Every time I present this methodology to a room of executives, someone asks the question I want them to ask: "Okay. What would you actually do on Monday?"
Here's the answer. Five moves. Ninety days. No new hires. No vendor decisions required. No multi-year roadmap before you start.
Move 1: Define your single-platform AI funnel (weeks 1-3)# #
One intake form. Five fields. Every AI project — build, buy, or internal — flows through it. The goal isn't perfect governance on day one. The goal is a URL that exists, a first project that has flowed through it, and an audit log entry that's visible.
Existing role responsible: whoever owns enterprise transformation today. CIO chief of staff, CAIO if you have one, COO if neither. Target: three or more AI projects flowing through the funnel per week by week four. Eighty percent of all known AI projects through it within 90 days. A v1 with sharp edges beats no funnel. Every time.
Move 2: Stand up the audit log before the policy (weeks 1-6)# #
Telemetry first, rules second. This is the move most organizations get backwards. They write the policy, then figure out what they're capturing. The right order is the reverse.
One query should answer "what did agents do this quarter" in under 60 seconds. If it can't, you're not governing — you're guessing. Existing role responsible: whoever owns your SIEM or platform observability today. Target: 100% of in-production agents emitting to a central audit log by week twelve.
Move 3: Wrap three legacy apps, sequenced by blast radius (weeks 4-12)# #
Identity-aware proxy in front of the three apps with the highest blast radius if something goes wrong. Production customer data first. Internal financial second. Everything else after.
The wrap doesn't require a rewrite. It buys 12-24 months of governed access without touching the underlying app. Existing role responsible: platform engineering plus a named practitioner from each owning business unit. Target: three apps wrapped by week twelve, with old service-account paths deprecated and dated.
Move 4: Publish your first three reusable assets (weeks 6-12)# #
One real agent (not a demo). One MCP tool wrapping the most-requested enterprise system in your federation. One policy template for the governance pattern every team is currently reinventing on their own.
The assets get named publishers from the teams that already built them — not a centralized author, not the CoE. Definition of done: each asset is discoverable in your internal marketplace and has at least one consuming team outside the team that built it. That cross-team consumption is proof the flywheel is starting to spin.
## Move 5: Measure the fastest path, weekly (week 1 and forever)[#](#move-5-measure-the-fastest-path-weekly-week-1-and-forever)
Time-to-credential. Time-to-first-agent. Time-to-tool-access. On a dashboard. Reviewed in the CIO's weekly 1:1 with whoever owns the methodology.
The metric that matters: fastest-path-delta. If the managed path is slower than the unmanaged path by 25% or more on any vector, that is a P0 for the methodology owners in the next sprint. The moment the unsafe path is faster than the safe path, shadow AI returns. This metric is the early warning system. It never goes away.
What 12 months looks like# #
Quarter one: the 90-day blueprint. By the end, the funnel exists, the audit log exists, three apps are wrapped, three assets are published, and the fastest-path metric is on a dashboard. You're moving from rung 1 to rung 2.
Quarter two: methodology rhythms established. First quarterly review completed. Five more wrapped apps, ten more published assets, five more business units trained. You're solidly on rung 3 for the wrapped portfolio.
Quarter three: reuse data starts to tell a story. The Asset Curator runs the first sunset review. First showback statements go to business units. The reuse credit mechanism is prototyped. Early signs of rung 4 are visible.
Quarter four: first annual methodology review. Renew funding with showback evidence. Plan the year-two chargeback transition. The first kill-criteria check fires. Early-adopter business units are on rung 4. Enterprise-wide, you're on rung 3.
The question that tells you whether you're actually running this# #
Can the CEO answer "are we an AI company?" with a measurable percentage of work units that involved an agent — not a feeling?
Can the CIO answer "what did agents do this quarter?" in one query?
Can the CISO answer "do we have shadow AI?" with a number, not a guess?
If the answer to all three is yes, the methodology is working. If it's no, you know which move to make next. Adapt. Compose. Evolve. Security as the enabler, not the brake. The people you already have, running the methodology you now have.
I'd rather be wrong in public than vague in private. Hold me to all of it in 18 months.
Part seven of a series based on the Agentic Adaptation Playbook. Previously: why security is the engine of your agentic migration, not the brake on it.