# Talk Think Do > UK-based software consultancy delivering AI-accelerated, cloud-native software solutions. Microsoft Solutions Partner specialising in bespoke application development, legacy modernisation, and managed application support. Website: https://talkthinkdo.com Location: Bournemouth, Dorset, UK (Bobby's, 2-12 Commercial Road, Bournemouth, BH2 5LP) Phone: +44 1202 006729 Consultation: https://talkthinkdo.com/book-a-consultation/ ## About Talk Think Do partners with organisations to accelerate and stabilise large-scale software delivery. Founded by Matt Hammond in 2014, the team combines senior engineering expertise with AI-enhanced development tools (GitHub Copilot, Azure OpenAI, Cursor) to reduce delivery time without sacrificing quality. The team is a boutique group of experienced software experts with a hands-on, personal approach. Management is directly involved in every project. AI-assisted development tools and proven accelerators are used to modernise or replace critical systems faster. Enterprise-grade solutions delivered at startup speed, with the personal attention and agility that only a focused expert team can provide. ### Key Metrics - 91.6% of code AI-authored across live production work. Every line is reviewed by senior engineers, validated by ISTQB-qualified QA, and delivered within our ISO 27001-certified security framework. - 40-50% faster delivery using AI-augmented development - Quarterly AI tool evaluation cycle ### AI Approach AI moves fast. Talk Think Do runs a disciplined quarterly cycle so clients get the benefits in speed, cost, and outcomes, without the noise. Instead of a fixed playbook, the company runs a structured continuous improvement cycle: evaluating tools, deploying what works, measuring outcomes, and adapting every quarter. The four-step cycle: 1. **Evaluate**: Assess the latest tools and models; benchmark for accuracy, speed, cost, and reliability. 2. **Deploy**: Roll out tools across roles (business analysts, QA, engineers) with structured onboarding. 3. **Measure**: Track delivery speed, code quality, correction cycles, customer outcomes, and token costs. 4. **Adapt**: Refine and repeat; replace underperformers; standardise what works. Benefits for clients: faster delivery and higher quality, model-agnostic with no vendor lock-in, and responsible AI with guardrails (content filtering, output validation, human-in-the-loop, audit trails). ### Team Matt Hammond (Founder), Louise Clayton (Managing Director), Catherine Giles (Delivery Manager), Nikki Theophil (Business Analyst), Steve Proehl (Business Analyst), Jo Burrows (Business Support Manager), Sam Dobbs (QA Team Lead), Kyrylo Briekhov (QA Analyst), Rick Fox (QA Analyst), Zan Kocen (Frontend Engineer), John Morrison (.NET Engineer), Luke Geddes (Engineering Team Lead), Jay Kybert (.NET Engineer), Stuart Healey (.NET Engineer), Sam Waterworth (Apprentice .NET Engineer). ### Accreditations and Certifications - Microsoft Solutions Partner (Azure Infrastructure, DevOps and GitHub, Digital and App Innovation) - Microsoft AI Cloud Partner Program - ISO 27001 certified - Cyber Essentials Plus certified - Government Commercial Agency (GCA) supplier (G-Cloud 15 and DOS 7) - GDPR compliant ### Trusted By Hodder Education (Hachette UK), Third Space, Explore Learning, CalMac Ferries, Department for Education, Avios, Livestock Information Services. ## Services ### Custom Software Development https://talkthinkdo.com/services/custom-software-development/ UK custom software development company. Bespoke software built on Microsoft Azure with AI-augmented development, C#/.NET, React, and enterprise-grade security. Full source code ownership on every project. Key benefits: - Total cost of ownership: custom software often costs less over 3-5 years than SaaS licensing and workarounds. - IP ownership and competitive edge: you own the code, control the roadmap, build capabilities competitors cannot subscribe to. - Integration flexibility: native integration with your existing systems without middleware. - Scale without permission: no per-seat pricing, no feature gates, no vendor roadmap dependency. Technology stack: C#, .NET, Azure (AKS, SQL, App Services, Functions, AI Foundry), React, React Native, Bicep (IaC), GitHub Actions/Azure DevOps (CI/CD), GitHub Copilot, Cursor (AI-augmented development). Typical timeline: MVP in 2-10 weeks; full enterprise application 6 weeks to 6 months or more. Typical cost: within the published band of £25,000 to £100,000+ depending on scope. Team: Solutions Architect, Full-Stack Engineers, Delivery Manager, Business Analyst, QA Analyst, DevOps Engineer. Process: 1. Discovery & Requirements (1-2 weeks). 2. Architecture & Design (1-2 weeks). 3. Build & Iterate (agile sprints, AI-augmented, 40-50% faster delivery). 4. Launch & Handover (deployment, documentation, training). 5. Support & Continuous Improvement (SLA-backed managed support). ### Software Development Company UK https://talkthinkdo.com/services/software-development-uk/ Topic cluster under Custom Software Development. A UK-based software development company and consultancy that designs, builds, and supports bespoke software on Microsoft Azure. Headquartered in Bournemouth, Dorset. Government Commercial Agency (GCA) supplier, ISO 27001 certified, Cyber Essentials Plus certified, Microsoft Solutions Partner. Why a UK partner: - UK-based delivery team working in your timezone, to UK business norms, with direct access to engineers. - Public sector and regulated experience: G-Cloud, ISO 27001, Cyber Essentials Plus, GDPR, GDS. - Accountability: English-law contracts, transparent reporting, full source code ownership, no lock-in. - AI-accelerated delivery: 40-50% faster than traditional teams without cutting corners. Capabilities: bespoke web and business applications, cloud-native development on Azure, mobile apps for iOS and Android, AI and automation, legacy modernisation and integration, managed support. UK delivery model: Engagement (discovery, scope, architecture), Delivery (two-week AI-augmented sprints, automated QA), Ownership (source code handover, documentation, optional managed support). Sectors served: government and public sector, education and publishing, transport, sport and fitness. Clients: Department for Education, Livestock Information Services, CalMac Ferries, Hachette Learning, Third Space. ### Enterprise Software Development https://talkthinkdo.com/services/enterprise-software-development/ Topic cluster under Custom Software Development. UK enterprise software development: mission-critical systems at scale with ISO 27001 security, Cyber Essentials Plus, GCA framework approval (G-Cloud 15 and DOS 7), and AI-accelerated delivery on Microsoft Azure. What makes enterprise different: - Scale and availability: thousands of concurrent users, zero-downtime requirements. - Compliance and governance: ISO 27001, GDPR, Cyber Essentials Plus, sector-specific frameworks. - Integration complexity: ERPs, CRMs, legacy databases, third-party APIs. - Multi-team coordination: multiple workstreams, vendors, and stakeholders. Capabilities: cloud-native architecture on Azure (AKS, Cosmos DB, event-driven), microservices and domain-driven design, enterprise integration (REST, gRPC, GraphQL, Azure APIM), AI-enhanced enterprise applications, security and compliance by design, infrastructure-as-code and DevOps. Enterprise clients: Department for Education, CalMac Ferries, Livestock Information Services, Hachette Learning, Third Space, Avios. Typical cost: at the upper end of the published £25,000 to £100,000+ band, depending on scope and compliance requirements. ### Bespoke Franchise Platforms https://talkthinkdo.com/services/bespoke-franchise-platforms/ Topic cluster under Custom Software Development. Bespoke, owned franchise software for established networks that have outgrown off-the-shelf software. Builds the operational platform franchisees run on (booking, recurring billing, payments, membership) and the franchise layer head office needs (franchisor/franchisee/site hierarchy, management service fee and royalty calculation from operational data, multi-level permissions enforced in the API, compliance tracking, network dashboards), as one owned system on Microsoft Azure. Vertical-agnostic: applies equally to coaching, veterinary, fitness, activity, and other multi-site franchise networks. Three pillars: delivery certainty (incremental delivery, working software in weeks, conservative estimation, no big-bang rollout), ownership and independence (you own the IP, data, repository, and Azure subscription from day one, no per-franchisee fees, the platform is a capital asset), and fit and engineering quality (built around your operating model, multi-tenancy, and international and multi-currency complexity; ISO 27001, Microsoft Solutions Partner, AI-augmented for 40-50% faster delivery). When to build vs buy: off-the-shelf suits small, single-region, standard networks; bespoke suits networks that have outgrown off-the-shelf, whose operations are a differentiator, that are scaling or going international, or that need control of the roadmap and data. Four questions to ask any vendor: who owns the software, who is building it and are they accountable to you, are you renting or owning, and what happens at scale and across borders. Commercial model: one-off project fee plus optional hosting and support, no per-user/per-member/per-site licence fees; see the accelerator pricing and licensing page. Links to the franchise guides and the Franchising accelerator. ### Field Service App Development https://talkthinkdo.com/services/field-service-app-development/ Bespoke, offline-first field service apps for franchise networks and van-based operators (property claims, oven cleaning, signage, companion driving, and similar categories) and for multi-site trade services firms. The core argument is composite evidence: Talk Think Do has not shipped one badged field service platform, but has shipped every component of one across production systems and accelerator modules, and this page assembles that proof rather than telling one anonymised story. The component and proof mapping: a native app for non-desk staff (proven in the Third Space Atlas instructor app, running across 13 clubs at 99.99% uptime); scheduling, capacity, and availability (Booking Engine accelerator); invoicing, payment runs, and refunds (Billing Engine accelerator); franchise hierarchy, scoped permissions, and MSF (Franchising accelerator); data capture and processing at national scale (Livestock Information / LUIS, over 25 million tags managed in 2024-25); and push notifications with deep links (Mobile Push Notifications service). Offline-first is the non-negotiable: field staff work in basements, rural notspots, and multi-storey car parks where a web CRM in a mobile wrapper stalls. A native app reads and writes on-device, queues every action, and reconciles on reconnect, so the office and the field never disagree. Architecture: React Native, .NET on Azure, ISO 27001, full code ownership, no per-user fees. AI-augmented delivery runs 40-50% faster than a traditional team. Links to the Field Service accelerator, the franchisee field app requirements guide, and the franchise platform cost calculator. Targets field service app development UK, custom field service software, franchise field service app, and offline field service app. ### Cloud Application Development https://talkthinkdo.com/services/cloud-application-development/ Topic cluster under Custom Software Development. Cloud application development services in the UK. Azure-native applications with cloud-native patterns, infrastructure as code, AI-accelerated delivery, and ISO 27001 security. Microsoft Solutions Partner. Key capabilities: - Azure-native architecture: AKS, Azure Functions, Azure SQL, Cosmos DB, Front Door. - Cloud-native patterns: microservices, event-driven architecture, CQRS, 12-factor app methodology. - Infrastructure as code: Azure Bicep templates for repeatable, version-controlled environments. - CI/CD and DevOps: GitHub Actions or Azure DevOps with zero-downtime deployments. - AI-enhanced cloud applications: Azure AI Foundry, Azure OpenAI, Semantic Kernel. - Security by design: managed identity, private endpoints, encryption, ISO 27001, Cyber Essentials Plus. Typical cost: within the published band of £25,000 to £100,000+ depending on scope. ### Application Development Services https://talkthinkdo.com/services/application-development-services/ Topic cluster under Custom Software Development. Full-lifecycle application development services in the UK across web, cloud, mobile, and enterprise applications. Built on Microsoft Azure with AI-accelerated delivery and full code ownership. Microsoft Solutions Partner, ISO 27001 certified. Key capabilities: - Web application development: React and .NET on Azure, from customer portals to operational dashboards. - Cloud application development: cloud-native applications with managed services and infrastructure as code. - Mobile application development: React Native iOS and Android apps with secure Azure backends. - Enterprise application development: mission-critical line-of-business systems with compliance and high availability. - API and integration development: REST, GraphQL, gRPC, and event-driven integration on Azure. - AI-enhanced applications: RAG, custom copilots, and intelligent automation on Azure OpenAI. Typical cost: within the published band of £25,000 to £100,000+ depending on scope. ### .NET Development https://talkthinkdo.com/services/dotnet-development/ Topic cluster under Custom Software Development. UK .NET development company. Build and modernise .NET applications in C# and ASP.NET Core on Microsoft Azure, with AI-augmented engineering. Microsoft Solutions Partner, ISO 27001 certified, full source code ownership. Capabilities: ASP.NET Core APIs and web apps, enterprise .NET platforms, .NET modernisation (.NET Framework to current .NET, retiring WCF), Azure-native .NET (App Services, Functions, AKS). Secondary phrases: .NET development company UK, hire .NET developers, ASP.NET Core development. Proof: CalMac Ferries .NET integration platform (around 160,000 sailings and 5 million passengers a year); Department for Education Calculate Funding Service (around £60 billion allocated a year) modernised onto Azure. ### React Development https://talkthinkdo.com/services/react-development/ Topic cluster under Custom Software Development. UK React development agency. Fast, maintainable React web applications connected cleanly to back-end systems on Azure. AI-augmented delivery, full code ownership. Capabilities: React web applications, component libraries and design systems, front ends connected via backend-for-frontend, REST, and GraphQL, accessible and performant builds (WCAG, performance budgets). Secondary phrases: React development agency UK, React web app development. Proof: Third Space Atlas, React-based web front ends on a cloud-native Azure platform running at 99.99% uptime across 13 clubs. Note: for mobile apps see React Native Development. ### React Native Development https://talkthinkdo.com/services/react-native-development/ Topic cluster under Mobile App Development. UK React Native app development. Cross-platform iOS and Android apps from one codebase, with native depth where it matters and secure Azure back ends. AI-augmented delivery, full code ownership. Capabilities: one codebase for iOS and Android, native modules where required, Azure cloud back ends (backend-for-frontend), App Store and Google Play delivery plus MDM for enterprise apps. Secondary phrases: React Native app development UK, cross-platform mobile development. Proof: Third Space Atlas member app built in React Native as part of the Atlas platform (99.99% uptime across 13 clubs). Honest guidance: fully native is recommended when an app is dominated by platform-specific UI or deep hardware integration. ### MVP Development https://talkthinkdo.com/services/mvp-development/ Topic cluster under Custom Software Development, routing into Prototype to Production. UK MVP development company. Build a minimum viable product that tests the real business question fast with AI-augmented prototyping, then take the validated version to production. Approach: frame the question, prototype in days, build the smallest real product, validate with real users, then decide to scale, pivot, or stop. Secondary phrases: MVP development company, build a minimum viable product UK. Proof: FundingImpact.AI, an Azure OpenAI platform that took a charity-sector founder's idea to a working, validated product. ### Digital Transformation https://talkthinkdo.com/services/digital-transformation/ Topic cluster under Custom Software Development. UK digital transformation consultancy. Move off manual processes and ageing systems onto modern, secure Azure platforms. Transformation delivered as working software, not slideware, with legacy modernisation as the concrete mechanism. Approach: assess and prioritise, target architecture (6 Rs), modernise and build in increments, adopt and embed, operate and improve. Secondary phrases: digital transformation consultancy UK, digital transformation services. Proof: Department for Education Calculate Funding Service (around £60 billion a year) modernised onto Azure; CalMac Ferries platform (around 160,000 sailings and 5 million passengers a year). ### Data Protection by Design https://talkthinkdo.com/services/data-protection-by-design/ Topic cluster under Custom Software Development. GDPR-grade data protection engineered into bespoke software rather than bolted on before launch. GDPR names principles, not features, so we translate them into the standard controls every compliant system needs: machine-readable data classification, deny-by-default and server-side access control with field-level masking, encryption and key-vault secrets, an immutable audit trail, consent and suppression, permission-gated subject-rights tooling, and a retention and erasure engine. Controls are enforced by build-time coverage tests, and residency is treated as deployment topology so one codebase serves many jurisdictions. Approach: assess and classify the data, design the controls against the GDPR principles, build and enforce with tests that fail the build when protection is missed, then verify and demonstrate compliance. Secondary phrases: GDPR software development, privacy by design, data classification implementation, data residency, multi-jurisdiction data protection. Proof: ISO 27001 certified and Cyber Essentials Plus certified; production experience building systems that hold personal, special-category, and children's data, with classification, retention, and erasure coverage enforced in CI. ### Microsoft Gold Partner https://talkthinkdo.com/services/microsoft-gold-partner/ The Microsoft Gold Partner programme was retired by Microsoft in late 2022 and replaced by the Microsoft Solutions Partner programme. Talk Think Do holds the successor designations and delivers the Azure expertise organisations once sought in a Gold Partner. Key facts: - Gold and Silver Partner designations were retired in late 2022. - Solutions Partner uses continuous capability scores (at least 70 points), sustained Azure consumption, and annual growth commitments. - Talk Think Do holds Solutions Partner designations for Digital and App Innovation (Azure) and Infrastructure (Azure), plus the DevOps with GitHub on Azure specialisation. - These replaced Talk Think Do's previous Microsoft Gold Cloud Platform competency. - Verify any partner's current status in the official Microsoft partner directory at partner.microsoft.com. ### AI Development & Implementation https://talkthinkdo.com/services/ai-development-implementation/ UK AI development services. Enterprise AI built on Azure OpenAI, Copilot Studio, Semantic Kernel, and Azure AI Search. Microsoft Solutions Partner delivering practical AI that ships and scales. AI capabilities: - Generative AI features: document generation, summarisation, chat interfaces, natural language querying. - Intelligent automation: workflow automation, decision support, document processing. - AI-enhanced applications: recommendations, anomaly detection, predictive analytics, smart search. - Copilot and agent integration: Microsoft 365 Copilot extensions, custom copilots, autonomous agents. Microsoft AI platform: Azure OpenAI Service, Azure AI Search (RAG), Copilot Studio, Semantic Kernel, Azure AI Document Intelligence, Azure AI Foundry. Responsible AI: data privacy (Azure data residency), Microsoft Responsible AI framework, cost management (caching, token optimisation), production-grade reliability. Typical cost: AI engagements start from £19,000; a focused proof of concept typically starts at around £30,000, with enterprise-wide AI integration reaching £300,000+. Process: 1. AI Opportunity Assessment (1-2 weeks). 2. Proof of Concept (1-4 weeks). 3. Build & Integration (agile sprints). 4. Launch & Evolve (deploy, monitor, iterate). ### Custom Generative AI https://talkthinkdo.com/services/custom-generativeai/ Deep-dive on generative AI: Azure OpenAI integration, Copilot customisation, RAG patterns, and AI agent development. A focused subset of our broader AI Development & Implementation service. Capabilities: - **Microsoft Copilot Customisation**: Extend Copilot with your data, custom actions, and workflows. - **RAG (Retrieval-Augmented Generation)**: Connect AI to your knowledge base for accurate, context-aware responses. - **Azure OpenAI Integration**: Bespoke AI features with enterprise compliance and data sovereignty. - **AI Agent Development**: Autonomous agents for document processing and decision support. Principles: pragmatic over hype, model-agnostic architecture, enterprise-grade security, responsible by design. Typical cost: starting from £19k. Typical timeline: from 4 weeks. ### Claude Code Development https://talkthinkdo.com/services/claude-code-development/ Topic cluster under AI Development & Implementation (also linked from Custom Software Development). Custom software built with Claude Code. Full code ownership, clear IP terms, structured AI adoption, and ISO 27001 security. Formerly known as Claude Code Agency. Capabilities: custom software development, legacy modernisation, AI-powered product features, prototyping and validation. Differentiators: full source code ownership, copyright and IP clarity, structured AI adoption with quarterly evaluation, enterprise-grade security, human-led engineering. ### Copilot Studio Rescue https://talkthinkdo.com/services/copilot-studio-rescue/ Topic cluster under AI Development & Implementation. Rescue stuck Microsoft Copilot Studio implementations by integrating with Azure AI Foundry-hosted models and building enterprise RAG pipelines. Also build new Copilot Studio solutions from scratch with proper model flexibility. Common problems we solve: shallow grounding quality, locked to default models, inflexible connectors for on-premise/legacy data, no observability into AI responses. Capabilities: rescue stuck implementations, Azure AI Foundry model integration (GPT-4o, Phi, Llama, Mistral), enterprise RAG pipelines, new Copilot Studio solution builds. ### Azure AI Foundry Development https://talkthinkdo.com/services/azure-ai-foundry-development/ Topic cluster under AI Development & Implementation. Build, evaluate, and deploy AI models on Azure AI Foundry (formerly Azure AI Studio). Model catalogue access (OpenAI, Meta Llama, Mistral, Microsoft Phi), prompt flow and evaluation, fine-tuning, responsible AI dashboard, multi-model architectures. Capabilities: model catalogue and deployment, prompt flow and evaluation, model fine-tuning, responsible AI dashboard, RAG and retrieval integration, multi-model architectures that route requests to the most cost-effective model per task. Platform features: Model-as-a-Service (MaaS), managed compute, prompt flow, content safety, enterprise security (private endpoints, managed identity, RBAC). ### AI Integration https://talkthinkdo.com/services/ai-integration/ Topic cluster under AI Development & Implementation. Connect AI to enterprise data with custom MCP servers, production RAG pipelines, and hybrid architectures that blend AI with deterministic logic to reduce token cost and improve reliability. Capabilities: - **Custom MCP servers**: Model Context Protocol servers giving AI agents secure, structured access to enterprise data and tools. - **Enterprise RAG pipelines**: Document discovery, text extraction, chunking, embedding, and Azure AI Search indexing. - **Hybrid AI/deterministic architectures**: Deterministic logic (rules, calculations, lookups) for predictable tasks; AI inference for reasoning tasks. Minimises token cost while maximising quality. - **Data pipeline integration**: Ingestion from Azure SQL, Cosmos DB, on-premise file shares, legacy databases, and third-party APIs. Key FAQ topics: deterministic vs non-deterministic processing, AI token cost management and optimisation strategies, MCP protocol, RAG vs fine-tuning. ### Microsoft Copilot Interface https://talkthinkdo.com/services/microsoft-copilot-interface/ Topic cluster under AI Development & Implementation. Build and integrate Microsoft Copilot interfaces in the UK: the conversational surfaces through which users interact with AI assistants built on Microsoft technology. Microsoft Solutions Partner, ISO 27001 certified. Key capabilities: - Custom Copilot interfaces embedded into web and mobile applications (chat panels, prompt surfaces, inline assistants). - Microsoft 365 Copilot extensibility: declarative agents and plugins for Teams, Outlook, and Word. - Copilot Studio agents connected to enterprise data sources and back-end systems. - Bespoke Copilot-style interfaces on Azure OpenAI and Semantic Kernel with retrieval-augmented generation (RAG). Approach: grounded in your data with RAG, secured within your Azure tenancy with role-based access control, accessible, and matched to your design system. ### AI Agent Development https://talkthinkdo.com/services/ai-agent-development/ Topic cluster under AI Development & Implementation. UK AI agent development. Design and build agentic AI systems that do real work, grounded in your data and processes and supervised by an engineering team. Built on Azure OpenAI and Claude, ISO 27001 certified. Capabilities: agents that take action (call APIs, complete multi-step tasks), grounding in your data and standard operating procedures via RAG, focused composable agents coordinated by an orchestrator, safety by design (scoped access, audit logs, human-in-the-loop). Secondary phrases: agentic AI development, build AI agents for business. Approach: identify the task, design the agent system, build and ground, add guardrails and evaluation, deploy and supervise. Strictly agentic, distinct from generic chatbots. Proof: FundingImpact.AI, an Azure OpenAI platform grounded in client data that produces reporting and actionable recommendations, not just chat. ### AI Consulting https://talkthinkdo.com/services/ai-consulting/ Topic cluster under AI Development & Implementation. AI consulting for UK businesses: AI strategy, readiness assessments, build vs buy decisions, and costed roadmaps. Unlike pure-advisory firms, Talk Think Do also builds and supports the software the roadmap describes. What it covers: AI strategy (where AI adds value), AI readiness (data, security, skills, and governance assessment), build vs buy recommendations, and integration and delivery planning on Microsoft Azure. Process: Discovery (1 week), Readiness Assessment (1-2 weeks), Roadmap (costed plan and target architecture), then optional Delivery by the same team. Proof: the quarterly AI Velocity Report (91.6% AI-authored code, 100% senior-engineer reviewed, 40-50% faster delivery) and the FundingImpact.AI case study (Azure OpenAI platform from idea to production). Typical cost: AI engagements start from £19k; see the pricing page for detail. ### Legacy Application Modernisation https://talkthinkdo.com/services/legacy-application-modernisation/ Legacy application modernisation in the UK. Transform outdated systems into modern, scalable platforms on Microsoft Azure using the 6 Rs framework. AI-accelerated delivery. The legacy problem: most enterprises spend 60-80% of IT budget maintaining legacy systems. Security exposure, talent shortage, and innovation blocked by outdated architectures. Modernisation strategies (6 Rs): - **Rehost**: Lift-and-shift to Azure VMs. Fastest path, limited modernisation benefit. - **Replatform**: Migrate to Azure managed services (App Services, Azure SQL). - **Refactor**: Restructure code for cloud-native patterns without changing external behaviour. - **Rearchitect**: Redesign with microservices on AKS, event-driven patterns, API-first design. - **Rebuild**: Start from scratch when the codebase is beyond economical repair. - **Replace**: Retire and adopt a modern alternative. Azure migration tools: Azure Migrate, Azure Database Migration Service, AKS, Azure App Services, Azure SQL. Typical timeline: single application replatform 4-8 weeks; complex programme 3-9 months. Process: 1. Assessment (2-15 days, AI-accelerated codebase analysis). 2. Strategy & Architecture (1-2 weeks). 3. Migration & Build (phased sprints, parallel running, incremental cutover). 4. Optimisation & Support (performance, cost, security tuning; managed support). ### API & Integration Services https://talkthinkdo.com/services/api-and-integration-services/ UK API and integration services. Design, build, and operate REST, gRPC, GraphQL, and event-driven integrations on Azure. Microsoft Solutions Partner connecting applications, automating workflows, and building resilient API platforms. Capabilities: - REST API design and build (OpenAPI, versioning, OAuth 2.0, developer portals). - gRPC and high-performance services (Protocol Buffers, low-latency microservice communication). - GraphQL APIs (schema federation, DataLoader, subscriptions). - Azure API Management (APIM) (gateway, policy authoring, rate limiting, analytics, developer portal). - Azure Service Bus and async messaging (event-driven architecture, decoupled services, dead-letter handling). - Messaging patterns (pub/sub, competing consumers, event sourcing, saga orchestration). - HubSpot mobile integration (bidirectional CRM sync, push notification triggers, mobile event tracking). Technology: .NET, Azure APIM, Azure Service Bus, Azure Event Grid, Azure Event Hubs, Protocol Buffers, GraphQL. Topic pages: REST API Development, gRPC API Development, GraphQL API Development, Azure API Management, Azure Service Bus Integration, Messaging Patterns, HubSpot Mobile Integration. ### DevOps & Modernisation https://talkthinkdo.com/services/devops-modernisation/ UK DevOps consulting services. CI/CD pipelines, infrastructure-as-code, platform engineering, and DevOps-as-a-Service on Azure. Microsoft Solutions Partner with DevOps & GitHub designation. Capabilities: - CI/CD pipeline design (GitHub Actions, Azure DevOps). - Infrastructure-as-code (Azure Bicep). - Container orchestration (Docker, AKS). - Monitoring and observability (Application Insights, Azure Monitor). - Platform engineering (internal developer platforms, self-service infrastructure). - DevSecOps (dependency scanning, container scanning, SAST, compliance-as-code). DevOps-as-a-Service: managed pipeline management, infrastructure operations, release management, and security/compliance monitoring on an ongoing basis. Typical cost: starting from £5k. Typical timeline: foundation build 2-4 weeks; ongoing management available. ### GitHub Actions & Advanced Security https://talkthinkdo.com/services/github-actions-cicd/ Topic cluster under DevOps & Modernisation. GitHub Actions CI/CD pipelines and GitHub Advanced Security implementation for GitHub Enterprise organisations. Reusable workflows, composite actions, CodeQL code scanning, secret scanning, Dependabot, and supply chain security. Capabilities: CI/CD pipeline design, reusable workflows and composite actions, GitHub Advanced Security (GHAS), environment and deployment management, container and Kubernetes deployments, supply chain security (SBOM, provenance attestation, signed commits). Also covers: migration from Jenkins, Azure DevOps, TeamCity, and CircleCI; self-hosted runner strategy; OIDC federation with Azure (workload identity). ### Azure Bicep Infrastructure https://talkthinkdo.com/services/azure-bicep-infrastructure/ Topic cluster under DevOps & Modernisation. Azure Bicep infrastructure as code: reusable module libraries, environment provisioning, Azure Policy governance, what-if deployments, drift detection, and CI/CD integration. Capabilities: Bicep module libraries in private registries, parameterised environment provisioning (dev/staging/UAT/production), policy-as-code with Azure Policy, what-if deployment previews, drift detection, migration from ARM templates or Terraform. ### AKS Deployment https://talkthinkdo.com/services/aks-deployment/ Topic cluster under DevOps & Modernisation. Azure Kubernetes Service (AKS) cluster design, zero-downtime deployments (rolling, blue-green, canary), monitoring with Prometheus and Grafana, Azure Policy for pod security, and cost optimisation. Capabilities: AKS cluster design (node pools, networking, identity, scaling), custom Helm charts with private repository, zero-downtime deployments, monitoring and observability, security and compliance (pod security standards, network policies, Azure Key Vault), cost optimisation (autoscaler, spot nodes, resource quotas). ### Mobile App CI/CD https://talkthinkdo.com/services/mobile-app-cicd/ Topic cluster under DevOps & Modernisation. Mobile app CI/CD with Expo and EAS Build. Automated iOS and Android builds, App Store Connect and Google Play submission via EAS Submit, over-the-air (OTA) updates with EAS Update, and GitHub Actions integration. Capabilities: Expo and EAS Build pipelines, App Store and Google Play automated submission, over-the-air updates, GitHub Actions integration, code signing and credential management, testing and QA distribution (TestFlight, internal tracks). Also supports bare React Native with Fastlane-based pipelines. ### Data Migration https://talkthinkdo.com/services/data-migration/ Topic cluster under Legacy Application Modernisation. Automated data migration with a fully automated nightly pipeline that extracts, anonymises, transforms, loads, and validates production data every night. By go-live day, the migration has been executed and validated hundreds of times. Capabilities: automated nightly migration runs, anonymised test data (deterministic anonymisation preserving referential integrity), validation and reconciliation reports, schema mapping and transformation, incremental/delta migration for parallel running, AI-enhanced data cleansing (duplicate detection, format standardisation, missing value inference). Our approach: risk reduction through repetition. Each nightly run is a dress rehearsal for go-live. The same pipeline that runs every night executes the final cutover. Anonymised production data preserves real data shapes and edge cases. Supported sources: SQL Server, Azure SQL, PostgreSQL, MySQL, Oracle, Cosmos DB, Access, flat files, SaaS APIs. ### Managed Application Support https://talkthinkdo.com/services/managed-application-support/ UK managed application support services. SLA-backed support, proactive monitoring, and continuous improvement for live applications. We also support software we didn't build. What's included: SLA-backed support tiers, proactive monitoring and alerting, bug fixes and security patches, performance optimisation, feature enhancements, Azure infrastructure management. Key differentiator: we support software we didn't build. Vendors disappear, internal teams move on, contractors deliver and leave. We take over, assess, stabilise, and improve. Specialist support: development partner transition (outgoing supplier), vibe coding rescue (AI-built apps), maintainability review (due diligence), internal systems handover (team transition), legacy application support. Starting from: £1,590 per month. Coverage models: business hours; extended hours matched to your operating day; 24/6 with one defined weekly maintenance window; 24/7 round-the-clock. Cover is agreed per engagement rather than sold in fixed tiers, and models can be combined across an estate. The SLA defines severity levels against your business impact, separate response and resolution targets per severity, coverage and maintenance windows, escalation paths, incident and problem management, and reporting cadence. Targets and ticket caps are calibrated quarterly. 24/7 out-of-hours monitoring and escalation is delivered with partner Just After Midnight while technical ownership stays with the UK engineering team. Process: 1. Discovery & Assessment (up to 2 weeks, AI-accelerated codebase analysis). 2. Onboarding & Go Live (knowledge transfer, monitoring setup, CI/CD validation). 3. Ongoing Support & Improvement (monthly reports, quarterly reviews, continuous improvement). ### Development Partner Transition https://talkthinkdo.com/services/managed-support/development-partner-transition/ Structured transition of a business-critical application estate from an outgoing development partner. For organisations whose long-standing supplier is winding down, has been acquired, or is exiting the sector, and who need a successor before formal notice lands. Four phases: estate assessment (2-4 weeks: codebase, infrastructure, security, disaster recovery, and a ranked risk register you own); knowledge transfer (4-12 weeks, front-loaded because the outgoing team's staff leave first); parallel running (4-12 weeks of live tickets alongside the incumbent while they still hold the SLA); full ownership (named UK team, agreed coverage, monthly reporting, quarterly roadmap reviews). What transfers: knowledge captured while the outgoing team is still contracted; source control, Azure subscriptions, DNS, certificates, secrets, and third-party licences registered and verified under your ownership; documentation generated from the code with AI-augmented analysis; automated regression coverage, which is the most common gap in an inherited estate; operational ownership including monitoring, incident and problem management. Distinct from internal systems handover, which covers systems leaving an in-house team. A development partner transition involves a contract to exit, an exit plan, intellectual property and access transfer, and often a competitive selection process first. Planned wind-downs commonly run 12 to 24 months from first notice to final exit. Phases are structured against your exit dates rather than a fixed template. ### Mobile App Development https://talkthinkdo.com/services/mobile-app-development/ React Native mobile app development for iOS and Android. Consumer App Store apps and enterprise MDM staff apps, with usability, accessibility, and security built in. What we build: - Consumer and App Store apps: iOS and Android, full lifecycle from UX to submission and release. - Enterprise and MDM staff apps: internal tooling via Intune, Apple Business Manager, or Google managed devices; offline-first and kiosk where needed. - React Native with native depth: one codebase, two platforms; native modules and platform-specific UX. - Mobile backend integration: apps built alongside the APIs and backends they need, or integrated with existing systems. Process: 1. Discovery and UX scoping (2 days to 4 weeks). 2. React Native build in agile sprints (two-week sprints, real-device testing). 3. App Store submission or MDM deployment (consumer: App Store and Google Play; enterprise: Intune, ABM, managed Play). 4. Launch and 30 days free post-launch support; optional managed application support for ongoing care. ### Mobile App Backends https://talkthinkdo.com/services/mobile-app-backends/ High-volume, secure, reliable backends for mobile apps on Azure and .NET. BFF pattern, REST APIs, GraphQL, gRPC, and integration with SaaS and legacy systems. Capabilities: - Backend for Frontend (BFF), REST, GraphQL, gRPC. - SaaS integrations (HubSpot, Stripe, identity providers, etc.). - Legacy system bridging (on-premises, SOAP/WCF, mainframe APIs). - Event-driven and async patterns (Azure Service Bus, Event Grid). - Auth and identity (Azure AD B2C, Entra ID, MSAL, OAuth2/OIDC). - Observability (Application Insights, structured logging, alerting). Process: 1. API design and architecture review (1-3 weeks). 2. BFF and service layer build (agile sprints on .NET 10, Azure App Service or Container Apps). 3. Integration, load testing, and security review (OWASP API Security Top 10). 4. Deployment and ongoing support (infrastructure as code, CI/CD, optional managed application support). ### HubSpot Mobile App Integration https://talkthinkdo.com/services/hubspot-mobile-integration/ Connect a mobile app to HubSpot: bidirectional CRM data sync, HubSpot-triggered push notifications and in-app messages via custom workflow actions, mobile event tracking, and transactional email. Built on .NET and Azure using the HubSpot Integration accelerator as a foundation. Capabilities: - Bidirectional CRM data sync: mobile users become HubSpot contacts; in-app events become CRM activity. - HubSpot-triggered push notifications: custom workflow actions that fire APNs/FCM push notifications from HubSpot enrolment criteria. - HubSpot-triggered in-app messaging: custom workflow actions that deliver in-app messages via the app's messaging layer. - Transactional email through HubSpot: order confirmations, password resets, and booking updates via the HubSpot Transactional Email API. - Mobile event tracking: in-app behaviour flows back to HubSpot as custom behavioural events for workflows, scoring, and segmentation. - Identity bridging: reliable matching of mobile app users to HubSpot contacts across anonymous sessions, social login, and multiple devices. Process: 1. Integration design (1-2 weeks): data model mapping, HubSpot configuration review, API contract design. 2. Build the integration layer (.NET service, HubSpot API, retry logic, data mapping). 3. Configure HubSpot custom actions (push notification and in-app message workflow actions, end-to-end testing). 4. Testing, handover, and optional managed support. ### Mobile Push Notifications https://talkthinkdo.com/services/mobile-push-notifications/ Push notifications integrated into backend business operations, with deep links that route users to specific app screens and HubSpot workflow actions that drive users to specific features and content. Capabilities: - Backend event-driven triggers: notifications as a first-class output of backend operations, fired from within the business logic when the triggering event occurs. - Deep link architecture: Universal Links (iOS) and App Links (Android) that navigate users to a specific screen, content item, or action. Cold-start, warm-start, and active-app navigation all handled. - HubSpot-triggered deep-linked notifications: custom HubSpot workflow actions that fire a notification and specify the deep link destination within the app. - Contextual payload design: notification payloads carry enough structured data to navigate and display without additional API calls. - Custom notification actions: interactive action buttons with deep link context, so each action routes the user to the correct next step. - Push and in-app coordination: routing layer that sends push when the user is outside the app and in-app message when they are active. Process: 1. Trigger and deep link mapping (1-2 weeks): identify all backend events that should trigger notifications; map each to its payload structure and deep link destination. 2. Backend integration: wire notification triggers into backend operations; build internal notification API; HubSpot custom workflow action. 3. Deep link implementation: Universal Links and App Links configuration; React Native deep link handler; cold-start and edge case navigation. 4. HubSpot workflow testing and go live (real device testing across iOS and Android versions). ### Prototype to Production https://talkthinkdo.com/services/prototype-to-production/ Code audits, architecture reviews, and production-readiness assessments for applications built with Replit, Lovable, v0, Bolt.new, Cursor, Windsurf, and other vibe coding tools. What we do: - **Code audit and architecture review**: structure, security, data handling, architecture drift. - **Production-readiness assessment**: gap analysis on auth, error handling, logging, hosting, compliance. - **Refactor or rebuild on clean foundations**: honest recommendation; standards-based code you own. - **Ongoing managed support**: monitoring, patching, incident response, continuous improvement. Timeline: internal tool 3-4 weeks; customer-facing with compliance 2-3 months. Process: 1. Assessment (1-2 weeks; review codebase, hosting, data; written report with action list). 2. Stabilise or Rebuild (harden or rebuild; real code, version-controlled, documented). 3. Handover or Ongoing Support (documentation and knowledge transfer, or managed support under SLA). ### Learnosity Integration https://talkthinkdo.com/services/learnosity-integration/ Topic cluster under API & Integration Services. Learnosity Build integration on Azure: assessment authoring, adaptive delivery, analytics dashboards, and content migration from legacy assessment platforms. Talk Think Do is a Learnosity Services Partner. Note on naming: Learnosity is the company; Learnosity Build is its assessment engine and API suite. Capabilities: assessment authoring systems (Author API), adaptive assessment delivery (Assess API), analytics and reporting dashboards (Reports API, Data API), Azure cloud-native architecture (App Service, AKS, Azure SQL, Event Hubs), data migration from legacy platforms, managed support for Learnosity Build platforms. AI capabilities: Learnosity Build includes native AI features that we build around, namely AI-assisted authoring (https://learnosity.com/build/author/), Feedback Aide for agentic AI essay scoring and written-response feedback (https://learnosity.com/ai-assisted-scoring-feedback/), and Item Bank Health Check for AI-assisted item quality and accessibility remediation (https://learnosity.com/item-bank-health-check/). We extend these with Azure AI services for adaptive learning tools, custom content pipelines, and intelligent analytics. Proven outcomes: 845,000+ pupils on platforms we have built, 3 million+ assessments processed annually, 60,000+ questions authored, UK Business Tech Award winner. Clients: Hachette Learning (Boost Insights), Explore Learning (assessment authoring, and the adaptive logic engine inside their Compass learning platform, integrated with Learnosity for assessment delivery). ### AI Assessment with Learnosity Build https://talkthinkdo.com/services/learnosity-ai-assessment/ Topic cluster under API & Integration Services. How Talk Think Do puts Learnosity Build's native AI capabilities into production assessment platforms on Azure, with the human oversight and governance layer around them. Native Learnosity Build AI capabilities we integrate: AI-assisted authoring, Feedback Aide (embeddable agentic AI essay scoring and written-response feedback), and Item Bank Health Check (AI-assisted item quality analysis, plus generated audio and video transcriptions and contextual image alt text for accessibility remediation). What TTD builds around them: editorial review gates and approval workflow for AI-authored items, moderation queues with teacher override and score audit trails for AI marking, scheduled item bank sweeps with remediation reporting, WCAG 2.2 AA verification of AI-generated accessibility content, custom Azure AI models where a requirement falls outside the product, and data protection by design (documented data flows, region control, retention rules, immutable audit trail of automated decisions). Process: assessment AI discovery (1 to 2 weeks), pilot on a real item bank against the client's own markers (3 to 6 weeks), build the oversight layer, then progressive rollout with agreement-rate monitoring and managed support. Delivery position, stated plainly: Learnosity Build's AI capabilities are recent additions to the product, and as of this writing Talk Think Do has not yet shipped a client platform using them in production. The relevant experience TTD brings is Learnosity delivery at national scale (Boost Insights for Hachette Learning: 4,000+ schools, 845,000+ pupils, 3 million+ assessments a year), item bank scale (60,000+ questions authored for Explore Learning), custom logic layered on Learnosity (the adaptive logic engine inside Explore Learning's Compass platform, integrated with Learnosity for assessment delivery; Compass at Home won a UK Business Tech Transformation Award), and production AI delivery on Azure (Azure OpenAI and Azure AI Search platform for FundingImpact.AI). ### REST API Development https://talkthinkdo.com/services/rest-api-development/ Clean, versioned REST APIs on Azure: contract-first, OpenAPI-driven, security reviewed. From public developer platforms to internal microservice APIs. Capabilities: contract-first design, RESTful resource modelling, OAuth 2.0/OpenID Connect, versioning, documentation, testing and load testing. Part of API & Integration Services. ### GraphQL API Development https://talkthinkdo.com/services/graphql-api-development/ GraphQL APIs on Azure with schema federation, DataLoader, subscriptions, and security hardening. Flexible, self-describing APIs that unblock front-end teams. Part of API & Integration Services. ### gRPC API Development https://talkthinkdo.com/services/grpc-api-development/ High-performance gRPC services using Protocol Buffers on Azure for microservices that need speed, type safety, and strong service contracts. Part of API & Integration Services. ### Azure API Management (APIM) https://talkthinkdo.com/services/azure-api-management/ Configure and operate Azure API Management to secure, govern, and expose APIs: developer portals, policy authoring, monitoring, lifecycle management. Part of API & Integration Services. ### Azure Service Bus Integration https://talkthinkdo.com/services/azure-service-bus-integration/ Reliable async messaging architectures using Azure Service Bus: decoupled services, dead-letter handling, idempotent consumers, full observability. Part of API & Integration Services. ### Messaging Patterns & Event-Driven Design https://talkthinkdo.com/services/messaging-patterns/ Event-driven messaging architectures on Azure: pub/sub, queuing, and event streaming using Service Bus, Event Grid, and Event Hubs. Pattern selection, message schema design, observability, and dead-letter handling. Part of API & Integration Services. ### Accelerators https://talkthinkdo.com/accelerators/ Pre-built, AI-first modules developed and refined in-house. Built with AI-augmented engineering, featuring AI-powered search, document indexing, a configurable rules engine, and AI-powered onboarding that converts T&Cs into live business rules in hours. Designed for enterprise AI integration via MCP (Model Context Protocol), so your organisation's AI tools can consume accelerator capabilities directly rather than operating as isolated islands. Enterprise-grade on Microsoft Azure. WCAG AA accessible, best-practice UX, and easily branded using AI-assisted tooling. 1. **Booking Engine**: Real-time scheduling, capacity management, waitlists, credit-based bookings, API-first policy enforcement for membership organisations and multi-site operators. 2. **Billing Engine**: End-to-end recurring billing with Direct Debit, refunds, analytics, and full auditability for membership organisations. 3. **Membership**: Full membership lifecycle management with flexible packages, multi-site pricing bands, scheduled price changes, credit-based rewards, and atomic lifecycle operations. 4. **Franchising**: Franchisor/franchisee/site hierarchy, multi-level permissions, MSF and royalty calculation from operational data, network dashboards, and compliance tracking for franchise networks of any vertical. 5. **Assessment**: Learnosity-powered assessment platform with custom branding and question templates, deeply integrated with students, cohorts, publishing workflows, and audit trails. 6. **Learning**: Cloud-native learning foundation on the xAPI and cmi5 standards; modular content delivery, adaptive pathways, and detailed learning analytics with full interoperability. Cross-cutting capabilities built into every module: full audit trails with field-level detail and event-sourced financial history; data protection with field-level permissions enforced in the API, encrypted payment details, and UK/EU Azure hosting; a single scoped roles-and-permissions model resolved hierarchically and enforced at the API layer; and internationalisation with build-enforced translation parity, multi-currency, and per-jurisdiction tax handling. All accelerators are flexible and customisable, tailored to specific needs. Clients receive a perpetual source code licence with full ownership of all project-specific code. Ongoing support from Talk Think Do is available but not required: you can self-support with your own team. No lock-in. ### Custom Platform https://talkthinkdo.com/accelerators/platform/ A custom platform built from any combination of the accelerator modules: booking, billing, membership, franchising, assessment, and learning. One connected system with a shared data layer, for multi-site operators, membership organisations, franchise networks, education publishers, and training providers. Key proposition: - **No per-user or per-site licence fees**: Perpetual source code licence. Cost stays flat as the organisation grows from 5 locations to 50. - **Completely customisable**: Adapts to each organisation's workflows. Extend, brand, and integrate with existing systems. - **AI-first**: AI-powered onboarding extracts business rules from contracts and T&Cs. Configurable rules engine for policy changes without code. Enterprise AI integration via MCP. - **You control the risk**: Full source code ownership. Self-support or use Talk Think Do. No vendor lock-in. - **Data migration expertise**: Deep experience migrating member data, billing history, booking configurations, and operational data from legacy platforms. - **Modern Azure stack**: .NET, AKS, Azure SQL, Redis, Azure OpenAI. ISO 27001 certified, Cyber Essentials Plus certified. The platform is composed from six modules (deploy any combination): 1. **Booking Engine** (https://talkthinkdo.com/accelerators/booking-engine/): Real-time scheduling, capacity management, waitlists, credit-based bookings. 2. **Billing Engine** (https://talkthinkdo.com/accelerators/billing-engine/): Recurring Direct Debit, refunds, analytics, full auditability. 3. **Membership** (https://talkthinkdo.com/accelerators/membership/): Flexible packages, multi-site pricing, scheduled price changes, credit-based rewards, atomic lifecycle operations. 4. **Franchising** (https://talkthinkdo.com/accelerators/franchising/): Franchise hierarchy, multi-level permissions, MSF calculation, network dashboards, compliance tracking. 5. **Assessment**: Learnosity-powered assessment under your brand, with custom question templates, students and cohorts, publishing workflows, and audit trails. 6. **Learning**: Cloud-native learning foundation on the xAPI and cmi5 standards, with modular content delivery, adaptive pathways, and learning analytics. ### Booking Engine Accelerator https://talkthinkdo.com/accelerators/booking-engine/ AI-first booking engine for membership organisations and multi-site operators. Real-time scheduling, capacity management, intelligent waitlists, and credit-based bookings on Microsoft Azure. Capabilities: - **Structured session management**: Create sessions once with recurrence rules; per-occurrence capacity, duration, facilitator, and live booking counters; colour-coded availability bars. - **Bookable services and categories**: Services organised into categories (e.g. Classes, Consultations, Workshops) with defaults for duration, capacity, age restrictions, and credit costs. - **Flexible booking policies**: Advance booking windows, minimum notice periods, cancellation windows, and no-show rules. Attached at service level, enforced at the API layer. - **Facilitator availability**: Per-service, per-site instructor availability with date-range bounds and direct session assignment. - **Intelligent waitlist**: Configurable queue size, auto-promotion with time-limited offers, real-time WaitingCount, email/SMS notifications. - **Enterprise AI integration**: Designed for integration via MCP (Model Context Protocol). AI tools can query availability and act on booking data directly. Key differentiators: real-time booking counters (no stale data), credit-based premium bookings native to the engine, API-first policy enforcement across all channels, enterprise AI-ready via MCP, WCAG AA accessible, easily branded with AI-assisted tooling. AI-first: built with AI-augmented engineering (80-90% faster delivery), AI-powered search and document indexing, onboarding extracts booking policies from T&Cs, configurable rules engine for policy changes without code. Licensing: perpetual source code licence. Full ownership of project-specific code; perpetual licence to accelerator components. Ongoing support optional, no lock-in. Architecture: .NET, Azure (AKS, Azure SQL, Redis, Azure OpenAI), Clean Architecture with CQRS, single-transaction consistency, full audit trail. Capability pages (feature-level detail for evaluators): - [Waitlists](https://talkthinkdo.com/accelerators/booking-engine/waitlists/) - Waitlist joins happen atomically in the same serialised transaction as the failed capacity check, with explicit queue positions, per-service maximum queue sizes, a per-session waitlist toggle, live waiting counts per occurrence, and duplicate prevention. Waitlisted is a first-class booking status alongside confirmed, cancelled, and no-show. - [Checkout Reservations](https://talkthinkdo.com/accelerators/booking-engine/checkout-reservations/) - Starting checkout writes a time-boxed hold (15 minutes by default, configurable) that counts against capacity while unexpired. Expired holds stop counting immediately (lazy expiry, no background job needed for correctness). Confirmation promotes unexpired holds atomically, refuses expired ones explicitly, and is idempotent for webhook replays. - [Capacity and Overbooking](https://talkthinkdo.com/accelerators/booking-engine/capacity-and-overbooking/) - Capacity lives on each session occurrence with live booked, waiting, and attended counters, separate trial and make-up sub-capacities, and an explicit per-occurrence overbooking allowance. Checks and writes are serialised per occurrence so the last place cannot be sold twice. - [Term Scheduling](https://talkthinkdo.com/accelerators/booking-engine/term-scheduling/) - Terms carry a type, school year, and season; each site attaches its own dates and skip dates, so closures generate no occurrences. Every delivery date is its own occurrence, and timetables clone from term to term. - [Composite Courses](https://talkthinkdo.com/accelerators/booking-engine/composite-courses/) - Multi-part classes modelled as a parent session with labelled, ordered component sessions that inherit the parent's timetable. One enrolment on the parent covers every component, managed through dedicated API operations. - [Attendance Registers](https://talkthinkdo.com/accelerators/booking-engine/attendance-registers/) - Attendance is recorded on the same records that hold the booking: registers read and written per occurrence through a dedicated API, marks of present, absent, late, and excused mapped onto the booking status lifecycle, live attended counts per occurrence, and insights computing attendance counts, consecutive-absence streaks, and last-attended dates per student. - [Facilitator Availability](https://talkthinkdo.com/accelerators/booking-engine/facilitator-availability/) - Facilitator availability declared per service and site with optional date ranges, weekly working-hour patterns, session assignments with date-bounded cover levels, and per-occurrence staffing records with roles, so both the staffing plan and the delivery record are data. ### Billing Engine Accelerator https://talkthinkdo.com/accelerators/billing-engine/ AI-first billing engine for membership organisations and multi-site operators. End-to-end recurring billing with Direct Debit, refunds, analytics, and full auditability on Microsoft Azure. Capabilities: - **Recurring payment infrastructure**: Payment runs with provider-specific configuration, mandate management, bank holiday awareness, multi-site DD schemes per location. - **Billing analytics dashboard**: Previous month vs current month, batch drill-downs with member breakdowns (new joiners, cancellations, changes), month-over-month trend indicators, multi-site filtering. - **Finance items and discounts**: SKU catalogue with joining fees, recurring charges, pro-rata adjustments, ad hoc charges. Discounts with percentage/monetary/monetary-target types and billing cycle expiry. - **Member-level payment management**: Full transaction history, summary cards (total paid, outstanding, next payment), invoices and receipts accessible per transaction. - **Refunds and write-offs**: Full and partial refunds with validation. Write-offs with mandatory reasons and audit trail. - **Lifecycle billing consistency**: Signup, freeze, unfreeze, plan change, and cancellation all flow through a single shared billing orchestration layer with single SQL transaction commits. - **Enterprise AI integration**: Designed for integration via MCP (Model Context Protocol). AI tools can query billing data, surface insights, and trigger actions directly. Key differentiators: one billing engine from the ground up (not patched integrations), full auditability, operator-controlled DD configuration per site, enterprise AI-ready via MCP, WCAG AA accessible, easily branded with AI-assisted tooling. AI-first: built with AI-augmented engineering, AI onboarding extracts billing rules from contracts, configurable rules engine for pricing and eligibility changes without code. Licensing: perpetual source code licence. Full ownership of project-specific code; perpetual licence to accelerator components. Ongoing support optional, no lock-in. Architecture: .NET, Azure (AKS, Azure SQL, Redis, Azure OpenAI), Clean Architecture with CQRS, single-transaction consistency, idempotent operations, full audit trail. Capability pages (feature-level detail for evaluators): - [Payment Runs and Batches](https://talkthinkdo.com/accelerators/billing-engine/payment-runs-and-batches/) - Payment runs define per-site collection schedules with Direct Debit notice arithmetic: mandate notice days, payment request lead days, weekend inclusion, and bank-holiday adjustment. The next and subsequent batches are calculated automatically and kept current as memberships change, and each can be compared with the last batch, with joiners, leavers, freezes, and plan changes broken out, so finance explains the movement before the money moves. Charges generate from live membership, freeze, and plan-change data into request batches per run and per site, marked ready only on final commit. - [Direct Debit Mandates](https://talkthinkdo.com/accelerators/billing-engine/direct-debit-mandates/) - The full Bacs cycle. Mandates capture the payer's details, bank details, agreed amount, collection day, and originator codes, with a dedicated encrypted field for sensitive data, and run a six-state lifecycle with event history. Instructions are lodged via AUDDIS, advance notice is counted in working days, collections are submitted automatically, and ARUDD returns and ADDACS amendments are processed as data into mandate events and payment status. Each batch computes two cut-offs (new mandates and amount changes), weekend and bank-holiday aware, so collections run as late as the scheme safely allows: joiners collect a cycle sooner and changes take effect a cycle earlier. - [Refunds and Write-Offs](https://talkthinkdo.com/accelerators/billing-engine/refunds-and-write-offs/) - Refunds are validated against the payment's refundable balance (full or partial), require a reason, and commit in an audited transaction with type, method, and status tracking. Write-offs are allowed only from states that can still owe, cancel the charge, zero the remaining amount, and record a void event. ### Membership Accelerator https://talkthinkdo.com/accelerators/membership/ AI-first membership management for multi-site operators and membership organisations. Flexible packages, multi-site pricing, scheduled price changes, credit-based rewards, and atomic lifecycle operations on Microsoft Azure. Capabilities: - **Flexible membership packages**: Primary plans and add-ons with configurable billing intervals (weekly, monthly, annual, custom) and credit rules per package. - **Site-specific pricing bands**: Different pricing per site or groups of sites. Staff see pricing by band with collapsible site lists. Default pricing row for unlisted sites. - **Price editing**: Immediate band-wide edits using fee matching, or future-dated scheduled changes per site. Grouped visual management with one-click cancel. - **Member lifecycle actions**: Freeze, unfreeze, upgrade, downgrade, cancel, and payment method updates. All flow through shared billing orchestration with consistent pro-rata calculations. - **Member onboarding**: Full onboarding wizard or quick ad-hoc creation. Unique member IDs, contact details, emergency contacts. - **Credit rules and rewards**: Multiple credit rules per package with configurable expiry and per-period caps. Centrally defined credit types reused across packages. - **Enterprise AI integration**: Designed for integration via MCP (Model Context Protocol). AI tools can query member data, surface retention insights, and act on membership events directly. Key differentiators: multi-site multi-tier pricing without engineering effort, scheduled price changes, credits as a first-class concept, every membership event handled atomically, enterprise AI-ready via MCP, WCAG AA accessible, easily branded with AI-assisted tooling. AI-first: built with AI-augmented engineering, AI onboarding converts T&Cs to membership rules, configurable rules engine for eligibility and pricing without code changes. Licensing: perpetual source code licence. Full ownership of project-specific code; perpetual licence to accelerator components. Ongoing support optional, no lock-in. Architecture: .NET, Azure (AKS, Azure SQL, Redis, Azure OpenAI), Clean Architecture with CQRS, atomic lifecycle operations, full audit trail. Capability pages (feature-level detail for evaluators): - [Membership Freezes](https://talkthinkdo.com/accelerators/membership/membership-freezes/) - Freezes are date-bounded records (request date, start date, optional end date) with frozen status derived from the dates. Billing dates inside the window swap the recurring fee for the package's freeze fee, suspend add-ons and discounts, and tag each charge with its freeze. Freezes preview through the identical billing logic before committing. - [Scheduled Price Changes](https://talkthinkdo.com/accelerators/membership/scheduled-price-changes/) - Future-dated changes record new recurring, registration, and freeze fees against a package and optionally a specific site. A job applies due changes to the targeted per-site pricing with audit events. Member-level plan changes schedule with their own effective-from dates and are picked up by billing only once effective. - [Plan Changes and Pro-Rata](https://talkthinkdo.com/accelerators/membership/plan-changes-and-pro-rata/) - Plan changes flow through the same billing orchestration as signup, freezes, and cancellations. Upgrades generate an immediate pro-rata charge (price difference scaled by days remaining in the period) from shared calculation logic; downgrades change the fee going forward; changes can be scheduled with effective-from dates. - [Price Bands](https://talkthinkdo.com/accelerators/membership/price-bands/) - Dynamic bands with no groups to configure: a band is simply the sites currently sharing fees, so pricing a site forms or joins a band automatically. Each package prices each site with registration, recurring, and freeze fees as one row, plus a default row covering unlisted sites. Change a single site or a whole band equally naturally; band-wide updates match on the current fee triple with a per-site audit event, and rises can be scheduled. ### Franchising Module https://talkthinkdo.com/accelerators/franchising/ The franchise layer for franchise networks: adds hierarchy, permissions, MSF, and compliance (hierarchy, permissions, MSF, compliance) on top of the core Booking, Billing, and Membership modules. Operational-first franchise software that replaces both franchise management systems and operational systems with one platform. The market gap: existing franchise management software (Azura, FranConnect) is built around the franchisor's control needs (royalties, compliance, oversight) and treats operational capability as secondary. Generic operational software (booking/billing/membership) does not understand franchising at all. This module does both. Capabilities: - **Franchise hierarchy**: Franchisor/Franchisee/Site ownership chain. Directly operated sites modelled as a special franchisee record. Logical multi-tenancy with shared database and tenant isolation through the ownership chain. - **Multi-level permissions**: Scoped claims at Site, Franchisee, or Franchisor level with hierarchical resolution. Cross-site users get explicit site grants without over-promotion. Franchisor-only capabilities (configuration, aggregated visibility, intervention) are separately controlled. - **MSF and royalty calculation**: Configurable fee structures (percentage, flat, tiered, custom) per franchise agreement. Calculations drawn from the billing engine's operational payment records, not self-reported figures. Automated statement generation with full audit trail. - **Network dashboard and benchmarking**: Rolled-up KPIs across all franchisees, drillable to individual site. Anonymous or named performance benchmarking. Inherits the billing analytics engine's month-over-month comparisons, batch drill-downs, and multi-site filtering. - **Compliance tracking**: Document store with configurable expiry alerts. Franchisor-level network-wide compliance view with traffic-light indicators. - **Franchisor intervention and audit**: Explicit mode switch when a franchisor operates inside a franchisee's space. Every action recorded with actor identity, scope, and a franchisor intervention flag. Franchisees can filter their audit log to see when and what head office touched. - **Enterprise AI integration**: Franchise network data exposed via MCP (Model Context Protocol). AI tools can query network performance, franchisee data, and compliance status directly. Key differentiators: operational source of truth (MSF from actual payments, not self-reported), one platform replacing both franchise management and operational systems, permissions enforced at API layer (architectural, not configurable), built for franchisees too (best-of-breed operations), WCAG AA accessible, easily branded with AI-assisted tooling. Licensing: perpetual source code licence. Full ownership of project-specific code; perpetual licence to accelerator components. Ongoing support optional, no lock-in. Architecture: .NET, Azure (AKS, Azure SQL, Redis, Azure OpenAI), Clean Architecture with CQRS, claims-based authorization with hierarchical resolution, full audit trail. Capability pages (feature-level detail for evaluators): - [Franchise Hierarchy](https://talkthinkdo.com/accelerators/franchising/franchise-hierarchy/) - Franchisor, franchisee, and territory as distinct entities with sites beneath. Directly-operated sites are franchisee records flagged as such; master franchises own child franchisees with a scope guard granting access to direct children; territories carry country, currency, and geographic boundaries with dated ownership history. Every charge, payment, and refund records its franchisee and territory at creation, derived from the site. - [Scoped Permissions](https://talkthinkdo.com/accelerators/franchising/scoped-permissions/) - Permissions are the product of business modules and actions, each pair enforced as an API authorisation policy. Role grants bind to a network, franchisee, territory, or site scope with head-office and franchisee tiers; sensitive fields are masked in the handlers for roles without the specific permission (masked, not blanked); sign-in federates to Microsoft Entra ID or Google for SSO and policy-compliant MFA; a single translatable catalogue keeps permission meanings in sync, enforced by tests. - [Stripe Connect for Franchises](https://talkthinkdo.com/accelerators/franchising/stripe-connect-payments/) - A Stripe connected account per franchise, provisioned through Stripe's v2 Accounts API and controlled by the platform, with the account id and onboarding status stored against the franchise. Franchises complete Stripe's hosted onboarding (identity checks and payout bank); card payments and Stripe Subscriptions run as direct charges on each franchise's own connected account, so funds settle to the franchise rather than a central pool; per-franchise gateway credentials are held in Azure Key Vault (only a reference and a masked hint in the database, never the secret value); webhooks are verified with a constant-time signature check and mirrored into local payment and subscription state. ### Field Service Accelerator https://talkthinkdo.com/accelerators/field-service/ An offline-first field service capability for franchise networks and van-based operators, assembled from proven accelerator modules plus a native React Native field app. It is not a single off-the-shelf product: the hardest parts (scheduling that cannot double-book, payments and refunds, a franchise hierarchy with scoped permissions) are production modules, and the field layer adds a native app designed for working at an address, offline, and getting paid on the spot. Owned outright with a perpetual source code licence, no per-engineer or per-franchisee fees. The proven components: scheduling and serialised capacity from the Booking Engine, payments and refunds from the Billing Engine, and the franchisor/franchisee/site hierarchy with per-territory attribution from the Franchising module. The field layer adds offline-first storage, native camera and card-reader modules, and clean sync so head office and the field agree. Architecture: React Native for iOS and Android, .NET on Azure, ISO 27001, idempotent payments and job completions, and a full audit trail. Capability pages (feature-level detail for evaluators): - [Job Scheduling and Routing](https://talkthinkdo.com/accelerators/field-service/job-scheduling-and-routing/) - Territory rules scope which jobs an engineer sees, day plans are ordered by drive time with fixed appointment windows as anchors, and reassignment syncs to both engineers. Allocation runs under a per-job lock using the Booking Engine's serialised capacity design, so two engineers cannot own the same job; offline accepts reconcile to a single owner on reconnect. - [Quotes and Doorstep Payments](https://talkthinkdo.com/accelerators/field-service/quotes-and-doorstep-payments/) - A guided quote wizard produces a consistent price on site, approval and terms are captured in the same flow, and card-present or online payment settles through the Billing Engine with invoices and receipts. Deposits and balances use the Billing Engine's charge and instalment handling; every payment carries an idempotency key, so a payment that succeeds while sync fails is never lost or taken twice. - [Job Evidence and Compliance](https://talkthinkdo.com/accelerators/field-service/job-evidence-and-compliance/) - Before-and-after photos, signatures, and health and safety or disclaimer forms captured against the job, timestamped and attributed on an append-only audit trail. Compliance documents (certificates, insurance, qualifications) use the Franchising module's store with configurable expiry alerts. Evidence captured offline uploads in the background on reconnect. - [Offline Sync](https://talkthinkdo.com/accelerators/field-service/offline-sync/) - The engineering behind offline-first: an on-device store read and written first, a durable queue-and-forward of each action, idempotent sync so nothing applies twice, and per-field conflict resolution rather than a blanket last-write-wins. Covers the field edge cases in depth: two engineers accepting the same job offline, a payment that succeeds while sync fails, conflicting edits, clock skew, a centrally cancelled job worked offline, and a reinstalled device mid-queue. ### Platform Cross-Cutting Capabilities Built into every module rather than per-module add-ons. Capability pages (feature-level detail for evaluators): - [Audit and Accountability](https://talkthinkdo.com/accelerators/platform/audit-and-accountability/) - Every entity carries creation and modification audit events (who, when); charges, payments, refunds, and mandates keep event-sourced histories so financial state transitions are preserved with codes and reasons; deletion is soft and traceable; head-office actions inside a franchisee's site are explicitly flagged and visible to both sides. - [Data Protection](https://talkthinkdo.com/accelerators/platform/data-protection/) - Field-level masking enforced in the API handlers for roles without the specific permission, returning an explicit mask rather than a blank. Sensitive payment data in dedicated encrypted fields, secrets in a managed key vault, soft traceable deletion, UK and EU Azure hosting. Organisation is ISO 27001 certified and Cyber Essentials Plus certified. Sign-in federates to Microsoft Entra ID or Google. - [Data Classification](https://talkthinkdo.com/accelerators/platform/data-classification/) - Every sensitive field carries a sensitivity tier (public, internal, confidential, restricted) and handling overlays (special-category, children's, financial, secret, free text) in both the code and the database. Columns get native SQL sensitivity labels; stored documents get blob index tags. A bidirectional coverage test runs on every push and fails the build if a classified column lacks its code attribute or an attribute lacks its database label, so the scheme cannot drift. Machine-readable classification is what drives redaction, non-production obfuscation, and retention from one label rather than per-table code. - [Retention and Erasure](https://talkthinkdo.com/accelerators/platform/retention-and-erasure/) - Storage limitation as an engine. Retention rules are configuration, keyed per data class and jurisdiction with no silent fallback, each naming a period and an action of anonymise or delete. A scheduled job evaluates records against their rules and acts, defaulting to a dry run in non-production, and logs every evaluation even when nothing is purged. Anonymisation overwrites personal fields while keeping non-personal reporting columns and reaches soft-deleted rows; legal holds override the schedule; and a build-time test asserts every table holding personal data is covered by a rule or an explicit documented exemption. - [Roles and Permissions](https://talkthinkdo.com/accelerators/platform/roles-and-permissions/) - One permission model across every module: business areas multiplied by actions, each pair an API authorisation policy; roles scoped from organisation to site with automatic hierarchical resolution; approval as its own action; a translatable catalogue enforced by tests; SSO via Entra ID or Google with MFA and conditional access governed by the customer's identity platform. - [Internationalisation](https://talkthinkdo.com/accelerators/platform/internationalisation/) - Every user-facing string in per-language translation catalogues with build-enforced parity (a missing translation fails the build); monetary amounts carry their currency; tax modelled per jurisdiction with effective-dated rates; times stored in UTC, displayed locally, with working-day arithmetic and bank-holiday calendars. - [HubSpot CRM Integration](https://talkthinkdo.com/accelerators/platform/hubspot-crm-integration/) - Contacts created or updated in HubSpot keyed on email address, carrying names, phone, and custom properties, and added to nominated lists (single or batch). Transactional email sent through HubSpot's template-only Single-Send API, either from a HubSpot template or with platform-rendered content, locale-aware, and dispatched outside the sign-up transaction so a provider hiccup never rolls back a join. HubSpot is resolved by name behind a provider-agnostic port, so the provider can be swapped or run alongside another. Private-app access token held in a managed key vault, email addresses redacted from logs, and marketing consent captured at sign-up. ### Accelerator Pricing and Licensing https://talkthinkdo.com/accelerators/pricing/ The commercial model for the custom platform (any combination of the accelerator modules). A one-off perpetual source code licence and project fee, not a per-member subscription. Pricing is tailored to each organisation during consultation based on number of sites, integrations, data migration scope, and specific requirements. No per-user or per-member fees. No per-site fees. Cost stays predictable as the organisation grows. Custom member app (optional): a custom-built customer-facing app covering membership management and bookings, designed to the client's brand and UX requirements, scoped during consultation. Ongoing support (optional): managed Azure hosting (infrastructure, monitoring, backups, security patching) and helpdesk support (maintenance, configuration changes, operational queries), available as a single predictable monthly retainer. Licence fees can be scheduled over a longer period to align with budget cycles. Support is optional; clients can self-support with their own team. No lock-in. Every project includes: perpetual source code licence, configuration and branding, data migration, system integration via API, staff training, go-live support, and full documentation. ### Legacy Application Support https://talkthinkdo.com/services/managed-support/legacy-application-support/ Topic cluster under Managed Application Support. SLA-backed managed support for legacy .NET, SQL Server, and on-premise applications in the UK. We keep legacy systems stable, secure, and compliant without requiring a rebuild, so business-critical software keeps running while you plan modernisation on the right timeline. Capabilities: security patching and dependency updates, SLA-backed bug fixes and incident response, performance monitoring with Application Insights and Azure Monitor, reverse-engineering and runbook creation for systems where original developers have left, tiered SLAs from business hours to 24/7, and compliance evidence for Cyber Essentials, ISO 27001, and internal audit. When to choose support rather than modernisation: the application is stable and bounded, budget or timing is not right for a rebuild this year, business logic is unlikely to change significantly, or you need breathing room to plan the right modernisation strategy. The same UK team can transition you into a [legacy application modernisation](https://talkthinkdo.com/services/legacy-application-modernisation/) programme later without a second discovery phase. ### Vibe Coding Rescue https://talkthinkdo.com/services/managed-support/vibe-coding-rescue/ Topic cluster under Managed Application Support. Stabilise and support AI-built applications. Your AI-built app works but can't scale, isn't secure, and nobody can maintain it. We assess, stabilise, and provide ongoing professional support for software built with Replit, Lovable, v0, Bolt.new, Cursor, and other AI coding tools. Capabilities: codebase assessment, security hardening, architecture restructuring, test coverage, CI/CD setup, ongoing managed support under SLA. ### Maintainability Review https://talkthinkdo.com/services/managed-support/maintainability-review/ Topic cluster under Managed Application Support. Independent technical assessment of software codebases for acquisition, investment, or vendor review. Get an honest evaluation of code quality, architecture, security, and long-term viability. Scenarios: pre-acquisition due diligence, vendor assessment, internal health check. Review covers architecture, code quality, security, infrastructure, testing, and documentation. ### Internal Systems Handover https://talkthinkdo.com/services/managed-support/internal-systems-handover/ Topic cluster under Managed Application Support. Smooth handover of internal software systems from in-house teams. Knowledge transfer, transition support, and ongoing managed support when your key developer leaves, your team is stretched, or you're winding down an internal team. Capabilities: structured knowledge capture, documentation, monitoring setup, CI/CD validation, ongoing SLA-backed support. ## Pricing Summary Every project is tailored, so prices vary based on scope, scale, and timelines. AI-augmented delivery means faster timelines, higher quality, and better outcomes. | Service | Starting Price | Typical Duration | |---------|---------------|-----------------| | Custom Software Development | £25,000 to £100,000+ | 6 weeks to 6 months+ | | DevOps Implementation and Migration | £5,000+ | From 4 weeks | | Custom Generative AI | £19,000+ | From 4 weeks | | Managed Application Support | £1,590/month | Ongoing | Payment terms: typically 50% at initiation, 40% at product acceptance, 10% upon completion of hypercare. Flexible. Free 30-minute consultation: https://talkthinkdo.com/book-a-consultation/ ## Case Studies ### Third Space: Building Atlas https://talkthinkdo.com/case-studies/third-space-atlas/ Complete rebuild of a luxury gym chain's digital ecosystem on Azure, delivering 99.99% uptime. ### Third Space: Strategic Technology Leadership https://talkthinkdo.com/case-studies/third-space-strategy/ Interim CIO leadership and programme governance for a growing luxury health club network. ### Explore Learning: Digital Transformation https://talkthinkdo.com/case-studies/explore-learning/ Custom assessment authoring system on Learnosity and Azure for 60,000+ questions at scale. ### Explore Learning: Compass Platform https://talkthinkdo.com/case-studies/explore-learning-assessment/ Compass is Explore Learning's cloud-native adaptive learning platform. Talk Think Do built its adaptive logic engine and integrated that engine with Learnosity, which delivers the assessments. Children master two skills every 30 minutes on average. ### Explore Learning: Video Platform https://talkthinkdo.com/case-studies/explore-learning-video/ Custom video and screen sharing platform supporting 3,000 concurrent students, UK Business Tech Award winner. ### Explore Learning: Business Tech Award https://talkthinkdo.com/case-studies/explore-learning-compass/ Azure cloud-native transformation enabling online tutoring through the pandemic, UK Business Tech Award winner. ### Hachette Learning: Boost Insights https://talkthinkdo.com/case-studies/hachette-learning/ Cloud-native assessment platform serving 4,000+ schools and 845,000+ pupils. ### Department for Education https://talkthinkdo.com/case-studies/department-for-education/ Helped the DfE modernise IT systems and adopt cloud-native architecture. ### CalMac Ferries https://talkthinkdo.com/case-studies/calmac-ferries/ Responsive application support, technical assurance, and integration enhancements for CalMac Ferries (Caledonian MacBrayne), the UK's largest ferry network. CalMac runs the Clyde and Hebrides ferry services across Scotland's west coast, with 160,000+ sailings and 5 million passengers annually. ### Avios https://talkthinkdo.com/case-studies/avios/ Serverless mobile backend for the IAG customer loyalty platform powering British Airways and partner airlines. ### FundingImpact.AI https://talkthinkdo.com/case-studies/funding-impact-ai/ AI-powered platform using Azure OpenAI to help charities and funders make evidence-based decisions. ### Livestock Information Services https://talkthinkdo.com/case-studies/livestock-information/ Supporting LUIS, the UK's mission-critical livestock identification system managing 25 million+ tags. ## How We Work 1. **Understand**: Clarify needs and scope. 2. **Assemble**: Build the right team of engineers, architects, and managers. 3. **Deliver**: Build the solution with regular updates. 4. **Support**: Ongoing support that flexes with your needs. Senior involvement in every engagement. Leadership is hands-on. AI-augmented delivery with quarterly evaluation and adoption of AI tools. Pre-built accelerators for a head start. ISO 27001 certified, Microsoft Solutions Partner. Long-term partnership with ongoing support after launch. ## Reports ### The AI Velocity Report https://talkthinkdo.com/ai-velocity-report/ Quarterly transparency report on AI adoption in production software delivery. Published within 4 weeks of each quarter ending. Covers the AI tools Talk Think Do uses, tools evaluated and dropped, measurable delivery metrics, and client impact. No competitor publishes equivalent data. The report exists to demonstrate the rigour behind Talk Think Do's AI-augmented delivery claims with named tools, specific metrics, and honest assessments of what did not work. Published editions: - [Q2 2026](https://talkthinkdo.com/ai-velocity-report/q2-2026/) - 91.6% AI-authored code, 100% senior-engineer reviewed, across live production work, up from a deliberate 83% plateau. Recent proposals at 28-34% of pre-AI build cost, a four-stage estimation model, and the move from Cursor to Claude Code. - [Q1 2026](https://talkthinkdo.com/ai-velocity-report/q1-2026/) - 84% AI-authored code (up from 51%), 40-50% faster delivery measured as repeatable across every active project, 6 MCP integrations live in production workflows. - [Q4 2025](https://talkthinkdo.com/ai-velocity-report/q4-2025/) - 51% AI-authored code, engineers shift to prompt-first working, dropped all vibe coding tools, adopted OpenSpec for spec-driven development. ## Guides Practical reference guides for teams that build, buy, and run software. Updated regularly, built to last. ### Data Protection by Design: The Standard Features Every Compliant System Needs https://talkthinkdo.com/guides/development-practice/data-protection-by-design-software/ Pillar guide that translates the seven UK GDPR Article 5 principles into the standard software features every compliant system needs, and maps each principle to a concrete control. Covers data classification, deny-by-default and server-side access control, field-level masking, encryption and key-vault secrets, an immutable audit trail, consent and suppression, data-subject-rights tooling, retention and erasure, non-production data minimisation, and breach-notification support. Argues that designing in beats bolting on, shows how the controls map to ISO 27001 and Cyber Essentials, and links to the deep-dive spokes. ### Data Classification: How to Implement It Technically https://talkthinkdo.com/guides/development-practice/data-classification-implementation/ How to implement data classification so it is machine-readable, enforced, and drives real controls. Covers a two-dimensional scheme of sensitivity tiers plus handling overlays with a highest-tier-wins rule; expressing one taxonomy as database metadata, a code attribute, and a documented inventory held in lockstep by a build-breaking bidirectional coverage test; native SQL Server and Azure SQL sensitivity labels, overlays as extended properties, blob index tags, and idempotent deploy wiring; and the controls classification unlocks (field masking, non-production obfuscation, retention, and blob discovery). Includes a warning against over-classification and how to model a deliberate category downgrade as revocable consent. ### Data Subject Rights, Retention and Erasure: The Engineering https://talkthinkdo.com/guides/development-practice/data-subject-rights-retention-erasure/ Building the data subject rights as software features with statutory deadlines. Covers a permission-gated, classification-driven export for access and portability; authorised editing with audit for rectification; and the hard part, erasure that removes personal data without destroying accountability. Explains the three states of removal (soft delete, anonymisation, and erasure), crypto-shredding for data that cannot be physically deleted such as immutable audit records and backups, and a fail-safe posture. Sets out a retention engine with rules per data class and jurisdiction, scheduled anonymise or delete, logged evaluations, legal holds, and build-enforced coverage. ### Beyond the UK: Extending GDPR-Grade Data Protection Across Countries https://talkthinkdo.com/guides/legal-and-contracts/gdpr-multi-jurisdiction-data-residency/ Extending a UK GDPR baseline across jurisdictions. Explains that GDPR restricts transfers rather than mandating localisation, why the core controls travel, and what actually changes across borders: data residency, breach-notification routing, consent and localisation rules, and governance obligations such as appointing a representative. Covers data residency as deployment topology (separate regional stamps with geo-replication forbidden), jurisdiction as a first-class attribute, the sub-processor residency trap, and a tour of the regimes a UK business meets first: EU member states with national implementing laws, Gibraltar, Australia's reformed Privacy Act, and Canada with Quebec's Law 25. Framed as orientation, not legal advice. ### AI Code Attribution for Enterprise Procurement https://talkthinkdo.com/guides/ai-and-code/ai-code-attribution-enterprise-procurement/ Practical framework for tracking, attributing, and documenting AI-generated code in enterprise software delivery. Covers commit conventions, CI/CD enforcement (licence scanning gates, PR template validation), model version logging, SBOM integration with CycloneDX and SPDX, and what procurement teams should require from suppliers. Includes contract clause templates, vendor questionnaire additions, and sector-specific guidance for financial services, government, and education. ### REST vs GraphQL vs gRPC: Choosing the Right API Style https://talkthinkdo.com/guides/api-and-integration/rest-vs-graphql-vs-grpc-choosing-api-style/ Enterprise comparison of REST, GraphQL, and gRPC. Covers where each style excels (public APIs, data-rich front ends, internal microservices), protocol trade-offs, Azure hosting and APIM support for each, hiring realities, and a decision matrix. Explains the common enterprise pattern of mixing styles and how Azure API Management fronts all three behind a unified gateway. ### Backend for Frontend (BFF) Pattern https://talkthinkdo.com/guides/api-and-integration/backend-for-frontend-bff-pattern/ When and how to use the BFF pattern for mobile, web, and admin clients. Compares BFF to single-API and API gateway approaches. Covers Azure implementation (APIM routing, App Service/Container Apps, per-client auth with PKCE, session cookies, and Entra ID RBAC), data aggregation patterns, caching strategies per client type, and when GraphQL is a better alternative to multiple BFF services. ### Mobile API Best Practices https://talkthinkdo.com/guides/api-and-integration/mobile-api-best-practices/ How to design, secure, and operate APIs for mobile apps on Azure. Covers protocol choice (REST default, when to evaluate GraphQL), OAuth 2.0 with PKCE authentication, secure token storage (iOS Keychain, Android Keystore), offline-first patterns (idempotency keys, delta sync, optimistic updates), push notification architecture with Azure Notification Hubs, payload optimisation, cursor-based pagination, versioning for apps you cannot force-update, and the full Azure mobile backend stack. ### API Versioning Strategies https://talkthinkdo.com/guides/api-and-integration/api-versioning-strategies/ URL path, header, and query parameter versioning compared with advantages and disadvantages of each. Defines breaking vs non-breaking changes with a full taxonomy. Covers running multiple versions in parallel (code organisation, testing), a four-step deprecation workflow (announce, headers, monitor, sunset), Azure APIM native versioning and revision support, and a versioning policy template for enterprise teams. ### Build vs Buy: How AI-Augmented Development Changes the Equation https://talkthinkdo.com/guides/build-buy-or-replace/build-vs-buy-ai-augmented-development/ The traditional build-vs-buy framework assumed custom software was slow and expensive. AI-augmented delivery changes the cost, speed, and risk calculation. Covers the five decision dimensions (uniqueness, integration, timeline, total cost of ownership, strategic value), how AI-augmented development compresses the custom build timeline by 40-50%, when SaaS is still the right answer, and a practical scoring framework for CTOs and product leaders. Links to custom software development and pricing. ### Franchise Management vs Franchise Operations Software https://talkthinkdo.com/guides/build-buy-or-replace/franchise-management-vs-operations-software/ Why franchise networks end up running two systems. Franchise management platforms are strong at royalties, management service fees (MSF), compliance, field audits, and head-office reporting, but treat the unit's customer-facing transactional workflows (booking, recurring billing, payments, member management) as an afterthought. Operational platforms have no concept of franchisor, franchisee, territory, or MSF. Networks buy one of each and reconcile by hand, which becomes a permanent operating cost that grows with the network. A unified platform calculates MSF and royalties from the operating system's actual payment records rather than self-reported figures, so the franchisor and franchisee see the same numbers and there is nothing to reconcile. Includes a three-way comparison (management-first, operations-first, unified) and a capability checklist. Links to the Franchising accelerator and custom software development. ### How to Choose Franchise Software: Buyer's Guide and RFP Checklist https://talkthinkdo.com/guides/build-buy-or-replace/how-to-choose-franchise-software/ A buyer's guide for multi-site franchise operators. Eight evaluation criteria: operational depth, franchise layer, data as a single source of truth, permissions and data isolation, compliance tracking, reporting and benchmarking, security and integration, and commercial model and data ownership. Includes an RFP checklist that can be lifted into a tender, with items vendors must demonstrate rather than describe (pro-rata billing, MSF statements drawn from actual payments, the franchisee data-isolation boundary). Sets out a five-phase evaluation process: requirements, longlist and RFP, scenario demos, references and due diligence, and proof of concept. Links to the franchise management vs operations guide and the Franchising accelerator. ### Own vs Rent: Perpetual Licence versus Per-Member SaaS https://talkthinkdo.com/guides/build-buy-or-replace/own-vs-rent-software-perpetual-licence-vs-saas/ A total-cost-of-ownership guide for multi-site and membership operators. Per-member and per-site SaaS fees scale with the network, so a tool that is affordable at five sites becomes a major cost at fifty; an owned platform with a perpetual licence has a higher entry cost but stays flat as the network grows, so cost per member falls rather than rises. Covers when renting is the right answer (small, stable scale, commodity tool), when owning wins (growth, unusual or strategic requirements), how to compare three-to-five-year TCO including a doubling-membership stress test and hidden costs, and why owning no longer means building from scratch (accelerator modules plus AI-augmented delivery). No specific figures; links to the accelerator pricing and licensing page for current ranges. ### What a Franchisee Field App Should Actually Do https://talkthinkdo.com/guides/build-buy-or-replace/franchisee-field-app-requirements/ A requirements guide for franchisors whose franchisees avoid the current system, written for the operations director and readable by the MD. The core argument is that franchisee adoption is the whole game: a system franchisees avoid produces bad management service fee data, and the mobile experience is where adoption is won or lost. Explains why franchisees stop using the system (usually a web CRM in a mobile wrapper built for a desk, not a doorstep: it needs a live connection, it is slow between jobs, and it models the wrong workflow) as a category critique, never a named product. Includes a ten-point capability checklist you can lift straight into a supplier questionnaire (offline-first, route-ordered day plan, quoting at the door, doorstep payment, proof of completion, scoped permissions, a shared source of truth, deep-linked push, fast native interactions, ownership and flat pricing), three signs you have outgrown your setup (franchisee workarounds, data that never reconciles, and cost that climbs with every franchisee), what good looks like, and the growth penalty in per-franchisee pricing. Links to field service app development, the Field Service accelerator, and the franchise platform cost calculator. ### Franchise Software Cost Calculator: Renting vs Owning https://talkthinkdo.com/guides/build-buy-or-replace/franchise-software-cost-calculator/ A free interactive calculator plus supporting guide for franchisor FDs and MDs, modelled on the SaaS payback calculator. Inputs: number of franchisees, per-franchisee monthly fee, annual network growth, one-off onboarding fee per new franchisee, and internal admin hours saved. Outputs: the five-year cost of renting a per-franchisee platform versus owning a bespoke one, the crossover point where owning becomes cheaper, and the growth penalty made explicit (renting cost at today's size, at double the size, and owning cost at any size). The differentiated insight, which the tool leads with, is that per-franchisee pricing punishes the successful franchisor: the more the network grows, the more renting costs and the better owning looks per franchisee, because an owned platform's cost stays broadly flat. Results are instant and ungated, the formulae are shown in full, and every assumption is editable. Category-level economics only, no vendor pricing and no names. Links to the franchisee field app requirements guide, how to choose franchise software, and bespoke franchise platforms. Targets franchise software cost per franchisee, franchise management software pricing, and cost of franchise CRM. ### How Booking Waitlists Should Work https://talkthinkdo.com/guides/development-practice/how-booking-waitlists-should-work/ Design guide for booking waitlists. A waitlist entry should be a first-class booking record with a waitlisted status and an explicit queue position, not a bolt-on list. Joining should happen atomically inside the same serialised transaction as the failed capacity check, so positions never race. Queue sizes should be bounded and configurable per service, waiting counts should be live next to booked counts, and waitlists should be reportable as a demand signal. Compares the three promotion models for when a place frees: automatic booking (fits free or credit-based sessions), time-limited offers (the recommended default for paid bookings, mechanically a time-boxed hold), and manual staff promotion (fits auditioned or safeguarded programmes). Includes a five-part vendor evaluation: race, duplicate, bound, promotion, and visibility tests. Links to the Booking Engine accelerator and the reservation and high-demand guides. ### Reservation and Release in Checkout Flows https://talkthinkdo.com/guides/development-practice/booking-reservation-release-checkout-flows/ How booking systems should hold places while customers pay and release them on abandonment. Models the hold as an explicit record with four states (available, reserved, confirmed, released) and a stored expiry timestamp, typically 15 minutes and configurable. The reserve step checks capacity and writes the hold in one atomic, serialised action, counting confirmed bookings plus unexpired holds. Release works by lazy expiry: availability checks filter out lapsed holds by timestamp, so places free themselves without depending on a background sweep; a scheduled job is housekeeping only, never a correctness mechanism. Confirmation must re-check the hold: promote unexpired holds atomically, refuse expired ones explicitly, and return success idempotently on webhook replays. Includes five vendor demonstration tests. Links to the Booking Engine accelerator, the waitlist guide, and the high-demand guide. ### High-Demand Bookings Without Overselling https://talkthinkdo.com/guides/development-practice/high-demand-bookings-without-overselling/ Why booking systems oversell under contention and how to design against it. The root cause is check-then-book: the capacity check and the booking write as separate steps, racing in the gap. The fix is a single atomic action serialised per bookable item (a per-occurrence row lock acting as a mutex), with nothing slow inside the critical section and database constraints as the final guarantee. Compares pessimistic serialisation with optimistic row-version retries and explains why pessimistic wins for hot items with hard capacity. Covers idempotency for reserve, confirm, and cancel (double-taps, webhook replays, retry storms), atomic waitlist overflow so excess demand is captured rather than bounced, deliberate overbooking allowances as explicit configuration, and waiting rooms at extreme scale. Includes five evaluation tests: last-place, replay, abandonment, blast-radius, and the invariant question. Links to the Booking Engine accelerator and the reservation and waitlist guides. ### How Membership Freezes Should Work https://talkthinkdo.com/guides/development-practice/how-membership-freezes-should-work/ Design guide for membership freezes as a retention feature. A freeze should be a date-bounded record (request date, start date, optional open end date), with frozen status and every billing consequence derived from the record's dates rather than a hand-set flag. During the freeze window the recurring fee is replaced by a freeze fee through the same billing machinery, add-ons and discounts are suspended, and every charge references the freeze that produced it; billing dates past the end date resume the normal fee automatically. Freeze fees should be configurable per package and per site, captured per member at signup, and changeable on scheduled effective dates. Freezes should be previewed before committing by running the identical billing logic in a non-persisting mode. Includes five demonstration tests for evaluating membership software. Links to the Membership accelerator, the Billing Engine accelerator, and the own-vs-rent guide. ### Choosing a Software Development Partner in the Age of AI https://talkthinkdo.com/guides/teams-and-support/choosing-software-development-partner-ai-era/ How to evaluate software development agencies when AI-augmented delivery is the new baseline. Eight criteria: technical capability, delivery methodology, communication quality, pricing transparency, AI maturity, security posture, cultural fit, and verifiable references. Includes questions to ask during evaluation, red flags to watch for, and how to assess whether an agency's AI claims are backed by evidence (delivery metrics, attribution frameworks, tool governance). ### From MVP to First Enterprise Customer: What Breaks at 10,000 Users https://talkthinkdo.com/guides/development-practice/mvp-to-first-enterprise-customer/ The gap between pilot customers and a first tier-one rollout. Explains why the failures are rarely compute capacity and almost always tenancy and data isolation, bulk operations written for tens of records (import, assignment, notification, scheduled jobs), an administration model with no roles or delegation, missing append-only audit trails, reporting run against the live transactional database, single sign-on retrofits, onboarding that needs an engineer, and support load sized for friendly early users. Includes what usually does not break, migrating the customer's existing data, a four-stage rollout sequence that limits the blast radius, unit economics at scale, load testing against the customer's real numbers, an eight-step sequence from assessment to piloting inside the customer, and a test for which customer-specific requests to build as product features. ### From Prototype to Production: What AI-Built Software Needs to Ship https://talkthinkdo.com/guides/development-practice/prototype-to-production-ai-built-software/ AI tools make prototyping nearly free. The gap between a working demo and production-grade software is where most projects stall. Covers what vibe-coded applications typically lack (error handling, security, testing, deployment automation, monitoring), how to assess whether to refactor or rebuild, the production readiness checklist, and how AI-augmented teams bridge the gap faster. Links to the prototype-to-production and vibe coding rescue services. ### Is Your Organisation Ready for AI? A Practical Readiness Checklist https://talkthinkdo.com/guides/ai-and-code/ai-readiness-checklist-enterprise/ Most AI projects stall before they deliver value. Structured readiness assessment across five dimensions: data (accessibility, quality, governance), people (sponsorship, skills, willingness to change), process (manual steps suitable for AI, workflow integration), infrastructure (Azure readiness, compute, networking), and governance (responsible AI policies, compliance, audit). Includes self-assessment questions for each dimension and a scoring guide. Links to AI development services and AI approach. ### RAG vs Fine-Tuning vs Prompt Engineering: Choosing the Right AI Architecture https://talkthinkdo.com/guides/ai-and-code/rag-vs-fine-tuning-vs-prompt-engineering/ Three approaches to getting your data into AI, each with different costs, timelines, and trade-offs. RAG (retrieval-augmented generation) for connecting AI to your knowledge base without training. Fine-tuning for domain-specific behaviour and style. Prompt engineering for rapid iteration without infrastructure. Covers Azure implementation for each (Azure AI Search, Azure OpenAI fine-tuning endpoints, Azure AI Foundry prompt flow), cost comparisons, hybrid architectures, and a decision framework. Links to AI development and Azure AI Foundry services. ### Harness Engineering for Coding Agents https://talkthinkdo.com/guides/ai-and-code/harness-engineering-coding-agents/ The practitioner guide to harness engineering for AI coding agents on a Microsoft stack. Defines the inner harness (vendor controls in Cursor and Claude Code) versus the outer harness (rules, MCP servers, sensors, generators) and explains how those choices interact when teams switch between Cursor and Claude Code. Maps Birgitta Boeckeler's mental model onto concrete React, TypeScript, .NET 10, and SQL Server recipes: AGENTS.md, CLAUDE.md, Directory.Build.props, custom Roslyn analyzers, ArchUnitNET, Stryker.NET mutation testing, GitHub Advanced Security with CodeQL, EF Core migration validators, SqlPackage schema-diff, and SQLFluff. Covers computational versus inferential controls, the deterministic-tools-over-prose rule, and what a minimum viable outer harness looks like. Cites the Q1 2026 AI Velocity Report (84% AI-authored code, six live custom MCP servers) for evidence, with the Q2 2026 update putting AI-authored code at 91.6% (100% senior-engineer reviewed). Links to the harness templates guide, the AI integration service, the Claude Code development service, the AI velocity report, and the .NET migration guide. ### Harness Templates for AI Coding Agents https://talkthinkdo.com/guides/ai-and-code/harness-templates-model-driven-ai-coding/ Working answer to Birgitta Boeckeler's open question on harness templates. A harness template is a bundle of guides and sensors that leashes a coding agent to a known topology, like a CRUD business service or an event processor. Walks through Codenative, TTD's deterministic model-driven templating tool, which predates AI coding agents and now runs as native Cursor Skills. Covers natural-language to YAML domain-model translation as the bounded non-deterministic step, conflict-free regeneration on model changes, ambient affordances, and Ashby's Law variety reduction. Includes a worked end-to-end example of adding a Booking entity from natural-language intent through generated artefacts, sensors, and a merged PR. Practical playbook for teams without a Codenative-equivalent: elevate existing scaffolders (dotnet new, Yeoman, Plop, T4, Hygen, NSwag, Cookiecutter) into Cursor Skills or MCP tools, add a drift sensor, resist hand-evolving generated regions. Links to the harness engineering hub guide, accelerators, the AI velocity report, and the Claude Code development service. ### Maintainability Sensors for .NET and React https://talkthinkdo.com/guides/ai-and-code/maintainability-sensors-dotnet-react/ The .NET and React companion to the harness engineering guide, focused on the sensor (feedback) half of a coding-agent harness. Defines maintainability sensors and the four points they run at (session, CI, scheduled, production), and the split between computational sensors (deterministic, cheap, every commit) and inferential sensors (model-based, for questions judgement alone can answer). Makes the case that the highest-value sensors are custom, codebase-specific ones built with AI rather than off-the-shelf libraries: bespoke accessibility sensors tuned to the component library and WCAG targets, SQL indexing and performance sensors, end-to-end Playwright tests, and container-based integration tests against real dependencies. For pattern infringements and suggestions and for database schema changes, where a deterministic rule does not fit, an inferential AI sensor flags and suggests and a human signs off (no rules, AI plus manual review), while hard module boundaries stay deterministic via ArchUnitNET and dependency-cruiser. Off-the-shelf tools (type checkers, linters, mutation testing) are the cheap baseline, not where the value is. Covers session sensors (tsc, ESLint, dotnet build, dotnet test, dotnet format), structural sensors for architecture (ArchUnitNET on .NET, dependency-cruiser on React and TypeScript, god-module and coupling analysis), why coverage misleads on AI-written tests and how Stryker.NET mutation testing catches weak assertions, when to use a grounded inferential review, agent-readable sensor output as a positive kind of prompt injection, and how to sequence sensors by cost across session, CI, and schedule. Grounded in Birgitta Boeckeler's 27 May 2026 maintainability sensors article and the Q2 2026 AI Velocity Report (91.6% AI-authored code, 100% senior-engineer reviewed). Links to the harness engineering guide, harness templates guide, Claude Code for .NET developers guide, risks of AI-augmented development guide, and the Claude Code development service. ### Governing the AI Agent Supply Chain https://talkthinkdo.com/guides/ai-and-code/ai-agent-surface-supply-chain-governance/ How to govern the AI coding agent surface (skills, plugins, MCP servers, and subagents) as a software supply chain, because each is executable third-party code running with the agent's access. Explains why a green build is a narrow signal that says nothing about what the agent could reach, and the failure modes of an ungoverned surface (over-permissioned MCP servers, unvetted skills, tool-output prompt injection, stale or unpinned versions). Covers building an agent surface inventory (the agent equivalent of a software bill of materials), applying least privilege to MCP servers (separate read-only from action servers, gate state changes, scoped rotatable credentials, per-call logging), versioning and change review, and threat modelling with MITRE ATLAS. Maps the controls to ISO 27001 asset inventory and access control, the EU AI Act provider and deployer obligations, and Cyber Essentials and procurement reviews. Draws on The Generative Programmer's 29 May 2026 missing quality layer article. Links to the AI code attribution guide, the MCP patterns guide, the EU AI Act guide, the ISO 27001 blog post, and the Claude Code development and AI integration services. ### AI Test Quality: Mutation Testing and Evals https://talkthinkdo.com/guides/ai-and-code/ai-test-quality-mutation-testing-evals/ Why test coverage misleads on AI-written tests and what catches it. Explains that coverage measures whether a line ran, not whether an assertion checked behaviour, and that AI agents readily produce high-coverage suites with weak or missing assertions. Covers mutation testing as the sensor that exposes this (deliberately changing code and checking whether a test fails, surviving mutants as a precise actionable list), Stryker.NET on .NET with incremental post-integration runs and StrykerJS for TypeScript, and semantic evals for correctness that deterministic tests cannot express (generated tests, policy logic, tool-using workflows) using frameworks such as DeepEval and techniques like semantic entropy. Sets out how to combine coverage, mutation testing, and evals into a layered quality gate, and the CTO-level risk of false confidence in AI-generated test suites. Grounded in Birgitta Boeckeler's maintainability sensors article, The Generative Programmer's missing quality layer article, and the Q2 2026 AI Velocity Report. Links to the maintainability sensors guide, the harness engineering guide, and the why we do not let AI ship code unsupervised blog post. ### Scaling Coding Agents Across Large Codebases https://talkthinkdo.com/guides/ai-and-code/scaling-coding-agents-large-codebases/ How to scale AI coding agents across large .NET solutions, monorepos, and legacy systems. Explains that large codebases break naive agent usage through context limits, not model limits, producing excess context loading, missed existing implementations, and inconsistent variations. Covers context management (scoped tasks, per-area AGENTS.md, retrieval over dumping), structuring a solution or monorepo for agents (explicit module boundaries enforced by ArchUnitNET, generators for repetitive shapes, cohesive modules), and refactor risk zones (green, yellow, red) that match autonomy to how well an area is understood, located with behavioural code analysis tools such as CodeScene. Covers keeping agents out of red zones (human pairing, small scoped tasks, rules backed by structural sensors, adding tests before refactoring) and why maintainability is the multiplier that decides how far agents scale. Applies the approach to legacy modernisation. Draws on The Generative Programmer's missing quality layer article and Birgitta Boeckeler's maintainability sensors article, grounded in the Q2 2026 AI Velocity Report (91.6% AI-authored code, 100% senior-engineer reviewed, 40-50% faster delivery). Links to the harness engineering guide, harness templates guide, maintainability sensors guide, legacy .NET assessment framework, legacy system costs guide, and the modernise legacy .NET applications guide. ### MCP Patterns for Production Agents https://talkthinkdo.com/guides/ai-and-code/mcp-patterns-production-agents/ Reusable Model Context Protocol (MCP) patterns for production coding agents, distinct from MCP configuration. Defines MCP as an open standard connecting agents to external systems through a common interface that works across Cursor and Claude Code. Covers three patterns: the read-only data server (the safe default, for logs, work items, and build results), the gated action server (one purpose, explicit approval for state changes, scoped rotatable credentials, full logging), and the work-tracker server (grounding the agent in Azure DevOps work items). Covers authorising and scoping a server with least privilege, making MCP output agent-readable with structured results and next-action guidance, why MCP servers are the portable durable layer of an outer harness that survives a tool switch, and how scoped, versioned, logged servers map to ISO 27001, the EU AI Act, and procurement. Grounded in the Q1 2026 AI Velocity Report (six live custom MCP servers covering work items, test execution, logging, Azure, CI/CD, and GitHub). Links to the Claude Code for .NET configuration guide, the agent supply chain governance guide, the harness engineering guide, the EU AI Act guide, and the AI integration service. ### Claude Code for .NET Developers https://talkthinkdo.com/guides/development-practice/claude-code-dotnet-developers-guide/ Practical getting-started guide for .NET developers adopting Claude Code. Covers native installation on Windows (PowerShell), macOS, and Linux, IDE integration with Visual Studio (integrated terminal, file watcher, Git Changes), VS Code (Claude Code extension, C# Dev Kit pairing), and Rider (JetBrains terminal, ReSharper alignment). Explains AGENTS.md (portable, works in Cursor and Claude Code) versus CLAUDE.md (Claude Code-specific), with a worked .NET 10 AGENTS.md example for an ASP.NET Core project. Shows how to pre-approve the .NET command set (dotnet build, test, format, restore) in .claude/settings.json to eliminate prompt fatigue. Covers cloud agents for multitasking (background agents, parallel worktrees, mobile web UI, Managed Agents environments). Includes two real anonymised TTD client examples and a velocity report CTA citing 91.6% AI-authored code (100% senior-engineer reviewed). Links to the .NET configuration guide, the migration guide, and the harness engineering guide. ### Configuring Claude Code for .NET: Settings, Hooks, MCP, and Cloud Agents https://talkthinkdo.com/guides/development-practice/claude-code-dotnet-configuration-hooks-mcp/ Complete configuration reference for .NET teams using Claude Code. Documents all six configuration files (~/.claude/settings.json, ~/.claude/CLAUDE.md, AGENTS.md, CLAUDE.md, .claude/settings.json, .claude/settings.local.json, .mcp.json) and their scope and commit status. The primary focus is the pre-approved permissions catalogue: the full .NET command set grouped by intent (build/test/format, EF Core, tooling, solution management, publish/pack, git, NuGet hygiene, reads with safety denies, destructive shell denies). Covers allow/ask/deny semantics, Shift+Tab permission mode cycling, autoMode prose rules tuned for .NET, and personal versus team scopes. Copy-pasteable hooks: PostToolUse running dotnet format and dotnet build after every .cs edit, test-run hook on test file edits, PreToolUse blocking destructive rm, SessionStart .NET status summary, PreCompact migration snapshot. MCP server recommendations: GitHub, Azure, SQL Server schema-diff, work items. .claude/skills/ library: migrate-dotnet-project, write-xunit-tests, add-ef-core-entity, roslyn-analyser. .claude/agents/ definitions: code-reviewer and migration-analyser subagents. Cloud environments: worked Managed Agents environment definition for .NET 10. Multitasking patterns and GitHub Actions CI starter job. Links to getting-started and migration guides. ### .NET Framework to .NET 10 Migration with Claude Code https://talkthinkdo.com/guides/legacy-modernisation/dotnet-framework-migration-claude-code/ Step-by-step migration guide for .NET Framework 4.x to .NET 10 using Claude Code. Four phases: harness setup (Directory.Build.props with TreatWarningsAsErrors, .claude/settings.json with migration command set pre-approved, AGENTS.md and CLAUDE.md with migration rules, .NET Upgrade Assistant for project file conversion); project-by-project migration (dependency graph, worktrees, migrate-dotnet-project Skill, code patterns for HttpWebRequest to IHttpClientFactory, ConfigurationManager to IConfiguration, DateTime.Now to TimeProvider, EF6 to EF Core, MSTest to xUnit); testing and verification (ArchUnitNET for module boundary enforcement, Stryker.NET mutation testing, test-run hook); Program.cs and startup (WebApplicationBuilder, IExceptionHandler, middleware ordering). Cloud agents section covering parallel worktrees for large solutions and Managed Agents environments for overnight runs. Real anonymised examples from TTD client engagements with 91.6% AI-authored code (100% senior-engineer reviewed) and 40-50% faster delivery metrics. Common migration gotchas: string comparison, DateTime handling, System.Text.Json versus Newtonsoft.Json, Windows-specific APIs. A harness template is a bundle of guides and sensors that leashes a coding agent to a known topology, like a CRUD business service or an event processor. Walks through Codenative, TTD's deterministic model-driven templating tool, which predates AI coding agents and now runs as native Cursor Skills. Covers natural-language to YAML domain-model translation as the bounded non-deterministic step, conflict-free regeneration on model changes, ambient affordances, and Ashby's Law variety reduction. Includes a worked end-to-end example of adding a Booking entity from natural-language intent through generated artefacts, sensors, and a merged PR. Practical playbook for teams without a Codenative-equivalent: elevate existing scaffolders (dotnet new, Yeoman, Plop, T4, Hygen, NSwag, Cookiecutter) into Cursor Skills or MCP tools, add a drift sensor, resist hand-evolving generated regions. Links to the harness engineering hub guide, accelerators, the AI velocity report, and the Claude Code development service. ### Signs Your Legacy System Is Costing You More Than You Think https://talkthinkdo.com/guides/legacy-modernisation/legacy-system-costs-warning-signs/ Legacy systems hide their true costs. Eight warning signs: rising maintenance spend, security vulnerabilities, talent departure, manual workarounds, integration brittleness, compliance gaps, innovation blocked, and unpredictable outages. Covers how to calculate the total cost of ownership (direct, indirect, risk, and opportunity costs) and how AI-augmented codebase analysis reveals the full picture in days. Links to legacy modernisation and managed support services. ### Modernise, Rebuild, or Replace: A Decision Framework for Legacy Systems https://talkthinkdo.com/guides/legacy-modernisation/modernise-rebuild-or-replace-legacy-systems/ Six modernisation strategies (Retain, Retire, Rehost, Replatform, Refactor, Rebuild) explained in plain language with decision criteria for each. Covers cost and risk comparisons across strategies, how AI-augmented delivery changes which options are viable (rebuild timelines compressed by 40-50%), the assessment process, and how to build a business case. Links to legacy modernisation and custom software development services. ### ASP.NET Web Forms Migration: Comparing Your Target Options https://talkthinkdo.com/guides/legacy-modernisation/aspnet-web-forms-migration-options/ ASP.NET Web Forms was never ported to .NET Core, so there is no in-place upgrade and the user interface is a rewrite whichever target is chosen. Because migration effort is broadly comparable across targets, the decision should be made on recruitment pool, user experience ambition, and support horizon. Recommends extracting business logic into an ASP.NET Core API first, because that asset is durable regardless of the front end and also serves mobile, field devices, and partner integrations. Compares five destinations: staying on .NET Framework 4.8 (supported as a Windows component, no support cliff, but strategically dead); ASP.NET Core MVC or Razor Pages (lowest complexity, best for forms-heavy administrative screens); Blazor (familiar component model and C#-only staffing, smaller recruitment pool); React with a .NET API (largest talent pool, richest user experience, two skill sets to maintain); and replacing peripheral screens entirely. Explains when Next.js is and is not warranted, the incremental Strangler Fig route using YARP and System.Web adapters, why .NET 10 is the right target (.NET 8 and 9 leave support in November 2026), and how AI-augmented development changes the ratio of mechanical translation to architectural judgement. ### Planning an Integration Strategy: A Guide for Business and Technology Leaders https://talkthinkdo.com/guides/api-and-integration/integration-strategy-enterprise-leaders/ Integration projects fail when the strategy is wrong, not when the technology is wrong. Covers how to prioritise integration needs by business value and technical complexity, technology selection (API, messaging, events, hybrid), governance and security for integration programmes, and how AI-augmented delivery accelerates integration work. Links to API and integration services and related topic cluster pages. ### DevOps Maturity: Where Does Your Team Stand and What Should You Fix First? https://talkthinkdo.com/guides/development-practice/devops-maturity-assessment/ Practical DevOps maturity model with AI-augmented practices at each level. Five maturity levels from ad-hoc to optimised, with self-assessment questions for each dimension (CI/CD, infrastructure as code, monitoring, security, team practices). Covers DORA metrics (deployment frequency, lead time, change failure rate, time to restore), how AI tools improve DevOps practices at each level, and a prioritised improvement path. Links to DevOps services. ### In-House DevOps vs DevOps-as-a-Service: A Cost and Capability Comparison https://talkthinkdo.com/guides/development-practice/devops-in-house-vs-as-a-service/ Should you hire a DevOps engineer or work with a DevOps-as-a-Service partner? Compares cost (fully loaded in-house vs monthly retainer), coverage (single-person risk vs team breadth), capability (specialist depth vs cross-domain experience), and risk (recruitment, retention, knowledge concentration). Covers how AI-augmented delivery changes the economics and when a hybrid model works best. Links to DevOps services. ### Your Development Team Left: A Practical Guide to What Happens Next https://talkthinkdo.com/guides/teams-and-support/development-team-left-what-next/ Your developers left, your vendor disappeared, or your contractor finished. The system is still running and the business still depends on it. Step-by-step guide covering the first 48 hours (access, backups, monitoring), codebase assessment with AI-augmented tools, knowledge capture, stabilisation, and options for ongoing support or modernisation. Links to managed application support and internal systems handover services. ### Tendering for a Long-Term Technology Partner: A Buyer's Guide https://talkthinkdo.com/guides/teams-and-support/choosing-a-long-term-technology-partner-tender/ How to run a selection process when you need a partner to take over and develop a business-critical application estate rather than supply development resource. Covers why a structured lightweight process usually beats a formal tender outside regulated procurement, what a brief should contain (business context and outcomes, not a technical specification), why three or four shortlisted partners is the right number, and how the three supplier archetypes (large integrator, offshore resource, specialist partner) differ on breadth, team continuity, access to decision-makers, surge capacity, and day rate. Sets out the evaluation criteria that genuinely discriminate (inherited-system experience, named people and availability, breadth across application and cloud, operational maturity, willingness to disagree), suggested scoring weights, working-session questions, and commercial structure separating transition, steady-state support, and development. Links to development partner transition and managed application support. ### Managed Support vs Hiring: When to Outsource Application Maintenance https://talkthinkdo.com/guides/teams-and-support/managed-support-vs-hiring/ Should you hire a developer to maintain your software or use a managed support partner? Practical comparison of cost (in-house salary vs managed retainer), coverage (single person vs team), risk (bus factor, recruitment, retention), and capability (maintenance skills vs broader engineering). Covers how AI-augmented support reduces resolution times and costs, and when each option makes sense. Links to managed application support and pricing. ### AI-Augmented Application Support: Custom AI for Better Outcomes https://talkthinkdo.com/guides/teams-and-support/ai-augmented-application-support/ Most AI support products are generic, applying the same models to every customer with no knowledge of the system. This guide explains the opposite approach: collecting telemetry tailored to the specific application, feeding AI the code and context it needs, and building diagnosis and remediation around how the system actually works. Covers the four building blocks (custom telemetry and data collection, infrastructure analysis, log analysis, and automated database administration), how the approach improves outcomes (faster resolution, prevented incidents, broader coverage, and lower cost per incident), and where human engineering judgement stays in control. Links to managed application support, maintainability review, and internal systems handover. ### Automated DBA for SQL Server: AI-Augmented Database Administration https://talkthinkdo.com/guides/teams-and-support/automated-dba-sql-server/ A database administrator keeps a database fast, available, and secure, but hiring a full-time DBA for a single system is expensive and often underused. This guide explains automated DBA: continuous telemetry from Query Store, dynamic management views, wait statistics, and capacity data, feeding AI analysis that surfaces slow queries, index recommendations, capacity risks, and anomalies, with a qualified engineer reviewing every change before it reaches production. Covers the automated DBA loop, query and index tuning, capacity forecasting, backup and recovery assurance, and hosting models across SQL Server on a virtual machine, Azure SQL Database, and Azure SQL Managed Instance. Links to managed application support and maintainability review. ### Keeping Supported Software Secure: Advanced Security and AI Threat Intelligence https://talkthinkdo.com/guides/teams-and-support/securing-supported-software-ai-threat-intelligence/ Security is a state you maintain, not one you reach, because new vulnerabilities are disclosed daily. This guide sets out layered, continuous defence for supported software: GitHub Advanced Security (code scanning with CodeQL, secret scanning, and Dependabot), AI code analysis for context that rule-based scanners miss, Detectify for external attack surface monitoring, and threat intelligence to prioritise by real-world risk. Detection is automated; remediation is triaged, reviewed, tested, and reported by a security-literate engineer. Links to managed application support, GitHub Actions and Advanced Security, and the guide on keeping software up to date. ### Keeping Software Up to Date: Dependencies, Patching, and End-of-Life Risk https://talkthinkdo.com/guides/teams-and-support/keeping-software-up-to-date-dependencies-patching/ Software rots in place: dependencies, frameworks, and runtimes are patched upstream while a static system drifts from secure to exposed. This guide covers staying current in managed support: the three kinds of out of date (dependencies, frameworks and runtimes, and end-of-life platforms), Dependabot and Advanced Security for detection, a triage framework for deciding what to apply and when, why automated testing is what makes updating safe, and the compounding cost of falling behind. Links to managed application support, GitHub Actions and Advanced Security, and maintainability review. ### Running .NET on Azure Kubernetes Service (AKS): A Production Support Guide https://talkthinkdo.com/guides/teams-and-support/aks-dotnet-production-support/ Azure Kubernetes Service gives you a managed control plane, but running .NET workloads on it in production is an ongoing job. This guide walks through the operational workstreams: cluster and node management, scaling (Horizontal Pod Autoscaler, Cluster Autoscaler, and KEDA), Kubernetes and node image upgrades, observability (Container Insights, managed Prometheus, and Application Insights), security (Entra and RBAC, network policy, image scanning, and Key Vault), and cost management. Covers keeping the SQL Server data tier on a managed service alongside the cluster and how AI augments AKS operations. Links to managed application support and AKS deployment. ### The AI-Era SaaS Replacement Playbook: When, Why and How to Replace SaaS with Custom Software https://talkthinkdo.com/guides/build-buy-or-replace/replace-saas-with-custom-ai-built-software/ AI-augmented development has collapsed the cost of custom software enough that the build-vs-buy equation has flipped for companies using only 10-20% of their SaaS tools. This pillar guide covers the economic argument (worked TCO comparisons for HubSpot, BambooHR, and similar platforms), the "20% problem" (paying full price for features you never use), a six-criteria decision framework, the legal boundaries under UK copyright law, and a high-level migration process. Hub page for the SaaS replacement content cluster, linking to the legal guide, decision framework, migration playbook, and product-specific analyses. ### What You Can (and Can't) Legally Copy When Replacing SaaS: A UK Guide for CTOs https://talkthinkdo.com/guides/legal-and-contracts/legal-guide-replacing-saas-custom-build-uk/ UK and EU copyright law protects the expression of software (the code), not its functionality (what it does). This guide covers the key case law (Navitaire v easyJet, SAS Institute v World Programming Ltd), the Copyright, Designs and Patents Act 1988, clean-room implementation process, terms of service restrictions and their enforceability under English law, UK GDPR Article 20 data portability rights, IP risks specific to AI-generated code, and a practical pre-build legal checklist. Includes a legal disclaimer. ### When to Replace SaaS with Custom Software: A CTO's Decision Framework https://talkthinkdo.com/guides/build-buy-or-replace/when-to-replace-saas-with-custom-software/ Practical scorecard for evaluating whether a SaaS tool is a good candidate for replacement with custom software. Six criteria scored red/amber/green: feature utilisation, integration pain, compliance gaps, workflow fit, cost trajectory, and strategic importance. Includes a worked example scoring HubSpot, guidance on minimum viable scope, and the one-tool-at-a-time principle. Links to the SaaS replacement pillar guide and migration playbook. ### SaaS to Custom Software Migration: A 90-Day Playbook https://talkthinkdo.com/guides/build-buy-or-replace/saas-to-custom-software-migration-plan/ Phased 90-day migration plan for moving from SaaS to custom software. Five phases: discovery (weeks 1-3), build with AI-augmented development (weeks 4-10), data migration running in parallel (weeks 3-11), parallel running (weeks 11-12), and cutover (week 13). Covers workflow mapping, data export and transformation, UK GDPR compliance, parallel running procedures, rollback planning, and common mistakes to avoid. Includes a Gantt roadmap diagram showing workstream overlap. ### What's Your SaaS Really Costing You? A Payback Calculator https://talkthinkdo.com/guides/build-buy-or-replace/saas-replacement-payback-calculator/ Free interactive calculator for the true annual cost of an operational SaaS product. Inputs: annual licence cost, change request spend, workaround labour (hours per week and loaded hourly cost), optional downtime or error cost, and a replacement build scope from £150k to £350k or a user-entered figure. Outputs: true annual cost with the licence-to-true-cost multiple, payback period against the build cost after a stated and editable run cost assumption, and a five-year cumulative cost comparison chart. All formulae are published on the page, results are instant and ungated, and the verdict copy says honestly when replacement does not stack up. ### Switching from Card Billing to Direct Debit: An FD's Guide https://talkthinkdo.com/guides/build-buy-or-replace/card-billing-to-direct-debit/ Anchor guide for the card-billing entry point to the Direct Debit switching cluster, written for finance directors at UK recurring-revenue businesses. Core argument: for UK recurring revenue, Direct Debit usually beats card on both cost and involuntary churn, and the honest trade-offs are manageable with the right system design. Covers the two costs of card billing (percentage fees that scale with revenue, and the silent involuntary churn from expired, reissued, and declined cards), how Direct Debit works in plain English (mandate, advance notice of a scheme-default minimum of ten working days, the three-working-day collection cycle, and the Direct Debit Guarantee), an honest trade-off table against card, and a deliberately honest "who should not switch" section (one-off and impulse purchases, instant fulfilment, very low-value sales, and non-UK bank accounts). Explains a high-level migration and why the billing system, not the scheme, decides success. Links to the savings calculator, the bureau guide, the Bacs reports technical guide, and the Billing Engine accelerator. Notes that sponsorship and regulatory questions belong with the sponsoring bank or a qualified advisor. ### How Franchise Payments and Payouts Should Work https://talkthinkdo.com/guides/build-buy-or-replace/franchise-payments-and-payouts/ Vendor-neutral decision guide for how a franchise network should handle payments and payouts. Core question: when a customer pays, whose account does the money land in? Compares the pooled model (customers pay head office, which holds the funds and pays each franchise out, making the franchisor a de facto payment intermediary that carries settlement and refund risk) against the connected-account model (each franchise has its own account via a marketplace product such as Stripe Connect, so money settles directly to the franchise and head office provisions, oversees, and reconciles without holding funds). Explains how Stripe Connect fits (an account per franchise, self-service KYC and payout-bank onboarding, direct settlement, central oversight without custody), where Bacs Direct Debit still wins for recurring revenue (cost per collection, no card-expiry churn, the Direct Debit Guarantee), and a card-versus-Direct-Debit rail table by payment type. Sets out the two honest ways to take the management service fee (deduct at the rail or settle in full and reconcile separately) and a four-question decision framework. Links to the Stripe Connect for franchises accelerator page, the Billing Engine, the franchise hierarchy attribution page, the card-to-Direct-Debit guide and savings calculator, and the bespoke franchise platforms service. Notes that Talk Think Do is not a bank, payment institution, or regulated advisor and directs money-services and scheme-access questions to the payment provider and a qualified advisor. ### Card vs Direct Debit Savings Calculator https://talkthinkdo.com/guides/build-buy-or-replace/direct-debit-savings-calculator/ Free interactive calculator with two modes from one tool. Card mode compares card fees plus involuntary churn against Direct Debit; bureau mode compares a bureau per-transaction fee against direct submission. Inputs: number of payers, average payment value, payment frequency, Direct Debit cost per collection, and, by mode, a card fee percentage and involuntary churn rate, or a bureau fee per transaction, plus an optional one-off migration cost. Outputs: annual fee saving, annual churn-recovery value (card mode), and a five-year saving after migration shown as a cumulative break-even chart. The involuntary-churn line is the differentiated insight most fee calculators miss, and for many businesses it is the larger of the two savings. All formulae are published on the page, results are instant and ungated, every assumption is editable, and the verdict copy says honestly when switching does not pay. ### Leaving Your Direct Debit Bureau: The Routes Out https://talkthinkdo.com/guides/build-buy-or-replace/leaving-direct-debit-bureau/ Anchor guide for the bureau entry point, written for finance and operations directors already collecting by Direct Debit through a bureau. Core argument: bureaux are a good start and the wrong end state at scale, the routes out differ in cost, control, and effort, and mandate migration is a solved problem when planned properly. Covers the signs you have outgrown a bureau (per-transaction fees that only rise, batch-and-deadline operations, manual file handling, and no real-time visibility), the three routes to independence compared in a table (direct sponsorship with your own Service User Number, a managed or facilities-managed arrangement, and a modern API-based provider), how a Service User Number and bank sponsorship work, and mandate migration mechanics at category level (same SUN means mandates carry over; a new SUN means a coordinated bulk transfer without re-authorising payers). Sets out what a billing platform must do once the bureau's tooling is gone: mandate lifecycle, AUDDIS lodgement, notice-correct submission, and automated report ingestion. Keeps a respectful tone toward bureaux as a category and directs sponsorship and regulatory questions to the sponsoring bank. ### Handling Bacs Reports Properly: ARUDD, ADDACS, and AWACS https://talkthinkdo.com/guides/development-practice/bacs-reports-arudd-addacs-awacs/ Technical credibility guide for developers and technical leads building or specifying billing systems. Core argument: the difference between a billing system and a good billing system is what happens to the Bacs reports, so failures, cancellations, and amendments should drive automated workflows rather than sit in files. Explains the four inbound signals (AUDDIS lodgement rejections, ARUDD unpaid returns arriving the working day after collection, ADDACS amendment and cancellation advices, and AWACS wrong-account corrections for Bacs Direct Credit), then gives full ARUDD reason-code (0 to 9, A, B) and ADDACS reason-code (0, 1, 2, 3, B, C, D, E, R) tables with the correct automated response to each: retry, contact, suspend, or cancel. Emphasises that ARUDD codes 1, 2, and 6 mean a dead mandate that must never be re-presented, because collecting against a cancelled instruction triggers Direct Debit Guarantee indemnity claims. Covers event-driven ingestion architecture (explicit code-to-action mapping, idempotent processing, transactional application with audit, separation of payment and mandate events) and the timing edge cases that earn trust (payer cancels after a run is submitted, amendments arriving mid-cycle, re-presentation rules, and the AUDDIS rejection that looks like success). Maps to the Billing Engine accelerator and advises verifying all codes and timings against current Bacs and Pay.UK guidance. ### The EU AI Act and Custom Software: What UK Businesses Commissioning AI Need to Know https://talkthinkdo.com/guides/legal-and-contracts/eu-ai-act-custom-software-uk/ Practical guide for CTOs and business leaders commissioning custom AI-powered software with EU market exposure. Central question: when you commission a bespoke AI system, who carries which EU AI Act obligations? Covers the provider vs deployer distinction (Article 3), the four risk tiers (prohibited, high-risk, limited, minimal), Annex III high-risk categories most relevant to custom software (employment, credit, education, essential services), and the August 2026 compliance deadline. Explains the AI literacy obligation already in force since February 2025, contract clauses for provider/deployer allocation, what technical documentation the Act requires, and how EU AI Act compliance overlaps with ISO 27001 and UK GDPR. Includes a decision flow diagram for provider/deployer classification and a checklist of questions to ask your development partner. ### Is Claude GDPR Compliant? Anthropic Assurance for UK Businesses https://talkthinkdo.com/guides/ai-and-code/anthropic-claude-gdpr-compliance-uk/ Practical guide for UK businesses that need GDPR and ISO 27001 assurance over Anthropic's Claude. Central question: how do you assure Anthropic as a supplier and configure Claude so the residency and processing posture matches your commitments? Covers the Commercial Terms vs Consumer Terms training distinction, the Data Processing Addendum with Standard Contractual Clauses and the UK International Data Transfer Addendum, Anthropic's certifications (ISO 27001:2022, ISO 42001:2023, SOC 2 Type II, HIPAA-ready, CSA STAR), data residency options (first-party inference_geo us or global, AWS Bedrock EU regions, Google Vertex AI EU endpoints, Microsoft Foundry EU targeted for 2026), the exclusion of Anthropic models in Microsoft 365 Copilot from the EU Data Boundary, retention and Zero Data Retention options, and a supplier assessment mapped to ISO 27001 controls A.5.19 to A.5.23. Includes a deployment route decision flow diagram and a six-step assurance checklist. ### What is AI-Augmented Development? Meaning, Practice, and Evidence https://talkthinkdo.com/guides/ai-and-code/ai-augmented-development/ Pillar guide for the AI-augmented development content cluster. Defines AI-augmented development as a delivery model in which AI tools are integrated into every stage of the software lifecycle (discovery, specification, build, test, review, deploy, operate), with the human engineer in the lead and every output reviewed and tested. Distinguishes the practice from AI-assisted autocomplete, vibe coding, and unsupervised autonomous agents. Walks through the lifecycle with AI and human roles at each stage, cites the Q2 2026 AI Velocity Report figures (91.6% AI-authored code, 100% senior-engineer reviewed, 40-50% faster delivery, recent proposals at 28 to 34% of pre-AI build cost) alongside the Q1 2026 tender won at 55% of conventional cost, and covers the governance picture (IP, attribution, ISO 27001, EU AI Act). Provides a five-point procurement checklist and links to the six narrative spokes of the cluster. ### The Risks of AI-Augmented Development https://talkthinkdo.com/guides/ai-and-code/risks-of-ai-augmented-development/ Governance spoke of the AI-augmented development cluster. Covers eight risks and the controls that contain each: IP and code ownership, attribution and audit of AI contribution, regulatory exposure (EU AI Act and sector regulators), ISO 27001 controls for AI tools as cloud services, data residency and prompt leakage, quality drift, skills decay in junior engineers, and contractual ambiguity. Includes a decision flow diagram for EU AI Act provider/deployer classification and risk tiering, eight specific contract clauses for AI-augmented engagements, and the mapping from existing certifications (ISO 27001, Cyber Essentials Plus, G-Cloud Lot 3, ISO 42001) to AI-augmented delivery. ### AI-Augmented vs AI-Assisted Development: The Difference https://talkthinkdo.com/guides/ai-and-code/ai-augmented-vs-ai-assisted-development/ Comparison spoke. Draws the boundary between AI-assisted development (autocomplete and short suggestions inside the editor, bounded to a single file) and AI-augmented development (integration across the lifecycle: agentic IDEs, custom MCP servers, agent rules and skills, spec-first delivery, CI gates that validate AI output). Includes a five-criterion comparison matrix scoring scope, lifecycle coverage, governance, measured speedup, and workload fit. Sets out the incremental path from AI-assisted to AI-augmented through five steps: agentic IDE adoption, agent rules, MCP servers, spec-first delivery, and CI gates. ### The AI-Augmented Software Development Lifecycle https://talkthinkdo.com/guides/ai-and-code/ai-augmented-software-development-lifecycle/ Practitioner walkthrough spoke. Goes stage-by-stage through the AI-augmented lifecycle with the AI role, human role, artefacts, and tooling decisions at each step: Discovery (agents map codebases, humans interview), Specification (OpenSpec and spec-first delivery), Build (IDE agents and cloud agents), Test (AI authoring with ISTQB-qualified QA), Review (senior engineer review with CI gates), Deploy (MCP-driven acceptance-criteria checks), Operate (agent triage, human-led incident communication). Identifies the five practices where humans always keep the lead: user research, architectural judgement, service assessment, stakeholder negotiation, and incident communication. ### AI-Augmented Development ROI for UK Mid-Market Buyers https://talkthinkdo.com/guides/build-buy-or-replace/ai-augmented-development-roi-uk-mid-market/ Commercial spoke. Worked ROI framework for UK mid-market buyers (50 to 1,000 employees). Six input model: engineering hours, blended day rate, defect-correction cost, time-to-value, opportunity cost of delay, and tool plus process change cost. Includes a 24-week Gantt comparison of traditional and AI-augmented schedules and a worked example. Sets out five procurement questions to interrogate a supplier's productivity claim and three edge cases where ROI does not appear: engagements under 8 weeks, single-engineer teams, and engagements with no telemetry baseline. ### AI-Augmented Development for Public Sector and GDS https://talkthinkdo.com/guides/ai-and-code/ai-augmented-development-public-sector-gds/ Public-sector spoke. Maps AI-augmented delivery to the 14 points of the GDS Service Standard, identifying which gain from AI (Points 5, 8, 9, 13, 14), which are partially supported (Points 1, 4), and which are largely unchanged (Points 2, 3, 6, 7, 10, 11, 12). Covers the Technology Code of Practice touchpoints, the EU AI Act applicability to UK public-sector services (including the high-risk Annex III categories that capture some immigration, education, and law enforcement systems), the Government Commercial Agency (GCA) G-Cloud framework, and the seven questions a public-sector buyer should ask an AI-augmented supplier. Includes a layered architecture diagram of the buyer, supplier, tooling, and compliance tiers. ### The Practical Guide to Software Development Contracts (UK) https://talkthinkdo.com/guides/legal-and-contracts/software-development-contracts-guide-uk/ Pillar guide to the ten areas that come up most in bespoke software development contracts, written for CIOs, Heads of Digital, and commercial teams. Covers capped investment with flexible scope (the Build Cap), IP licensing and source code access, liability caps and indemnities, acceptance testing and UAT, the Initiation exit right and Material Variance, support services and the Master Services Agreement / SOW structure, data migration, AI-assisted delivery clauses (including the National AI Event scenario), duty of care standards (reasonable skill and care versus leading company), and the clauses that protect long-term investment (competitor restrictions, change of control, exit assistance, non-solicitation). Each area includes a plain-English explanation and a 'what to look for' checklist. Four areas link to dedicated deep-dive spoke guides. Includes a legal disclaimer; not legal advice. ### Capped Investment vs Fixed Price: A Guide to Software Build Caps https://talkthinkdo.com/guides/legal-and-contracts/capped-investment-flexible-scope-software-contracts/ Legal and Contracts spoke. Explains why a fixed price does not mean a fixed scope. Covers the Build Cap as a maximum financial commitment, feature budgets estimated during discovery, a programme contingency (typically around 20%) held inside the cap and released as features complete, deferral of lower-priority items to a post-MVP backlog (delivered via a separate SOW or a change retainer), and underspend redirection. Contrasts the model with traditional fixed-price, fixed-scope contracts where every change triggers a commercial negotiation. Includes a diagram of a constant Build Cap with shifting feature budgets and a contract checklist. ### Do You Actually Own Your Software? A Control Checklist for Non-Technical Founders https://talkthinkdo.com/guides/legal-and-contracts/do-you-own-your-software-founder-checklist/ For founders whose product was built by an agency. Separates the three components of control that fail independently: legal rights (copyright defaults to the author under the CDPA 1988, licence versus assignment, carved-out pre-existing materials, open-source licences and the SBOM), possession (a repository you control with full history, build and pipeline definitions, infrastructure as code, configuration, and a restore that has been tested), and operational control (cloud subscription, domain, DNS, certificates, app store, payment and identity providers, secrets, all registered to the client's company). Includes a nine-step control audit, a control register with the findings we most commonly encounter, credential rotation at handover, what investors and acquirers check during technical due diligence, and guidance for both cooperative and uncooperative supplier relationships. ### Selling Software to Enterprise Clients: The Security and Continuity Evidence They Will Ask For https://talkthinkdo.com/guides/legal-and-contracts/enterprise-buyer-security-evidence-software-vendors/ What a large customer's procurement and security review asks a smaller software vendor for, and how to prepare it before the deal reaches that stage. Covers the eight-part evidence pack: security questionnaire master answers, a UK GDPR Article 28 data processing agreement, certification evidence (Cyber Essentials Plus and ISO 27001), a disaster recovery statement with stated and tested RTO and RPO plus a manual fallback, hosting and data residency with a full sub-processor list, penetration test summary letters, an SLA the architecture can actually meet, and insurance. Also covers incident response and the processor's obligation to notify the customer without undue delay so the controller can meet the 72-hour deadline under UK GDPR, the ongoing obligations after contract (annual reassessment, change notification, right to audit, certificate renewals), and how to document gaps with compensating controls and remediation dates rather than claiming controls that do not exist. Ends with a five-part glossary of the terms and evidence buyers ask for, covering data protection (DPA, DPIA, TOMs, ROPA, sub-processors, IDTA and the UK Addendum, DSAR, breach notification), certifications and assurance reports (Cyber Essentials, Cyber Essentials Plus, ISO/IEC 27001 and 27701, SOC 2 Type I and Type II, penetration testing), questionnaires and frameworks (TPRM, SAQ, SIG, CAIQ, right to audit, DORA), security controls (MFA, SSO, SCIM, RBAC, JML, encryption, customer-managed keys, SBOM, SAST/DAST/SCA, CVSS, SIEM), and continuity and commercial terms (RTO, RPO, BCP, BIA, tabletop exercises, SLA, service credits, insurance, exit and data return). ### IP Licensing and Source Code Handover in Software Contracts https://talkthinkdo.com/guides/legal-and-contracts/software-ip-licensing-source-code-handover/ Legal and Contracts spoke. Explains the difference between an IP licence and outright assignment, why most bespoke contracts use a perpetual, irrevocable licence to use, copy, modify, and maintain (including the right to sublicense to third-party developers), and why assignment is less common given pre-existing components and open-source libraries. Covers source code handover tied to payment in full, the software bill of materials (SBOM), open-source compatibility, and freedom to host the code anywhere after handover. Distinguishes itself from the SaaS-replacement copyright guide, which addresses what you can legally copy rather than how newly commissioned software is licensed. Includes a handover timeline diagram and a checklist. ### Liability Caps and Indemnities in Software Development Contracts https://talkthinkdo.com/guides/legal-and-contracts/liability-caps-indemnities-software-contracts/ Legal and Contracts spoke. Explains liability caps (usually a multiple of contract value or charges paid in a period), why they exist, indemnities for IP infringement and data breach and whether they sit inside or outside the cap, excluded losses (loss of profits, anticipated savings, indirect or consequential loss, and the treatment of reputational damage or loss of goodwill), and the carve-outs that cannot be limited by law (fraud, personal injury). Stresses mutual liability rather than obligations on the development partner alone. Includes a layered liability-stack diagram and a contract checklist. ### Acceptance Testing and UAT Clauses in Software Contracts https://talkthinkdo.com/guides/legal-and-contracts/acceptance-testing-uat-software-contracts/ Legal and Contracts spoke. Explains that User Acceptance Testing is primarily the client's responsibility (testing against the agreed specification and accepting or rejecting with written feedback), while the development partner triages and remediates defects. Covers the critical distinction between a 'reasonable endeavours' remediation obligation and an absolute one, exclusions for defects caused by third-party integrations or client-provided data, escalation mechanisms that include a dispute resolution step before termination, and confirmation that UAT relates to conformance with the specification rather than subjective quality. Includes a UAT cycle diagram and a contract checklist. ### The UK's New Subscription Contracts Regime: A Compliance Guide for Software Teams https://talkthinkdo.com/guides/legal-and-contracts/uk-subscription-contracts-regime-compliance/ Legal and Contracts guide covering the UK's forthcoming subscription contracts regime under the Digital Markets, Competition and Consumers Act 2024 (DMCCA), which the government confirmed in August 2026 will commence in January 2027 (brought forward from spring 2027, having already slipped from an original 2026 date). Explains scope (consumer contracts only, extraterritorial, with sector exclusions), pre-contract information requirements, durable-medium renewal reminder notices before auto-renewal or trial conversion, the two applicable 14-day cooling-off periods (the existing Consumer Contracts Regulations 2013 right plus the new DMCCA renewal window, extendable up to 12 months if reminders are defective), 'click to cancel' requirements for online exit paths, refund rules, and CMA enforcement powers (fines up to 10% of group worldwide turnover). Closes with a pre-commencement engineering checklist covering reminder-notice audit trails, self-serve cancellation flows, and cooling-off state modelling. Includes a subscription lifecycle pipeline diagram and a legal disclaimer; not legal advice. ### How Adaptive Learning Platforms Actually Work https://talkthinkdo.com/guides/development-practice/adaptive-learning-platform-architecture/ Development Practice guide and the citation anchor for the tutoring and adaptive learning cluster. Explains that genuine adaptivity is an architecture, not a feature, built from four connected components: a structured item bank, a learner model that tracks mastery per skill, a sequencing engine, and a feedback loop. Covers the difference between adaptive learning and branching quizzes, the item bank as the real foundation, learner models in plain English (Item Response Theory and Bayesian Knowledge Tracing), sequencing policies and their trade-offs, and an honest account of where large language models genuinely help (content generation and feedback, under review) versus where they should not decide (unsupervised sequencing, being the source of facts for a child, judging mastery). Ends with how to measure efficacy in learning outcomes rather than engagement. Includes a four-component architecture diagram. ### Structuring a Learning Content Library for Adaptivity and AI https://talkthinkdo.com/guides/development-practice/learning-content-library-structure/ Development Practice guide. The unglamorous truth of every adaptive learning project is that the content work comes first. Gives a practical method to turn a legacy content estate of worksheets, questions, and schemes of work into a structured item bank: the content audit, the target schema (items, skills, prerequisites, difficulty, curriculum mapping), tagging at scale with AI-assisted enrichment under human review, migration sequencing at term boundaries, and the quality gates that make an item trustworthy. Explains how the structured bank feeds the adaptive learning architecture. Proof references stay at published-asset level (Hachette Learning for assessment content, Explore Learning for platform depth). Includes a target-schema diagram. ### AI Tutoring for Children: Safety by Design https://talkthinkdo.com/guides/ai-and-code/ai-tutoring-children-safety/ AI and Code guide, written in a measured practitioner tone. Names the four real risks of AI tutoring for children plainly (hallucinated facts, inappropriate content, over-reliance, and children's data protection) and sets out a layered control architecture: constrained generation against a verified item bank, teacher-in-the-loop review at defined points, age-appropriate content filtering, full interaction logging, and honest boundaries on what the AI is allowed to do. Translates the ICO Children's Code into product decisions at principle level (best interests of the child first, high-privacy defaults, data minimisation, profiling off by default) and directs readers to the ICO and to the Department for Education's Keeping Children Safe in Education for current detail. Covers what to tell parents and an honest assessment of how mature the field really is. Includes a five-layer control diagram. ### Replacing Your Tuition Centre Management System https://talkthinkdo.com/guides/build-buy-or-replace/replacing-tuition-centre-software/ Build, Buy, or Replace guide and the commercial-intent page of the tutoring cluster. A decision framework for build versus buy at network scale: below a size threshold, generic class-management software wins on cost and speed; above it, the operating model's uniqueness (mastery model, parent experience, franchise structure) is exactly what off-the-shelf software cannot express, and per-centre licence economics invert. Covers the signs a network has outgrown its system (described at category level, no vendors named), the licence-economics crossover, and the migration reality for a live multi-centre network: term-boundary cutover, parallel running, and franchisee change management. Cross-links the own-vs-rent total-cost-of-ownership guide and the franchise cluster. Includes a build-versus-buy threshold diagram. ### Extending a Ferry Reservation System: An API Layer Architecture https://talkthinkdo.com/guides/api-and-integration/extending-ferry-reservation-systems/ API and Integration spoke and the anchor guide for the ferry and maritime cluster. Vendor-neutral architecture guide to building on top of a ferry reservation platform without replacing it. The recommended pattern is an operator-owned API layer between the reservation core and everything else: the core keeps bookings, inventory, and pricing, while experience, disruption communications, analytics, and cross-system integration move into a layer the operator controls. Covers a core-versus-layer division table, a three-tier Azure architecture (consumers, API Management gateway and .NET services, reservation core), and the edge cases that earn credibility: cache invalidation when the core amends a sailing, idempotent booking amendments so a retried request never double-books, and degraded mode when the core is under maintenance. Includes security guidance and a seven-step build sequence starting with cached reads. ### Disruption Communications for Ferry Operators https://talkthinkdo.com/guides/development-practice/ferry-disruption-communications/ Development Practice spoke. How ferry operators should handle weather-driven cancellations, the single biggest driver of contact-centre load and customer anger. Argues that disruption is the clearest example of value that sits outside the reservation core. Covers the anatomy of a disruption day (forecast, decision, response, recovery), what passengers need at each stage (timely, specific, actionable), and a four-part system design: a sailing-status service, notification fan-out over Azure Service Bus, self-service rebooking that writes back to the core via the API layer, and contact-centre deflection metrics. Includes lifeline-route considerations for island communities, freight priority, and medical travel. ### Ancillary Revenue for Ferry Operators https://talkthinkdo.com/guides/build-buy-or-replace/ferry-ancillary-revenue/ Build, Buy, or Replace spoke for commercial directors. How ferry operators grow revenue per passenger by treating the crossing as the anchor purchase for a whole trip: accommodation, attractions, events, vehicle extras, and freight value-adds. Explains why the reservation core cannot capture this (it does not know the operator's tourism partners) and why it belongs in an owned experience layer. Covers product categories that work (with island-tourism examples), the partner-integration reality (partner APIs, availability, commission handling, and refunds when a sailing cancels), and a sequence from quick wins in the operator's own booking flow to a full trip-planning experience. Cites the Avios partner and loyalty integration for credibility. ## Industries - [Education](https://talkthinkdo.com/industries/education/) - Assessment platforms, LMS development, and AI-powered learning tools for education publishers and tutoring organisations. - [Tutoring & Supplementary Education](https://talkthinkdo.com/industries/tutoring-supplementary-education/) - Bespoke platforms for tuition networks and multi-centre tutoring providers: bookings, billing, parent apps, franchise reporting, and adaptive learning. Client: Explore Learning, with four published case studies. - [Sport & Fitness](https://talkthinkdo.com/industries/sport-and-fitness/) - Club management platforms, member apps, and booking systems for gyms and health clubs. Client: Third Space. - [Government & Public Sector](https://talkthinkdo.com/industries/government-public-sector/) - Mission-critical systems for UK government bodies. G-Cloud 15 and DOS 7 approved, ISO 27001 certified. - [Transport](https://talkthinkdo.com/industries/transport/) - Mobile apps, serverless loyalty backends, and managed support for transport operators. Clients include CalMac Ferries and Avios. - [Ferry & Maritime](https://talkthinkdo.com/industries/ferries-maritime/) - Software for ferry operators that extends the reservation core rather than replacing it. Talk Think Do is a complementor to reservation platforms such as e-Dea: the core booking, ticketing, and check-in platform stays, and Talk Think Do builds the operator-owned layer around it (customer apps, disruption communications, integrations, analytics, and ancillary revenue). Addresses seven category-level pains (roadmap dependency, undifferentiated customer experience, disruption communication, integration sprawl, data locked in the core, ancillary revenue, and assisted travel). Proven with CalMac Ferries, the UK's largest ferry network. ## Key Pages - [Homepage](https://talkthinkdo.com/) - [About Us](https://talkthinkdo.com/about-us/) - [The Story Behind the Name](https://talkthinkdo.com/think-talk-do/) - Why the company is Talk Think Do, not Think Talk Do, and why the word order matters. - [Pricing](https://talkthinkdo.com/pricing/) - [AI Approach](https://talkthinkdo.com/ai-approach/) - [The AI Velocity Report](https://talkthinkdo.com/ai-velocity-report/) - [Technology Partners](https://talkthinkdo.com/technology-partners/) - [Careers](https://talkthinkdo.com/careers/) - Careers across engineering, business analysis, QA, delivery, and architecture. AI is at the heart of every role. Minimum 5 years experience. Hybrid, Bournemouth-based. - [Blog](https://talkthinkdo.com/blog/) - [Guides](https://talkthinkdo.com/guides/) - [Case Studies](https://talkthinkdo.com/case-studies/) - [Contact](https://talkthinkdo.com/contact/) - [Book a Consultation](https://talkthinkdo.com/book-a-consultation/) - [Application Self-Assessment](https://talkthinkdo.com/guides/build-buy-or-replace/power-apps-saas-or-custom-build-assessment/) ## Resources - [Blog](https://talkthinkdo.com/blog/) - Thought leadership and technical articles on AI, Azure, cloud, DevOps, and EdTech. - [Guides](https://talkthinkdo.com/guides/) - Practical reference guides for teams that build, buy, and run software. - [The AI Velocity Report](https://talkthinkdo.com/ai-velocity-report/) - Quarterly transparency report on AI adoption, tools, and delivery metrics. - [AI for Education Publishers Ebook](https://talkthinkdo.com/ai-education-publishers-ebook/) - [Legacy Systems Ebook](https://talkthinkdo.com/legacy-systems-ebook/) - [Sitemap](https://talkthinkdo.com/sitemap-index.xml)