| A1 | DPIA (standard) One DPIA on a well-bounded processing activity, single-system, with existing data-flow documentation. | 5 days | GDPR Technical Compliance Sprint |
| A2 | DPIA (complex) One DPIA on cross-system, multi-vendor, special-category, or novel ML/AI processing - including supervisory-authority consultation prep. | 8–10 days | GDPR Technical Compliance Sprint |
| A3 | DPIA Bundle (×3) Three DPIAs across distinct processing activities, sequenced and cross-referenced. | 12–15 days | GDPR Technical Compliance Sprint |
| A4 | ROPA Build Article 30-compliant Record of Processing Activities for a single business unit or product line, structured for ongoing maintenance. | 5 days | GDPR Technical Compliance Sprint |
| A5 | Vendor DPA Review Sub-processor inventory + DPA gap-list + Standard Contractual Clauses status + transfer-impact assessment scoping. | 4 days | GDPR Technical Compliance Sprint |
| A6 | Breach Response Runbook 72-hour notification clock, decision tree, supervisory-authority drafting templates, internal communication plan, one tabletop exercise. | 4 days | GDPR Technical Compliance Sprint |
| A7 | Postmortem Facilitation Independent facilitator for a high-stakes incident postmortem; structured write-up; remediation register with owners. | 2 days | Engineering Health Check / Performance & Goals |
| A8 | Single Senior Interview Round One senior-round technical interview (panel participation + structured write-up + calibration debrief). | 0.5 days | Senior Engineering Hire Sprint |
| A9 | Vendor Selection (single decision) One vendor decision (observability / IAM / CDP / search / data warehouse / similar) - weighted matrix, TCO math, recommendation memo. | 3 days | Foundation Sprint / Tech Audit |
| A10 | Customer Compliance Questionnaire Response One enterprise security / DPA / vendor-risk questionnaire drafted, reviewed, returned with the supporting evidence pack. | 2 days | Compliance & DD Readiness Sprint |
| A11 | On-Call Health Check Audit on-call rota, paging discipline, incident-response posture, runbook coverage; prioritised remediation list. | 3 days | Engineering Health Check / Performance & Goals |
| A12 | LLM Vendor / Routing Decision One decision: OpenAI vs Anthropic vs open-source vs gateway routing - cost / latency analysis, recommendation, eval-gate plan; informed by WARRANT-Standard authorisation principles where agent behaviour is in scope. | 3 days | AI Integration Strategy Sprint |
| A13 | Data-Room Tech Section Audit Review of the tech section of a data room before opening to buyers - gap list, narrative coherence, risk pre-flagging. | 3 days | Acquisition Tech DD Sprint |
| A14 | ADR Facilitation One Architectural Decision Record-shaped engagement - option framing, weighted trade-off, design-review session, signed ADR artefact. | 3 days | Foundation Sprint |
| A15 | Vendor Portfolio Cost Review Review of the existing vendor / SaaS portfolio for overspend, overlap, renewal traps, and consolidation opportunities - quantified rationalisation plan with renewal-window calendar. | 4 days | Tech Audit / Engineering Health Check |
| A16 | Annual Tech Budget Advisory Pre-fiscal-year working session with CFO + CTO - tech budget model, headcount-vs-SaaS trade-offs, quarterly allocation, board-ready financial narrative and Q&A pack. | 5 days | Fractional CIO |
| A17 | Cloud Cost Architecture Review Architecture-led review of cloud spend - right-sizing, scaling patterns, environment hygiene, architectural inefficiencies driving cost. Not a line-item FinOps audit. | 3 days | Tech Audit / Engineering Health Check |
| A18 | SBOM & License Audit Software Bill of Materials across the codebase, open-source license inventory, copyleft/viral flagging, license-compatibility matrix, remediation list, regulatory-readiness note (EU CRA, enterprise procurement, M&A buyer-side legal). | 4 days | Acquisition Tech DD / Tech Audit |
| A19 | MCP Server Scaffold Bootstrap one MCP server for a single existing API or data source. Tool definitions with input schemas, /.well-known/mcp.json manifest, robots.txt allowance, Claude Desktop and Cursor smoke-test. Hand-over package: code + deployment notes + observable behaviour. | 5 days | MCP Server Implementation sprint |
| A20 | x402 Integration Pilot Wire one endpoint to x402 on Base Sepolia. Test wallet, facilitator setup, server-side 402 response with payment requirements, verify-and-settle flow, receipt header echoed back, tested 402-pay-retry end-to-end. Foundation for the full Agentic Payments sprint when scope grows. | 4 days | Agentic Payments sprint |
| A21 | Agentic Modernization Pilot Stand up the governed agent pipeline on one bounded legacy service. Dependency map, containerization (Docker), an agent-opened pull request under branch protection and a human merge gate, characterization smoke-test, and a structured audit trail of agent actions. Proof-of-concept for the full Agentic DevOps sprint. | 5 days | Agentic DevOps sprint |