Every agent your firm runs gets a named owner, only the access it needs, a person checking its work, and a line in an inventory. I build them, govern them, and keep them running inside the Microsoft 365 you already pay for. Columbia, Maryland.
By Mark Lucas, founder of JamesTech LLC, Columbia, MD. Roughly thirty years on the Microsoft stack, three of them at Microsoft. Artemis program contractor at NASA.
An AI agent is different from the software you bought before. It reads your files, sends messages, updates records, and decides what to do next, within whatever permissions somebody gave it. In practice that somebody was often a staff member on a Tuesday afternoon, and nobody wrote it down.
Once an agent can reach your SharePoint, your inbox, your CRM, or your accounting system, it's part of the firm's operations. It needs the same things a new hire needs: a defined job, a manager, access limited to that job, and someone reviewing the work until it earns more trust.
Turning the platform on is the easy part. What the agent is allowed to touch, who answers for it, and what happens when it's wrong, that's the management. Most 5 to 200 person firms don't have anyone doing it.
Ask any AI a question about your business. Does it answer like a teammate, or like a stranger who met you five seconds ago? A managed agent answers like a teammate, because somebody gave it the right context and the right limits.
An agent is only as safe as the identity it runs under, the device it runs on, and the tenant it reads from. So the practice covers the whole stack, from the logins to the workloads to the agents on top, with my Microsoft 365 security partner alongside for the deep security work. One team, one inventory, one report.
| Layer | What gets done |
|---|---|
| Identity and access | Microsoft Entra, MFA, passkeys, Conditional Access, role-based access, admin roles named and reviewed |
| Devices and endpoints | Laptops, desktops, and phones enrolled in Intune, Defender for Endpoint on every one, compliance policies, the unmanaged Macs and home laptops brought in |
| Email and collaboration security | Defender for Office 365 policies, phishing and malware protection tuned, external sharing decided on purpose |
| Microsoft 365 tenant | Licensing, idle seats, groups, guest access, retention, and the SharePoint and Teams structure the agents will read from |
| Backup and recovery | Microsoft 365 backup in place and tested, because "we use Microsoft" is not a backup strategy |
| Monitoring | Security alerts, sign-in risk, and agent run logs watched by a person, with a monthly report you can read |
| Network and hardware | Reviewed for what AI work actually needs. Most firms need fewer upgrades than they've been told |
| The agents | Inventory, owners, identities, permissions, review points, policy, training, and the builds themselves |
How this fits with the IT you already have comes down to three lines:
Whichever it is, nobody outside the firm signs off on what your own agents are allowed to do.
Agents touch email, client records, financial data, and the documents your firm runs on. Without limits they can leak what they read, act on stale information, or automate a step that should have stopped for a person. So every agent I build or take over follows the same five rules, written into its inventory entry.
Regulated data gets the same treatment it gets in my other work. I've handled Controlled Unclassified Information for NASA and delivered for the Department of Justice and NATO, so "where can this data go?" is a question I ask before the build, not after.
Some work should run on its own. A reminder that fires when a report is three days late. A summary of yesterday's meetings waiting in your inbox at 7 AM. A status list updated from a form nobody has to re-key.
Other work should stop and wait. Anything that moves money. Anything about a person's employment. Any message that goes out under the firm's name to a client, a donor, or a regulator. There the agent drafts, and a human sends.
Every firm draws those lines a little differently, based on its risk, its regulators, and its people. Drawing them, in writing, before the first agent runs is most of what management means. Adjusting them as the agents earn trust is the rest.
I'm not selling a platform. Whether the firm is evaluating Microsoft Copilot and Copilot Studio, a Claude organization, ChatGPT for business, or custom agents on Power Automate, Dataverse, and n8n, the management work is the same: inventory, owner, identity, review point, trail.
Most agents I build live inside the firm's own Microsoft 365 tenant and read from SharePoint, because that's where the firm's knowledge already is and where its permissions already apply. That is also what an AI operating system is: the firm's context written down where the agents can read it, under the firm's own control.
If the tenant itself needs work first, idle seats, a shared admin login, files still on an office server, MFA not enforced everywhere, that's the Microsoft 365 side of the practice, and it usually comes before the first agent.
Owners and practice leaders of 5 to 200 person firms who already have AI in the building, some of it sanctioned and some of it not, and nobody whose job it is to own it. Professional services, financial services, nonprofits and church organizations, and manufacturing operations are where I do most of this work.
The usual entry point is the AI Opportunity Review, which produces the first roadmap and the first agent inventory. Ongoing management runs under a Fractional AI Officer retainer, scoped to the size of your team.
The ongoing work of owning the AI agents a business runs: keeping an inventory of them, giving each one a named human owner and only the access it needs, deciding which steps a person reviews, writing the AI use policy, watching what the agents do, and building the next one. I provide it to 5 to 200 person firms in and around Columbia, Maryland, and remotely across the Baltimore-Washington corridor.
Three lines. Already have an MSP? Keep them. No MSP, or ready for a new one? Work with me for everything, with my Microsoft 365 security partner covering the deep security work. Either way, I own the part an MSP isn't doing: the fractional CIO or fractional AI officer role, the agents, and the workloads.
Microsoft Copilot and Copilot Studio, Claude, ChatGPT, and custom agents on Power Automate, Power Apps, Dataverse, and n8n. Most of what I build lives inside your own Microsoft 365 tenant and reads from SharePoint.
No. Reminders and status updates should run on their own. Money, personnel, and anything that goes out under the firm's name should stop for a person. Deciding which is which, in writing, is the first job.
A short call to scope it. Most firms start with the AI Opportunity Review, which produces the first roadmap and the first agent inventory. Ongoing management runs under a retainer sized to your team.
A short call to scope it. You'll leave knowing which agents you already have, which ones are worth building, and who should own each one. Scoped to your team.
Book a scoping call