How-to guides

How to build, run, validate and govern AI you control

Each guide gives the short answer first, then numbered steps with copyable commands, what you should see, a troubleshooting table and a checklist to confirm it worked. Every guide carries the date its commands were last checked and the official sources used.

26 guides.

Build

Make a model, an agent, a knowledge layer or a retrieval system that runs on your own data.

  • How to Build a Company Brain for AI: A Practical Guide

    Build a permission-aware knowledge layer for AI: resolve identities, copy access lists from each source, keep provenance, retrieve under access control, and test freshness and leaks.

    • Intermediate
    • Two to three days for one source and one team, then about a week per extra source
    • 9 steps
  • How to Build a RAG System: Step-by-Step, Runs Locally

    Build a retrieval-augmented generation system end to end on one machine, with hybrid search, per-group permissions, citations and a retrieval test set.

    • Intermediate
    • About 90 minutes to a working system, plus time to collect your own documents
    • 9 steps
  • How to Build an AI Agent in 2026 (Code & No-Code)

    Build an agent as a loop with tools, a turn budget and an eval set: define a narrow job, pick a build path, connect tools, choose models per step, test, deploy and observe.

    • Intermediate
    • About an afternoon for the loop; longer for the eval set
    • 6 steps
  • How to Choose an LLM for Your Company: A Scorecard

    A selection process, not a leaderboard: requirements, a hosted and open-weight shortlist, a test on your own tasks, a weighted scorecard, licence and data-terms checks, and an exit plan.

    • Beginner
    • About 2 to 5 working days, mostly collecting the test cases and reading terms. The test runs themselves take hours.
    • 7 steps
  • How to Create Your Own Local Model: LoRA to GGUF

    Adapt a small open-weight model to your own examples on one machine, convert it to GGUF, run it locally and check it beats the base model on cases it has not seen.

    • Advanced
    • About 1 day for a first working model: a few hours for data, then training time that depends on your hardware and example count.
    • 9 steps
  • How to Fine-Tune an LLM on Your Own Data (2026)

    The decision and the method: when fine-tuning beats prompting and retrieval, how to build and split the dataset, two training routes, how to evaluate, and what it really costs.

    • Advanced
    • About 1 to 2 weeks end to end, most of it on data and evaluation. The training run itself is usually the shortest part.
    • 7 steps

Deploy

Run models on hardware and in regions you choose, from a laptop to an air-gapped site.

  • How to Build an Air-Gapped AI Environment (2026)

    Stage model weights, container images and Python packages on a connected machine, verify and carry them across, run the model with every online lookup switched off, and prove nothing leaves.

    • Advanced
    • Allow one to two days for the first environment, mostly waiting on downloads, transfers and approvals. Later updates take a few hours.
    • 8 steps
  • How to Deploy an LLM in the EU: Data Residency Steps

    Choose between EU-region hosted APIs, a self-hosted open-weight model on EU infrastructure, or on-premises, then check storage, processing, logs, support access and sub-processors, and test where requests actually run.

    • Intermediate
    • About half a day to choose and configure a hosted EU option; one to two days to add a verification test and write the record. Self-hosting adds the time in the self-hosting guide.
    • 7 steps
  • How to Run LLMs Locally: Ollama, LM Studio, llama.cpp

    Install Ollama, LM Studio or llama.cpp, download a model that fits your memory, chat with it and call it from code through a local OpenAI-compatible endpoint.

    • Beginner
    • About 20 to 30 minutes, most of it downloading the model.
    • 7 steps
  • How to Self-Host an LLM with vLLM (2026 Guide)

    Serve an open-weight model as a private, OpenAI-compatible endpoint on your own GPU server, with memory sizing, authentication, TLS, metrics and an upgrade routine.

    • Advanced
    • About 2 to 3 hours for a first working endpoint; add a day for hardening, monitoring and a load test.
    • 9 steps
  • How to Self-Host a ChatGPT Alternative (Open WebUI)

    A hands-on setup of Open WebUI in front of a model you host, with admin accounts, roles, HTTPS, backups and a clear view of where prompts go.

    • Intermediate
    • About 1 to 2 hours for a working pilot, plus time for single sign-on and a short policy for users.
    • 9 steps

Validate

Test whether a model or a system does the job before you rely on it, and keep testing.

  • How to Audit AI Systems: Scope, Evidence, Findings

    How to audit an AI system, internally or for a client: scope it, choose criteria, request and sample evidence, test logs, change control and human oversight, and write findings that can be fixed.

    • Intermediate
    • Two to four weeks for one system, depending on how quickly evidence arrives
    • 10 steps
  • How to Evaluate an Open-Source LLM: Hands-On Steps

    Check the licence first, write a small task set of your own, run it against the full-precision and quantised model, add a public benchmark as a sanity check, measure speed and memory, and write down the decision.

    • Intermediate
    • About 4 hours for one candidate, plus the time to write your task set
    • 9 steps
  • How to Validate Your AI: Eval Sets, Gates, Evidence

    A system-level method to validate an AI product: define the task and risk, build a held-out eval set, score it, gate releases, sample for human review, monitor and keep an evidence pack.

    • Intermediate
    • One to two working days for the first suite; minutes per release after that
    • 10 steps

Govern

Decide who and what may act, what needs a human, and how you will show it afterwards.

  • How to Detect Shadow AI in Your Organisation

    Define what counts as unsanctioned AI, then find it through identity grants, network logs, expense data and a short staff survey, rank what you find by the data it touches, replace the risky tools with approved ones, and keep monitoring in a proportionate way.

    • Intermediate
    • About one to two weeks for a first sweep; then a monthly review
    • 8 steps
  • How to Govern AI Agents: Identity, Policy, Approvals

    Govern agents at runtime: list every agent, give each an identity and an owner, write down what it may and may not do in a Trust Profile, enforce allow, deny and approve rules, choose an autonomy level, record every action and review on a schedule.

    • Intermediate
    • About one week for the first inventory, profiles and policy on your main agents; then a standing monthly review
    • 8 steps
  • How to Set Up Human Approval for AI Agents (With Code)

    Decide which agent actions need a person, set thresholds, pause the agent with LangGraph interrupts, route requests to a queue with a timeout that denies by default, show reviewers the evidence, and record every decision.

    • Intermediate
    • About half a day for the design, one to two days to wire in and test
    • 7 steps

Secure

Close the gaps that models, tools and agents open: injection, tool access, red-team testing.

  • How to Red Team an LLM App: Tools, Scoring, Retest

    A step-by-step LLM red-team exercise: authorisation and scope, a threat model mapped to the OWASP LLM Top 10, automated testing with promptfoo, garak and PyRIT, manual attack sessions, scoring, fixes and retest.

    • Advanced
    • Two to five working days for a first exercise on one application
    • 10 steps
  • How to Secure MCP Servers: OAuth, Scopes, Allow-Lists

    Harden an MCP deployment against the attacks the specification names: validate token audience, never pass tokens through, ask for minimal scopes, sandbox local servers, allow-list servers, gate sensitive tools with a human, and log every call.

    • Advanced
    • About half a day to inventory and apply client-side controls; one to three days to harden a server you build
    • 9 steps
  • How to Stop Prompt Injection: Layered Defences That Work

    A layered defence for prompt injection: assume it will happen, keep untrusted content apart from instructions, give agents the fewest tools and shortest-lived privileges, require human approval for risky actions, block data leaving, and test with canary documents.

    • Intermediate
    • About one to two days to map and apply the controls to one application
    • 8 steps

Comply

Work through the EU AI Act and data protection steps in the order a regulator would ask.

  • How to Do a DPIA for AI: GDPR Article 35 Steps

    Decide whether an AI system needs a DPIA, then describe the processing, assess necessity, identify risks to people, choose measures, record the sign-off and review it, with AI-specific risks and a worked example.

    • Intermediate
    • Allow two to five working days for a first DPIA on a moderately complex system, spread over a few weeks for the consultations and sign-off.
    • 7 steps
  • How to Prepare for the EU AI Act: 2026 Readiness Steps

    A readiness workflow for the EU AI Act: inventory AI systems, rule out prohibited uses, set provider or deployer role, classify risk, plan obligations and evidence, and track the dates after the Digital Omnibus.

    • Intermediate
    • About one to two weeks for a first inventory and classification of a mid-sized organisation, longer if tools are bought across many teams. Evidence work continues after.
    • 8 steps

Operate

Keep AI systems affordable, observable and routable once they are in production.

  • How to Migrate from OpenRouter or LiteLLM (Safely)

    Inventory what you use, map model names, replay real requests against old and new routes, switch the base URL, then canary the traffic with a rollback ready.

    • Intermediate
    • About 1 to 2 days of work for one application, plus a canary period of a few days
    • 9 steps
  • How to Monitor AI Agents in Production (2026 Guide)

    Give every agent run an id, record each model and tool step as a span, redact before you store, alert on loops, tool failures and cost per run, and read a weekly sample by hand.

    • Advanced
    • About 4 hours for tracing, redaction and the first alerts; the weekly review is ongoing
    • 8 steps
  • How to Reduce LLM Costs: Step-by-Step Guide (2026)

    Measure token spend per feature first, then apply the levers in order of payoff: output caps, prompt caching, batch APIs, model routing, response caching, and a self-hosting break-even check.

    • Intermediate
    • About 3 hours to add measurement and the first three levers; routing and batch work take longer
    • 8 steps
  • How to Set Up an LLM Gateway with LiteLLM (2026)

    Run the open-source LiteLLM proxy in Docker with a config file, add a model, issue virtual keys with budgets, set fallbacks, wire health checks, and harden it for production.

    • Intermediate
    • About 2 hours to a working, budgeted gateway; a day to production-harden it
    • 9 steps

Request a how-to

Tell us what you are trying to do and what you have already tried. We write the guides people ask for first, and we only publish commands we have checked against the official documentation.

Summaries and the research behind the guides

For coding agents and answer engines

The catalogue is available as JSON at /how-to/index.json, and each guide has a markdown copy at /how-to/<slug>.md. The same guides are listed in llms.txt.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.