One lifecycle governs every engagement, in every value stream — diagnosis through to running the work. Most firms deliver the first stage or two and hand you the rest.
What is constraining performance, and is the case for action credible?
Two beats. Scoping interviews and a data extract produce a signed Diagnose Roadmap: themes tagged process, people or technology, ranked by impact and readiness. That pack aims an in-depth diagnostic — it does not prescribe actions. The diagnostic walks the work and returns the case for action in your numbers, including the recommendation not to proceed.
See a sample Diagnose Roadmap — a fictional client, to show the shape of the output (PDF).
What operating model and control system will produce the outcome?
Design follows the tag the diagnostic confirmed. Process → standard work and cadence. People → owner, capacity, seat. Technology → native workflow first. Future-state, decision rights, governance, KPIs and the workforce design — plus a refreshed roadmap so the next workflow does not start from zero.
Will it work safely and economically?
Proof matched to what Design called for — Shadow Mode for AI-enabled work, a bounded pilot for a redesigned process, a supervised readiness period for a capability or role change — evidence against acceptance criteria agreed in writing, and a genuine go/no-go.
How will approved work run consistently at scale?
Fortress runs the workflow to defined standards, with reporting, exception handling and governance you can see into.
How will performance improve and expand over time?
Continuous improvement, demand reduction, capability transferred to your people, and expansion when it earns its place.
Enter at any phase. Stop at any phase. Most organizations start with Assess — one workflow, not the whole company.
Assess ranks the opportunity set once. Design keeps it current.
This isn't a rollout. It's a sequence you run against a single workflow at a time. Pick it, prove it against agreed criteria, and scale only what earns it.
Redesigning the workflow itself — the steps, the handoffs, the decision rights, and the exception paths that govern it.
Ownership, skills, and capacity — who does the work, and what they need to do it well.
AI-enabled capacity where it earns its place, governed from day one, not assumed on day one.
Most designs use more than one. None of them start by assuming which.
| Alternative | Stops at | Leaves you with |
|---|---|---|
| A consultancy | Assess, sometimes Design | A design you have to build, prove and run yourself. |
| An automation agency | A build, occasionally a pilot | Technology inside a workflow nobody assessed or governs. |
| A BPO | Operate — on the process as it stands | Lower cost per transaction and the same leakage underneath. |
| An IT services firm | Platform operation | Working technology and unchanged business performance. |
| Fortress | All five | A workflow that performs, documented process, and people able to run it. |
That sequence is the moat — not the breadth of what we do, but the order we do it in and the gates that hold it in place. Run against one workflow at a time, it's also the fast path, not the slow one.
The same discipline applies whether the stream is healthcare revenue cycle, insurance operations, revenue growth, customer operations or finance operations. What adapts is the workflow, the measures and the regulatory context — not the method.
Four of those five stages end. Operate does not — so it is worth being precise about what running the work actually means.
Not every workflow should be operated by anyone but you. The candidates are the high-volume, rule-bound work where consistency matters more than judgement, and where your team's time is currently spent on throughput rather than on decisions.
| Value stream | Typically operated | Always stays with you |
|---|---|---|
| Healthcare RCM | Denial management · A/R follow-up · Eligibility verification · Claim status and queue management | Clinical judgement, coding decisions, patient relationships |
| Insurance Operations | Claims intake and triage · Underwriting data assembly · Renewal preparation · Policy administration transactions | Coverage decisions, pricing authority, claim settlement |
| Revenue Growth | Market intelligence · List building and prioritization · Pipeline hygiene · Commercial reporting | Selling, negotiation, pricing authority |
| Customer Operations | Intake classification and routing · Status response · Knowledge maintenance · Escalation triage | Relationship ownership, commercial decisions |
| Finance Operations | Invoice handling · Collections follow-up · A/P processing · Reconciliation preparation · Recurring reporting | Approval authority, payment release, financial judgement |
Every operated workflow carries standards on four dimensions, set against your baseline rather than against a generic benchmark.
Volume processed within the agreed period.
Accuracy measured against a defined sampling method.
Time from queue entry to completion.
Work falling outside scope, treated as a design signal rather than only a performance one.
High-volume, rule-bound work runs on AI-enabled capacity under named human supervision. Authority begins at observation and expands only on evidence, and never past the level your own governance can supervise. The detail lives on the governance section below, and we would rather you read it than take our word for it.
See how governance works →These are design targets, not results we are claiming. Every one is baselined against your operation during Assess, and what is achievable in your environment is what goes into your service schedule.
| Design target | What it means |
|---|---|
| 60–80% queue-age reduction | The design target for aged work in a queue-based workflow, baselined per workflow. |
| 90 days to measurable value | A service commitment. Measurable movement against the baseline within 90 days of go-live. |
| 100% human review in Shadow Mode | Absolute. Not a target — a condition of the stage. |
Performance against baseline on every agreed measure, with the attribution method restated. Volume and throughput with trend. The exception log — what fell outside scope and what it implies for the design. Authority level and the evidence supporting it. Every change since the last review. Open risks with owners and dates.
You get the same pack every month, from the same template, so you can compare across periods without interpreting a new format each time.
Nothing here is designed to trap you.
Every operated workflow carries a runbook detailed enough for a qualified person to resume the work without us — that is what makes continuity real rather than a promise. On exit, transition assistance is contractual: documentation, knowledge transfer and a handover to an agreed schedule.
We would rather you stayed because the work performs.
Most operational AI fails because authority is granted at contract signature and evidence arrives later — if at all. Fortress works the other way round, and this section is how.
Every operated workflow runs at a defined authority level. Work starts at the bottom and moves up only against evidence agreed in advance. Levels are never granted at signature.
| Level | What it can do | Human review | Min. governance |
|---|---|---|---|
| A0 · Observe | Nothing. The workflow runs as it does today while behaviour is baselined. | Full. Nothing is acted on. | L1 |
| A1 · Recommend | Proposes actions for a person to decide. | Every recommendation reviewed. | L1 |
| A2 · Prepare | Assembles and stages work for human approval. | Every item approved before release. | L2 |
| A3 · Execute Bounded | Acts within an explicitly defined envelope. | Risk-weighted sampling plus full exception review. | L3 |
| A4 · Expanded Bounded | Acts across a widened envelope, on sustained evidence. | Reduced sampling plus full exception review. Never zero. | L4 |
The same requirement — human-in-the-lead oversight, authority earned through evidence rather than granted at signature — is named as a core AI-adoption capability in Carnegie Mellon University's AI Adoption Maturity Model, developed with Accenture (2026). This ladder is Fortress's version of that discipline.
Your own governance maturity — whether policy, ownership, review cadence and exception handling actually operate — sets the maximum authority any workflow can reach. An organization at Level 1 governance cannot run a workflow at A3, however well the tool performs.
Where there is a gap between the governance you have and the authority the work needs, closing it becomes part of Design. You will hear about that before you sign, not after go-live.
On your side, that named owner is who we call the Vanguard Operator — the person on your team who directs, supervises and holds authority over the operated workflow, and who the runbook is written for. Built into your team, not hired in: Fortress trains the owner already on your payroll rather than requiring a new AI-native role to make this work.
Fortress does not operate a workflow that makes a final adverse determination about a person. Coverage decisions, pricing authority, payment release, clinical judgement and claim settlement stay with you — by design and in the service schedule, not as a matter of practice.
Where operated work affects someone's access to care, coverage, credit or money, the design is documented and reviewed for consistency of treatment across comparable cases.
Authority governs what operated work may do. This governs whether the tool doing it is any good, and whether it stays that way.
| Control | What it means |
|---|---|
| Selection on evidence | Tools are chosen on measured performance against your workflow, not on general capability. Data handling terms are verified in writing before anything of yours reaches them. |
| Version pinning | We use versions we can pin and changes we are notified about. A tool that shifts underneath your workflow without notice is not one we will build on. |
| Evaluation sets | Every operated workflow has a set of cases with known-correct outcomes, drawn from your real work and reviewed by your subject expert. That is what "performing well" is measured against. |
| Regression testing | The full set re-runs before any change to a tool, prompt or rule reaches production. A failed run blocks the change. |
| Drift monitoring | Performance against the evaluation set is tracked. Decline pauses advancement and triggers investigation before the next cycle. |
| Change control | No change reaches your workflow without a reason, a regression run, sign-off, a log entry — and your notice where scope, authority or measured outcomes are affected. |
Confidentiality applies to all three. Not collecting your data is not the same as not seeing anything sensitive, and our engagement terms cover what we see as well as what we hold.
| Engagement | What happens to your data |
|---|---|
| The free readiness assessment | Nothing is collected. Responses are not stored or transmitted. No agreement required, because there is nothing to agree about. |
| Target Operating Model Design | Nothing is extracted, transferred or retained. We observe how your results are presented and used — dashboards, scorecards, trend charts — not your underlying records. This can begin without a data processing agreement, a business associate agreement or a security review. |
| Operated workflows | Access to your systems of record is required, because a baseline and attribution are impossible without it. Full data posture applies: least-privilege named access you grant and can revoke, multi-factor authentication, access logging, and a business associate agreement executed before any protected health information is touched. |
Every partner, platform or vendor that touches your data appears on a register available to you, with what they touch and the obligations they are held to. Changes are notified in advance. Partners are bound to the same terms we owe you — confidentiality, data handling, breach notification, and limits on further subcontracting. Your client data is never used to train third-party tools. We verify that in writing rather than assuming it.
It will, eventually — in any operation. What matters is what happens next.
| Severity | What it covers | What we do |
|---|---|---|
| Critical | Workflow stopped, data exposed, or your revenue or compliance directly at risk. | You are told immediately — before we have finished assessing it, not after. Continuous work until contained. |
| Major | Service standards materially breached, or a systemic error affecting a class of work. | Same-business-day notification, remediation plan within one business day, and authority reduced pending resolution. |
| Minor | Isolated errors or degraded performance within tolerance. | Logged, reported in the monthly review, remediated in cycle. |
Every critical and major incident produces a written review: what happened, why, and the control change that prevents recurrence. You get it whether or not you ask.
Everything on this page is a mechanism rather than an intention, which means it can be inspected. If you are evaluating Fortress for regulated work, ask for the security and data handling overview — it goes into more detail than a web page usefully can.
Excellence rests on a small set of universal principles — alignment, capable people, continuous improvement, and results that matter. You'll find them named differently across the Shingo Model, Baldrige, EOS, and other established frameworks. If you're already running one, we work inside it. If you're not, we install FORT Whole Enterprise Excellence, our own operating model built on the same principles.
If your leadership team runs EOS®, Scaling Up, OKRs, or has already built its own discipline around Shingo principles or Baldrige criteria, keep it. Your cadence, criteria, or cultural framework is doing exactly what it's built to do. We work inside what you have rather than replacing it — the gap we fill sits a layer deeper, in the workflows that framework was never built to diagnose or run.
We install FORT Whole Enterprise Excellence — Fortress's own operating model for organizations that don't already run one, built to run itself from week one, not a binder, not an audit. Direction that cascades, so priorities are clear from the top down and results travel back up to change the plan — a Hoshin-style deployment, lightly applied. People who are capable and coached, not trained once and left to it. Work standardized enough to flow, with capacity matched to what's actually coming in rather than guessed at. And a small set of results that actually matter, watched every week, with problems caught and worked before they calcify. Five principles, twenty-five elements, measured the way Baldrige and Shingo measure real performance — no external assessor, no award application, nothing that requires a dedicated quality function.
| Layer | Engagement | What it looks like |
|---|---|---|
| Workflow | Any of the five value streams | A named owner for every metric, a huddle where problems surface early as a habit, a scorecard the team trusts, and the discipline to hold a gain. |
| Organizational | Target Operating Model Design | Strategy deployment that actually cascades, named owners at every level, and a leadership team that keeps getting better at running the plan instead of relaunching it every year. |
| Leadership | Fractional COO & Transformation Leadership | Named leaders owning decisions that today only one person can make, a cadence that runs without them in the room, and a bench that keeps developing. |
These principles go in across the five stages rather than at a handover meeting. Your people learn the ownership model, the measurement discipline and the improvement method by running them on live work, coached as they go. By the time an engagement ends, the cadence is a habit rather than a plan.
That is also what makes handing a workflow to us safe. Every operated workflow carries a runbook detailed enough for a qualified person to pick it up without us, and transition assistance is contractual rather than goodwill. What can be handed back was documented from the first week — which is the only honest basis on which to hand it over at all.
A binder doesn't catch a problem in week three. A cadence does.
Twenty minutes on the problem — what's breaking, who owns it, and whether it's worth fixing this year. If the answer is that we're not the right fit, we'll say so.