Find out where you actually stand
A structured look at your data, permissions, security posture, and licensing — ending in a written verdict on whether you're ready to adopt AI, and what to fix first if you're not.
45 min · Free · No commitment
You can't govern what you haven't inventoried
The instinct is to start with tools: which assistant, which license, which pilot group. But an AI assistant is a permissions amplifier. It reads what the user can already read, and it does so instantly, across everything, without the friction that used to keep badly scoped access harmless.
That means the assessment has to start underneath the tooling. Where does data live? Who can reach it? What has already left through unmanaged accounts? What does your licensing actually entitle you to enable?
Those questions are answerable in weeks, not months, and the answers determine everything downstream. Businesses that skip this step tend to discover the gaps in production, which is the expensive way to find them.
What the assessment covers
Data inventory & hygiene review
We map where your business data actually lives — SharePoint, OneDrive, network shares, email, personal accounts, that one server nobody logs into. AI assistants are only as trustworthy as the data they can reach, so this is where the assessment starts.
Permissions & access audit
Who can currently open what. In most businesses this is the finding that stops the project: permissions inherited from a structure that changed three reorganizations ago, sharing links that never expired, and folders marked 'everyone' that shouldn't be. We document it before anything gets switched on.
Shadow AI discovery
What your team is already using without approval, and what has likely left the building through it. This is rarely malicious and almost always present. We establish the real picture rather than the assumed one.
Security posture check
MFA coverage, identity hygiene, endpoint management, and offboarding. AI adoption widens the blast radius of every one of these, so weaknesses that were tolerable before stop being tolerable.
Licensing & platform review
What you're already paying for, what Copilot or an equivalent would actually cost, and whether your current tier supports the controls you'd need. Businesses routinely discover they're licensed for capability they never enabled.
Use-case discovery
Where AI could plausibly help in your specific operation, ranked by whether the work is repetitive, text-heavy, and measurable. Most proposed use cases fail one of those three tests, which is useful to learn early.
Written readiness verdict
A document you can hand to leadership: where you stand on each dimension, what a safe first step looks like, and what it would cost. If the verdict is that you shouldn't adopt yet, it says that plainly and lists what to fix first.
What you walk away with
- A clear yes, not yet, or no — with the reasoning behind it
- A prioritized list of what to fix before any AI tool is switched on
- An honest licensing picture, including what you already own
- Use cases ranked by likely return rather than novelty
- A document that answers the board's AI question without hand-waving
Why this assessment is different
We check the foundations, not the hype.
The assessment is mostly about permissions, data, and identity — the unglamorous things that determine whether AI is safe. That's the work most AI conversations skip.
We're willing to tell you no.
Sometimes the honest conclusion is that a business should fix its access control before adopting anything. We'd rather say that than sell a pilot that creates an incident.
We already run the underlying stack.
Identity, Microsoft 365, endpoint management, and backup are our day job. The readiness gaps we find are gaps we can actually close, not findings we hand off.
AI readiness assessment questions
We just want to turn on Microsoft 365 Copilot. Do we really need an assessment?
That is exactly the case the assessment is built for. Copilot works over whatever each user can already reach in Microsoft 365, so oversharing that has been harmless for years becomes searchable in seconds. We check permissions, sharing links, and your licensing tier first, so switching it on does not surface the wrong files to the wrong people.
What happens if the verdict is "not yet"?
You get an ordered list of what to fix and why, starting with whatever carries the most risk. Because identity, Microsoft 365, and permissions are our day job, we can close those gaps ourselves or hand the list to your team — and then re-check before anyone switches an AI tool on.
What access do you need to run the assessment?
Administrative read access to your identity platform and your Microsoft 365 or Google Workspace tenant, so permissions and sharing can be reviewed from the source rather than from memory. We also talk briefly with a few of the people doing the day-to-day work, because they know where the data really lives and which tools they already use.
How is this different from your vCIO service?
vCIO is an ongoing relationship across your whole IT estate. The AI readiness assessment is a bounded engagement that answers one question: can this business adopt AI without hurting itself, and what is worth doing first. If you have a vCIO relationship with us, the findings go straight into your standing roadmap.
Ready to take this off your plate? Six questions.
Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.