Your staff are already using AI. The open question is which tools, with what company data, and under whose policy. West Computers builds the inventory, policy, and technical controls that let your team use AI productively without pasting client data into a vendor nobody reviewed.
AI adoption in most small businesses did not go through IT. It started with one person pasting a contract into a free chatbot to summarize it, and it spread from there. Nobody signed a vendor agreement, nobody checked where that data is stored, and nobody wrote down what is allowed. That is the exposure — not the model itself.
We start by finding out what is actually in use, then we make a decision on each tool: approved, approved with conditions, or blocked. Approved tools get configured properly and documented. Blocked tools get enforced through application control and network policy rather than an email asking people to stop. Staff get a policy short enough to read and specific enough to follow, plus training on what should never go into a prompt.
Because we already manage the security stack, the controls behind the policy are ones we can enforce and evidence — data classification and loss prevention in Microsoft 365, conditional access on the accounts that reach your data, application control on the endpoint, and monitoring that surfaces new tools as they appear. For regulated clients, every AI vendor gets the same contract and Business Associate Agreement scrutiny as any other subprocessor. If a vendor cannot produce one, it does not touch regulated data.
Related reading: How to run a shadow AI audit without slowing down your team · what happens to private data in public AI tools.
Every deliverable your business receives as part of this service.
We inventory the AI tools already in use — browser extensions, desktop apps, third-party app consents in your Microsoft 365 tenant, and traffic to known AI services. You get a named list, not a guess, with a risk rating on each.
A written policy your staff will actually read: which tools are approved, what data is never permitted in a prompt, how AI output must be reviewed before it goes to a client, and who to ask when something isn't covered.
Sensitivity labeling and data loss prevention configured in Microsoft 365 so regulated and confidential data is flagged and restricted before it leaves your tenant. Unapproved AI applications blocked at the endpoint through application control.
Copilot inherits whatever permissions your users already have. We audit SharePoint and OneDrive oversharing, tighten permissions and sharing links, then scope a pilot group so your first rollout doesn't surface files people were never meant to see.
Every proposed tool reviewed on the terms that matter: where data is stored, whether it trains on your inputs, retention and deletion, subprocessors, security attestations, and whether a Business Associate Agreement is available for regulated data.
Practical, role-relevant training — what AI is good at, where it fails, how to spot a fabricated answer, and how to use approved tools without exposing client data. Paired with awareness training on AI-assisted phishing and voice impersonation.
We identify the AI tools in use across endpoints, browsers, and your Microsoft 365 tenant, and interview department leads on what they are trying to accomplish. Most engagements surface tools leadership did not know were in play.
We map where your sensitive data lives — client records, financials, protected health information, intellectual property — and assess which AI use cases can touch it, which cannot, and what your compliance obligations require in each case.
We write the acceptable-use policy, review and approve a working tool set, and implement the technical controls that back it up: data loss prevention, sensitivity labels, conditional access, and application control on unapproved tools.
Approved tools deployed to a pilot group first, then broadly. Staff trained on the policy and on getting real value out of the approved tools. Managers briefed on how to review AI-assisted work before it reaches a client.
Quarterly review of the tool inventory, new vendor requests, policy exceptions, and control effectiveness. The AI market changes monthly — a policy written once and filed away is out of date by the next quarter.