Services

AI OperationsIntake, scheduling, reporting, handoffs Secure AITesting, guardrails, audit trail, fractional CISO AI AgentsOne-time builds and team training

Explore

DemoPricingProcessJournalFounder & ZaraFAQ

Manuals

AI Assessment ManualSecuring AI, for business leaders AI Field ManualBuilding and securing AI agents Book a free 15-minute workflow call

AI Operations · Secure AI · AI Agents

Put intelligence
into the work,
not another
dashboard.

TheZaraAI builds and runs AI operations for teams that want the hours back without unmanaged risk. Every workflow is logged, attributable, and reversible, and you get a written record of exactly what each system can reach.

U.S. Army Special Forces veteran Cyber Electronic Warfare Officer RSA Conference speaker
operations · todayexample workflow
Email arrivesreceived 9:02 ✓
Dana Whitfield 9:02 AM
Weekly vendor access report, attached for review
▤ vendor-access-wk32.pdf · 14 pp
Agent reviews the reportreviewed · 41s ✓
  • Read 14 pages, extracted access table
  • Compared against last week's report
  • 3 items flagged for a person
Summary report writtenreport ready ✓
  • 2 accounts with unused admin access
  • 1 new integration with no named owner
  • Everything else unchanged since last week
Reply drafted from templatesent · logged ✓
To: Dana Whitfield template · vendor follow-up
Hi Dana, thanks for this week’s report. Summary attached. Three items need a named owner by Friday: two unused admin accounts and one new integration.

Illustrative interface with fictional data. Not live customer activity, and not a performance claim.

Runs on the tools you already use

EmailCalendarFile storageSlackTeamsNotionCRMsScheduling toolsMost systems with a usable API

The gap

Most AI programs stall between the demo and the ledger.

Adoption is running ahead of governance. These are other people's numbers, linked to the source, because ours would not be checkable.

The risk is not using AI poorly. It is running it without visibility.

Three services

What we provide.

Pick one to see what it covers.

Intake, qualification, scheduling, reporting, and handoffs, run by agents on the tools you already use. Every action is logged, attributable, and reversible.

  • Intake queue
  • Scheduling
  • Reporting
  • Handoffs

Know what your AI did, who told it to, and what it touched. Prompt-injection testing, shadow-AI discovery, guardrails, and a fractional CISO who signs off on the controls.

  • Injection testing
  • Shadow-AI discovery
  • Guardrails & audit
  • Fractional CISO

One agent built for you on a fixed scope and a fixed price, then handed over with the documentation to run it without us. Team training is available à la carte.

  • Starter Agent
  • Integrated Agent
  • Care plan
  • Team training

Interactive demo

Watch one urgent request become a booked job.

Seven screens, start to finish. It plays on its own. Click any step to take over. This is a fictional home-services scenario built to show how the workflow behaves. Every name, address, and timestamp is invented.

01 / 07 A homeowner emails at 7:42 PM. Nobody is at a desk. In most shops this sits until morning, by which time he has called someone else.

Marcus WebbUrgentUpstairs AC blowing warm · There is ice on the pipe outside. How soon can someone…
Priya RamanQuoteFull system replacement · Looking for a quote on a 3-ton…
D. OkaforAnnual maintenance plan pricing? · Saw your post and wondered…
Hollis PropertyRepliedRooftop unit estimate · Thanks, the 14th works for us.
Supplier NoticesFilter order shipped · Tracking attached.
S. AlvarezRepliedDuctwork follow-up · Great, see you then.

02 / 07 Zara replies in 38 seconds, in the same thread, clearly labelled as automated. It asks the qualifying questions and offers real open slots.

Marcus Webb7:42 PM
Hi, my upstairs AC is blowing warm air. Started last night and there is ice on the pipe outside. How soon can someone look at it? 4417 Ridgeway Dr, Durham.
Zara · automated assistant7:42 PM · 38 seconds later
Hi Marcus, sorry about the warm air upstairs. Ice on the line usually points to airflow or refrigerant, so it is worth switching the system off to let the coil thaw. You are inside our service area. I have Thursday at 8:00 or 10:00 AM open. Which should I hold?
Marcus Webb7:51 PM
Thursday 10 works. Thank you!

03 / 07 The owner gets a text, not a task. It says what came in, what was done about it, and that nothing is needed.

Zarayour operations agent
New urgent request: Marcus Webb, Durham 27703. AC not cooling, ice on line. I replied in 38 sec and offered Thu 8 or 10 AM.
Marcus picked Thu 10:00 AM. All booking rules passed, so I scheduled it and assigned Ray T. Nothing needed from you.
Thanks
Logged. Full trail is in tomorrow's report.

04 / 07 Before anything is booked, four rules are checked. Anything that fails stops here and goes to a person instead of being guessed at.

Service areaAddress geocoded against the coverage mapZone 2
Urgency thresholdNo cooling, reported line iceHigh
Decision authorityConfirmed homeowner, not a tenantOwner
Existing accountNo prior service history on fileNew
Cleared to schedule without human review. Anything failing a rule stops here and goes to a person.

05 / 07 Thursday 10:00 AM is held against real zone capacity. The technician is assigned by route, and the confirmation goes out.

Mon 3Tue 4Wed 5Thu 6Fri 7 8:00
Booked
Open
L. Ferraro
Open
Booked
10:00
Open
Booked
Open
Open
Marcus Webb
AC estimate · Ray T.
T. Nguyen
1:00
Booked
Open
Booked
Booked
Open

06 / 07 The job lands in the Booked column of the pipeline on its own. One view instead of four apps.

New2

D. OkaforMaintenance plan
(919) 555-0148Text-back sent

Qualifying1

Priya RamanSystem replacement

Booked3

Marcus WebbThu Aug 6 · 10:00 AM
L. FerraroWed Aug 5 · 8:00 AM
T. NguyenFri Aug 7 · 10:00 AM

Estimate sent2

Hollis PropertyRooftop unit
S. AlvarezDuctwork

07 / 07 The next morning: seven actions, each with a time, an actor, and a reason. Every one of them is reversible.

What happened overnight7 actions · 0 needed a person · all reversible
19:42:06Request received, emailsystem
19:42:44First reply sentzara
19:49:18Address validated, zone 2rule
19:49:20Urgency classified, highrule
19:51:02Slot held, Thu Aug 6, 10:00zara
19:51:03Technician assigned, Ray T.rule
19:51:05Confirmation + owner text sentzara
01 / 07

Interactive demo. The interface, names, addresses, phone numbers, and timestamps are fictional and exist to illustrate how the workflow behaves. Nothing here represents a real customer, a live system, or a claimed result.

Outcomes & evidence

What you can hold at the end of it.

Automation is easy to demo and hard to trust. These are the artefacts every engagement produces, the things that outlive the enthusiasm of week one.

Deliverable

A written workflow map

Every trigger, handoff, exception, and escalation path documented, including what the system deliberately will not do on its own.

Deliverable

An audit trail

Automated actions are attributable and reversible. When something goes sideways you can see what acted, on what basis, and when.

Deliverable

A handoff document

Written so your team can operate and modify the system without us. Dependence is not a business model we are interested in.

Credential

Operator background

More than 20 years across military cyber operations and enterprise security. Former Deputy CISO. RSA Conference speaker. Security is the practice, not a bolt-on.

We do not publish customer counts, revenue impact, time-saved figures, or security outcomes on this site. Numbers like those are trivial to invent and impossible for you to verify, so treating their absence as a signal is reasonable. Ask on the call and you will get specifics with the client's permission attached.

How engagement works

Five stages. A decision point at every one.

No stage begins before you have seen what the last one produced. You can stop at any gate and keep everything built so far.

Stage 01

Discover

A free 15-minute call, then a short working session. We map where manual effort and unmanaged risk actually sit, usually not where people expect.

You receive

A written map of current state, friction ranked by cost.

Risk control

Read-only access. Nothing is changed, connected, or granted.

Your call

Do you agree with the diagnosis, and is the top item worth fixing?

Stage 02

Design

We specify the workflow before building it: triggers, rules, exceptions, and the explicit boundary of what the system may never decide alone.

You receive

A workflow spec and data-flow diagram any competent engineer could build from.

Risk control

Data classes identified up front; sensitive material scoped out or protected.

Your call

Does the spec match how you would want a good employee to behave?

Stage 03

Build

Implementation against the spec, in test mode, on your real tools but not your real customers until you say so.

You receive

A working system you can drive yourself, plus the test evidence behind it.

Risk control

Outbound is gated. Nothing reaches a customer while it is still being proven.

Your call

Having watched it run on your data, do you trust it to talk to a customer?

Stage 04

Secure

The stage most automation work skips. Access is narrowed, credentials move into managed storage, and the audit trail goes on before go-live.

You receive

An access inventory and audit configuration you could show an auditor.

Risk control

The blast radius of any single compromised credential is established in writing.

Your call

Are you comfortable with what each system could reach if compromised tomorrow?

Stage 05

Operate

Go-live, then the unglamorous part: watching it, tuning rules as your season shifts, and keeping it working as vendor APIs move underneath it.

You receive

Ongoing operation, or a clean handoff to your team, your choice, stated up front.

Risk control

Patching and dependency review continue. An unmaintained automation is a liability.

Your call

Do you want us operating this, or do you want the keys?

Selected patterns

Systems of this shape, built before.

Each panel below is a working prototype or an illustrative reconstruction of a system pattern we build. Client identities and data are not shown. Open one to see how it is put together.

Interactive demo
Home services · lead response

Inquiry to booked estimate

Unified inbox across phone, web, and social. Qualification against service area and urgency rules, then scheduling into real calendar capacity.

  • Missed calls trigger an immediate text-back and continue by message
  • Rules validate service area, urgency, and decision authority before booking
  • Only genuinely open calendar slots are offered; technician assigned by route
  • Anything failing a rule escalates to a person rather than being guessed at
  • Every automated action written to an attributable audit trail
Interactive demo
Multi-location · internal comms

One brief, every channel

A single message published to email, SMS, and social at once, with per-recipient link tracking flowing back into one engagement view.

  • One authored brief fans out to email, SMS, and social channels
  • Per-recipient tracked links attribute every open and click back to a send
  • Quiet hours and consent state enforced before any message leaves
  • Engagement rolls up into a dashboard by location and audience segment
  • Test mode gates all outbound until go-live is explicitly authorised
Example workflow
Security for AI

Boundaries around a model

An access and monitoring architecture: what the model may reach, what it retains, who authorised each action, and how misbehaviour surfaces.

  • Data classification determines what may enter a prompt at all
  • Per-integration credentials scoped to least privilege and rotated into managed storage
  • Tool and action allowlists constrain what the system can do, not just what it can read
  • Monitoring on anomalous volume, unusual targets, and off-hours activity
  • Audit log designed to answer "what acted, on what basis, and when"
Example workflow
Back office · document operations

Intake to structured record

Unstructured inbound (email, attachments, forms) read, classified, and turned into a structured record with the exceptions surfaced rather than silently guessed.

  • Inbound documents classified by type before any extraction is attempted
  • Extracted fields carry a confidence signal; low confidence routes to review
  • Nothing is written to a system of record without passing validation rules
  • Ambiguity is surfaced as an exception queue rather than resolved by guessing
  • Original document retained and linked to the resulting record for audit

Pricing

Find the shape that fits, then we scope it properly.

Answer four questions and you get the engagement that fits, with its published price. The call confirms scope. It is not where the number appears for the first time.

1 · Primary need
2 · Team size
3 · Systems to connect
4 · Timeline
Recommendation

Answer the four questions above

You will get a suggested engagement shape and where to start. It takes about ten seconds.

A starting point, not a quote. These are the published rates for each engagement; what changes on the call is which one you actually need, and whether the scope shifts it.

Monthly retainer

The main engagement. Ongoing build and advisory capacity for AI operations.

Reconnaissance

$2,600starting / month

Get one workflow off your plate at a time, done properly. The usual entry point.

Typically 1 month of workEnough to prove one workflow end to end

What you get

  • One workflow, taken from manual to runningMapped, built, tested on your real tools, then put live. Intake, scheduling, reporting, or a handoff.
  • Kept working after launchMonitored, fixed when a vendor changes its API, and rules tuned as your season shifts.
  • Bi-weekly strategy callsReview what ran and pick what to automate next.
  • Monthly report and email supportWhat the system did, what it escalated, what needs a decision.
  • The paperwork is yoursWorkflow map, access inventory, and handoff document.
Start here
Most common

Operations

$5,525starting / month

Ship new automations while everything already live keeps getting tuned.

Typically a 3-month minimumTime to build several workflows and let them settle

What you get

  • Several workflows built in parallelNew automations ship while the live ones are watched and optimised.
  • A named lead who knows your stackOne person, weekly strategy calls, priority response.
  • Tooling integration and documentationYour systems connected, and every connection written down.
  • Monthly operations reportWhat ran, what was escalated, and what to automate next.
  • Quarterly access and audit-trail reviewWho and what can reach your data, re-checked every quarter.
  • Runbook kept current, priority build slotThe handover stays accurate as the system changes, and new builds jump the queue.
Book a call →

Command

$14,625starting / month

Run AI operations with an embedded partner. Security leadership included, hosting covered.

6-month minimumAn embedded engagement, not a project

What you get

  • Dedicated build-and-governance capacityA standing team slot for building, securing, and running your AI operations.
  • Full AI workspace architectureHow agents, data, and people fit together, designed once and documented.
  • AI security audit includedInjection testing, access review, and guardrails, not sold back to you later.
  • Dedicated lead, embedded weekly cadenceIn your meetings and your channels, not a ticket queue.
  • Hosting, monitoring & governance includedThe $325/month hosting and security add-on is part of the price.
Talk to Jax

AI agent builds

Fixed scope, fixed price, yours to keep. The care plan carries the agent after handoff.

Starter Agent

$789one-time

Hand your email and your files to a lean assistant.

Built in under 30 daysFixed scope, fixed price, yours to keep

What you get

  • Email triaged and answered
  • File storage organised
  • Core automations configured
  • Written handoff + a month of light support
Start here

Integrated Agent

$1,250one-time

Connect your calendar and the tools your day actually runs on.

Roughly six weeksFixed scope, fixed price, yours to keep

What you get

  • Everything in the Starter Agent
  • Calendar invites drafted and sent
  • Up to 5 more integrationsSlack, Notion, CRM and similar.
  • Custom skills & templates
Book a call →

Care Plan

$232/ month · after a build

Keeps the agent running as your tools and their APIs change.

Month to monthThe default next step after handoff

What you get

  • Monitoring on the live workflows
  • Updates and fixes as vendors change
  • The on-ramp to a monthly retainer
Add to a build

À la carte

Interested in a single build, or in training your team? These are scoped and priced on what is needed, not off a rate card.

  • BuildIndividual AI agent buildOne agent, one workflow, scoped to the tools you already run.
  • SecurityIndividual cybersecurity assessmentWhere your AI and your systems are exposed, in writing.
  • TrainingAI trainingWhat AI can and cannot do for your business, for leaders and teams.
  • TrainingAI prompt training for your teamReliable output from the tools you already pay for.
  • TrainingHands-on trainingYour people build and run an agent with us in the room.

All prices in USD. Reconnaissance and Operations add $325/month for hosting & security: managed hosting, uptime monitoring, updates, and patching. Command includes it. One-time builds cover a fixed scope. Anything beyond it is quoted separately, before the work starts, and can roll into a monthly retainer.

Free downloads · two manuals

Start with the AI Assessment Manual.

The AI Assessment Manual

Securing AI, written for business leaders. Your organization adopted AI before it decided to. Ten practical protocols for using it without surrendering your data, your credentials, or your reputation. No technical background required.

  • Ten protocols
  • 30-day quick start
  • Five-minute self-check
Get the AI Assessment Manual →

Free PDF. The download form is on the manual's own page.

Also free

The AI Field Manual

The practical guide for people who want to build and secure their own agents. Answer two questions and it downloads straight away, with a copy to your inbox. If it saves you hiring us, that is a perfectly good outcome.

Delivered instantly · No spam · Unsubscribe anytime

Jaclyn "Jax" Scott, Founder and Principal of TheZaraAI

The practice

One operator. One agent. No account layer.

You work with the person doing the work. That is the whole staffing model, and it is why the engagement volume is deliberately limited.

Jaclyn “Jax” Scott

Founder & Principal

Cybersecurity and AI executive with more than 20 years across military cyber operations and enterprise security. A U.S. Army Cyber and Electronic Warfare Special Operations Warrant Officer, she supported SOCOM, SOCEUR, the Department of State, and NATO, and still serves as a Chief Warrant Officer in the 75th Innovation Command, delivering AI innovation to the warfighter.

Former Deputy CISO and VP of Cybersecurity at Pearson. Co-author of Cybersecurity Career Master Plan, co-host of the award-winning 2 Cyber Chicks, and a board member of the Special Operations Association of America, where she authored the Jax Act. Master’s in Cybersecurity Risk Management, Georgetown University.

  • Special Operations
  • Cyber & EW Warrant Officer
  • Former Deputy CISO
  • Georgetown MS
  • RSA Speaker
  • Published Author
AI agent · not a person

Zara

The system at the centre of the practice

Zara is the agent layer that runs client automations: triaging, drafting, routing, scheduling, and escalating around the clock. It is software, and it is represented here as an abstract mark rather than a face for exactly that reason.

Every action Zara takes in a client system is scoped, logged, and attributable. It does not have judgement. It has rules you approved, and a boundary it is not permitted to cross without a human.

  • Scoped access
  • Audit trail
  • Human escalation

Questions

The things people actually ask.

How does an engagement begin?

With a free 15-minute workflow call. We map where the manual work and unmanaged risk actually sit before any money changes hands, then scope from what we found rather than from a package list. If nothing worth fixing turns up, we will say so.

What does pricing actually depend on?

Scope and cadence. How many workflows are being automated, how many systems are involved, how much security and governance work is required, and the depth of ongoing involvement you need each month. The engagement selector above gives you a shape; the call gives you a number.

How much does it cost to have you build an agent?

One-time builds start at $789 for the Starter Agent, a lean assistant that answers your email and organises your files, built in under 30 days with a month of light support while you take over. The Integrated Agent is $1,250 and adds your calendar plus up to five more integrations, delivered in roughly six weeks, with an optional $232/month care plan. Individual builds and team training are also available à la carte, scoped and priced on what is needed.

Can we adjust scope mid-engagement?

Yes. Monthly retainers are scoped by deliverables, not a fixed task list, so priorities can move between workflows as your season or strategy shifts. Larger new builds are scoped and quoted before the work starts, never sprung on you after.

What tools do you integrate with?

The ones you already use. Email and calendar, file storage, Slack or Teams, Notion, CRMs, scheduling tools, and most systems with a usable API. If something has no API we will say so early rather than build a fragile workaround and hand you the maintenance bill.

What makes this different from other automation agencies?

Security is in the build, not sold back to you afterwards. Most automation work grants broad access to move fast and never revisits it. Here the access inventory, the least-privilege pass, and the audit trail are stages of the engagement, and you get the documentation to prove it.

How is my data handled? Is it secure?

Least-privilege access per integration, documented data flows, credentials in a managed secret store rather than pasted into a workflow tool, and an audit trail on automated actions. You receive a written record of exactly what each system can reach, which is also the document that tells you your blast radius if a credential is ever compromised.

15-minute discovery call

Fifteen minutes. One workflow. A straight answer.

A short working call, not a sales sequence. We walk your current setup and name the specific places manual effort and unmanaged risk are costing you. Free, and it books straight into the calendar.

  • Where your inbound actually lands, and how fast it gets answered
  • Which repetitive work is worth automating first, and which is not
  • What your systems can currently reach that you have not thought about
  • A recommended engagement shape, or an honest "you do not need us yet"
Free 15-minute workflow callBook a call →