New York credit-focused investment manager · $1–10bn AUM
AI adoption was moving faster than any one internal team could coordinate.
We became the firm's trusted AI adviser across platform controls, employee connector requests, policy support and staff enablement.
What changed
One trusted AI adviser
Technology, legal, compliance and staff gained a common route from a new request to a reasoned decision.
- Reviewed through one operating lens
- 3 platforms
- Administrative views assessed
- 100+
- Used to test the visible controls
- 13 exports
- Advice as new requests arise
- Ongoing
The firm already had three AI platforms in active use. Technical users were writing code with agents. Other employees wanted AI connected to email, collaboration tools, repositories and internal systems.
Operations, technology and compliance were being asked to make decisions across products that exposed different controls, produced different audit records and changed frequently. Each function held part of the answer; no one internal team held the complete operating view.
Altitude 7 filled that gap. The work began with a detailed environment review, then continued through staff requests, follow-up calls, policy support, connector decisions and the design of the firm's training program.
Inside the advisory role
Turn every new AI request into an operating decision.
The adviser connects the employee's intended workflow to the live permissions, available evidence and people responsible for the decision.
Fractional AI officer decision loop
From employee request to governed operating decision
Operating decision path
OBSERVE → INTERPRET → DECIDE → RECORD → REVISIT
Requests enter from across the firm
Staff requests
Connectors · AI applications
Platform changes
New models · licences · controls
Policy questions
Legal · compliance · records
Enablement needs
Training · workflows · access
Fractional AI officer
Connect the technical facts, proposed workflow and governance consequence.
Data
What can it reach?
Identity
Who does it act as?
Action
Can it read, write or publish?
Evidence
What is logged and retained?
Owner
Who approves and revisits it?
A clear route, with reasons
Proceed
Use case and controls are clear
Add guardrails
Narrow access, identity or permissions
Hold & clarify
Purpose or oversight is incomplete
Example decision · public deployment
Vercel request: hold and clarify
The platform was capable. The proposed use, authentication and public exposure were not yet defined.
Content
Could firm research be deployed?
Authentication
Who can reach the application?
Purpose
What workflow requires public hosting?
Continuing advisory cadence
01
Observe the estate
02
Answer requests
03
Record decisions
04
Train the teams
05
Revisit as tools change
Start with the facts
The firm had tools. It needed one operating view across them.
We reviewed Claude, ChatGPT Enterprise with Codex and Cursor using the firm's own administrative consoles and data exports. The work covered more than 100 administrative views and 13 exports across identity, provisioning, data controls, models, connectors, code execution, network access, spending and auditability.
Each observation was classified as a setting the firm could change, a product or licence limitation, or a fact that required context before anyone treated it as a problem. That distinction kept the review from becoming an indiscriminate remediation project.
The combined view exposed patterns no single platform owner could see. All three coding environments offered a code-review capability, and none was switched on. A connector export showed materially more connections than the administrative console. One product tier had no downloadable audit log; another logged many events without a named user.
A repeatable decision lens
Review the connection, not just the product name.
The same five questions now provide a common language for employees, technology, legal and compliance.
- Lens 01
Data
Identify the information the connection can reach, including firm research, mail, repositories and internal systems.
- Lens 02
Identity
Establish whether the tool acts as an individual employee, a shared account or a broader firm identity.
- Lens 03
Action
Separate read access from the ability to create, change, send, execute or publish on the firm’s behalf.
- Lens 04
Evidence
Check what the platform logs, retains and attributes to a named user—and what it cannot show.
- Lens 05
Ownership
Name the person who approves the use, reviews it and removes access when the purpose ends.
Why a strong platform was held
The unanswered use case mattered more than the vendor name.
One employee asked to connect Vercel. The platform itself was not the concern; it is a capable development and deployment product. The firm still needed to understand what the employee intended to publish.
Without that context, firm research or other internal material could reach a publicly available server. The authentication model, intended audience and ownership of the deployed application were also unclear. Altitude 7 recommended holding the connection until those questions were answered.
Remote computer control was held for a similar reason: the oversight and review path needed to be clearer. The advice was designed to make useful technology deployable on known terms, rather than accept or reject a product in the abstract.
Stay involved after the report
A baseline became a continuing advisory function.
The firm continued to bring Altitude 7 questions about connectors, platform changes and requests from staff. We joined follow-up calls, explained the technical and governance consequences in plain language and gave legal and compliance enough context to make their own decisions.
The firm's legal and compliance team also created a connector and AI-application request form. We reviewed it, separated one-time vendor diligence from per-connection approval and added a route for controls that a particular product tier did not offer.
Altitude 7 advised on configuration and governance design. The firm's compliance and legal owners remained responsible for policy language and regulatory decisions.
What the engagement established
The firm gained a repeatable process and a specialist it could return to.
Three active AI platforms were assessed through one operating view.
Controls already working were separated from configurable gaps and licence limitations.
Employee connector and AI-application requests gained a consistent decision process.
A public-deployment connection and remote control were held until their use and oversight were clear.
The firm’s request checklist became a practical, repeatable approval process.
Legal, compliance, technology and staff gained continuing access to an independent AI specialist.
Platforms change, employees find new uses and vendors add capabilities. The operating pattern is designed for that reality: observe the environment, understand the proposed use, identify the decision, assign an owner, record the reasoning and revisit it when the technology changes.
The service behind this work
Fractional AI Officer
A standing AI leadership seat for strategy, roadmap, architecture, governance, cost and measurable value.
See how the Fractional AI Officer works →Read next
AI training
PDF reports into model-ready data
Three working sessions on specialist extraction, Excel model updates and agents the investment team could test.
AI training
A firm-wide AI day with a defined next step
Investment, technology, operations and compliance worked through live workflows, reusable skills and the decisions behind a coordinated programme.
Does your firm need an AI owner before it needs another tool?
Start with the AI decisions already crossing technology, compliance and the business. A fractional AI officer connects those decisions into one managed path.