CASE STUDY  |  ELECTION SERVICES, 2024 – PRESENT

Developing enterprise AI and data capabilities

This case study covers selected decisions from developing enterprise AI and data capabilities: connecting business priorities to architecture, evaluating alternatives, establishing governance, and widening access in controlled stages.

AI should increase the capacity of the business.

My approach follows four principles.

  1. 01

    Start with measurable business outcomes

    Every initiative begins with a business owner, a desired outcome, and a way to measure it. Build the platform by solving real problems, not by adding infrastructure for hypothetical ones.

  2. 02

    Build reusable capability while solving real problems

    A successful project solves today's problem and leaves behind capability that reduces the effort of solving tomorrow's. That capability can be governed data, a connector, a service, a model, a security control, a workflow pattern, or institutional knowledge.

  3. 03

    Keep authoritative data and permissions at the center

    The definitions, relationships, permissions, and knowledge that make the business's data useful should not depend on a particular model, AI vendor, consultant, or application. Keep them at the center, so they stay in place when the business changes models or infrastructure.

  4. 04

    Put intelligence into existing workflows

    Do not create another tool that employees have to remember to open. Put reporting, search, predictions, recommendations, and automation into the products and workflows where the work already happens.

Expand investment when a project shows value, adoption, and demand.

HOW IT COMPOUNDS
  1. Business constraint

  2. Owner, outcome, and measure

  3. Useful vertical slice

  4. Reusable capability added

    Data · Knowledge · APIs · Models · Controls · Integration · Patterns

    This step is why the work compounds. Each reusable capability lowers the cost of every later slice. The diagram shows this step in a different color.

  5. Embedded in the workflow

  6. Adoption and business result

  7. Expand, iterate, or stop

SUCCESS MEANS

  • More capacity
  • Higher throughput
  • Faster decisions
  • Fewer manual steps
  • Faster capability delivery
  • Earlier detection of problems
  • Measurable adoption
  • Controlled cost and risk

Each of these is a measurable change in how the company runs. A deployed model does not count as success on its own.

Conceptual architecture

Authoritative sources feed one governed platform, and every capability uses it.

I designed the platform and its capabilities as one system. Each new capability reuses the data, permissions, and services the platform already provides.

  1. Sources

    • Authoritative systems
    • Documents
    • Machine data
  2. Governed AI & data platform

    • Shared definitions
    • Permissions
    • Knowledge
    • Data services and APIs
    • Evaluation and monitoring
  3. Capabilities

    • Reporting
    • Search
    • Prediction
    • Applications
    • Automation

Strategy and governance

Connected business priorities to an AI and data strategy and an operating model.

I authored the AI and data strategy and developed the function's operating model and roadmap. I work with business owners and IT on priorities and approvals. Every initiative begins with an owner, an outcome, and a measure. I recommend expanding investment when a project shows value, adoption, and demand.

Business owners define the outcome, source owners own their data and content, and IT and security review architecture and releases. My part is the strategy, the architecture, and hands-on delivery.

Architecture

All use cases share one governed platform.

The decision was whether each new use case would bring its own data integration, access model, and hosting, or whether they would share them. I chose a shared, governed platform. Its sources are authoritative systems, documents, and machine data. The platform prepares that data once, then serves it to reporting, search, applications, and automation under the same permissions. A new use case reuses the data integration, access model, and hosting already in place. A control added once applies wherever it is used.

Business owners agree on each data definition before anyone automates it.

Enterprise search

Implemented, and refined through evaluation and pilot feedback.

I designed and implemented permission-aware enterprise search and retrieval-augmented generation (RAG). The system grounds its answers in internal sources, with citations and access controls. The system is designed to decline when supporting evidence is insufficient, and evaluation includes abstention behavior. I used evaluation sets, pilot feedback, and production monitoring to refine retrieval and answer quality. The diagram below shows how the system ingests content, answers a question, and measures quality. It also shows the order in which access widens.

Answer quality depends on the source content, so content upkeep is part of the system. AI helps draft content and flag problems, and a named person decides what to publish. Access widens in stages, starting with the people who own the content and the subject-matter experts who can test the answers against what they know.

HOW PERMISSION-AWARE SEARCH AND RAG WORK

Ingest

  1. Company content

    Documents, pages, lists, scans

  2. Keep the structure

    Headings, tables, figures, OCR

  3. Label

    Content keeps its sensitivity labels

  4. Split and embed

    Passages with their context

  5. One hybrid index

    Keyword and semantic search together

Ask

  1. Question

    Compound questions split into focused ones

  2. Search in parallel

    • Strict keyword
    • Rare-term recall
    • Semantic
    • Title
    • Domain vocabulary
  3. Fuse the rankings

    Direct matches stay on top

  4. Assemble evidence

    Room reserved for the strongest sources

  5. Answer or decline

    Answers cite sources, and the system checks figures against the evidence

Measure quality

  1. Regression suite

    Real questions against the live index

  2. Score retrieval and answers

    Recall, precision, citations, abstention

Staged rollout

  1. Technical writers

    They own the content and fix the gaps

  2. Key subject-matter experts

    They test answers against what they know

  3. Documentation-heavy pilot

    The pilot validates the system at real volume

  4. Other teams

    They get access once each stage meets its criteria

AI security

Security controls are part of the design from the start.

I developed security controls for internal AI applications and AI-assisted engineering. The work includes threat modeling, permission boundaries, controlled releases, documented testing, and explicit treatment of residual risk.

That work covers identity and access, the permissions given to agents and their tools, release controls, and human accountability for judgment calls. Testing shows how a control behaved at the time of the test. The testing supports review by IT and leadership and is not an audit or a certification.

Reporting and document generation

Built and iterated with business users.

I built and iterated internal reporting and document-generation capabilities with business users, including weekly reporting that rolls up the management chain and stays searchable afterward.

For document generation, a working prototype already existed. I extended it rather than rebuilding it. I added business-managed templates and version control so engineering would not have to own every content change.

Workflow discovery and automation design

This is early-stage work in print and mail operations.

I am documenting the end-to-end process, identifying waste and failure modes, and determining where automation or AI would materially improve throughput or quality. I combine interviews, existing documentation, and operational data to map and measure each workflow before deciding what to automate.

The constraints include work that spans physical production, files, and several systems. They also include inputs that vary by customer, knowledge held by experienced people, election-cycle timing, and the need to preserve auditability.

From constraint to capability

I work in five stages that start from the business constraint, whatever the technology turns out to be.

  1. 01

    Understand the work

    I use process mapping, observation, interviews, system walkthroughs, data lineage, and existing documentation to identify bottlenecks, critical-to-quality measures, and failure modes. I apply Lean Six Sigma and UML where they help. I go into the details of how the work actually happens.

  2. 02

    Establish the source of truth

    Identify the authoritative systems and definitions. Assign owners where ownership is missing. Create governed data. Capture institutional knowledge. Make the important processes observable. When the data is not ready for AI, make it usable.

  3. 03

    Deliver a vertical slice

    Take one useful problem from source to user, through data, logic, application, workflow, and adoption. A working slice proves value and shows what the next layer needs. Waiting for the whole enterprise to be ready does neither.

  4. 04

    Harden what works

    Hardening covers security, permissions, quality, testing, human oversight, monitoring, support, cost, fallbacks, and documentation. Without this work, a working slice is still a demo the business cannot rely on.

  5. 05

    Reuse and compound

    Anything useful beyond the current problem becomes reusable capability for the next one: a connector, a curated dataset, a security control, a service, a model, a deployment pattern, or a piece of institutional knowledge.

The work compounds because each solution lowers the cost of the next one.

Working with the people who own the work

  • Subject-matter experts are the authority on their own work.
  • Business owners define the outcome and what is critical to quality.
  • I make the system easy to understand and turn opportunities into capabilities that can be built.
  • I challenge assumptions when the evidence warrants it.
  • I say what is uncertain instead of pretending to be certain.
  • I ask for expertise when the problem exceeds my own.
  • I take on unglamorous foundation work.
  • Success means the capability exists and others can use it, not that my name is on it.

The delivery standard

I build this standard into delivery from the start rather than adding it at the end, so speed does not cost quality.

Security

Least privilege, identity, isolation, defense in depth.

Privacy

Data boundaries, approved processing, sensitive-data controls.

Quality

Evaluation, testing, source grounding, failure handling.

Transparency

Auditability, citations, observable behavior, documented decisions.

Economics

Explicit build-versus-buy decisions, right-sized infrastructure, cost monitoring.

Human accountability

Within defined authority, AI assists people or carries out tasks. People stay accountable for judgment calls.

AI systems meet the same quality bar as any other system.

Cost is an architectural constraint too.

I design around the workload, reuse shared infrastructure, and question any cost that is not buying business value or necessary risk reduction.

Design around the workload

Use serverless and consumption-priced services where demand is uneven, and reserved capacity only where demand is steady. Do not size anything for a load that has not arrived.

Reuse before rebuild

Workloads share identity and access standards, networking, security, data, and a delivery path. Sharing them reduces duplicated development and operating effort.

Build versus buy, explicitly

Base each build-versus-buy decision on requirements, integration, governance, total cost, and long-term maintainability.

Controls are not a cost to cut

Private networking, identity, key management, and monitoring are part of the baseline cost.