Can we trust AI to act on its own?→Governance and guardrails
Who allowed the AI to do that?→Identity travels with every request
Can someone talk the AI into something risky?→Risk-graded autonomy
Can we see who did what, and why?→One thread from request to result
Where are the keys kept?→One vault, no shared secrets
Why did the AI bill jump, and who spent it?→One counted doorway
Is every task getting the right model?→Right model, right task
What if our AI vendor goes down or raises its price?→No single point of supply
Are we paying for tools that do the same job?→One tool per job
Does the AI forget everything between conversations?→Governed shared memory
Is this producing real work, or just answers?→The digital factory
Which work should run itself?→Managed, not scripted
Can we get more from the Copilot licences we already pay for?→Copilot proposes, the platform verifies
Will people actually use it?→Meet people where they work
How much time do people lose sorting inbound information?→Intake to insight, untouched
Can the same platform run a real business?→One governed foundation for every product
What happens when it breaks at night?→Detect, fix, escalate
Where is the list of what is open, and who owns it?→One list, closed with evidence
Could we recover if we lost everything?→Proven by restoring
Can you prove it to an auditor?→Challenge before acceptance
Does it get better over time, or just older?→Every lesson becomes a rule
Will this still work after the next upgrade?→Clean Core for AI
Do our documents match what is actually running?→Documentation as a by-product
Portfolio / Secure by Design
Secure by Design
“Who allowed the AI to do that?”
Security teams stop AI programs when nobody can say who asked an agent to act, or what it was allowed to touch. I designed identity, roles and approvals first, and made the agent work inside them.
Watch the answerWho is your AI acting for?See all six answers
How it works
The flow at a glance.
Signs in with Microsoft 365
Carries the verified identity
Decides which tools exist
Risky actions wait for approval
Who, what and why is kept
Case studies
Secure by Design, case by case.
Agent and user authentication
“Who allowed the AI to do that?”
The conceptIdentity travels with every request
Read the case studyApprovals and guardrails
“Can someone talk the AI into something risky?”
The conceptRisk-graded autonomy
Read the case studyAudit trail
“Can we see who did what, and why?”
The conceptOne thread from request to result
Read the case studySecrets and certificates
“Where are the keys kept?”
The conceptOne vault, no shared secrets
Read the case studyContact
Looking for someone to lead AI from pilot to production?
I would be glad to walk you through any part of this live and talk about the role you have in mind.
j.walters@erpaiintegration.com
Go deeper: Lessons · The journey · How it’s built · Live health