Microsoft 365
AI governance
Work through AI adoption with your IT team. We review access, agree which agents can run and test a first use case against the controls your organisation needs.
Internal policy assistant
A named staff group can ask questions about approved policies. IT controls the source material and permissions.
Agree the rules for the actual workflow
A Microsoft licence is the starting point. We establish which products are in use, what they can access and which external services receive data.
Data and permissions
Review the relevant SharePoint sites, files and other sources. Identify oversharing and agree what the proposed assistant should be able to read.
Agents and ownership
Set out who can create, publish and use agents. Name an owner and agree review, approval and retirement arrangements.
Connections and actions
Map connectors, tool permissions and supplier processing. Agree which actions need human approval and how access can be revoked.
Available controls depend on your Microsoft products, licences and tenant configuration. We verify those before promising a particular setup.
A first use case your IT team can review
Understand the block
Confirm the policy, technical concern or missing evidence. Identify the person who can approve the proposed use.
Apply the controls
Agree the users, data sources, permitted actions and providers. Document the required tenant changes.
Run a bounded pilot
Use synthetic records first. Test useful work, denied access and the response to unsafe instructions.
Evidence and ownership
Review results with IT, record the decision and hand over the configuration and operating instructions.
Configuration and evidence
We work alongside internal engineers and external IT providers. The scope identifies who makes changes and who owns the controls afterwards.
- Agent inventory and named owners
- Data-flow and supplier processing map
- Permission and tenant configuration record
- Pilot tests, results and outstanding actions
- Approval, review and revocation procedure
Choose where processing happens
A Microsoft app registration lets your administrator grant access. Application hosting, model processing, logs and backups need their own design decisions.
We can scope a client-controlled or private deployment where your requirements call for it, and check each supplier’s processing terms.
Private AI deployment ↗Include the testing IT needs
We can test prompt injection, unsafe actions and data access within the agreed pilot. Application penetration testing and independent assessment can be included where required.
We agree the acceptance criteria and evidence with your IT lead before the pilot begins.
Penetration testing ↗Our IT team has switched agents off. Can you help?
Yes. We start with the reason for the restriction and work through it with the decision maker. We can propose a limited pilot and the evidence needed for approval. Existing policy stays in force until your organisation approves a change.
Can you work with our AI engineers or IT provider?
Yes. We can own a defined piece of work, such as permission review, governance, a bespoke integration or testing. We agree responsibilities and handover at the start.
Does this include Copilot Studio and external agents?
The engagement can include them. We identify the exact products and connections in scope, then review their permissions, data flows and terms separately. An external agent does not inherit every protection of a Microsoft service just because it appears inside Microsoft 365.
Can we use Raq.com with Microsoft 365 Copilot?
Raq.com provides a package your Microsoft administrator can review and assign. We can run a tenant pilot to verify identity, account permissions, action confirmations and revocation. Raq.com remains a separate service with its own data handling. Read the Raq.com guide for IT teams.
Bring your IT team into the conversation
Send the first job you want an agent to do, the data it would use and any approval requirements. We’ll agree the scope, fee and access needed before work starts.