AI governance that starts with a one-page policy.
AI governance means deciding which AI tools your team can use, writing that down in a plain policy, and training people to follow it. We also handle the setup: a Microsoft Copilot rollout, and turning off the personal AI accounts nobody approved.
AI is already in your business. The question is whether anyone approved it.
Someone on your team is probably already pasting customer information into a personal AI account, or running a browser extension nobody vetted. 63% of breached organizations had no AI governance policy.
IBM Cost of a Data Breach 2025.
A policy doesn't need to be long to work. It needs to say which tools are approved, what data can go into them, and who to ask when a new one shows up. We write it, roll out the tools you approve, and train the team on both.
Rolling out an AI tool the right way.
How a new tool goes from a request to something your team is trained on.
From someone asking to use a tool, to it showing up on the approved list.
- People keep it: Tool requested
Someone asks to use a new AI tool for real work.
- Machines run it: Data risk checked
What it would touch, and whether that's allowed under the policy.
- People keep it: Decision made
Approved, denied, or flagged for review, decided by an owner.
- Machines run it: Access granted
Turned on for the team that asked, logged on the approved list.
- Machines run it: Training sent
A short walkthrough of what it can and can't touch.
- People keep it: Quarterly review
The whole list gets checked again as tools change.
Sample automations.
What triggers each one, what it does, and what a person still checks.
| Automation | Trigger | What it does | A person checks |
|---|---|---|---|
| New tool intake | A request submitted through the AI policy form | Logs it and routes it to the approved-tools review | The risk decision, every time |
| Copilot rollout | A new employee is added to Microsoft 365 | Assigns the right Copilot license and starter training | Which license tier they actually need |
| Policy reminder | Quarterly, on the review date | Sends the current AI policy and approved list to the team | Whether the list still matches reality |
| Unapproved use flagged | A blocked AI tool is used on a managed device | Logs it and notifies the owner | Whether it's a training gap or a policy gap |
Built around Microsoft Copilot and Microsoft 365.
The policy names the tools your team can actually use.
- Microsoft Copilot
- Microsoft 365
- Google Workspace
- HubSpot
What this isn't.
Plain answers to the things owners worry about most.
Questions about AI governance and training.
What is an AI governance policy?
An AI governance policy is a short, written rule set: which AI tools your team can use, what data can go into them, and who decides on a new one. It's the difference between AI arriving on purpose or through a side door.
Do we need a policy if we're small?
Yes. A policy doesn't scale with headcount, it scales with how much customer data your team already handles. One page is usually enough to start.
What does AI training for employees look like?
A short walkthrough for each approved tool: what it's for, what not to paste into it, and who to ask about anything new.
Do you help with Microsoft Copilot specifically?
Yes. Copilot rollout and licensing are usually part of the build, alongside whatever else the policy approves.
What does it cost?
The review is a fixed fee, quoted before we start. The build is fixed scope, usually 4 to 10 weeks, priced before any work begins.
Start with a two-week review.
Fixed fee. You finish with a ranked plan of what to fix first, what it saves and what it protects.
Prefer email? Write to hello@satsumahq.com