Skip to main content
Success
Security & governance

Microsoft 365
AI governance

Work through AI adoption with your IT team. We review access, agree which agents can run and test a first use case against the controls your organisation needs.

Agent approval recordIllustrative example
Pilot proposal

Internal policy assistant

A named staff group can ask questions about approved policies. IT controls the source material and permissions.

DataApproved policy site
ActionsRead and answer
AudienceNamed pilot group
Go-live decisionIT review required
Each agent has an owner, an agreed purpose and evidence for approval.
Build on your Microsoft environment

Agree the rules for the actual workflow

A Microsoft licence is the starting point. We establish which products are in use, what they can access and which external services receive data.

Data and permissions

Review the relevant SharePoint sites, files and other sources. Identify oversharing and agree what the proposed assistant should be able to read.

Agents and ownership

Set out who can create, publish and use agents. Name an owner and agree review, approval and retirement arrangements.

Connections and actions

Map connectors, tool permissions and supplier processing. Agree which actions need human approval and how access can be revoked.

Available controls depend on your Microsoft products, licences and tenant configuration. We verify those before promising a particular setup.

A first use case your IT team can review

Review

Understand the block

Confirm the policy, technical concern or missing evidence. Identify the person who can approve the proposed use.

Configure

Apply the controls

Agree the users, data sources, permitted actions and providers. Document the required tenant changes.

Demonstrate

Run a bounded pilot

Use synthetic records first. Test useful work, denied access and the response to unsafe instructions.

Hand over

Evidence and ownership

Review results with IT, record the decision and hand over the configuration and operating instructions.

Your handover

Configuration and evidence

We work alongside internal engineers and external IT providers. The scope identifies who makes changes and who owns the controls afterwards.

  • Agent inventory and named owners
  • Data-flow and supplier processing map
  • Permission and tenant configuration record
  • Pilot tests, results and outstanding actions
  • Approval, review and revocation procedure
Deployment requirements

Choose where processing happens

A Microsoft app registration lets your administrator grant access. Application hosting, model processing, logs and backups need their own design decisions.

We can scope a client-controlled or private deployment where your requirements call for it, and check each supplier’s processing terms.

Private AI deployment ↗
Security requirements

Include the testing IT needs

We can test prompt injection, unsafe actions and data access within the agreed pilot. Application penetration testing and independent assessment can be included where required.

We agree the acceptance criteria and evidence with your IT lead before the pilot begins.

Penetration testing ↗
Our IT team has switched agents off. Can you help?

Yes. We start with the reason for the restriction and work through it with the decision maker. We can propose a limited pilot and the evidence needed for approval. Existing policy stays in force until your organisation approves a change.

Can you work with our AI engineers or IT provider?

Yes. We can own a defined piece of work, such as permission review, governance, a bespoke integration or testing. We agree responsibilities and handover at the start.

Does this include Copilot Studio and external agents?

The engagement can include them. We identify the exact products and connections in scope, then review their permissions, data flows and terms separately. An external agent does not inherit every protection of a Microsoft service just because it appears inside Microsoft 365.

Can we use Raq.com with Microsoft 365 Copilot?

Raq.com provides a package your Microsoft administrator can review and assign. We can run a tenant pilot to verify identity, account permissions, action confirmations and revocation. Raq.com remains a separate service with its own data handling. Read the Raq.com guide for IT teams.

Bring your IT team into the conversation

Send the first job you want an agent to do, the data it would use and any approval requirements. We’ll agree the scope, fee and access needed before work starts.

Message us on WhatsApp