AI governance that starts with a one-page policy.

AI governance means deciding which AI tools your team can use, writing that down in a plain policy, and training people to follow it. We also handle the setup: a Microsoft Copilot rollout, and turning off the personal AI accounts nobody approved.

AI is already in your business. The question is whether anyone approved it.

Someone on your team is probably already pasting customer information into a personal AI account, or running a browser extension nobody vetted. 63% of breached organizations had no AI governance policy.

IBM Cost of a Data Breach 2025.

A policy doesn't need to be long to work. It needs to say which tools are approved, what data can go into them, and who to ask when a new one shows up. We write it, roll out the tools you approve, and train the team on both.

Rolling out an AI tool the right way.

How a new tool goes from a request to something your team is trained on.

From someone asking to use a tool, to it showing up on the approved list.

Machines run it People keep it
  1. People keep it: Tool requested

    Someone asks to use a new AI tool for real work.

  2. Machines run it: Data risk checked

    What it would touch, and whether that's allowed under the policy.

  3. People keep it: Decision made

    Approved, denied, or flagged for review, decided by an owner.

  4. Machines run it: Access granted

    Turned on for the team that asked, logged on the approved list.

  5. Machines run it: Training sent

    A short walkthrough of what it can and can't touch.

  6. People keep it: Quarterly review

    The whole list gets checked again as tools change.

Sample automations.

What triggers each one, what it does, and what a person still checks.

AutomationTriggerWhat it doesA person checks
New tool intakeA request submitted through the AI policy formLogs it and routes it to the approved-tools reviewThe risk decision, every time
Copilot rolloutA new employee is added to Microsoft 365Assigns the right Copilot license and starter trainingWhich license tier they actually need
Policy reminderQuarterly, on the review dateSends the current AI policy and approved list to the teamWhether the list still matches reality
Unapproved use flaggedA blocked AI tool is used on a managed deviceLogs it and notifies the ownerWhether it's a training gap or a policy gap

Built around Microsoft Copilot and Microsoft 365.

The policy names the tools your team can actually use.

  • Microsoft Copilot
  • Microsoft 365
  • Google Workspace
  • HubSpot

What this isn't.

Plain answers to the things owners worry about most.

A ban on AI
The policy approves tools, it doesn't block all of them. Most requests get a yes.
A long document
One page that says what's approved, what isn't, and who to ask. Not something nobody reads.
A black box
The approved list and every decision on it stays visible to your team, not locked in an inbox.

Questions about AI governance and training.

What is an AI governance policy?

An AI governance policy is a short, written rule set: which AI tools your team can use, what data can go into them, and who decides on a new one. It's the difference between AI arriving on purpose or through a side door.

Do we need a policy if we're small?

Yes. A policy doesn't scale with headcount, it scales with how much customer data your team already handles. One page is usually enough to start.

What does AI training for employees look like?

A short walkthrough for each approved tool: what it's for, what not to paste into it, and who to ask about anything new.

Do you help with Microsoft Copilot specifically?

Yes. Copilot rollout and licensing are usually part of the build, alongside whatever else the policy approves.

What does it cost?

The review is a fixed fee, quoted before we start. The build is fixed scope, usually 4 to 10 weeks, priced before any work begins.

Start with a two-week review.

Fixed fee. You finish with a ranked plan of what to fix first, what it saves and what it protects.

Prefer email? Write to hello@satsumahq.com

One line is plenty. We will ask the rest on the call.