Skip to main content
VSI Technologies

Automation that survives a security review.

Mission workflows, correspondence and case handling, inside the controls you already operate under.

Industry overview

Inside a government & defense operation

The work is well documented and largely manual. Case handling, correspondence, records requests and reporting each have a defined process and a queue, and the queue is the problem. Adding people is slow, and the last modernisation programme delivered a system that the process now works around.

Government work has a property that makes it unusually good ground for automation and unusually hostile to the way most automation is sold: the processes are already written down. There is a manual, a delegation of authority, a records schedule and a defined route for an exception. What a commercial operator would have to reconstruct through interviews already exists as a document, which removes the discovery risk that sinks a lot of private-sector projects.

What is missing is not clarity but throughput. The queue grows because the intake grows and the establishment does not, and because hiring against a vacancy takes a length of time that has nothing to do with how urgent the work is. So the backlog absorbs the difference, and the backlog is politically visible in a way the staffing constraint is not.

The previous modernisation is usually part of the problem rather than part of the solution. A system was procured, configured to a process that has since changed, and is now worked around by staff who have developed a parallel practice involving a spreadsheet and a shared mailbox. Nobody is going to say this in a stakeholder workshop, and any automation designed from the official process rather than the actual one will automate a fiction.

And the authorisation environment is the real gate. A working prototype is not the difficult part in government; getting the thing into production inside an existing boundary, with the logging, the records retention and the human decision points documented, is where twelve-month timelines come from. A supplier who treats that as paperwork to be handled later is a supplier whose pilot will never leave the pilot environment.

Common challenges

Challenges we see across government & defense

If three or more are true, the rest of this page is about your operation.

  • The backlog is reported upward monthly and has not fallen in a year
  • Staff maintain a parallel spreadsheet because the official system does not fit
  • A records request takes weeks and most of that is redaction review
  • The same recurring return is rebuilt by hand every reporting period
  • A previous modernisation delivered a system the process now works around
  • Hiring against a vacancy takes longer than the backlog can absorb

How we help

Five practices, applied to government & defense

AI, cloud, cybersecurity, hardware and programme delivery, one integrated bench, each practice applied to how government & defense actually operates.

  1. Agents built for the mission-support workload: correspondence triage, FOIA request intake, records classification against your retention schedule, and case routing inside ServiceNow, every action logged to an audit trail a records officer can reconstruct, with a human on every determination that touches a member of the public.

  2. Architecture designed for government cloud regions and agency ATO processes from the first diagram, boundary documentation, control inheritance mapping, and data-residency decisions made before the build, because retrofitting an authorisation boundary is the most expensive change order in federal IT.

  3. Control implementation aligned to NIST 800-53 families and your agency’s continuous-monitoring regime: least-privilege service accounts, complete audit logging, and system-security-plan artefacts produced as the system is built rather than reverse-engineered for the assessor afterwards.

  4. Procurement-compliant sourcing through the VSI TechSource storefront with supply-chain provenance on every line item, asset tagging to your property system, and end-of-life sanitisation documented to your media-disposition policy.

  5. Delivery run in the structure your contracting officer expects: an integrated master schedule, earned-value visibility where the vehicle requires it, deliverable acceptance criteria written into the plan, and a single accountable point of contact with the authority to decide.

Where we start

Automation candidates

Deliberately mundane. The impressive-sounding workflow is rarely the one worth doing first.

  • Records and information requests: intake, redaction triage, response drafting
  • Correspondence: classification, routing, drafted response for review
  • Case handling: eligibility checks against the systems of record
  • Reporting: the recurring return somebody rebuilds by hand
  • Procurement documentation: assembly and consistency checking

Systems we integrate with here

If you run one of these, this is the conversation.

  • ServiceNow
  • Microsoft 365
  • Salesforce
  • SAP
  • Documentum

Our solutions

How we transform government & defense operations

What happens today, what changes, and what to watch for as each workflow is automated.

Records and information requests

Today
Requests arrive by several routes, get logged manually, and then wait for a reviewer to read every page and mark what has to be withheld. Redaction review is the bottleneck and it is done by people whose time is expensive and whose attention degrades over a long document.
After
Intake is normalised regardless of route, the request is classified against the exemption categories, and a first-pass redaction proposal is prepared with every proposed withholding tied to the exemption it relies on. The reviewer works from a marked-up document rather than a blank one.
What to watch
The proposal is a proposal. A wrongly released record cannot be unreleased, so the reviewer approves every withholding and every release, the agent narrows the reading, it does not make the decision. Any design that lets the automated pass release a page unreviewed is the wrong design.

Correspondence

Today
Incoming correspondence is read, classified by subject and sent to a team, which is a routing decision made by an experienced person doing work far below their grade. Drafting then starts from a template nobody can find quickly.
After
Classification and routing happen on arrival, with confidence stated, and a draft response is assembled from the approved language for that subject with the case-specific facts inserted from the record. The officer edits and approves.
What to watch
Correspondence that is actually a complaint, a legal notice, or a matter with a statutory clock has to be recognised as such and escalated rather than answered. The classification design has to fail toward escalation, not toward a confident wrong category.

Case handling

Today
An officer checks eligibility by opening three or four systems and reconciling what they say, which is where most of the handling time goes and where most of the inconsistency comes from.
After
The checks run against the systems of record and return a single position with the evidence attached and any conflict between sources surfaced rather than silently resolved. The officer makes the determination.
What to watch
A conflict between two systems is a finding, not an error to be smoothed over. If the agent picks a winner quietly, the officer loses the one signal that tells them to look harder.

Reporting

Today
A recurring return is rebuilt each period by someone who knows where the numbers live. When they are on leave it takes twice as long and the definitions drift.
After
The return is assembled from the source systems on a schedule, with the definitions applied consistently and any figure that moved beyond a threshold flagged for a human to look at before submission.
What to watch
Consistency is the point, so the definitions have to be agreed and written down first. Automating a return whose definitions are contested produces a fast, consistent, disputed number.

Procurement documentation

Today
Solicitation packages are assembled from prior packages, and the inconsistencies between sections are found by whoever reads it last, if at all.
After
Assembly from the approved clause library with a consistency pass across sections, dates, references, defined terms, and the requirements matrix against the statement of work.
What to watch
This one assists rather than authors. A contracting professional signs the package, and the value is the consistency check catching what a tired reader misses, not the drafting.

The operating picture

Where the agent layer sits in a mission-support cycle

Your operating loop todayThe agent layer we deploy into it
01

Intake

Requests, correspondence and casework arrive by portal, mail and phone.

Agent layer

Classifies and routes each item against your taxonomy, with the full text preserved for review.

02

Adjudication

A specialist works the case against policy and precedent.

Agent layer

Assembles the case file, prior contacts, relevant records, deadlines, so the specialist starts with context, not a search.

03

Response

Determinations are drafted, reviewed and issued.

Agent layer

Drafts from approved templates for human signature; nothing issues without a named approver.

04

Reporting

Workload, timeliness and backlog roll up to leadership and oversight.

Agent layer

Builds the recurring reports from live queue data instead of a month-end spreadsheet scramble.

The loop every programme office walks: work arrives, gets classified, gets processed, gets reported. The agent layer carries the routing and assembly at each stage; determinations that affect the public stay with a person, and every action lands in the audit trail.

Platforms and systems

Technology we work with in government & defense

The systems of record this sector runs on, and why each one matters to a deployment.

ServiceNow
Frequently the case and workflow platform of record. Integrating here rather than beside it is what keeps the audit trail in one place.
Microsoft 365
Where the correspondence actually lives, and where the records retention policy is enforced. Most correspondence automation is a Microsoft 365 integration problem before it is anything else.
Salesforce
Constituent and licensing systems are often built on it. The permission model is the design constraint, not the API.
SAP
Financial and procurement data. Read-only integration is usually the right first move, and often the only one that will be approved.
Documentum
Long-lived records repositories with retention rules that predate everything else in the estate and outrank them.

The constraint

What makes this sector harder

Nothing here is a technology problem first. It is an authorisation problem, a records-retention problem and a human-in-the-loop problem, and a deployment that treats those as paperwork does not reach production. The controls are the design input, not the obstacle.

The authorisation boundary decides the architecture. Whether a system can operate inside an existing boundary or would require a new one is the difference between a deployment measured in weeks and one measured in quarters, and it is a question to answer in the first conversation rather than the third month. Frequently the right design is a more constrained one that fits an existing boundary, and saying so early is worth more than a better architecture nobody can authorise.

Records retention is not a storage question. If an agent generates a draft response, that draft may be a federal record, and where it lives, how long it is kept, and whether it is retrievable are governed by a schedule that predates every system in the estate. Designing that in is straightforward; discovering it after go-live is a remediation project.

Human-in-the-loop is a design requirement rather than a reassurance. The specific decisions that must remain with a person, a determination, a release, a denial, anything with a right of appeal attached, get identified before the build, and the interface is designed so the person is genuinely deciding rather than approving a recommendation they have no practical ability to challenge. A confirm button on a decision nobody can inspect is automation wearing a human’s clothes.

And procurement shapes the sequencing more than the technology does. The work has to fit a vehicle, the vehicle has a period of performance, and the modernisation everybody wants may not survive a continuing resolution. Scoping in increments that each deliver something usable is not agile theatre here; it is how the work survives the funding calendar.

The United States Capitol dome with the flag flying, against a clear sky.

Compliance

Compliance that shapes government & defense deployments

The regimes your organisation operates under, and what each one constrains in a deployment. We design to these from the first architecture diagram, they describe your obligations rather than our credentials, and VSI's own position publishes only once it is substantiated.

Records retention schedules
Anything the system generates may itself be a record. Retention, disposition and retrievability get designed in, not added afterwards.
Section 508 and WCAG 2.2 AA
Any interface a citizen or an employee uses has to be accessible. This is a condition of sale rather than a quality goal, an inaccessible system is an unsellable system.
Privacy Act considerations
Systems of records carry their own notice and handling obligations, which constrain where data may be processed and what may be combined with what.
FAR-based procurement
The Federal Acquisition Regulation shapes how the work is bought, which shapes how it is scoped. Increments that each deliver something usable survive a funding calendar; a single large deliverable often does not.

How we work with public-sector and regulated buyers

Success stories

The track record behind the practice

Published engagements from adjacent sectors carry the same disciplines, programme governance, systems integration, workflow automation, that a government & defense deployment draws on. Every figure publishes under a named attestation.

Browse the case-study library

The first month

What starting looks like

What actually happens, week by week. Note where the design conversations sit, before the build, not after it.

  1. 01Week 1

    Sessions with the people who actually process the queue, not only their management

    Sessions with the people who actually process the queue, not only their management. The official process and the practised process both get written down, and the gap between them is the most valuable output of the week.

  2. 02Week 2

    Authorisation position established: which boundary this would live in, what the logging and retention obligations are, and which decisions must stay with a person

    Authorisation position established: which boundary this would live in, what the logging and retention obligations are, and which decisions must stay with a person. This is what determines whether the rest is weeks or quarters.

  3. 03Weeks 3-4

    One workflow built against real data in a non-production environment, with the human decision point in place

    One workflow built against real data in a non-production environment, with the human decision point in place. Small enough to finish, real enough to judge.

  4. 04End of month

    A go or no-go with the evidence attached, including an honest statement of what authorisation still has to happen before it can carry live work

    A go or no-go with the evidence attached, including an honest statement of what authorisation still has to happen before it can carry live work.

Next step

A free 20-minute government & defense assessment

Mission workflows, security posture and how the work gets contracted.

No preparation required and nothing to install. Bring the workflow that costs you the most hours; leave with a view of what we would automate first, what it depends on, and what we would not touch.

Book the free assessment

Questions

Asked often enough to answer here

Can this run inside our existing authorisation boundary?
That is the first question we answer, in week two, because it determines everything downstream. Often the answer is yes with a more constrained design than the ideal one, fewer external dependencies, processing kept inside the boundary, no new data flows. Where the honest answer is that a new authorisation would be needed, we say so with the likely timeline attached, because that timeline usually dwarfs the build and you should know it before committing.
What stays a human decision?
Anything with a right of appeal attached, anything constituting a determination, and any release or withholding of a record. Those get identified before the build and the interface is designed so the person is genuinely deciding, with the evidence in front of them and a real ability to disagree, rather than approving a recommendation they cannot inspect. A confirm button on an opaque recommendation is not human-in-the-loop.
How do you handle the gap between the written process and the real one?
By writing down both in the first week and treating the difference as the finding. Staff have usually built a workaround for a good reason, and it encodes knowledge the official process lost. Automating the documented process while ignoring the practised one produces a system that joins the list of things people work around.
Is the output a federal record?
Frequently, yes, a generated draft response can be. That means retention, disposition and retrievability have to be part of the design rather than a later question, and it is one of the reasons the records team belongs in week two rather than at go-live. This is straightforward to design in and expensive to retrofit.
How does this get bought?
Through whatever vehicle you hold or can reach, and the scoping follows the vehicle rather than the other way round. Increments that each deliver something usable are how the work survives a period of performance and a funding calendar. Our federal profile page carries the registration detail, and where a required registration is not yet confirmed it says so rather than implying it.
What about the previous system nobody uses?
It gets assessed honestly. Sometimes the right move is to integrate with it because it holds the record of authority; sometimes it is to route around it and be explicit that it is now a read-only archive. What does not work is pretending the workaround does not exist, because the workaround is where the actual process lives.