Tony Bleything

THE OPERATING MODEL

The rollout had energy. What it didn't have was an operating model.

The human gate: guest data is the first question.

Client delivery

An organization that has already bought AI seats at scale and now has to decide what is safe to build, share and scale.

In financial services: Thousands of licensed staff building their own assistants, with anything touching customer data or a credit decision stopped for formal review and everything else governed by platform defaults.

A pattern, not a past engagement: it describes how this system would be used, not where it has been.

A colleague buildsa GPT or a skillQuestion 1guest data, a real decision, or many properties?YESFORMAL REVIEWa named person signs offAI COUNCILif one of five triggers firesCleared to shareNOQuestion 2internal, non-confidential,in a sanctioned tool?YESGoes ahead under platform defaultsconnectors off until a role needs themNEITHER CLEARLY APPLIES: the team's AI lead decides
The routing as the governance model designs it. Guest data is the first question; anything unclear is a person's call.

The stages

  1. A colleague builds a GPT or a skill in the shared workspace
  2. The first question: does it touch guest data, inform a real decision, or deploy to many properties?
  3. A yes stops it for formal review, where a trained reviewer runs the risk assessor and a named person signs off before anything is shared
  4. Five escalation triggers send it on to the AI Council, whatever the risk score says
  5. The second question: is it internal work on non-confidential material in a sanctioned tool? Then it goes ahead under platform defaults, with connectors off until a role needs them
  6. If neither clearly applies, the team's AI lead decides
  7. The design records each shared skill twice: in a library that feels like sharing a win, and in a restricted governance log

Where the gate sits

Guest data is the first question. Anything touching it, anything that informs a consequential decision, and anything deployed across many properties stops for a person, and five escalation triggers override whatever score the assessor gives.

What moves between stages

The decision, not the artifact. Governance attaches to the data and the kind of decision a tool informs, because models expire in months while data classifications do not. The model has the platform enforce the boundary, with apps and connectors off by default and switched on per role, rather than a policy document asking people to behave.

What broke, and how it surfaced

The sequence. Readiness, governance and build all started in week one with no gate between them, so teams were building under rules that were still being decided, and a missing data connector surfaced two days before close. And the method stayed with the builders: the client can use what was built but is less equipped to rebuild it. The retrospective turned that into six phases with a gate on every one, and a handoff tracked one deliverable at a time.

Outcomes, with sources

17working AI skills co-built with six business teamsSource The client-facing retrospective, 21 Jul 2026, logged in my evidence register (P19). Other documents count 19 or 20; no single index existed at close, so this uses the retrospective's number
~4,000ChatGPT Enterprise licences deployed, against a client target of 7,000 by year endSource A client-facing governance deck, 6 Apr 2026, logged in my evidence register (P1). Licences, not users
93%of licence holders activeSource The client's own figure, from their enablement deck of 23 Mar 2026, where it is reported as monthly active. Logged in my evidence register
3,500+GPTs colleagues had built themselves, six of them through formal reviewSource Our audit of the workspace, from my records; the six reviewed is the client's own governance record. Logged in my evidence register (P2)
$13K–$18Kestimated annual value of the Finance team's skillsSource Estimate: modelled in the client-facing skills ROI document, June 2026, on 25–35 hours saved a month across the team. Logged in my evidence register. Not a measured result

A global hospitality company had deployed about 4,000 ChatGPT Enterprise licences, and our audit found more than 3,500 GPTs its people had built themselves; six had been through formal review. Over 16 weeks, contracted through Tribe AI as the AI Adoption and Change Lead, I co-designed the governance model with the client's executives and helped six business teams build 17 working skills. The rule at the centre of it: guest data, a real decision, or many properties means it stops for a person.

Read the full story · about 2 minutes

The use case

As the AI Adoption and Change Lead on a Tribe AI engagement, I needed a global hospitality company’s AI rollout to turn broad access into governed capability, so that thousands of people could keep building without the company losing track of what touched guest data or informed a real decision.

The problem

The rollout itself had worked. About 4,000 ChatGPT Enterprise licences had been deployed, against a target of 7,000 by year end, and in March the client reported 93% of licence holders active. Our audit found more than 3,500 GPTs colleagues had built of their own. Six had been through formal review.

That gap was the problem. Anything a builder wanted to share beyond a small circle went into a formal review that took about seven business days, and at 4,000 licences that queue did not work. It taught people to keep useful work private. Reviewing every artifact could not keep up, and trying to made the ungoverned share grow.

How it works

Govern the data and the decision, not the artifact. Models expire in months: OpenAI retired GPT-4o across all plans in April 2026. Data classifications and the kinds of decisions a tool informs do not expire. So the model sorts every use into three bands by data sensitivity and decision type, and a colleague can run the routing in thirty seconds with three questions, where the first yes wins.

The first question: does it touch guest data, make or materially inform a real decision, or deploy to many properties? Then it stops and goes to formal review. Is it internal work on non-confidential material in a sanctioned tool? Then it goes ahead, governed by platform defaults. Neither clearly applies? Ask the team’s AI lead. Guest data is deliberately the first question.

The model has the platform enforce the boundary, not a policy document: apps and connectors off by default and switched on per role. Before a skill is shared, a trained reviewer runs a risk assessor against it, and five escalation triggers send it to the AI Council whatever the score says. The design splits the record in two: a use-case library that feels like sharing a win, and a restricted governance log that works as the control record.

Alongside the governance, six business teams (revenue management, finance, operations and others) built 17 working skills, with a three-level training ladder and weekly office hours. I co-designed the use-case selection and the scoring rubrics. The Tribe AI product manager owned most of the builds.

Where the human sits

At the first fork. Guest data, a consequential decision, or a deployment across many properties stops for a person, and the five escalation triggers override any score the assessor produces. Internal work on non-confidential material in a sanctioned tool runs on platform defaults, and anything unclear is a person’s call, so review effort goes where the risk is instead of spreading evenly across thousands of GPTs.

The governance model was co-designed with three of the client’s executives, and ten of its decisions were written down with what each one ruled out, so the client can defend them without us in the room.

Demo

This is client work, so the demo is a sanitized diagram I drew of the routing, not a recording or a screenshot. No client artifact appears on this site, and the client is not named.

Outcomes

Seventeen working skills in the hands of six teams, by the client-facing retrospective’s count. One team’s monthly KPI task went from a full day of work to an automated analysis. The Finance team’s skills were estimated at $13,000 to $18,000 a year, on 25 to 35 hours saved a month across the team: a deliberately conservative model, and a defensible small number rather than an indefensible large one.

The outcome I rate highest is not one I built. Once enablement was under way, client colleagues built their own tools without us, among them a market-research agent and a six-skill system with a router, several before the relevant training had even been delivered. The client named the governance facilitation as the most durable thing the engagement left behind.

What broke in production

The sequence. Readiness, governance and build all started in week one with no gate between them, so teams were building while the rules they were building under were still being decided. A missing data connector that one integration depended on surfaced two days before close instead of in the first week.

And the method stayed with the builders. The client can use what was built, but is less equipped to rebuild it, because there was no handoff model and knowledge moved informally. The champion structure never settled either: three incompatible role models were still in the record at close.

The retrospective turned both into the design I would use next time: six phases with a gate on every one, so governance is decided before building starts, and a gradual-release handoff tracked one deliverable at a time: I do it and you watch, then you do it and I watch. Everything that went wrong here went wrong in the human system, not the technology. The skills worked.