AI Risk and App Vetting
Is It Safe to Let Staff Use AI Tools?
Yes, with guardrails. The risk is rarely the AI itself. It is the app wrapped around it, and what that app is allowed to reach once somebody connects it.
It usually starts innocently. Someone finds a tool that summarizes meetings or cleans up a spreadsheet, connects it to Microsoft 365 or Google Workspace, and clicks through a consent screen that hands it read access to their mailbox or (yikes) every single mailbox in the organization’s tenant. Nobody approved it. Nobody read the privacy policy. Nobody looks at it again.
Worth remembering that if an app is cheap or free, you and your company data are the product. That is not a slogan, it is the business model.
How Do You Decide If an App Can Be Trusted?
First of all, we take the decision-making away from end users. As we all know, George in sales isn’t going to read the privacy policy.
We read the data usage and privacy policies before anything connects to your environment. What the vendor does with your data, where it is stored, whether it is used to train models, and who else it gets shared with.
Then we look at what the app is actually asking for, which is often far more than it needs. A meeting notetaker requesting full mailbox access is telling you something. We weigh the permission scope against the job the tool is supposed to do, and we say no when the two do not match.
What we are protecting is specific: your client records, your financial data, your email history, and anything covered by a regulator or a contract you have signed.
What Happens When Nobody Is Checking?
In most Microsoft and Google environments, any user can authorize a third-party app on their own. No approval, no record, no review. That is how a company ends up exposed to data misuse without a single person making a bad decision on purpose.
We close that door. New connections run through an approval process instead of a consent screen, and we audit what is already connected. Almost every environment we review has something in it that nobody remembers adding.
None of this is a one-time exercise. The tools change monthly, vendors update their terms quietly, and an app that was fine last year may not be fine now. Reviewing it is part of the ongoing relationship, not a project with an end date.
Where We Land on AI
We are not in the business of telling clients to avoid AI. Used well, these tools are genuinely useful, and the companies that work that out early will have an advantage over the ones that do not.
The goal is letting your staff use good tools without handing your client data to a vendor nobody has evaluated. That means having a position on which tools are approved, what can go into them, and who decides. Most small and midsize companies have never had that conversation. We have it with you, write it down, and then enforce it in the environment rather than in a policy document nobody reads.