Engineering practice and AI governance, installed by the principals who built the substrate.
Four anchored sub-products covering Claude Code governance at engineering-org scale, MCP server authoring for agent-readable docs, and discord-ops automation for orgs that run engineering in Discord. Anchored on REA, HELiXiR, and discord-ops — the open-source projects BST publishes.
Most "AI governance" is a slide deck. The middleware that actually stops a bad tool call is somebody else's problem.
Engineering orgs are rolling out Claude Code, Cursor, and agentic tooling at pace. The leadership question that lands a few weeks in is the same every time: who has the kill switch, what is the audit trail, and where is the policy that decides what an agent is allowed to touch?
The honest answer in most shops is “nobody, none, and we have not written one.” The available remedies are mostly slide decks dressed up as governance — a policy doc with no enforcement, a runbook nobody runs, or a vendor framework that your engineers immediately bypass because it does not match how they actually work.
You need agentic governance installed in the repo where the agents run. Hash-chained audit so the trail is not editable. A kill switch your security team can pull. Autonomy levels and blocked-path policy that survive a reorg. And — separately but adjacently — your component library, your internal API, and your engineering-org Discord need to be agent-legible without leaking out from under your governance perimeter.
BST is a senior engineering consultancy that goes deep on AI tooling because we build it. REA is the agentic infrastructure project we publish; HELiXiR is the MCP server we ship for HELiX; discord-ops is the Discord MCP we run for engineering orgs that live in Discord. The cluster is the practice install; the OSS is the substrate. We are principal-led — a small senior team — not a deployment-services arm of a framework vendor.
The four anchored sub-products
-
AI Code Generation Practice Install (REA) — Coming Wave 2
Agentic governance for Claude Code adoption at engineering-org scale. Hash-chained audit trail, kill-switch enforcement, and the 13-layer middleware pipeline that ships in REA — installed and tuned to your autonomy posture, blocked-path policy, and review gates. The right fit when "we are rolling out Claude Code" needs to mean something more rigorous than a generic policy doc. Anchored on REA, the open-source agentic-infrastructure project BST publishes.
-
MCP Server Authoring (HELiXiR-shaped) — Coming Wave 2
Building agent-readable documentation for your component library, internal API, or design system as an MCP server — so agents stop hallucinating prop names, event shapes, and slot behavior. Authored in the same shape as HELiXiR, the MCP server BST published for HELiX. The right fit for a platform team tired of agents guessing at internal contracts. Anchored on HELiXiR.
-
discord-ops Team Install — Coming Wave 2
Discord MCP server install plus multi-guild routing for engineering orgs that run their stand-ups, oncall handoffs, and roadmaps in Discord rather than Slack. Channel-aware automation, audit-friendly message routing, and brand boundaries between guilds. The right fit when the engineering org already lives in Discord and the AI tooling needs to respect the rooms it speaks in. Anchored on discord-ops.
-
discord-ops Brand Voicing — Coming Wave 2
Companion engagement to the discord-ops install — voice and persona scaffolding for your Discord presence so the bot voice carries the brand voice and stays consistent across guilds, channels, and message types. The right fit when the Discord presence is half-formed and the bot voice keeps drifting from the brand voice. Sells alongside or after the team install.
How to choose
-
Rolling out Claude Code at engineering-org scale
Wave 2Deliverable AI Code Generation Practice Install (REA)
You need governance, audit, and a kill switch — not a generic policy doc. The install is REA tuned to your autonomy ceilings, blocked paths, review gates, and audit retention. Sub-page published in Wave 2.
-
Agents hallucinating against your component library or API
Wave 2Deliverable MCP Server Authoring (HELiXiR-shaped)
Build agent-readable docs as an MCP server so the agent reads ground-truth from CEM / OpenAPI / your design system instead of guessing. Sub-page published in Wave 2.
-
Engineering org runs in Discord, needs MCP-driven automation
Wave 2Deliverable discord-ops Team Install
Discord MCP server install with multi-guild routing, channel-aware automation, and audit trails. Stand-ups, oncall, roadmaps — wired to respect channels, brands, and audit. Sub-page published in Wave 2.
-
Discord presence is half-formed; bot voice off-brand
Wave 2Deliverable discord-ops Brand Voicing
Voice and persona scaffolding so the bot voice carries the brand voice across guilds and message types. Often sold alongside or after the team install. Sub-page published in Wave 2.
-
Scope outside the kitted four
BespokeDeliverable Request a bespoke scope
Multi-org agent governance, custom MCP server portfolios, multi-guild Discord brand programs, and engineering-practice retainers are sold bespoke under the cluster patterns. We return a draft SOW within five business days.
Pricing posture
Engagement model Combined cap with bundled discount
Cluster pricing varies by sub-product and lands on each sub-page in Wave 2. Directional anchors: REA install is the entry-point engagement; MCP server authoring scales with library / API surface area; discord-ops team install scales with guild and channel count; brand voicing is the smallest of the four. Combined caps with a bundled discount are available when two or more land in the same engagement window. Bespoke scopes (multi-org governance, custom MCP portfolios, multi-guild brand programs, engineering-practice retainers) return a draft SOW within five business days. All published anchors are time-and-materials with a not-to-exceed cap, per the BST Engagement Model.
Anchor pricing reflects typical engagement ranges. Actual fees are scoped per engagement under time-and-materials with a not-to-exceed cap. Pricing shown does not constitute a binding offer.
Frequently asked questions
Why BST for engineering practice and AI governance?
What does the REA install actually deliver?
- Hash-chained audit log
- Kill-switch (HALT) enforcement
- Autonomy levels (L0–L3) tuned to your team
- Blocked-path policy
- The 13-layer middleware that gates tool invocations
What is an MCP server and why would I need to author one?
Do I have to use Discord for the discord-ops install?
When will the sub-pages be live?
Can you do all four engagements at once?
Do you offer ongoing retainers?
How does this relate to your AI Security Review?
Often combined with
-
AI Security Review
When the engineering org adopting Claude Code also needs an audit of the AI surface itself. Governance install here, OWASP / agentic lens there. Common attach for first-time agentic deployments.
-
Healthcare AI Compliance Review
When the engineering practice covers a PHI-touching surface and the governance install needs to land under HIPAA / BAA / SaMD doctrine.
Ready to install the practice?
Four anchored sub-products. Principal-led senior team. The OSS substrate published, audited, and supported by the same firm that runs the engagement.