Your name goes on
this architecture.
Here is the whole path before you commit to it. What connects each week, what you sign off, and what to hand the people who will ask you to defend it.
You keep the systems. We run the layer on top.
Your warehouse, your model vendors, your identity stack, your policy framework. Ward inherits all of it.
| Surface | Yours | Ward’s |
|---|---|---|
| Warehouse and source systems | Owned and operated by you, unchanged | Read-only SELECT via a service account you issue |
| Data residency | Your existing rules govern | No copy is made, so nothing moves region |
| Model providers | Your contracts, your API keys | Routes across them, holds none of them |
| Identity and access | Your IdP, your RBAC roles | Consumes SSO/SAML and SCIM, defines nothing |
| Agent scope and policy | Cedar policy and charters in your repo | Enforces what your repo says at runtime |
| Write approval | You name the approver role per playbook | Blocks every write until that role signs |
| Audit record | Streams into your SIEM, your retention | Emits JSONL, keeps its own copy too |
| The platform itself | Configured by your team after week six | Runs, patches, and supports it |
The reference architecture and the data-flow diagram are in the evaluation packet. The controls behind each row are on the security posture.
Six weeks, and what you sign off at each gate.
Read-only until week six. Every gate is a place you can stop.
Before you commit to anything
Read the packet. Decide whether it clears your bar.
Send the packet and answer whatever your security team asks in writing.
- Data flow diagram and network topology
- Cedar policy bundle as deployed
- MSA, DPA, SOC 2 status, insurance certificate
Gate: Nothing is connected. No credentials have been issued.
Read-only connection
Issue the credentials. Point us at the schemas you want in scope.
Connect, profile the schema, and send your security team the architecture doc the same week.
- Service accounts locked to SELECT
- Federated query, no copy of your data
- SIEM stream live from the first query
Gate: Read-only. Ward has no path to write anything, anywhere.
First findings on your own data
Read the first cards. Tell us which ones your operators already knew.
Rank stores, SKUs, and vendors by dollars, name the cause, and cite the SQL under each one.
- Findings ranked by dollars, cause attributed
- Every number one click from its SQL
- Forecasts carry a model card and a MAPE
Gate: Still read-only. Still nothing written.
Policy and scope, in your repo
Review the Cedar policy and charters as a pull request. Name the approver role for each playbook you want live.
Write the first policy set against your role model and sit in the review with you.
- Cedar policy scoping each agent
- A charter per agent, versioned in your Git
- Rollback is a revert
Gate: Write scope stays closed until you merge.
First gated write
Pick the first playbook and the person who approves it.
Run it, log the state before and after, and show you the diff.
- One playbook, one system of record
- Before and after state streamed to your SIEM
- Every other playbook stays closed
Gate: Every write blocks on the approver role you named. Nothing runs unattended.
The number, either way
Read the KPI delta and decide.
Publish the result against the pre-agreed metric, whichever way it went.
- Measured KPI delta against the day-one metric
- Win rate per playbook
- If it did not move, the pilot ends
Gate: Month-to-month from here. Thirty days notice, no rollover clause.
The four dates you will be asked to repeat.
Your six gates above compress to these. Same sequence, same number, on every page of this site and in the packet.
-
48 hoursFirst insight cards
From a read-only connection. Findings on your own data, not a sandbox and not a slide.
-
Week 2Findings ranked by dollars
Stores, SKUs and vendors ranked by what they cost you, with the cause named and the SQL one click under every number.
-
Week 6First gated write
One playbook, one system of record, blocked on an approver role you named. Everything before this is read-only.
-
Day 90The number, either way
Measured KPI delta against the metric agreed on day one. If it did not move, the pilot ends.
Tier follows stack complexity: how many systems have to talk to each other, how many brands you run, and how custom your schema is. Not headcount, and not revenue.
- Month-to-month, 30 days notice
- No rollover clause
- Every tier is the full platform
Four rooms you will have to walk into.
You will make this case without us in the room. These are the versions that land.
What does this cost and what does it replace?
$60K a year for the tier most mid-market retailers land on, against $170K for Tableau plus one analyst, or $400K and up for ThoughtSpot. It is month-to-month with a 30-day exit, and the tier follows stack complexity, so the number does not move because revenue did.
What are we exposing, and can we prove it later?
Read-only service accounts locked to SELECT, federated query so no copy of the data leaves the warehouse, Cedar policy scoping every agent by role and resource, and a JSONL audit stream into our own SIEM from day one. Write access opens one playbook at a time behind a named approver.
Security posture, sub-processors, and the pre-answered questionnaire. →
Is this our AI strategy or a science project?
It is the retail-specific layer under the AI strategy we already have. It runs on the model vendors we already contracted and the warehouse we already built. The pilot has a KPI and a close date agreed in writing, so in 90 days we have a number rather than a roadmap.
The board page: the arithmetic, the shortlist, and the exit. →
Is this more work for us, and does it threaten our roadmap?
No ETL to schedule, no warehouse to stand up, no model to host. It reads what we already publish and takes the ad-hoc question queue off our backlog. Policy lives in our repo, so we control scope through the same review process we use for everything else.
The questions that land on you, and the answers.
None of these answers require taking our word for it.
Both stay. Ward reads the same warehouse your BI sits on and does not touch your reports. What it adds is the work after the chart: naming the cause, attaching a procedure, writing back to the system of record, and measuring whether the KPI moved. Your data team keeps the warehouse and stops fielding the ad-hoc queue.
The opposite is what makes it defensible. It consumes your IdP, your RBAC roles, and your SIEM. Agent scope lives in your Git as reviewed code. There is no separate user directory to drift and no second copy of the data to govern.
The model never produces the numbers. Forecasts and aggregates run on ARIMA, Holt-Winters, Bayesian hierarchical, and gradient-boosted models, backtested over 24 months with a MAPE attached. The LLM frames the answer around results it did not compute, and every number stays one click from the SQL that produced it.
We did not pick one. The application talks to an abstraction layer, so Anthropic, OpenAI, Gemini, and Ollama are configuration on your keys. An eval harness scores any candidate against your real cases before you promote it, which makes switching a measured decision rather than a migration.
A person you named, in a role you defined, who approved that specific write. The state before and after is logged and streamed to your SIEM. No playbook writes unattended, and write scope opens one playbook at a time.
Exit is not a migration, because there is nothing to migrate. The data never left your warehouse, the policies and charters are already in your repo, and the contract is month-to-month on 30 days notice. You would lose the findings, not the infrastructure.
Everything your reviewers need, before there is a contract.
One page, built to be printed or forwarded whole.
For security review
Data flow, network topology, Cedar policy bundle, sub-processors.
For procurement
MSA, DPA, insurance certificate, SOC 2 status, the 30-day exit.
For your board
The ownership split, the gates, and the close criteria.
Longer versions of three arguments on this page.
What a Retail Security Review Should Ask an AI Vendor
Your questionnaire was written for software that stores data and shows it back. An agent asks for the ability to act on your systems of record. Six questions that cover the difference, in the order the answers matter.
9 min read
A Pilot That Cannot Fail Is a Subscription
Ninety days later nobody can say whether it worked, because nobody agreed a number in advance. The four things to fix before a single system is connected, and the sentence a vendor should be willing to put in writing.
8 min read
The Second Semantic Layer Is the Real Objection
Security and finance objections are answerable with documents. The one that kills the deal comes from whoever owns the warehouse, is rarely said out loud, and is usually correct. How a competing metric definition gets built by accident, and the structural fix.
8 min read
What technical buyers ask first.
Issuing service accounts and confirming which schemas are in scope is most of week one, and it is measured in hours rather than days. The policy review in weeks three to five is a normal pull request against a policy set we draft first. There is no ETL to schedule, no warehouse to stand up, and no model to host.
Yes, and most technical buyers do. Weeks one through five are read-only by design. Write access is a separate decision you make at week six, one playbook at a time, against an approver role you define.
A data flow diagram, the Cedar policy bundle as it will be deployed, network topology, sub-processor list, SOC 2 Type II status, a pre-answered security questionnaire, and the MSA, DPA, and certificate of insurance. All of it comes before the contract, not after.
Cedar policies and agent charters live in your repository. Narrowing an agent, adding a source, or changing an approver role is a pull request your team reviews and merges. Because it is versioned, any change rolls back the same way the rest of your code does.
No. Ward runs federated queries against Snowflake, BigQuery, Redshift, Postgres, and SAP HANA in place. There is no ETL into a Ward-owned database and no shadow lake, so your data residency position is unchanged.
Close criteria are agreed in writing before the pilot starts. If the KPIs do not move by day 90, the pilot ends and you keep every artifact we produced. The contract is month-to-month with 30 days notice and no rollover clause.
Book an architecture review.
Ninety minutes with the people who built it. Bring your security lead.
Read-only to start · your LLM keys · SOC 2 Type II underway · or book a call directly
Find out what your data has been hiding.
Tell us about your operation. We’ll show you the problems Ward catches, and the ones your current tools miss.