
Introducing AI without giving your data away
Your people already use AI, usually on a personal account. We replace that with a managed environment: permissions cleared up first, then business licences, and a one-page policy people actually read. Copilot, Gemini, ChatGPT or Claude — the choice follows from where your documents already live.
AI is already there, just not on your terms
Whether your people use AI is no longer the question. They do, usually on an account they also have at home.
Someone pastes a complaint letter into a chat window to get a polite reply out of it. Someone has a quote summarised. Someone asks for a spreadsheet formula and pastes in three columns of real revenue alongside it. That does not happen out of defiance, but because it works and because nothing has been agreed. Offer no choice and you get the choice people make themselves.
The distinction that matters is not which vendor you pick but whether you are on the business or the consumer tier. A business agreement states whether your input is trained on, whether there is a data processing agreement and where it is processed. A free account states none of that, which leaves you without any arrangement under the GDPR for personal data that ends up in it.
The real work is in the permissions
An assistant that searches your own files works within the permissions of whoever asks the question. It invents no access. That sounds reassuring and it is not: it means it shows precisely which permissions in your environment are too wide. A site that was once set to "everyone in the organisation" because that was quicker becomes findable on the day you switch the assistant on.
So we look first at what is open organisation-wide and clear it up before the rollout, not after. Cleaning up afterwards means the content has already been out.
What we do not promise
We do not sell a model and we do not claim AI takes over your work. What the assistant produces is a draft, and whoever sends it is the author. Where it concerns people — applications, appraisals, case files — no outcome should come out of a model without somebody looking at it. We write that into your policy too.
What we set up and manage
You choose what you need. Only the baseline assessment, only the rollout, or the whole programme including policy and guidance, within the same agreement and with the same point of contact.
Baseline assessment of permissions and shared folders
Which sites, folders and shareable links are open organisation-wide, and what sits in them. A report you can have in a day, and one that is useful even if you go no further with AI.
Setting up business licences
The vendor that fits where your documents live, on a business subscription with a data processing agreement. Including the settings that decide what the assistant may and may not see.
Blocking consumer accounts
Once there is an approved route, we close the unwanted one. Otherwise company text keeps leaking to accounts with no contract behind them and no visibility for anyone.
AI policy and processing agreements
Which tools are allowed, what does not go into them, who remains responsible and where to go with a question. Plus the arrangements with the vendor, so the paperwork matches practice.
Explanation for the people using it
Not a course with a diploma but an explanation: what it can and cannot do, where it produces confident nonsense, and what you do not put into it. That has also been an obligation since early 2025.
Visibility of what is in use
Which AI services are being used with a work account, visible through your identity provider. That keeps the list accurate instead of something quietly appearing beside it.
Four phases, with a pilot in between
Not everything at once. Whatever a small group hits first would otherwise surface for everybody at the same time.
Baseline assessment
We map which AI tools are already in use and how your permissions stand: what is open organisation-wide, which shareable links have no expiry, where data sits that does not belong there.
Clearing up
The worst places are closed and sensitive folders put out of reach, with labels or by excluding the assistant. This is the part that takes time and the part that makes the difference.
Pilot with ten to twenty people
A defined group on a business licence, so we see what comes up in practice and can adjust the policy before everyone else joins.
Rollout, policy and guidance
The wider rollout, the single page of agreements, explanation for the people using it, and blocking the consumer versions. After that it runs along with regular management.
Goes well with AI
AI rarely stands on its own. These are the services that most often run alongside it.
Questions we get about this
The ones that come up most, answered briefly.
Which AI vendor do you recommend?
That follows from where your documents already live, not from which model scores best this month. If everything is in Microsoft 365, Copilot is the shortest route because it sits inside the programs your people already open and works within your existing permissions. If you work in Google Workspace, the same goes for Gemini. For work that is mostly writing and reasoning we often put ChatGPT or Claude alongside it. Two deliberately chosen tools work better than ten that appeared by themselves.
Why do you start with permissions rather than the licence?
Because an assistant shows what the user could already open. It invents no access, but in a single query it makes visible which SharePoint site was set to "everyone in the organisation" years ago. That is not an AI fault; it is a permissions problem that surfaces on the day you switch it on. We first map what is open organisation-wide, clear that up, and only then roll out.
What do you arrange around the AI Act?
Less than the name suggests, and exactly what does apply. The Act is aimed mainly at those who build AI systems and at high-risk applications; an employee having an email drafted does not fall under it. What applies to everyone is that your people must understand enough about AI to use it sensibly. We write that policy with you, provide the explanation, and make sure the processing agreements match what actually happens.
Want to know what an assistant would find at your place?
In an introductory conversation we go through where you stand: which tools are already in use, how your permissions look and what a sensible first step would be. Including if the answer is to wait a while longer.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.