Every data set has an owner. When Copilot arrives, it reads a governed estate.
A firm of 50-200 people holds information that mostly belongs to other people: client files, payroll, the pipeline, the archive. AI reads through the same permissions your people do, so an estate where data is ungoverned is where adoption fails first.
Data is one of the ten domains of The Technology Framework. One dimension of one framework, made AI-ready and owned by a named Head of IT.
Ownership, retention, labels: written down and applied
Data governance is unglamorous and specific. When this dimension of the framework is owned, four things are true and stay true.
Every significant data set has a named owner. The client files, the practice management system, the finance ledger, the shared drive. A person, on the org chart, who answers for it.
Retention is a decision, on a schedule. What the firm keeps, how long it keeps it, and what gets deleted when the clock runs out. Written down, applied, reviewed.
Sensitivity labels people actually use. Applied in Word, Outlook, Teams and SharePoint, where the work happens, so a confidential file behaves like one wherever it travels.
Access that can be explained. Who sees what and why, reviewed on a schedule. Joiners get what the role needs. Movers lose what it no longer needs. Leavers lose everything, the same day.
None of this needs a new department. It needs an owner, a map, and a rhythm.
The starting point
Where most firms begin
The starting point is usually familiar.
A shared drive nobody has mapped, with permissions that grew by copy.
Retention set to keep everything, because deleting felt risky and nobody owned the call.
Access that outlived the leavers it was granted to.
A data register written once, for an audit, and untouched since.
The work starts with the map: what the firm holds, where it lives, who touches it. Everything else is decided from there.
The after-state
When data is owned, awkward questions get short answers.
Who can see the client files? These people, for these reasons. How long do we keep this? This long, then it goes. What would Copilot read? Whatever the labels and permissions allow, and both are governed. The numbers the board reads inherit the same discipline: that is the neighbouring domain, Analytics.
02
AI in data
What it can see. What it must never see.
The enablement
AI is only as good as what it can see, and what it must never see
Copilot, and every agent that follows it, answers from whatever your permissions expose. Point it at a governed estate and it works from the right files. Point it at an overshared drive and it reads the oversharing. Making data AI-ready is the same governance work, done before the pilot rather than after the incident.
What we assess. What AI tools can reach today: the oversharing report, permissions that grew by copy, sensitive sets sitting unlabelled, and the data an actual pilot would need.
What we govern. Ownership, retention, labels and access, applied so the rules a file carries travel with it into anything that reads it, Copilot included.
What we put live. Copilot on a tenant governed through Purview, and production agents grounded on data sets with named owners. Copilot governance and production agents are work we do.
The order of work
Readiness first, then the pilot
The sequence matters. Map what the firm holds. Name the owners. Apply labels and retention. Fix the access. Then switch the pilot on, measured, on the seats that need it.
Skip the sequence and the pilot stalls on the first awkward answer. Run it in order and the pilot starts on an estate that can support it.
Proof you can dial: the voice that answers 0117 456 5486 is our own AI call agent, in production, on our own line. AI as a domain has its own page.
03
How it is bought
Two routes in. Prices published.
The seatALL TEN DOMAINS
Owned through the seat: a fractional Head of IT
Data is one of the ten domains the seat governs.
A named Head of IT, one or two days a week, owns the data map, the owners, the retention schedule and the access reviews, alongside the other nine domains. The MSP applies settings. The board gets the paper.
Entered through the tenant: Microsoft Copilot readiness
Purview and labels are the entry point.
A fixed sprint on the Microsoft 365 tenant: Purview, oversharing, sensitivity labels, the right seats. It is sold as Copilot readiness, and the same work is the working start of data governance, whether or not Copilot follows.
The seat covers all ten domains.Any single domain can be owned on its own, priced in conversation. Data sits alongside nine others on the framework map.
04
How it runs
Diagnose. Deliver. Decide.
01
Diagnose
We sit with the people who actually run the estate. MSP, finance, operations, whoever holds the passwords, and whoever holds the files.
02
Deliver
Visible progress in weeks, with a board-readable outcome. For data, often the map, the named owners, the retention position and the first access review.
03
Decide
It's your call. Keep the seat filled at one or two days a week, or keep the gains and run it yourselves. Either way the place is stronger.
The rhythm
First we listen. Then visible progress, scoped at diagnose. Then it's your call.
The same rhythm as how we work across the whole practice, applied to one domain.
05
FAQs
The questions boards actually ask
Questions
What does data governance mean for a firm of 50-200 people?
Four things, written down and owned. A named owner for every significant data set. A retention position that is applied on a schedule. Sensitivity labels people actually use. Access that can be explained: who sees what and why.
Is this a software project?
No. Most of the work runs on the Microsoft 365 tenant you already pay for: Purview, sensitivity labels, access reviews. The hard part is decisions and ownership. Tooling comes second.
How does this relate to Copilot?
Copilot reads whatever your permissions let it read. If the shared drive is overshared, so is Copilot. That is why the Copilot readiness sprint treats Purview and labels as the entry point: the same work that makes Copilot safe is the working start of data governance.
Do you give legal or GDPR advice?
No. Your DPO or legal adviser owns the legal position. We implement the practical side: the map, the owners, retention that is actually applied, labels and access. That gives whoever owns the legal position an estate they can describe accurately.
Who does the work day to day?
A named senior leads it. Owners inside the firm hold their own data sets: the practice manager, the head of finance, whoever genuinely owns the set. The MSP applies technical settings under that governance. Nothing here creates a new department.
Can we buy data governance on its own?
Yes. Any single domain of the framework can be owned on its own, priced in conversation. The two published routes into data are the seat, from £4,750 a month, and Microsoft Copilot readiness, from £7,500 fixed, where Purview and labels are the entry point.
06
Start the conversation
Bring the thing that hurts
Contact
Start the conversation.
The first conversation costs nothing and changes what happens next. Bring the thing that hurts, or the thing you want to build.
Talk to an agent starts a voice conversation with our own AI agent, right here on the page. Prefer email? Pick the thing that hurts above and your mail app opens with the subject filled in. Nothing sends from this page.