For a bounded, lower-risk workflow with usable information and a committed owner, 90 days can be enough to put one focused AI capability into controlled operation. It is not enough to transform the entire company, connect every system, or prove every future use case. A strong 90-day plan selects one valuable workflow, defines ownership and boundaries, tests representative work, launches a limited version, and ends with evidence for the next decision.
This roadmap is a Northern Logic delivery pattern, not an industry standard or a promise that every project fits the same calendar. Regulated, sensitive, high-impact, seasonal, or data-intensive uses may require more time. A simpler product configuration may require less.
The focus is consistent with current adoption evidence. A 2026 U.S. Census Bureau working paper found that 57% of firms using AI did so in three or fewer business functions during its supplement period. Our inference is practical: start with a narrow operating result and expand from evidence, not from a long feature list.
The roadmap at a glance
| Phase | Days | Main question | Decision or deliverable |
|---|---|---|---|
| Assess | 1–15 | Is this the right problem for AI? | Baseline, options, and selected scope |
| Design | 16–30 | What must the system know, do, and never do? | Role, workflow, knowledge, controls, and tests |
| Build and shadow | 31–60 | Can it prepare useful work safely? | Tested system running beside the current process |
| Controlled launch | 61–75 | Can the team use it on a limited live scope? | Approved production route and support plan |
| Operate and decide | 76–90 | Is it valuable enough to keep or expand? | Value review and next-quarter decision |
The days are less important than the gates. Do not move forward only because a date arrived. Move when the owner can review the evidence and accept the next level of responsibility.
Days 1–15: Assess the opportunity
Choose one business result
Begin with work the team already recognizes. Good candidates happen often, follow a mostly repeatable route, depend on available information, and produce an output someone can judge.
Examples include:
- A decision-ready account brief.
- A complete project intake package.
- A recurring operations exception list.
- A sourced answer to an internal question.
- A document prepared for qualified review.
Avoid starting with "an AI assistant for everything." A broad role makes the knowledge, access, tests, and value impossible to bound.
Observe the current workflow
Follow real examples from trigger to result. Record:
- Who starts and owns the work.
- Which tools and information are used.
- Where data is copied or re-entered.
- Where the work waits.
- Which exceptions require judgment.
- How quality is checked.
- What happens after completion.
Build a baseline for volume, handling time, wait time, rework, exceptions, owner attention, and service effect. Use the AI readiness assessment scorecard to compare candidate workflows, then use the guide to measuring AI ROI for the value model.
Compare the alternatives
Do not approve a custom implementation until you compare:
- Improve the process without new technology.
- Configure a feature already available in a current product.
- Add rule-based automation for stable steps.
- Build a focused specialized AI assistant.
- Keep the work with people because the risk or variability is too high.
The deliverable for day 15 is a decision brief, not a prototype. It should name the result, baseline, options, expected value, major risks, process owner, and recommended first scope. An AI Opportunity Audit is designed for this decision.
Days 16–30: Design the operating system
Write the assistant's role
Create a one-page role definition:
- Mission and expected result.
- Trigger and eligible cases.
- Approved inputs and knowledge.
- Tools and exact functions required.
- Output format and acceptance standard.
- Actions it may take.
- Actions it must propose or leave to people.
- Stop conditions and escalation owner.
- Measures reviewed after launch.
The role should be clear enough that a process owner can identify work that is inside and outside scope.
Prepare company knowledge
List the approved procedures, examples, templates, terminology, policies, and records needed for the first job. Assign an owner and current source to each. Remove duplicates and mark unresolved conflicts.
Do not delay the whole project until every company file is organized. Build a bounded company knowledge base for the first job, with a path to add sources as the system earns trust.
Design permissions and approvals
Separate read, search, draft, change, send, approve, and delete capabilities. Use dedicated identities and the minimum permissions needed. Keep customer commitments, financial actions, legal or clinical judgment, employment decisions, access changes, and destructive actions with qualified people.
The NIST Generative AI Profile emphasizes governance, content provenance, pre-deployment testing, and incident disclosure. Translate that into a source map, test plan, issue owner, and response path for this implementation.
Define acceptance tests
Build the test set before the system is tuned to it. Include normal examples, edge cases, incomplete information, conflicting sources, prohibited requests, sensitive content, and tool failures. For each case, write the expected result and acceptable review threshold.
The day-30 gate is a design review. The business owner, process owner, and implementation lead should agree on the job, sources, tools, approvals, tests, and launch limits.
Days 31–60: Build and run in shadow mode
Build the smallest complete route
Connect only what the first result needs. A complete narrow workflow is more useful than several partial demonstrations. Configure the trigger, knowledge, tool access, output format, review queue, logging, and pause control together.
If the work can be handled inside one product, use that feature. If it crosses systems and shared knowledge, review the decision guide for built-in AI versus a connected business system.
Test offline first
Run historical or synthetic cases without changing live records. Record each failure and classify the cause:
- Missing or stale source information.
- Ambiguous process rule.
- Incorrect tool use.
- Weak output format.
- Permission or connection problem.
- Request that belongs outside the role.
Fix the process or source when that is the real cause. Do not try to solve every business ambiguity with more instructions to the model.
Move into shadow mode
In shadow mode, the specialized AI assistant prepares its result beside the current process. The team continues using the existing official route while reviewers compare outputs.
Track acceptance, corrections, missed context, exceptions, runtime, cost, and review burden. Invite the people who do the work to explain why a technically correct output may still be operationally unhelpful.
The day-60 gate asks whether the system is ready for a limited live scope. Open issues should have an owner, severity, workaround, and decision date.
Days 61–75: Launch a controlled live scope
Start with eligible cases
Choose cases that match the tested pattern. Exclude unusual, sensitive, or high-impact work until there is evidence and an approved control for it. Keep a qualified reviewer in the path.
For example, a document assistant might prepare completeness notes for standard files while unusual contracts continue through the existing manual route. A customer operations assistant might prepare account context without sending messages or changing commitments.
Train the team on the process
Team training should answer:
- What the assistant does and does not do.
- How work enters the system.
- Where prepared results appear.
- What reviewers must check.
- How to report a correction or concern.
- Who owns urgent issues.
- How to use the fallback process.
The message is operational: the assistant prepares defined work, and people remain responsible for judgment, relationships, and consequential decisions.
Run a weekly operating review
Review a small dashboard: completed units, acceptance, correction types, exceptions, review time, total cost, incidents, and one planned improvement. Look at actual examples behind the measures.
The day-75 gate confirms whether the limited launch can continue and whether any boundary should tighten.
Days 76–90: Operate, improve, and decide
Close the learning loop
Update approved examples, source ownership, process rules, tests, and output formats based on reviewed work. Keep a change history. Retest important cases when the model, tool, instruction, source, or permission changes.
The NIST AI RMF Core treats risk management as continuous across Govern, Map, Measure, and Manage. That pattern fits business value too. The system should be measured and managed after launch, not declared complete after the first successful run.
Make one of four decisions
At day 90, choose:
- Operate: Keep the current scope and continue improving it.
- Expand: Add one adjacent responsibility with its own design and test.
- Restrict: Reduce access, cases, or actions based on what was learned.
- Retire: Stop because the value, adoption, quality, or risk does not justify continued operation.
Expansion is not the only successful outcome. A well-supported decision to use a product feature or stop a weak idea can prevent a larger distraction.
Who must be involved
| Role | Responsibility |
|---|---|
| Business sponsor | Owns the desired result and investment decision |
| Process owner | Defines the work, exceptions, and acceptance standard |
| Reviewers | Judge prepared outputs and consequential actions |
| Knowledge owners | Maintain approved sources and resolve conflicts |
| Implementation partner | Designs, builds, tests, documents, and supports the system |
| Security or technical adviser | Reviews access, vendors, data flow, and response needs |
One person may hold several roles in a smaller company. The responsibilities still need names.
What should exist at day 90
- A defined business role and owner.
- A measured current-state baseline.
- A documented workflow and exception path.
- Approved company knowledge and source ownership.
- Scoped tools, identities, permissions, and approvals.
- A representative test set and results.
- A live operating dashboard and issue log.
- Team instructions and a fallback process.
- A 90-day value and risk review.
- A clear operate, expand, restrict, or retire decision.
Northern Logic can assess, build, and provide the managed operation behind this path. If you have a workflow in mind, book a free 15-minute AI assessment. You do not need a technology plan. Bring the business result, current frustration, and person who owns the work.
