The short version
A global hospitality company had deployed about 4,000 ChatGPT Enterprise licences, and our audit found more than 3,500 GPTs its people had built themselves; six had been through formal review. Over 16 weeks, contracted through Tribe AI as the AI Adoption and Change Lead, I co-designed the governance model with the client's executives and helped six business teams build 17 working skills. The rule at the centre of it: guest data, a real decision, or many properties means it stops for a person.
Read the full story · about 2 minutes
The use case
As the AI Adoption and Change Lead on a Tribe AI engagement, I needed a global hospitality company’s AI rollout to turn broad access into governed capability, so that thousands of people could keep building without the company losing track of what touched guest data or informed a real decision.
The problem
The rollout itself had worked. About 4,000 ChatGPT Enterprise licences had been deployed, against a target of 7,000 by year end, and in March the client reported 93% of licence holders active. Our audit found more than 3,500 GPTs colleagues had built of their own. Six had been through formal review.
That gap was the problem. Anything a builder wanted to share beyond a small circle went into a formal review that took about seven business days, and at 4,000 licences that queue did not work. It taught people to keep useful work private. Reviewing every artifact could not keep up, and trying to made the ungoverned share grow.
How it works
Govern the data and the decision, not the artifact. Models expire in months: OpenAI retired GPT-4o across all plans in April 2026. Data classifications and the kinds of decisions a tool informs do not expire. So the model sorts every use into three bands by data sensitivity and decision type, and a colleague can run the routing in thirty seconds with three questions, where the first yes wins.
The first question: does it touch guest data, make or materially inform a real decision, or deploy to many properties? Then it stops and goes to formal review. Is it internal work on non-confidential material in a sanctioned tool? Then it goes ahead, governed by platform defaults. Neither clearly applies? Ask the team’s AI lead. Guest data is deliberately the first question.
The model has the platform enforce the boundary, not a policy document: apps and connectors off by default and switched on per role. Before a skill is shared, a trained reviewer runs a risk assessor against it, and five escalation triggers send it to the AI Council whatever the score says. The design splits the record in two: a use-case library that feels like sharing a win, and a restricted governance log that works as the control record.
Alongside the governance, six business teams (revenue management, finance, operations and others) built 17 working skills, with a three-level training ladder and weekly office hours. I co-designed the use-case selection and the scoring rubrics. The Tribe AI product manager owned most of the builds.
Where the human sits
At the first fork. Guest data, a consequential decision, or a deployment across many properties stops for a person, and the five escalation triggers override any score the assessor produces. Internal work on non-confidential material in a sanctioned tool runs on platform defaults, and anything unclear is a person’s call, so review effort goes where the risk is instead of spreading evenly across thousands of GPTs.
The governance model was co-designed with three of the client’s executives, and ten of its decisions were written down with what each one ruled out, so the client can defend them without us in the room.
Demo
This is client work, so the demo is a sanitized diagram I drew of the routing, not a recording or a screenshot. No client artifact appears on this site, and the client is not named.
Outcomes
Seventeen working skills in the hands of six teams, by the client-facing retrospective’s count. One team’s monthly KPI task went from a full day of work to an automated analysis. The Finance team’s skills were estimated at $13,000 to $18,000 a year, on 25 to 35 hours saved a month across the team: a deliberately conservative model, and a defensible small number rather than an indefensible large one.
The outcome I rate highest is not one I built. Once enablement was under way, client colleagues built their own tools without us, among them a market-research agent and a six-skill system with a router, several before the relevant training had even been delivered. The client named the governance facilitation as the most durable thing the engagement left behind.
What broke in production
The sequence. Readiness, governance and build all started in week one with no gate between them, so teams were building while the rules they were building under were still being decided. A missing data connector that one integration depended on surfaced two days before close instead of in the first week.
And the method stayed with the builders. The client can use what was built, but is less equipped to rebuild it, because there was no handoff model and knowledge moved informally. The champion structure never settled either: three incompatible role models were still in the record at close.
The retrospective turned both into the design I would use next time: six phases with a gate on every one, so governance is decided before building starts, and a gradual-release handoff tracked one deliverable at a time: I do it and you watch, then you do it and I watch. Everything that went wrong here went wrong in the human system, not the technology. The skills worked.