The business problem
Employees were already experimenting with AI tools. Without direction, that meant uncertainty about what data could be shared, a mix of unapproved consumer accounts, and people building scripts and automations with AI assistance outside any review process. At the same time, generic chat tools gave limited value because they knew nothing about the company’s own documents and systems.
The goal was to adopt AI deliberately: choose the tools, set clear rules, connect them to real business context, and help people use them well.
Evaluating and choosing the platforms
Compared Microsoft Copilot, Claude, ChatGPT, OpenAI Codex, and GitHub Copilot against how the business actually worked. The program settled around two pillars: Claude for Teams for general work and development, and Microsoft Copilot Studio agents delivered inside Teams for self-service.
Writing the rules first
Authored two separate policies with different audiences. The company-wide AI policy covers approved tools, acceptable use, and how protected information is handled, and was reviewed with HR and business intelligence stakeholders. A companion AI-assisted development policy covers anyone building software with AI help, and is described in its own case study. Where the two overlap, the stricter rule applies.
IT applied the same rules to its own scripts and automations.
Building guardrails into the tools
Data definitions were not left in a document nobody reads. The definition of protected information, the approved-tool rule, and the incident-reporting path were written into org-wide instructions that load into every Claude session. Access and data controls used the identity and information-protection tools the company already ran.
The Claude admin configuration, including org instructions, managed settings, plugin sources, and distributed skills, lives in a version-controlled repository with an edit, review, and apply workflow. Changes are reviewable and recoverable instead of existing only as console settings.
Agents, rollout, and training
Deployed a set of Copilot Studio agents as Teams apps, including an HR and benefits assistant that cites its source documents, internal question-and-answer agents, and agents for engineering workflows. Licenses were rolled out in phases, with power-user enablement, prompt-engineering training, and adoption tracking.
The result
The company had written rules, approved tools, and agents grounded in its own documents, instead of unmanaged experimentation. Policy applies company-wide, while licensed Claude use expands in stages as the program matures.
Governance and enablement worked together: training helped people get value from the tools, and the guardrails kept that use safe and consistent.