The build is four weeks. Your process is the timeline.
For multi-site operations, the constraint is never delivery speed. It is security review, procurement, change management and getting three regions to agree on a job code. This page is about that half of the work.
Four things that are different above a few hundred users
Security review comes first, not last
Bring your reviewer to the first call. The AI boundary, access model and audit design are the questions that decide the timeline, and answering them at week six is how projects slip a quarter.
Rollout is site by site
Prove one terminal, one vessel or one district for a full cycle before the second. Simultaneous multi-site launches fail for organizational reasons, not technical ones.
Terminology has to be negotiated
Three regions with three sets of job codes is a governance problem the software surfaces rather than solves. It is better surfaced in scoping than in week five of a rollout.
Integration determines the estimate
Which systems must keep working, who owns them internally, and whether they have interfaces. This is usually the single largest driver of a multi-site timeline.
Beyond the standard footprint
Documented review support
Architecture, access model, pre-flight scope and the AI boundary, provided in writing under NDA for your security and procurement teams to work from.
Multi-site deployment design
How districts, regions or vessels are separated, what is shared, and how row-level access maps to your organizational structure.
Named delivery
Knomatic delivery or a certified partner who knows your sector, with escalation defined before you need it rather than after.
Contracted terms
Commercial terms, data handling, exit and support commitments negotiated rather than accepted from a click-through.
Enterprise questions
How long does an enterprise rollout actually take?
The first build is typically four weeks to a production pre-flight review. The calendar around it is governed by security review, procurement and internal approval, which commonly take longer than the build. Genwright compresses delivery, not your buying cycle, and any vendor telling you otherwise has not met your procurement team.
Can different sites have different configurations?
Yes, within one deployment. Row-level security and role design map to your organizational structure, so districts or regions can differ where they genuinely differ and share where they should. Deciding which is which is part of scoping.
What does the security review usually ask for?
Architecture and data flow, the access and audit model, the AI boundary, hosting and residency, backup and restore, subprocessors, and export and deletion. All of it is answerable in writing before contracting — see the security page.
Do we get a dedicated environment?
Deployment isolation options are discussed during scoping and depend on your requirements and the commercial arrangement. Ask specifically rather than accepting a general assurance; the answer has cost implications and should be in writing.
Bring procurement and security to the first call.
It feels early. It is the single thing that most reliably shortens an enterprise timeline.