AI Readiness Pack
Before you point Microsoft Copilot, ChatGPT, Claude, or an internal agent at your Microsoft 365, make sure it can't surface a salary spreadsheet, a board pack, or an M&A folder to the wrong person.
A no-cost audit of where AI would surface over-shared data - you keep the findings either way.
The problem
Any AI you point at Microsoft 365 - Microsoft Copilot, an enterprise ChatGPT or Anthropic Claude deployment wired to your data, or an internal agent over SharePoint - grants no new access. It works with the permissions each user already has, and simply makes existing access instant and searchable. Most tenants have accumulated years of broad access: organisation-wide sharing links, stale permissions, unlabelled sensitive content, and over-privileged admins. None of it is visible day to day - until a tool that searches across everything at once makes it visible all at once. That is why adopting AI is a security project first and a productivity project second.
What's Included
- An oversharing sweep for organisation-wide links, 'Everyone except external users' access, and stale permissions from people who moved or left
- Microsoft Purview sensitivity labels and Data Loss Prevention (DLP) applied to sensitive content to an agreed threshold
- Identity gaps closed - a Conditional Access baseline and privileged-role review ahead of rollout
- The AI's access scope set deliberately - Microsoft Copilot tenant controls where in use, and the connectors or grounding data any ChatGPT, Claude, or internal agent is allowed to reach
- A written, tenant-specific AI usage policy naming which assistants are sanctioned for which data
- A verification pass confirming the oversharing threshold is met before switch-on
What This Assumes
- Microsoft Purview licensing sufficient for sensitivity labels and Data Loss Prevention at the level agreed - typically Microsoft 365 E5 or the E5 Compliance add-on; a lower tier reduces what can be enforced and is flagged at scoping
- An agreed oversharing threshold, and a named data owner to decide what counts as sensitive
- Administrative access to Microsoft 365, Microsoft Entra, and Microsoft Purview
Not Included
- The AI assistant's own licensing, rollout, and end-user enablement or training
- Building AI agents or automation - that is AI Automation & Secure AI Adoption
- Remediation of data held outside Microsoft 365, and ongoing monitoring - that is the Continuous Evidence retainer
Outcomes
- AI switched on without surfacing data nobody meant to share - Copilot, ChatGPT, Claude, or an internal agent
- Oversharing hotspots found and closed to an agreed, verified threshold
- A clear record of what was already safe, what was fixed, and what to monitor
- AI adoption kept inside governance, with the policy in writing
Who It's For
- Organisations rolling out Microsoft Copilot, an enterprise ChatGPT or Claude deployment, or an internal AI agent over their Microsoft 365 data
- Teams whose staff are already pasting company data into whichever AI assistant they found first
- IT and security teams that need identity and data governance sorted before any AI reads across the estate
How to Start
Most engagements begin with the free audit and go no further until you have seen where you stand.
Oversharing Audit
Free
A no-cost audit of where AI would surface over-shared or sensitive data, followed by a call to talk through the highest-risk findings.
- A take-away report of oversharing hotspots - organisation-wide links, broad access, and unlabelled sensitive content
- The highest-risk exposures identified with you
- A conversation about what fixing them before rollout would involve
No cost, no obligation. We onboard a limited number of new estates each month, and return your findings within 5 working days of read access.
The AI Readiness Pack
from £15,000 / $19,200
A fixed-scope, fixed-price engagement that closes the oversharing and identity gaps and gets you to a verified, safe switch-on.
- Oversharing remediated, with sensitivity labels and DLP applied to the agreed threshold
- Conditional Access and privileged-role gaps closed ahead of rollout
- A written AI usage policy and a verification pass before AI is enabled
Priced by tenant size - larger estates from £25,000 / $32,000. The Switch-On Guarantee: oversharing remediated to the agreed threshold and verified before switch-on, or we keep working free.
Continuous Evidence
from £3,500 / $4,500
An ongoing retainer that keeps AI safe to use - oversharing in check and your readiness evidence current - as your estate and AI use grow.
- A fixed amount of expert time each month on data governance and AI guardrails
- Ongoing oversharing and label monitoring as content and permissions change
- A forward plan reprioritised every month
Month one: an oversharing baseline and a first evidence pack.
Engagement Model
A fixed-scope engagement with a defined start and end, timed to your AI rollout. Defined deliverables, a fixed price, no day rates. Priced by the size of your estate: a smaller tenant starts from £15,000 / $19,200, and a larger one with heavier SharePoint sprawl and more identities from £25,000 / $32,000 - the scope agreed in writing before work starts. Set that against what it protects: an AI licence you are already paying for every month and cannot safely switch on, and a single leak of salary, board, or client data through it. And it is guaranteed: oversharing is remediated to the agreed threshold and verified before switch-on, or we keep working at no extra charge until it is. And it graduates into Continuous Evidence, so AI stays safe to use as your estate grows - oversharing kept in check inside the retainer, not re-audited from scratch each time.
Pricing: from £15,000 / $19,200 - larger engagements are tailored to scope.
We run the policy we would write for you
This engagement produces a written AI usage policy for your tenant, so it is fair to ask what ours looks like. It is published: the providers we use and on what terms, what client data never reaches a model, that a named architect signs off every output, and that AI tooling holds no standing write access to client systems.
Read our AI policyRelated
Before you switch on AI, fix oversharing
The thinking behind this sprint - why AI inherits every permission your users already have.
Microsoft 365 Security & Hardening
The broader identity, device, and data hardening the sprint draws on. Start with a free posture audit.
AI Oversharing Report
Not ready for the full sprint? The fast, fixed-price report that shows what AI would expose before you switch it on.
AI Oversharing Self-Check
Want a free first read? The ten-question self-check flags whether AI would surface over-shared data, before you commit to the report or the sprint.
AI Automation & Secure AI Adoption
Beyond readiness - custom automation and governed OpenAI ChatGPT and Anthropic Claude adoption.
Get started
Find out where you stand, free
Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.