AI governance & advisory

Get the benefit of the AI your team already uses, without the risk.

Most businesses never decided to adopt AI; their people just started using it. We find out how AI is actually used in your business, what it touches and where it helps, then build the rules and guardrails into the tools themselves, so your team can keep using AI with confidence.

Works with
The AI tools your team already uses: ChatGPT, Microsoft Copilot, Google Gemini, Claude, and the AI features built into the software you run on.
Built around
Your data and your clients' trust. Every finding says what is at stake and what to do about it, in plain English.

What the assessment covers

We look at the work, not just the tools

A list of approved apps tells you very little. What matters is what your people do with AI day to day, and what it touches while they do it.

How AI is used today

Which tools your people use, for what, and on what information, including the personal accounts and browser extensions nobody signed off on.

Where your data goes

Which client, customer and business information reaches which AI services, and on what terms those services hold it.

Your key workflows

Where AI is saving time, where it creates risk or rework, and where it could do much more than it does today.

What's already deployed

AI features, integrations and automations already running, reviewed for what they can see and what they can do.

What you walk away with

Findings you can act on, and guardrails already in place

Not a report to file. Each piece is something your team uses the week it lands.

Findings

  • A map of how AI is used across the business today: which tools, by whom, and on what data
  • Ranked, actionable findings: what to stop, what to fix, and what to expand, each with the reason and the next step
  • A shortlist of the jobs better done by an agent or an automation, with a fixed build price for any you want

Policy

  • A plain-English AI use policy: approved tools, what data may go where, and what needs a person to check it
  • A security and data-handling policy your tools actually enforce, not a PDF nobody reads

Guardrails in the tools

  • Written house rules your AI tools load automatically, so every person gets the same standards
  • Reusable playbooks for the tasks your team repeats, so good prompting stops being tribal knowledge
  • Secure connections between your AI tools and your own systems, limited to what each person needs
  • A review of what's deployed today, with the risky parts fixed rather than just flagged

Why it sticks

Guardrails that live in the tools, not in a binder

A policy document on its own changes very little. Today's AI tools can load written instructions, security rules and reusable skills every time someone uses them, and connect to your own systems with the permissions you choose. We write those for your business and set them up, so the safe way to use AI is also the default way.

How an assessment works

From the first call to guardrails in place

  1. 01

    A 30-minute call

    You tell us how your team works and what worries you about AI. We tell you whether an assessment is a fit and what it would cover.

  2. 02

    Working sessions

    We sit with the people who do the work and trace how it actually moves, and where AI is already part of it.

  3. 03

    Findings and scope

    You get ranked findings and a written scope with a fixed price for the guardrails, plus a build price for anything worth automating.

  4. 04

    Guardrails in place

    We put the policy, house rules, playbooks and connections into your tools and fix the risky parts, then walk your team through what changed.

After the assessment

Keep it right, and build where it pays

Periodic review

AI tools, their terms and the rules around them change fast. An optional periodic review keeps your policy, house rules and playbooks current, and checks whatever has been added since.

Builds where they pay

When the assessment finds a job better done by an agent or an automation, we can build it, then host it for you or hand it over into your own cloud.

See example agents

Questions

What people ask about AI governance

Who needs AI governance?
Any business where people use AI for work, which is now most of them. It matters most where you handle information your clients trust you with: health, legal, financial or personal records, or anything covered by a contract or a regulator. If you can't say today which AI tools your team uses and what goes into them, that is the place to start.
How long does an assessment take?
It depends on the size of the team and how many tools are in play, and your written scope gives the dates. It is built to fit around the work: a few focused working sessions with the people who do the job, not weeks of interviews.
What access do you need?
Time with the people who do the work, and a look at the AI tools and settings they use. We ask for the least access that lets us see how things actually run, and you can revoke it when the work is done.
We're in a regulated industry. Can you help?
Yes. Healthcare, legal, financial services and insurance are where getting this right matters most. We work alongside your compliance obligations and your own advisers rather than replacing them, and the policy and guardrails are written to sit with your existing security and privacy practices. We are not a law firm and do not give legal advice.
What happens if you find something risky?
We tell you plainly, with what is at stake and what to do about it, ranked by how urgent it is. Where the fix is in scope, we make it rather than just flag it.
What does it cost?
A fixed price, quoted in your written scope after the first conversation. It depends on the size of the team and the number of tools involved. The optional periodic review afterwards is priced separately.

Which AI tools is your team using right now?

If you're not sure, that's the first finding. Book 30 minutes and we'll tell you what an assessment would look at.