Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

Engineering Team Design for AI: An Engineering Reference.

Team design is the layer of an AI programme that ships no artefact by default, which is why nobody audits it. This catalogue fixes that by admission rule: an item earned a place only if a reviewer could ask for the object that proves it and be handed one.

A register entry qualifies. A directory group, an access control list, a dated drill log and a signed approval all qualify. A principle does not, and neither does a completion percentage. Twenty-eight items, seven families, from the on-call boundary to the legal interface.

In depth

The Admission Rule That Removed Most Of What Is Written About Culture.

01

Every item here names an object somebody can be handed.

That test did the cutting: a register entry, a reporting line on a published chart, an access control list, a dated drill record and a signed approval all survived it, while every line that could only be satisfied by an attitude came out. What is left is the part of engineering culture you can build. Two failures recur across all seven families: a role that exists in a slide deck and not in a directory group, and an authority described in writing and never once exercised.

In shortTwo failures recur across all seven families: a role…
02

The pager watches latency while the system answers fluently and wrongly.

An on-call rota inherited from the service that hosts the model keeps error rate and saturation green through a quality regression, so nobody is woken and the first report arrives through an account manager eleven days later. ORG-1 settles it with named thresholds on groundedness, refusal rate or task success, routed to a rota that names which human they reach. A severity definition that only covers availability gives a wrong answer no response time at all.

In shortA severity definition that only covers availability…
03

A model change travels a different path from a code change.

A system prompt is edited in a console, a provider moves its default checkpoint, a decoding parameter is tuned against production traffic, and none of those three has a reviewer, a diff or a release to attribute the behaviour to. The segregation applied rigorously at the application layer stops exactly where behaviour is cheapest to change. Put prompts, system instructions, decoding parameters and retrieval configuration under the same review rule as code, and revoke the console write path.

In shortrevoke the console write path
04

The standard remediation destroys the evidence.

Someone rolls back the deployment, the serving tier is replaced, and the prompt, the retrieved context and the model version that produced the behaviour leave with it. For an ordinary outage the logs survive the fix; for an AI incident the trace is the artefact, and it has to be snapshotted before anything is restored. Preservation goes ahead of remediation in the written procedure, held by a role that exists for that one purpose.

In shortheld by a role that exists for that one purpose
The detail

The Three Families Clients Fail First, And What Settles Each.

The catalogue runs to seven families. These three are where a review stalls first, and not one of them is settled by a statement of intent. Each resolves to a document with an owner, a date and a last-modified timestamp, which is why item numbers stay stable and are worth citing in a ticket.

Zone · 01

Ownership and on-call

ORG-1 wants one named owner per production system recorded as a directory identity rather than a job title, with a named deputy and a date the entry was last confirmed. The owner holds written authority to suspend without a further approval, and that authority is drilled on a schedule. The artefacts are a register entry, a delegation record and a timed suspension log.

Zone · 02

The evaluation reporting line

ORG-3 is a reporting line, and a reporting line is a structure with a diagram. Write access to the evaluation set and its labels belongs to a function that does not report to the delivery lead, evaluation is a funded headcount rather than a rotation that lapses when delivery is behind, and a threshold change records its approver, its date and its reason.

Zone · 03

The platform relationship

ORG-2 treats the platform as a product with a named owner, a published roadmap and consumers allowed to decline it, not as a ticket queue. DORA put developer independence at a 5% productivity gain in 2024, and a queue is how that gets spent. Measure from the consumer side: time to a new team's first successful production deploy.

By the numbers

The figures that make it a board-level conversation.

28
structural items across seven families, from the on-call boundary to the legal interface
7
team archetypes DORA identifies; declaring which one each team is comes first
63%
of organisations had no AI governance policy at all, which is the easier half of the problem
Inside the report

What you'll take away.

01

Step 1 - Record owners as directory identities, not job titles

A title moves with a reorganisation and a directory group does not. Add a named deputy and the date the entry was last confirmed, so a register nobody has touched in a year declares itself.

02

Step 2 - Route a quality threshold to the rota

Groundedness, refusal rate or task success with named thresholds, mapped in an alert routing table to the person they wake. Availability monitoring will stay green through the entire incident.

03

Step 3 - Revoke the console write path

Prompts, system instructions, decoding parameters and retrieval configuration go under version control and the same review rule as code. Behaviour edited in a production console has no diff and no reviewer to name.

04

Step 4 - Put preservation ahead of rollback in the runbook

Trace, prompt, retrieved context, model version and release bundle captured under a retention class before service is restored, held by a named preservation role with its own place on the rota.

Questions

Frequently asked.

Twenty-eight items is a lot. Where does a team start?

ORG-1 and ORG-6, in that order. Ownership decides whether anybody can stop a system, and incident roles decide whether the evidence survives the fix. Both are cheap to write down and expensive to discover missing, and the other five families are easier to fund once those two are settled.

Why exclude values and principles from the catalogue?

A value changes nothing at three in the morning when a system is answering fluently and incorrectly. An item made the list only if a reviewer could ask for the object proving it and be handed one, which rules out charters and training completion rates and leaves registers, rotas, access control lists and drill logs.

Our platform team is busy. Is a declared archetype worth the effort?

DORA identified seven archetypes across nearly 5,000 technology professionals in 2025, and a team simultaneously building the platform, shipping features and holding the pager matches none of them. Declaring the archetype and the capacity split is how that gets named out loud rather than absorbed quietly by three people.

We have an AI governance policy already. Does this still apply?

Probably more, not less. IBM found 63% of organisations with no policy at all in 2025, which is the easy half. The hard half is an organisation that wrote one and still cannot name the individual it binds, the group that individual belongs to, or the last time they did anything it describes.

What makes an authority real rather than written?

Exercise. A delegation record says somebody may suspend a system; a timed drill log says they did, on a date, against something that was serving traffic. ORG-1.2 asks for both, and the second one is what separates an owner from a name in a spreadsheet.

Does this cover the legal side of team design?

Only where a duty turns into a structure. Engineering Team Design for AI Under Regulation sets out why Regulation (EU) 2026/1744 assigns duties to people rather than to architecture, which duty lands on which role, and what evidences it.

Take that first if a supervisory deadline is driving the work, and this catalogue to build.

Who should be reading this?

VPs of engineering and the people who hold their org chart, plus the risk and legal counterparts named in ORG-7. It assumes you have AI systems in production and want item numbers to cite in a review note rather than a case for why team structure matters.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send Engineering Team Design for AI: An Engineering Reference straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Run it against ORG-1 and ORG-6 and see what survives the rollback.

A two-week trial sprint pointed at ownership and incident roles tells you whether anyone named in your register could suspend a system today, and what evidence would still exist afterwards. Two weeks, your repository, zero commitment. SECTION 7 - FAQ - 5 to 8 questions

Book a team design review