Operating Model & Governance
Define the operating rule, roles, KPIs, support, client health, product governance, decision rights, AI governance, security, review cadence, and HQ workspaces that turn Phases 1–4 into daily execution.
Strategy and pricing without governance become preferences. Phase 5 turns approved decisions into detectable rules, owned KPIs, and enforceable cadences.
KLOSIT operates on one rule: Rules detect. AI explains. Humans decide. System tracks. Every KPI, review, and escalation ladders back to this rule.
- Owner
- Founder Office
- Approved by
- Omar El-Mashaly
- Approval date
- 22 Jul 2026
- Source version
- v1.0
- Last updated
- 23 Jul 2026
- min read
- 22 min read
- 01The operating rule and four-stage ladder.
- 02Roles: what each owns and does not own.
- 03Client Health Score composition and thresholds.
- 04Support classification, severity, SLA, and ticket lifecycle.
- 05Product governance, weighted scoring, and decision-rights matrix.
- 06AI governance boundaries and security principles.
- 07Review cadence, HQ workspaces, and role dashboards.
- 08The 24-item success criteria.
Phase 5 is the operating spine. Every alert, ticket, KPI, and executive review in KLOSIT is authored to follow the rules in this phase — otherwise governance is decorative.
Operating Rule
The KLOSIT operating rule is: Rules detect. AI explains. Humans decide. System tracks. Every workflow, alert, and dashboard is designed to obey this sequence.
Governance Principles
- Detection before opinion.
- One owner per KPI.
- One decision, one approver.
- Every alert has an action.
- Every action has an SLA.
- Every SLA has a review.
Roles — Owns / Does Not Own
- Owns strategy, category, pricing, financing.
- Owns discount and refund approvals.
- Does not own individual ticket triage.
- Does not own daily support execution.
- Owns platform architecture, infrastructure, and security controls.
- Owns V0 hardening scope and V1/V1.5 sequencing recommendations.
- Does not own pricing or commercial policy.
- Does not own client-facing support tone.
- Owns onboarding, adoption, health-score follow-through, and renewals.
- Owns first response inside SLA.
- Does not own price changes or refunds.
- Does not own product roadmap decisions.
Payment Governance
Payment governance enforces the Phase 2 discipline through daily and weekly review cycles, escalation paths, and refund thresholds.
- Daily: invoice status board reviewed by CS lead.
- Weekly: aged receivables reviewed by Finance + CS lead.
- Refund below 10k EGP: CS decides with founder awareness.
- Refund at or above 10k EGP: Founder approval required.
- Discount request: proposed by CS, approved by Founder only.
Product KPI Framework
| KPI | Purpose | Owner | Cadence | Trigger |
|---|---|---|---|---|
| Weekly active brokerages | Adoption breadth | CTO | Weekly | Drop > 10% week-over-week |
| Feature adoption index | V0 hardening feedback | CTO | Weekly | Index < 0.4 for any core feature |
| Nabih AI usefulness rating | AI quality signal | CTO | Monthly | Rating < 3/5 |
Customer Success KPI Framework
| KPI | Target | Owner | Cadence | Required action on breach |
|---|---|---|---|---|
| Time-to-Go-Live | ≤ 30 days | CS lead | Per client | Weekly review + CTO support |
| First-response SLA compliance | ≥ 95% | CS lead | Weekly | Root-cause + staffing review |
| Client Health Score ≥ 80 | ≥ 70% of clients | CS lead | Monthly | Recovery plan per client < 80 |
| Renewal capture | ≥ 90% | CS lead | Per renewal | Founder review below target |
Client Health Score (100 points)
Every active client carries a Health Score composed of five weighted components summing to 100. Thresholds trigger CS intervention and, at the risk band, founder escalation.
Support · Categories, Severity, SLA, Lifecycle
Support tickets are classified by category and severity. SLA times below apply to first response, workaround, and full resolution.
- Intake → triage (auto + human) → assignment → response → workaround → resolution → post-mortem for S1/S2.
- S1 post-mortems are shared with the client within 5 business days.
Product Governance & Weighted Scoring
Every product idea is classified as Revenue-critical, Governance-critical, Adoption-critical, or Nice-to-have. Feature scoring uses a weighted 100 model.
Decision-Rights Matrix
Every recurring decision names a Recommender, an Approver, and an Executor. Only one Approver per row.
AI Governance (Nabih AI)
Nabih AI operates strictly within the Explain step of the operating ladder. It does not decide, spend, refund, sign, or discount.
- No autonomous action on financial or contractual events.
- Every AI-generated brief includes source references.
- Human approver named on every AI-triggered escalation.
- AI outputs may be overridden by any owner within their scope.
Security & Compliance Principles
- Least privilege by default; role-based access enforced.
- Every data change is auditable; nothing hard-deletes without a documented policy.
- Access reviews are quarterly; offboarding is same-day.
- Secrets never in code, never in chat, never on personal devices.
- Backups verified by restore, not by presence.
Review Cadence
The management rhythm is small, opinionated, and durable.
HQ Workspaces & Role Dashboards
- Founder workspace: strategy, financing, decisions, escalations.
- CTO workspace: platform, security, V0/V1 progress, AI governance.
- CS workspace: onboarding pipeline, Health Score, renewals, SLA compliance.
- Finance workspace: invoices, aging, refunds, marketing spend.
Phase 2 Governance Integration
Phase 5 explicitly inherits and enforces Phase 2 commercial rules. The two most common misinterpretations are called out here to prevent recurrence.
Governance Success Criteria (24 items)
- 01Operating rule visible in every alert card.
- 02One owner per KPI declared.
- 03One approver per decision declared.
- 04Every alert linked to a defined action.
- 05Every action linked to an SLA.
- 06Every SLA linked to a review.
- 07Client Health Score computed for every active tenant.
- 08Health thresholds trigger CS intervention automatically.
- 09Risk band escalates to founder within 24 hours.
- 10Support severity applied to every ticket.
- 11SLA compliance visible in Support workspace.
- 12S1 post-mortems shared with clients ≤ 5 business days.
- 13Feature scoring applied to every V1 candidate.
- 14Decision-rights matrix visible to every operator.
- 15Refund threshold enforced automatically.
- 16Discount requests routed to founder only.
- 17AI never signs, spends, or refunds.
- 18Nabih briefs cite source references.
- 19Access reviews executed quarterly.
- 20Offboarding executed same-day.
- 21Backups verified by restore quarterly.
- 22Weekly commercial review meets on cadence.
- 23Monthly financial review meets on cadence.
- 24Quarterly board & strategy meets on cadence.
Conclusion
Phase 5 makes KLOSIT operable. It converts the identity, pricing, GTM, and financial anchors into daily behavior — with named owners, measurable KPIs, and enforceable cadence.
Operationalization Gate
The next operational gate is bringing the decision-rights matrix and Client Health Score into live use inside HQ workspaces.
- Operating rule declaredApproved
- Governance principlesApproved
- Roles: owns / does not ownApproved
- Payment governanceApproved
- Product & CS KPI frameworksApproved
- Client Health ScoreApproved
- Support classification & SLAApproved
- Product governance & scoringApproved
- Decision-rights matrixApproved
- AI governanceApproved
- Security & complianceApproved
- Review cadenceApproved
- HQ workspaces & dashboardsApproved
- P2 governance integrationApproved
- 24-item success criteriaApproved
Phase 5 is 100% APPROVED and CLOSED. Operational bring-up of the decision-rights matrix and Client Health Score is the next execution gate.
Live enforcement inside HQ workspaces.
Every claim on this page traces to the canonical source below.
KLOSIT Phase 5 — Operating Model & Governance- Version
- v1.0
- Approved
- Omar El-Mashaly · 22 Jul 2026
- Owner
- Founder Office
- Last updated
- 23 Jul 2026
Governance updates require founder approval and a change entry against the specific subsection. AI governance rules and decision rights are frozen without a founder-approved override.