← How I work

Working method / governance and enablement

NaaS YaaS

My own shorthand, and a small play on SaaS, PaaS and IaaS: No as a Service becomes Yes as a Service.

Good governance starts with a better question.

Understand the real need, connect it to the wider system and give people a safe, practical route to get their work done.

People come to a platform or security team because they need to get something done. They may ask for a particular tool, permission or design because it is the part of the problem they can see.

My job is to understand the wider need: what they are trying to achieve, who the service is for, what it connects to, what it costs and what needs to be protected. I do not expect every person making a request to understand the full ecosystem. That is part of the value I bring.

The first answer is often: tell me more

A request is the start of a conversation, not the end of one.

Tell me more about what you are trying to do. Have you considered this approach instead? Here are the guides, support and safe options available to you.
Illustrative exampleAI model access

“Give me access to Model X”

Understand the work before deciding the capability.

Someone asks for access to a more capable AI model because they need help with a piece of work. The useful answer begins by understanding what they are trying to achieve.

01What are you trying to achieve?

The business outcome determines the right capability and urgency.

02What information will the work involve?

The model and route need to be appropriate for the data being handled.

03Will an existing route do the job?

Guidance, configuration or a different supported model may solve the need immediately.

04What access is actually needed?

The request may need a smaller, safer entitlement than the first tool requested.

Link to this example

Balance is part of the design

The route has to work for the person, the business and the platform.

Business goalProgress on work that matters.
User experienceA supported path that is clear and proportionate.
SecurityControls that match the real risk.
EfficiencyNo unnecessary cost, rework or manual support.
OperationsA service the team can run reliably.

Build the paved road

If people keep asking for the same thing, improve the platform.

The response should not remain a repeated conversation or ticket. It may be a documented guide, a self-service workflow, a reusable access pattern or an automated control. The compliant route should be the easiest route.

That is where governance becomes enabling. It gives people more confidence and freedom inside safe boundaries, while reserving detailed review for the work that genuinely needs it.

When a request reaches beyond one team or platform, the same approach can bring a wider group of experts into the answer.

Read: The safest route has to be the easiest one →
Read: Flat AI access and earned capability →
Explore a Centre of Excellence approach →
Explore more working methods