technologymonkey/courses Technology Monkey Ltd

Written course · 10 modules · no video

Your AI feature works. Now prove it's governed.

Someone has told you to make it compliant. They have not told you what that means in a pull request. This course answers that in code: the gateway, the audit schema, the approval workflow, the budget guard, and the queries that turn all of it into evidence.

For developers and engineering teams — not lawyers, not compliance officers. Implementation, not legal theory.

Read Module 1 free →

audit_record outcome: blocked
timestamp2026-08-28T21:14:07Z
actor_idsvc:ticket-triage
on_behalf_ofuser_8841
requested_modeldrafting-v2
served_model— (never dispatched)
outcomeblocked_dlp
dlp_findings["card_number"]
policy_version2026.08.1
A control that fired, recorded as a positive fact. Most teams log only successes — and then cannot demonstrate that any control does anything.

Who this is for

Written for

  • Developers shipping AI features into production
  • Tech leads asked to make a feature auditable
  • Engineering managers facing a customer security questionnaire
  • Anyone who owns the code behind an automated decision

Not written for

  • Lawyers or DPOs — this is not legal advice
  • Compliance officers looking for policy templates
  • Anyone wanting a framework overview without code
  • People after prompt engineering or model training

The modules

Cumulative rather than standalone. Module 2 builds a gateway with stub hooks; Modules 4, 5 and 6 fill them in; Modules 7 and 8 consume the data that results. Exercises accumulate too — the gap list you write in Module 1 becomes the rollout plan in Module 10.

01 AI Governance Foundations for Engineers

What governance means at the code level, the regulatory map without the legalese, and where controls belong in your architecture.

Free
02 Building the AI Gateway Layer

The single choke point that makes governance enforceable rather than optional — provider abstraction, error taxonomy, failover, and the hook pipeline every later module plugs into.

Core
03 Human-in-the-Loop Workflow Design

When a human gate is real oversight and when it is theatre — selective routing, escalation, queue starvation, and the review screen that decides whether either happens.

Core
04 Audit Logging and Traceability

Why application logs are not audit logs, a full request-lifecycle schema, append-only storage, and designing so that erasure is a query rather than a crisis.

Practitioner
05 Cost Governance and Rate Limiting

Attribution before enforcement, token-aware limiting with reserve-and-settle, effective-dated pricing, and the per-trace budget that stops a runaway agent loop.

Core
06 Prompt Injection and DLP Basics

Why filtering is detection and not a boundary, the architectural controls that actually hold, and building a DLP scanner that logs categories rather than values.

Core
07 Model Drift and Output Quality Monitoring

The four things people call drift, pinning and deprecation planning, a golden-set evaluation harness, and the production signals you are already discarding.

Practitioner
08 Compliance Reporting — Turning Logs into Evidence

What auditors and enterprise customers actually ask, the mapping layer from claim to query, deterministic reports, and subject access as an engineering workflow.

Core
09 GDPR-Relevant Considerations for AI Features

Where personal data really enters an AI system, minimisation as a whitelist rather than a filter, crypto-shredding for erasure, and the DPIA and subprocessor triggers to recognise.

Practitioner
10 Rolling Out Governance Without Stalling Delivery

Sequencing in five phases where each is independently useful, avoiding quiet bypass of the gateway, and making the case to the audience whose support you need.

Practitioner

Pricing

One-off payment, lifetime access, all future updates included. Buy Core and upgrade later for the difference.

Core

£99

6 modules · the build-it path

  • Foundations, gateway and HITL design
  • Cost governance and rate limiting
  • Prompt injection and DLP
  • Compliance reporting
  • Companion code repository
Notify me at launch

Practitioner

£199

All 10 modules · audit-ready

  • Everything in Core
  • Full audit logging schema
  • Model drift and evaluation harness
  • GDPR for AI features
  • Rollout without stalling delivery
Notify me at launch

Team

Invoice / 5+ seats

For engineering teams

  • Practitioner access per seat
  • Invoiced directly, UK VAT reverse charge
  • Volume pricing from five seats
Get in touch

Who wrote it

I'm Ken Herring, a full-stack developer and Head of Development at a UK SaaS company. This course came out of building the thing it describes: a multi-provider AI proxy spanning Anthropic, OpenAI, Google and Mistral, with cost governance, human-in-the-loop workflows, audit logging and compliance reporting layered on top.

Several modules include notes on what that build got wrong the first time — the mandatory metadata field that wasn't mandatory, the review schema that stored a boolean, the pricing table with no effective dates. The design decisions in this course are the ones I'd make differently with hindsight.

Questions

What format is it?

Written lessons with code, read in the browser or downloaded as PDF. No video. Roughly 13–16 hours including the exercises, at your own pace.

What language are the code examples in?

The patterns are language-agnostic pseudocode, so they transfer to any stack. The companion repository has runnable implementations in Node/TypeScript.

Is this legal advice?

No. It's engineering guidance on building systems that can satisfy legal and audit requirements. The judgement calls — lawful basis in particular — belong with your DPO or counsel. The course gives you the vocabulary to have that conversation productively.

Do I need to be senior?

You need to be comfortable reading code and thinking about system design. No prior compliance knowledge is assumed — that's rather the point.

Can I upgrade from Core to Practitioner?

Yes, at any time, for the difference in price.

Refunds?

Fourteen days, no questions. Module 1 is free so you can judge the writing before paying anything.

Launching shortly

Checkout opens once payment processing is approved. Leave an email and I'll tell you the day it does — nothing else, no sequence.