Staff signed up on their own
Individual ChatGPT or Claude accounts are appearing on expense claims, and nobody agreed which one the business is standardising on.
A short, practitioner-led review of the artificial intelligence (AI) tools your business already uses and pays for, so you can standardise where the work happens, set rules people can actually follow, and decide the next useful step without buying more technology by default.
Rory does this work himself. You speak to the person doing the review.
This review is for businesses where AI use has already started. It is not an introduction to AI, and it is not a case for adopting it.
Individual ChatGPT or Claude accounts are appearing on expense claims, and nobody agreed which one the business is standardising on.
Copilot seats were bought, and there is no clear answer to who needs one, who is using it, or what changed as a result.
Proposals, reports and client correspondence are being pasted into tools, and the rule for what is acceptable has never been written down.
Two or three overlapping products are being paid for because each team solved the problem separately.
There is a request to connect AI to SharePoint, the CRM or a finance system, and no shared view of what it would then be able to change.
A flow, an agent or a custom assistant exists, and no one can explain what it touches or who signed it off.
If AI use has not started, or none of these sound familiar, start with a Discovery Review to decide the next useful step. It is not limited to AI.
Every finding ends in a decision with a named owner. All of it written down, in plain English, and yours to use whether or not MDE does the work that follows.
Most disagreements about AI risk are really disagreements about which of these four things the system is allowed to do. MDE classifies every proposed use against this ladder before anyone designs anything. Each level requires everything the level below it required, and more.
1
The tool finds or summarises information the person is already entitled to see. Copilot summarising a project folder sits here. This keeps the proposed action at retrieval and summarisation; the underlying permissions still need review.
2
The tool proposes a document, a reply or an answer for a person to accept, edit or reject. A drafted client proposal sits here. Accountability for what is sent stays with the person who sends it.
3
The tool prepares a change and stops, leaving it in a queue for approval. Staged CRM updates sit here. This needs a real approval queue, identity design and an audit trail, not just an intention to check.
4
The tool changes a business record, sends an external message or executes a transaction on its own authority. This is the highest bar: least-privilege access, negative testing, rollback, a named owner and an escalation path.
Where the evidence does not support a higher level, the review says so and recommends Read or Draft. "A human is in the loop" is not a control unless that person has real information and real authority before the change happens.
Said plainly, because a review that turns into something else serves nobody.
MDE does not run a helpdesk. If you need someone on call for prompt help and day-to-day user support, an MSP or an internal owner is the right answer.
The review does not supply, resell or arrange licences, and its findings are not a procurement recommendation. Detailed procurement advice without an architecture or governance mandate is not something MDE takes on.
MDE's Workshop, Training & IP engagement is for turning an agreed policy into practice. It is not a general AI skills programme delivered at volume.
MDE will not design a system that makes consequential decisions about people, such as employment, credit or service access, without a person who has the information and authority to intervene.
MDE identifies exposure, designs controls and tells you what a specialist would need to look at. It does not certify you as compliant and does not give legal advice.
The review earns the right to a good next decision. Where further work is justified, it runs through MDE's existing engagements. There is no separate AI programme.
Front door
Every engagement starts here. The Business AI Review is this review, scoped to the AI decision in front of you.
Then, if justified
Where one workflow warrants proper design: data and identity boundaries, approval, logging, failure and rollback, before anything is built.
Then, if justified
Where a design is approved and one reversible workflow is ready to build, with agreed acceptance checks.
Where practice is the gap
Where a policy or method needs to be adopted, used well and sustained by the team. The outcome is reusable practice, not indefinite consultant dependence.
Where the estate keeps moving
Senior oversight where use cases, connectors and agents keep changing and someone needs to keep making the call.
Scope, exclusions and cost are agreed in writing before any review starts. Implementation is always a separate decision.
Bring the subscriptions you are paying for, the question someone has asked you, or the thing somebody has already built. That is enough to begin.