Grace Hill — Discovery to Annuity

One company, every phase: what governance looks like when you actually run it.

Confidential · June 2026. Grace Hill is a real company; its public profile (compliance & training SaaS, the "Gracie" generative-AI assistant, CTO Chris Fontan) is sourced from prior OSINT. Everything about their internal estate below is ASSUMED — modeled from a mature mid-market B2B SaaS profile, not confirmed. All dollar figures are illustrative placeholders. The Aperture engine is built and tested on synthetic data; connectors are not yet live, so findings here are modeled, not measured.

Grace Hill is the worked example because it has the shape every account does: a real product that ships AI into a regulated workflow, a competent engineering org, and an internal estate nobody has fully counted. They sell compliance and training software to property managers. They ship Gracie, a generative assistant embedded where fair-housing and tenant-screening exposure lives. That makes them a clean test of the whole arc — Assess → Design → Implement → Operate → Attest → re-baseline.

Day 0 — Discovery

Lead: Founder / Delivery Lead · Duration: ~1 week · Deliverable: scope memo + access plan + the shadow-AI question on the table.

We set the boundary: which business units, which products, which clouds. We negotiate read-only access to one administrative API (identity, or the model gateway) — metadata only, "pointers, not payloads." And we ask the one question every account answers wrong: how many AI tools are in use here? Leadership names three or four. We tell them up front the real number is usually higher, and that surfacing it — with a cost attached — is the first thing the engine does.

Assess — the three lenses + the product-AI review

Lead: Lead Assessor · Tools: the crosswalk library, Langfuse traces of Gracie · Duration: ~2–3 weeks · Deliverable: baseline record across Technology, Security, and AI lenses, plus the Gracie review.

We run the three lenses against the assumed estate and review the AI they ship, not just the AI they buy. Three sample findings, each modeled:

#LensFinding (modeled)Risk / cost
F-1AI / ProductGracie can generate tenant-screening guidance without a logged human-review gate on fair-housing-sensitive responsesDisparate-impact exposure; ~$420K modeled regulatory + remediation reserve
F-2Security~14 SaaS AI tools in use; 9 never went through review (shadow AI), 2 with customer PII in prompts~$180K/yr modeled redundant spend + uncontrolled data egress
F-3TechnologyNo lineage from Gracie outputs back to source training/policy data; attestation can't trace a decisionAudit-failure risk; blocks any defensible "the model did X because Y"

Each maps to the six crosswalks (NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, MITRE ATLAS, CSF 2.0) so the findings speak the language an auditor already trusts.

Design — operating model, policies, autonomy tiers

Lead: Solutions Architect · Tools: OPA/Rego policy drafts, OSCAL control catalog · Duration: ~2 weeks · Deliverable: target operating model + policy set + the evidence-interface spec.

We define who owns AI risk, the policy set as code, and autonomy tiers for Gracie — Tier 0 (suggest, human sends), Tier 1 (act in low-stakes paths), Tier 2 (gated, fair-housing responses always human-reviewed). The evidence-interface spec says exactly what metadata the engine reads and what it never touches.

Implement — connect one API, stand up the toolchain

Lead: Governance Engineer · Tools: Aperture, OPA, OSCAL, Langfuse, OpenTelemetry · Duration: ~3–4 weeks · Deliverable: live metadata connection + standing control plane.

The engine connects to one admin API. OPA enforces the Design policies, OSCAL holds machine-readable evidence, Langfuse instruments Gracie, OTel carries telemetry. Deterministic by design — no model sits in the measurement path. This is where "modeled" begins turning into "measured."

Operate — dashboard live, meter running

Lead: Delivery Lead · Tools: Aperture dashboard, the cost meter · Duration: ongoing · Deliverable: the live record.

The dashboard goes live, the meter runs, and shadow AI surfaces with a dollar figure attached — one record, two lenses (governance and cost). The funnel from Discovery's "three or four tools" to the real inventory becomes visible and attributable.

Attest — the independent verdict

Lead: Attestation Lead (structurally separate from the build/run team) · Tools: crosswalk library, the operating record · Duration: ~2 weeks · Deliverable: attestation report.

The body that built and ran the engine does not attest. Independence is the point. The Attestation Lead renders a verdict against the six frameworks, valid only against the current record. (Today this separation is intended structure — we're pre-entity.)

Annuity — re-baseline

Lead: Standard / Crosswalk Owner + Delivery Lead · Cadence: quarterly · Deliverable: fresh record, renewed attestation.

An attestation expires the moment the estate changes — new tools, new Gracie capabilities, new regulation. So measurement is continuous and the verdict re-baselines. What recurs: the meter, the shadow-AI sweep, crosswalk updates, and re-attestation. That loop — not a one-time report — is the annuity.

See the process in full, who runs it on the team, the toolchain, and the assumed estate.