Your staff are already using AI. The question is which tools, and with whose files.
Nobody announces this. A staff member uses AI now. It works, and it quietly becomes part of how your company operates. This is an audit of what is actually in use, what access those tools hold, and what it would take to make the useful ones safe rather than forbidden.
The self-check is answered from your own tenant. Nothing is submitted to us unless you ask for the written interpretation.
Five minutes, your own tenant
Go and look at one thing
- 1Open the Entra admin centre and go to Enterprise applications.
- 2Filter to applications added in the last twelve months.
- 3Find any your IT provider did not deploy, and open its permissions.
Each one is there because a staff member clicked Accept on a consent screen. Some of those grants carry standing read access to that person's mail and files. They do not expire when the password changes, and in most firms nobody removes them when the person leaves.
Three different problems
Tools holding a key
A consent grant is a standing token, not a session. The tool keeps reading mail and files until someone revokes it, and revocation is nobody's job.
Material pasted, not connected
The larger volume of your business information leaves by copy and paste into a browser tab, with no record of it inside your tenant at all.
Nothing to attest to
Client security questionnaires now ask which AI tools touch their data. A firm that cannot answer in writing might be answering anyway, but badly.
What the audit does
Two weeks, fixed scope, fixed price. Remote, against your tenant. No staff interviews unless you want them β the point is not to catch anyone.
What is covered
What you receive
What this cannot tell you
Material typed or pasted into a browser leaves no trace inside your tenant. We can tell you which tools hold access, which were signed into with work accounts, and what the pattern suggests. We cannot reconstruct every document that has ever been pasted into a chatbot.
The useful output is not a list of offenders. It is a defensible position going forward, and an honest statement of where you are.
Indicative pricing. Scope and final price are confirmed on a short call before any work starts β tenants above roughly 100 seats, or with more than one tenant in play, are quoted separately.
What happens after
Enforcement only holds if someone watches it. Ongoing monitoring of new consent grants and sign-ins, with a monthly exception report. It is not a condition of the audit, and the register is yours regardless.
If you have also licensed Microsoft 365 Copilot, the adjacent question is what it can now surface from inside your own tenant. That is a separate piece of work: the Copilot Exposure Assessment.
Book the audit
$4,500 fixed Β· Two weeks Β· Around two hours in total of your time. Send the details below and we will confirm scope and the final price on a short call before any work starts.
Start with the self-check
Six questions about your own tenant. You get a rating and a plain explanation of what it means, on the spot, without handing over an email address.
Or call (02) 8313 0464 and talk it through first.