Services · SIC 62020

Six advisory lines, each ending in a document you keep.

Everything below is consultancy. We are not a software house with a consulting arm and we hold no reseller agreements, so each line is written the way we would want it written if we were the ones buying: what it covers, what it deliberately does not, what you receive at the end, and what we need from you to do it properly.

01 — Assessment

Technology assessment

The honest inventory. What you are running, what it costs, and where it is going to hurt.

Most organisations have never had anybody independent look at the whole estate at once. Systems accumulate: one bought by finance, one inherited from a departed manager, one written years ago by somebody's nephew. An assessment puts all of it on a single page and tells you, in order, what deserves your attention.

What we examine

  • Applications in genuine daily use, and the ones being paid for but quietly abandoned.
  • Hosting, servers, domains and where each one is actually registered.
  • Licence counts against real headcount, and renewal dates that arrive without warning.
  • Integrations and the manual re-keying that exists because an integration does not.
  • Backups, and whether anyone has tried restoring from one.
  • Support arrangements — who is contracted to fix what, and by when.
  • Key-person risk: the systems only one person understands.

What it excludes

An assessment is a review, not a repair. We do not remediate what we find, we do not configure or install anything, and we do not perform penetration testing — where a genuine security test is warranted, we say so and help you scope it for a specialist testing firm. We also stop short of auditing your finances; if a licence looks over-purchased we will say so, but the numbers remain yours to verify.

What you receive

  • A current-state map of systems, hosting and the data moving between them.
  • A findings register, each item scored for cost, risk and urgency.
  • A recommendation list separated into fix now, plan for, and leave alone.
  • A walkthrough session where you are invited to argue with all of it.

What we need from you

An hour each with three or four people who use the systems daily, read-only access where an interface tells us more than a description would, a list of what you currently pay for, and one person empowered to answer questions between sessions.

02 — Architecture

Architecture & systems design

A target design precise enough to build against, and to hold a supplier to.

Bad systems are rarely the result of bad programming. They are the result of nobody ever writing down how the pieces were meant to fit together, so each supplier made a reasonable local decision and the whole became incoherent. This line exists to produce that missing document before the money is spent.

What we produce

  • A component diagram: what exists, what is being added, what is being retired.
  • Data flows, with the system that owns each piece of information named explicitly.
  • Integration points — protocol, direction, frequency and what happens when one fails.
  • Environment and deployment expectations, described so a supplier can price them.
  • A staged migration route, sequenced so each stage leaves you in a working state.
  • The decisions we rejected, and why — so nobody re-opens them in six months.

What it excludes

We do not write the code, configure the platform or manage the build. The design is deliberately vendor-neutral: where a category of product is required we describe the category and the selection criteria rather than naming a favourite, and if you want help choosing within that category, that is the vendor selection line below.

What you receive

  • A design document with diagrams, in an editable format you own outright.
  • A written record of the constraints and assumptions the design rests on.
  • A phased route from the current state to the target, with a checkpoint per phase.
03 — Cloud

Cloud & infrastructure advice

The options priced side by side — including the option of changing nothing.

“Move to the cloud” is not a decision; it is a category of decisions, each with a different bill attached. Our job is to put the realistic figures next to each other, be explicit about the assumptions holding them up, and tell you which parts of the estate genuinely benefit — because some of them will not.

What we cover

  • Which workloads move, which stay, and which should be retired instead of migrated.
  • Run-cost modelling past the introductory discount, including egress and storage growth.
  • Licensing implications of moving — often the largest surprise in the whole exercise.
  • Resilience and recovery expectations, written as targets rather than adjectives.
  • Migration sequencing and the rollback position at each step.
  • Exit and portability: what it would take to leave the provider you are about to join.

What it excludes

We do not perform the migration, hold your cloud accounts, or resell hosting of any kind. We hold no partner status with any provider, which is precisely why the appraisal is worth reading. Where a figure depends on something only the provider can confirm, we label it as an estimate rather than presenting it as fact.

What you receive

  • A costed options paper, with a recommendation and the conditions under which it holds.
  • A sequenced migration outline suitable for putting out to tender.
  • A written statement of the assumptions behind every number in it.
04 — Security

Security & resilience review

The unglamorous baseline: who can get in, what is patched, and whether the backup actually restores.

Small and mid-sized organisations rarely lose their data to a sophisticated attack. They lose it to a shared password, a leaver whose account was never disabled, or a backup that had been failing silently for eleven months. This review looks for those, not for headlines.

What we review

  • Accounts and access: who has what, who no longer should, and where administrator rights sit.
  • Multi-factor authentication coverage, and the accounts quietly exempted from it.
  • Leaver and joiner process, as written and as actually practised.
  • Patching and end-of-life software still carrying real work.
  • Backup scope, frequency, retention — and a genuine test restore, not a green tick.
  • A recovery walkthrough: what the first four hours look like if a key system is gone.
  • Data protection housekeeping: what personal data you hold, where, and for how long.

What it excludes

This is a review, not a penetration test and not a formal certification audit. We do not attempt to break into your systems, and we do not issue Cyber Essentials or ISO 27001 certificates — where you need either, we will tell you plainly and help you prepare for the body that does. We also do not implement the fixes; the remediation list is written so your existing IT support can act on it directly.

What you receive

  • A prioritised remediation list in plain English, addressed to whoever holds the keys.
  • A written restore test result — what was restored, how long it took, what failed.
  • A one-page recovery summary a non-technical director can follow under pressure.
05 — Data

Data & reporting advice

Why two systems disagree, and what a single trustworthy set of figures would require.

The usual symptom is a board pack where the sales figure does not match the finance figure, and an hour is lost every month reconciling them by hand. The usual cause is not a broken system but two reasonable definitions of the same word. We trace the numbers and write the definitions down.

What we do

  • Take a small number of measures that matter and trace each one to its origin.
  • Identify the system that should own each piece of information, and say why.
  • Document the definition of each measure in language a non-specialist can apply.
  • Find the manual steps between source and report where the discrepancy is created.
  • Recommend a reporting route proportionate to your size — often far simpler than expected.

What it excludes

We do not build dashboards, write ETL pipelines or administer your reporting tools, and we do not sell a data platform. We are also not accountants: where a definition has a statutory or accounting meaning, we defer to your accountant and record their answer rather than inventing one.

What you receive

  • A lineage note for each measure, from origin to the report it lands in.
  • An agreed written definition per measure, ready to be adopted as policy.
  • A recommendation for how reporting should be produced going forward.
06 — Vendor

Vendor selection & oversight

Requirements suppliers can be compared against, and a decision you can defend to a board.

Selection processes usually fail at the first step: the requirements are written loosely enough that every supplier can answer yes to everything, so the decision falls back to whoever demonstrated best. We write requirements that separate the field, and a scoring method that survives being questioned afterwards.

What we do

  • Draft requirements in testable terms, separated into essential and desirable.
  • Build a weighted scoring sheet agreed with you before any supplier is seen.
  • Prepare the demonstration script — the same scenarios put to every supplier.
  • Flag the contract points that matter: data ownership, exit, support response, price review.
  • Sit in on demonstrations and record what was promised, not merely what was shown.
  • Set acceptance criteria so “finished” has a written meaning before work begins.

Oversight, where you want it

Once a supplier is appointed, we can stay on as your side of the table: reviewing what is delivered against the acceptance criteria, attending progress meetings, and telling you when an explanation does not hold up. We take no fee from the supplier and no share of their contract, so our only interest is whether you got what you paid for.

What it excludes

We are not a procurement agency, we do not sign contracts on your behalf, and we do not provide legal advice — the contract points we raise are for your solicitor to draft. And we never bid for the delivery work ourselves, which is what makes it possible for us to judge it.

07 — Formats & fees

How the work is packaged

Any of the six lines can be bought in one of three shapes. All three are fixed-fee against a written scope.

F—01

Single question

One decision, answered properly, in a short paper. Suited to a board that needs an independent read on a proposal, or an operations lead facing one significant choice.

Shape One question · one document
Fee Fixed, quoted after scoping

F—02

Full assessment

The estate reviewed end to end, ending in a findings report and a prioritised programme. Suited to a new finance or operations director inheriting an unfamiliar set of systems.

Shape Estate review · findings report
Fee Fixed, quoted after scoping

F—03

Standing adviser

A recurring day or half-day for organisations with no internal technology lead — decisions handled as they arrive, supplier work reviewed, and a written record kept of what was decided and why.

Shape Recurring day · rolling term
Fee Monthly · one month's notice


The fee rules, stated once

  • The scoping call is free and carries no obligation to proceed.
  • No work is chargeable until a written scope and a fixed fee are accepted.
  • If the question proves larger than the proposal described, we stop and re-quote.
  • Expenses are agreed in advance and passed through at cost, never marked up.
  • No commission, rebate or referral fee is taken from any supplier, in any circumstance.
  • Every document we produce is yours, editable, to reuse or hand on as you wish.

Start with a scoping call

Next step

Not sure which line you need?

Describe the situation in an email. Part of the free scoping call is telling you which of the six applies — or that none of them does, and what you should do instead.