GTM & Channel
Independent attestation is the product; evidence collection is how we earn the right to deliver it. We lead with the one question no platform can answer for itself — can you prove your AI is governed, across every cloud, model, and agent, no matter who built them? — then expand into the continuous work that keeps the attestation valid.
Confidential · June 2026. All financial figures are illustrative placeholders and do not represent measured results, customer outcomes, or commitments.
The Wedge: Governance Is the Lowest-Friction Door
Every enterprise buyer now has the same unanswered question on their desk: can we prove our AI is governed — across every cloud, model, and agent — to a board, a regulator, and an insurer who won't take our own word for it? Regulatory compliance is the #1 barrier to GenAI adoption (38%, Deloitte), board AI-risk oversight jumped from 16% to 48% of the Fortune 100 in a single year (EY), and the EU AI Act carries penalties of 7% of global turnover — in force today. The buyer doesn't need to be convinced the problem exists. They need a signed, independent attestation they can put in front of the board.
That is the wedge. The platforms now ship their own AI governance — Microsoft Agent 365 and Purview give enterprises an agent registry, monitoring, and self-scored ISO 42001 / NIST AI RMF readiness — and that only sharpens the gap, because no vendor can attest its own control plane. The govrn standard — three-lens assessment, six-framework crosswalks, and independent, vendor-neutral attestation (never self-certified), spanning every cloud, model, and agent no matter who built them — answers the question the board is already asking. It requires no platform migration and no rip-and-replace. It is the cheapest "yes" a CISO can give.
The Discovery Dividend
Prove it — with a signed, independent attestation a board and regulator will accept. Getting there starts with evidence. The moment the Aperture engine is pointed at an account — consuming the telemetry the platforms already emit, including Microsoft Agent 365 and Purview, and extending coverage across every other cloud, model, and agent — it surfaces shadow AI with a dollar figure attached: attributed cost and usage, metadata-only, no model in the measurement path. That evidence collection is the dividend: what was sold as a compliance checkbox becomes the substrate for an independent attestation, returning a map of unmanaged spend and unmanaged risk the buyer didn't know they had. Each finding is a reason to go deeper.
Honest staging. The engine is built and tested on synthetic seed data; its connectors have not yet run against a live customer API. The discovery dividend is the designed motion, proven against modeled data. The proof-of-concept against live data is the gate that converts it from a thesis into a result. We say "modeled" until connected, "measured" after.
Land and Expand
The account economics follow a deliberate arc:
| Stage | What we sell | What it buys the customer | What it buys us |
|---|---|---|---|
| Land | Cross-vendor evidence collection | A dollar figure on unmanaged AI, every cloud and agent | A foothold and a map |
| Expand | Attributed usage + independent verification | Audit-defensible records, spanning vendors | Engine runtime in the account |
| Entrench | Independent, signed attestation | Board-ready attestation on a fresh record | The annuity |
The annuity is structural, not contractual. An attestation is valid only against a fresh record, so continuous measurement is required to stay attested. The engine runs, the record refreshes, the attestation renews. Evidence stays portable — sovereignty, not lock-in. We deliver coupled and renew decoupled, and the moat compounds: the accumulated, attributed record gets more valuable with every cycle.
The Two-Buyer Motion
One record, two lenses, two buyers — and each lens opens a different door into the same account:
- The engine → CTO / CFO. The Aperture lens is Run. It speaks in attributed cost, shadow-AI dollars, and reproducible measurement. The CFO funds it because it pays for itself; the CTO owns it because it's infrastructure.
- The standard → CISO / board. The govrn lens is independent proof. It speaks in cross-vendor frameworks, signed attestation, and audit-defensibility — the assurance no platform can issue for its own AI. The CISO sponsors it; the board mandates it.
Either buyer is a valid entry point, and each pulls the other in. The standard creates the obligation; the engine satisfies it.
Kelly / MCG: The First Channel
Channel, not destination. MCG Kelly Services is the first channel into enterprise accounts — de-risked distribution into established relationships, not the pitch target. The strategy is entity-first: stand up the company — entity, team, raise — before any partner conversation, then license the process, the product, and the brand through the channel. Kelly carries govrn into accounts it already serves; Microsoft is the horizon, reachable through the team's senior-Microsoft relationships.
This sequencing keeps independence intact. The attest arm stays structurally separate from build and run — the body that builds is never the body that attests — which is precisely what makes a channel partner able to carry the standard without compromising it.
See Roadmap for the PoC-to-live-data sequence that gates this motion, and Business Model for licensing mechanics.