Buyer Discovery

Two doors into the same account: the value lens that runs the engine, and the governance lens that proves the standard.

Confidential · June 2026. Figures referenced here are illustrative and described in the documents they link to. This note describes how govrn.ai enters an enterprise account — the buyers, their questions, and the events that put budget in motion.

govrn.ai sells one record viewed through two lenses. Each lens has a different first reader, a different question, and a different trigger. The discipline of buyer discovery is matching the entry point to whoever is already feeling pressure — and letting the second lens follow once the first is in the building.

The two doors

Door one — the value lens (CTO / CFO). This buyer is trying to answer a money question: what AI are we actually running, who is using it, and what is it costing us? The Aperture engine is the wedge here. It is deterministic — no model in the measurement path, so the number is reproducible and audit-defensible — and it works on metadata, not payloads ("pointers, not payloads"). The deliverable a CFO understands instantly: shadow AI with a dollar figure attached, plus attributed cost and usage. On synthetic seed data the engine already produces a modeled shadow-spend picture; on a customer's connected systems it produces a measured one. The CTO buys reproducibility; the CFO buys the line item.

Door two — the governance lens (CISO / board). This buyer is trying to answer an exposure question: can we prove we govern our AI, and would that proof survive an outside examiner? The govrn standard answers it — a three-lens assessment (technology, security, AI), crosswalked to six frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, ATLAS, CSF 2.0), delivered as independent attestation, never self-certification. It also reviews the AI a company ships, not just the AI it runs. The CISO buys defensibility; the board buys the ability to answer the question they were just asked in a meeting.

What each buyer is actually trying to answer

BuyerThe question in their headWhat lands
CFO"What is our AI spend, including the part nobody approved?"Attributed cost; shadow AI quantified
CTO"Is this number reproducible if someone challenges it?"Deterministic engine, no model in the path
CISO"Can we prove we're governed if examined?"Independent attestation, six-framework crosswalk
Board"What do we say when asked about AI risk?"A defensible posture they can speak to

The trigger events

Budget for governance is rarely planned; it is provoked. The wedge enters cleanest on the back of a specific event:

How the wedge enters

The pattern is consistent: lead with the lens whose buyer is already under pressure, deliver a fast, narrow win, then let the second lens follow inside the account. A CFO who sees shadow spend wants the governance posture that explains it; a board that demands attestation needs the engine to keep the record fresh — because an attestation is only valid against a fresh record, which is exactly what turns a one-time assessment into a running relationship (see Business Model).

This entry is de-risked by channel: MCG Kelly Services is the first distribution channel, not the buyer — they carry the wedge into accounts that already trust them. Evidence stays portable throughout; the buyer is buying proof they own, not a dependency. See Market for the demand signals and Team for the relationships that open the larger doors.