours reclaimed, error rate, approval lag.
Data classification of every field the app will touch.
Identity model, roles, least privilege, logging, retention and offboarding decided before build starts.
Access model and logging standard signed off by the accountable owner.
Bounded scope, real data handled under real controls, integrations logged at each hop, no shortcuts that create a later cleanup.
Secrets management, environment separation and change history.
Where AI sits inside the workflow, we set the review points, the evaluation criteria and the rollback path before it touches production.
Human-in-the-loop evidence mapped to ISO 42001 controls.
A controlled pilot group, measured against the outcome agreed at Gate 1, then handover with documentation and a runbook.
App entered in your application register with an owner and review date.
In most organisations we walk into, staff have already built something — a Power App, a Copilot Studio agent, an automation wired to a personal account. That is not a discipline problem, it is an unmet need. We inventory what exists, classify the data each one touches, keep the ones that earn their place under proper controls, and retire the rest.
The output is an application register with an owner, a data classification and a review date against every entry — the same artefact that satisfies an ISO 27001 assessor and an ISO 42001 AI inventory requirement.
See how we govern AI and app sprawlIn your repository, under your ownership, with the commit history intact.
Architecture, data model, access model, integrations and known limitations, written for the person who inherits it.
How to deploy, how to restore, who to call, what to check monthly and what triggers a review.
The questions an internal IT, security or privacy lead tends to ask before an app is allowed into production. Answers assume the app is deployed and run inside your environment, not ours.
It runs in your environment — your Microsoft 365 tenant, your Azure or AWS subscription, or your own hosting. We never host your app or your data. You hold the admin accounts, the billing and the deletion keys; we hold contributor access for the build, which is revoked or scoped down at handover.
Single sign-on against your existing identity provider (Entra ID, Google Workspace or equivalent), with role-based access and least privilege as the default. No separate app passwords, no shared accounts. Offboarding is wired to your joiner-mover-leaver process so access dies the moment the account is disabled.
Every approval step names an accountable role, a delegation path and a dollar or risk threshold. The app records who approved, what they approved, when, and on what basis — a defensible audit trail rather than a forwarded email. Thresholds and delegations are configuration, so they change without a rebuild.
Delegation is explicit. Each role has a named delegate and an expiry, set at build time. When an approver is away, their delegate sees the pending items; when they return, the delegation lapses automatically. Nothing sits unactioned because one person is on annual leave.
At Gate 1 we classify every field the workflow will touch — public, internal, confidential or sensitive — against your obligations (Privacy Act, client contracts, sector regulation). We collect only what the workflow needs, store it only as long as the retention rule requires, and never log or duplicate sensitive fields downstream.
In your tenant or your data store, under your existing backup, retention and recovery controls. Access is scoped by role and, where it matters, by record — a caseworker sees only their assigned clients, a reviewer sees only items waiting on them. We document the data map so you can answer a "who can see what" question in minutes, not a fortnight.
The app goes into your application register with an owner, a data classification, a review date and a logging standard. That register is the same artefact an ISO 27001 assessor and an ISO 42001 AI inventory expect to see. We hand over a runbook covering deployment, restore, monthly checks and review triggers, and the optional retainer covers patching and the quarterly "does it still earn its place" review.
You are — and we make that accountability practical rather than theoretical. Every AI step has a named human reviewer, evaluation criteria and a rollback path, decided before production. The review points and the evidence of review are logged, so you can show an assessor not just that AI was used, but where a human caught it and what they did.
A few questions about the workflow, the data it touches and the approvals it must pass. Enough for us to tell you whether it is worth building, and what it would take to get it through your own security review.
Not another consulting firm. Former enterprise CIOs bringing operator-grade cyber and AI leadership to Australian SMEs.
Cyber strategy, compliance and AI sit with one operator who has led technology inside banking, healthcare, higher education and government.
ISO 42001 practitioners. We secure the enterprise for AI before spinning up flashy tools. Frameworks first, tooling second.
Cybersecurity strategy, ISO 27001 and ISO 42001 compliance, and AI consulting delivered as one plan with shared evidence and a single audit cycle.
Sydney-based, delivering across NSW. On-site when it matters, remote-first when it does not.
Every engagement includes FORTE/CYBERx platform access. Our consultants use it live in your board meetings — you keep using it after we leave.
Share the decision or constraint. A senior operator replies within one business day — no sales pod, no scripted discovery.
Run two full decision analyses free, compare practical paths and create a Decision Record and Tactical Plan.
Something small and specific: a leave or purchase approval flow, a client onboarding tracker, an asset or supplier register, an incident intake form, a compliance evidence portal, a reporting pack generator. If it currently lives in a spreadsheet plus a mail thread, it is a candidate.
Most builders can produce a working app. Far fewer can tell you where the data lives, who can see it, what happens when an AI step gets it wrong, and how the whole thing answers a client due-diligence questionnaire. We build and govern, because we run the cyber and ISO 42001 work as well.
We design and build end to end — discovery, architecture, build, secure deployment, pilot and handover. The same fractional CIO who scopes it stays accountable through go-live.
We are deliberately not tied to one stack. Where you already run Microsoft 365, Power Platform is often the fastest safe path. Where you need more control, we build a purpose-built web app. The choice is made on data sensitivity, integration needs and total cost of ownership, not on what we prefer to sell.
No. You own the code, the documentation, the environment and the runbook. The support retainer is optional and month to month — plenty of clients take the handover and run it internally.
By registering every app: an owner, a data classification, an access model, a logging standard and a review date. That register is the same artefact that governs whatever your staff have already built in Power Apps or Copilot Studio.
A discovery sprint is typically two weeks. A first bounded micro app is commonly four to eight weeks from sign-off to pilot, depending on integrations and how clean the source data is.
Fixed scope for discovery and for each build, then an optional monthly retainer for run and improve. Pricing is consultative and scoped after a discovery call.
Tell us the decision, constraint or opportunity. A senior operator responds within one business day.