An AI rollout program is the work of turning “our staff are already using AI” into a set of approved tools, a written policy, data that is classified before an assistant can read it, tenant controls that enforce the policy, a pilot group, and a review cadence. We run that program for Los Angeles businesses deploying Microsoft 365 Copilot, Claude, or both, in six stages over roughly eight to twelve weeks.

The reason it needs stages is that the risk is not the model. It is your file shares. Microsoft 365 Copilot answers a user’s question using content the user already has permission to open, which means a decade of overshared SharePoint sites becomes searchable by plain question rather than by knowing where to look. Microsoft describes the same problem and its controls in its own oversharing blueprint for Copilot deployments.

What the program covers

  1. Assessment. What AI tools are already in use, what data they can access, and where the permissions are wrong.
  2. Policy. A governance policy (AI Acceptable Use Policy or AI AUP) for the business and an acceptable use policy for employees. They are different documents.
  3. Data classification. A small label set is applied where it matters, before an assistant is turned on.
  4. Tenant controls. Data loss prevention, oversharing controls, and audit logging are configured in accordance with the policy.
  5. Pilot. A named group, a fixed period, and a decision at the end of it.
  6. Training and review. Role-based training at rollout, then a standing review of usage, exceptions, and new tools.

Stage 1: Assessment

We start by finding out what is already happening because, in every engagement so far, something has been. The assessment covers which AI tools staff have signed up for with a work email, which have been granted access to your Microsoft 365 or Google Workspace tenant through an OAuth consent, what your current sharing settings expose, and which SharePoint sites or shared drives hold sensitive content with permissions nobody has reviewed since they were created.

The output is a short written finding: the tool inventory, the data exposure list ranked by severity, and the specific items that must be fixed before a Copilot or Claude rollout, rather than after.

Stage 2: Policy

Two documents, because they answer different questions. The governance policy specifies who approves a new AI tool, what review it undergoes, which data classifications may be used with which tools, how usage is logged, and who owns the decision in the event of a dispute. The acceptable use policy is the employee-facing version: what you may paste into an assistant, what you may not, what you have to check before you act on an answer, and who to ask.

We write against the environment we found in stage 1 rather than from a template, and we align the structure with a recognized framework. Hence, the document survives a customer security questionnaire. The usual references are the NIST AI Risk Management Framework (NIST AI 100-1, published January 2023) and ISO/IEC 42001:2023 for organizations that need a certifiable management system.

If you want to read where we stand before engaging, our AI governance policy framework and our guide to an AI acceptable use policy for business are both published in full.

Stage 3: Data Classification

Classification schemes fail when they have too many labels. We start with three or four, mapped to how your business actually talks about its information, then apply them where the exposure is: client files, financials, HR records, and anything covered by a contractual confidentiality obligation.

In Microsoft 365, these are Purview sensitivity labels, and the practical benefit for an AI rollout is label inheritance. When Copilot generates a document from a labeled source, the generated item carries the label, so the protection follows the content into its new form. Encryption applied by a label also keeps Copilot entirely out of the most sensitive items, which is often the simplest control available.

Stage 4: Tenant Controls

This is the configuration work, where a governance policy becomes more than a document.

  • Oversharing controls first. Restricted SharePoint Search limits Copilot to an approved list of sites while the permissions cleanup is underway, and data access governance reports identify the sites that need that cleanup. Microsoft documents both in its Restricted SharePoint Search guidance.
  • Data loss prevention for AI interactions. Purview DLP has a policy location for Microsoft 365 Copilot and Copilot Chat that can stop prompts containing specific types of sensitive information from being processed and can exclude files with particular sensitivity labels from being used as grounding data. The behavior is described in Microsoft’s DLP for Copilot documentation.
  • Endpoint DLP for third-party assistants. On Windows devices onboarded to Purview, endpoint policies can warn on or block pasting sensitive content into generative AI sites in a browser. This is how you manage the tools you have not approved without pretending nobody uses them.
  • Posture management. Purview Data Security Posture Management for AI reports on which sensitive items are being referenced in assistant responses, which is the feedback loop that tells you whether the classification work landed.
  • Audit and retention. Copilot interactions are auditable and discoverable through the same Microsoft 365 tooling as email and files. We turn that on and set retention deliberately rather than accepting the default.
  • Identity. Conditional access and multi-factor authentication on the accounts that now have a much faster path to your whole document estate.

For Claude deployments the control surface is different: a business or enterprise plan, single sign-on, administrative control of which connectors and integrations are enabled, and clarity in the policy about what may be pasted rather than what may be indexed. We configure both stacks the same way in one respect: the tool follows the classification rather than the other way around.

Stage 5: Pilot

A pilot is a named group of 10 to 25 people, a fixed period of four to six weeks, a small number of use cases they were actually asked to try, and a decision at the end. We collect what worked, what produced output nobody trusted, what the audit logs show about which content was reached, and what the DLP policies caught. The output is a go, no-go, or fix-first recommendation with the reasons attached.

Running a pilot without a decision date is the most common way for an AI program to stall, so the date is set at the start.

Stage 6: Training and Ongoing Review

Training is role-based and short. Leadership gets the governance model and the exception process. Managers know how to review AI-assisted work. Everyone gets the acceptable use policy in plain language, with the three or four examples from your own business that matter most.

The review cadence is quarterly for usage, exceptions, and newly requested tools, and annually for the policy itself. New assistants appear faster than policies get rewritten, which is why the governance policy defines an approval path rather than a fixed list of approved products.

What this does not cover

We are not building or fine-tuning models, and we do not write the parts of an AI policy that are legal opinions. Where a rollout touches regulated data, we work alongside your counsel and your compliance obligations rather than replacing them. We help you meet the requirements; we do not issue the certification itself.

Contact Be Structured to schedule an AI governance assessment for your organization.

Be Structured Technology Group has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, and runs security operations, identity, and Microsoft 365 administration for the same clients we run AI governance for. That matters here because the controls in stage 4 are tenant configuration work rather than a separate product.

➤ Schedule Your Free IT Assessment

Frequently Asked Questions About AI Governance and Copilot Rollouts

What is an AI governance program, and how is it different from an AI policy?

A policy is a document. A program is the work that makes the document true: an assessment of what is already in use, the policy itself, a data classification scheme, tenant controls that enforce it, a pilot, training, and a review cadence. Businesses that write the policy and stop usually find within a quarter that staff behavior did not change, because nothing in the environment was configured to match what the policy said.

Is Microsoft 365 Copilot safe to turn on for a small business?

It is safe in that it respects existing permissions, and risky in that most businesses do not know what those permissions are. Copilot answers a user with content the user could already open, so overshared SharePoint sites and stale group memberships become findable by asking a question rather than by knowing where to look. The fix is to run the permissions and classification work first, use oversharing controls such as Restricted SharePoint Search while that work is underway, and then enable broadly.

How long does a Copilot or Claude rollout take?

Eight to twelve weeks for a business of 25 to 250 people, assuming the Microsoft 365 environment is in reasonable shape. Assessment and policy take two to three weeks; classification and tenant configuration take three to four weeks; the pilot takes four to six weeks with overlap; and training happens at rollout. The variable that stretches the timeline is nearly always permissions remediation discovered during the assessment.

What data should never go into an AI assistant?

That is a policy decision, not a technical one, which is why the classification stage comes first. In practice, the categories that most Los Angeles businesses restrict are client data covered by a confidentiality agreement, regulated data such as protected health information or cardholder data, credentials and keys, unreleased financial results, and anything covered by legal privilege. The useful move is to define those categories once, label them, and then enforce the rule with data loss prevention rather than relying on staff to remember it.

Can we control which AI tools employees use?

Partly, and pretending otherwise is why the use of shadow AI is common. You can control which applications are granted access to your Microsoft 365 or Google Workspace tenant, which are installed on managed devices, and what can be pasted into a browser-based assistant from a device onboarded to endpoint data loss prevention. What you cannot control is a personal phone. The policy has to account for that, which usually means defining what may be shared rather than only which products are banned.

Do we need Microsoft Purview to do this?

Not to write the policy, and yes, to enforce most of it inside Microsoft 365. Sensitivity labels, data loss prevention for Copilot interactions, endpoint controls for third-party assistants, and posture reporting are all Purview capabilities, and some of them require higher-tier licensing. Part of the assessment is to tell you what your current licensing already includes, since businesses frequently own capabilities they have never enabled.

How do we prove to a client or an insurer that we govern the use of AI?

With the artifacts the program produces: a written governance policy with an approval path, an acceptable use policy that staff have acknowledged, a classification scheme, the configured controls with evidence, training records, and the review minutes. Aligning the structure to the NIST AI Risk Management Framework or ISO/IEC 42001 makes those artifacts easier to map onto a customer security questionnaire, which is usually the form the question arrives in.

What does an AI governance engagement cost?

It is scoped per environment rather than per seat because the work is driven by how much remediation is needed for permissions and classification. The assessment is priced separately, so you can see the findings before committing to the rest. Clients on our managed services agreements have the tenant configuration work covered under the existing agreement rather than as a separate project. Could you ask for the assessment quote first?