Frequently Asked Questions
Clear answers about our methodology, products, and technical terms. Everything you need to know to make decisions.
About WatchZ
WatchZ is a consulting firm specialized in technology capability evolution with direct impact on financial results.
Unlike traditional consultancies, we don't just deliver diagnostics. We evolve your company's technology maturity with proprietary methodology and result metrics.
Our slogan is "Technology that drives results" because we believe technology only makes sense when it generates measurable business value.
We work with technology executives and leaders from mid-size and large companies:
- CTOs and CIOs
- COOs and CFOs
- VPs and Heads of Engineering
- Technology Directors
Our clients include companies like Hapvida, Tok&Stok, Infracommerce, Braspress, Burger King, Popeyes, Subway, Starbucks, and L'Occitane.
Three main differentiators:
- Alignment-First: We connect each technology capability to a clear business outcome. Every investment in technology has direct impact on financial results.
- Capability Economics: We translate each technical gap into monthly cost and each improvement into return. You know exactly how much immaturity costs and how much each evolution returns.
- AI as a cross-cutting layer: AI is not an isolated item. It shows up inside every capability, from Platform Engineering to Data & Analytics. Technology is the starting point, financial results are the measure.
Methodology
Technology capabilities are organizational abilities to execute technical functions repeatedly and scalably.
Unlike projects that end, capabilities evolve continuously. WatchZ works with six structural capabilities and Artificial Intelligence as a cross-cutting layer that shows up inside all of them:
- Platform Engineering
- High-Performance Teams
- Enterprise Architecture
- Software Engineering & Architecture
- Security Engineering
- Data & Analytics
AI runs through them all: detects degradation in Platform, accelerates review in Software, maps bottlenecks in Architecture, identifies vectors in Security, delivers insight in Data.
- M1 (Reactive): Ad-hoc, dependent on heroes, no connection to strategy.
- M2 (Repeatable): Documented processes, inconsistent execution.
- M3 (Defined): Organizational standard, consistent execution.
- M4 (Managed): Metrics-driven, predictable, data-based improvement.
- M5 (Optimized): Continuous improvement, innovation, market benchmark.
Important: Not every capability needs to reach M5. The target level is defined by business impact. Some capabilities stop at M3 by economic decision.
Each capability is evaluated across 7 dimensions:
- Strategy & Purpose: Does the capability have a clear role in results?
- Processes & Flow: Is the flow clear, repeatable, predictable?
- Technology & Automation: Real automation or heroic scripts?
- People & Organization: Who owns it? Is there hero dependence?
- Governance & Decision: Who decides changes? Is there a roadmap?
- Data & Analytics: Does data enable decision and analytics connect to margin and revenue?
- Economic Impact: What is the financial result impact? (our differentiator)
A Gap is the distance between current maturity and target maturity of a capability.
For example: if your Platform Engineering is at M2 and the target is M4, you have a 2-level gap. Each gap has a monthly financial cost that we calculate in the Assessment.
Products
The Capability Assessment is an executive technology maturity diagnostic conducted in 47 days (7 weeks).
You receive:
- Maturity Map: M1-M5 level per capability
- Financial Impact: Monthly cost of each gap
- Prioritized Roadmap: Actions ordered by return
- Quick Wins: 30-day actions with immediate results
- Market Benchmark: Comparison with your segment
- Risk Assessment: Map of technical and operational risks
The Capability Assessment takes exactly 47 days (7 weeks):
- Week 1: Kick-off, stakeholder alignment, system access
- Weeks 2-4: Discovery with interviews and metrics analysis
- Weeks 5-6: Data consolidation and financial impact calculation
- Week 7: Executive delivery to C-Level and detailed technical report
The Evolution Program is a capability evolution program organized in quarterly waves.
After the Assessment identifies gaps, the Evolution Program executes the evolution of priority capabilities with:
- Measurable goals per quarterly wave
- Continuous monitoring
- DORA and business metrics
- Knowledge transfer
- Measurable ROI at the end of each quarter
The Operating System is a continuous sustenance model that maintains and evolves capabilities after the Evolution Program.
Includes:
- 24x7 Operation: Dedicated or shared specialists
- Health Dashboard: Real-time visibility
- Defined SLAs: Availability, performance, response time
- Proactive Evolution: Identifying improvements before they become gaps
- Monthly Executive Report: Performance, incidents, ROI
- Team Enablement: Onboarding and technical workshops
The goal is to protect investment and ensure sustained M4-M5 maturity. 80% of transformations lose gains in 12 months. The Operating System prevents this.
The typical journey is: Assessment โ Evolution Program โ Operating System.
Assessment is the entry point because it establishes the baseline and identifies priorities with financial impact. Without it, it's difficult to prioritize investments objectively.
In specific cases, we can adapt. Talk to us to understand your context.
Commercial
Investment in the Capability Assessment varies according to scope and number of capabilities assessed.
Contact us for an initial conversation. Within 24 business hours a specialist will get back to align your needs and present the appropriate proposal for your context.
We serve mid-size and large companies with technology teams of 20+ people.
Our clients include companies like Hapvida, Tok&Stok, Infracommerce, Braspress, Burger King, Popeyes, Subway, Starbucks, L'Occitane, among other market leaders.
WatchZ works exclusively with companies (B2B).
Corporate email helps us direct you to the right specialist and ensures the conversation is with someone who can make decisions.
Personal emails (@gmail, @hotmail, @outlook, etc.) are not accepted in contact forms.
A specialist will contact you within 24 business hours after form submission.
Currently our focus is the Brazilian market, but we have the capacity to serve companies in Portuguese and English.
Contact us to discuss your specific case.
Platform Engineering
Platform Engineering is the discipline of building and maintaining internal platforms that enable developers to deliver software with autonomy and velocity.
Key data (Gartner):
- 75% of organizations with platform teams now operate Internal Developer Portals
- Organizations without AIOps face increasing operational fragility as complexity scales
- Demand for platform engineering skills grew exponentially from 2020 to 2022
Platform Engineering solves the problem of product teams lost in tool complexity and fragmented workflows.
Internal Developer Portal is a self-service portal that unifies tools, documentation, and workflows in a single interface.
Works as an internal "app store" with:
- Day 0 (Discover and Create): Templates, golden paths, service catalog
- Day 1 (Integrate and Deploy): CI/CD, infrastructure, APIs
- Day 2 (Operate and Improve): Monitoring, observability, incident management
Examples: Backstage (open-source by Spotify), Humanitec, Mia-Platform. Companies like American Airlines and Adidas built their own portals based on Backstage.
AIOps (AI for IT Operations) applies AI to automate and improve IT operations.
Two main approaches:
- Deterministic AI: Step-by-step fault tree analysis. Precise and explainable results. Automatic root cause analysis
- Machine Learning AI: Correlates metrics and events. Suggests probable causes. Requires historical data for training
Proven benefits:
- 90% faster incident triage
- 52 billion dependencies analyzed per day in enterprise environments
- Auto-remediation: Problems fixed before users notice
Monitoring answers "is the system up?". Observability answers "why is the system slow?".
The three pillars of observability:
- Metrics: Numbers showing behavior (CPU, latency, throughput)
- Logs: Discrete events with context
- Traces: Journey of a request through services
The difference is correlation. Monitoring shows isolated problems. Observability shows the problem path through topology maps and service flows.
High Performance Teams
Team Topologies is a team structuring model created by Matthew Skelton and Manuel Pais.
Defines 4 fundamental team types:
- Stream-aligned: Focused on business value flow. End-to-end product owner
- Platform: Provide self-service capabilities for other teams
- Enabling: Help other teams overcome knowledge gaps
- Complicated Subsystem: Manage complex parts requiring specialized expertise
The model reduces cognitive load and increases autonomy. Stream-aligned teams deploy 4.7x more than traditional structures.
DORA Metrics are 4 metrics developed by DevOps Research and Assessment that correlate with engineering performance:
- Deployment Frequency: How often do you deploy to production?
- Lead Time for Changes: How long from commit to deploy?
- Change Failure Rate: What % of deploys cause incidents?
- MTTR (Mean Time to Recovery): How long to restore service?
Elite vs Low Performers:
- Elite: on-demand deploy, lead time < 1h, MTTR < 1h, change failure < 15%
- Low: monthly deploy, lead time > 6 months, MTTR > 1 week, change failure > 46%
Developer Experience (DX) refers to all aspects of interaction between developers and the tools, platforms, processes and people they work with.
Three essential pillars (Gartner):
- Smooth journeys: Fast onboarding, self-service DevOps, accelerated feedback loops
- Creative work: Focus time, automation of repetitive tasks, collaborative environment
- Meaningful impact: Contributing to community, freedom to experiment, direct user feedback
38% of engineering leaders cite talent retention as top 3 challenge. Superior DX is competitive advantage for attracting and retaining talent.
Cognitive load is the amount of mental processing needed to do work. High load = low productivity and burnout.
Reduction strategies:
- Clear boundaries: Defined scope per team. "You own X, not Y"
- Internal platforms: Abstract infra complexity. Devs focus on code, not Kubernetes
- Living documentation: Not static PDFs, but docs integrated into workflow
- Protected focus time: Meeting-free blocks for deep work. 34% suffer from constant interruptions
Result: -40% cognitive load with well-applied Team Topologies structures.
Enterprise Architecture
The 6Rs are strategies for legacy application modernization:
- Rehost (Lift-and-Shift): Move to cloud without changes. Fast, but not optimized
- Replatform (Lift-Tinker-Shift): Small optimizations during migration (e.g., managed database)
- Refactor/Re-architect: Redesign application for cloud-native. Most effort, most benefit
- Repurchase: Replace with SaaS (e.g., swap legacy ERP for Salesforce)
- Retire: Decommission. 30-40% of systems are redundant or unused
- Retain: Keep as-is. Not everything needs to change now
WatchZ helps prioritize by ROI and risk, not technical complexity.
ADRs are short documents that record significant architecture decisions along with their context and consequences.
Typical structure:
- Title: Decision in one sentence
- Status: Proposed, accepted, deprecated, superseded
- Context: What motivated this decision?
- Decision: What did we decide to do?
- Consequences: What results from this decision? Tradeoffs?
ADRs avoid the "why did we do this again?" 2 years later. They're versioned with code and serve as organizational memory.
Technology Radar is a tool for technology portfolio management, popularized by ThoughtWorks.
Organizes technologies in 4 rings:
- Adopt: Ready for use. Recommended as standard
- Trial: Use in specific projects to gain experience
- Assess: Explore to understand potential. Don't use in production
- Hold: Don't start new projects. Migrate gradually
The radar is organization-specific. What's "Adopt" for Google might be "Assess" for a traditional bank. Context matters.
Anti-Overlap is the practice of identifying and eliminating redundancy of systems and capabilities.
The problem:
- Companies accumulate systems over years: acquisitions, parallel projects, "temporary solutions"
- Portfolio assessments reveal 30-40% overlap in large companies
- Each redundant system has cost: license, infra, maintenance, training, integration
The solution:
- Capability mapping: Map what each system does vs. what business needs
- Consolidation: One system per capability. Each problem solved once
- Typical result: -30% to -40% infrastructure cost
Software Engineering & Architecture
Domain-Driven Design is a software modeling approach that puts the business domain at the center of technical decisions.
Main concepts:
- Ubiquitous Language: Shared language between devs and domain experts. Code speaks business language
- Bounded Context: Explicit boundaries where a model applies. "Customer" can mean different things in different contexts
- Context Mapping: How bounded contexts relate (Partnership, Customer/Supplier, Anticorruption Layer)
When to use: Complex systems where domain is competitive differentiator. When not to use: Simple CRUDs, short projects.
They are variations of the same principle: dependencies point inward (toward domain/business rules).
- Clean Architecture (Uncle Bob): Entities โ Use Cases โ Controllers โ Frameworks. Well-defined layers
- Hexagonal/Ports & Adapters (Alistair Cockburn): Ports (interfaces) and Adapters (implementations). Domain at center
- Onion Architecture (Jeffrey Palermo): Onion-like layers. Domain Model โ Domain Services โ Application Services โ Infrastructure
Common benefit: frameworks and databases are implementation details. You can swap PostgreSQL for MongoDB without rewriting business rules.
Evolutionary Architecture is architecture that supports guided, incremental change as a first principle.
Key concepts:
- Fitness Functions: Automated tests validating architectural characteristics (e.g., "no module can depend directly on database")
- Incremental change: Frequent small evolutions vs. big rewrites
- Reversible decisions: Prefer decisions that can be easily undone
Fitness function examples: "Build time < 10 min", "Test coverage > 80%", "No cyclic dependencies between modules".
There's no universal answer. Depends on context.
Modular Monolith when:
- Small team (< 20 people)
- Domain not yet clear
- Latency between services is a problem
- Operations lack maturity for distributed orchestration
Microservices when:
- Large, independent teams
- Clear and stable bounded contexts
- Need to scale parts of system independently
- Mature Platform Engineering (CI/CD, observability, service mesh)
Tip: start with modular monolith. Extract microservices when boundaries become clear and pain justifies complexity.
Security Engineering
Shift-Left means moving security to the beginning of development cycle, not leaving it to the end.
Cost of fixing vulnerabilities:
- Development: $80 (code still fresh, easy to change)
- Build/Test: $240 (3x more expensive)
- QA: $960 (12x more expensive)
- Production: $7,600 (95x more expensive!)
Shift-left tools:
- SAST: Static analysis on code (finds SQL injection before running)
- SCA: Dependency analysis (does that lib have a CVE?)
- DAST: Dynamic analysis in test environment
Result: -80% production vulnerabilities with well-implemented shift-left.
Threat Modeling is identifying threats and vulnerabilities before writing code.
Most common framework - STRIDE:
- Spoofing: Can someone pretend to be another user?
- Tampering: Can data be improperly altered?
- Repudiation: Can actions be denied without trace?
- Information Disclosure: Can sensitive data leak?
- Denial of Service: Can system be taken down?
- Elevation of Privilege: Can user gain improper permissions?
When to do: during new feature design, before third-party integrations, in architecture reviews.
Security Champions are developers who act as security ambassadors in their teams.
Typical model:
- 1 champion per squad (10-15% of time dedicated to security)
- Continuous training by central AppSec team
- Community of practice with regular meetings
- Responsible for security code review and threat modeling in team
Benefits:
- Distributed security scales better than central team
- Problems found earlier by those who know the code
- Security-first culture multiplied organically
Result: +5x security awareness across organization.
According to Gartner, 80% of AI/data violations come from broken internal policies, not external hackers.
Main internal causes:
- Misconfigurations: Public S3 buckets, open ports, default passwords
- Excessive privileges: Everyone has admin on everything
- Shadow IT: Unauthorized systems with sensitive data
- Lack of automation: Policies exist but aren't verified
Solution - Compliance as Code:
- Policies defined as code, not documents
- Automated verification in CI/CD
- Drift detection: "someone manually changed this config"
- Continuous auditing, not annual
Artificial Intelligence
According to Gartner research, despite an average investment of $1.9 million in 2024, less than 30% of CEOs are satisfied with AI ROI.
Main reasons:
- Lack of AI Engineering: 57% of companies admit their data is not AI-ready
- Unrealistic expectations: Successful companies expect 2-4 year ROI cycles, not immediate results
- Absence of governance: Companies with AI Governance platforms are 3.4x more effective
- GenAI without use case: 30% of GenAI projects are abandoned after PoC without proper governance and scaling strategy
WatchZ addresses these issues with AI Engineering as foundation, AI Governance (TRiSM) as protection, and focus on use cases with validated ROI.
AI Engineering is the discipline that sustains AI in production at scale. According to Gartner, it's "climbing the slope of enlightenment" in the Hype Cycle and will be mainstream in 2-3 years.
Includes:
- AI-Ready Data: Feature engineering, data quality, ingestion pipelines
- Scalable infrastructure: Training environments, serving, and monitoring
- Engineering practices: Model versioning, testing, automated deployment
- Model Operations: Complete model lifecycle in production
57% of companies don't have AI-ready data. Without AI Engineering, GenAI becomes an expensive experiment that never reaches production.
AI TRiSM (Trust, Risk, and Security Management) is the Gartner framework for AI governance. It's not bureaucracy. It's protection.
Important data:
- 80% of AI violations come from broken internal policies, not external attacks
- 3.4x more effectiveness in companies with AI Governance platforms vs. without governance
- 20% reduction in regulatory costs with structured governance
- 25% of large companies will have dedicated AI Governance teams by 2027 (was <1% in 2023)
The AI Governance platform market exceeds $1 billion by 2030, driven by EU AI Act, NIST AI RMF, and ISO 42001.
Gartner shows a stark difference:
- 45% of mature companies keep AI projects in production for 3+ years
- Only 20% of immature companies achieve the same
What mature companies do differently:
- Rigorous financial analysis: 63% conduct ROI analysis and measure customer impact
- Dedicated budget: Commit 20%+ of digital budget to AI
- People before technology: Invest 70% of AI resources in people and processes
- Governance from the start: AI Governance platforms implemented
- Realistic expectations: Expect 2-4 year ROI cycles
In the Gartner Hype Cycle, GenAI has fallen from the "Peak of Inflated Expectations" to the "Trough of Disillusionment". This means organizations are confronting reality after the hype.
What's happening:
- 30% of GenAI projects are abandoned after PoC without proper governance and scaling strategy
- Main causes: Poor data quality, inadequate risk controls, escalating costs, unclear business value
- Hallucinations and bias: Real problems that weren't solved by marketing promises
This doesn't mean GenAI is bad. It means the hype is over and companies need solid foundations (AI Engineering, Governance) to extract real value.
WatchZ treats AI as a cross-cutting capability, not a technology experiment.
Our approach:
- AI Engineering first: We build the foundation that 57% of companies lack. AI-ready data, pipelines, infrastructure
- AI Governance (TRiSM): Structured governance that delivers 3.4x more effectiveness
- MLOps in production: Models that work, not notebooks that impress
- Measurable ROI: Validated use cases with calculated financial impact
Our method is designed to take projects from PoC to production with governance and defined success criteria.
Data & Analytics
"Without data, you're just another person with an opinion." (W. Edwards Deming)
Data & Analytics is the capability that transforms raw data into business decisions. Without it, strategy becomes guesswork and operations become improvisation.
It covers 4 dimensions:
- Data Engineering: Pipelines, ingestion, quality and data availability
- Analytics & BI: Dashboards, reports and analyses that inform decisions
- Data Governance: Policies, cataloging, lineage and data compliance
- Data Strategy: Alignment between data strategy and business objectives
Data & Analytics is the foundation. Artificial Intelligence is the acceleration.
Without organized, governed, and accessible data, AI doesn't work. 73% of AI projects fail due to data problems, not algorithm issues.
- Data & Analytics: Answers "what happened?" and "why did it happen?"
- Artificial Intelligence: Answers "what will happen?" and "what should we do?"
Both capabilities complement each other. Data & Analytics provides the foundation for AI to generate real value.
Data Governance is the set of policies, processes, and responsibilities that ensure data is reliable, secure, and usable.
Without governance:
- Each department has "its own truth" in different spreadsheets
- Decisions are made with outdated or incorrect data
- Compliance with LGPD/GDPR is at risk
- AI projects fail due to inconsistent data
With mature governance, data becomes a strategic asset. Without it, it's an operational liability.
Who trusts us
Market leaders evolve their capabilities with us. From banks to retail, from healthcare to logistics. Companies that decide by result choose WatchZ to reposition the technology capability that sustains growth, result and performance.




















Didn't find your answer?
Get in touch. Our team is ready to clarify your questions.

