Skip to content
Griffin IT Group griffin markOakville IT ServicesPowered by Griffin IT Group

Capability

AI Enablement and Automation

AI tooling is easy to switch on and difficult to switch on safely. The gap between those two is almost entirely data permissions and governance.

At a glance

  • Permission remediation before AI rollout
  • Written usage policy and approved tooling
  • Automation of specific, measurable workflows
  • Honest assessment of where AI does not help

Readiness before rollout

Assistants such as Microsoft Copilot surface content the user already has access to. In most environments, years of over-permissive SharePoint sites, broad sharing links and orphaned team sites mean that access is far wider than anyone intends. Enabling AI turns a latent permission problem into an immediate discovery problem.

Readiness work therefore begins with permission review and remediation: site and library permissions, sharing link inventory, sensitivity labelling for material that should not be surfaced, and cleanup of abandoned workspaces.

  • SharePoint and Teams permission review
  • Sharing link inventory and expiry policy
  • Sensitivity labelling for restricted content
  • Orphaned site and workspace cleanup
  • Licensing and pilot group planning

Governance

Staff will use AI tools with or without a policy. A short, specific policy is better than a prohibition nobody follows: which tools are approved, what categories of information may never be entered, when output must be verified, and where client or contractual restrictions apply.

Some sectors carry explicit constraints — client confidentiality, health information, or contract terms restricting where data is processed. Those get identified before tooling is approved rather than after an incident.

  • Approved tool list with sanctioned accounts
  • Prohibited data categories stated plainly
  • Verification expectations for AI output
  • Contractual and regulatory constraints mapped

Automation with measurable outcomes

Beyond assistants, the durable value is in automating specific processes: approval routing, document generation, data movement between systems that currently rely on re-keying, scheduled reporting and notification workflows.

We scope these against a measured baseline — how long the process takes now, how often it is done, where errors occur — so the result can be assessed honestly. Where automation would cost more than the process wastes, we say so.

Questions

Frequently asked questions

Is our data used to train public models?
With enterprise tenancy services under your organisational agreement, generally no. With free consumer tools, frequently yes. That distinction is the main reason to provide sanctioned accounts.
How long does Copilot readiness take?
Assessment is usually two to three weeks. Remediation depends on how much permission sprawl exists — that is the variable, and it is why assessment comes first.
Will you tell us not to do it?
If that is the right answer, yes. Some processes are too variable, too low-volume or too consequential to automate well.

Do the readiness work first

A permission and governance assessment turns AI rollout from an exposure into a controlled programme.