The question has stopped being "should we use AI?" and become "how do we do this without client data ending up in personal chatbot accounts?" The answer is unglamorous and works: identity, data and policy first, tools second – all enforced by the Microsoft 365 you already pay for.
Every business we speak to raises the same thing: staff want AI, some are already using it, and nobody's quite sure what data has gone where. The industry numbers say that instinct is right.
Single sign-on and domain capture bring every seat under the business, so access starts and ends with employment. The biggest single risk – personal accounts – is closed first.
Entra conditional access and device compliance rules decide where the approved tool can be used – the same discipline your email and files already get.
Sensitivity labels and DLP protect documents inside Microsoft 365, and Copilot honours them natively. They do not reach inside third-party AI chats – so for Claude or ChatGPT the protection comes from business-plan data terms, what the tool may connect to, and rules people can follow. We put the boundary in writing.
An approved-tools list, plain rules about client data, and enough training that the policy describes reality. Start with our free AI usage policy template – written for Australian SMBs, no email required.
No commissions, no reseller margin on licences – our vendor-neutrality disclosure is public. The tool follows the work, and sometimes the honest answer is "not yet".
Inside the apps your people already use, with tenant permissions applied natively. The governance conversation is easiest here; the licence maths only works for daily users.
Read the honest comparison →Stronger sustained reasoning, drafting and analysis, plus the platform we build automations on. Needs the identity and policy guardrails set up deliberately – which is exactly what we do.
Claude for business, set up properly →The same four layers apply to any tool: business plan, SSO where available, access rules, honest data boundaries. If a niche tool earns its place, it gets governed like the rest.
Ask about a specific tool →Shadow AI exposure snapshot, data governance readiness, the identity and access plan, a vendor-neutral tool recommendation with real licence costs, and a ready-to-adopt AI usage policy. Ends with a fixed-price quote for the rollout.
See the assessment →The controls implemented – SSO and domain capture, conditional access, governance settings – the approved tool deployed on the right plan, the policy adopted, and your staff shown how to use it. You own everything we set up.
Book a 15-minute chat →You can try, and for a few high-risk roles it can be right. For most businesses a pure block fails: staff move to phones and home devices where you have no visibility at all. The pattern that works is an approved tool rolled out properly, visibility over what else is being reached, and a policy people can actually follow.
Only Copilot, which inherits your tenant permissions natively. For third-party tools like Claude or ChatGPT, labels and DLP don't reach inside the chat – protection comes from business-plan data terms, SSO and access rules, and policy. Anyone who tells you otherwise is selling something.
The tool follows the work. Copilot for teams living in Outlook and Teams; Claude for heavier reasoning, drafting and automation; sometimes both, licensed only for the people who'll use them; sometimes none yet. The assessment gives you the recommendation with the licence maths attached.
It raises the bar rather than closing the door: enterprise plan tiers with audit logs and retention controls, tighter access rules, and a policy your compliance obligations can live with. It's a configuration we do often – say so on the scoping call.
Start with the AI-Ready 365 assessment, or grab the free policy template and start the conversation internally.