1. Identity and authentication.
How users actually get in, versus how policy says they get in. SSO enforcement, session controls, magic links, service accounts.
A fixed-fee, six-area security and configuration review of your Claude, Copilot, or ChatGPT Enterprise tenant. Findings document in two weeks. No implementation upsell required.
Enterprise AI rollouts are usually configured once, under deadline, by a small IT team doing it for the first time. Then the organization builds on top of that configuration for years.
A recent review we ran was scoped as a pre-launch check of an unused tenant. It wasn't unused. The tenant was live with active users, and the audit logs showed single sign-on connected but not enforced. Staff had been logging in by magic link for a month. Nobody knew, because nobody had looked.
That's not a rare story. That's a Tuesday. The organizations most at risk are the ones handling sensitive data with lean IT teams: donor records, client files, patient information, financials.
How users actually get in, versus how policy says they get in. SSO enforcement, session controls, magic links, service accounts.
Who can do what, who can see what, and whether the role design matches your org chart or just grew.
Every data source your AI tenant can reach, what it can pull, and whether each connection was a decision or a default.
Scoped in or out based on your environment. If your teams use AI coding tools, we review what those tools can touch.
What's being logged, how long it's kept, what your audit trail can actually prove, and what it can't.
The gap between your written AI policy and observed behavior in the logs. Training status. Acceptable-use reality.
A findings document, ranked by risk, written twice: once for your IT lead with technical specifics, once for your leadership and counsel in plain language. Open items flagged inline with recommended owners. If findings warrant implementation work, that's a separate engagement you're free to run internally or bid out. The review stands on its own.
Fixed fee. Defined scope. Two weeks from access to findings.