Agentic AI Management · Maryland

AI agents are employees now. Somebody has to manage them.

Every agent your firm runs gets a named owner, only the access it needs, a person checking its work, and a line in an inventory. I build them, govern them, and keep them running inside the Microsoft 365 you already pay for. Columbia, Maryland.

By Mark Lucas, founder of JamesTech LLC, Columbia, MD. Roughly thirty years on the Microsoft stack, three of them at Microsoft. Artemis program contractor at NASA.

The problem

Why an agent needs a manager.

An AI agent is different from the software you bought before. It reads your files, sends messages, updates records, and decides what to do next, within whatever permissions somebody gave it. In practice that somebody was often a staff member on a Tuesday afternoon, and nobody wrote it down.

Once an agent can reach your SharePoint, your inbox, your CRM, or your accounting system, it's part of the firm's operations. It needs the same things a new hire needs: a defined job, a manager, access limited to that job, and someone reviewing the work until it earns more trust.

Turning the platform on is the easy part. What the agent is allowed to touch, who answers for it, and what happens when it's wrong, that's the management. Most 5 to 200 person firms don't have anyone doing it.

Ask any AI a question about your business. Does it answer like a teammate, or like a stranger who met you five seconds ago? A managed agent answers like a teammate, because somebody gave it the right context and the right limits.

The work

What I manage.

  • →Agent inventory and ownership. A single list of every agent, automation, and AI connector in the firm, including the ones staff set up on their own. Each one has a named human owner and a stated job.
  • →AI readiness review. Which workflows are worth automating, whether the data behind them is clean enough, whether the tenant and the devices are ready, and which permissions and policies need to exist before the first agent runs.
  • →Identity and least privilege. Agents run under their own named identities in Microsoft Entra, never a shared login or a personal account. Each one gets only the sites, lists, and mailboxes its job needs. MFA, passkeys, and Conditional Access on the humans, too.
  • →Devices and security monitoring. Every machine an agent or its owner works from is enrolled, protected, and watched: Intune, Defender, sign-in risk, and alerts that a person reads. Done with my Microsoft 365 security partner.
  • →Human review, by design. For each agent, a written answer to "which steps does a person check?" Money, personnel, and anything that goes out under the firm's name stop for a human. Reminders and status updates don't.
  • →The AI use policy. A two-page document staff will actually read: which tools are approved, what data never goes into a consumer chatbot, who owns what, and how to report a problem. Includes the tools people already installed on their own.
  • →Microsoft 365 integration. Agents that read from SharePoint, post in Teams, run through Power Automate, and use Copilot Studio or Claude, all inside your own tenant under your own permissions.
  • →Monitoring and run logs. Every action an agent takes leaves a trail you can read. Failed runs get noticed by me before they get noticed by a client.
  • →The builds themselves. I don't only govern agents, I build them. Approval workflows, document pipelines, meeting debriefs, morning briefs, reactivation outreach, in your voice and on your stack.
  • →Staff training. A short session per quarter on using AI well at the firm: what's allowed, what to check, and who to ask. New agents get a one-page how-to for the people who work with them.
The foundation

Agents run on a stack. I run the stack.

An agent is only as safe as the identity it runs under, the device it runs on, and the tenant it reads from. So the practice covers the whole stack, from the logins to the workloads to the agents on top, with my Microsoft 365 security partner alongside for the deep security work. One team, one inventory, one report.

LayerWhat gets done
Identity and accessMicrosoft Entra, MFA, passkeys, Conditional Access, role-based access, admin roles named and reviewed
Devices and endpointsLaptops, desktops, and phones enrolled in Intune, Defender for Endpoint on every one, compliance policies, the unmanaged Macs and home laptops brought in
Email and collaboration securityDefender for Office 365 policies, phishing and malware protection tuned, external sharing decided on purpose
Microsoft 365 tenantLicensing, idle seats, groups, guest access, retention, and the SharePoint and Teams structure the agents will read from
Backup and recoveryMicrosoft 365 backup in place and tested, because "we use Microsoft" is not a backup strategy
MonitoringSecurity alerts, sign-in risk, and agent run logs watched by a person, with a monthly report you can read
Network and hardwareReviewed for what AI work actually needs. Most firms need fewer upgrades than they've been told
The agentsInventory, owners, identities, permissions, review points, policy, training, and the builds themselves

How this fits with the IT you already have comes down to three lines:

  • →Already have an MSP? Keep them.
  • →No MSP, or ready for a new one? Work with me for everything, from the logins to the agents.
  • →Either way, I own the part an MSP isn't doing: the fractional CIO or fractional AI officer role, the agents, and the workloads your staff use.

Whichever it is, nobody outside the firm signs off on what your own agents are allowed to do.

Governance

Five rules every agent follows.

Agents touch email, client records, financial data, and the documents your firm runs on. Without limits they can leak what they read, act on stale information, or automate a step that should have stopped for a person. So every agent I build or take over follows the same five rules, written into its inventory entry.

  • 01A named owner. A person in your firm, by name, who answers for what the agent does.
  • 02Its own identity. No shared credentials, no borrowed API keys, no running under somebody's personal login.
  • 03Least privilege. Access to the sites, lists, and mailboxes its job needs, and nothing else. Reviewed when the job changes.
  • 04A human review point. Written down per agent. Draft-only for anything outbound until it has earned more.
  • 05A trail. Every run logged. Every failure visible. Nothing silent.

Regulated data gets the same treatment it gets in my other work. I've handled Controlled Unclassified Information for NASA and delivered for the Department of Justice and NATO, so "where can this data go?" is a question I ask before the build, not after.

Judgment

What to automate fully, and what not to.

Some work should run on its own. A reminder that fires when a report is three days late. A summary of yesterday's meetings waiting in your inbox at 7 AM. A status list updated from a form nobody has to re-key.

Other work should stop and wait. Anything that moves money. Anything about a person's employment. Any message that goes out under the firm's name to a client, a donor, or a regulator. There the agent drafts, and a human sends.

Every firm draws those lines a little differently, based on its risk, its regulators, and its people. Drawing them, in writing, before the first agent runs is most of what management means. Adjusting them as the agents earn trust is the rest.

Platforms

Copilot, Claude, ChatGPT, or custom.

I'm not selling a platform. Whether the firm is evaluating Microsoft Copilot and Copilot Studio, a Claude organization, ChatGPT for business, or custom agents on Power Automate, Dataverse, and n8n, the management work is the same: inventory, owner, identity, review point, trail.

Most agents I build live inside the firm's own Microsoft 365 tenant and read from SharePoint, because that's where the firm's knowledge already is and where its permissions already apply. That is also what an AI operating system is: the firm's context written down where the agents can read it, under the firm's own control.

If the tenant itself needs work first, idle seats, a shared admin login, files still on an office server, MFA not enforced everywhere, that's the Microsoft 365 side of the practice, and it usually comes before the first agent.

Fit

Who hires this.

Owners and practice leaders of 5 to 200 person firms who already have AI in the building, some of it sanctioned and some of it not, and nobody whose job it is to own it. Professional services, financial services, nonprofits and church organizations, and manufacturing operations are where I do most of this work.

The usual entry point is the AI Opportunity Review, which produces the first roadmap and the first agent inventory. Ongoing management runs under a Fractional AI Officer retainer, scoped to the size of your team.

Questions

The honest answers.

What is agentic AI management? +

The ongoing work of owning the AI agents a business runs: keeping an inventory of them, giving each one a named human owner and only the access it needs, deciding which steps a person reviews, writing the AI use policy, watching what the agents do, and building the next one. I provide it to 5 to 200 person firms in and around Columbia, Maryland, and remotely across the Baltimore-Washington corridor.

Do we still need a separate IT provider? +

Three lines. Already have an MSP? Keep them. No MSP, or ready for a new one? Work with me for everything, with my Microsoft 365 security partner covering the deep security work. Either way, I own the part an MSP isn't doing: the fractional CIO or fractional AI officer role, the agents, and the workloads.

Which AI platforms do you manage? +

Microsoft Copilot and Copilot Studio, Claude, ChatGPT, and custom agents on Power Automate, Power Apps, Dataverse, and n8n. Most of what I build lives inside your own Microsoft 365 tenant and reads from SharePoint.

Does every agent need a person approving its work? +

No. Reminders and status updates should run on their own. Money, personnel, and anything that goes out under the firm's name should stop for a person. Deciding which is which, in writing, is the first job.

How do we start? +

A short call to scope it. Most firms start with the AI Opportunity Review, which produces the first roadmap and the first agent inventory. Ongoing management runs under a retainer sized to your team.

Find out what's already running in your building.

A short call to scope it. You'll leave knowing which agents you already have, which ones are worth building, and who should own each one. Scoped to your team.

Book a scoping call

← Back to JamesTech