Direct access, no handoffs

Technology and AI consulting for software companies
navigating growth, modernization, and change

NLT Labs is technology and AI consulting by Bill Thornton. Twenty-five years leading enterprise engineering organizations, AI delivered into production under SOC 2 and FedRAMP constraints, and the agent platform further down this page, built hands-on.

Software companies stuck between desktop AI and production

Mid-market and growth-stage teams where individual AI use is high, but the company program is still a proof of concept. The blocker is rarely access to models. It's structure, integration, ownership, and someone who has carried this work before.

POCs that never reach production

The proof of concept looked great in a sandbox. Months later it's still a POC: no evals, messy integrations, and nobody owns what happens when the model gets deprecated.

Shadow AI on every desktop

Employees reach for personal ChatGPT or Claude because sanctioned tools are slower or stuck in pilot. Work gets done. Confidential data leaves on copy-paste. IT finds out later.

Human glue between systems

AI generates an answer. Someone copies it into the CRM, ticket queue, or spreadsheet. That's not a workflow. It's a tax on every person who touches the output.

Governance nobody built yet

SOC 2, ISO 27001, customer contracts, responsible AI policies. Mid-market companies face enterprise audit questions with a fraction of the staff.

Enterprise playbook, sized for your company

Years leading AI and platform programs at enterprise scale: board readouts, compliance reviews, multi-team rollouts, production agentic systems. Mid-market companies don't need a 200-person transformation office. They need someone who's done this before to walk alongside their team.

01

From shadow AI to approved workflows

Inventory what's already running on desktops and design company paths that match the speed people expect. Sanctioned tools, clear data rules, workflows wired into your stack.

02

From POC to production, with evals

Integration contracts, LLM-as-judge evals, error handling, and ownership when models deprecate. Discipline without the six-month architecture review.

03

Integration without the human glue

Connect AI outputs to CRM, ERP, ticketing, and document stores so people stop copying answers between tabs.

04

Governance your size can run

SOC 2, ISO 27001, and FedRAMP patterns scaled down to what a 50- or 500-person company needs. Procurement-ready evidence from week one.

05

Fractional depth, not a permanent vendor

Embed as fractional CTO or implementation partner until your people own what you built together.

06

Honest build vs. buy

Pick a small, coherent stack. Say no to the rest. Tool sprawl is the silent budget leak.

Five ways to work together

Strategy

AI transformation roadmap

Honest current-state audit and a 90-day plan with owners, dates, and someone accountable for each line of it.

  • Current-state audit across product, data, and workflows
  • Build vs. buy with ROI tied to your numbers
  • Governance and responsible-use framing early
  • An executive narrative that survives the first hard question
Implementation

Agentic systems in production

Agents, RAG, document intelligence, and copilots that call real tools and fail gracefully. Evals from day one.

  • Agent architecture from workflow design to deployment
  • RAG: ingestion, chunking, retrieval tuning
  • Tool orchestration and schema contracts
  • LLM-as-judge evals wired into CI/CD
Leadership

Fractional CTO

CTO-level judgment without full-time headcount. Org design, delivery, modernization, security and compliance, and where AI genuinely helps.

  • Engineering org design, hiring bar, and delivery cadence
  • Platform modernization and cloud cost discipline
  • Security, compliance, and audit readiness
  • Interim leadership into a portfolio company between permanent hires
  • AI adoption where it pays, and honesty where it doesn't
  • Updates that don't need translating for whoever's asking
Enablement

Upskill the teams doing the work

Agentic patterns, eval discipline, and production judgment so capability stays when the engagement ends.

  • AI-assisted development standards for your codebase
  • Separate tracks for engineers, PMs, and leadership
  • When to trust the model and when not to
  • Patterns your team can use Monday morning

The calls that didn't have an obvious right answer

What you're actually buying is how someone decides once the constraint is real: what got picked, what got refused, and what it returned. Three of those calls, with the numbers attached. The agent work further down this page was built by one person on no engineering payroll, and that part is new.

Prior executive role · security and compliance

A compliance program built before the deals needed it

Situation
Enterprise and government buyers were asking audit questions the company had no program to answer.
The call
Build the SOC program from the ground up: vendor selection, cross-department controls, the system narrative, and the company-wide information security policy.
Said no to
Answering questionnaires one deal at a time and calling it a program.
Returned
Multiple SOC 1 and SOC 2 Type II audits passed between 2016 and 2019, with national retail, restaurant, and logistics brands on the customer list. The same posture now covers ISO 27001 and FedRAMP LI-SaaS.

What transfersCompliance sequenced ahead of the pipeline is a revenue lever. Sequenced behind it, it's a stalled quarter.

Executive role · production agent AI

The evals that decide whether an agent reaches a customer

Situation
A production agent that takes real actions for real customers. The failure mode isn't an awkward sentence, it's a wrong booking.
The call
Every agent change runs a five-level evaluation before rollout, covering outcome, path, details, quality and safety, scored by LLM-as-judge against sampled live traffic and on-demand test suites.
Said no to
Open-ended autonomy. Strict tool schemas, policy-driven prompts, and explicit confirm-before-acting steps, so the agent follows defined rules instead of improvising near a customer.
Returned
Agent changes get validated before a customer sees them, not after.

What transfers"We'll add evals later" is the sentence that keeps a proof of concept a proof of concept. The eval pyramid is the thing that makes it safe to put in front of a customer.

Prior executive role · margin and org scaling

Ten points of margin while the org tripled

Situation
A services-heavy business moving to pure software, with revenue compounding and headcount climbing to match. Gross margin is usually the thing that quietly gets worse during that transition.
The call
Run the services-to-software move as a margin program with its own targets, rather than treating margin as whatever fell out of the product roadmap.
Said no to
Buying growth with headcount. Every implementation that stayed bespoke was a services contract wearing a software label.
Returned
Ten points of gross margin added while the organization grew from 28 people to 80.

What transfersIn a services-to-software transition the revenue mix moves first and the cost base only follows if somebody makes it. Margin is a decision, not an outcome.

The scale those calls were made at: a global enterprise SaaS business grown two and a half times in ARR, and technology and organizational integration led across four acquisitions. Three more calls, including the agent-platform builds, are written up in the same format.

Results in this section are from Bill's prior work as a technology executive, not from NLT Labs client engagements. They're shared as experience, not as a promise of comparable outcomes.

We hit these problems on our own company first

An agent is only worth running once somebody has decided what it's allowed to touch, what it's allowed to spend, and how you'd find out it went wrong. That's the unglamorous part, it's most of the work, and it's what we built first.

When we say agent, we mean something specific: a versioned workflow with a defined role, an explicit tool grant, and a budget cap, scored by a go-live gate before it touches anything real. On the storefront fleet, nine of the 30 agents do nothing but check the other 21: five judges covering claims, disclosure, originality, replies and visuals, three domain experts covering brand, commerce and compliance, and one that scans for prompt injection. None of this is client work. It's our own company, so we've already hit the problems you'd hit in month three.

150+ agents on the platform
36 production workflows
11,000+ agent runs to date
7 live projects, one platform

Agent Stack · platform

AgentForge

The runtime everything else registers into, with its own library of expert reviewers for code, security, architecture and observability. A request gets matched to an agent, composed into a system prompt, and executed under a budget cap and an explicit tool grant.

Enterprise platform teams · hosts every agent on the platform · 45 reviewer agents · v4.59.1

Portfolio Suite · products

NLT Portfolio Engine

Our biggest fleet: 39 agents behind a capital gate. An intake doc runs an 11-step evaluation covering market, feasibility, financial model, regulatory exposure and a devil's advocate pass, and comes out as FUND, PASS or DIG DEEPER. On FUND, a build workflow assembles and deploys it.

Teams that need a decision before the building starts · 39 agents · 6 workflows

Reference build · not sold as a product

Web-Store-DNA

A whole storefront operation, broken into five jobs a small business actually recognises: catalog and listings, multi-channel marketing, customer service, analytics, and the go-live gate every agent clears before it runs. First commit was 28 July 2026, and by 5 August the same kit was running a second, independent storefront. That gap, eight days, is the honest answer to whether this transfers.

Small commerce teams · 30 agents · 5 workflows · running on 2 storefronts · v0.1.0 · in development

Three more platform pieces, shared agent memory, document generation, and idea intake, are documented on the product side of NLT Labs.

The same thing works in your company. If there's a process in your business that eats a person's week, that's where we'd start.

From first conversation to a production result

1

Discovery call Free · 30 min

Where you are, what you've tried, and whether NLT Labs is the right fit. No pitch deck.

2

Diagnosis & proposal ~1 week

Stack, workflows, and blockers assessed. Scoped proposal with timeline, owners, and measurable outcomes.

3

Engagement & handoff

Build with your team, not around them. Your people own what lands when the engagement ends.

The person you meet is the person who does the work

Bill Thornton

Bill Thornton

Founder, NLT Labs · Technology executive & hands-on CTO

Bill Thornton has spent more than 25 years building and scaling enterprise software organizations. His experience includes SaaS growth, engineering transformation, cloud modernization, acquisition integration, security and compliance, and practical AI adoption.

Through NLT Labs, Bill works directly with leadership teams that need experienced technology guidance without a large consulting firm or unnecessary overhead.

What colleagues and clients say

Verbatim excerpts from the recommendations on Bill's LinkedIn profile, where all 21 are public: direct reports, executive peers, and clients, written across 20 years.

Executive peer · 10 years working together

"Bill has a rare combination of deep technical expertise, operational discipline, and executive-level judgment. In moments where the business was moving quickly, priorities were changing, or acquisitions introduced new complexity, Bill brought clarity and calm."

Bart Waldeck · Chief product and strategy executive

Client · 4-year consulting relationship

"In 4 years he has consistently performed at an exceptionally high level for us. He has helped guide us through difficult decisions, always landing us on safe ground."

Tom McCormick · Business owner

Direct report · 20 years working together

"Bill builds high-performing teams, drives clarity in execution, and leads with integrity. Any organization would be fortunate to have his leadership."

Heather Griffin · Director of Quality Assurance

Read all 21 recommendations on LinkedIn →

Start with a question.
You don't need a project yet.

Thirty minutes, no obligation. Whether you're scoping real work or you just want a second opinion before a decision, it's a straight conversation either way. If we're not the right people, we'll say so and point you at who is.

Want to talk to someone who's worked with Bill before? Ask on the call and we'll make the introduction.

Prefer to write? hello@nltlabs.ai · About Bill