PHASE 05Approved · 100% Closed

Operating Model & Governance

Define the operating rule, roles, KPIs, support, client health, product governance, decision rights, AI governance, security, review cadence, and HQ workspaces that turn Phases 1–4 into daily execution.

Why this phase exists

Strategy and pricing without governance become preferences. Phase 5 turns approved decisions into detectable rules, owned KPIs, and enforceable cadences.

What it proves

KLOSIT operates on one rule: Rules detect. AI explains. Humans decide. System tracks. Every KPI, review, and escalation ladders back to this rule.

Owner
Founder Office
Approved by
Omar El-Mashaly
Approval date
22 Jul 2026
Source version
v1.0
Last updated
23 Jul 2026
min read
22 min read
What you will understand
  • 01The operating rule and four-stage ladder.
  • 02Roles: what each owns and does not own.
  • 03Client Health Score composition and thresholds.
  • 04Support classification, severity, SLA, and ticket lifecycle.
  • 05Product governance, weighted scoring, and decision-rights matrix.
  • 06AI governance boundaries and security principles.
  • 07Review cadence, HQ workspaces, and role dashboards.
  • 08The 24-item success criteria.
Why this phase matters to KLOSIT

Phase 5 is the operating spine. Every alert, ticket, KPI, and executive review in KLOSIT is authored to follow the rules in this phase — otherwise governance is decorative.

5.0

Operating Rule

The KLOSIT operating rule is: Rules detect. AI explains. Humans decide. System tracks. Every workflow, alert, and dashboard is designed to obey this sequence.

5.1

Governance Principles

  • Detection before opinion.
  • One owner per KPI.
  • One decision, one approver.
  • Every alert has an action.
  • Every action has an SLA.
  • Every SLA has a review.
5.2

Roles — Owns / Does Not Own

CEO (Founder)
  • Owns strategy, category, pricing, financing.
  • Owns discount and refund approvals.
  • Does not own individual ticket triage.
  • Does not own daily support execution.
CTO
  • Owns platform architecture, infrastructure, and security controls.
  • Owns V0 hardening scope and V1/V1.5 sequencing recommendations.
  • Does not own pricing or commercial policy.
  • Does not own client-facing support tone.
Customer Success (CS)
  • Owns onboarding, adoption, health-score follow-through, and renewals.
  • Owns first response inside SLA.
  • Does not own price changes or refunds.
  • Does not own product roadmap decisions.
5.3

Payment Governance

Payment governance enforces the Phase 2 discipline through daily and weekly review cycles, escalation paths, and refund thresholds.

  • Daily: invoice status board reviewed by CS lead.
  • Weekly: aged receivables reviewed by Finance + CS lead.
  • Refund below 10k EGP: CS decides with founder awareness.
  • Refund at or above 10k EGP: Founder approval required.
  • Discount request: proposed by CS, approved by Founder only.
5.4

Product KPI Framework

KPIPurposeOwnerCadenceTrigger
Weekly active brokeragesAdoption breadthCTOWeeklyDrop > 10% week-over-week
Feature adoption indexV0 hardening feedbackCTOWeeklyIndex < 0.4 for any core feature
Nabih AI usefulness ratingAI quality signalCTOMonthlyRating < 3/5
5.5

Customer Success KPI Framework

KPITargetOwnerCadenceRequired action on breach
Time-to-Go-Live≤ 30 daysCS leadPer clientWeekly review + CTO support
First-response SLA compliance≥ 95%CS leadWeeklyRoot-cause + staffing review
Client Health Score ≥ 80≥ 70% of clientsCS leadMonthlyRecovery plan per client < 80
Renewal capture≥ 90%CS leadPer renewalFounder review below target
5.6

Client Health Score (100 points)

Every active client carries a Health Score composed of five weighted components summing to 100. Thresholds trigger CS intervention and, at the risk band, founder escalation.

5.7

Support · Categories, Severity, SLA, Lifecycle

Support tickets are classified by category and severity. SLA times below apply to first response, workaround, and full resolution.

Ticket lifecycle
  • Intake → triage (auto + human) → assignment → response → workaround → resolution → post-mortem for S1/S2.
  • S1 post-mortems are shared with the client within 5 business days.
5.8

Product Governance & Weighted Scoring

Every product idea is classified as Revenue-critical, Governance-critical, Adoption-critical, or Nice-to-have. Feature scoring uses a weighted 100 model.

5.9

Decision-Rights Matrix

Every recurring decision names a Recommender, an Approver, and an Executor. Only one Approver per row.

5.10

AI Governance (Nabih AI)

Nabih AI operates strictly within the Explain step of the operating ladder. It does not decide, spend, refund, sign, or discount.

  • No autonomous action on financial or contractual events.
  • Every AI-generated brief includes source references.
  • Human approver named on every AI-triggered escalation.
  • AI outputs may be overridden by any owner within their scope.
5.11

Security & Compliance Principles

  • Least privilege by default; role-based access enforced.
  • Every data change is auditable; nothing hard-deletes without a documented policy.
  • Access reviews are quarterly; offboarding is same-day.
  • Secrets never in code, never in chat, never on personal devices.
  • Backups verified by restore, not by presence.
5.12

Review Cadence

The management rhythm is small, opinionated, and durable.

5.13

HQ Workspaces & Role Dashboards

  • Founder workspace: strategy, financing, decisions, escalations.
  • CTO workspace: platform, security, V0/V1 progress, AI governance.
  • CS workspace: onboarding pipeline, Health Score, renewals, SLA compliance.
  • Finance workspace: invoices, aging, refunds, marketing spend.
5.14

Phase 2 Governance Integration

Phase 5 explicitly inherits and enforces Phase 2 commercial rules. The two most common misinterpretations are called out here to prevent recurrence.

5.14A

Governance Success Criteria (24 items)

  1. 01Operating rule visible in every alert card.
  2. 02One owner per KPI declared.
  3. 03One approver per decision declared.
  4. 04Every alert linked to a defined action.
  5. 05Every action linked to an SLA.
  6. 06Every SLA linked to a review.
  7. 07Client Health Score computed for every active tenant.
  8. 08Health thresholds trigger CS intervention automatically.
  9. 09Risk band escalates to founder within 24 hours.
  10. 10Support severity applied to every ticket.
  11. 11SLA compliance visible in Support workspace.
  12. 12S1 post-mortems shared with clients ≤ 5 business days.
  13. 13Feature scoring applied to every V1 candidate.
  14. 14Decision-rights matrix visible to every operator.
  15. 15Refund threshold enforced automatically.
  16. 16Discount requests routed to founder only.
  17. 17AI never signs, spends, or refunds.
  18. 18Nabih briefs cite source references.
  19. 19Access reviews executed quarterly.
  20. 20Offboarding executed same-day.
  21. 21Backups verified by restore quarterly.
  22. 22Weekly commercial review meets on cadence.
  23. 23Monthly financial review meets on cadence.
  24. 24Quarterly board & strategy meets on cadence.
5.15

Conclusion

Phase 5 makes KLOSIT operable. It converts the identity, pricing, GTM, and financial anchors into daily behavior — with named owners, measurable KPIs, and enforceable cadence.

5.16

Operationalization Gate

The next operational gate is bringing the decision-rights matrix and Client Health Score into live use inside HQ workspaces.

Closure Checklist
  • Operating rule declared
    Approved
  • Governance principles
    Approved
  • Roles: owns / does not own
    Approved
  • Payment governance
    Approved
  • Product & CS KPI frameworks
    Approved
  • Client Health Score
    Approved
  • Support classification & SLA
    Approved
  • Product governance & scoring
    Approved
  • Decision-rights matrix
    Approved
  • AI governance
    Approved
  • Security & compliance
    Approved
  • Review cadence
    Approved
  • HQ workspaces & dashboards
    Approved
  • P2 governance integration
    Approved
  • 24-item success criteria
    Approved
Final Closure Decision

Phase 5 is 100% APPROVED and CLOSED. Operational bring-up of the decision-rights matrix and Client Health Score is the next execution gate.

Next Business Plan Gate

Live enforcement inside HQ workspaces.

Source & Traceability

Every claim on this page traces to the canonical source below.

KLOSIT Phase 5 — Operating Model & Governance
Version
v1.0
Approved
Omar El-Mashaly · 22 Jul 2026
Owner
Founder Office
Last updated
23 Jul 2026
Update Rule

Governance updates require founder approval and a change entry against the specific subsection. AI governance rules and decision rights are frozen without a founder-approved override.